What is the difference between event.categoryDeviceType , event.categoryDeviceGroup and event.categoryObject?
for example --> event.categoryDeviceType = Operating system
event.categoryDeviceGroup = /Operating system
eventcategory.Object = /Host/Operating system
Another example --> event.categoryDeviceType = Network-based IDS/IPS
event.categoryDeviceGroup = /Firewall
eventcategory.Object = /Host/Application/Service
This three seems identical . What is the difference? Can anyone explain a bit further?
What they are explained in the white paper is still not clear and fully understand. And also im a amateur in this arcsight cef field. Can you explain a bit about the three field?
Those fields have nothing to do with CEF. CEF is the format of the log. Those 3 fields are related to categorization. Each log should be categorized correctly in Arcsight to use categorization in ESM rules.
Please use the Like button below, if you find this post useful or mark it as an accepted solution if it resolves your issue.