01.01.2013 Views

Web Gateway 7.1.5 Product Guide - McAfee

Web Gateway 7.1.5 Product Guide - McAfee

Web Gateway 7.1.5 Product Guide - McAfee

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

8<br />

Monitoring<br />

Logging<br />

Found Viruses<br />

This nested logging rule set records names of viruses and other malware found in requested web<br />

objects.<br />

Nested logging rule set — Found Viruses Log<br />

Criteria — Always<br />

The rule set contains the following rule:<br />

Write found viruses.log<br />

Antimalware.Infected equals true –> Continue —<br />

Set User-Defined.logLine = DateTime.To<strong>Web</strong>ReporterString + “ ”” ...<br />

FileSystemLogging.WriteLogEntry (User-Defined.logLine)<br />

The rule uses an event to fill a log file entry with parameter values relating to web objects infected<br />

by viruses or other malware, such as virus names or IP addresses. It uses another event to write<br />

this entry to a log file.<br />

The log file entry is specified as a parameter in both events. The log that stores the log file is<br />

specified by the settings of the write event.<br />

Values for the following parameters are set and logged by the events of the rule (properties used<br />

by the set event in italics):<br />

• Date and time — DateTime.To<strong>Web</strong>ReporterString<br />

• User name — Authentication.UserName<br />

• Client IP address — String.ReplaceIfEquals (IP.ToString(Client.IP), “”, “-”)<br />

• Virus and malware names — List.OfString.ToString (Antimalware.VirusNames)<br />

• URL — URL<br />

The logging rule applies whenever a requested web object has been found to be infected. The two<br />

rule events for filling and writing a log entry are then executed.<br />

Processing continues with the next rule or rule set.<br />

296 <strong>McAfee</strong> <strong>Web</strong> <strong>Gateway</strong> <strong>7.1.5</strong> <strong>Product</strong> <strong>Guide</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!