Daemon/Version Startup And Shutdown

Classification

Rule Name

Rule Type

Classification

Common Event

Daemon/Version Startup And Shutdown

Base Rule

Startup and Shutdown

Process/Service Startup Or Shutdown Activity

Received SIGTERM : Shutting Down

Sub Rule

Startup and Shutdown

Process/Service Stopping

Starting Up Daemon

Sub Rule

Startup and Shutdown

Process/Service Starting

Version Starting

Sub Rule

Startup and Shutdown

Process/Service Starting

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

N/A

<severity>

Text/String

Jul 20 12:40:07

<dname>

Text/String

N/A

<process>

Text/String

N/A

<processid>

Number

N/A

<tag1>

Text/String

caught signal

<command>

Text/String

N/A

<version>

Number