Skip to main content
Skip table of contents

Event : System

Vendor Documentation

Classification

Rule Name

Rule Type

Classification

Common Event

Event : SystemBase RuleInformationGeneral Event Log Information
Event Admin Login FailSub RuleAuthentication FailureAuthentication Failure Activity
Event Ext RemoteSub RuleInformationGeneral Remote Access Information
Event Reportd Report SuccessSub RuleInformationReport Generation
Event VWL Volume StatusSub RuleInformationVLAN Manager Info Msg
Event Log RollSub RuleInformationGeneral Disk Information
Event DHCP StatSub RuleInformationGeneral DHCPServer Information
Event Nac QuarantineSub RuleActivityQuarantine
Event Mail Sent FailSub RuleFailed ActivityGeneral Failed Activity
Event DSSCC ExecSub RuleOther AuditGeneral Policy Compliance Information
Event DHCP AckSub RuleNetwork TrafficDHCP ACK
Event Sys PerfSub RuleInformationGeneral Performance Statistics
Event Admin Login LogoutSub RuleInformationLogout Request
Event Backup Conf By ScpSub RuleInformationBackup Completed
Event Upd Fsa VirdbSub RuleInformationDatabase Update Event
Event Reportd Report SuccessSub RuleInformationReport Deleted
Event Admin Login SuccSub RuleAuthentication ActivityAuthentication Activity
Event Log Del DirSub RuleAccess SuccessObject Deleted/Removed
Event Log Del FileSub RuleAccess SuccessObject Deleted/Removed
Event Report DeletedSub RuleAccess SuccessObject Deleted/Removed
Event Report Deleted GUISub RuleAccess SuccessObject Deleted/Removed
Event Delete ObjectSub RuleAccess SuccessObject Deleted/Removed
Event Config AttrSub RuleAccess SuccessObject Added
Event Add Object AttributeSub RuleAccess SuccessObject Added
Event Auth Snmp Query FailedSub RuleErrorError : SNMP_GET_ERROR1
Event Conf ChgSub RuleConfigurationConfiguration Modified : System
Event Admin Login DisableSub RuleAccess RevokedAccount Disabled
Event Session ClashSub RuleInformationPossible Address Conflict
Event Log Roll ForticronSub RuleInformationRotation Information
Event Upd Fgt SuccSub RuleInformationOperation Succeeded
Event DHCP Client LeaseSub RuleInformationDHCP Lease Obtained

Mapping with LogRhythm Schema  

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
severity<severity>Text/Stringseverity
logid

<vmid>

<tag1>

NumberN/A
subtype<object>Text/StringN/A
sn<serialnumber>Text/StringN/A
user<login>Text/String/NumberN/A
method<sessiontype>Text/StringN/A
srcip<sip>IP AddressIP Address
dstip<dip>IP AddressIP Address
session<account>Text/String/NumberN/A
action<action>Text/StringN/A
status<status>Text/StringN/A
reason<reason>Text/StringN/A
msg<subject>Text/StringN/A
ui<sip>IP AddressN/A
src_int<sinterface>Text/StringN/A
dst_int<dinterface>Text/StringN/A
srcport<sport>NumberN/A
dstport<dport>NumberN/A
version<version>Text/String/NumberN/A
proto<protnum>NumberN/A
banned_rule<threatname>Text/StringN/A
sensor<policy>Text/StringN/A
interface<sinterface>Text/StringN/A
ip<sip>IP AddressN/A
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.