Skip to main content
Skip table of contents

Behavior Monitoring Log Messages

Vendor Documentation

Log Fields and Parsing

This section details the log fields available in this log message type, along with values parsed for both LogRhythm Default and LogRhythm Default v2.0 policies. A value of "N/A" (not applicable) means that there is no value parsed for a specified log field.

Log FieldLogRhythm DefaultLogRhythm Default v2.0
N/A<severity>N/A
Header (pver)<version>N/A
Header (eventid)<vendorinfo>
<tag1>
N/A
Header (eventName)<action><vmid>
Header (severity)<severity><severity>
dvcHost<dname>N/A
cs2Label<policy>N/A
cs2N/A<policy>
sproc<parentprocesspath><process>
cs1<process><object>
act<result><action>
<tag1>
shost<sname><dname>
src<sip><dip>
N/AN/A<reason>

Log Processing Settings

This section details log processing changes made from the LogRhythm Default policy to LogRhythm Default v2.0. In some cases, base rules are broken down into sub rules to appropriately parse log message types by their event types.

LogRhythm Default

Rule IDRule NameRule TypeClassification Common Event
1010818Behavior Monitoring Log MessagesBase RuleInformationGeneral Behavior Information
BM : 1000 - Threat Behavior AnalysisSub RuleInformationGeneral Behavior Information

LogRhythm Default v2.0

Rule IDRule NameRule TypeClassificationCommon Event
1012134V 2.0 : Behavior Monitoring EventBase RuleActivityGeneral Threat Message
V 2.0 : Behavior Monitoring : AllowSub RuleActivityGeneral Threat Message
V 2.0 : Behavior Monitoring : AskSub RuleFailed ActivityGeneral Security
V 2.0 : Behavior Monitoring : DenySub RuleFailed ActivityThreat Blocked
V 2.0 : Behavior  Monitoring : Terminate : 3Sub RuleFailed ActivityThreat Blocked
V 2.0 : Behavior Monitoring : Read OnlySub RuleActivityGeneral Threat Message
V 2.0 : Behavior Monitoring : Read/Write OnlySub RuleActivityGeneral Threat Message
V 2.0 : Behavior Monitoring : Read/Execute OnlySub RuleActivityGeneral Threat Message
V 2.0 : Behavior Monitoring : FeedbackSub RuleActivityGeneral Threat Message
V 2.0 : Behavior Monitoring : CleanSub RuleFailed ActivityThreat Deleted
V 2.0 : Behavior Monitoring : UnknownSub RuleActivityGeneral Threat Message
V 2.0 : Behavior Monitoring : AssessSub RuleActivityGeneral Threat Message
V 2.0 : Behavior Monitoring : Terminate : 1004Sub RuleFailed ActivityThreat Blocked
V 2.0 : Behavior Monitoring : Terminate : 1005Sub RuleFailed ActivityThreat Blocked
V 2.0 : Behavior Monitoring : Terminate : 1006Sub RuleFailed ActivityThreat Blocked
V 2.0 : Behavior Monitoring : Terminate : 1007Sub RuleFailed ActivityThreat Blocked
V 2.0 : Behavior Monitoring : Terminate : 1008Sub RuleFailed ActivityThreat Blocked
V 2.0 : Behavior Monitoring : Terminate : 1009Sub RuleFailed ActivityThreat Blocked
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.