EVID 19101...19136 : McAfee ePO DLP

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

EVID 19101, 19115, 19125, 19136 : McAfee ePO DLP

Base Rule

General Information Log Message

Information

ePO DLP - Agent Installed

Sub Rule

Software Installed

Configuration

ePO DLP - Device Connected

Sub Rule

New Device Found

Information

ePO DLP - Agent Memory Limit Exceeded

Sub Rule

Memory Error

Error

ePO DLP - User Session Info

Sub Rule

General User Information

Information

Mapping with LogRhythm Schema


Device Key in Log Message

LogRhythm Schema

Data Type

Schema Description

N/A

N/A

N/A

N/A

MachineName

<dname>

Text/String

Name of the system hosting the detecting product.

AgentGUID

N/A

N/A

Unique identifier of the agent that forwarded the event.

IPAddress

<dip>

IP Address

IP address of the system hosting the detecting product (if given in the event).

OSName

N/A

N/A

N/A

UserName

<domainimpacted>
<account>

Text/String

N/A

TimeZoneBias

N/A

N/A

N/A

RawMACAddress

<dmac>

Text/String/Number

MAC address of the system hosting the detecting product.

ProductName

<vendorinfo>

Text/String

Name of the detecting managed product.

ProductVersion

<version>

Text/String/Number

Version number of the detecting product.

ProductFamily

N/A

N/A

N/A

EventID

<vmid>

Number

Unique identifier of the event class.

Severity

<severity>

Text/String/Number

N/A

GMTTime

N/A

N/A

N/A

OPGData

N/A

N/A

N/A

UserInfo

N/A

N/A

N/A

ThreatName

<threatname>

Text/String

N/A

PolicyName

<policy>

Text/String/Number

N/A

TimeSZone

N/A

N/A

N/A