Content Awareness

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

Content Awareness

Base Rule

General File Monitoring Event

Other Audit

Content Awareness : Traffic Blocked

Sub Rule

Traffic Denied by Network Firewall

Network Deny

Content Awareness : Traffic Accept

Sub Rule

Traffic Allowed by Network Firewall

Network Allow

Content Awareness : Traffic Denied

Sub Rule

Traffic Denied by Network Firewall

Network Deny

Content Awareness : Traffic Allowed

Sub Rule

Traffic Allowed by Network Firewall

Network Allow

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

Product

<version>

Number/Text

Action

<action>

Number/Text

Action

<tag1>

Number/Text

SIP

<sip>

Number/Text

origin

<sender>

Number/Text

src_machine_name

<sname>

Number/Text

DIP

<dip>

Number

dst_machine_name

<dname>

Number/Text

dport

<dport>

Number

protocol

<protname>

Number/Text

ifname

<sinterface>

Number/Text

ifdirection

<tag2>

Number/Text

User

<login>

Number/Text

src_user_name

<login>

Number/Text

dst_user_name

<account>

Number/Text

file_name

<object>

Number/Text

file_direction

<tag3>

Number/Text

file_type

<objecttype>

Number/Text

file_size

<size>

Number

connection_luuid

<session>

Number/Text

duration

<duration>

Number