FireWallConfig Messages 1

Classification

Rule Name

Rule Type

Common Event

Classification

FireWallConfig Messages 1

Base Rule

General Information

Information

Firewall Rule Created

Sub Rule

Policy Created : Firewall/ACL

Policy

Firewall Rule Deleted

Sub Rule

Policy Disabled : Firewall/ACL

Policy

Firewall Rule Enabled

Sub Rule

Policy Enabled : Firewall/ACL

Policy

Firewall Rule Disabled

Sub Rule

Policy Disabled : Firewall/ACL

Policy

Firewall Rule Changed

Sub Rule

Policy Modified : Firewall/ACL

Policy

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

N/A

<vmid>

Text\String

N/A

<severity>

Text\String

N/A

<sip>

IP Address

N/A

<login>

Text\String

N/A

<object>

Text\String

N/A

<tag1>

Text\String