Skip to main content
Skip table of contents

V 2.0 : Symantec DLP Events

Vendor Documentation

Classification

Rule NameRule TypeCommon EventClassification
V 2.0 : Symantec DLP EventsBase RuleGeneral DLP MessageInformation

Mapping with LogRhythm Schema

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
N/AN/AN/AFormat
N/AN/AN/ADevice Vendor
N/A<vendorinfo>Text/StringDeviceProduct
N/AN/AN/ADevice Version
N/AN/AN/AruleID
N/AN/AN/APOLICY
N/AN/AN/ASeverity
APPLICATION_NAME<process>Text/StringSpecifies the name of the application that is associated with the incident.
ATTACHMENT_FILENAME<object>Text/StringSpecifies the name of the attached file.
BLOCKED<action>Text/StringIndication of whether or not Symantec Data Loss Prevention blocked the message (yes or no).
DESTINATION_IP<dip>IP AddressSpecifies the destination IP address.
INCIDENT_IDN/AN/AThe unique identifier of the incident.
INCIDENT_SNAPSHOT<url>Text/StringThe fully qualified URL to the incident snapshot page for the incident.
MATCH_COUNTN/AN/AThe incident match count.
OCCURED_ONN/AN/ASpecifies the date on which the incident occurred. This date may be different than the date the incident was reported.
POLICY<policy>Text/StringThe name of the policy that was violated.
POLICY_RULES / RULESN/AN/AA comma-separated list of one or more policy rules that were violated.
PROTOCOL<protname>Text/StringThe protocol, device type, and target type of the incident, where applicable.
RECIPIENTS<recipient>Text/StringA comma-separated list of one or more message recipients. Includes the requested URL in web incidents.
REPORTED_ONN/AN/ASpecifies the date on which the incident was reported.
MONITOR_NAMEN/AN/ASpecifies the detection server or cloud detector that created the incident.
SENDER<sender>Text/StringThe message sender.
SEVERITY<severity>Text/StringThe severity that is assigned to incident.
STATUS<status>Text/StringSpecifies the remediation status of the incident.
SUBJECT<subject>Text/StringThe subject of the message.
URL<url>Text/StringSpecifies the file path or location.
APPLICATION_USER<account>N/AThe name of the application user.
DATAOWNER_NAMEN/AN/AThe person responsible for remediating the incident. This field must be set manually, or with one of the lookup plug-ins.
Reports can automatically be sent to the data owner for remediation.
DATAOWNER_EMAILN/AN/AThe email address of the person responsible for remediating the incident. This field can be set manually, or with one of the lookup plug-ins.
ENDPOINT_LOCATIONN/AN/AThe location of the endpoint computer.
ENDPOINT_MACHINE<sname>Text/StringThe name of the endpoint computer that generated the violation.
ENDPOINT USERNAME<domainorigin>/<login>Text/StringThe name of the endpoint user.
MACHINE_IP<sip>IP AddressThe corporate IP address of the endpoint computer.
USER_JUSTIFICATION<reason>Text/StringThe justification that was provided by the endpoint user.
PATHN/AN/AThe full path to the file in which the incident was found.
FILE_NAME<object>Text/StringThe name of the file in which the incident was found.
PARENT_PATHN/AN/AThe path to the parent directory of the file in which the incident was found.
QUARANTINE_PARENT_PATHN/AN/AThe path to the parent directory in which the file was quarantined.
SCAN_DATEN/AN/AThe date of the scan that found the incident.
TARGETN/AN/AThe name of the target in which the incident was found.
FNAME<object>Text/StringN/A
ENDPOINT_DEVICE_IDN/AN/AN/A
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.