This page (revision-1) was last changed on 29-Nov-2024 16:16 by UnknownAuthor

Only authorized users are allowed to rename pages.

Only authorized users are allowed to delete pages.

Page revision history

Version Date Modified Size Author Changes ... Change note

Page References

Incoming links Outgoing links

Version management

Difference between version and

At line 1 added 99 lines
!!! Overview
[{$pagename}] ([CEF]) is a [Logging] and [Auditing] file format from [ArcSight] and is an extensible, text-based format designed to support multiple device types by offering the most relevant information.
Message syntaxes are reduced to work with [ESM] normalization. Specifically, [{$pagename}] defines a syntax for log records comprised of a standard header and a variable extension, formatted as key-value pairs.
[{$pagename}] can be used with on-premise devices by implementing the [ArcSight] Syslog SmartConnector.
[{$pagename}] can also be used by cloud-based service providers by implementing the SmartConnector for [ArcSight] Common Event Format [REST].
[{$pagename}] is probably the widest used [Logging] and [Auditing] file format.
!! More Information
There might be more information for this subject on one of the following:
[{ReferringPagesPlugin before='*' after='\n' }]