Skip to main content
Skip table of contents

Event : Endpoint 1

Vendor Documentation

Classification

Rule NameRule TypeCommon EventClassification
Event : EndpointBase RuleGeneral Endpoint MessageInformation
Event : Endpoint : FortiClient Connection ClosedSub RuleClient Connection ClosedOther Audit Success
Event : Endpoint : Add A FortiClient ConnectionSub RuleConnection BuiltNetwork Traffic
Event : Endpoint : FortiClient Registration RenewSub RuleRegistrationInformation
Event : Endpoint : FortiClient Registration RenewSub RuleConfiguration InformationInformation
Event : Endpoint Vulnerbility ScanSub RuleGeneral Critical Log MessageCritical

Mapping with LogRhythm Schema  

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
logid<vmid>NumberThe ID (logid) is a 10-digit field. It is a unique identifier for that specific log.
level<severity>Text\StringEach log entry contains a Level (level) field that indicates the estimated severity of the event that caused the log entry.
logdesc<vendorinfo>Text\StringN/A
ip<sip>IP AddressIP address of the traffic’s origin
name<sname>Text\StringN/A
srcmac<smac>Text\StringN/A
user<login>Text\StringN/A
vd<domainorigin>Text\String
N/A
connection_type<sessiontype>Text\StringN/A
vulncat<objecttype>Text\StringN/A
vulnname<objectname>Text\StringN/A
subtype<subject>Text\String
N/A
vendorurl<url>Text\StringN/A
type<policy>Text\StringN/A
action<action>Text\StringN/A
msg<result>Text\String
N/A
status<status>Text\StringN/A
count<quantity>NumberN/A
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.