Connection Information

Vendor Documentation

Classification

Rule Name

Rule Type

Classification

Common Event

Connection Information

Base Rule

Other Audit Failure

Port Access Failure

Connection Closed

Sub Rule

Network Traffic

Connection Closed

Connection Established

Sub Rule

Network Traffic

Connection Established

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

N/A

<vmid>

Text/String

N/A

<severity>

Text/String

N/A

<sip>

Ip Address

N/A

<object>

Text/String

N/A

<tag1>

Text/String

N/A

<sport>

Numeric