McAfee Web Gateway

Use the IBM® QRadar® Custom Properties for McAfee Web Gateway Content Extension to closely monitor your McAfee Web Gateway deployment.

Important: To avoid content errors in this content extension, keep the associated DSMs up to date. DSMs are updated as part of the automatic updates. If automatic updates are not enabled, download the most recent version of the associated DSMs from IBM Fix Central (https://www.ibm.com/support/fixcentral).

IBM Security QRadar Custom Properties for McAfee Web Gateway Content Extension 1.0.0

The following table shows the custom properties in IBM Security QRadar Custom Properties for McAfee Web Gateway Content Extension 1.0.0.

Table 1. Custom Properties in IBM Security QRadar Custom Properties for McAfee Web Gateway Content Extension 1.0.0
Name Optimized Capture Group Regex
Bytes No 1 totalBytes=(\d+)
BytesReceived Yes 1 BytesToClient=(\d+)

bytestoClient=(\d+)

dstBytes=(\d+)

BytesSent Yes 1 BytesFromClient=(\d+)

bytesfromClient=(\d+)

srcBytes=(\d+)

Policy Name Yes 1 policyRule=([^\|]+)

policy=([^\|]+)

Reason Yes 1 blockReason=([^\|]+)
Referrer URL No 1 referer=([^\|]+)
URL Yes 1 url=([^\|]+)
Web Category Yes 1 urlCategories=([^\|]+)