Skip to main content
Skip table of contents

DCMoveEventData 36999|36998

Vendor Documentation

Classification

Rule Name

Rule Type

Classification

Common Event

DCMoveEventData 36999|36998Base RuleInformationGeneral Information
EPO MOVE AV - Scan StartedSub RuleInformationScan Started
EPO MOVE AV - Scan CompletedSub RuleInformationScan Stopped

Mapping with LogRhythm Schema

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
MachineName<dname>Text/StringName of the system hosting the detecting product.
AgentGUIDN/AN/AUnique identifier of the agent that forwarded the event.
IPAddress<dip>IP AddressIP address of the system hosting the detecting product (if given in the event).
OSNameN/AN/AN/A
UserName<domainimpacted>
<account>
Text/StringN/A
TimeZoneBiasN/AN/AN/A
RawMACAddress<dmac>Text/StringMAC address of the system hosting the detecting product.
ProductName<vendorinfo>Text/StringName of the detecting managed product.
ProductVersion<version>Text/String/NumberVersion number of the detecting product.
ProductFamilyN/AN/AN/A
EventID<vmid>NumberUnique identifier of the event class.
Severity<severity>Text/String/NumberN/A
GMTTimeN/AN/AN/A
MOVEOpt_product_idN/AN/AN/A
MOVEOpt_event_name<subject>Text/StringN/A
MOVEOpt_evt_idN/AN/AN/A
MOVEOpt_evt_sinkN/AN/AN/A
MOVEOpt_time_stampN/AN/AN/A
MOVEOpt_server_stateN/AN/AN/A
MOVEOpt_file_name<domainimpacted>
<account>
Text/StringN/A
MOVEOpt_action_taken<process>Text/StringN/A
MOVEOpt_file_name<object>Text/StringN/A
MOVEOpt_action_taken<action>Text/StringN/A
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.