Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 

McAfee MVISION Cloud (formerly known as Skyhigh Networks Cloud Security Platform)

 

The JSA DSM for McAfee MVISION Cloud collects logs from a McAfee MVISION Cloud Platform.

McAfee MVISION Cloud is formerly known as Skyhigh Networks Cloud Security Platform.

The following table identifies the specifications for the McAfee MVISION Cloud DSM:

Table 1: McAfee MVISION Cloud DSM Specifications

Specification

Value

Manufacturer

McAfee

DSM name

McAfee MVISION Cloud

RPM file name

DSM-SkyhighNetworksCloudSecurityPlatform-JSA_versionbuild_ number.noarch.rpm

Supported versions

2.4 and 3.3

Protocol

Syslog

Event format

LEEF

Recorded event types

Privilege Access, Insider Threat, Compromised Account, Access, Admin, Data, Policy, and Audit

Automatically discovered?

Yes

Includes identity?

No

Includes custom properties?

No

More information

McAfee MVision Cloud

To integrate McAfee MVISION Cloud with JSA, complete the following steps:

  1. If automatic updates are not enabled, download and install the most recent version of the following RPMs on your JSA Console:
    • Skyhigh Networks Cloud Security Platform DSM RPM

    • DSMCommon RPM

  2. Configure your McAfee MVISION Cloud device to send syslog events to JSA.
  3. If JSA does not automatically detect the log source, add a McAfee MVISION Cloud log source on the JSA Console. The following table describes the parameters that require specific values for McAfee MVISION Cloud event collection:

    Table 2: McAfee MVISION Cloud Log Source Parameters

    Parameter

    Value

    Log Source type

    McAfee MVISION Cloud

    Protocol Configuration

    Syslog

    Log Source Identifier

    The IP address or host name of the McAfee MVISION Cloud that sends events to JSA.

Configuring McAfee MVISION Cloud to Communicate with JSA

  1. Log in to the McAfee Enterprise Connector administration interface.
  2. Select Enterprise Integration > SIEM Integration.
  3. Configure the following SIEM SYSLOG SERVICE parameters:

    Parameter

    Value

    SIEM server

    ON

    Format

    Log Event Extended Format (LEEF)

    Syslog Protocol

    TCP

    Syslog Server

    <JSA IP or hostname>

    Syslog Port

    514

    Send to SIEM

    new anomalies only

  4. 4. Click Save.

McAfee MVISION Cloud Sample Event Messages

Use these sample event messages to verify a successful integration with JSA.

Note

Due to formatting issues, paste the message format into a text editor and then remove any carriage return or line feed characters.

McAfee MVISION Cloud Sample Message When You Use the Syslog Protocol

The following sample event message shows that a CAP incident occurred.

Table 3: JSA field names and highlighted values in the event payload

JSA field name

Highlighted values in the event payload

Event ID

Incident

Event Category

Alert.Policy.CloudAccess

Username

user@user.example.com

Device Time

Sep 18 2018 03:28:08.000 UTC (extracted from the date and time fields)