Proofpoint Enterprise Protection and Enterprise Privacy 샘플 이벤트 메시지

샘플 이벤트 메시지를 사용하여 QRadar 제품과의 성공적인 통합을 확인하십시오.

Syslog 프로토콜을 사용하는 Proofpoint Enterprise Protection and Enterprise Privacy 샘플 이벤트 메시지

중요: 형식화 문제로 인해 메시지를 텍스트 편집기에 붙여넣고 캐리지 리턴 또는 줄 바꾸기 문자를 제거하십시오.

샘플 1: '발송된' 이메일 로그 메시지의 예가 아래에 제공되어 있습니다.

<22>Feb 11 08:22:26 proofpoint.enterpriseprotection.test sendmail[31248]: s1BDHmHc028570: 
to=<user_test@proof.point.test>, delay=00:00:00, xdelay=00:00:00, mailer=esmtp, pri=186258, 
relay=[172.16.10.32] [172.16.10.32], dsn=2.0.0, stat=Sent (a1AAAAAa111111 Message accepted for delivery)
표 1. Proofpoint Enterprise Protection and Enterprise Privacy 이벤트에서 강조표시된 필드
QRadar 제품 필드 이름 강조표시된 페이로드 필드 이름
이벤트 ID to= (으) 로부터 정보 메시지가 전송되었습니다.
카테고리 Proofpoint
디바이스 시간 발신 페이로드 헤더
소스 IP relay=
사용자 이름 to=

샘플 2: '수신된' 이메일 로그 메시지의 예제가 아래에 제공되어 있습니다.

<22>Feb 11 08:22:26 proofpoint.enterpriseprotection.test sendmail[28570]: s1BDHmHc028570: 
from=<user.1234@proof.point.test>, size=66258, class=0, nrcpts=1,
msgid=<USER.TEST.0@proof.point.test>, proto=SMTP, daemon=MTA, relay=proofpoint.test [127.0.0.1]
표 2. Proofpoint Enterprise Protection and Enterprise Privacy 이벤트에서 강조표시된 필드
QRadar 제품 필드 이름 강조표시된 페이로드 필드 이름
이벤트 ID from= 을 (를) 기반으로 하는 정보 MESSAGE RECEIVED
카테고리 Proofpoint
디바이스 시간 발신 페이로드 헤더
소스 IP 시작 relay=
사용자 이름 from=에서, msgid=