McAfee EPO
StandardMcAfee EPO normalizes McAfee EPO events and enables you to analyze the attack summary, threats, firewall activities, and attack severities using dashboards.
Release Details
Enhancement
Installation
To install McAfee EPO v 5.1.0 :
- Download the McAfee EPO package from the Download section in the Release Details table.
- Add McAfee EPO as a required device in LogPoint.
- Create a collection policy with the Syslog collector and an appropriate processing policy.
- Assign the policy to the device.
- Add the dashboard.
- Download the Trend Micro DB package from the Download section in the Release Details table..
- Add McAfee EPO as a required device in LogPoint.
- Configure ODBC fetcher. To learn more, go to the Configuring the ODBC Fetcher for McAfee EPO in the McAfee EPO v5.1.0 guide.
- Assign the policy to the device.
- Add the dashboard.
Past Releases
6.7.0 or later ▾
Enhancements
Bug Fixes
6.0.0 to 6.6.6 ▾
Enhancement
Log Formats
Expected Log Format Sample
McAfee EPO (Syslog Collector)
CEF
<9>CEF:0|McAfee EPO|VirusScan Enterprise|8.8|1092|Solidcore<Test Send threat events to Syslog Server> alert|2|alertId=1092 alertName=Test Send threat events to Syslog Server alertType='File' class or access eventType=SolidcoreEvent host=LOGPOINT eventname=Anti-virus Standard Protection:Prevent remote creation of autorun files workflowid= eventTimestamp=06/03/13 08:38:36 UTC eventObject=H:\PROJECTS\ISFDY\BD DEFENSE\SALES\PROPOSALS\COUNTRY\EDGYPT\EGYPT FAC-M\OBSOLETE\RWM - MASS(TM) (D)\AUTORUN.INF eventProgramName= eventProgramUser=SYSTEM
Expected Log Format Sample (1)
McAfee EPO (Syslog Collector)
CEF
<9>CEF:0|McAfee EPO|VirusScan Enterprise|8.8|1092|Solidcore<Test Send threat events to Syslog Server> alert|2|alertId=1092 alertName=Test Send threat events to Syslog Server alertType='File' class or access eventType=SolidcoreEvent host=LOGPOINT eventname=Anti-virus Standard Protection:Prevent remote creation of autorun files workflowid= eventTimestamp=06/03/13 08:38:36 UTC eventObject=H:\PROJECTS\ISFDY\BD DEFENSE\SALES\PROPOSALS\COUNTRY\EDGYPT\EGYPT FAC-M\OBSOLETE\RWM - MASS(TM) (D)\AUTORUN.INF eventProgramName= eventProgramUser=SYSTEM
Expected Log Format Sample (2)
McAfee EPO (ODBC Fetcher)
Semicolon-separated
"36172608";"2014-10-21 06:55:39.963000";"none";"none";"1119";"ops.update.end";"4";"2014-10-21 06:00:24";"None";"AutoUpdate";"none";"True";"SYSTEM";"jria";"DCCAT";"DC014134"; "DC014134";
"DC014134.DCCAT.DK" ;"10.11.0.82";"";"001f1639e203";"Windows 8.1";"Service Pack 1";"6.1";"7601";"Rom, normaltid";"None";"10.11.0.68";"None";"None";"None";"None";"1";"VirusScan Enterprise";"8.8";"5600.1067";"5600.1067";"7597.0000";"N/A";"5600.1067";
"2";"8.8.0.975.Wrk";"";
Expected Log Format Sample (3)
McAfee EPO
XML
<29>May 12 01:11:44 XXXXX EPOEvents <?xml version="1.0" encoding="UTF-8"?><SCORData><MachineInfo><MachineName>ABC1234</MachineName><AgentGUID>{64c1dd34-f3bc-11e8-00ee-2XXXXXXXXXXX}</AgentGUID><IPAddress>1.1.1.1</IPAddress><OSName>Windows 8 Workstation</OSName><UserName>SYSTEM</UserName><TimeZoneBias>-120</TimeZoneBias><RawMACAddress>242ffa151533</RawMACAddress></MachineInfo><SCORSoftware ProductName="XYZ" ProductVersion="8.0.0" ProductFamily="Secure"><SCOREvent><EventID>20719</EventID><Severity>1</Severity><GMTTime>2022-05-12T13:11:17</GMTTime><SCORevent_name>WRITE_DENIED</SCORevent_name><SCORevt_id>20</SCORevt_id><SCORevt_type>EVT_CAT_TYPE_MAJOR</SCORevt_type><SCORevt_sink>7</SCORevt_sink><SCORseq_no>401234</SCORseq_no><SCORtime_stamp>1589289077527</SCORtime_stamp><SCORserver_state>0</SCORserver_state><SCORuser_name>NT AUTHORITY\SYSTEM</SCORuser_name><SCORprocess_name>C:\windows\abc\abc.exe</SCORprocess_name><SCORprocess_id>2408</SCORprocess_id><SCORfile_name>C:\Windows\abc\ABC.dll</SCORfile_name><SCORprocess_sha1>3342761485c5aed17bc5dabd34219e4cbf836b9b</SCORprocess_sha1><SCORprocess_md5>edf009f55cd092
8009c5c05780616e3d</SCORprocess_md5><SCORprocess_sha256>9bfa82f4c09461c3452b4edc5fd5de32e37d135ff4db3f6762b
706928ae1ed50</SCORprocess_sha256></SCOREvent></SCORSoftware></SCORData>#015
Support
If you have any questions or require assistance, create a support ticket.
Comments
Article is closed for comments.
Please confirm is the instruction in the post is correct:
"Download the Trend Micro DB package from the customer site"
Since EPO uses does it not require MS SQL fetcher?
Please update this page to include a zip as seen here https://servicedesk.logpoint.com/hc/en-us/articles/115003783925