Syslog - Generic Linux OS: Auditd Messages

Vendor Documentation

N/A

Classification

Rule Name

Rule Type

Common Event

Classification

Auditd Messages

Base Rule

General Information

Information

Auditd Emergency Message

Sub Rule

General Emergency Log Message

Critical

Auditd Alert Message

Sub Rule

General Alert

Critical

Auditd Critical Message

Sub Rule

General Critical

Critical

Auditd Error Message

Sub Rule

General Error

Error

Auditd Warning Message

Sub Rule

General Warning

Warning

Auditd Notice Message

Sub Rule

General Notice

Information

Auditd Information Message

Sub Rule

General Information

Information

Auditd Debug Message

Sub Rule

General Debug Message

Information

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

Schema Description

N/A

<severity>

Text/String

N/A

N/A

<tag1>

Text/String

N/A

N/A

<dip>

IP Address

N/A

N/A

<dname>

Text/String

N/A

N/A

<process>

Text/String

N/A

N/A

<processid>

Number

N/A

N/A

<subject>

Text/String

N/A