Vendor Documentation
Classification
|
Rule Name |
Rule Type |
Classification |
Common Event |
|---|---|---|---|
|
Catch-All Events |
Base Rule |
Information |
General Information Log Message |
|
System Maintenance Event |
Sub Rule |
Information |
General Maintenance Information |
|
System Errors Event |
Sub Rule |
Error |
General System Error |
|
Blocked Web Sites Event |
Sub Rule |
Failed Activity |
Blocked Message |
|
Blocked Java Event |
Sub Rule |
Failed Activity |
Blocked Message |
|
Dropped UDP Event |
Sub Rule |
Information |
Message Dropped |
|
Dropped ICMP Event |
Sub Rule |
Information |
Message Dropped |
|
Dropped LAN TCP Event |
Sub Rule |
Information |
Message Dropped |
|
Dropped LAN UDP Event |
Sub Rule |
Information |
Message Dropped |
|
Dropped LAN ICMP Event |
Sub Rule |
Information |
Message Dropped |
|
Modem Debug Event |
Sub Rule |
Information |
General Modem Information |
|
VPN Tunnel Status Event |
Sub Rule |
Information |
VPN Session Information |
|
802.11 Management Event |
Sub Rule |
Information |
802.11b Management |
|
System Environment Event |
Sub Rule |
Information |
Environmental Info Msg |
|
Expanded - VOIP Activity |
Sub Rule |
Information |
General VOIP Message |
|
Expanded - WLAN IDS Activity |
Sub Rule |
Activity |
IDS Event |
|
Expanded - SonicPoint Activity |
Sub Rule |
Information |
SonicPoint Status |
Mapping with LogRhythm Schema
|
Device Key in Log Message |
LogRhthm Schema |
Data Type |
Schema Description |
|---|---|---|---|
|
id |
N/A |
N/A |
N/A |
|
sn |
<serialnumber> |
Number |
Indicates the device serial number |
|
time |
N/A |
N/A |
Reports the time of event |
|
fw |
N/A |
N/A |
Indicates the WAN IP Address |
|
pri |
<severity> |
Number |
Displays the event priority level (0=emergency, 7=debug) |
|
c |
<vmid>
|
Number |
Indicates the legacy category number (Note: SonicOS/X does not currently send new category information) |
|
gcat |
N/A |
N/A |
Display event group category when using Enhanced Syslog |
|
m |
N/A |
N/A |
Provides the message ID number |