Skip to main content
Skip table of contents

Event : User

Vendor Documentation

Classification

Rule Name

Rule Type

Classification

Common Event

Event : UserBase RuleInformationGeneral User Information
User Event Auth FGOVRD SuccessSub RuleOther Audit SuccessSuccessful Activity
User Event Auth FSAE LogonSub RuleAuthentication SuccessUser Logon
User Event Auth LogonSub RuleAuthentication SuccessUser Logon
User Event Auth FSAE LogoffSub RuleAuthentication SuccessUser Logoff
User Event Auth LogoutSub RuleAuthentication SuccessUser Logoff
User Event Auth Time OutSub RuleOther AuditAuthentication Timeout
User FSSO SVR StatusSub RuleInformationGeneral Active Directory Information

Mapping with LogRhythm Schema  

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
severity<severity>Text/Stringseverity
logid

<vmid>

<tag1>

NumberN/A
logdesc<status>Text/StringN/A
srcip<sip>IP AddressIP Address
dstip<dip>IP AddressIP Address
user<login>Text/StringN/A
group<group>Text/StringN/A
action<action>Text/StringN/A
status<status>Text/StringN/A
reason<reason>Text/StringN/A
oldwprof<object>Text/StringN/A
profile<objecttype>Text/StringN/A
msg<subject>Text/StringN/A
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.