Skip to main content
Skip table of contents

Syslog - FireEye EX

Device Details

VendorFireEye
Device TypeEmail Security
Supported Model Name/NumberN/A
Supported Software VersionN/A
Collection MethodSyslog
Configurable Log OutputN/A
Log Source TypeSyslog - FireEye EX
Log Processing PolicyLogRhythm Default
ExceptionsN/A
Additional Informationhttps://www.fireeye.com/content/dam/fireeye-www/products/pdfs/pf/email/fireeye-ex-series.pdf
https://docs.mcafee.com/bundle/enterprise-security-manager-data-sources-configuration-reference-guide/page/GUID-DEE7F31A-23FA-4A89-B641-C2DF422E7748.html
 https://www.fireeye.com/content/dam/fireeye-www/global/en/partners/pdfs/fireeye-splunk-intro-to-integration.pdf   

Currently Supported Log Types

TypeVersionSupported Schema Fields
Riskware Object MessageAll

<version>, <severity>, <objectname>, <objecttype>, <threatname>, <action>, <dip>, <login>, <hash>, <subject>, <vmid>, <url>, <sname>, <account>, <domainorigin>, <protname>

Malware Object MessageAll

<version>, <severity>, <objectname>, <objecttype>, <object>, <action>, <dip>, <login>, <hash>, <subject>, <vmid>, <url>, <sname>, <account>, <domainorigin>, <protname>, <parentprocessname>, <status>, <threatname>

CatchallAll<severity>

Parsed Metadata Fields

Field NameLogRhythm Metadata FieldValue/Data Type
actActionText/String
applicationProtocolProtNameText/String
cs1ThreatNameText/String
cs4URLText/String
duserAcccountText/String
dvcDIPIP Address
dvchostLoginText/String
filehashHashHash
filetypeObjectTypeText/String
fnameObjectNameText/String
msgSubjectText/String
msgObjectText/String
severitySeverityNumber
sourceDnsDomainDomainOriginText/String
sprocParentProcessNameText/String
suserSNameText/String
versionVersionNumber
vmidVMIDNumber
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.