McAfee MAP-3300-SWG Product Guide - Page 271

Device Event Mapping to ArcSight Data Fields, Table 271

Page 271 highlights

Overview of System features Logging, Alerting and SNMP Device Event Mapping to ArcSight Data Fields Information contained within vendor-specific event definitions is sent to the ArcSight SmartConnector, then mapped to an ArcSight data field. The following table lists the mappings from ArcSight data fields to the supported vendor-specific event definitions. Table 271 Email and Web Security Appliance v5.6 Connector Field Mappings McAfee-Specific Event Definition ArcSight Event Data Field The Action taken for the event: act ESERVICES:REPLACE - Replace with an alert WEBSHIELD:REFUSEORIGINAL - Refuse the email WEBSHIELD:ACCEPTANDDROP - Accept the email and then drop it ESERVICES:ALLOWTHRU - Allow the email through WEBSHIELD:DENYCONNECTION - Refuse the email and deny the connection for a period of time Protocol app A descriptive message for the event msg Host responsible for scanning dvc Destination IP address of the connection (if dst available) Destination hostname of the connection (if available) dhost Originating IP address of the host making the src connection Originating hostname of the host making the connection shost The sender of the email suser A list of recipient email addresses duser Whether inbound (0) or outbound(1) as defined deviceDirection by the administrator for the policy Name of active policy sourceServiceName Filename in which the detection occurred filePath A unique id assigned to each mail message fileId Size of the message in bytes fsize Time of the event, in milliseconds since epoch rt URL which caused the event to be generated request Reason ID for event. See 'msg' field for textual description flexNumber1 'reason-id' flexNumber1Label The definition of this field depends on the value of cs1 the field 'cs5': If cs5 is 'AV' or 'PA' or 'PU': The name of the detected virus/packer/PuP. If cs5 is 'AS': The spam rules that triggered the event If cs5 is 'DL': The file that triggered the DLP rule If cs5 is 'FF': The file rule that triggered the event If cs5 is 'PX': The content rule that triggered the event McAfee Email and Web Security Appliances 5.6.0 Product Guide 271

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336

Device Event Mapping to ArcSight Data Fields
Information contained within vendor-specific event definitions is sent to the ArcSight SmartConnector,
then mapped to an ArcSight data field.
The following table lists the mappings from ArcSight data fields to the supported vendor-specific event
definitions.
Table 271
Email and Web Security Appliance v5.6 Connector Field Mappings
McAfee-Specific Event Definition
ArcSight Event Data Field
The Action taken for the event:
ESERVICES:REPLACE - Replace with an alert
WEBSHIELD:REFUSEORIGINAL - Refuse the email
WEBSHIELD:ACCEPTANDDROP - Accept the email
and then drop it ESERVICES:ALLOWTHRU - Allow
the email through
WEBSHIELD:DENYCONNECTION - Refuse the
email and deny the connection for a period of time
act
Protocol
app
A descriptive message for the event
msg
Host responsible for scanning
dvc
Destination IP address of the connection (if
available)
dst
Destination hostname of the connection (if
available)
dhost
Originating IP address of the host making the
connection
src
Originating hostname of the host making the
connection
shost
The sender of the email
suser
A list of recipient email addresses
duser
Whether inbound (0) or outbound(1) as defined
by the administrator for the policy
deviceDirection
Name of active policy
sourceServiceName
Filename in which the detection occurred
filePath
A unique id assigned to each mail message
fileId
Size of the message in bytes
fsize
Time of the event, in milliseconds since epoch
rt
URL which caused the event to be generated
request
Reason ID for event. See 'msg' field for textual
description
flexNumber1
'reason-id'
flexNumber1Label
The definition of this field depends on the value of
the field 'cs5': If cs5 is 'AV' or 'PA' or 'PU': The
name of the detected virus/packer/PuP. If cs5 is
'AS': The spam rules that triggered the event If
cs5 is 'DL': The file that triggered the DLP rule If
cs5 is 'FF': The file rule that triggered the event If
cs5 is 'PX': The content rule that triggered the
event
cs1
Overview of System features
Logging, Alerting and SNMP
McAfee Email and Web Security Appliances 5.6.0 Product Guide
271