McAfee MAP-3300-SWG Product Guide - Page 224

External Access, Email Details, Web Details, Configuration Change, Option, Definition

Page 224 highlights

Overview of System features Appliance Management External Access Use this area to configure your appliance to allow limited access from an off box SQL client to view information about email detections, web detections and configuration change events stored available in three separate views. System | Appliance Management | Database Maintenance | External Access Introduction to External Access External access to a limited set of views in the reports database on an appliance can be configured. By default, the three views are: • Email Details shows a unique event identifier, the date and time the event was added, a unique identifier for the message, its intended destination, the IP address, domain, and email address of the originator, the IP address, domain, and email address of the intended recipient, the action taken by the appliance and the scanning policy and any content filtering used, the detection category and name of the detection if available. • Web Details shows a unique event identifier, the date and time the event was added, a unique identifier for the web access attempt, the IP address, domain name, and username of the originator, the requested URL, the action taken by the appliance and the scanning policy and detection category, and name of the detection if available. • Configuration Change shows a unique event identifier, the date and time the event was added, the login name of the person who made the changes, and the IP address of the computer used to make the change. Table 218 Option definitions Option Enable off box sql access Allow external database access for this address range Allow external database access to user Set Reporting Password Definition Select to allow an off box SQL client to access the appliance. Define the address and subnet mask for the external hosts to which you want to allow access. Define the user that the external client uses to log into the appliance. This is set to reporter by default. Define the password that the external database uses to log into the appliance. This is set to reports by default. Task - Viewing information about email detections from an off-box client using Postgres' PSQL interactive application 1 Open the command line on the computer from which you want to view the database. 2 Type psql -U -d reports - h and press the Enter key. 3 Type the password for the user to whom you gave access 4 Press the Enter key to see the list of report view that you have available. Choose from: • Email_details • Web_details • Configuration_change_view. 224 McAfee Email and Web Security Appliances 5.6.0 Product Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336

External Access
Use this area to configure your appliance to allow limited access from an off box SQL client to view
information about email detections, web detections and configuration change events stored available
in three separate views.
System
|
Appliance Management
|
Database Maintenance
|
External Access
Introduction to External Access
External access to a limited set of views in the reports database on an appliance can be configured. By
default, the three views are:
Email Details
shows a unique event identifier, the date and time the event was added, a unique
identifier for the message, its intended destination, the IP address, domain, and email address of
the originator, the IP address, domain, and email address of the intended recipient, the action
taken by the appliance and the scanning policy and any content filtering used, the detection
category and name of the detection if available.
Web Details
shows a unique event identifier, the date and time the event was added, a unique
identifier for the web access attempt, the IP address, domain name, and username of the
originator, the requested URL, the action taken by the appliance and the scanning policy and
detection category, and name of the detection if available.
Configuration Change
shows a unique event identifier, the date and time the event was added,
the login name of the person who made the changes, and the IP address of the computer used to
make the change.
Table 218
Option definitions
Option
Definition
Enable off box sql access
Select to allow an off box SQL client to access the appliance.
Allow external database access for
this address range
Define the address and subnet mask for the external hosts to which
you want to allow access.
Allow external database access to
user
Define the user that the external client uses to log into the appliance.
This is set to reporter by default.
Set Reporting Password
Define the password that the external database uses to log into the
appliance. This is set to reports by default.
Task — Viewing information about email detections from an off-box client using
Postgres' PSQL interactive application
1
Open the command line on the computer from which you want to view the database.
2
Type psql -U <username> -d reports - h <host address> and press the Enter key.
3
Type the password for the user to whom you gave access
4
Press the Enter key to see the list of report view that you have available. Choose from:
Email_details
Web_details
Configuration_change_view.
Overview of System features
Appliance Management
224
McAfee Email and Web Security Appliances 5.6.0 Product Guide