cancel
Showing results for 
Search instead for 
Did you mean: 

Available on ESM Signature ID List

Hello guys,

I would like to create some alarm, views, report. Problem is that not all system behaviors I can simulate.

Is there existing any list of all parsed by McAfee Messages? Specially Internal Messages generated by McAfee SIEM?

8 Replies

Re: Available on ESM Signature ID List

Actually there is a list of predefined alarms within ESM that are purely for internal events.

Re: Available on ESM Signature ID List

Do you mean list from Policy Editor? Problem is those signatures are not normalize most important operations done on system.

An example:

Account creation/ change is there but account deletion not.

Would you be so kind and share this list or link to it, please?

Re: Available on ESM Signature ID List

Hi Michel,

Under the ESM settings on the alarms tab there are some alarms or you can create your own and filter based on events and devices.

alarms.PNG

alarms2.PNG

Re: Available on ESM Signature ID List

Hi Alexander,

Yup I know how to do it, problem is that I cannot see events which I need. An example is User has been deleted from any McAfee SIEM appliance. Such normalized event does not exist. ( or I cannot find it). Or a log source has been added to McAfee REC, deleted or modyfied etc... Those logs exist on Appliance log but not are parsed or I cannot find it. That's why I am asking for a List of all parsed messages from McAfee SIEM BOX.

Re: Available on ESM Signature ID List

Honestly there are some limitations i believe that not everything is logged.

Highlighted

Re: Available on ESM Signature ID List

Yep Know that. I have  opened PER case for it.

Re: Available on ESM Signature ID List

Yeah that's probably the best

protah
Level 7
Report Inappropriate Content
Message 9 of 9

Re: Available on ESM Signature ID List

Michal,

Firstly; your question on parsing.. the message parsed is dependent on the Device and the ASP applied to it.

Second; the link below is the KnowledgeBase for native SIEM "Health" rules..

These are "306" rules ie. SID: 306-500XX


McAfee KnowledgeBase - How to determine which rules/signature IDs are generated by the SIEM Health S...

More McAfee Tools to Help You
  • Subscription Service Notification (SNS)
  • How-to: Endpoint Removal Tool
  • Support: Endpoint Security
  • eSupport: Policy Orchestrator
  • Community Help Hub

      New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

    • Find Forum FAQs
    • Learn How to Earn Badges
    • Ask for Help
    Go to Community Help

    Join the Community

      Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

    • Get helpful solutions from McAfee experts.
    • Stay connected to product conversations that matter to you.
    • Participate in product groups led by McAfee employees.
    Join the Community
    Join the Community