Catch All : Level 3 2
Classification
Rule Name | Rule Type | Common Event | Classification |
---|---|---|---|
Catch All : Level 3 | Base Rule | General Operations | Other Operations |
Return Status Success | Sub Rule | Return Status Success | Other Audit Success |
Session Closed For User | Sub Rule | Session Closed For User | Other Audit Success |
Return Status Ignore | Sub Rule | Return Status Ignore | Information |
Error On Subcontainer | Sub Rule | Error On Subcontainer | Error |
Connection Closed | Sub Rule | Connection Closed | Network Traffic |
Crond Executed Command | Sub Rule | Command Executed | Access Success |
Change Directory Failure | Sub Rule | Access Object Failure | Access Failure |
Change Directory Failure : No Such File Or Dir | Sub Rule | Access Object Failure | Access Failure |
Command Line Interface Logout | Sub Rule | User Logoff | Authentication Success |
Command Line Interface Login | Sub Rule | User Logon | Authentication Success |
Crond Executed Command As Root | Sub Rule | Crond Executed Command As Root | Information |
User Session | Sub Rule | Session Started For User | Other Audit Success |
Access Policy | Sub Rule | General Policy | Other Audit |
Session Information | Sub Rule | Session Information | Information |
No User Found | Sub Rule | SQL Transaction | Other Audit |
Disk Alert | Sub Rule | General Disk Error | Error |
RADIUS Auth Successful | Sub Rule | Authentication Activity | Authentication Success |
Authentication Failed | Sub Rule | User Logon Failure | Authentication Failure |
Mapping with LogRhythm Schema
Device Key in Log Message | LogRhythm Schema | Data Type |
---|---|---|
N/A | <vmid> | Number |
N/A | <severity> | Text/String |
N/A | <sip> | IP Address |
N/A | <sport> | Number |
N/A | <login> | Text/String |
N/A | <account> | Text/String |
N/A | <domainorigin> | Text/String |
N/A | <processid> | Number |
N/A | <process> | Text/String |
N/A | <object> | Text/String |
N/A | <subject> | Text/String |
N/A | <url> | Text/String |
N/A | <amount> | Number |
N/A | <result> | Text/String |
N/A | <tag2> | Text/String |
N/A | <tag3> | Text/String |
N/A | <tag4> | Text/String |
N/A | <tag5> | Text/String |