01.01.2013 Views

Web Gateway 7.1.5 Product Guide - McAfee

Web Gateway 7.1.5 Product Guide - McAfee

Web Gateway 7.1.5 Product Guide - McAfee

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

8<br />

Monitoring<br />

Logging<br />

• List.OfString.ToString (Antimalware.VirusNames) — List with the names of the found viruses<br />

and other malware items<br />

The list is converted into a string.<br />

• URL — URL that was requested<br />

• FileSystemLogging.WriteLogEntry ... — Executes the write event.<br />

The entry that is to be written and the log file it is written into are specified with the event:<br />

• (User-Defined.logLine) — Event parameter specifying the entry<br />

This is a log file line with the parameter values that have been set by the other event of the rule.<br />

• — Event settings specifying the log file<br />

Note: Clicking the settings name on the user interface opens the settings for editing.<br />

You can modify this logging rule or create similar rules of your own. For more information, see Create a<br />

sample logging rule.<br />

Create a sample logging rule<br />

This section describes steps for creating a sample logging rule. The rule is taken from the Found Virus<br />

Log Rule Set, which is provided on the appliance by default.<br />

Note: The rule name is slighty modified to avoid a conflict with the existing rule.<br />

To create a sample logging rule:<br />

1 Go to Policy | Rule Sets.<br />

2 From the Rule Sets menu, select Log Handler and then the Found Viruses Log rule set.<br />

3 On the settings pane, click Add Rule. The Add Rule Window opens with the Name step selected. In<br />

the main window area, items appear for adding a name and other general settings.<br />

4 Add the following general settings:<br />

a Name — Type Write Found Malware Log.<br />

Note: The name of the already existing logging rule is Write Found Viruses Log.<br />

b Enable rule — Deselect this checkbox, so the sample rule gets not enabled.<br />

5 Select Rule Criteria. Items for adding the criteria appear.<br />

6 Click Add. The Add Criteria window opens.<br />

7 Add the criteria of the rule (Antimalware.Infected equals true):<br />

a From the Property list, select Antimalware.Infected.<br />

b In the Operator list, leave equals.<br />

c In the Parameter area, select true from the Value list.<br />

8 Click OK. The Add Criteria window closes and the added criteria appears in the main window area. It<br />

lets the rule write a log file entry if an object is actually found to be infected.<br />

9 Select Action and from the Action list, select Continue. This action lets the filtering process continue<br />

after the log file entry has been written.<br />

10 Select Events.<br />

11 Click Add and from the drop-down menue that appears select Set Property Value. The Add Set<br />

Property window opens.<br />

12 From the list under Set this property (string), select User-Defined.logLine.<br />

280 <strong>McAfee</strong> <strong>Web</strong> <strong>Gateway</strong> <strong>7.1.5</strong> <strong>Product</strong> <strong>Guide</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!