EPCL IPS Policy

Classification

Rule Name

Rule Type

Common Event

Classification

EPCL IPS Policy

Base Rule

SSL Information-Only Event

Information

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

N/A

<severity>

Text/String

N/A

<sip>

Number

N/A

<sname>

Text/String

N/A

<dip>

Number

N/A

<sport>

Number

N/A

<dport>

Number

N/A

<sinterface>

Number

N/A

<dinterface>

Number

N/A

<protname>

Text/String

N/A

<login>

Text/String

N/A

<session>

Number

N/A

<sessiontype>

Text/String

N/A

<object>

Text/String

N/A

<objectname>

Text/String

N/A

<subject>

Text/String

N/A

<version>

Number

N/A

<url>

Number/Text

N/A

<policy>

Number/Text

N/A

<action>

Number/Text

N/A

<bytesout>

Number

N/A

<bytesin>

Number

N/A

<itemsin>

Number

N/A

<itemsout>

Number

N/A

<amount>

Number

N/A

<quantity>

Number