Connection Information 1

Classification

Rule Name

Rule Type

Common Event

Classification

Connection Information

Base Rule

General Connection Messages

Network Traffic

EVID 750001 : Received Tunnel Request

Sub Rule

Request Received

Other Audit Success

EVID 750002 : Received Init Request

Sub Rule

Request Received

Other Audit Success

EVID 750003 : Negotiation Aborted

Sub Rule

IKE Negotiation Aborted Timeout

Error

EVID 750007 : SA DOWN Connection Information

Sub Rule

Connection Is Down

Error

EVID 750006 : SA UP Connection Information

Sub Rule

Connection Up

Information

EVID 751011 : User Authentication Failure

Sub Rule

Authentication Failure Activity

Authentication Failure

EVID 751005 : Client Reconnect Auth Failure

Sub Rule

Client Authentication Failure

Warning

EVID 751014 : Unsupported Configuration Attribute

Sub Rule

Request Unsupported

Warning

EVID 751025 : Session Assignment

Sub Rule

IP Address Assigned

Information

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

N/A

<vmid>

Number

N/A

<severity>

Number

Local

<sip>

IP Address

Remote

<dip>

IP Address

N/A

<sport>

Number

N/A

<dport>

Number

Username

<login>

Text/String

N/A

<reason>

Text/String