Skip to main content
Skip table of contents

Firewall Messages

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification


Firewall MessagesBase RuleGeneral Firewall LogNetwork Traffic
1004 : FW_Related-ConnectionSub RuleTraffic Allowed by Host FirewallNetwork Allow
70022 : Connection_Closed-AbnormallySub RuleConnection TerminatedNetwork Traffic
70026 : Connection_ProgressSub RuleConnection StartingNetwork Traffic
70019 : Connection_DiscardedSub RuleConnection ClosedNetwork Traffic
70018 : Connection_AllowedSub RuleTraffic Allowed by Host FirewallNetwork Allow
71257 : TCP_Segment-SYN-No-OptionsSub RuleTCP SYN ReceivedNetwork Traffic
70021 : Connection_ClosedSub RuleConnection ClosedNetwork Traffic

Mapping with LogRhythm Schema

Device Key in Log MessageLogRhythm SchemaData Type
Version

<version>

Number
vmid<vmid>Number
objectname<objectname>Text/String
severity<severity>Text/String/Number
spt<sport>Number
dst<dip>IP Address
request<object>Text/String
app<session>Text/String/Number
act<command>Text/String
msg<object>Text/String
deviceoutboundinterface<sinterface>Text/String/Number
deviceinboundinterface<dinterface>Text/String/Number
proto<protnum>Number
dpt<dport>Number
in<bytesin>Number
out<bytesout>Number
src<sip>IP Address
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.