Skip to main content
Skip table of contents

Deny List Transaction

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

Deny List Transaction Events

Base Rule

Detected Malware Activity

Malware

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

Schema Description

N/A

N/A

N/A

CEF format version

N/A

N/A

N/A

Appliance vendor

N/A

N/A

N/A

Appliance product

N/A

<version>

Numbers

Appliance version

N/A

<vmid>

Numbers

Event ID

N/A

<vendorinfo>

Text/String

Description

N/A

<severity>

Number

Severity

rt

N/A

N/A

Event logged

dvc

<dip>

IP Address

Appliance IP address

dvchost

<dname>

Text/String

Appliance hostname

dvcmac

<dmac>

Text/String

Appliance MAC address

deviceExternalId

N/A

N/A

Appliance GUID

cs1Label

N/A

N/A

Deny List type

cs1

<objecttype>

Text/String

Type:
Deny List IP/Port
Deny List URL
Deny List File SHA1
Deny List Domain

end

N/A

N/A

Report end time

act

<action>

Text/String

The action in the event

request

<url>

Text/String

URL

cs2Label

N/A

N/A

Risk level

cs2

N/A

N/A

Risk level

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.