Skip to content

Latest commit

 

History

History
29 lines (22 loc) · 860 Bytes

b33374ad-6ddd-4505-8012-ed17b09690d6.md

File metadata and controls

29 lines (22 loc) · 860 Bytes

Mappings: McAfee Endpoint Update Event Logs

Input Requirements

Input Value
Vendor McAfee
Product Endpoint Security
Log Format JSON
Event ID Regex Pattern UpdateEvents

Record Output

Output Value
Vendor McAfee
Product Endpoint Security
Record Type Endpoint

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
device_hostname UpdateEvents.MachineInfo.MachineName
device_ip UpdateEvents.MachineInfo.IPAddress
device_mac UpdateEvents.MachineInfo.RawMACAddress
timestamp UpdateEvents.McAfeeCommonUpdater.UpdateEvent.GMTTime We expect the orginal record value of UpdateEvents.McAfeeCommonUpdater.UpdateEvent.GMTTime is in the format YYYY-MM-dd'T'HH:mm:ss
user_username UpdateEvents.MachineInfo.UserName