Skip to main content
Skip table of contents

EVID 20720...20846 : McAfee Ep

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

EVID 20720, 20748, 20761, 20776, 20778, 20795, 20831, 20846 : McAfee Ep

Base Rule

General Information Log Message

Information

ePO - AC - Execution Denied

Sub Rule

Command Execution Failure

Access Failure

ePO - AC - Registry Write Denied

Sub Rule

Delete/Remove Object Failure

Access Failure

ePO - AC - Inventory Corrupt

Sub Rule

General Error Message

Error

ePO - AC - File Modified

Sub Rule

Object Modified

Access Success

ePO - AC - File Renamed

Sub Rule

Object Renamed

Access Success

ePO - AC - Package Install Denied

Sub Rule

Application Blocked

Failed Activity

ePO - AC - Cache Throttling

Sub Rule

General Warning Log Message

Warning

ePO - AC - General Event

Sub Rule

General Information Log Message

Information

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

Schema Description

N/AN/AN/AN/A
Machinename<dname>Text/StringName of the system hosting the detecting product.
AgentGUIDN/AN/AUnique identifier of the agent that forwarded the event.
IPAddress<dip>IP AddressIP address of the system hosting the detecting product (if given in the event).
OSNameN/AN/AN/A
UserName<account>
<domainimpacted>
Text/StringN/A
TimeZoneBiasN/AN/AN/A
RawMACAddress<dmac>Text/String/NumberMAC address of the system hosting the detecting product.
ProductName<vendorinfo>Text/StringName of the detecting managed product.
ProductVersion<version>Text/String/NumberVersion number of the detecting product.
ProductFamilyN/AN/AN/A
EventID<vmid>NumberUnique identifier of the event class.
Severity<severity>Text/String/NumberN/A
GMTTimeN/AN/AN/A
SCORevent_name<action>Text/StringN/A
SCORevt_idN/AN/AN/A
SCORevt_typeN/AN/AN/A
SCORevt_sinkN/AN/AN/A
SCORseq_noN/AN/AN/A
SCORtime_stampN/AN/AN/A
SCORserver_stateN/AN/AN/A
SCORuser_name<domainorigin>
<login>
Text/StringN/A
SCORprocess_name<process>Text/StringN/A
SCORprocess_id<processid>Text/String/NumberN/A
SCORreputation_scoreN/AN/AN/A
SCORparent_process_name<parentprocesspath>
<parentprocessname>
Text/StringN/A
SCORfile_name<object>Text/StringN/A
SCORfile_sha1<hash>Text/StringN/A
SCORfile_md5N/AN/AN/A
SCORfile_sha256N/AN/AN/A
SCORfile_type<objecttype>Text/StringN/A
SCORdeny_reason<reason>Text/StringN/A
SCORdeny_reason_codeN/AN/AN/A
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.