111009 : User Executed Command

Classification

Rule Name

Rule Type

Common Event

Classification

111009 : User Executed Command

Base Rule

Command Executed

Access Success

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

N/A

<vmid>

Number

N/A

<severity>

Number

N/A

<login>

Text/String

N/A

<command>

Text/String