Catch All : System Restore Messages
Classification
Rule Name | Rule Type | Common Event | Classification |
|---|---|---|---|
| Catch All : System Restore Messages | Base Rule | General Backup Information | Information |
| EVID 8194 : System Restore Point Created | Sub Rule | Backup Succeeded | Information |
| EVID 8212 : System Restore Information | Sub Rule | General Backup Information | Information |
Mapping with LogRhythm Schema
Device Key in log message | LogRhythm Schema | Data Type |
|---|---|---|
| Provider name | <vendorinfo> | Text/String |
| Qualifiers | <vmid> | Number |
| level | <severity> | Text/String |
| N/A | <processid> | Number |
| N/A | <session> | Number |
| Computer | <dname> | Text/String |
| EventData | <command> | Text/String |
| N/A | <action> | Text/String |