Certificate Services Client: Cert Enrollment

Classification

Rule Name

Rule Type

Common Event

Classification

Certificate Services Client : Cert Enrollment

Base Rule

General CERT_ENROLL Message

Information

EVID 64 : Cert Enroll Successfully Loaded Policy

Sub Rule

SSL Certificate Loaded

Information

EVID 65 : Cert Enroll Auth Success

Sub Rule

SSL Certificate Verified

Information

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

Provider name

<vendorinfo>

Text/String

Eventid

<vmid>

Number

Level

<severity>

Text/String

Computer

<dname>

Text/String

processid

<processid>

Number

threadid

<session>

Number

userid

<domain>

Text/String

N/A

<login>

Text/String

Context

<group>

Text/String

N/A

<object>

Text/String