Document toolboxDocument toolbox

Antivirus

This group includes tables that start with the level av. These tables receive data generated by antivirus and protection software.

Company

Product / Service

Data tables

Company

Product / Service

Data tables

Mobile Threat Prevention 

  • av.checkpoint.mtp.audit

  • av.checkpoint.mtp.event


F-Secure Internet Gatekeeper

  • av.fsecure.igk.access


McAfee ePolicy Orchestrator (McAfee ePO)


SentinelOne Endpoint Protection Platform (EPP)

  • av.sentinelone.events


Sophos AntiVirus

  • av.sophos.applicationcontrol

  • av.sophos.devicecontrol 

  • av.sophos.enterprise

  • av.sophos.events

  • av.sophos.tamperprotection 

  • av.sophos.threatinstances 

  • av.sophos.threats 

    More info about these parsers


Symantec Endpoint Protection

 

 

 

Symantec Endpoint Protection Cloud

 

  • av.symantec.sep.mail






  • av.symantec.sepc.events


Deep Security Software

 

 

InterScan Web Security Virtual Appliance

  • av.trendmicro.deepsec.agent

  • av.trendmicro.deepsec.console

  • av.trendmicro.deepsec.manager


  • av.trendmicro.iwsva.event

Â