6Event categories
CEFIndustry-standard format
UDPSyslog transport
MITREATT&CK mapped
Sample Event

NET_EVENT — a network threat, fully described

Includes source/destination IPs, ports, risk assessments, threat scores, geographic data, and MITRE ATT&CK technique mappings — plus PUT_DECISION events logging every enforcement action with a complete audit trail.

CEF:0|OneFirewall|F3DAgent|4.0|
NET_EVENT|Network Threat Detected|8|
rt=1740000000000 src=185.220.101.45
dst=10.0.1.100 spt=44281 dpt=22
act=BLOCK cs1=847 cs1Label=crime_score
cs2=T1110 cs2Label=mitre_ttp
cs3=RU cs3Label=src_country
msg="SSH brute-force; TOR exit node"
What Triggers an Event

A polling loop, a threshold, and three places it can go

Every five minutes, the platform checks live IPv4 and malicious-traffic feeds against your configured Crime Score threshold. Nothing is sent while traffic stays under it. The moment it isn't, the event fires out to app notification, email, and syslog (UDP) simultaneously — no polling required on your end.

Flowchart showing an automated check every 5 minutes against live threat feeds, branching to no action if the Crime Score threshold isn't met, or to app notification, email, and syslog UDP if it is
SIEM Integration in Minutes

CEF over syslog is the universal language

Splunk

Configure a UDP syslog input. Events appear as parsed sourcetype=cef fields automatically.

Microsoft Sentinel

Use the CEF connector in Azure Monitor. Fields map directly to the CommonSecurityLog schema.

Elastic SIEM

Filebeat syslog input with the CEF processor module — events become ECS-compliant documents.

IBM QRadar

Add a Log Source of type Universal CEF. Events are normalised and categorised automatically.

Connect OneFirewall to your SIEM.

Talk to our team to configure your event stream.

Speak with OneFirewall