Feed : Process Storage Hit

Vendor Documentation


Classification

Rule Name

Rule Type

Common Event

Classification

Feed: Process Storage Hit

Base Rule

Watchlist Hit

Activity

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

cmdline

<command>

Text/String

comms_ip

<dinterface>

Number

feed_name

<sender>

Text/String

group

<group>

Text/String

hostname

<dname>

Text/String

sinterface_ip

<sip>

IP Address

digsig_result

<result>

Text/String

parent_name

<parentprocessname>

Text/String

parent_id

<parentprocessid>

Number

path

<process>

Text/String

process_md5

<objectname>

Text/String

process_md5

<hash>

Text/String

sprocess_name

<object>

Text/String

sprocess_pid

<processid>

Number

username

<domain>

Text/String

username

<login>

Text/String