Catch-All Events
Vendor Documentation
Classification
Rule Name | Rule Type | Classification | Common Event |
---|---|---|---|
Catch-All Events | Base Rule | Information | General Information Log Message |
System Maintenance Event | Sub Rule | Information | General Maintenance Information |
System Errors Event | Sub Rule | Error | General System Error |
Blocked Web Sites Event | Sub Rule | Failed Activity | Blocked Message |
Blocked Java Event | Sub Rule | Failed Activity | Blocked Message |
Dropped UDP Event | Sub Rule | Information | Message Dropped |
Dropped ICMP Event | Sub Rule | Information | Message Dropped |
Dropped LAN TCP Event | Sub Rule | Information | Message Dropped |
Dropped LAN UDP Event | Sub Rule | Information | Message Dropped |
Dropped LAN ICMP Event | Sub Rule | Information | Message Dropped |
Modem Debug Event | Sub Rule | Information | General Modem Information |
VPN Tunnel Status Event | Sub Rule | Information | VPN Session Information |
802.11 Management Event | Sub Rule | Information | 802.11b Management |
System Environment Event | Sub Rule | Information | Environmental Info Msg |
Expanded - VOIP Activity | Sub Rule | Information | General VOIP Message |
Expanded - WLAN IDS Activity | Sub Rule | Activity | IDS Event |
Expanded - SonicPoint Activity | Sub Rule | Information | SonicPoint Status |
Mapping with LogRhythm Schema
Device Key in Log Message | LogRhthm Schema | Data Type | Schema Description |
---|---|---|---|
id | N/A | N/A | N/A |
sn | <serialnumber> | Number | Indicates the device serial number |
time | N/A | N/A | Reports the time of event |
fw | N/A | N/A | Indicates the WAN IP Address |
pri | <severity> | Number | Displays the event priority level (0=emergency, 7=debug) |
c | <vmid> <tag1> | Number | Indicates the legacy category number (Note: SonicOS/X does not currently send new category information) |
gcat | N/A | N/A | Display event group category when using Enhanced Syslog |
m | N/A | N/A | Provides the message ID number |