Build/Teardown Outbound TCP/UDP Connections

Classification

Rule Name

Rule Type

Common Event

Classification

Build/Teardown Outbound TCP/UDP Connections

Base Rule

General DNS Information

Information

ASA-6-302016 : Teardown UDP Connection

Sub Rule

Connection Teardown

Network Traffic

ASA-6-302015 : Built Outbound UDP Connection

Sub Rule

Built UDP Connection

Network Traffic

ASA-6-302014 : Teardown Outbound TCP Connection

Sub Rule

Connection Teardown

Network Traffic

ASA-6-302013 : Built Outbound TCP Connection

Sub Rule

Connection Built

Network Traffic

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

N/A

<vmid>

Number

N/A

<severity>

Number

N/A

<sip>

IP Address

N/A

<dip>

IP Address

N/A

<sport>

Number

N/A

<dport>

Number

N/A

<snatip>

IP Address

N/A

<dnatip>

IP Address

N/A

<snatport>

Number

N/A

<dnatport>

Number

N/A

<sinterface>

Text/String

N/A

<dinterface>

Text/String

N/A

<protname>

Text/String

N/A

<Session>

Number

N/A

<bytesout>

Number

N/A

<duration>

Number

N/A

<size>

Number