Catch All : System Restore Messages
Classification
Rule Name | Rule Type | Common Event | Classification |
---|---|---|---|
Catch All : System Restore Messages | Base Rule | General Backup Information | Information |
EVID 8194 : System Restore Point Created | Sub Rule | Backup Succeeded | Information |
EVID 8212 : System Restore Information | Sub Rule | General Backup Information | Information |
Mapping with LogRhythm Schema
Device Key in log message | LogRhythm Schema | Data Type |
---|---|---|
Provider name | <vendorinfo> | Text/String |
Qualifiers | <vmid> | Number |
level | <severity> | Text/String |
N/A | <processid> | Number |
N/A | <session> | Number |
Computer | <dname> | Text/String |
EventData | <command> | Text/String |
N/A | <action> | Text/String |