21 : Logs the consumer name and filter path when a consumer binds to a filter.
Event ID
21
Log Fields and Parsing
This section details the log fields available in this log message type, along with values parsed for both LogRhythm Default and LogRhythm Default v2.0 policies. A value of "N/A" (not applicable) means that there is no value parsed for a specified log field.
Log Field
LogRhythm Default
LogRhythm Default v2.0
Provider
N/A
N/A
EventID
<vmid>
<vmid>
Version
N/A
N/A
Level
<severity>
<severity>
Task
N/A
<vendorinfo>
Opcode
N/A
N/A
Keywords
N/A
<result>
TimeCreated
N/A
N/A
EventRecordID
N/A
N/A
Correlation
N/A
N/A
Execution
N/A
N/A
Channel
N/A
N/A
Computer
<dname>
<dname>
Security
N/A
N/A
EventType
<vendorinfo>
N/A
Operation
<tag1>, <action>
N/A
User
<domain>, <login>
<login>, <domainorigin>
Consumer
<object>
N/A
Filter
<objectname>
N/A
Query
N/A
<command>
RuleName
<policy>
<policy>
Log Processing Settings
This section details log processing changes made from the LogRhythm Default policy to LogRhythm Default v2.0. In some cases, base rules are broken down into sub-rules to appropriately parse log message types by their event types.
LogRhythm Default
Regex ID
Rule Name
Rule Type
Common Event
Classification
1009740
EVID 21 : WMI Consumer To Filter Activity
Base Rule
Object Accessed
Access Success
EVID 21 : WMI Consumer To Filter Created
Sub Rule
Object Created
Access Success
EVID 21 : WMI Consumer To Filter Modified
Sub Rule
Object Modified
Access Success
LogRhythm Default v2.0
Regex ID
Rule Name
Rule Type
Common Event
Classification
1011226
V 2.0 : WMI Events
Base Rule
Object Modified
Access Success
V 2.0 : EVID 19 : WMI Filter Registered
Sub Rule
Object Created
Access Success
V 2.0 : EVID 20 : WMI Consumer Registered
Sub Rule
Object Created
Access Success
V 2.0 : EVID 21 : WMI Filter Bound
Sub Rule
Connection Enabled
Information
JavaScript errors detected
Please note, these errors can depend on your browser setup.
If this problem persists, please contact our support.