8966 - MESGID_SCAN_ARCHIVE_MULTIPART_WARNING
Message ID: 8966
Message Description: MESGID_SCAN_ARCHIVE_MULTIPART_WARNING
Message Meaning: File is a multipart archive or contains multiple files within the archive
Type: Virus
Category: scanerror
Severity: Warning
Log Field Name |
Description |
Data Type |
Length |
---|---|---|---|
action |
The status of the session: blocked - Blocked infected file by AV engine passthrough - Allowed by AV engine monitored - Log, but do NOT block infected file analytics - Submitted to Sandbox for analysis |
string |
18 |
agent |
User agent - eg. agent="Mozilla/5.0" |
string |
1024 |
analyticscksum |
The checksum of the file submitted for analytics |
string |
64 |
analyticssubmit |
The flag for analytics submission |
string |
10 |
attachment |
|
string |
3 |
authserver |
Server used to authenticate the involved user |
string |
64 |
cc |
|
string |
512 |
cdrcontent |
|
string |
256 |
checksum |
The checksum of the scanned file |
string |
16 |
contentdisarmed |
Content Disarm action- eg. disarmed, detected |
string |
13 |
craction |
Threat Weight action |
uint32 |
10 |
crlevel |
Threat Weight Level |
string |
10 |
crscore |
Threat Weight Score |
uint32 |
10 |
date |
Date |
string |
10 |
devid |
|
string |
16 |
direction |
Message/packets direction |
string |
8 |
dstauthserver |
|
string |
64 |
dstcountry |
|
string |
64 |
dstintf |
Destination Interface |
string |
32 |
dstintfrole |
Destination Interface's assigned role (LAN, WAN, etc.) |
string |
10 |
dstip |
Destination IP Address |
ip |
39 |
dstport |
Destination Port |
uint16 |
5 |
dstuser |
|
string |
256 |
dstuuid |
|
string |
37 |
dtype |
Data type for virus category |
string |
32 |
eventtime |
Time when detection occured |
uint64 |
20 |
eventtype |
Event type of AV |
string |
32 |
fctuid |
Forticlient user ID |
string |
32 |
filehash |
Used by Outbreak Prevention External Hash: the hash signature used in the detection |
string |
64 |
filehashsrc |
Used by Outbreak Prevention External Hash: external source that provided the hash signature |
string |
32 |
filename |
File name |
string |
256 |
filetype |
File type |
string |
16 |
forwardedfor |
|
string |
128 |
from |
Email address from the Email Headers (IMAP/POP3/SMTP) |
string |
128 |
group |
Group name (authentication) |
string |
512 |
httpmethod |
|
string |
20 |
icbaction |
|
string |
7 |
icbconfidence |
|
string |
6 |
icbfileid |
|
string |
65 |
icbfiletype |