If you are parsing the notifications sent through email, script, or pager, Trellix recommends that you define your custom message template. Default template may change in newer releases and it may break your parsing algorithms.
The following tables describe the variables used in the various message templates.
Note
“%” "/” and "$" are reserved characters. Do not use them as a delimiter in custom templates.
| Variable name | Description |
|---|---|
| ALERT_ID | Unique ID assigned to an alert by the Manager |
| ALERT_TYPE | The type of the attack that triggered the alert. The value, for example, can be exploit, host sweep, or port scan. |
| ATTACK_TIME | Time when the attack was detected |
| ATTACK_NAME | Name of the attack that triggered the alert |
| ATTACK_ID | The Trellix IPS ID for the attack |
| ATTACK_SEVERITY | System impact severity posed by the attack: high, medium, low, or informational |
| ATTACK_SIGNATURE | Signature that matched the attack traffic (applicable only to signature-based attacks) |
| ATTACK_CONFIDENCE | Higher the confidence, the lower is the chance for the attack to be a false-positive. |
| ADMIN_DOMAIN | The admin domain to which the Sensor that detected the attack belongs |
| ATTACK_COUNT | The number of times the attack was detected within the throttle duration |
| SENSOR_NAME | The Sensor that detected the attack |
| INTERFACE | The Sensor's interface where the attack was detected |
| SENSOR_CLUSTER_MEMBER | The Sensor in a fail-over pair that detected the attack |
| SOURCE_IP | IP address of the host from where the attack originated |
| SOURCE_PORT | The source port number of the attack traffic |
| DESTINATION_IP | IP address of the targeted host |
| DESTINATION_PORT | The destination port number of the attack traffic |
| CATEGORY | General attack type |
| SUB_CATEGORY | Within the attack type, a specific classification such as virus and Trojan horse |
| DIRECTION | Whether the traffic was inbound or outbound |
| RESULT_STATUS | Whether the attack was successful, blocked, or a failed attempt |
| DETECTION_MECHANISM | The method used to detect the attack. Each method relates to a specific attack category. Some of these methods are signature, threshold, statistical anomaly, and flow correlation. |
| APPLICATION_PROTOCOL | The application protocol found in the attack traffic |
| NETWORK_PROTOCOL | The transport protocol used for the attack traffic |
| RELEVANCE | Information whether the attack is relevant for the targeted host based on information from McAfee Vulnerability Manager |
| QUARANTINE_END_TIME | Time when an attacking host will be out of quarantine |
| SENSOR_ALERT_UUID | Unique ID assigned to an alert by the Sensor |
| SOURCE_VM_ESX_NAME | The VMware ESX server that hosts the VMware from which the attack traffic originated |
| SOURCE_VM_NAME | The VMware host from which the attack traffic originated |
| TARGET_VM_NAME | The targeted VMware host for the attack |
| TARGET_VM_ESX_NAME | The VMware ESX server that hosts the targeted VMware |
| URI_INFO |
The URI found in the attack traffic |
| VLAN_ID | The VLAN tagged with the attack traffic |
| DEST_APN | Applicable only to attacks targeted at data-enabled mobile equipments such as a mobile phone or a tablet PC.
The Access Point Name (APN) of the targeted mobile equipment |
| DEST_IMSI | Applicable only to attacks targeted at data-enabled mobile equipments such as a mobile phone or a tablet PC.
The International Mobile Subscriber Identity (IMSI) of the targeted mobile equipment |
| DEST_PHONE_NUMBER | Applicable only to attacks targeted at data-enabled mobile equipments such as a mobile phone or a tablet PC.
The phone number of the targeted mobile equipment |
| SRC_APN | Applicable only to attacks from data-enabled mobile equipments such as a mobile phone or a tablet PC.
The Access Point Name (APN) of the mobile equipment that is the source of the attack traffic |
| SRC_IMSI | Applicable only to attacks from data-enabled mobile equipments such as a mobile phone or a tablet PC.
The International Mobile Subscriber Identity (IMSI) ID of the source mobile equipment |
| SRC_PHONE_NUMBER | Applicable only to attacks from data-enabled mobile equipments such as a mobile phone or a tablet PC.
The phone number of the source mobile equipment |
| LAYER_7_DATA | The application-layer data found in the attack traffic |
| ZONE_NAME | Zone from which the alert was raised; applicable only for NTBA alerts |
| SOURCE_OS | Source OS name |
| DEST_OS | Destination OS name |
| MALWARE_FILE_TYPE | Malware file type |
| MALWARE_FILE_LENGTH | Malware file length |
| MALWARE_FILE_NAME | Malware file name |
| MALWARE_FILE_MD5_HASH | Malware file MD5 hash |
| MALWARE_VIRUS_NAME | Malware virus name |
| MALWARE_CONFIDENCE | Malware confidence |
| MALWARE_DETECTION_ENGINE | Malware detection engine |
The following table describes the fault template variables.
| Name | Description |
|---|---|
| ADMIN_DOMAIN | The admin domain associated with the fault message |
| FAULT_NAME | Name of the fault |
| FAULT_TYPE | The state of the fault, whether it is created, acknowledged, or cleared |
| OWNER_ID | The Sensor ID where the fault occurred. This field is not applicable to Manager faults. |
| OWNER_NAME | The user-defined name of the Sensor where the fault occurred. For Manager fault, the value is 'Manager.' |
| FAULT_LEVEL | The level of the fault. Whether it occurred at the Manager system level, Sensor level, or Sensor interface level. |
| FAULT_TIME | Timestamp of when the fault occurred |
| FAULT_SOURCE | Whether the fault was sent by the Sensor to the Manager or it was generated by the Manager |
| FAULT_COMPONENT | The component where the fault occurred |
| SEVERITY | Whether the fault is critical, an error, warning, informational, or unknown |
| DESCRIPTION | The description as found in the faultNameAndText.properties file |
| ACK_INFORMATION | If true, the fault has been acknowledged by someone. |
| SENSOR_NAME | The user-defined name of the Sensor where the fault occurred |
The following table describes Firewall access rule template variables.
| Name | Description |
|---|---|
| SENSOR_NAME | The Sensor that parsed the traffic matching the Firewall access rule |
| ADMIN_DOMAIN | The admin domain to which the Sensor belongs |
| INTERFACE | The interface where the matching traffic was detected |
| ACL_ACTION | Whether the traffic was inspected, dropped, denied, or ignored |
| SOURCE_IP | The IP address of the host from which the traffic originated |
| SOURCE_PORT | The source port number of the traffic that matched the Firewall access rule |
| DESTINATION_IP | The IP address of the destination host for the traffic |
| DESTINATION_PORT | The destination port number of the traffic that matched the Firewall access rule |
| APPLICATION_PROTOCOL | The layer 7 protocol associated with the traffic that matched the Firewall access rule |
| NETWORK_PROTOCOL | The IP protocol that matched |
| ALERT_DURATION | The number of Firewall syslog messages that were suppressed |
| ALERT_COUNT | The number of Firewall syslog messages that were forwarded |
| ALERT_DIRECTION | Whether the traffic that matched was inbound or outbound |
| APPLICATION | The layer 7 application associated with the matched traffic |
| ACL_DESCRIPTION | The user-entered description of the Firewall policy |
| SOURCE_HOSTNAME | The host DNS name from which the traffic originated |
| DESTINATION_HOSTNAME | The host DNS name to which the traffic is destined |
| SOURCE_COUNTRY | The country from which the traffic originated |
| DESTINATION_COUNTRY | The country to which the traffic is destined to |
| ACL_POLICY | The name of the Firewall policy |
| ACL_RULE_NUMBER | The order of the rule in the effective list of Firewall access rules |