Skip to main content
Skip table of contents

AD FS Messages

Classification

Rule NameRule TypeCommon EventClassification
AD FS MessagesBase RuleGeneral Active Directory InformationInformation
EVID 516 : Account Locked - Too Many AttemptsSub RuleUser Logon Failure : Account Locked OutAuthentication Failure
EVID 1200 : Federation Service Issued Valid TokenSub RuleToken ModifiedOther Audit Success
EVID 1201 : Federation Service Failed IssuingTokenSub RuleToken ErrorError
EVID 1202 : Federation Service ValidatedCredentialSub RuleAccounts ValidatedOther Audit Success
EVID 1203 : Federation Service Failed CredentialsSub RuleRequest Failed To ValidateWarning
EVID 1206 : Signout Request Successfully ProcessedSub RuleLogoffOther Audit Success
EVID 1210 : Extranet Lockout Event OccurredSub RuleAuthentication Failure ActivityAuthentication Failure
EVID 512 : Account Locked - Bad Password AttemptSub RuleUser Logon Failure : Bad PasswordAuthentication Failure
EVID 431 : Request ReceivedSub RuleRequest ReceivedOther Audit Success
EVID 515 : Suspicious Authentication ActivitySub RuleAuthentication ActivityAuthentication Success

Mapping with LogRhythm Schema  

Device Key in Log MessageLogRhythm SchemaData Type
N/A<vmid>Number
N/A<severity>Text/String
N/A<vendorinfo>Text/String
N/A<sip>Number
N/A<dip>Number
N/A<dname>Text/String
N/A<snatip>Number
N/A<dnatip>Number
N/A<login>Text/String
N/A<account>Text/String
N/A<domainorigin>Text/String
N/A<domainimpacted>Text/String
N/A<session>Text/String
N/A<object>Text/String
N/A<objecttype>Text/String
N/A<subject>Text/String
N/A<result>Text/String
N/A<reason>Text/String
N/A<size>Number
N/A<useragent>Text/String
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.