Central Source Events
Vendor Documentation
Classification
Rule Name | Rule Type | Common Event | Classification |
|---|---|---|---|
Central Source Events | Base Rule | General Information Log Message | Information |
Mapping with LogRhythm Schema
Device Key in Log Message | LogRhythm Schema | Data Type | Schema Description |
Event ID | <vmid> | Number | Event ID 14601, 14602, 14603, 14604, 14605, 14606 |
Severity | <severity> | Text/String | For All: Information |
Message | <subject> | Text/String | Event ID 14601: |
<subject> | <subject> | Event ID 14602: | |
<subject> | Text/String | Event ID 14603: | |
<subject> | Text/String | Event ID 14604: | |
<subject> | Text/String | Event ID 14605: | |
<subject> | Text/String | Event ID 14606: |