Skip to main content
Skip table of contents

Anomaly : Anomaly

Vendor Documentation

Classification

Rule Name

Rule Type

Classification

Common Event

Anomaly : AnomalyBase RuleCriticalGeneral Traffic Other Alert
Anomaly Attack Anomaly Tcp UdpSub RuleAttackGeneral Attack Activity

Mapping with LogRhythm Schema  

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
severity<severity>Text/StringN/A
logid

<vmid>

<tag1>

NumberN/A
severity<severity>Number/Text/StringN/A
srcip<sip>IP AddressIP Address
dstip<dip>IP AddressN/A
srcintf<sinterface>sinterface
N/A
dstintf<dinterface>dinterfaceN/A
sessionid<session>Number/Text/StringN/A
action

<action>


Text/StringN/A
proto

<protnum>

NumberN/A
attack<threatname>Text/StringN/A
srcport<sport>NumberN/A
dstport<dport>NumberN/A
policytype<policy>Text/StringN/A
ref<url>Text/StringN/A
msg<subject>Text/StringN/A
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.