Format for text logs sent over syslog by firewalls and similar devices. A Linux log forwarder passes these messages to Microsoft Sentinel, which stores them in CommonSecurityLog.
Also called Common Event Format.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains CEF in context, with comparison tables and the common traps.
Terms in this definition
- FORMAT
A DAX function that turns a value into text according to a format string, for instance "MMMM" to show a month's name. Since the output is text, numeric operations can't use it, and dynamic format strings were introduced to get around that.
- OVER
Gives a T-SQL window function its window: PARTITION BY, ORDER BY and, if wanted, a ROWS or RANGE frame. Rankings and running totals can then be worked out while every row is kept.
- Syslog
Table in Log Analytics holding syslog messages from Linux.
- Linux log forwarder
Linux machine set aside to collect syslog and CEF messages from devices on port 514 using rsyslog or syslog-ng, then pass them via the Azure Monitor Agent into a Microsoft Sentinel workspace.
- Agents (classic) API
First-generation Foundry Agent Service API, based on threads, messages and runs. It is deprecated, replaced by conversations and responses, and retires on 31 March 2027.
- Microsoft Sentinel
Microsoft's cloud-native SIEM, with SOAR capabilities, which stores and queries its data in a Log Analytics workspace.
- CommonSecurityLog
Destination table in Log Analytics for CEF-formatted messages that a Microsoft Sentinel log forwarder passes on.
Related terms
- CEF via AMA
Sentinel data connector in which a Linux forwarder runs the Azure Monitor Agent with a DCR to receive CEF messages; it supersedes the older CEF connector built on the Log Analytics agent.
- Log forwarder
A Linux server set aside to collect CEF and Syslog messages from devices, by default on port 514, using rsyslog or syslog-ng, and pass them through the Azure Monitor Agent to the Microsoft Sentinel workspace.
- Microsoft Threat Intelligence Analytics
A Microsoft Sentinel rule built from a template that cannot be edited. It checks Windows DNS, CEF and Syslog data for matches with indicators from Microsoft's threat intelligence and raises high-fidelity alerts when it finds them.
- Windows Event Forwarding
Using subscriptions, this Windows capability sends event log entries from source machines to a collector server. CEF and syslog are not things it can receive.