Classification
|
Rule Name |
Rule Type |
Common Event |
Classification |
|---|---|---|---|
|
Catch All : Level 3 |
Base Rule |
General Operations |
Other Operations |
|
Return Status Success |
Sub Rule |
Return Status Success |
Other Audit Success |
|
Session Closed For User |
Sub Rule |
Session Closed For User |
Other Audit Success |
|
Return Status Ignore |
Sub Rule |
Return Status Ignore |
Information |
|
Error On Subcontainer |
Sub Rule |
Error On Subcontainer |
Error |
|
Connection Closed |
Sub Rule |
Connection Closed |
Network Traffic |
|
Crond Executed Command |
Sub Rule |
Command Executed |
Access Success |
|
Change Directory Failure |
Sub Rule |
Access Object Failure |
Access Failure |
|
Change Directory Failure : No Such File Or Dir |
Sub Rule |
Access Object Failure |
Access Failure |
|
Command Line Interface Logout |
Sub Rule |
User Logoff |
Authentication Success |
|
Command Line Interface Login |
Sub Rule |
User Logon |
Authentication Success |
|
Crond Executed Command As Root |
Sub Rule |
Crond Executed Command As Root |
Information |
|
User Session |
Sub Rule |
Session Started For User |
Other Audit Success |
|
Access Policy |
Sub Rule |
General Policy |
Other Audit |
|
Session Information |
Sub Rule |
Session Information |
Information |
|
No User Found |
Sub Rule |
SQL Transaction |
Other Audit |
|
Disk Alert |
Sub Rule |
General Disk Error |
Error |
|
RADIUS Auth Successful |
Sub Rule |
Authentication Activity |
Authentication Success |
|
Authentication Failed |
Sub Rule |
User Logon Failure |
Authentication Failure |
Mapping with LogRhythm Schema
|
Device Key in Log Message |
LogRhythm Schema |
Data Type |
|---|---|---|
|
N/A |
<vmid> |
Number |
|
N/A |
<severity> |
Text/String |
|
N/A |
<sip> |
IP Address |
|
N/A |
<sport> |
Number |
|
N/A |
<login> |
Text/String |
|
N/A |
<account> |
Text/String |
|
N/A |
<domainorigin> |
Text/String |
|
N/A |
<processid> |
Number |
|
N/A |
<process> |
Text/String |
|
N/A |
<object> |
Text/String |
|
N/A |
<subject> |
Text/String |
|
N/A |
<url> |
Text/String |
|
N/A |
<amount> |
Number |
|
N/A |
<result> |
Text/String |
|
N/A |
<tag2> |
Text/String |
|
N/A |
<tag3> |
Text/String |
|
N/A |
<tag4> |
Text/String |
|
N/A |
<tag5> |
Text/String |