Default Resource Used

Classification

Rule Name

Rule Type

Common Event

Classification

Default Resource Used

Base Rule

Resource Allocated

Information

Mapping of  with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

N/A

<severity>

Text/String

N/A

<process>

Text/String

opID

<command>

Text/String

Default resource used for

<object>

Text/String

expected in module 

<objectname>

Text/String

N/A

<domain>

Number/Text

N/A

<process>

Number/Text

N/A

<session>

Number/Text

opID

<vmid>

Number/Text