Skip to main content
Skip table of contents

Detection Results Events

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

Detection Results Events

Base Rule

General Threat Message

Information

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

Schema Description

N/A

N/A

N/A

CEF format version

N/A

N/A

N/A

Appliance vendor

N/A

N/A

N/A

Appliance product

N/A

<version>

Numbers

Appliance version

N/A

<vmid>

Numbers

Event ID

N/A

<vendorinfo>

Text/String

Description

N/A

<severity>

Number

Severity

  • 1: Unrated

  • 2: No risk

  • 4: Low

  • 6: Medium

  • 8: High

rt

N/A

N/A

Analysis Time

dvc

<dip>

IP Address

Appliance IP address

dvchost

<dname>

Text/String

Appliance hostname

dvcmac

<dmac>

Text/String/Number

Appliance MAC address

deviceExternalId

N/A

N/A

Appliance GUID

cn1Label

N/A

N/A

Sample Type

cn1

N/A

N/A

Sample Type

fname

<object>

Text/Stting

File Name

fileType

<objecttype>

Text/Stting

True File Type

fileHash

<hash>

Text/String/Number

SHA1

suser

<sender>

Text/Stting

Email Sender

duser

<recipient>

Text/Stting

Email Recipients

msg

<subject>

Text/Stting

Email Subject

cs2Label

N/A

N/A

Email ID

cs2

N/A

N/A

Email ID

app

<protname>

Text/Stting

Application Protocol

cs3Label

N/A

N/A

Application Protocol Group

cs3

N/A

N/A

Application Protocol Group

cs4Label

N/A

N/A

Submitter

cs4

N/A

N/A

Submitter

cs5Label

N/A

N/A

Submitter host name

cs5

N/A

N/A

Submitter host name

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.