Skip to main content
Skip table of contents

Netskope : Malware Event

Vendor Documentation

Classification

Rule Name

Rule Type

Classification

Common Event

Base RuleMalwareDetected Malware Activity

Mapping with LogRhythm Schema

Device Key in Log MessageLogRhythm SchemaData Type
Device vendorN/AN/A
device productN/AN/A
Device versionN/AN/A
Device event class id<vmid>Text/String
Event nameN/AN/A
Severity of the event<severity>Text/String
accessMethodN/AN/A
actN/AN/A
action<action> Text/String
appcategory<subject>Text/String
cciN/AN/A
cclN/AN/A
dst<dip>IP Address
fsize<size> Number
hostname<dname>Text/String
md5<hash> Text/String/Number
mwDetectionEngineN/A N/A
mwDetectionName<threatname> Text/String
mwId<threatid>Text/String/Number
mwProfileN/AN/A
mwScannerResultN/AN/A
mwTypeN/AN/A
object<object>Text/String/Number
requestClientApplicationN/AN/A
src<sip>IP Address
sha256<hash> Text/String
sourceServiceName<process>Text/String
suser<login>Text/String
timestampN/AN/A
 url<url>Text/String
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.