Skip to main content
Skip table of contents

Catch All : Level 2 1

Vendor Documentation

Classification

Rule NameRule TypeClassificationCommon Event
Catch-All : Level 2Base RuleOperations : InformationGeneral Information

Mapping with LogRhythm Schema  

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
CEF:VersionN/AN/AIdentifies the version of the CEF format.
Device VendorN/AN/AIdentifies the vendor of the sending device.
Device ProductN/AN/AIdentifies the product of the sending device.
Device VersionN/AN/AIdentifies the version of the sending device.
Signature IDN/AN/AUnique event-type identifier.
NameN/AN/ADescription of the event.
Severity<severity>NumberReflects the importance of the event.
ExtensionN/AN/ACollection of key-value pairs.
contentN/AN/ADetailed description of the event.
asset_ipN/AN/A

Asset IP address for single asset events.

asset_hostnameN/AN/A

Asset hostname(s) for single asset events.

dst_asset_ipN/AN/A

Destination asset IP address for multiple asset events.

dst_asset_hostnameN/AN/A

Destination asset host names for directional events.

dst_asset_macN/AN/A

Destination asset MAC address for multiple asset events.

dst_asset_domainN/AN/A

Destination asset domain names for directional events.

src_asset_ipN/AN/A

Destination asset IP address for multiple asset events.

src_asset_hostnameN/AN/A

Destination asset host names for directional events.

src_asset_macN/AN/ADestination asset MAC address for multiple asset events.
src_asset_domainN/AN/ADestination asset domain names for directional events.
idN/AN/AUnique ID for the event.
asset_domainN/AN/AAsset domain names for single asset events.
asset_idN/A

N/A

Dragos system asset ID for single asset events.
asset_macN/AN/A

Asset MAC address for single asset events.

createdAtN/AN/A

Date and time when the event was created (not the same as the transmission time sent in syslog).

detection quad<objecttype>String

Name of the quad in the four types of detection quad used in the Dragos platform.

detectoridN/AN/A

Unique ID of the collector that originated the event.

dst_asset_idN/AN/A

Dragos system destination asset ID for multiple asset events.

matchedRuleIdN/AN/A

Dragos notification rule that triggered sending the alert over syslog.

occurredAtN/AN/A

Date and time the event occurred at based off the record(s) processed by the sensor.

originalSeverityN/AN/A

Original Dragos severity; some events become higher severity if they are repeated over time.

reviewedN/AN/ATrue if the event has been marked reviewed by a human.
src_asset_idN/AN/A

Dragos system destination asset ID for multiple asset events.

typeN/AN/A

Type of event; this field is free form so the values can be inconsistent at times.





JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.