Log Schemas
MalOp detection log (syslog CEF, event_id = Malop)
MalOp records collected from the MalOp management API (POST /rest/mmng/v2/malops)
Malware detection and prevention log (syslog CEF, event_id = Malware)
Process suspicions collected from the investigation API (POST /rest/visualsearch/query/simple)
Console user action audit log (syslog CEF, event_id = UserAction)