Access Logs - No Sub Rules (Do Not Use)

Vendor Documentation

Classification

Rule Name

Rule Type

Classification

Common Event

Access Logs - No Sub Rules Do NOT use

Base Rule

Other Audit Success

General Access

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

N/A

<vmid>

Text/String/Number

N/A

<sip>

Ip Address

N/A

<dport>

Number

N/A

<process>

Text/String

N/A

<object>

Text/String

N/A

<bytesin>

Number

N/A

<bytesout>

Number

N/A

<tag1>

Text/String/Number

N/A

<tag2>

Text/String/Number