Skip to main content
Skip table of contents

EVID 1087EPO - Access Protection Violation Blocked

Vendor Documentation

Classification

Rule Name

Rule Type

Classification

Common Event

EVID 1087EPO - Access Protection Violation Blocked

Base Rule

Failed Activity

Threat Blocked

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

Schema Description

N/AN/AN/AN/A
MachineName<dname>Text/StringName of the system hosting the detecting product.
AgentGUIDN/AN/AUnique identifier of the agent that forwarded the event.
IPAddress<dip>IP AddressIP address of the system hosting the detecting product (if given in the event).
OSNameN/AN/AN/A
UserName<domainimpacted><account>Text/StringN/A
TimeZoneBiasN/AN/AN/A
RawMACAddress<dmac>Text/StringMAC address of the system hosting the detecting product.
ProductName<vendorinfo>Text/StringName of the detecting managed product.
ProductVersion<version>Text/String/NumberVersion number of the detecting product.
ProductFamilyN/AN/AN/A
EngineVersionN/AN/AVersion number of the detecting product.
DATVersionN/AN/AName of the system hosting the detecting product.
ScannerTypeN/AN/AThe name of the task or task type that was responsible for detecting the threat.
TaskName<action>Text/StringUnique identifier of the event class.
ProductFamilyN/AN/AN/A
ProductNameN/AN/AN/A
ProductVersionN/AN/ACategory of the event. Possible categories depend on the product.
EventID<vmid>NumberUnique identifier of the event class.
Severity<severity>NumberName of the threat.
GMTTimeN/AN/AClass of the threat.
UTCTimeN/AN/AN/A
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.