Skip to main content
Skip table of contents

Cortex Management Audit Messages

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification
Cortex Management Audit MessagesBase RuleGeneral Audit MessagesInformation
Cortex Mgmt - Logon SuccessSub RuleUser LogonAuthentication Success
Cortex Mgmt - Logon FailureSub RuleUser Logon FailureAuthentication Failure
Cortex Mgmt - Failed TaskSub RuleFailed OperationWarning

Mapping with LogRhythm Schema 

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
host nameN/AN/AName of any relevant affected hosts.
HEADER/VendorN/A N/AVendor information
HEADER/Device ProductN/AN/ADevice Product information
HEADER/Device Version<version>Text/StringDevice Version information
HEADER/Device Event Class ID<vmid>Text/StringN/A
HEADER/name<vendorinfo>
<tag1>
Text/StringAction type
HEADER/Severity<severity>Number

Severity:

0 - Unknown
6 - Low
8 - Medium
9 - High

suser<login>Text/StringUsername of the user who initiated the action.
endN/A N/ATimestamp
externalId<threatid>NumberExternal ID
cs1LabelN/AN/AN/A
cs1<login>,<domainorigin>Text/StringEmail address of the user.
cs2LabelN/AN/AN/A
cs2<action>Text/StringSub-category of the action.
cs3LabelN/AN/AN/A
cs3<result>
<tag2>
Text/StringThe result of the action (Success, Fail, or N/A)
cs4LabelN/AN/AN/A
cs4<reason>Text/StringIf the action or activity failed, this field indicates the identified cause.
msg<subject>Text/StringN/A 
tenantnameN/A N/AName of the tenant
tenantCDLidN/A N/AID of the tenant
CSPaccountnameN/AN/ACSP ID
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.