Common Event Expression (CEE) v0.6
Common Event Expression (CEE) Architecture Specification version 0.6 has been published for comment.
As noted noted in June, CEE defines the structure and components comprising the community-developed event log standard that intends to be industry accepted and practical. The following v0.6 documents were released on 26th August 2011:
I will be having a read through these to see how they can be applied to application logging in some upcoming projects.
Feedback is sought on these documents using the CEE Email Discussion List or by email to cee@mitre.org.
Posted on: 30 August 2011 at 08:06 hrs

Comments are filtered automatically and should appear shortly after they been checked.
As an educational excercise I'm trying to look at OWASP's AppSensor detection points and figure out what the CEE log entry should look like. Any pointers would be appreciated.
Thanks,
Bill
Yes, I included CEE in the [Application Security] Logging Cheat Sheet at https://www.owasp.org/index.php/Logging_Cheat_Shee... to future proof it a bit. No, I haven't attempted to create example CEE log entries, mainly because when I last had time to delve into it, I don't think it was finalised enough. But I think it has moved on now, and is an area we need to address in the new version of the AppSensor book (in progress). I have added it to the list.
I did see this article mentioned today in the CEE newsletter feed:
http://www.networkworld.com/community/node/80324
It might not help, but there are Common Event Format (CEF) examples in my presentation from AppSec EU 21011 in Dublin:
https://www.owasp.org/index.php/File:Appsensor-app...
See pages 28-31.