CEE Profile: cee_base_profile

Related Links
CEE ProfileXMLcee_base_profile.xml
Associated SchemaXSDcee-profile.xsd
CEE HomepageHTMLhttp://cee.mitre.org

Base Profile

Summary
Includes0
Tag Types2
Tags61
Field Types34
Fields242
Event Profiles

cee_base_event


Includes

Tag Types

Tag TypeactionTag
Tag TypestatusTag

Tags

Tagaccess
TypeactionTag
TitleAccess Event
DescriptionA file, user account, network share, or other object has been accessed. If more is known regarding the access, use a more precise action such as read, write, or execute.
Tagalert
TypeactionTag
TitleAlert Event
Tagallocate
TypeactionTag
TitleAllocate Event
Metadata
Tagallow
TypeactionTag
TitleAllowed Event
Metadata
Tagaudit
TypeactionTag
TitleAudit Event
Tagbackup
TypeactionTag
TitleBackup Event
Tagbind
TypeactionTag
TitleBind Event
Tagblock
TypeactionTag
TitleBlock Event
Metadata
Tagclean
TypeactionTag
TitleClean Event
Tagclose
TypeactionTag
TitleClose Event
Tagcompress
TypeactionTag
TitleCompress Event
Metadata
Tagconnect
TypeactionTag
TitleConnect Event
Tagcopy
TypeactionTag
TitleCopy Event
DescriptionAn object was duplicated or copied. Commonly copied objects include files, partitions, and database tables.
Tagcreate
TypeactionTag
TitleCreate Event
DescriptionAn object was created. Commonly created objects include files, accounts, and roles. If the object is a stream or session, then the action open must be used.
Metadata
Tagdecode
TypeactionTag
TitleDecode Event
Tagdecompress
TypeactionTag
TitleDecompress Event
Metadata
Tagdecrypt
TypeactionTag
TitleDecrypt Event
Metadata
Tagdepress
TypeactionTag
TitleDepress Event
Metadata
Tagdetect
TypeactionTag
TitleDetect Event
DescriptionFinding evidence of something as it is occurring, usually through the use of sensors or triggers. For example, an attack or exploit can be detected as it is occurring, or evidence of the event can be found through later searches.
Tagdisconnect
TypeactionTag
TitleDisconnect Event
Metadata
Tagdownload
TypeactionTag
TitleDownload Event
Metadata
Tagencode
TypeactionTag
TitleEncode Event
Metadata
Tagencrypt
TypeactionTag
TitleEncrypt Event
Metadata
Tagexecute
TypeactionTag
TitleExecute Event
DescriptionAn object (usually a file or memory) was run or executed.
Metadata
Tagfilter
TypeactionTag
TitleFilter Event
Tagfind
TypeactionTag
TitleFind Event
DescriptionAn object was found, usually as a result of a search or scan, such as an anti-virus product found malware or an IDS found suspicious packets.
Tagfree
TypeactionTag
TitleFree Event
DescriptionThe deallocation or freeing of memory
Metadata
Tagget
TypeactionTag
TitleGet Event
Taginitialize
TypeactionTag
TitleInitialize Event
DescriptionInitialize memory or set a buffer or variable to their initial values.
Taginitiate
TypeactionTag
TitleInitiate Event
DescriptionInitiate an external connection, stream, or other object, usually as part of a hand-shake or other initialization process
Taginstall
TypeactionTag
TitleInstall Event
Metadata
Taglock
TypeactionTag
TitleLock Event
Metadata
Taglogin
TypeactionTag
TitleLogin Event
DescriptionA user or other entity gains access to a system through a successful authentication or login attempt
Metadata
Taglogout
TypeactionTag
TitleLogout Event
DescriptionAn entity that has already gained access to a system or application (through a login action), ends their user account session. Another session can be established to the user account only through another successful logon action.
Metadata
Tagmodify
TypeactionTag
TitleModify Event
Tagmove
TypeactionTag
TitleMove Event
DescriptionAn object was moved. Usually 'move' describes the moving of a file between directories. A 'move' may be implemented as a sequence of copy and remove actions.
Tagopen
TypeactionTag
TitleOpen Event
Metadata
Tagread
TypeactionTag
TitleRead Event
Metadata
Tagrelease
TypeactionTag
TitleRelease Event
Metadata
Tagremove
TypeactionTag
TitleRemove Event
Metadata
Tagreplicate
TypeactionTag
TitleReplicate Event
Tagresume
TypeactionTag
TitleResume Event
Metadata
Tagsave
TypeactionTag
TitleSave Event
Tagscan
TypeactionTag
TitleScan Event
Tagsearch
TypeactionTag
TitleSearch Event
DescriptionAn actor (user or application) searched or queried for something. For 'search' actions, the object should contain the query of what was sought.
Tagstart
TypeactionTag
TitleStart Event
DescriptionA service, task, scan, or related object activity has begun.
Metadata
Tagstop
TypeactionTag
TitleStop Event
DescriptionA service, task, scan, or related activity was been stopped, usually by another process or user, or due to an error condition.
Metadata
Tagsuspend
TypeactionTag
TitleSuspend Event
Metadata
Taguninstall
TypeactionTag
TitleUninstall Event
Metadata
Tagunlock
TypeactionTag
TitleUnlock Event
Metadata
Tagupdate
TypeactionTag
TitleUpdate Event
Tagupgrade
TypeactionTag
TitleUpgrade Event
DescriptionA type of update that upgrades an entire application, usually involving substantial changes and a change in major version numbers. For example, installing the Microsoft Windows XP Service Pack 2 (SP2) would upgrade a base Windows XP installation.
Metadata
Tagupload
TypeactionTag
TitleUpload Event
Metadata
Tagviolate
TypeactionTag
TitleViolate Event
DescriptionThe infringement or breaking of a policy, rule, or other guideline.
Tagwrite
TypeactionTag
TitleWrite Event
DescriptionAn object (usually a file or memory location) was written to.
Metadata
Tagcancel
TypestatusTag
TitleEvent Canceled
DescriptionThe event action was canceled
Tagerror
TypestatusTag
TitleEvent Errored
DescriptionThe event action terminated with an error
Tagfailure
TypestatusTag
TitleEvent Failed
DescriptionThe event failed due to some unmet condition, such as an incorrect password
Tagongoing
TypestatusTag
TitleEvent Ongoing
DescriptionThe event has started and has yet to complete. Another event should be sent to notify when the event completed and the final status
Tagsuccess
TypestatusTag
TitleEvent Success
DescriptionThe event completed successfully. For example, a successful user authentication event would be an instance where the authentication activity was successfully completed and the user was fully authenticated.
Tagunknown
TypestatusTag
TitleEvent Status Unknown
DescriptionThe result state of an event occurrence was unknown. It was not known to the observer of the event whether or not the event successfully completed.

Field Types

Field TypeactionTagType
Tag Restriction
Field Typebinary
TitleBinary
DescriptionA sequence of binary octets
Field Typeboolean
TitleBoolean
DescriptionA Boolean value: "true" or "false"
String Restriction
Field Typecpe
TitleCommon Platform Enumeration (CPE) Formatted String Identifier
DescriptionA Common Platform Enumeration (CPE) 2.3 Formatted String identifier as listed http://nvd.nist.gov/cpe.cfm or http://cpe.mitre.org
String Restriction
Field Typecve
TitleCommon Vulnerability and Exposure (CVE) Identifier
DescriptionA Common Vulnerability and Exposure (CVE) identifier as listed http://nvd.nist.gov or http://cve.mitre.org
String Restriction
Field TypedirEnum
TitleThe direction of something, such as a network flow
String Restriction
Field Typeduration
TitleDuration
DescriptionThe specification of a period of time, or duration. Due to problems with the processing and calculations surrounding the use of the XML Schema 1.0 xs:duration datatype, this definition is most compatible with IETF RFC 3339 http://tools.ietf.org/html/rfc3339, and fully compatible with ISO 8601:2004 and XML 1.0 xs:duration definitions http://dotat.at/tmp/ISO_8601-2004_E.pdf, http://www.w3.org/TR/xmlschema-2/#duration. For use with events and to avoid issues surrounding time duration calculations with days and months, the CEE duration field type only supports the specification of duration in seconds, minutes, hours, and days
String Restriction
Field TypeemailAddress
TitleE-mail Address
String Restriction
Field Typefloat
TitleFloating-point Number
DescriptionA floating-point number, represented as a 64-bit binary ("double") IEEE floating point
String Restriction
Field Typefqdn
TitleFully-Qualified Domain Name (FQDN)
String Restriction
Field Typehostname
TitleHostname
Union

localHostname

or

fqdn

or

ldapName

or

netbiosName

Field TypeidType
String Restriction
Field Typeinteger
TitleInteger
DescriptionA bounded integer that is constrained to a 64-bit integer value.
Integer Restriction
Field Typeipv4Address
TitleIPv4 Address
DescriptionAn IPv4 address, represented in dot-decimal notation
String Restriction
Field Typeipv6Address
TitleIPv6 Address
DescriptionAn IPv6 address, represented in hex-colon notation according to the IETF RFC 4291 specification http://tools.ietf.org/html/rfc4291. The IPv6 address should adhere to the recommendations in RFC 5952 http://tools.ietf.org/html/rfc5952
String Restriction
Field TypelatDecDegrees
TitleLatitude in Decimal Degrees
Float Restriction
Field TypeldapName
TitleLDAP Distinguished Name
DescriptionDistinguished name (DN) as defined in IETF RFC 4514 and used by LDAP
String Restriction
Field TypelocalHostname
TitleLocal Hostname
String Restriction
Field TypelongDecDegrees
TitleLongitude in Decimal Degrees
Float Restriction
Field TypemacAddress
Title48-bit MAC Hardware Address
String Restriction
Field TypenetbiosName
TitleNetBIOS Name
DescriptionThe NetBIOS name or domain of a system
String Restriction
Field Typenumber
TitleNumber
DescriptionAn unbounded integer value. This is comparable to the XML Schema 1.0 xs:integer simpleType.
String Restriction
Field Typesigned16
Integer Restriction
Field Typesigned32
Integer Restriction
Field Typesigned8
Integer Restriction
Field TypessidType
String Restriction
Field TypestatusTagType
Tag Restriction
Field Typestring
TitleUnicode String
DescriptionA sequence of characters
Field Typetag
TitleCEE Taxonomy Tag
Tag Restriction
Field Typetimestamp
TitleTimestamp
DescriptionA date and time according to the IETF RFC 3339 http://tools.ietf.org/html/rfc3339 specification, which provides an ISO 8601:2004 and xs:dateTime compatible definition http://dotat.at/tmp/ISO_8601-2004_E.pdf, http://www.w3.org/TR/xmlschema-2/#dateTime
String Restriction
Field Typeunsigned16
Integer Restriction
Field Typeunsigned32
Integer Restriction
Field Typeunsigned8
Integer Restriction
Field Typeuri
String Restriction

Fields

Fieldacct_disabled_bool
Typeboolean
TitleAccount Disabled
DescriptionIf 'true', the account has been disabled
Fieldacct_disabled_bool_old
Typeboolean
TitlePrevious Account Disabled
Description*Previous* If 'true', the account has been disabled
Fieldacct_domain
Typestring
TitleAccount Domain
DescriptionThe local domain or system to which the account belongs
Fieldacct_domain_old
Typestring
TitlePrevious Account Domain
Description*Previous* The local domain or system to which the account belongs
Fieldacct_fullname
Typestring
TitleAccount FullName
DescriptionThe full name of the user persona associated with the account
Fieldacct_fullname_old
Typestring
TitlePrevious Account FullName
Description*Previous* The full name of the user persona associated with the account
Fieldacct_grp_id
Typestring
TitleAccount Group ID
DescriptionThe ID of the group to which the user account belongs
Fieldacct_grp_id_old
Typestring
TitlePrevious Account Group ID
Description*Previous* The ID of the group to which the user account belongs
Fieldacct_grp_name
Typestring
TitleAccount Group Name
DescriptionThe name of the group to which the user account belongs
Fieldacct_grp_name_old
Typestring
TitlePrevious Account Group Name
Description*Previous* The name of the group to which the user account belongs
Fieldacct_home_path
Typestring
TitleAccount Home Directory
DescriptionThe home directory associated with the user account
Fieldacct_home_path_old
Typestring
TitlePrevious Account Home Directory
Description*Previous* The home directory associated with the user account
Fieldacct_id
Typestring
TitleAccount ID
DescriptionThe unique identifier assigned to the user account, often called the user id (UID)
Fieldacct_id_old
Typestring
TitlePrevious Account ID
Description*Previous* The unique identifier assigned to the user account, often called the user id (UID)
Fieldacct_locked_bool
Typeboolean
TitleAccount Locked Out
DescriptionIf 'true', the account has been locked out
Fieldacct_locked_bool_old
Typeboolean
TitlePrevious Account Locked Out
Description*Previous* If 'true', the account has been locked out
Fieldacct_login_time
Typetimestamp
TitleAccount Login Time
DescriptionThe time the account was last logged into
Fieldacct_login_time_old
Typetimestamp
TitlePrevious Account Login Time
Description*Previous* The time the account was last logged into
Fieldacct_name
Typestring
TitleAccount Name
DescriptionThe name of the user account
Fieldacct_name_old
Typestring
TitlePrevious Account Name
Description*Previous* The name of the user account
Fieldacct_priv
Typestring
TitleAccount Privilege
DescriptionAccount privileges
Fieldacct_priv_old
Typestring
TitlePrevious Account Privilege
Description*Previous* Account privileges
Fieldacct_pwAge_dur
Typeduration
TitleAccount Password Age
DescriptionThe age of the account password
Fieldacct_pwReq_bool
Typeboolean
TitleAccount Password Required
DescriptionIf 'true', the account requires a password
Fieldacct_pwReq_bool_old
Typeboolean
TitlePrevious Account Password Required
Description*Previous* If 'true', the account requires a password
Fieldacct_role
Typestring
TitleAccount Role
DescriptionThe role assigned to the user account. Used for role-based access control (RBAC) and in systems such as Security Enhanced (SE) Linux
Fieldacct_role_old
Typestring
TitlePrevious Account Role
Description*Previous* The role assigned to the user account. Used for role-based access control (RBAC) and in systems such as Security Enhanced (SE) Linux
Fieldacct_script_path
Typestring
TitleAccount Script Path
DescriptionThe script path ($PATH) used by the user account
Fieldacct_script_path_old
Typestring
TitlePrevious Account Script Path
Description*Previous* The script path ($PATH) used by the user account
Fieldaction
TypeactionTagType
TitleEvent Action
Fieldbios_name
Typestring
TitleSystem BIOS Name
Fieldbios_name_old
Typestring
TitlePrevious System BIOS Name
Fieldbios_time
Typetimestamp
TitleSystem BIOS Timestamp
Fieldbios_time_old
Typetimestamp
TitlePrevious System BIOS Timestamp
Fieldbios_ver
Typestring
TitleSystem BIOS Version
Fieldbios_ver_old
Typestring
TitlePrevious System BIOS Version
Fieldconf
Typestring
TitleEvent Record Confidence
Fieldcount
Typeunsigned32
TitleEvent Count
DescriptionThe number of times similar events were observed
Fieldcrit
Typestring
TitleEvent Criticality
DescriptionAn identification of the event's criticality. This criticality is specific to the event source and should be interpreted within the role of the event source
Fielddirection
TypedirEnum
TitleNetwork Flow Direction
DescriptionThe direction of the network flow, relative to the observer. A value of "in" indicates an ingress (inbound) flow direction; "out" indicates an egress (outbound) flow (to keep compatibility with the IPFIX specification
Fielddst_ipv4
Typeipv4Address
TitleDestination IPv4 Address
Fielddst_ipv6
Typeipv6Address
TitleDestination IPv6 Address
Fielddst_mac
TypemacAddress
TitleDestination Mac Address
DescriptionThe destination MAC (IEEE-802) address
Fielddst_port
Typeunsigned16
TitleDestination Transport Port
DescriptionThe destination port number
Fielddst_prefix_ipv4
Typeipv4Address
TitleDestination IPv4 Prefix
DescriptionThe prefix for the destination IPv4 address. The relevant number of prefix bits should be specified in the dst_prefix_len field
Fielddst_prefix_ipv6
Typeipv6Address
TitleDestination IPv6 Prefix
DescriptionThe prefix for the destination IPv6 address. The relevant number of prefix bits should be specified in the dst_prefix_len field
Fielddst_prefix_len
Typeunsigned8
TitleDestination IP Address Prefix Length
DescriptionThe size (in number of bits) used to specify the destination IP address prefix from a dst_prefix_ipv4 or dst_prefix_ipv6 field
Fielddur
Typeduration
Fieldeff_grp_id
Typestring
TitleEffective Group ID
DescriptionThe identifier of the primary group associated with the effective/authorized user session
Fieldeff_grp_name
Typestring
TitleEffective Group Name
DescriptionThe name of the primary group associated with the effective/authorized user session
Fieldeff_id
Typestring
TitleEffective ID
DescriptionThe effective or authorized user ID (UID) for the current user session
Fieldeff_name
Typestring
TitleEffective Name
DescriptionThe effective or authorized user name associated with the current user session
Fieldemail_from_email
TypeemailAddress
TitleEmail 'From:' Address
Fieldemail_subj_str
Typestring
TitleEmail 'Subject' Line
Fieldemail_to_email
TypeemailAddress
TitleEmail 'To:' Address
Fieldend_time
Typetimestamp
TitleEvent End Time
DescriptionAn ISO8601 compliant timestamp designating the date, time, and timezone offset when the event completed
Fieldfile_a_time
Typetimestamp
TitleFile Last Accessed Time
DescriptionThe time the file was last accessed. On Unix systems, this information can be found by calling stat() on a file inode
Fieldfile_a_time_old
Typetimestamp
TitlePrevious File Last Accessed Time
Description*Previous* The time the file was last accessed. On Unix systems, this information can be found by calling stat() on a file inode
Fieldfile_bytes
Typeinteger
TitleFile Size in Bytes
DescriptionThe size of the file in 8-bit bytes
Fieldfile_bytes_old
Typeinteger
TitlePrevious File Size in Bytes
Description*Previous* The size of the file in 8-bit bytes
Fieldfile_c_time
Typetimestamp
TitleFile Create Time
DescriptionThe time the file was created. On Unix systems, this information can be found by calling stat() on a file inode
Fieldfile_c_time_old
Typetimestamp
TitlePrevious File Create Time
Description*Previous* The time the file was created. On Unix systems, this information can be found by calling stat() on a file inode
Fieldfile_data
Typebinary
TitleFile Contents
Fieldfile_data_old
Typebinary
TitlePrevious File Contents
Fieldfile_dev_id
Typestring
TitleFile Device ID
Fieldfile_dev_id_old
Typestring
TitlePrevious File Device ID
Fieldfile_dev_path
Typestring
TitleFile Device Path
Fieldfile_dev_path_old
Typestring
TitlePrevious File Device Path
Fieldfile_drive_name
Typestring
TitleFile Drive
Fieldfile_drive_name_old
Typestring
TitlePrevious File Drive
Fieldfile_ext
Typestring
TitleFile Extension
Fieldfile_ext_old
Typestring
TitlePrevious File Extension
Fieldfile_fullpath
Typestring
TitleFile Full Path
DescriptionThe path to the file that is the object of the event, including the file name
Fieldfile_fullpath_old
Typestring
TitlePrevious File Full Path
Description*Previous* The path to the file that is the object of the event, including the file name
Fieldfile_grp_name
Typestring
TitleFile Group
Fieldfile_grp_name_old
Typestring
TitlePrevious File Group
Fieldfile_id
Typestring
TitleFile Identifier
Fieldfile_id_old
Typestring
TitlePrevious File Identifier
Fieldfile_inode_num
Typeinteger
TitleFile Inode
Fieldfile_inode_num_old
Typeinteger
TitlePrevious File Inode
Fieldfile_m_time
Typetimestamp
TitleFile Modify Time
DescriptionThe time the file was last modified. On Unix systems, this information can be found by calling stat() on a file inode
Fieldfile_m_time_old
Typetimestamp
TitlePrevious File Modify Time
Description*Previous* The time the file was last modified. On Unix systems, this information can be found by calling stat() on a file inode
Fieldfile_md5_hash
Typebinary
TitleFile MD5 Hash
Fieldfile_md5_hash_old
Typebinary
TitlePrevious File MD5 Hash
Fieldfile_mode
Typestring
TitleFile Mode
Fieldfile_mode_old
Typestring
TitlePrevious File Mode
Fieldfile_name
Typestring
TitleFile Name
Fieldfile_name_old
Typestring
TitlePrevious File Name
Fieldfile_path
Typestring
TitleFile Path
DescriptionThe directory path to the file, excluding the file name
Fieldfile_path_old
Typestring
TitlePrevious File Path
Description*Previous* The directory path to the file, excluding the file name
Fieldfile_perm
Typestring
TitleFile Permissions
DescriptionThe permissions assigned to the file by the operating system or file system
Fieldfile_perm_old
Typestring
TitlePrevious File Permissions
Description*Previous* The permissions assigned to the file by the operating system or file system
Fieldfile_secAttr
Typestring
TitleFile Security Attributes
Fieldfile_secAttr_old
Typestring
TitlePrevious File Security Attributes
Fieldfile_sha1_hash
Typebinary
TitleSHA1 File Hash
Fieldfile_sha1_hash_old
Typebinary
TitlePrevious SHA1 File Hash
Fieldfile_sha256_hash
Typebinary
TitleSHA256 File Hash
Fieldfile_sha256_hash_old
Typebinary
TitlePrevious SHA256 File Hash
Fieldfile_sys_id
Typestring
TitleFile System ID
Fieldfile_sys_id_old
Typestring
TitlePrevious File System ID
Fieldfile_user_name
Typestring
TitleFile Owner Username
DescriptionThe name of the user account that owns the file
Fieldfile_user_name_old
Typestring
TitlePrevious File Owner Username
Description*Previous* The name of the user account that owns the file
Fieldfname_a_time
Typetimestamp
TitleFilename Last Accessed Time
DescriptionThe time the filename was last accessed by the filesystem
Fieldfname_a_time_old
Typetimestamp
TitlePrevious Filename Last Accessed Time
Description*Previous* The time the filename was last accessed by the filesystem
Fieldfname_c_time
Typetimestamp
TitleFilename Create Time
DescriptionThe time the file's filename was created in the filesystem
Fieldfname_c_time_old
Typetimestamp
TitlePrevious Filename Create Time
Description*Previous* The time the file's filename was created in the filesystem
Fieldfname_m_time
Typetimestamp
TitleFilename Modify Time
DescriptionThe time the file's filename was last modified in the filesystem
Fieldfname_m_time_old
Typetimestamp
TitlePrevious Filename Modify Time
Description*Previous* The time the file's filename was last modified in the filesystem
Fieldicmp_code
Typeunsigned8
TitleIPv4 ICMP Code
DescriptionThe code from the "TypeCode" Description of an IPv4 ICMP message. The TypeCode value is designated to be: (256 * ICMP Type) + ICMP Code
Fieldicmp_type
Typeunsigned8
TitleIPv4 ICMP Type
DescriptionThe type from the "TypeCode" Description of an IPv4 ICMP message. The TypeCode value is designated to be: (256 * ICMP Type) + ICMP Code
Fieldid
Typestring
TitleEvent ID
DescriptionA unique identifier provided by the event producer that identifies the type of event. If the identifier is intended to be globally unique reference to a specific event instance, use rec_id field instead. Examples of event identifiers are the Microsoft Windows Event ID, the Cisco PIX ID (e.g., %PIX-2-106001), or the Sourcefire Snort snortid.
Fieldin_bytes
Typeinteger
TitleInbound (Ingress) Bytes
DescriptionThe number of incoming bytes received from the network
Fieldin_pkts
Typeinteger
TitleInbound (Ingress) Packet Count
DescriptionThe number of incoming packets received from the network
Fieldip_dscp
Typeunsigned8
TitleIP Differentiated Service Class
DescriptionFor IPv4 packets, this is the value of the TOS field in the IPv4 packet Description. For IPv6 packets, this is the value of the Traffic Class field in the IPv6 packet Description.
Fieldip_frag_id
Typeunsigned32
TitleIPv4/IPv6 Fragment Identification
DescriptionThe fragmentation of the IP packet. This value is in the IPv4 "Identification" Description field or in the IPv6 "Fragment" Description
Fieldip_frag_offset
Typeunsigned16
TitleIPv4/IPv6 Fragment Offset
DescriptionThe value of the IP fragment offset field in the IPv4 packet Description or the IPv6 Fragment Description
Fieldip_multicastRep_count
Typeunsigned32
TitleMulticast Replication Factor
DescriptionThe amount of multicast replication that's applied to a traffic stream
Fieldip_proto_id
Typeunsigned8
TitleProtocol ID Number
DescriptionThe protocol ID value identifying the encapsulated IP payload. The protocol ID values are established by IANA and contained in the Description of an IP packet. In IPv4 packets, the protoID is in the "Protocol" field; in IPv6 packets, the value is in the "Next Description" field
Fieldip_ttl
Typeunsigned8
TitleTime To Live (TTL)
DescriptionThe TTL (Time-to-Live) value specified in the "ttl" field of the IP packet
Fieldip_ver
Typeunsigned8
TitleIP Version
DescriptionThe value of the IPv6 Flow Text_Title field in the IP packet Description.
Fieldipv6_extHdrs_count
Typeunsigned32
TitleIPv6 Extension Descriptions
DescriptionThe number of extension Descriptions attached to the IPv6 packet(s)
Fieldipv6_flow_label
Typeunsigned32
TitleIPv6 Flow Label
DescriptionThe value of the IPv6 Flow Label field in the IPv6 packet Description.
Fieldmem_avail_bytes
Typeinteger
TitleAvailable Physical Memory In Bytes
Fieldmem_avail_bytes_old
Typeinteger
TitlePrevious Available Physical Memory In Bytes
Fieldmem_total_bytes
Typeinteger
TitleTotal Physical Memory In Bytes
Fieldmem_total_bytes_old
Typeinteger
TitlePrevious Total Physical Memory In Bytes
FieldnextHop_ipv4
Typeipv4Address
TitleIPv4 Next Hop Address
DescriptionThe IPv4 address of the next hop
FieldnextHop_ipv6
Typeipv6Address
TitleIPv6 Next Hop Address
DescriptionThe IPv6 address of the next hop
Fieldout_bytes
Typeinteger
TitleOutbound (Egress) Bytes
DescriptionThe number of outgoing bytes sent to the network
Fieldout_pkts
Typeinteger
TitleOutbound (Egress) Packet Count
DescriptionThe number of outgoing packets sent to the network
Fieldp_proc_id
Typestring
TitleProducer Process ID
Fieldp_proc_name
Typestring
TitleProducer Process Name
Fieldp_prod_cpe
Typecpe
TitleProducer Product CPE Identifier
Description*Event Producer* The CPE Identifier corresponding to the product. The CPE name should be listed in http://nvd.nist.gov/cpe.cfm or http://cpe.mitre.org
Fieldp_prod_id
Typestring
TitleProducer Product Identifier
Fieldp_prod_name
Typestring
TitleProducer Product Name
Fieldp_prod_vend
Typestring
TitleProducer Product Vendor
Fieldp_prod_ver
Typestring
TitleProducer Product Version
Fieldp_sys_domain
Typestring
TitleProducer System Domain
Fieldp_sys_fqdn
Typefqdn
TitleProducer System Fully-Qualified Domain Name (FQDN)
Fieldp_sys_host
Typehostname
TitleProducer System Name
Fieldp_sys_id
Typestring
TitleProducer System Identifier
Fieldp_sys_ipv4
Typeipv4Address
TitleProducer System IPv4 Address
Fieldp_sys_ipv6
Typeipv6Address
TitleProducer System IPv6 Address
Fieldp_sys_lat
TypelatDecDegrees
TitleProducer System Latitude
Description*Event Producer* The latitude of the system, in decimal degrees
Fieldp_sys_loc
Typestring
TitleProducer System Location
Description*Event Producer* A description of the physical location of the system
Fieldp_sys_long
TypelongDecDegrees
TitleProducer System Longitude
Description*Event Producer* The longitude of the system, in decimal degrees
Fieldp_sys_mac
TypemacAddress
TitleProducer System Interface MAC Address
Description*Event Producer* The 48 or 64-bit MAC (Media Access Control), EUI (Extended Unique Identifier), or hardware address of the system
Fieldp_sys_netBIOS
Typestring
TitleProducer System NetBIOS Name
Fieldp_sys_ntDomain
Typestring
TitleProducer System NT Domain
Fieldpri
Typeinteger
TitleEvent Priority
DescriptionThe event priority
Fieldproc_id
Typestring
TitleProcess ID
Fieldproc_name
Typestring
TitleProcess Name
Fieldproc_par_id
Typestring
TitleProcess Parent ID
Fieldprocessor_name
Typestring
TitleSystem Processor Name
Fieldprocessor_name_old
Typestring
TitlePrevious System Processor Name
Fieldprocessor_type
Typestring
TitleSystem Processor Type
Fieldprocessor_type_old
Typestring
TitlePrevious System Processor Type
Fieldprod_cpe
Typecpe
TitleProduct CPE Identifier
DescriptionThe CPE Identifier corresponding to the product. The CPE name should be listed in http://nvd.nist.gov/cpe.cfm or http://cpe.mitre.org
Fieldprod_cpe_old
Typecpe
TitlePrevious Product CPE Identifier
Description*Previous* The CPE Identifier corresponding to the product. The CPE name should be listed in http://nvd.nist.gov/cpe.cfm or http://cpe.mitre.org
Fieldprod_id
Typestring
TitleProduct Identifier
Fieldprod_id_old
Typestring
TitlePrevious Product Identifier
Fieldprod_name
Typestring
TitleProduct Name
Fieldprod_name_old
Typestring
TitlePrevious Product Name
Fieldprod_type
Typestring
TitleProduct Type
Fieldprod_type_old
Typestring
TitlePrevious Product Type
Fieldprod_vend
Typestring
TitleProduct Vendor
Fieldprod_vend_old
Typestring
TitlePrevious Product Vendor
Fieldprod_ver
Typestring
TitleProduct Version
Fieldprod_ver_old
Typestring
TitlePrevious Product Version
Fieldrec_id
Typestring
TitleEvent Record ID
DescriptionA unique identifier that corresponds to an individual record instance. If the identifier indicates the type of event, use id
Fieldrec_time
Typetimestamp
TitleEvent Record Record Time
DescriptionThe timestamp when the event was recorded/produced
Fieldrecv_time
Typetimestamp
TitleEvent Record Receive Time
DescriptionA timestamp reflecting when the event record was received by an upstream device
Fieldrule_id
Typestring
TitleRule ID
Fieldrule_id_old
Typestring
TitlePrevious Rule ID
Fieldrule_type
Typestring
TitleRule Type
Fieldrule_val
Typestring
TitleRule Value
Fieldrule_val_old
Typestring
TitlePrevious Rule Value
Fields_eff_grp_id
Typestring
TitleSubject Effective Group ID
Description*Subject* The identifier of the primary group associated with the effective/authorized user session
Fields_eff_grp_name
Typestring
TitleSubject Effective Group Name
Description*Subject* The name of the primary group associated with the effective/authorized user session
Fields_eff_id
Typestring
TitleSubject Effective ID
Description*Subject* The effective or authorized user ID (UID) for the current user session
Fields_eff_name
Typestring
TitleSubject Effective Name
Description*Subject* The effective or authorized user name associated with the current user session
Fields_proc_id
Typestring
TitleSubject Process ID
Fields_proc_name
Typestring
TitleSubject Process Name
Fields_proc_par_id
Typestring
TitleSubject Process Parent ID
Fields_sess_id
Typestring
TitleSubject User Session ID
Fields_sess_login_time
Typetimestamp
TitleSubject User Session Login Time
Fields_sess_logout_time
Typetimestamp
TitleSubject User Session Logout Time
Fieldsess_id
Typestring
TitleUser Session ID
Fieldsess_login_time
Typetimestamp
TitleUser Session Login Time
Fieldsess_logout_time
Typetimestamp
TitleUser Session Logout Time
Fieldsev
Typeinteger
TitleEvent Severity
DescriptionAn indication of how severe the impact of the event may be
Fieldsrc_ipv4
Typeipv4Address
TitleSource IPv4 Address
Fieldsrc_ipv6
Typeipv6Address
TitleSource IPv6 Address
Fieldsrc_mac
TypemacAddress
TitleSource Mac Address
DescriptionThe source MAC (IEEE-802) address
Fieldsrc_port
Typeunsigned16
TitleSource Transport Port
DescriptionThe source port number
Fieldsrc_prefix_ipv4
Typeipv4Address
TitleSource IPv4 Prefix
DescriptionThe prefix for the source IPv4 address. The relevant number of prefix bits should be specified in the src_prefix_len field
Fieldsrc_prefix_ipv6
Typeipv6Address
TitleSource IPv6 Prefix
DescriptionThe prefix for the source IPv6 address. The relevant number of prefix bits should be specified in the src_prefix_len field
Fieldsrc_prefix_len
Typeunsigned8
TitleSource IP Address Prefix Length
DescriptionThe size (in number of bits) used to specify the source IP address prefix from a src_prefix_ipv4 or src_prefix_ipv6 field
Fieldstatus
TypestatusTagType
TitleEvent Status
Fieldsys_domain
Typestring
TitleSystem Domain
Fieldsys_domain_old
Typestring
TitlePrevious System Domain
Fieldsys_fqdn
Typefqdn
TitleSystem Fully-Qualified Domain Name (FQDN)
Fieldsys_fqdn_old
Typefqdn
TitlePrevious System Fully-Qualified Domain Name (FQDN)
Fieldsys_host
Typehostname
TitleSystem Name
Fieldsys_host_old
Typehostname
TitlePrevious System Name
Fieldsys_id
Typestring
TitleSystem Identifier
Fieldsys_id_old
Typestring
TitlePrevious System Identifier
Fieldsys_intf_id
Typestring
TitleSystem Network Interface Identifier
Fieldsys_intf_id_old
Typestring
TitlePrevious System Network Interface Identifier
Fieldsys_ipv4
Typeipv4Address
TitleSystem IPv4 Address
Fieldsys_ipv4_old
Typeipv4Address
TitlePrevious System IPv4 Address
Fieldsys_ipv6
Typeipv6Address
TitleSystem IPv6 Address
Fieldsys_ipv6_old
Typeipv6Address
TitlePrevious System IPv6 Address
Fieldsys_lat
TypelatDecDegrees
TitleSystem Latitude
DescriptionThe latitude of the system, in decimal degrees
Fieldsys_lat_old
TypelatDecDegrees
TitlePrevious System Latitude
Description*Previous* The latitude of the system, in decimal degrees
Fieldsys_loc
Typestring
TitleSystem Location
DescriptionA description of the physical location of the system
Fieldsys_loc_old
Typestring
TitlePrevious System Location
Description*Previous* A description of the physical location of the system
Fieldsys_long
TypelongDecDegrees
TitleSystem Longitude
DescriptionThe longitude of the system, in decimal degrees
Fieldsys_long_old
TypelongDecDegrees
TitlePrevious System Longitude
Description*Previous* The longitude of the system, in decimal degrees
Fieldsys_mac
TypemacAddress
TitleSystem Interface MAC Address
DescriptionThe 48 or 64-bit MAC (Media Access Control), EUI (Extended Unique Identifier), or hardware address of the system
Fieldsys_mac_old
TypemacAddress
TitlePrevious System Interface MAC Address
Description*Previous* The 48 or 64-bit MAC (Media Access Control), EUI (Extended Unique Identifier), or hardware address of the system
Fieldsys_netBIOS
Typestring
TitleSystem NetBIOS Name
Fieldsys_netBIOS_old
Typestring
TitlePrevious System NetBIOS Name
Fieldsys_ntDomain
Typestring
TitleSystem NT Domain
Fieldsys_ntDomain_old
Typestring
TitlePrevious System NT Domain
Fieldsys_recv_bytes
Typeinteger
TitleBytes Received
Fieldsys_recv_bytes_old
Typeinteger
TitlePrevious Bytes Received
Fieldsys_recv_pkts
Typeinteger
TitleNumber Of Packets Received
Fieldsys_recv_pkts_old
Typeinteger
TitlePrevious Number Of Packets Received
Fieldsys_sent_bytes
Typeinteger
TitleBytes Sent
Fieldsys_sent_bytes_old
Typeinteger
TitlePrevious Bytes Sent
Fieldsys_sent_pkts
Typeinteger
TitleNumber Of Packets Sent
Fieldsys_sent_pkts_old
Typeinteger
TitlePrevious Number Of Packets Sent
Fieldsys_uptime_dur
Typeduration
TitleSystem Uptime
Fieldtags
Typetag
TitleEvent Tags
DescriptionTags describing the event type, such as the action, status, and objects involved in the event. The tags should be chosen from the CEE Taxonomy
Fieldtcp_flags
Typeunsigned8
TitleTCP Control Flags
DescriptionThe control flags/bits in a TCP packet
Fieldtext
Typestring
TitleEvent Text
DescriptionAn unstructured text string describing the details of the event
Fieldtime
Typetimestamp
TitleEvent Start Time
DescriptionAn ISO8601 compliant timestamp designating the date, time, and timezone offset when the event began
Fieldvlan_id
Typeunsigned16
TitleVLAN ID
DescriptionThe VLAN identifier (VID) (IEEE-802.1Q) as specified in the "Tag Control Information" field of the VLAN'ed packet
Fieldvlan_name
Typestring
TitleVLAN Name
DescriptionThe name associated with the VLAN (IEEE-802.1Q) network
Fieldvuln_cve
Typecve
TitleVulnerability CVE identifier
Fieldvuln_id
Typestring
TitleVulnerability ID

Event Profiles

Profilecee_base_event
TitleCEE Base Event Profile
DescriptionThe base event structure for CEE Events. All CEE formatted events are expected to minimally conform to this event profile. The CEE Base Event is derived from the Syslog RFC5424 event structure http://tools.ietf.org/html/rfc5424.
EventProfile
Fields

Generated on: 2011-07-21T09:37:59.421-04:00