Skip to main content
Skip table of contents

Catch All : Level 2 5

Log Fields and Parsing

This section details the log fields available in this log message type, along with values parsed for both LogRhythm Default and LogRhythm Default v2.0 policies. A value of "N/A" (not applicable) means that there is no value parsed for a specified log field.

Log Field

LogRhythm DefaultLogRhythm Default v2.0
Provider<process>N/A
EventID Qualifiers<vmid>N/A
VersionN/AN/A
Level<severity>N/A
TaskN/AN/A
OpcodeN/AN/A
KeywordsN/AN/A
TimeCreatedN/AN/A
EventRecordIDN/AN/A
CorrelationN/AN/A
Execution ProcessID<processid>N/A
ThreadID<session>N/A
ChannelN/AN/A
Computer<dname>N/A
Security<domain>
<login>
N/A
Taskname<command>N/A

Log Processing Settings

This section details log processing changes made from the LogRhythm Default policy to LogRhythm Default v2.0. In some cases, base rules are broken down into sub-rules to appropriately parse log message types by their event types.

LogRhythm Default

Regex IDRule NameRule TypeCommon EventClassification
1008164Catch All : Level 2Base RuleGeneral InformationInformation
General Warning MessageSub RuleGeneral WarningWarning
General Critical MessageSub RuleGeneral CriticalCritical
General Error MessageSub RuleGeneral ErrorError
General Informational MessageSub RuleGeneral InformationInformation
EVID: 104 ID MESSAGESSub RuleLog ClearedAccess Success

LogRhythm Default v2.0

N/A

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.