Skip to content

Latest commit

 

History

History
34 lines (27 loc) · 811 Bytes

06d2310a-b511-48f4-b777-559b3e6e2be1.md

File metadata and controls

34 lines (27 loc) · 811 Bytes

Mappings: McAfee Web Gateway - LEEF

Input Requirements

Input Value
Vendor McAfee
Product Web Gateway
Log Format LEEF
Event ID Regex Pattern _default_

Record Output

Output Value
Vendor McAfee
Product Web Gateway
Record Type NetworkProxy

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
description blockReason
device_ip src
http_method HTTPMethod
http_response_statusCode httpStatus
http_url url
http_userAgent UserAgent
severity severity This is a lookup field. More info to come in the catalog later...
srcDevice_ip src
timestamp devTime We expect the orginal record value of devTime is in the format epoch
user_username usrName