Skip to main content
Skip table of contents

Event : Endpoint

Vendor Documentation

Classification

Rule Name

Rule Type

Classification

Common Event

Event : EndpointBase RuleInformationEndpoint Profiling Activity
EVID 45057 : Add ConnectionSub RuleNetwork TrafficConnection Established
EVID 45058 : Close ConnectionSub RuleOther Audit SuccessClient Connection Closed

Mapping with LogRhythm Schema  

Device Key in Log MessageLogRhythm SchemaData Type
vd<domainorigin>Text/String
logid

<vmid>

Number
type<policy>Text/String
subtype<subject>Text/String
level<severity>Text/String
logdesc<vendorinfo>Text/String
action

<action>

<tag1>

Text/String
status<status>Text/String
connection_type<sessiontype>Text/String
count<quantity>Number
user<login>Text/String
ip<sip>IP Address
name<sname>Text/String
srcip<sip>IP Address
srcname<sname>Text/String
srcmac<smac>MAC Address
vulnname<objectname>Text/String
vulncat<objecttype>Text/String
severity<severity>Text/String
vendorurl<url>Text/String
msg<result>Text/String
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.