Catch All : Level 3 2
Classification
Rule Name | Rule Type | Common Event | Classification |
|---|---|---|---|
| Catch All : Level 3 | Base Rule | General Operations | Other Operations |
| Return Status Success | Sub Rule | Return Status Success | Other Audit Success |
| Session Closed For User | Sub Rule | Session Closed For User | Other Audit Success |
| Return Status Ignore | Sub Rule | Return Status Ignore | Information |
| Error On Subcontainer | Sub Rule | Error On Subcontainer | Error |
| Connection Closed | Sub Rule | Connection Closed | Network Traffic |
| Crond Executed Command | Sub Rule | Command Executed | Access Success |
| Change Directory Failure | Sub Rule | Access Object Failure | Access Failure |
| Change Directory Failure : No Such File Or Dir | Sub Rule | Access Object Failure | Access Failure |
| Command Line Interface Logout | Sub Rule | User Logoff | Authentication Success |
| Command Line Interface Login | Sub Rule | User Logon | Authentication Success |
| Crond Executed Command As Root | Sub Rule | Crond Executed Command As Root | Information |
| User Session | Sub Rule | Session Started For User | Other Audit Success |
| Access Policy | Sub Rule | General Policy | Other Audit |
| Session Information | Sub Rule | Session Information | Information |
| No User Found | Sub Rule | SQL Transaction | Other Audit |
| Disk Alert | Sub Rule | General Disk Error | Error |
| RADIUS Auth Successful | Sub Rule | Authentication Activity | Authentication Success |
| Authentication Failed | Sub Rule | User Logon Failure | Authentication Failure |
Mapping with LogRhythm Schema
Device Key in Log Message | LogRhythm Schema | Data Type |
|---|---|---|
| N/A | <vmid> | Number |
| N/A | <severity> | Text/String |
| N/A | <sip> | IP Address |
| N/A | <sport> | Number |
| N/A | <login> | Text/String |
| N/A | <account> | Text/String |
| N/A | <domainorigin> | Text/String |
| N/A | <processid> | Number |
| N/A | <process> | Text/String |
| N/A | <object> | Text/String |
| N/A | <subject> | Text/String |
| N/A | <url> | Text/String |
| N/A | <amount> | Number |
| N/A | <result> | Text/String |
| N/A | <tag2> | Text/String |
| N/A | <tag3> | Text/String |
| N/A | <tag4> | Text/String |
| N/A | <tag5> | Text/String |