Table 272 Extended Syslog attributes for Splunk (continued)
Syslog entry
Notes
Example
size
Size of the message in bytes
231
attachments
The attachments of the email
(optional)
file1.doc, file2.doc
number_attachments
The number of attachments of
the email (optional)
2
virus_name
The name of the detected virus
EICAR test file
file_name
Filename in which the detection
occurred
eicar_com.zip
spamscore
The score this message achieved
spamthreshold
The threshold it exceeded
spamrules
A list of the rules to determine
it's status as spam
URL
Url which caused the event to be
generated
http://www.eicar.org/download/
eicar.com
contentrule
The rule that caused the event
content_terms
The terms that caused the
content filter event
tz
The timezone where the event is
generated
UTC
tz_offset
The timezone offset in use
where the event is generated
+0000
Table 273 Glossary
event_id
Name
Scanner
50006
Email Status
-
180000
Anti-virus engine detection
AV (Anti Virus)
180002
Anti-spam classification
AS (Anti Spam)
180002
Anti-spam classification
AP (Anti Phish)
180003
File format detection
FF (Format Blocking)
180004
MIME format detection
MF (Mime Format)
180008
URL request denied
UF (URL Filtering)
180010
Compliancy detection
PX (Compliance)
180010
Data Loss Prevention detection
DL (Data Loss Prevention)
180012
Mail Size detection
MS(Mail Size)
180031
URL has been blocked due to
categorization
SA (Site Advisor)
reason_id
Text
77
Email Delivered
83
Email Deferred
142
Access to the requested URL is not permitted
145
clean
146
replace
Overview of System features
Logging, Alerting and SNMP
274
McAfee Email and Web Security Appliances 5.6.0 Product Guide
Summary of Contents for MAP-3300-SWG - Web Security Appliance 3300
Page 1: ...Product Guide McAfee Email and Web Security Appliances 5 6 0 ...
Page 6: ......
Page 20: ......
Page 28: ......
Page 58: ......
Page 206: ......
Page 310: ......
Page 322: ......
Page 324: ......
Page 326: ......
Page 333: ......
Page 334: ......
Page 335: ......
Page 336: ...700 2647A00 00 ...