CB Server Events

Vendor Documentation


Classification

Rule Name

Rule Type

Common Event

Classification


CB Server Events

Base Rule

General File Monitoring Event

Informaton

Mapping with LogRhythm Schema

Device Key in log message

LogRhythm Schema

Data Type

alert_severity

<severity>

Text/String/Number

comms_ip

<dinterface>

Text/String

computer_name

<domain>

Text/String

feed_name

<sender>

Text/String

group

<group>

Text/String

interface_ip

<sip>

IP Address

ioc_value

<dip>

IP Address

md5

<hash>

Text/String

process_name

<process>

Text/String

process_path

<parentprocesspath>

Text/String

status

<status>

Text/String

username

<login>

Text/String

watchlist_id

<object>

Text/String

watchlist_name

<objectname>

Text/String