Skip to main content
Skip table of contents

EVID 4624 : Remote Interactive User Logon Success (XML - Security)

Event Details

Event TypeAudit Logon
Event Description4624(S) : An account was successfully logged on.
Event ID4624, Logn Type: 10

Log Fields and Parsing

This section details the log fields available in this log message type, along with values parsed for both LogRhythm Default and LogRhythm Default v2.0 policies. A value of "N/A" (not applicable) means that there is no value parsed for a specified log field.

Log FieldLogRhythm DefaultLogRhythm Default v2.0
ProviderN/AN/A
EventID<vmid><vmid>
VersionN/AN/A
Level<severity><severity>
Task<vendorinfo><vendorinfo>
OpcodeN/AN/A
KeywordsN/A<result>
TimeCreatedN/AN/A
EventRecordIDN/AN/A
CorrelationN/AN/A
ExecutionN/AN/A
ChannelN/AN/A
Computer<dname><dname>
SubjectUserSidN/AN/A
SubjectUserNameN/AN/A
SubjectDomainNameN/AN/A
SubjectLogonIdN/AN/A
TargetUserSidN/AN/A
TargetUserName<login>, <tag2><login>, <tag1>
TargetDomainName<domainimpacted><domainorigin>
TargetLogonId<session><session>
LogonType<sessiontype>, <tag1>, <command><sessiontype>, <tag2>
LogonProcessName<object><object>
AuthenticationPackageNameN/A<objectname>
WorkstationNameN/AN/A
LogonGuidN/AN/A
TransmittedServicesN/AN/A
LmPackageNameN/A<objecttype>
KeyLength<size><size>
ProcessIdN/A<processid>
ProcessName<process><process>
IpAddress<sip><sip>
IpPort<sport><sport>
ImpersonationLevelN/AN/A
RestrictedAdminModeN/AN/A
TargetOutboundUserNameN/A<account>
TargetOutboundDomainNameN/AN/A
VirtualAccountN/AN/A
TargetLinkedLogonIdN/AN/A
ElevatedTokenN/A<tag3>


Log Processing Settings

This section details log processing changes made from the LogRhythm Default policy to LogRhythm Default v2.0. In some cases, base rules are broken down into sub-rules to appropriately parse log message types by their event types.

LogRhythm Default

Regex IDRule NameRule TypeCommon EventClassification
1007742EVID 4624 : Logon EventsBase RuleAuthentication ActivityAuthentication Success
EVID 4624 : Logon Type 2Sub RuleUser LogonAuthentication Success
EVID 4624 : Logon Type 3Sub RuleUser LogonAuthentication Success
EVID 4624 : Logon Type 4Sub RuleUser LogonAuthentication Success
EVID 4624 : Logon Type 7Sub RuleUser LogonAuthentication Success
EVID 4624 : Logon Type 8Sub RuleUser LogonAuthentication Success
EVID 4624 : Logon Type 10Sub RuleUser LogonAuthentication Success
EVID 4624 : Logon Type 11Sub RuleUser LogonAuthentication Success
EVID 4624 : Logon Type 5Sub RuleService LogonAuthentication Success
EVID 4624 : Anonymous Logon Type 3Sub RuleAuthentication ActivityAuthentication Success
EVID 4624 : Administrator Logon Type 3Sub RuleAuthentication ActivityAuthentication Success
EVID 4624 : System Logon Type 3Sub RuleComputer LogonAuthentication Success
EVID 4624 : System Logon Type 2Sub RuleComputer LogonAuthentication Success
EVID 4624 : System Logon Type 4Sub RuleComputer LogonAuthentication Success
EVID 4624 : System Logon Type 7Sub RuleComputer LogonAuthentication Success
EVID 4624 : System Logon Type 8Sub RuleComputer LogonAuthentication Success
EVID 4624 : System Logon Type 10Sub RuleComputer LogonAuthentication Success
EVID 4624 : System Logon Type 11Sub RuleComputer LogonAuthentication Success
EVID 4624 : System Logon Type 5Sub RuleComputer LogonAuthentication Success

LogRhythm Default v2.0

Regex IDRule NameRule TypeCommon EventClassification
1012617V 2.0 : Remote Interactive User Logon SuccessBase RuleUser Logon  Authentication Success

V 2.0 : EVID 4624 : Remote Intractv Usr Logon Succ

Sub RuleUser LogonAuthentication Success
V 2.0 : EVID 4624 : Administrator Logon Type 10Sub RuleUser LogonAuthentication Success
V 2.0 : EVID 4624 : Anonymous Logon Type 10Sub RuleUser LogonAuthentication Success
V 2.0 : EVID 4624 : System Logon Type 10Sub RuleComputer LogonAuthentication Success
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.