| CEF Key | Description | Value | 
|---|---|---|
| Header (logVer) | CEF format version | CEF:0 | 
| Header (vendor) | Appliance vendor | Trend Micro | 
| Header (pname) | Appliance product | Apex Central | 
| Header (pver) | Appliance version | 2019 | 
| Header (eventid) | Behavior Monitoring: Policy ID | BM:1000 | 
| Header (eventName) | Log name | Behavior Monitoring | 
| Header (severity) | Severity | 3 | 
| rt | Log generation time in UTC | Example: "Feb 14 2017 11:14:08 GMT+00:00" | 
| dvchost | Host name | Example: "localhost" | 
| cn1Label | Corresponding label for the "cn1" field | "Risk Level" | 
| cn1 | Risk level | 
 | 
| cs2Label | Corresponding label for the "cs2" field | "Policy ID" | 
| cs2 | Policy ID | 
 | 
| sproc | Aegis subject | Example: "C:\\Windows\\SysWOW64\\rundll32.exe" | 
| cn2Label | Corresponding label for the "cn2" field | "Event Type" | 
| cn2 | Event type | 
 | 
| cs1Label | Corresponding label for the "cs1" field | "Target" | 
| cs1 | Target host | Example: "HKCU\\Software\\Microsoft\\Windows\ \CurrentVersion\\Run\\COM+" | 
| act | Translated action | 
 | 
| cn3Label | Corresponding label for the "cn3" field | "TranslatedAegisOperation" | 
| cn3 | Operation for the translated Aegis object | 
 | 
| shost | Source host (endpoint) | Example: "shost1" | 
| src | Source host IP address | Example: "10.0.147.105" | 
| deviceFacility | Product | Example: "Apex One" | 
Log sample:
CEF:0|Trend Micro|Apex Central|2019|BM:1000|Behavior Monit oring|3|rt=Aug 16 2017 05:00:40 GMT+00:00 dvchost=localhost cn1Label=Risk_Level cn1=1 cs2Label=Policy cs2=1000 sproc=C:\ \Windows\\SysWOW64\\rundll32.exe cn2Label=Event_Type cn2=4 c s1Label=Target cs1=HKCU\\Software\\Microsoft\\Windows\\Curre ntVersion\\Run\\COM+ act=3 cn3Label=Operation cn3=302 shost= shost1 src=10.0.76.40 deviceFacility=Apex One
 
		