McAfee MAP-3300-SWG Product Guide - Page 270

Extended Syslog attributes for ArcSight, Off-box system, Enable off-box system log, Receiving server

Page 270 highlights

Overview of System features Logging, Alerting and SNMP Table 269 Option definitions (continued) Option Off-box system log Definition Enable off-box system log - To send system logs for storage off-box, enable this setting and define the receiving server parameters: Receiving server - Specifies the IP address or host name of the server that receives the syslog information. Use IPv6 protocol - Check this option when sending system logging information over an IPv6 network. Port - Specify the port on the receiving server to be used to transfer the system log information. When using off-box system logging, you can specify different ports for each configured off-box syslog server. System Log Archive Protocol - Either TCP or UDP. Specifies the packet type. UDP has a limit of 1024 bytes per packet. Add Server - You can configure multiple off-box servers. Send archive copies of the mail logs to another server, and set up a schedule for this to happen. Extended Syslog attributes for ArcSight Using the extended Syslog functions within the appliance, you can use external, third party software - such as ArcSight - to generate Syslog reports. Table 270 Events for ArcSight Event ID Event Description 50005 Logging of the email status during processing 50006 Logging of the email status during processing 50022 Logging of the email status during McAfee Quarantine Manager processing 180000 Anti-Virus Engine Detection 180001 Content rule detection 180002 Anti-spam classification 180003 File-format detection 180004 Mail-Filtering detection 180008 URL request denied 180010 Compliancy detection 180011 Data Loss Prevention detection 180012 Mail Size detection 180013 Regular expression scanning failure 180031 URL has been blocked due to categorization 180032 URL has been coached due to categorization 180033 Categorized URL has been permitted 180035 Categorized URL has been permitted for a monitored user 270 McAfee Email and Web Security Appliances 5.6.0 Product Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336

Table 269
Option definitions
(continued)
Option
Definition
Off-box system
log
Enable off-box system log
— To send system logs for storage off-box, enable this setting and
define the receiving server parameters:
Receiving server
— Specifies the IP address or host name of the server that receives the
syslog information.
Use IPv6 protocol
— Check this option when sending system logging information over an
IPv6 network.
Port
— Specify the port on the receiving server to be used to transfer the system log
information.
When using off-box system logging, you can specify different ports for each configured
off-box syslog server.
Protocol
— Either TCP or UDP. Specifies the packet type. UDP has a limit of 1024 bytes
per packet.
Add Server
— You can configure multiple off-box servers.
System Log
Archive
Send archive copies of the mail logs to another server, and set up a schedule for this
to happen.
Extended Syslog attributes for ArcSight
Using the extended Syslog functions within the appliance, you can use external, third party software
— such as ArcSight — to generate Syslog reports.
Table 270
Events for ArcSight
Event ID
Event Description
50005
Logging of the email status during processing
50006
Logging of the email status during processing
50022
Logging of the email status during McAfee Quarantine Manager processing
180000
Anti-Virus Engine Detection
180001
Content rule detection
180002
Anti-spam classification
180003
File-format detection
180004
Mail-Filtering detection
180008
URL request denied
180010
Compliancy detection
180011
Data Loss Prevention detection
180012
Mail Size detection
180013
Regular expression scanning failure
180031
URL has been blocked due to categorization
180032
URL has been coached due to categorization
180033
Categorized URL has been permitted
180035
Categorized URL has been permitted for a monitored user
Overview of System features
Logging, Alerting and SNMP
270
McAfee Email and Web Security Appliances 5.6.0 Product Guide