Document toolboxDocument toolbox

mail.mcafee

Introduction

The tags beginning with mail.mcafee identify events generated by McAfee Email Gateway.

Valid tags and data tables 

The full tag must have 3 levels. The first two are fixed as mail.mcafee. The third level identifies the type of events sent.

These are the valid tags and corresponding data tables that will receive the parsers' data:

Product / Service

Tags

Data tables

Product / Service

Tags

Data tables

McAfee Email Gateway

mail.mcafee.emailgateway

mail.mcafee.emailgateway

For more information, read more About Devo tags.

Table structure

These are the fields displayed in this table:

mail.mcafee.emailgateway

Field

Type

Extra fields

Field

Type

Extra fields

eventdate

timestamp

 

hostname

str

 

cefVersion

str

 

embDeviceVendor

str

 

embDeviceProduct

str

 

deviceVersion

str

 

signatureID

str

 

name

str

 

severity

str

 

_cefVer

str

 

cn3Label

str

 

cs1Label

str

 

cs4

str

 

sourceServiceName

str

 

cn2Label

str

 

cn3

int8

 

fileId

str

 

suser

str

 

cs3

str

 

cs5Label

str

 

app

str

 

cn1Label

str

 

shost

str

 

src

ip4

 

cs5

str

 

fsize

int8

 

msg

str

 

cn1

int8

 

cn2

int8

 

cs6Label

str

 

duser

str

 

cs6

str

 

deviceDirection

int4

 

cs2

str

 

cs1

str

 

cs2Label

str

 

dhost

str

 

act

str

 

dvc

str

 

cs4Label

str

 

filePath

str

 

rt

timestamp

 

dst

ip4

 

cs3Label

str

 

mcafeeEmailgatewayScanHostIP

str

 

mcafeeEmailgatewayEmailHybridID

str

 

mcafeeEmailgatewayMacAddress

str

 

mcafeeEmailgatewayOriginalSender

str

 

mcafeeEmailgatewayFileSize

str

 

flexNumber1Label

str

 

flexNumber1

str

 

mcafeeEmailgatewayHostDomainName

str

 

mcafeeEmailgatewayUUID

str

 

mcafeeEmailgatewayUserName

str

 

mcafeeEmailgatewayOriginalSubject

str

 

mcafeeEmailgatewayOriginalMessageId

str

 

mcafeeEmailgatewayFileSig

str

 

mcafeeEmailgatewayProduct

str

 

mcafeeEmailgatewayEmailEncryptionType

str

 

mcafeeEmailgatewayHostName

str

 

hostchain

str

 ✓

tag

str

 ✓

rawMessage

str

 ✓