Skip to main content
Skip table of contents

Firewall Messages - v6.3.X

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification


Firewall Messages - v6.3.XBase RuleGeneral Firewall EventInformation
Firewall Related ConnectionSub RuleGeneral Firewall EventInformation
Connection AllowedSub RuleTraffic Allowed by Network FirewallNetwork Allow
Connection DiscardedSub RuleTraffic Denied by Network FirewallNetwork Deny
Connection ClosedSub RuleConnection ClosedNetwork Traffic
Connection Closed AbnormallySub RuleConnection ClosedNetwork Traffic
Connection ProgressSub RuleConnection StartingNetwork Traffic
Connection Interface ChangedSub RuleNetwork Interface Changed StateInformation
TCP Segment SYN Has No OptionsSub RuleTCP SYN ReceivedNetwork Traffic
TCP Checksum MismatchSub RuleGeneral Checksum InformationInformation
Logged HTTP URLSub RuleURL InformationInformation

Mapping with LogRhythm Schema

Device Key in Log MessageLogRhythm SchemaData Type
severity<severity>Text/String/Number
Version

<version>

Number
vmid<vmid>Number
command<command>Text/String
requestURL<url>Text/String
in<packetsin>Number
out<packetsout>Number
app<object>Text/String/Number
deviceFacility<objectname>Text/String
msg<subject>Text/String
destinationTranslatedPort<dport>Number
sourceTranslatedPort<sport>Number
destinationTranslatedAddress<dnatip>IP Address
sourceTranslatedAddress<snatip>IP Address
act<action>Text/String
deviceinboundinterface<sinterface>Text/String/Number
proto<protnum>Number
dpt<dport>Number
spt<sport>Number
dst<dip>IP Address
src<sip>IP Address
dvchost<dname>Text/String/Number
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.