Classification
|
Rule Name |
Rule Type |
Common Event |
Classification |
|---|---|---|---|
|
Catch All : ESENT Messages |
Base Rule |
Database Information |
Information |
|
VMID 102 : Database Engine Starting New Instance |
Sub Rule |
General ESENT Information |
Information |
|
VMID 103 : Database Engine Stopped An Instance |
Sub Rule |
General ESENT Information |
Information |
|
VMID 104 : Application Log Cleared |
Sub Rule |
Log Cleared |
Access Success |
|
VMID 105 : Database Engine Started New Instance |
Sub Rule |
General ESENT Information |
Information |
|
VMID 326 : Database Engine Attached A Database |
Sub Rule |
General ESENT Information |
Information |
|
VMID 327 : Database Engine Attached A Database |
Sub Rule |
General ESENT Information |
Information |
|
VMID 412 : DNS Bound High Number of IPs |
Sub Rule |
General DNS Error |
Error |
|
VMID 413 : Cannot Create New Log File |
Sub Rule |
Failed Audit Log Write |
Other Audit Failure |
|
VMID 428 : Failed To Update Database |
Sub Rule |
Update Failed |
Error |
|
VMID 454 : Multiple Mac Addresses Detected |
Sub Rule |
MAC Address Addition Failed |
Error |
|
VMID 455 : Failed To Open File |
Sub Rule |
Failed To Open File |
Error |
|
VMID 471 : Unable To Execute Rollback Operation |
Sub Rule |
Failed Rollback Command |
Error |
|
VMID 482 : Failed To Write Into File |
Sub Rule |
File Write Failure |
Error |
|
VMID 486 : File Move Failure |
Sub Rule |
Move Object Failure |
Access Failure |
|
VMID 492 : Logging Stopped |
Sub Rule |
Failed Audit Log Write |
Other Audit Failure |
|
VMID 507 : Abnormally Long Access Time - HW Error |
Sub Rule |
Hardware Problem |
Warning |
|
VMID 508 : Abnormally Long Access Time - HW Error |
Sub Rule |
Hardware Problem |
Warning |
Mapping with LogRhythm Schema
|
Device Key in log message |
LogRhythm Schema |
Data Type |
|---|---|---|
|
Provider Name |
<vendorinfo> |
Text/String |
|
EventID Qualifiers |
<vmid> |
Number |
|
Level |
<severity> |
Text/String |
|
N/A |
<process> |
Text/String |
|
Computer |
<dname> |
Text/String |
|
N/A |
<processid> |
Number/Text/String |