Source types for the Splunk Add-on for McAfee Web Gateway
The Splunk Add-on for McAfee Web Gateway supports the following data source using the following collection method and provides the following source type, event types, and CIM mappings.
Data source | Collection method | Source type | Event type | CIM data models |
---|---|---|---|---|
McAfee Web Gateway kv pairs log | Syslog using Splunk Connect for Syslog or file monitor or TCP/UDP | mcafee:wg:kv
|
mcafee_wg_web
|
Web |
mcafee_wg_alert
|
||||
mcafee_wg_malware
|
Malware |
Lookups for the Splunk Add-on for McAfee Web Gateway | Release notes for the Splunk Add-on for McAfee Web Gateway |
This documentation applies to the following versions of Splunk® Supported Add-ons: released
Feedback submitted, thanks!