Skip to main content
Skip table of contents

LSO : Syslog - Symantec DLP CEF (Mapping Doc)

This document explains the changes required to apply new Message Processing Engine (MPE) rules developed during the Log Source Optimization (LSO) project for the Syslog - Symantec DLP CEF log source type. 

Vendor Documentation


Supported Log Messages

The following table lists the log message types supported in the current MPE rules. Each page contains detailed information on parsing changes and new log processing settings.

Log Message TypeEvent Type
Catch All : Level 1General Information
DLP Enforce Archive MessageEmail DLP Archive Message
DLP MessagesGeneral Data Loss Message
DLP Messages - CEF FormatGeneral Data Loss Message
DLP Messages - CEF Format 2General DLP Message
Last Message RepeatedLast Message Repeated
Personal InformationGeneral User Information
Personal Information - CEF FormatUser Information
Security Number Pattern Log MessagesGeneral Security Information
Symantec Service RequestSymantec Server Information Message

Log Processing Policy Updates

This section details log processing policy updates made to AIE Rules, system reports, system investigations, system report templates, and system tails as part of LSO.

Updates to AIE Rules

  • No changes

Updates to System Reports

  • No changes

Updates to System Investigations

  • No changes

Updates to System Report Templates

  • No changes

Updates to System Tails

  • No changes

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.