Build/Teardown ICMP Connections

Classification

Rule Name

Rule Type

Common Event

Classification

Build/Teardown ICMP Connections

Base Rule

General Firewall Log

Network Traffic

ASA-6-302020 : Built ICMP Connection

Sub Rule

Connection Built

Network Traffic

ASA-6-302021 : Teardown ICMP Connection

Sub Rule

Connection Teardown

Network Traffic

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

302020

<vmid>

Number

N/A

<severity>

Text/String

N/A

<sip>

Number

N/A

<sname>

Text/String

N/A

<dip>

Number

N/A

<dname>

Text/String

N/A

<sport>

Number

N/A

<dport>

Number

N/A

<sinterface>

Text/String

N/A

<protname>

Text/String

N/A

<domainorigin>

Text/String