Skip to main content
Skip table of contents

Event : VPN

Vendor Documentation

Classification

Rule Name

Rule Type

Classification

Common Event

Event : VPNBase RuleNetwork TrafficGeneral VPN Traffic Event
VPN Event SSL VPN User SSL Login FailSub RuleAuthentication FailureConnection Authentication Failed
VPN Event SSL VPN Session Tunnel StatsSub RuleInformationVPN Session Information
VPN Neg I P1 ErrorSub RuleErrorGeneral IPSec Error
VPN Conn StatsSub RuleInformationGeneral IPSec Information
VPN Event VPN Cert RegenSub RuleActivityCertificate Renewal Request
VPN Event SSL VPN User Tunnel DOWNSub RuleOther Audit SuccessVPN Connection Closed
VPN Event SSL VPN Session New ConSub RuleNetwork TrafficVPN Session Started
VPN Event SSL VPN Session Tunnel UpSub RuleNetwork TrafficVPN Session Started
VPN Event SSL VPN Session Tunnel DownSub RuleNetwork TrafficVPN Session Terminated
VPN Neg Generic P2 Notif IKEV2Sub RuleNetwork TrafficIPSec Negotiation
VPN Neg I P1 Error IKEV2Sub RuleErrorIPSec Negotiation Error
VPN Neg Progress P1 Notif IKEV2Sub RuleInformationIPSec Information Message
VPN Neg Progress P2 Notif IKEV2Sub RuleInformationIPSec Information Message
VPN Conn Stats IKEV2Sub RuleInformationIPSec Information Message
VPN Install SA IKEV2Sub RuleInformationInstalled IPSec Security Association
VPN Neg Progress P1 ErrorSub RuleErrorIPSec Progress Error
VPN Neg Progress P2 ErrorSub RuleErrorIPSec Progress Error
VPN Neg Progress P1 Error IKEV2Sub RuleErrorIPSec Progress Error
VPN Event SSL VPN Session Cert OkSub RuleInformationCertificate Valid
VPN Event SSL VPN User Tunnel UPSub RuleOther Audit SuccessVPN Session Started

Mapping with LogRhythm Schema  

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
severity<severity>Text/Stringseverity
logid

<vmid>

<tag1>

NumberN/A
logdesc<status>Text/StringN/A
action<action>Text/StringN/A
tunnelid<session>Text/String/NumberN/A
remip<sip>IP AddressN/A
userN/AText/StringN/A
group<group>Text/StringN/A
dst_host<dname>Text/StringN/A
reason<reason>Text/StringN/A
duration<seconds>NumberN/A
sentbyte<bytesout>NumberN/A
rcvdbyte<bytesin>NumberN/A
msg<subject>Text/StringN/A
locip<dip>IP AddressIP Address
remport<sport>NumberN/A
locport<dport>NumberN/A
outintf<sinterface>Text/String/NumberN/A
result<result>Text/StringN/A
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.