EVID : 20559|20500|20503|20504 Device Logs

Vendor Documentation

Classification

Rule Name

Rule Type

Classification

Common Event

EVID : 20559|20500|20503|20504 Device Logs

Base Rule

Information

General Information

EPO FRP - Device Inserted

Sub Rule

Information

USB Device Connected

EPO FRP - Device Initialized

Sub Rule

Information

Device Initializing

EPO FRP - Device Ejected

Sub Rule

Information

USB Device Disconnected

EPO FRP - Device Authorization

Sub Rule

Information

General Information

Mapping with LogRhythm Schema 

Device Key in Log Message

LogRhythm Schema

Data Type

Schema Description

AgentGUID

N/A

N/A

Unique identifier of the agent that forwarded the event.

MachineName

<dname>

Text/String

Name of the system hosting the detecting product.

RawMACAddress

<dmac>

Text/String

MAC address of the system hosting the detecting product.

IPAddress

<dip>

IP Address

IP address of the system hosting the detecting product (if given in the event).

AgentVersion

N/A

N/A

N/A

OSName

N/A

N/A

N/A

TimeZoneBias

N/A

N/A

N/A

UserName

<domainimpacted>
<account>

Text/String

N/A

ProductName

<vendorinfo>

Text/String

Name of the detecting managed product.

ProductVersion

<version>

Text/String/Number

Version number of the detecting product.

ProductFamily

N/A

N/A

N/A

EventID

<vmid>

Number

Unique identifier of the event class.

Severity

<severity>

Text/String/Number

N/A

GMTTime

N/A

N/A

N/A