Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Sovereign, high-performance data protection

CEF export format

The KMS can export audit events in the Common Event Format (CEF) — a text-based, vendor-neutral log format widely ingested by SIEM products (ArcSight, Splunk, IBM QRadar, Microsoft Sentinel, and others) without a custom parser.

CEF export is a serialisation view of the tamper-evident JSONL audit log (see Audit logs). It does not replace the JSONL file, which remains the authoritative, hash-chain-verifiable record.


Specification

The KMS produces CEF version 0 (CEF:0) as defined by the ArcSight CEF Implementation Standard, version 27 (OpenText/ArcSight, April 2024).

Reference links


Format overview

Each audit event is serialised as a single line:

CEF:0|Cosmian|KMS|<version>|<operation>|<operation>|<severity>|<extensions>

Header fields

PositionCEF field nameValueMax length
1CEF VersionAlways 0—
2deviceVendorCosmian63
3deviceProductKMS63
4deviceVersionKMS version string (e.g. 5.25.0)31
5deviceEventClassIdKMIP operation name (e.g. Encrypt)1023
6nameSame as deviceEventClassId512
7agentSeverityInteger 0–10 (see severity table below)—

Extension fields

All extension keys below are standard CEF v27 dictionary keys — no custom labels are used.

CEF keyCEF v27 full nameTypeDescription
rtdeviceReceiptTimeDateTimeEvent time as Unix epoch milliseconds.
susersourceUserNameStringAuthenticated username.
srcsourceAddressIP addressClient IP. Omitted when not available.
outcomeeventOutcomeString"Success" or "Failure".
reasonreasonStringFailure reason. Omitted on success.
actdeviceActionStringKMIP operation name.
cn1deviceCustomNumber1LongWall-clock operation duration in milliseconds.
cn1LabeldeviceCustomNumber1LabelStringAlways "durationMs".
cs1deviceCustomString1StringKMIP UniqueIdentifier. Omitted when null.
cs1LabeldeviceCustomString1LabelStringAlways "objectUID".
cs2deviceCustomString2StringCryptographic algorithm. Omitted when null.
cs2LabeldeviceCustomString2LabelStringAlways "algorithm".
externalIdexternalIdStringAudit record ID (monotonically increasing integer).
devicePayloadIddevicePayloadIdStringRequest correlation UUID. Omitted when absent.

Severity mapping

OutcomeCEF severityMeaning
Success5Medium
Authentication failure (401 / 403)7High
Other failure6Medium-High

CEF severity follows the ArcSight scale: 0–3 = Low, 4–6 = Medium, 7–8 = High, 9–10 = Very-High.


Escaping rules

CEF uses special characters as delimiters. The serialiser escapes them to prevent injection:

Header fields (pipe-delimited):

CharacterEscaped as
\\\
||
newline\n
carriage return\r

Extension values (key=value pairs):

CharacterEscaped as
\\\
=\=
newline\n
carriage return\r

Pipe characters (|) in extension values do not need escaping — they only delimit the header.


Example

Annotated CEF line for a successful Encrypt operation:

CEF:0|Cosmian|KMS|5.25.0|Encrypt|Encrypt|5|rt=1784574156704 suser=admin src=127.0.0.1 outcome=Success act=Encrypt cn1=12 cn1Label=durationMs cs1=359019d8-1543-4e2e-9d96-674dd64fcffc cs1Label=objectUID cs2=AES cs2Label=algorithm externalId=1 devicePayloadId=3618ade8-5db7-4635-9d05-5af6a7614d52
FieldValue
deviceVendorCosmian
deviceProductKMS
deviceVersion5.25.0
deviceEventClassIdEncrypt
nameEncrypt
agentSeverity5 (Medium — success)
rt1784574156704 (epoch ms)
suseradmin
src127.0.0.1
outcomeSuccess
actEncrypt
cn112 (ms)
cs1359019d8-1543-4e2e-9d96-674dd64fcffc
cs2AES
externalId1
devicePayloadId3618ade8-5db7-4635-9d05-5af6a7614d52

CLI usage

Export audit events as CEF using the ckms CLI (works offline, no running server needed):

# Export all events as CEF
ckms audit export --path /var/log/cosmian-kms/audit.jsonl --format cef

# Export with a specific KMS version in the header
ckms audit export --path /var/log/cosmian-kms/audit.jsonl \
  --format cef --kms-version 5.25.0

# Export events since a given date
ckms audit export --path /var/log/cosmian-kms/audit.jsonl \
  --format cef --since 2026-01-01T00:00:00Z

For the full CLI reference, see Audit log management.


Interoperability validation

The KMS CEF output is validated against jc (kellyjonbrazil/jc, 8.7k+ GitHub stars, MIT licence) — an independent, widely used, actively maintained CEF parser.

The interop test (mise test:cef) verifies:

  1. Structural parse — jc can parse every CEF line and extracts exactly one record
  2. Field round-trip — every field value matches the original JSONL source event
  3. CEF v27 compliance — header field lengths within spec limits, severity in 0–10 range, all extension keys exist in the CEF v27 dictionary
  4. Type validation — rt is a valid epoch-ms integer, cn1 is numeric, src is a valid IP address
  5. Escaping round-trip — jc correctly unescapes values with special characters (=, |, \, newlines) back to the originals
  6. Injection hardening — no raw newlines in CEF output; malicious input cannot inject forged CEF records