Vendor Documentation
Classification
|
Rule Name |
Rule Type |
Common Event |
Classification |
|---|---|---|---|
|
Catch All : Level 2 |
Base Rule |
General Information |
Information |
Mapping with LogRhythm Schema
|
Device Key in Log Message |
LogRhythm Schema |
Data Type |
Schema Description |
|
Header (logVer) |
N/A |
N/A |
CEF format version. |
|
Header (vendor) |
N/A |
N/A |
Appliance vendor. |
|
Header (pname) |
N/A |
N/A |
Appliance product. |
|
Header (pver |
<version> |
Text/String |
Appliance version. |
|
Header (eventid) |
<vmid> |
Number |
Signature ID. |
|
Header (eventName) |
<vendorinfo> |
Text/String |
Description. |
|
Header (severity) |
<severity> |
Number |
Severity
|