Skip to main content
Skip table of contents

V 2.0 : FireEye MPS Events

Vendor Documentation

Classification

Rule NameRule TypeCommon EventClassification
V 2.0: FireEye MPS EventsBase RuleFireEye NotificationOperations: Other Operations
V 2.0: Trellix FMPS EventsSub RuleGeneral Firewall EventOperations: Information

Mapping with LogRhythm Schema

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
N/AN/AN/AFormat
N/A<tag1>Text/StringDevice Vendor
N/A<vendorinfo>Text/StringDevice Product
N/AN/AN/ADevice Version
N/AN/AN/ASignature ID
N/A<process>Text/StringName
N/A<severity>NumberSeverity
rtN/AN/ALog generation time in UTC
src<sip>Ip AddressSource IP address
cn2LabelN/AN/ACorresponding label for the "cn2" field
cn2N/AN/AProtocol
shost<sname>Text/StringEndpoint hostname
proto<protname>Text/StringThe network protocol being exploited
dvchost<dname>Text/StringHost Name
dst<dip>Ip AddressDestination IP address
spt<sport>NumberSource Port
dvcN/AN/ADevice IP address
smac<smac>Text/String/NumberSource Mac address
cn1LabelN/AN/ACorresponding label for the "cn1" field
cn1N/AN/AVLAN
dpt<dport>NumberDestination Port
externalIdN/AN/AID
cs4LabelN/AN/ACorresponding label for the "cs4" field
cs4<url>Text/StringURL
dmac<dmac>Text/String/NumberDestination MAC address
cs1LabelN/AN/ACorresponding label for the "cs1" field
cs1<subject>Text/StringMessage
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.