Cisco Monitoring

Classification

Rule Name

Rule Type

Common Event

Classification

Cisco Monitoring

Base Rule

Service Monitoring

Information

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

N/A

<vmid>

Number

N/A

<severity>

Text/String

N/A

<dip>

IP Address

N/A

<dname>

Text/String

N/A

<dport>

Number

N/A

<session>

Text/String

N/A

<process>

Text/String

N/A

<object>

Text/String

N/A

<objectname>

Text/String

N/A

<command>

Text/String

N/A

<tag1>

Text/String

N/A

<tag2>

Text/String

N/A

<tag3>

Text/String

N/A

<tag4>

Text/String

N/A

<tag5>

Text/String