Skip to main content
Skip table of contents

Administrative Configuration Event

Vendor Documentation

Classification

Rule NameRule TypeClassificationCommon Event
Administrative Configuration EventBase RuleConfigurationConfiguration Modified : System
VPM Policy ChangedSub RulePolicyPolicy Modified : System
Syslog EnabledSub RuleConfigurationConfiguration Enabled : System
Event Log Threshold ChangedSub RuleConfigurationConfiguration Modified : Security
Local Realm CreatedSub RuleConfigurationConfiguration Loaded : System
Realm DeletedSub RuleConfigurationConfiguration Deleted : System
DNS Cache ClearedSub RuleAccess SuccessObject Modified
Access Logging EnabledSub RuleConfigurationConfiguration Modified : Security
CLI Session Timed OutSub RuleWarningSession Timed Out

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

N/A

<vmid>Text/String/Number
N/A<sip>Ip address 
N/A<login>Text/String/Number
N/A<tag1>Text/String/Number
N/A<domain>Text/String/Number
N/A<object>Text/String/Number
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.