EVID 1 : CVE Messages

Classification

Rule Name

Rule Type

Common Event

Classification

EVID 1 : CVE Messages

Base Rule

Vuln High Severity : Windows

Vulnerability

Mapping with LogRhythm Schema  

Device Key in log message

LogRhythm Schema

Data Type

Eventid

<vmid>

Number

Level

<severity>

Text/String

Computer

<dname>

Text/String

userid

<account>

Text/String

ProcessID

<processid>

Number

sha1

<object>

Text/Number

cveid

<cve>

Text/Number

N/A

<tag1>

Text/Number