mail.mcafee
Introduction
The tags beginning with mail.mcafee
identify events generated by McAfee Email Gateway.
Valid tags and data tables
The full tag must have 3 levels. The first two are fixed as mail.mcafee
. The third level identifies the type of events sent.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
McAfee Email Gateway |
|
|
For more information, read more About Devo tags.
Table structure
These are the fields displayed in this table:
mail.mcafee.emailgateway
Field | Type | Extra fields |
---|---|---|
eventdate |
|
|
hostname |
|
|
cefVersion |
|
|
embDeviceVendor |
|
|
embDeviceProduct |
|
|
deviceVersion |
|
|
signatureID |
|
|
name |
|
|
severity |
|
|
_cefVer |
|
|
cn3Label |
|
|
cs1Label |
|
|
cs4 |
|
|
sourceServiceName |
|
|
cn2Label |
|
|
cn3 |
|
|
fileId |
|
|
suser |
|
|
cs3 |
|
|
cs5Label |
|
|
app |
|
|
cn1Label |
|
|
shost |
|
|
src |
|
|
cs5 |
|
|
fsize |
|
|
msg |
|
|
cn1 |
|
|
cn2 |
|
|
cs6Label |
|
|
duser |
|
|
cs6 |
|
|
deviceDirection |
|
|
cs2 |
|
|
cs1 |
|
|
cs2Label |
|
|
dhost |
|
|
act |
|
|
dvc |
|
|
cs4Label |
|
|
filePath |
|
|
rt |
|
|
dst |
|
|
cs3Label |
|
|
mcafeeEmailgatewayScanHostIP |
|
|
mcafeeEmailgatewayEmailHybridID |
|
|
mcafeeEmailgatewayMacAddress |
|
|
mcafeeEmailgatewayOriginalSender |
|
|
mcafeeEmailgatewayFileSize |
|
|
flexNumber1Label |
|
|
flexNumber1 |
|
|
mcafeeEmailgatewayHostDomainName |
|
|
mcafeeEmailgatewayUUID |
|
|
mcafeeEmailgatewayUserName |
|
|
mcafeeEmailgatewayOriginalSubject |
|
|
mcafeeEmailgatewayOriginalMessageId |
|
|
mcafeeEmailgatewayFileSig |
|
|
mcafeeEmailgatewayProduct |
|
|
mcafeeEmailgatewayEmailEncryptionType |
|
|
mcafeeEmailgatewayHostName |
|
|
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |