CN/OU LDAP Messages

Classification

Rule Name

Rule Type

Common Event

Classification

CN/OU LDAP Messages

Base Rule

Authentication Activity

Authentication Success

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

SAU2

<severity>

Text/String

CN

<account>

Text/String

N/A

<domainorigin>

Text/String

N/A

<session>

Text/String

N/A

<sessiontype>

Text/String

N/A

<process>

Text/String

N/A

<processid>

Number

OU

<object>

Text/String

OU

<objectname>

Text/String

N/A

<subject>

Text/String

OU

<group>

Text/String