Catch All : Level 3 2

Classification

Rule Name

Rule Type

Common Event

Classification

Catch All : Level 3

Base Rule

General Operations

Other Operations

Return Status Success

Sub Rule

Return Status Success

Other Audit Success

Session Closed For User

Sub Rule

Session Closed For User

Other Audit Success

Return Status Ignore

Sub Rule

Return Status Ignore

Information

Error On Subcontainer

Sub Rule

Error On Subcontainer

Error

Connection Closed

Sub Rule

Connection Closed

Network Traffic

Crond Executed Command

Sub Rule

Command Executed

Access Success

Change Directory Failure

Sub Rule

Access Object Failure

Access Failure

Change Directory Failure : No Such File Or Dir

Sub Rule

Access Object Failure

Access Failure

Command Line Interface Logout

Sub Rule

User Logoff

Authentication Success

Command Line Interface Login

Sub Rule

User Logon

Authentication Success

Crond Executed Command As Root

Sub Rule

Crond Executed Command As Root

Information

User Session

Sub Rule

Session Started For User

Other Audit Success

Access Policy

Sub Rule

General Policy

Other Audit

Session Information

Sub Rule

Session Information

Information

No User Found

Sub Rule

SQL Transaction

Other Audit

Disk Alert

Sub Rule

General Disk Error

Error

RADIUS Auth Successful

Sub Rule

Authentication Activity

Authentication Success

Authentication Failed

Sub Rule

User Logon Failure

Authentication Failure

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

N/A

<vmid>

Number

N/A

<severity>

Text/String

N/A

<sip>

IP Address

N/A

<sport>

Number

N/A

<login>

Text/String

N/A

<account>

Text/String

N/A

<domainorigin>

Text/String

N/A

<processid>

Number

N/A

<process>

Text/String

N/A

<object>

Text/String

N/A

<subject>

Text/String

N/A

<url>

Text/String

N/A

<amount>

Number

N/A

<result>

Text/String

N/A

<tag2>

Text/String

N/A

<tag3>

Text/String

N/A

<tag4>

Text/String

N/A

<tag5>

Text/String