<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Request for CEF(ArcSight) Fields Description for Harmony Mobile in Mobile</title>
    <link>https://community.checkpoint.com/t5/Mobile/Request-for-CEF-ArcSight-Fields-Description-for-Harmony-Mobile/m-p/155765#M859</link>
    <description>&lt;P&gt;Hello Team,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Previously I posted in the community for the help on log reference guide for Harmony Mobile.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was provided solution to refer&amp;nbsp;&lt;SPAN&gt;sk144192.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I went through all the fields but I could not find any field matching of my CEF Harmony Mobile(Sandblast Mobile) Log.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Request all to provide log reference guide or fields description which can explain me CEF (ArcSight) syslog fields of Harmony Mobile.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our CEF format for reference:&lt;/P&gt;&lt;P&gt;CEF:0|Check Point|SMB|XXX|XXX|Application|X|act=XXX alert_details=XXXX app_name=XXX app_package=XXX bssid=None cat=Alert cnt=XX cs1=XX cs1Label=DeviceType cs2=XX cs2Label=Phone cs3=XX cs3Label=OSLevel cs4=XX cs4Label=DeviceDetails cs5=None cs5Label=NetworkCertificate cs6=XX cs6Label=Current Device Risk deviceDirection=XX deviceExternalId=XX deviceInboundInterface=XX device_client_version=XX duid=XXX duser=XX dvchost=XX externalId=dXX fileHash=XX fileId=XXX filePermission=XX fileType=XXXXXXXXXXXXXXXXXX msg=XXXXXXXXXXX resource=None rt=XX sender=None sms_urls=XX ssid=XX start=XX suid=XX suser=XX&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 26 Aug 2022 09:33:57 GMT</pubDate>
    <dc:creator>Devavrat</dc:creator>
    <dc:date>2022-08-26T09:33:57Z</dc:date>
    <item>
      <title>Request for CEF(ArcSight) Fields Description for Harmony Mobile</title>
      <link>https://community.checkpoint.com/t5/Mobile/Request-for-CEF-ArcSight-Fields-Description-for-Harmony-Mobile/m-p/155765#M859</link>
      <description>&lt;P&gt;Hello Team,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Previously I posted in the community for the help on log reference guide for Harmony Mobile.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was provided solution to refer&amp;nbsp;&lt;SPAN&gt;sk144192.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I went through all the fields but I could not find any field matching of my CEF Harmony Mobile(Sandblast Mobile) Log.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Request all to provide log reference guide or fields description which can explain me CEF (ArcSight) syslog fields of Harmony Mobile.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our CEF format for reference:&lt;/P&gt;&lt;P&gt;CEF:0|Check Point|SMB|XXX|XXX|Application|X|act=XXX alert_details=XXXX app_name=XXX app_package=XXX bssid=None cat=Alert cnt=XX cs1=XX cs1Label=DeviceType cs2=XX cs2Label=Phone cs3=XX cs3Label=OSLevel cs4=XX cs4Label=DeviceDetails cs5=None cs5Label=NetworkCertificate cs6=XX cs6Label=Current Device Risk deviceDirection=XX deviceExternalId=XX deviceInboundInterface=XX device_client_version=XX duid=XXX duser=XX dvchost=XX externalId=dXX fileHash=XX fileId=XXX filePermission=XX fileType=XXXXXXXXXXXXXXXXXX msg=XXXXXXXXXXX resource=None rt=XX sender=None sms_urls=XX ssid=XX start=XX suid=XX suser=XX&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Aug 2022 09:33:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Mobile/Request-for-CEF-ArcSight-Fields-Description-for-Harmony-Mobile/m-p/155765#M859</guid>
      <dc:creator>Devavrat</dc:creator>
      <dc:date>2022-08-26T09:33:57Z</dc:date>
    </item>
    <item>
      <title>Re: Request for CEF(ArcSight) Fields Description for Harmony Mobile</title>
      <link>https://community.checkpoint.com/t5/Mobile/Request-for-CEF-ArcSight-Fields-Description-for-Harmony-Mobile/m-p/156303#M860</link>
      <description>&lt;P&gt;Suggest discussing the requirement further with your local SE / TAC who can enquire further on your behalf.&lt;/P&gt;
&lt;P&gt;Meanwhile if I find an alternate reference I will update you here.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Sep 2022 07:43:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Mobile/Request-for-CEF-ArcSight-Fields-Description-for-Harmony-Mobile/m-p/156303#M860</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-09-02T07:43:36Z</dc:date>
    </item>
  </channel>
</rss>

