Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

FireEye Sample Event Message

Use this sample event message to verify a successful integration with JSA.

Note:

Due to formatting issues, paste the message format into a text editor and then remove any carriage return or line feed characters.

FireEye sample message when you use the Syslog or TLS syslog protocol

The following sample event message shows that an Indicator of Compromise (IOC) was detected.

Table 1: Highlighted values in the FireEye event payload

JSA field name

Highlighted values in the event payload

Event ID

IOC Hit Found

Event Category

FireEyeMPS (extracted from the event content)

Destination IP

192.168.1.172

Destination MAC

00-00-5e-00-53-00

Log Source Time

Jul 23 2019 16:54:24 UTC