mail.mcafee
Introduction
The tags beginning with mail.mcafee
identify events generated by McAfee Email Gateway.
Valid tags and data tablesÂ
The full tag must have 3 levels. The first two are fixed as mail.mcafee
. The third level identifies the type of events sent.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
McAfee Email Gateway |
|
|
For more information, read more About Devo tags.
Table structure
These are the fields displayed in this table:
mail.mcafee.emailgateway
Field | Type | Extra fields |
---|---|---|
eventdate |
| Â |
hostname |
| Â |
cefVersion |
| Â |
embDeviceVendor |
| Â |
embDeviceProduct |
| Â |
deviceVersion |
| Â |
signatureID |
| Â |
name |
| Â |
severity |
| Â |
_cefVer |
| Â |
cn3Label |
| Â |
cs1Label |
| Â |
cs4 |
| Â |
sourceServiceName |
| Â |
cn2Label |
| Â |
cn3 |
| Â |
fileId |
| Â |
suser |
| Â |
cs3 |
| Â |
cs5Label |
| Â |
app |
| Â |
cn1Label |
| Â |
shost |
| Â |
src |
| Â |
cs5 |
| Â |
fsize |
| Â |
msg |
| Â |
cn1 |
| Â |
cn2 |
| Â |
cs6Label |
| Â |
duser |
| Â |
cs6 |
| Â |
deviceDirection |
| Â |
cs2 |
| Â |
cs1 |
| Â |
cs2Label |
| Â |
dhost |
| Â |
act |
| Â |
dvc |
| Â |
cs4Label |
| Â |
filePath |
| Â |
rt |
| Â |
dst |
| Â |
cs3Label |
| Â |
mcafeeEmailgatewayScanHostIP |
| Â |
mcafeeEmailgatewayEmailHybridID |
| Â |
mcafeeEmailgatewayMacAddress |
| Â |
mcafeeEmailgatewayOriginalSender |
| Â |
mcafeeEmailgatewayFileSize |
| Â |
flexNumber1Label |
| Â |
flexNumber1 |
| Â |
mcafeeEmailgatewayHostDomainName |
| Â |
mcafeeEmailgatewayUUID |
| Â |
mcafeeEmailgatewayUserName |
| Â |
mcafeeEmailgatewayOriginalSubject |
| Â |
mcafeeEmailgatewayOriginalMessageId |
| Â |
mcafeeEmailgatewayFileSig |
| Â |
mcafeeEmailgatewayProduct |
| Â |
mcafeeEmailgatewayEmailEncryptionType |
| Â |
mcafeeEmailgatewayHostName |
| Â |
hostchain |
|  ✓ |
tag |
|  ✓ |
rawMessage |
|  ✓ |