Catch-All Events

Vendor Documentation

Classification

Rule Name

Rule Type

Classification

Common Event

Catch-All Events

Base Rule

Information

General Information Log Message

System Maintenance Event

Sub Rule

Information

General Maintenance Information

System Errors Event

Sub Rule

Error

General System Error

Blocked Web Sites Event

Sub Rule

Failed Activity

Blocked Message

Blocked Java Event

Sub Rule

Failed Activity

Blocked Message

Dropped UDP Event

Sub Rule

Information

Message Dropped

Dropped ICMP Event

Sub Rule

Information

Message Dropped

Dropped LAN TCP Event

Sub Rule

Information

Message Dropped

Dropped LAN UDP Event

Sub Rule

Information

Message Dropped

Dropped LAN ICMP Event

Sub Rule

Information

Message Dropped

Modem Debug Event

Sub Rule

Information

General Modem Information

VPN Tunnel Status Event

Sub Rule

Information

VPN Session Information

802.11 Management Event

Sub Rule

Information

802.11b Management

System Environment Event

Sub Rule

Information

Environmental Info Msg

Expanded - VOIP Activity

Sub Rule

Information

General VOIP Message

Expanded - WLAN IDS Activity

Sub Rule

Activity

IDS Event

Expanded - SonicPoint Activity

Sub Rule

Information

SonicPoint Status

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhthm Schema

Data Type

Schema Description

id

N/A

N/A

N/A

sn

<serialnumber>

Number

Indicates the device serial number

time

N/A

N/A

Reports the time of event

fw

N/A

N/A

Indicates the WAN IP Address

pri

<severity>

Number

Displays the event priority level (0=emergency, 7=debug)

c

<vmid>
<tag1>

Number

Indicates the legacy category number (Note: SonicOS/X does not currently send new category information)

gcat

N/A

N/A

Display event group category when using Enhanced Syslog

m

N/A

N/A

Provides the message ID number