Skip to content

Latest commit

 

History

History
49 lines (42 loc) · 1.18 KB

02d0e53b-6a92-4837-9aa6-a5d4af42b09c.md

File metadata and controls

49 lines (42 loc) · 1.18 KB

Mappings: McAfee WebGateway - JSON

Input Requirements

Input Value
Vendor McAfee
Product WebGateway
Log Format JSON
Event ID Regex Pattern Authenticate With NTLM

Record Output

Output Value
Vendor McAfee
Product Web Gateway
Record Type NetworkProxy

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
action cheStatus
description urlLongCat
device_hostname hostName
device_ip pxyAd
dstDevice_ip dstAd
dstPort pxyPort
file_mimeType bodyFile
http_hostname urlDom
http_method commName
http_referer headReferer
http_response_contentLength bodySize
http_response_contentType headContent
http_response_statusCode respStatus
http_url dstURL
http_userAgent headUsrAgt
srcDevice_hostname hostName
srcDevice_ip srcAd
srcDevice_natIp pxyOutAd
tcpProtocol connProto
threat_identifier appRep
threat_name ruleName
threat_referenceUrl urlHost
timestamp timeStamp We expect the orginal record value of timeStamp is in the format [dd/MMM/yyyy:HH:mm:ss Z]
user_authDomain authRealm
user_username authUser