Menlo Security

Download 10
Last updated Aug 4, 2024

menlo-web-logs

Get web access logs from Menlo Security service.

menlo-web-logs [profile=PROFILE] [duration=NUM{mon|w|d|h|m|s}] [from=yyyyMMddHHmmss] [to=yyyyMMddHHmmss]
profile=PROFILE
Menlo Security connect profile code
duration=NUM{mon|w|d|h|m|s}
Scan only recent data. You should use s(second), m(minute), h(hour), d(day), mon(month) time unit. For example, 10s means data from 10 seconds earlier.
from=yyyyMMddHHmmss
Start time of range. yyyyMMddHHmmss format. If you omit time part, it will be padded by zero.
to=yyyyMMddHHmmss
End time of range. yyyyMMddHHmmss format. If you omit time part, it will be padded by zero.

Output Fields

FieldTypeNameDescription
_timeDateTime
riskStringRiske.g. LOW, MEDIUM, HIGH
risk_tallyIntegerRisk counte.g. -1
userStringUserEmail format
req_typeStringRequest typee.g. page_request, file_download
site_categoryStringSite categorye.g. Malware Sites, Phishing and Other Frauds
domainStringDomain
src_ipIP addressSource IP
dst_ipIP addressDestination IP
dst_addrsStringDestination addressesComma separated values.
egress_ipIP addressEgress IPMenlo Security gateway address.
categoryStringCategorye.g. Malware, Phishing
signatureStringSignaturee.g. cats_Malware, cats_Phishing & Fraud
actionStringActione.g. allow, isolate
reasonStringReasone.g. file_download_LinuxEXE_isolated_site
statusIntegerStatuse.g. 200, 404
methodStringMethode.g. GET
urlStringURL
top_urlStringTop URLURL of parent browser frame
appStringAppe.g. http, https
is_iframeBoolIs iframe
has_passwordBoolHas password
is_inconsistent_domainBoolIs inconsistent domain
num_subfilesIntegerFile count
file_sizeLongFile size
content_typeStringContent typee.g. text/html;charset=utf-8
browser_versionStringBrowser versione.g. Chrome_127
user_agent_typeStringUser agent typee.g. supported_browser
user_agentStringUser agent
refererStringReferer
full_session_idStringSession ID
vendorStringVendore.g. Menlo Security
productStringProducte.g. MSIP
versionStringVersione.g. 2.0
regionStringRegione.g. ap-northeast-1c
tab_idIntegerTab IDe.g. 1
pe_rule_nameStringRule namee.g. Phishing Threat
rendering_modeStringRendering modee.g. ACR1