McAfee MAP-3300-SWG Product Guide - Page 274

Table 272, Extended Syslog attributes for Splunk, Glossary, content_terms

Page 274 highlights

Overview of System features Logging, Alerting and SNMP Table 272 Extended Syslog attributes for Splunk (continued) Syslog entry Notes Example size Size of the message in bytes 231 attachments The attachments of the email (optional) file1.doc, file2.doc number_attachments The number of attachments of 2 the email (optional) virus_name The name of the detected virus EICAR test file file_name Filename in which the detection eicar_com.zip occurred spamscore The score this message achieved spamthreshold The threshold it exceeded spamrules A list of the rules to determine it's status as spam URL Url which caused the event to be http://www.eicar.org/download/ generated eicar.com contentrule The rule that caused the event content_terms The terms that caused the content filter event tz The timezone where the event is UTC generated tz_offset The timezone offset in use where the event is generated +0000 Table 273 Glossary event_id 50006 180000 180002 180002 180003 180004 180008 180010 180010 180012 180031 Name Email Status Anti-virus engine detection Anti-spam classification Anti-spam classification File format detection MIME format detection URL request denied Compliancy detection Data Loss Prevention detection Mail Size detection URL has been blocked due to categorization Scanner AV (Anti Virus) AS (Anti Spam) AP (Anti Phish) FF (Format Blocking) MF (Mime Format) UF (URL Filtering) PX (Compliance) DL (Data Loss Prevention) MS(Mail Size) SA (Site Advisor) reason_id 77 83 142 145 146 Text Email Delivered Email Deferred Access to the requested URL is not permitted clean replace 274 McAfee Email and Web Security Appliances 5.6.0 Product Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336

Table 272
Extended Syslog attributes for Splunk
(continued)
Syslog entry
Notes
Example
size
Size of the message in bytes
231
attachments
The attachments of the email
(optional)
file1.doc, file2.doc
number_attachments
The number of attachments of
the email (optional)
2
virus_name
The name of the detected virus
EICAR test file
file_name
Filename in which the detection
occurred
eicar_com.zip
spamscore
The score this message achieved
spamthreshold
The threshold it exceeded
spamrules
A list of the rules to determine
it's status as spam
URL
Url which caused the event to be
generated
eicar.com
contentrule
The rule that caused the event
content_terms
The terms that caused the
content filter event
tz
The timezone where the event is
generated
UTC
tz_offset
The timezone offset in use
where the event is generated
+0000
Table 273
Glossary
event_id
Name
Scanner
50006
Email Status
-
180000
Anti-virus engine detection
AV (Anti Virus)
180002
Anti-spam classification
AS (Anti Spam)
180002
Anti-spam classification
AP (Anti Phish)
180003
File format detection
FF (Format Blocking)
180004
MIME format detection
MF (Mime Format)
180008
URL request denied
UF (URL Filtering)
180010
Compliancy detection
PX (Compliance)
180010
Data Loss Prevention detection
DL (Data Loss Prevention)
180012
Mail Size detection
MS(Mail Size)
180031
URL has been blocked due to
categorization
SA (Site Advisor)
reason_id
Text
77
Email Delivered
83
Email Deferred
142
Access to the requested URL is not permitted
145
clean
146
replace
Overview of System features
Logging, Alerting and SNMP
274
McAfee Email and Web Security Appliances 5.6.0 Product Guide