Event : User

Vendor Documentation

Classification

Rule Name

Rule Type

Classification

Common Event

Event : User

Base Rule

Information

General User Information

User Event Auth FGOVRD Success

Sub Rule

Other Audit Success

Successful Activity

User Event Auth FSAE Logon

Sub Rule

Authentication Success

User Logon

User Event Auth Logon

Sub Rule

Authentication Success

User Logon

User Event Auth FSAE Logoff

Sub Rule

Authentication Success

User Logoff

User Event Auth Logout

Sub Rule

Authentication Success

User Logoff

User Event Auth Time Out

Sub Rule

Other Audit

Authentication Timeout

User FSSO SVR Status

Sub Rule

Information

General Active Directory Information

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

Schema Description

severity

<severity>

Text/String

severity

logid

<vmid>

<tag1>

Number

N/A

logdesc

<status>

Text/String

N/A

srcip

<sip>

IP Address

IP Address

dstip

<dip>

IP Address

IP Address

user

<login>

Text/String

N/A

group

<group>

Text/String

N/A

action

<action>

Text/String

N/A

status

<status>

Text/String

N/A

reason

<reason>

Text/String

N/A

oldwprof

<object>

Text/String

N/A

profile

<objecttype>

Text/String

N/A

msg

<subject>

Text/String

N/A