Skip to content

Latest commit

 

History

History
29 lines (22 loc) · 749 Bytes

b95bbe75-269b-4b8a-bf90-cbc1470aeacc.md

File metadata and controls

29 lines (22 loc) · 749 Bytes

Mappings: McAfee WebGateway - CEF - File Download

Input Requirements

Input Value
Vendor McAfee
Product WebGateway
Log Format CEF
Event ID Regex Pattern FILE_DOWNLOAD

Record Output

Output Value
Vendor McAfee
Product Web Gateway
Record Type Audit

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
action Action
description None The static text An audit file was downloaded from the web gateway is populated in this schema field.
device_hostname Appliance
timestamp Timestamp We expect the orginal record value of Timestamp is in the format dd/MMM/yyyy:HH:mm:ss.SSS
user_username User