Syslog - Forcepoint Web Security V2.0

Device Details

Device Name

Forcepoint Web Security

Vendor

Forcepoint

Device Type

Security

Supported Model Name/Number

N/A

Supported Software Version

N/A

Collection Method

Syslog

Configurable Log Output

CEF

Log Source Type

Syslog - Forcepoint Web Security

Log Processing Policy

LogRhythm Default V 2.0

Exceptions

N/A

Additional Information

https://www.websense.com/content/support/library/web/v85/siem/siem.pdf

Supported Log Messages

(List of LR tags used to parse the log information for each message type)

Type

Product Version

Supported Schema Fields

V 2.0 : Forcepoint Secure web Gateway Events

N/A

<vendorinfo>, <version>, <severity>, <action>, <protname>, <dip>, <domainorigin>, <dport>, <sip>, <sport>, <login>, <snatport>, <bytesin>, <bytesout>, <command>, <useragent>, <reason>,  <policy>, <objecttype>, <responsecode>, <milliseconds>, <url>, <objectname>, <object>, <processid>, <threatid>, <protnum>, <quantity>

Revision History

KB Version

Log Type

Change Type

Details

KB 7.1.659.0

Syslog - Forcepoint Web Security

New Log Source Optimization (LSO) policy: LogRhythm Default v2.0

Optimized new log processing policy for Syslog - Forcepoint Web Security.