Splunk® Supported Add-ons

Splunk Add-on for McAfee Web Gateway

Source types for the Splunk Add-on for McAfee Web Gateway

The Splunk Add-on for McAfee Web Gateway supports the following data source using the following collection method and provides the following source type, event types, and CIM mappings.

Data source Collection method Source type Event type CIM data models
McAfee Web Gateway kv pairs log Syslog using Splunk Connect for Syslog or file monitor or TCP/UDP mcafee:wg:kv mcafee_wg_web Web
mcafee_wg_alert
mcafee_wg_malware Malware
Last modified on 08 February, 2022
Lookups for the Splunk Add-on for McAfee Web Gateway   Release notes for the Splunk Add-on for McAfee Web Gateway

This documentation applies to the following versions of Splunk® Supported Add-ons: released


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters