Vendor Documentation
Classification
|
Rule Name |
Rule Type |
Common Event |
Classification |
|---|---|---|---|
|
Catch All : Level 2 |
Base Rule |
General Information |
Information |
Mapping with LogRhythm Schema
|
Device Key in Log Message |
LogRhythm Schema |
Data Type |
Schema Description |
|
Version |
N/A |
N/A |
N/A |
|
Vendor |
N/A |
N/A |
N/A |
|
Device Product |
N/A |
N/A |
N/A |
|
Device Version |
<version> |
Number |
N/A |
|
Device Event Class_ID |
<vmid> |
Text/String |
The number representing the type of the event. If translation is used, the type enum name is defined by the ICD Schema. |
|
Name |
<vendorinfo> |
Text/String |
The description of the event. If the message attribute is missing and translation is used, the name is generated using the type_id and id enum names. |
|
Severity |
<severity> |
Number |
The severity of the event, mapped as follows:
|