CLISH User Information

Classification

Rule Name

Rule Type

Classification

Common Event

CLISH User Information

Base Rule

Operations : Information

User Information

Mapping with LogRhythm Schema  

Device Key in log message

LogRhythm Schema

Data Type

<LOC0:NOTE>

<process>

Text/String

N/A

<processid>

Number

admin

<sname>

Text/String

t

<object>

Text/String

clish

<login>

Text/String

N/A

<session>

Number