Anomaly : Anomaly

Vendor Documentation

Classification

Rule Name

Rule Type

Classification

Common Event

Anomaly : Anomaly

Base Rule

Critical

General Traffic Other Alert

Anomaly Attack Anomaly Tcp Udp

Sub Rule

Attack

General Attack Activity

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

Schema Description

severity

<severity>

Text/String

N/A

logid

<vmid>

<tag1>

Number

N/A

severity

<severity>

Number/Text/String

N/A

srcip

<sip>

IP Address

IP Address

dstip

<dip>

IP Address

N/A

srcintf

<sinterface>

sinterface

N/A

dstintf

<dinterface>

dinterface

N/A

sessionid

<session>

Number/Text/String

N/A

action

<action>


Text/String

N/A

proto

<protnum>

Number

N/A

attack

<threatname>

Text/String

N/A

srcport

<sport>

Number

N/A

dstport

<dport>

Number

N/A

policytype

<policy>

Text/String

N/A

ref

<url>

Text/String

N/A

msg

<subject>

Text/String

N/A