Expressions in CEF format for structured data
Structured data in CEF format contains one or more properties, which are represented as key-value pairs.
About this task
You can extract properties from an event that is presented in CEF format by writing a CEF expression that matches the property. Valid CEF expressions are in the form of either a single key reference, or a special CEF header field reference.
CEF:0|ABC Company|SystemDefender|1.13|console_login|Console Login|1|start=Oct 18 2017 11:26:03 duser=jsmith cs1=John Smith cs1Label=Person Name cs2=interactivePassword cs2Label=authType src=220.127.116.11
You can extract a property or a header key property from the event by choosing one of the following methods:
- To extract the 'cs1' property, type
cs1in the Expression field.The possible keys that can be extracted are:
- To extract a header key property, type the key in the following format in the
$id$The CEF header values can be extracted by using the following expressions: