Mappings: McAfee Web Gateway - LEEF
Input | Value |
---|---|
Vendor | McAfee |
Product | Web Gateway |
Log Format | LEEF |
Event ID Regex Pattern | _default_ |
Output | Value |
---|---|
Vendor | McAfee |
Product | Web Gateway |
Record Type | NetworkProxy |
Cloud SIEM Schema Field | Original Record Key | Notes |
---|---|---|
description | blockReason | |
device_ip | src | |
http_method | HTTPMethod | |
http_response_statusCode | httpStatus | |
http_url | url | |
http_userAgent | UserAgent | |
severity | severity | This is a lookup field. More info to come in the catalog later... |
srcDevice_ip | src | |
timestamp | devTime | We expect the orginal record value of devTime is in the format epoch |
user_username | usrName |