McAfee MAP-3300-SWG Product Guide - Page 272

Extended Syslog attributes for Splunk, Table 271

Page 272 highlights

Overview of System features Logging, Alerting and SNMP Table 271 Email and Web Security Appliance v5.6 Connector Field Mappings (continued) McAfee-Specific Event Definition ArcSight Event Data Field The definition of this field depends on the value of cs1Label the field 'cs5': If cs5 is 'AV' or 'PA' or 'PU': 'virus-names' If cs5 is 'AS': 'spam-rules-broken' If cs5 is 'DL': 'dlpfile' If cs5 is 'FF': 'content-rules' If cs5 is 'PX': 'content-rules' The definition of this field depends on the value of cs2 the field 'cs5': If cs5 is 'AV' or 'PA' or 'PU': The version of the Anti-Virus engine If cs5 is 'AS': The spam score If cs5 is 'DL': The DLP categories that triggered If cs5 is 'PX': The terms that caused the content filter event The definition of this field depends on the value of cs2Label the field 'cs5': If cs5 is 'AV' or 'PA' or 'PU': 'av-engine-version' If cs5 is 'AS': 'spam-score' If cs5 is 'DL': 'dlp-rules' If cs5 is 'PX': 'compliance-terms' The definition of this field depends on the value of cs3 the field 'cs5': If cs5 is 'AS': The threshold the message exceeded The definition of this field depends on the value of cs3Label the field 'cs5': If cs5 is 'AS': 'spam-threshold-score' The attachments of the email (if available) cs4 'email-attachments' cs4Label For a detection event, the scanner which cs5 triggered the event: 'AP' - Anti-Phish 'AS' - Anti-Spam 'AV' - Anti-Virus 'DL' - Data Loss Prevention 'FF' - File Filtering 'MF' - Mail Filtering 'MS' - Mail Size 'PA' - Packer 'PU' - Potentially Unwanted Program 'PX' - Compliancy 'SA' - SiteAdvisor 'UF' - URL Filtering 'master-scan-type' cs5Label The subject of the email cs6 'email-subject' cs6Label Indicates if the action taken is the main action cn1 defined for the event. 1 indicates primary action 'is-primary-action' cn1Label The number of attachments in the email (if cn2 available) 'num-email-attachments' cn2Label The number of recipients of the email cn3 'num-email-recipients' cn3Label Extended Syslog attributes for Splunk Using the extended Syslog functions within the appliance, you can use external, third party software - such as Splunk - to generate Syslog reports. Table 272 Extended Syslog attributes for Splunk Syslog entry Notes Example Time and Appliance Name Dec 30 10:58:10 Appliance1 app Protocol Smtp 272 McAfee Email and Web Security Appliances 5.6.0 Product Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336

Table 271
Email and Web Security Appliance v5.6 Connector Field Mappings
(continued)
McAfee-Specific Event Definition
ArcSight Event Data Field
The definition of this field depends on the value of
the field 'cs5': If cs5 is 'AV' or 'PA' or 'PU':
'virus-names' If cs5 is 'AS': 'spam-rules-broken'
If cs5 is 'DL': 'dlpfile' If cs5 is 'FF': 'content-rules'
If cs5 is 'PX': 'content-rules'
cs1Label
The definition of this field depends on the value of
the field 'cs5': If cs5 is 'AV' or 'PA' or 'PU': The
version of the Anti-Virus engine If cs5 is 'AS': The
spam score If cs5 is 'DL': The DLP categories that
triggered If cs5 is 'PX': The terms that caused the
content filter event
cs2
The definition of this field depends on the value of
the field 'cs5': If cs5 is 'AV' or 'PA' or 'PU':
'av-engine-version' If cs5 is 'AS': 'spam-score' If
cs5 is 'DL': 'dlp-rules' If cs5 is 'PX':
'compliance-terms'
cs2Label
The definition of this field depends on the value of
the field 'cs5': If cs5 is 'AS': The threshold the
message exceeded
cs3
The definition of this field depends on the value of
the field 'cs5': If cs5 is 'AS': 'spam-threshold-score'
cs3Label
The attachments of the email (if available)
cs4
'email-attachments'
cs4Label
For a detection event, the scanner which
triggered the event: 'AP' - Anti-Phish 'AS' -
Anti-Spam 'AV' - Anti-Virus 'DL' - Data Loss
Prevention 'FF' - File Filtering 'MF' - Mail Filtering
'MS' - Mail Size 'PA' - Packer 'PU' - Potentially
Unwanted Program 'PX' - Compliancy 'SA' -
SiteAdvisor 'UF' - URL Filtering
cs5
'master-scan-type'
cs5Label
The subject of the email
cs6
'email-subject'
cs6Label
Indicates if the action taken is the main action
defined for the event. 1 indicates primary action
cn1
'is-primary-action'
cn1Label
The number of attachments in the email (if
available)
cn2
'num-email-attachments'
cn2Label
The number of recipients of the email
cn3
'num-email-recipients'
cn3Label
Extended Syslog attributes for Splunk
Using the extended Syslog functions within the appliance, you can use external, third party software
— such as Splunk — to generate Syslog reports.
Table 272
Extended Syslog attributes for Splunk
Syslog entry
Notes
Example
Time and Appliance Name
Dec 30 10:58:10 Appliance1
app
Protocol
Smtp
Overview of System features
Logging, Alerting and SNMP
272
McAfee Email and Web Security Appliances 5.6.0 Product Guide