Skip to main content
Skip table of contents

Audit Events 1

Classification

Rule Name

Rule Type

Common Event

Classification

Audit Events 1Base RuleGeneral Auditing MessageOther Audit
Create Session Command FailedSub RuleCommand Execution FailureAccess Failure
Close Session FailedSub RuleClose Session FailedError
Authentication FailedSub RuleAuthentication Failure ActivityAuthentication Failure
User Account Summary FailedSub RuleGeneral Audit FailureError
Link To File FailedSub RuleLink To File FailedError
Directory Creation FailedSub RuleCreate Object FailureAccess Failure
Set Group ID FailedSub RuleModify Object FailureAccess Failure
File Ownership Change FailedSub RuleModify Object FailureAccess Failure
File Permissions Set FailedSub RuleModify Object FailureAccess Failure
Object Opened FailedSub RuleAccess Object FailureAccess Failure
System Call FailedSub RuleFailed System CallError
Login Attempt FailedSub RuleAuthentication Failure ActivityAuthentication Failure
Service Started FailedSub RuleService Start FailureError
Service Stop FailedSub RuleService Stop FailedError
Working Directory Change FailedSub RuleRead Object FailureAccess Failure
Credentials Set FailedSub RuleAuthentication Failure ActivityAuthentication Failure
Credentials Dispense FailedSub RuleFailed To Dispense CredentialsError
Credentials Acquire FailedSub RuleFailed To Acquire CredentialsError
Configuration Change FailedSub RuleModify Object FailureAccess Failure
Session Started For UserSub RuleUser LogonAuthentication Success
User LoginSub RuleUser LogonAuthentication Success
Session Closed For UserSub RuleSession Closed For UserOther Audit Success
AuthenticationSub RuleAuthentication ActivityAuthentication Success
User Account SummarySub RuleGeneral Auditing MessageOther Audit
Link To File CreatedSub RuleObject CreatedAccess Success
Directory CreatedSub RuleObject CreatedAccess Success
File Group ChangedSub RuleObject ModifiedAccess Success
File Owner ChangedSub RuleObject Attribute ModifiedAccess Success
File Permissions SetSub RulePolicy Enabled : ObjectPolicy
File OpenedSub RuleObject ReadAccess Success
System CallSub RuleSystem CallOther Audit Success
Object Path OpenedSub RuleObject ReadAccess Success
LoginSub RuleUser LogonAuthentication Success
Service StartedSub RuleProcess/Service StartedStartup and Shutdown
Service StoppedSub RuleProcess/Service StoppedStartup and Shutdown
Working Directory ChangedSub RuleCommand ExecutedAccess Success
Credentials SetSub RuleAuthentication ActivityAuthentication Success
Credentials DispensedSub RuleAuthentication ActivityAuthentication Success
Credentials AcquiredSub RuleAuthentication ActivityAuthentication Success
Configuration ChangeSub RuleConfiguration Modified : SystemConfiguration
User Login FailedSub RuleUser Logon FailureAuthentication Failure
Access Vector Cache MessageSub RuleObject ReadAccess Success
User CommandSub RuleCommand ExecutedAccess Success
User Command FailedSub RuleCommand Execution FailureAccess Failure
Abnormal Process TerminationSub RuleSuspicious ActivitySuspicious
Security Label SetSub RuleObject Attribute ModifiedAccess Success
Configuration ChangedSub RuleConfiguration Modified : SystemConfiguration
Policy LoadedSub RulePolicy Enabled : SystemPolicy
Mandatory Access Control StatusSub RuleSecurity StatusActivity
User Access Vector Cache MessageSub RuleGeneral Audit MessageOther Audit
Authentication CheckSub RuleAuthentication ActivityAuthentication Success
Authentication Check FailedSub RuleUser Logon FailureAuthentication Failure
User Role ChangeSub RuleRole Attribute ModifiedAccount Modified
User Role Change FailedSub RuleCommand Execution FailureAccess Failure
System Configuration ChangedSub RuleConfiguration Modified : SystemConfiguration
System Configuration Change FailedSub RuleModify Object FailureAccess Failure
File Descriptor PairSub RuleGeneral Auditing MessageOther Audit
Object Process IDSub RuleObject Process ID InformationOther Audit
End Of Event MessageSub RuleGeneral Information Log MessageInformation
Command ExecutedSub RuleCommand ExecutedAccess Success
User ErrorSub RuleUser ErrorError

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

N/A<severity>Number/Text
type<vmid>Number/Text
msg<process>Number
argc<amount>Number
a0<command>Number/Text
a1<vendorinfo>Text/String
a2<object>Text/String
a3<objectname>Text/String
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.