Catch All : System Restore Messages

Classification

Rule Name

Rule Type

Common Event

Classification

Catch All : System Restore Messages

Base Rule

General Backup Information

Information

EVID 8194 : System Restore Point Created

Sub Rule

Backup Succeeded

Information

EVID 8212 : System Restore Information

Sub Rule

General Backup Information

Information

Mapping with LogRhythm Schema  

Device Key in log message

LogRhythm Schema

Data Type

Provider name

<vendorinfo>

Text/String

Qualifiers

<vmid>

Number

level

<severity>

Text/String

N/A

<processid>

Number

N/A

<session>

Number

Computer

<dname>

Text/String

EventData

<command>

Text/String

N/A

<action>

Text/String