FileAuditReports Log Messages
Vendor Documentation
Classification
Rule Name | Rule Type | Common Event | Classification |
|---|---|---|---|
FileAuditReports Log Messages | Base Rule | General Audit Messages | Information |
Mapping with LogRhythm Schema
Device Key in Log Message | LogRhythm Schema | Data Type | Schema Description |
N/A | <severity> | Text/String | N/A |
Category | <object> | Text/String | N/A |
REPORT_PROFILE | <objectname> | Text/String | N/A |
EVENT_NUMBER | N/A | N/A | N/A |
TIME_GENERATED | N/A | N/A | N/A |
EVENT_TYPE | N/A | N/A | N/A |
EVENT_TYPE_TEXT | <status> | Text/String | N/A |
SOURCE | <login> | Text/String | N/A |
REMARKS | <reason> | Text/String | N/A |
HANDLE_ID | N/A | N/A | N/A |
OBJECT_NAME | N/A | N/A | N/A |
UNC_NAME | N/A | N/A | N/A |
FILE_NAME | <parentprocessname> | Text/String | N/A |
FILE_LOCATION | <parentprocesspath> | Text/String | N/A |
LOGON_ID | N/A | N/A | N/A |
DOMAIN | <domainorigin> | Text/String | N/A |
ACCESSES | N/A | N/A | N/A |
PROCESS_ID | N/A | N/A | N/A |
PROCESS_NAME | <process> | Text/String | N/A |
CLIENT_HOST_NAME | <dname> | Text/String | N/A |
CLIENT_IP_ADDRESS | <dip> | IP Address | N/A |
TRANSACTION_ID | N/A | N/A | N/A |
ACCESS_MASK | N/A | N/A | N/A |
USERNAME | <account> | Text/String | N/A |
RECORD_NUMBER | N/A | N/A | N/A |
USER_SID | <session> | Text/String | N/A |
ACCESS_TYPE | N/A | N/A | N/A |
ACCESS_TYPE_TEXT | N/A | N/A | N/A |
FORMAT_MESSAGE | <subject> | Text/String | N/A |
USER_SAM_ACCOUNT_NAME | N/A | N/A | N/A |
USER_DISPLAY_NAME | N/A | N/A | N/A |
USER_PRINCIPAL_NAME | N/A | N/A | N/A |
USER_GUID | N/A | N/A | N/A |
USER_DISTINGUISH_NAME | N/A | N/A | N/A |
USER_OU_GUID | N/A | N/A | N/A |
USER_DEPARTMENT | N/A | N/A | N/A |
USER_MANAGER_NAME | N/A | N/A | N/A |
SOURCE_NAME | N/A | N/A | N/A |
LOG_FILE_NAME | N/A | N/A | N/A |
KEYWORDS_NAME | N/A | N/A | N/A |
TASK_CATEGORY_NAME | N/A | N/A | N/A |
TASK_CATEGORY_ID | N/A | N/A | N/A |
FILE_TYPE | N/A | N/A | N/A |
SHARE_NAME | N/A | N/A | N/A |
EXTRA_COLUMN1 | N/A | N/A | N/A |
EXTRA_COLUMN2 | N/A | N/A | N/A |
EXTRA_COLUMN3 | N/A | N/A | N/A |
EXTRA_COLUMN4 | N/A | N/A | N/A |
EXTRA_COLUMN5 | N/A | N/A | N/A |
EXTRA_COLUMN6 | N/A | N/A | N/A |
EXTRA_COLUMN7 | N/A | N/A | N/A |
EXTRA_COLUMN8 | N/A | N/A | N/A |
EXTRA_COLUMN9 | N/A | N/A | N/A |
EXTRA_COLUMN10 | N/A | N/A | N/A |
CONFIGURED_DOMAIN_NAME | N/A | N/A | N/A |
NEW_PRIVILEGES_USED | N/A | N/A | N/A |