Skip to main content
Skip table of contents

Catch All : Level 4 1

Vendor Documentation

Classification

Rule NameRule TypeCommon EventClassification
Catch All : Level 4Base RuleGeneral InformationInformation
Alert MessagesSub RuleGeneral AlertWarning
Emergency MessagesSub RuleGeneral Critical Log MessageCritical
Informational MessagesSub RuleGeneral InformationInformation
Notification MessagesSub RuleGeneral InformationInformation
Warning MessagesSub RuleGeneral Warning Log MessageWarning

Mapping with LogRhythm Schema  

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
logid<vmid>NumberThe ID (logid) is a 10-digit field. It is a unique identifier for that specific log.
level<severity>Text\StringEach log entry contains a Level (level) field that indicates the estimated severity of the event that caused the log entry.
srcip<sip>IP AddressIP address of the traffic’s origin.
dstip<dip>IP AddressDestination IP address for the web.
srcport<sport>NumberPort number of the traffic's origin.
dstport<dport>NumberPort number of the traffic's destination.
srcintf<sinterface>Text\StringInterface name of the traffic's origin.
dstintf<dinterface>Text\StringInterface of the traffic's destination.
vd<domainorigin>Text\StringName of the virtual domain in which the log message was recorded.
type<object>Text\StringEach log entry contains a Type (type) or category field.
subtype<objectname>Text\StringEach log entry contains a Sub Type (subtype) or subcategory field.
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.