Connection Status

Vendor Documentation

Classification

Rule Name

Rule Type

Classification

Common Event

Connection Status

Base Rule

Information

Connection Information

Authentication Agent Connection Established

Sub Rule

Network Traffic

Connection Established

Authentication Agent Connection Closed

Sub Rule

Network Traffic

Connection Closed

Authentication Agent Connection Failure

Sub Rule

Error

Connection Failure

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

N/A

<vmid>

Text/String/Number

N/A

<tag1>

Text/String/Number

N/A

<domain>

Text/String/Number

N/A

<dip>

Ip address 

N/A

<dport>

Text/String/Number

N/A

<tag2>

Text/String/Number

N/A

<object>

Text/String/Number