Vendor Documentation
Classification
|
Rule Name |
Rule Type |
Common Event |
Classification |
|
AviatrixUser Log Messages |
Base Rule |
General Information |
Information |
Mapping with LogRhythm Schema
|
Device Key in Log Message |
LogRhythm Schema |
Data Type |
Schema Description |
|
Header |
<severity> |
Text/String |
N/A |
|
N/A |
N/A |
N/A |
N/A |
|
N/A |
N/A |
N/A |
N/A |
|
N/A |
N/A |
N/A |
N/A |
|
[Timestamp] |
|
N/A |
N/A |
|
GW-[Name of Gateway]-[Public IP of Gateway] |
<objectname>
|
Text/String/Ip Address |
N/A |
|
[Name of Application generating log] |
<process> |
Text/String |
N/A |
|
[Application Process ID] |
<parentprocessid> |
Number/Text/String |
N/A |
|
[Log message] |
<subject>
|
Text/String/Ip Address |
IN: Indicates incoming interface.
|