Application Control 1

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

Application Control

Base Rule

General Network Traffic

Network Traffic

Application Control : Traffic Accepted

Sub Rule

Traffic Allowed by Network Firewall

Network Allow

Application Control : Traffic Dropped

Sub Rule

Traffic Denied by Network Firewall

Network Deny

Application Control : Traffic Blocked

Sub Rule

Traffic Denied by Network Firewall

Network Deny

Application Control : Traffic Allowed

Sub Rule

Traffic Allowed by Network Firewall

Network Allow

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

Product

<version>

Number/Text

Origin

<sender>

Number/Text

Action

<action>

Number/Text

Action

<tag1>

Number/Text

SIP

<sip>

Number

SPort

<sport>

Number

DIP

<dip>

Number

DPort

<dport>

Number

Protocol

<protname>

Number

IFName

<sinterface>

Number/Text

IFDirection

<tag2>

Number/Text

Reason

<reason>

Number/Text

Info

<vendorinfo>

Number/Text

XlateSIP

<snatip>

Number/Text

XlateDIP

<dnatip>

Number/Text

URL

<url>

Number/Text

User

<login>

Number/Text

PolicyName

<policy>

Number/Text

appi_name

<process>

Number/Text

matched_category

<subject>

Text/String

app_risk

<severity>

Number

web_client_type

<useragent>

Number/Text

received_bytes

<bytesin>

Number

sent_bytes

<bytesout>

Number

src_machine_name

<sname>

Number/Text

src_user_name

<login>

Number/Text