Skip to main content
Skip table of contents

Catch All : Level 1 2

Vendor Documentation

Classification

Rule NameRule TypeCommon EventClassification
Catch All : Level 1Base RuleGeneral Message InformationInformation

Mapping with LogRhythm Schema

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
TSN/AN/AN/A
SESSIDN/AN/ASession information
COMMAND<command>Text/StringCommand name
USERTYPE<objecttype>Text/StringType of user
USERKEYN/AN/AUser key informations hexadecimal value
WORKLOAD

<process>

<vendorinfo>

Text/StringAudit log record type
RESULTCODEN/AN/AResults
OBJECTN/AN/AObject name
USERN/AN/ASource user name
SIPN/AN/ASource IP address
OBJECTNAMEN/AN/AN/A
PARAMETERSN/AN/AN/A
MODIFIEDPROPERTIESN/AN/AN/A
EXTERNALACCESSN/AN/AN/A
ORIGINATINGSERVERN/AN/AN/A
ORGANIZATIONNAMEN/AN/AN/A
LOGONTYPEN/AN/AN/A
MAILBOXOWNERN/AN/AN/A
MAILBOXMASTERN/AN/AN/A
LOGONUSERSIDN/AN/AN/A
LOGONUSERDISPLAYNAMEN/AN/AN/A
USERAGENT<useragent>Text/StringN/A
CLIENTIPADDRESSN/AN/AN/A
CLIENTPROCESSNAMEN/AN/AN/A
CLIENTVERSIONN/AN/AN/A
FOLDERN/AN/AN/A
CROSSMAILBOXOPERATIONSN/AN/AN/A
DESTMAILBOXN/AN/AN/A
DESTMAILBOXOWNERN/AN/AN/A
DESTMAILBOXMASTERN/AN/AN/A
DESTFOLDERN/AN/AN/A
FOLDERSN/AN/AN/A
AFFECTEDITEMSN/AN/AN/A
ITEMN/AN/AN/A
SENDASUSERN/AN/AN/A
SENDONBEHALFOFUSERN/AN/AN/A

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.