EVID 5605 : Microsoft-Windows-WMI

Classification

Rule Name

Rule Type

Common Event

Classification

EVID 5605 : Microsoft-Windows-WMI

Base Rule

General Application Warning

Warning

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

Name

<vendorinfo>

Text/String

Eventid

<vmid>

Number

Level

<severity>

Text/String

Computer

<dname>

Text/String

Data

<domainorigin>

Text/String

N/A

<login>

Text/String

ProcessID

<processid>

Number

Version

<version>

Number