Skip to main content
Skip table of contents

V 2.0 : MTA Events

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

V 2.0 : MTA EventsBase RuleGeneral InformationInformation
V 2.0 : Email DeliveredSub RuleEmail DeliveredInformation
V 2.0 : Scan CompletedSub RuleScan CompletedOther Audit Success

Mapping with LogRhythm Schema

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
virtuallogsourceN/AN/AN/A
subproductN/AN/AN/A
Product<vmid>Text/StringProduct name
OriginipN/AN/AIP of the log origin 
originN/AN/AName of the first Security Gateway that reported this event
Action<action>Text/StringDescription of detected malware activity
SIP<sip>IP AddressSource IP
SPort<sport>NumberSource host port number
DIP<dip>IP AddressDestination IP
dport<dport>NumberDestination host port number
protocol<protnum>NumberProtocol detected on the connection
ifname<sinterface>Text/StringThe name of the Security Gateway interface through which a connection traverses
ifdirectionN/AN/AConnection direction
reason<reason>Text/StringInformation on the error occurred
RuleN/AN/AN/A
InfoN/AN/AN/A
XlateSIP<snatip>IP AddressSource ipv4 after applying NAT
XlateSport<snatport>NumberSource port after applying hide NAT on source IP
XlateDIP<dnatip>IP AddressDestination ipv4 after applying NAT
XlateDPort<dnatport>NumberDestination port after applying NAT
user<login>Text/StringSource user name
alertN/AN/AAlert level of matched rule (for connection logs)
icmp-codeN/AN/AN/A
icmp-typeN/AN/AN/A
matched_categoryN/AN/AName of matched category
rule_nameN/AN/AAccess rule name
Url<url>Text/StringMatched URL
timeN/AN/AThe time stamp when the log was created
to<recipient>Text/StringEmail recipient
from<sender>Text/StringEmail sender
Email_Subject<subject>Text/StringSubject of the email
file_size<size>NumberSize of the file
flagsN/AN/AN/A
logidN/AN/AN/A
loguidN/AN/AN/A
originsicnameN/AN/AN/A
sequencenumN/AN/AN/A
versionN/AN/AN/A
arrival_timeN/AN/AN/A
attachments_numN/AN/AN/A
delivery_timeN/AN/AN/A
email_contentN/AN/AN/A
email_headersN/AN/AN/A
email_message_idN/AN/AN/A
email_queue_idN/AN/AN/A
email_queue_nameN/AN/AN/A
email_status<status>
<tag1>
Text/StringN/A
lastupdatetimeN/AN/AN/A
links_numN/AN/AN/A
original_queue_idN/AN/AN/A
scan_endedN/AN/AN/A
scan_startedN/AN/AN/A
status_updateN/AN/AN/A
log_linkN/AN/AN/A
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.