Auditd Status Messages

Classification

Rule Name

Rule Type

Common Event

Classification

Auditd Status Messages

Base Rule

General Audit Message

Other Audit

Auditd Initialization Complete

Sub Rule

Object Initialized

Access Success

Auditd Started Dispatcher

Sub Rule

Process/Service Started

Startup and Shutdown

Auditd Exiting

Sub Rule

Process/Service Stopping

Startup and Shutdown


Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

N/A

<severity>

Text\String

N/A

<dname>

Text\String

N/A

<process>

Text\String

N/A

<processid>

Number

N/A

<object>

Text\String

N/A

<command>

Text\String

N/A

<subject>

Text\String

N/A

<tag1>

Text\String