Skip to main content
Skip table of contents

Audit Events 2

Classification

Rule Name

Rule Type

Classification

Common event

Audit Events 2Base RuleGeneral Auditing MessageOther Audit
System Configuration Change FailedSub RuleModify Object FailureAccess Failure
System Configuration ChangedSub RuleConfiguration Modified : SystemConfiguration
User Role Change FailedSub RuleCommand Execution FailureAccess Failure
User Role ChangeSub RuleRole Attribute ModifiedAccount Modified
Authentication Check FailedSub RuleUser Logon FailureAuthentication Failure
Authentication CheckSub RuleAuthentication ActivityAuthentication Success
User Access Vector Cache MessageSub RuleGeneral Audit MessageOther Audit
Mandatory Access Control StatusSub RuleSecurity StatusActivity
Policy LoadedSub RulePolicy Enabled : SystemPolicy
Configuration ChangedSub RuleConfiguration Modified : SystemConfiguration
Security Label SetSub RuleObject Attribute ModifiedAccess Success
Abnormal Process TerminationSub RuleSuspicious ActivitySuspicious
User Command FailedSub RuleCommand Execution FailureAccess Failure
User CommandSub RuleCommand ExecutedAccess Success
Access Vector Cache MessageSub RuleObject ReadAccess Success
User Login FailedSub RuleUser Logon FailureAuthentication Failure
Configuration ChangeSub RuleConfiguration Modified : SystemConfiguration
Credentials AcquiredSub RuleAuthentication ActivityAuthentication Success
Credentials DispensedSub RuleAuthentication ActivityAuthentication Success
Credentials SetSub RuleAuthentication ActivityAuthentication Success
Working Directory ChangedSub RuleCommand ExecutedAccess Success
Service StoppedSub RuleProcess/Service StoppedStartup and Shutdown
Service StartedSub RuleProcess/Service StartedStartup and Shutdown
LoginSub RuleUser LogonAuthentication Success
Object Path OpenedSub RuleObject ReadAccess Success
System CallSub RuleSystem CallOther Audit Success
File OpenedSub RuleObject ReadAccess Success
File Permissions SetSub RulePolicy Enabled : ObjectPolicy
File Owner ChangedSub RuleObject Attribute ModifiedAccess Success
File Group ChangedSub RuleObject ModifiedAccess Success
Directory CreatedSub RuleObject CreatedAccess Success
Link To File CreatedSub RuleObject CreatedAccess Success
User Account SummarySub RuleGeneral Auditing MessageOther Audit
AuthenticationSub RuleAuthentication ActivityAuthentication Success
Session Closed For UserSub RuleSession Closed For UserOther Audit Success
User LoginSub RuleUser LogonAuthentication Success
Session Started For UserSub RuleUser LogonAuthentication Success
Configuration Change FailedSub RuleModify Object FailureAccess Failure
Credentials Acquire FailedSub RuleFailed To Acquire CredentialsError
Credentials Dispense FailedSub RuleFailed To Dispense CredentialsError
Credentials Set FailedSub RuleAuthentication Failure ActivityAuthentication Failure
Working Directory Change FailedSub RuleRead Object FailureAccess Failure
Service Stop FailedSub RuleService Stop FailedError
Service Started FailedSub RuleService Start FailureError
Login Attempt FailedSub RuleAuthentication Failure ActivityAuthentication Failure
System Call FailedSub RuleFailed System CallError
Object Opened FailedSub RuleAccess Object FailureAccess Failure
File Permissions Set FailedSub RuleModify Object FailureAccess Failure
File Ownership Change FailedSub RuleModify Object FailureAccess Failure
Set Group ID FailedSub RuleModify Object FailureAccess Failure
Directory Creation FailedSub RuleCreate Object FailureAccess Failure
Link To File FailedSub RuleLink To File FailedError
User Account Summary FailedSub RuleGeneral Audit FailureError
Authentication FailedSub RuleAuthentication Failure ActivityAuthentication Failure
Close Session FailedSub RuleClose Session FailedError
Create Session Command FailedSub RuleCommand Execution FailureAccess Failure
User ErrorSub RuleUser ErrorError
Command ExecutedSub RuleCommand ExecutedAccess Success
End Of Event MessageSub RuleGeneral Information Log MessageInformation
Object Process IDSub RuleObject Process ID InformationOther Audit
File Descriptor PairSub RuleGeneral Auditing MessageOther Audit
User LogoutSub RuleUser LogoffAuthentication Success

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

type<vmid>Text/String
msg<subject>Number/String
auid<account>Number
pid<process>Number
cwd<object>Text/String
syscall<tag3>Text/String
success<tag2>Text/String
ogid<group>Text/String
hostname<sname>Number
addr<sip>Number
terminal<session>Text/String
op<tag1>Text/String
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.