McAfee MAP-3300-SWG Product Guide - Page 266

Table 264, Alert tokens for Email alerts Logging and Alerting, Token name, Description

Page 266 highlights

Overview of System features Logging, Alerting and SNMP Table 264 Alert tokens for Email alerts (Logging and Alerting) (continued) Token name Description %SERVERUSERNAME%: The login name of the user (POP3 and FTP) %LOCALTIME%: Local time %UTCTIME%: UTC time %WEBSHIELDNAME%: Messaging and Web Security appliance name %WEBSHIELDIP%: Messaging and Web Security IP address %APPLICATION%: The name of the process that generated the event %SENDER%: Envelope Email Sender (SMTP) %RECIPIENTS%: Envelope Email recipient list (SMTP) %DETECTIONS%: List of detections in the item %ICAP_X_CLIENT_IP%: The original web client IP address (ICAP) %ICAP_X_SERVER_IP%: The original web server IP address (ICAP) %AUTH_USER%: The name of the authenticated web user (HTTP and ICAP) %POLICY%: The name of the policy that triggered the event %POLICY_ID%: The ID of the policy that triggered the event %SUBJECT%: Email Subject (SMTP) %SIZE%: Size of data %AVDATVERSION%: The DAT version used by the anti-virus engine (AV) %AVENGINEVERSION%: The version of the anti-virus engine (AV) %ATTACHMENTNAME%: Name of the item being scanned (AV, DLP) %ATTACHMENTNAME%: Name of the item being scanned (compliance) %BLOCKED_URL%: The URL that was requested and blocked by the web categorization engine (URL) %BLOCKED_URL_ICAP%: The URL that was requested and blocked by the web categorization engine (URL) for the ICAP REQMOD %DLP_RULE%: The registered document categories that triggered %DLP_FINGERPRINTSOURCE%: The registered document name %DLP_REPORT%: Detailed report containing the document name, the category name, the size and the digest as per the registered documents %FILESYSTEM%: The name of the filesystem on the appliance (system events) %FILTERCONTEXT%: The name or names of the rules that triggered (compliance) %SPAMSCORE%: Spam score (AS) %SPAMRULESBROKEN%: The name or names of the spam rules that triggered the detection (AS) %SPAMTHRESHOLD%: Spam reporting threshold (AS) %URL_CATEGORY%: The filtered category that matched the requested URL (URL) Aggregated data: %PRODUCT%: The product name %EVENT%: The name of the event %SMTPNUMMESSAGES%: The number of messages received via SMTP %SMTPVIRUSDETECTED%: The number of viruses detected (SMTP) 266 McAfee Email and Web Security Appliances 5.6.0 Product Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336

Table 264
Alert tokens for Email alerts (Logging and Alerting)
(continued)
Token name
Description
%SERVERUSERNAME%:
The login name of the user (POP3 and FTP)
%LOCALTIME%:
Local time
%UTCTIME%:
UTC time
%WEBSHIELDNAME%:
Messaging and Web Security appliance name
%WEBSHIELDIP%:
Messaging and Web Security IP address
%APPLICATION%:
The name of the process that generated the event
%SENDER%:
Envelope Email Sender (SMTP)
%RECIPIENTS%:
Envelope Email recipient list (SMTP)
%DETECTIONS%:
List of detections in the item
%ICAP_X_CLIENT_IP%:
The original web client IP address (ICAP)
%ICAP_X_SERVER_IP%:
The original web server IP address (ICAP)
%AUTH_USER%:
The name of the authenticated web user (HTTP and ICAP)
%POLICY%:
The name of the policy that triggered the event
%POLICY_ID%:
The ID of the policy that triggered the event
%SUBJECT%:
Email Subject (SMTP)
%SIZE%:
Size of data
%AVDATVERSION%:
The DAT version used by the anti-virus engine (AV)
%AVENGINEVERSION%:
The version of the anti-virus engine (AV)
%ATTACHMENTNAME%:
Name of the item being scanned (AV, DLP)
%ATTACHMENTNAME%:
Name of the item being scanned (compliance)
%BLOCKED_URL%:
The URL that was requested and blocked by the web
categorization engine (URL)
%BLOCKED_URL_ICAP%:
The URL that was requested and blocked by the web
categorization engine (URL) for the ICAP REQMOD
%DLP_RULE%:
The registered document categories that triggered
%DLP_FINGERPRINTSOURCE%:
The registered document name
%DLP_REPORT%:
Detailed report containing the document name, the category
name, the size and the digest as per the registered documents
%FILESYSTEM%:
The name of the filesystem on the appliance (system events)
%FILTERCONTEXT%:
The name or names of the rules that triggered (compliance)
%SPAMSCORE%:
Spam score (AS)
%SPAMRULESBROKEN%:
The name or names of the spam rules that triggered the
detection (AS)
%SPAMTHRESHOLD%:
Spam reporting threshold (AS)
%URL_CATEGORY%:
The filtered category that matched the requested URL (URL)
Aggregated data:
%PRODUCT%:
The product name
%EVENT%:
The name of the event
%SMTPNUMMESSAGES%:
The number of messages received via SMTP
%SMTPVIRUSDETECTED%:
The number of viruses detected (SMTP)
Overview of System features
Logging, Alerting and SNMP
266
McAfee Email and Web Security Appliances 5.6.0 Product Guide