Configuration Change

Classification

Rule Name

Rule Type

Common Event

Classification

Configuration Change

Base Rule

Configuration Modified : System

Configuration

Configuration : Add Rule

Sub Rule

Object Added

Access Success

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

N/A

<severity>

Number/Text

type

<vmid>

Number

auid

<account>

Number/Text

op

<command>

Number/Text

key

<objectname>

Text/String

res

<subject>

Text/String

auid

<account>

Number/String

ses

<session>

Text/String