CDP Events

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

CDP Events

Base Rule

General CDP Message

Information

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

Schema Description

Event ID

<vmid>

Number

Event ID 8901, 8902, 8903, 8904, 8905, 8906

Severity

<severity>

Text/String

For All: Information

Message

<subject>

Text/String

Event ID 8901:
Logs CDP enabled

 

<subject>

Text/String

Event ID 8902:
Logs CDP disabled

 

<subject>
<dmac>
<sinterface>

Text/String

Event ID 8903:
Log to indicate CDP neighbor addition

 

<subject>
<dmac>
<sinterface>
<quantity>

Text/String/Number

Event ID 8904:
Log to indicate CDP neighbour modification

 

<subject>
<dmac>
<sinterface>

Text/String

Event ID 8905:
Log to indicate CDP neighbor deletion

 

<subject>

Text/String

Event ID 8906:
Log to indicate all CDP neighbor info is cleared