Distributed Firewall Packet Log
Vendor Documentation
https://www.vmware.com/in/products/esxi-and-esx.html https://www.vmware.com/topics/glossary/content/bare-metal-hypervisor |
Classification
Rule Name | Rule Type | Common Event | Classification |
---|---|---|---|
Distributed Firewall Packet Log | Base Rule | Permitted TCP Packet | Network Traffic |
Distributed Firewall Inbound Packet Log | Sub Rule | Packet Received | Network Traffic |
Distributed Firewall Outbound Packet Log | Sub Rule | Sending Packet | Network Traffic |
Distributed Network Firewall Packet Drop | Sub Rule | Traffic Denied by Network Firewall | Network Deny |
Distributed Network Firewall Packet Pass | Sub Rule | Traffic Allowed by Network Firewall | Network Allow |
Distributed Firewall Inbound Packet Dropped | Sub Rule | TCP Packet Dropped | Information |
Distributed Firewall Inbound Packet Allow | Sub Rule | Permitted TCP Packet | Network Traffic |
Distributed Firewall Outbound Packet Allow | Sub Rule | Permitted TCP Packet | Network Traffic |
Distributed Firewall Outbound Packet Drop | Sub Rule | TCP Packet Dropped | Information |
Distributed Firewall Outbound Packet Pass | Sub Rule | Traffic Allowed by Network Firewall | Network Allow |
Mapping with LogRhythm Schema
Device Key in Log Message | LogRhythm Schema | Data Type |
---|---|---|
N/A | <severity> | Text/String |
N/A | <process> | Text/String |
N/A | <tag2> | Text/String |
N/A | <domain> | Text/String |
N/A | <tag1> | Text/String |
N/A | <protname> | Text/String |
N/A | <protnum> | Text/String |
N/A | <sip> | Number/Text |
N/A | <sport> | Number/Text |
N/A | <dip> | Number/Text |
N/A | <dport> | Number/Text |
N/A | <sinterface> | Number/Text |
N/A | <dinterface> | Number/Text |
N/A | <sname> | Text/String |
N/A | <smac> | Text/String |
N/A | <dmac> | Text/String |