CLISH Messages : Login Logout Cmd Executed

Classification

Rule Name

Rule Type

Classification

Common Event

CLISH Messages : Login Logout Cmd Executed

Base Rule

Audit : Authentication Success

Authentication Activity

Command Executed

Sub Rule

Access Success

Command Executed

Logged Out From CLI

Sub Rule

Authentication Success

User Logoff

Logged In With RW Permission

Sub Rule

Authentication Success

User Logon

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

N/A

<login>

Text/String

N/A

<process>

Text/String

N/A

<processid>

Number

N/A

<object>

Text/String

N/A

<tag1>

Text/String