Help Center
< All Topics
Print

CEF Key Names For Event Consumers

CEF Specification VersionCEF Field NameCEF Key Name / AbbreviationData TypeLength / SizeDescription
0.1agentDnsDomainagentDnsDomainString255The DNS domain name of the ArcSight connector that processed the event.
0.1agentNtDomainagentNtDomainString255 
0.1agentTranslatedAddressagentTranslatedAddressIpAddress  
0.1agentTranslatedZoneExternalIDagentTranslatedZoneExternalIDString200 
0.1agentTranslatedZoneURIagentTranslatedZoneURIString2048 
0.1agentZoneExternalIDagentZoneExternalIDString200 
0.1agentZoneURIagentZoneURIString2048 
0.1agentAddressagtIpAddress The IP address of the ArcSight connector that processed the event.
0.1agentHostNameahostString1023The hostname of the ArcSight connector that processed the event.
0.1agentIdaidString40The agent ID of the ArcSight connector that processed the event.
0.1agentMacAddressamacMacAddress The MAC address of the ArcSight connector that processed the event.
0.1agentReceiptTimeartDateTime The time at which information about the event was received by the ArcSight connector.
0.1agentTypeatString63The agent type of the ArcSight connector that processed the event
0.1agentTimeZoneatzString255The agent time zone of the ArcSight connector that processed the event.
0.1agentVersionavString31The version of the ArcSight connector that processed the event.
0.1customerExternalIDcustomerExternalIDString200 
0.1customerURIcustomerURIString2048 
0.1destinationTranslatedZoneExternalIDdestinationTranslatedZoneExternalIDString200 
0.1destinationTranslatedZoneURIdestinationTranslatedZoneURIString2048The URI for the Translated Zone that the destination asset has been assigned to in ArcSight.
0.1destinationZoneExternalIDdestinationZoneExternalIDString200 
0.1destinationZoneURIdestinationZoneURIString2048The URI for the Zone that the destination asset has been assigned to in ArcSight.
0.1deviceTranslatedZoneExternalIDdeviceTranslatedZoneExternalIDString200 
0.1deviceTranslatedZoneURIdeviceTranslatedZoneURIString2048The URI for the Translated Zone that the device asset has been assigned to in ArcSight.
0.1deviceZoneExternalIDdeviceZoneExternalIDString200 
0.1deviceZoneURIdeviceZoneURIString2048Thee URI for the Zone that the device asset has been assigned to in ArcSight.
0.1destinationGeoLatitudedlatDouble The latitudinal value from which the destination’s IP address belongs.
0.1destinationGeoLongitudedlongDouble The longitudinal value from which the destination’s IP address belongs.
0.1eventIdeventIdId This is a unique ID that ArcSight assigns to each event.
0.1rawEventrawEventString4000 
0.1sourceGeoLatitudeslatDouble  
0.1sourceGeoLongitudeslongDouble  
0.1sourceTranslatedZoneExternalIDsourceTranslatedZoneExternalIDString200 
0.1sourceTranslatedZoneURIsourceTranslatedZoneURIString2048The URI for the Translated Zone that the destination asset has been assigned to in ArcSight.
0.1sourceZoneExternalIDsourceZoneExternalIDString200 
0.1sourceZoneURIsourceZoneURIString2048The URI for the Zone that the source asset has been assigned to in ArcSight.
1.2agentTranslatedZoneKeyagentTranslatedZoneKeyLong64-bitID of an agentTranslatedZone resource reference.
1.2agentZoneKeyagentZoneKeyLong64-bitID of an agentZone resource reference.
1.2customerKeycustomerKeyLong64-bitID of a customer resource reference.
1.2destinationTranslatedZoneKeydestinationTranslatedZoneKeyLong64-bitID of a destinationTranslatedZone resource reference.
1.2destinationZoneKeydZoneKeyLong64-bitID of a destinationZone resource reference.
1.2deviceTranslatedZoneKeydeviceTranslatedZoneKeyLong64-bitID of a deviceTranslatedZone resource reference.
1.2deviceZoneKeydeviceZoneKeyLong64-bitID of a deviceZone resource reference.
1.2sourceTranslatedZoneKeysTranslatedZoneKeyLong64-bitID of a sourceTranslatedZone resource reference.
1.2sourceZoneKeysZoneKeyLong64-bitID of a sourceZone resource reference.
1.2parserVersionparserVersionString8The release timestamp (DD-MM-YY) of the parser file that processed the event.
1.2parserIdentifierparserIdentifierString36The parser ID of the parser file that processed the event.

Table of Contents
en_USEnglish