Skip to main content
Skip table of contents

EVID 19101...19136 : McAfee ePO DLP

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

EVID 19101, 19115, 19125, 19136 : McAfee ePO DLP

Base Rule

General Information Log Message

Information

ePO DLP - Agent Installed

Sub Rule

Software Installed

Configuration

ePO DLP - Device Connected

Sub Rule

New Device Found

Information

ePO DLP - Agent Memory Limit Exceeded

Sub Rule

Memory Error

Error

ePO DLP - User Session Info

Sub Rule

General User Information

Information

Mapping with LogRhythm Schema


Device Key in Log Message

LogRhythm Schema

Data Type

Schema Description

N/AN/AN/AN/A
MachineName<dname>Text/StringName of the system hosting the detecting product.
AgentGUIDN/AN/AUnique identifier of the agent that forwarded the event.
IPAddress<dip>IP AddressIP address of the system hosting the detecting product (if given in the event).
OSNameN/AN/AN/A
UserName<domainimpacted>
<account>
Text/StringN/A
TimeZoneBiasN/AN/AN/A
RawMACAddress<dmac>Text/String/NumberMAC address of the system hosting the detecting product.
ProductName<vendorinfo>Text/StringName of the detecting managed product.
ProductVersion<version>Text/String/NumberVersion number of the detecting product.
ProductFamilyN/AN/AN/A
EventID<vmid>NumberUnique identifier of the event class.
Severity<severity>Text/String/NumberN/A
GMTTimeN/AN/AN/A
OPGDataN/AN/AN/A
UserInfoN/AN/AN/A
ThreatName<threatname>Text/StringN/A
PolicyName<policy>Text/String/NumberN/A
TimeSZoneN/AN/AN/A
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.