Skip to main content
Skip table of contents

Anti Malware

Vendor Documentation

Classification

Rule NameRule TypeCommon EventClassification
Anti MalwareBase RuleGeneral Threat Protection EventActivity
Anti-Malware : Traffic RejectedSub RuleThreat BlockedFailed Activity
Anti-Malware : Control TrafficSub RuleGeneral Threat MessageActivity
Anti-Malware : Traffic DroppedSub RuleThreat BlockedFailed Activity
Anti-Malware : Traffic AllowedSub RuleTraffic Allowed by Network FirewallNetwork Allow
Anti-Malware : Traffic BlockedSub RuleThreat BlockedFailed Activity
Anti-Malware : Activity DetectedSub RulePossible Malware ActivityMalware

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

Product<version>Number/Text
Origin<sender>Number/Text
Action<action>Number/Text
Action<tag1>Number/Text
SIP<sip>Number/Text
SPort<sport>Number
DIP<dip>Number
DPort<dport>Number
src_machine_name<sname>Number/Text
protocol<protname>Number/Text
ifname<sinterface>Number/Text
ifdirection<tag2>Number/Text
User<login>Number/Text
src_user_name<login>Number/Text
Url<url>Number/Text
web_client_type<useragent>Number/Text
sent_bytes<bytesout>Number
received_bytes<bytesin>Number
session_id<session>Number/Text
malware_family<objecttype>Number/Text
Confidence_Level<amount>Number
severity<severity>Number
malware_action<vendorinfo>Number/Text
rule_name<command>Number/Text
Protection_Name<threatname>Number/Text
Protection_Name<object>Number/Text
status<status>Number/Text
Dst_DNS_Host<dname>Number/Text
description<subject>Number/Text
Reason<reason>Number/Text
Attack<threatname>Number/Text
Virus_Name<threatname>Number/Text
short_desc<vmid>Number/Text


JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.