EVID 1008 : Microsoft-Windows-Perflib

Classification

Rule Name

Rule Type

Common Event

Classification

EVID 1008 : Microsoft-Windows-Perflib

Base Rule

Function Call Failed

Error

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

N/A

<vendorinfo>

Text/String

N/A

<vmid>

Number

N/A

<severity>

Text/String

N/A

<dname>

Text/String

N/A

<processid>

Number

N/A

<object>

Text/String

N/A

<objectname>

Text/String

N/A

<threatid>

Number

N/A

<version>

Number

N/A

<bytesin>

Number