Skip to main content
Skip table of contents

Application Control 1

Vendor Documentation

Classification

Rule NameRule TypeCommon EventClassification
Application ControlBase RuleGeneral Network TrafficNetwork Traffic
Application Control : Traffic AcceptedSub RuleTraffic Allowed by Network FirewallNetwork Allow
Application Control : Traffic DroppedSub RuleTraffic Denied by Network FirewallNetwork Deny
Application Control : Traffic BlockedSub RuleTraffic Denied by Network FirewallNetwork Deny
Application Control : Traffic AllowedSub RuleTraffic Allowed by Network FirewallNetwork Allow

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

Product<version>Number/Text
Origin<sender>Number/Text
Action<action>Number/Text
Action<tag1>Number/Text
SIP<sip>Number
SPort<sport>Number
DIP<dip>Number
DPort<dport>Number
Protocol<protname>Number
IFName<sinterface>Number/Text
IFDirection<tag2>Number/Text
Reason<reason>Number/Text
Info<vendorinfo>Number/Text
XlateSIP<snatip>Number/Text
XlateDIP<dnatip>Number/Text
URL<url>Number/Text
User<login>Number/Text
PolicyName<policy>Number/Text
appi_name<process>Number/Text
matched_category<subject>Text/String
app_risk<severity>Number
web_client_type<useragent>Number/Text
received_bytes<bytesin>Number
sent_bytes<bytesout>Number
src_machine_name<sname>Number/Text
src_user_name<login>Number/Text


JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.