McAfee MAP-3300-SWG Product Guide - Page 263

Token name, Description, Table 259, Alert tokens for Scanner alerts

Page 263 highlights

Overview of System features Logging, Alerting and SNMP Table 259 Alert tokens for Scanner alerts (continued) Token name Description %DLP_REPORT%: A detailed report of the rule(s) triggered; including the name, category, size and digest of the protected documents (DLP) %DLP_RULE%: Name of triggered DLP rule (DLP) %DOSLIMIT%: The DoS limit value that has been exceeded (DOS) %FILTERCONTEXT%: The name(s) of the rule(s) that triggered (Compliance) %FILTERNAME%: The name of the file filtering rule that has triggered (File Filtering) %FILTERNAME%: The name(s) of the top level rule(s)/group(s) that triggered (as per policy statement) (Compliance) %FORMAT%: Description of the type of blocked message format. (Mail Filtering) %ID%: Messaging and Web Security unique message ID (SMTP) %LOCALTIME%: Local time %POLICY%: Policy which triggered the event %POLICY_ID%: Policy identity which triggered the event %PROTOCOL%: Protocol %REASON%: Description of the DoS limit that has been exceeded. E.g. max nesting depth, file size or AV scanner timeout (DOS) %RECIPIENTS%: Envelope Email recipient list. Available in SMTP (SMTP) %SENDER%: Envelope Email Sender. Available in SMTP (SMTP) %SITEADVISOR%: The SiteAdvisor web reputation of the requested URL. (URL) %SIZE%: Size of data %SOURCEHOST%: Source host name %SOURCEIP%: Source IP address %SUBJECT%: Email Subject. Available in SMTP (SMTP) %TOTALSCORE%: Total accumulated score for the stream (Compliance) %URL_CATEGORY%: The filtered category that has matched the requested URL. (URL) %URL_REQUEST_DISPLAY_NAME%: Contact name for queries regarding URL alerts (URL) %URL_REQUEST_EMAIL_ADDR%: Contact email address for queries regarding URL alerts (URL) %UTCTIME%: UTC time %WEB_REPUTATION_INFO%: The SiteAdvisor web reputation of the requested URL. (URL) %WEBSHIELDIP%: Messaging and Web Security IP address %WEBSHIELDNAME%: Messaging and Web Security appliance name %WEBSHIELDVIRTUALIP%: Virtual IP address Table 260 Alert tokens for Email notifications Token name Description %ATTACHMENTNAME%: Name of the item being scanned %AVDATVERSION%: The DAT version used by the anti-virus engine %AVENGINENAME%: The name of the anti-virus engine %AVENGINEVERSION%: The version of the anti-virus engine McAfee Email and Web Security Appliances 5.6.0 Product Guide 263

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336

Table 259
Alert tokens for Scanner alerts
(continued)
Token name
Description
%DLP_REPORT%:
A detailed report of the rule(s) triggered; including the name,
category, size and digest of the protected documents (DLP)
%DLP_RULE%:
Name of triggered DLP rule (DLP)
%DOSLIMIT%:
The DoS limit value that has been exceeded (DOS)
%FILTERCONTEXT%:
The name(s) of the rule(s) that triggered (Compliance)
%FILTERNAME%:
The name of the file filtering rule that has triggered (File
Filtering)
%FILTERNAME%:
The name(s) of the top level rule(s)/group(s) that triggered (as
per policy statement) (Compliance)
%FORMAT%:
Description of the type of blocked message format. (Mail
Filtering)
%ID%:
Messaging and Web Security unique message ID (SMTP)
%LOCALTIME%:
Local time
%POLICY%:
Policy which triggered the event
%POLICY_ID%:
Policy identity which triggered the event
%PROTOCOL%:
Protocol
%REASON%:
Description of the DoS limit that has been exceeded. E.g. max
nesting depth, file size or AV scanner timeout (DOS)
%RECIPIENTS%:
Envelope Email recipient list. Available in SMTP (SMTP)
%SENDER%:
Envelope Email Sender. Available in SMTP (SMTP)
%SITEADVISOR%:
The SiteAdvisor web reputation of the requested URL. (URL)
%SIZE%:
Size of data
%SOURCEHOST%:
Source host name
%SOURCEIP%:
Source IP address
%SUBJECT%:
Email Subject. Available in SMTP (SMTP)
%TOTALSCORE%:
Total accumulated score for the stream (Compliance)
%URL_CATEGORY%:
The filtered category that has matched the requested URL. (URL)
%URL_REQUEST_DISPLAY_NAME%:
Contact name for queries regarding URL alerts (URL)
%URL_REQUEST_EMAIL_ADDR%:
Contact email address for queries regarding URL alerts (URL)
%UTCTIME%:
UTC time
%WEB_REPUTATION_INFO%:
The SiteAdvisor web reputation of the requested URL. (URL)
%WEBSHIELDIP%:
Messaging and Web Security IP address
%WEBSHIELDNAME%:
Messaging and Web Security appliance name
%WEBSHIELDVIRTUALIP%:
Virtual IP address
Table 260
Alert tokens for Email notifications
Token name
Description
%ATTACHMENTNAME%:
Name of the item being scanned
%AVDATVERSION%:
The DAT version used by the anti-virus engine
%AVENGINENAME%:
The name of the anti-virus engine
%AVENGINEVERSION%:
The version of the anti-virus engine
Overview of System features
Logging, Alerting and SNMP
McAfee Email and Web Security Appliances 5.6.0 Product Guide
263