Skip to main content
Skip table of contents

Gatekeeper Syslog Messages

Vendor Documentation

Classification

Rule NameRule TypeCommon EventClassification
Gatekeeper Syslog MessagesBase RuleGeneral WarningWarning
Timeout Expired MessagesSub RuleUser Timed Out And DisconnectedWarning
User Added MessagesSub RuleHost Information AddedInformation
Bad User ID MessagesSub RuleUser Logon Failure : Bad UsernameAuthentication Failure
Created Policy MessagesSub RulePolicy Created : User/PasswordPolicy
Download MessagesSub RuleObject DownloadedAccess Success
GIT Server Updated MessagesSub RuleGeneral Windows Server Update Services InformationInformation
Log Records MessagesSub RuleGeneral Information Log MessageInformation
Login Successful MessagesSub RuleInfo : LOGIN_INFORMATIONInformation
Logout MessagesSub RuleLogout RequestInformation
Port Scan MessagesSub RulePort ScanReconnaissance
Administration Section MessagesSub RuleGeneral Administration EventOther Audit
Configuration Section MessagesSub RuleConfiguration InformationInformation
Unauthorized Access MessagesSub RuleUnauthorized ActivityMisuse
User Update MessagesSub RuleUpdated User DataInformation
Updated Policy MessagesSub RulePolicy Modified : ObjectPolicy
Uploaded Object MessagesSub RuleFile UploadedInformation
Login Timeout MessagesSub RuleInfo : LOGIN_TIMED_OUTInformation

Mapping with LogRhythm Schema

Device Key in Log MessageLogRhythm SchemaData Type
severity<severity>Text/String
processid<processid>Number
Private IP<sip>IP Address
Nat/Proxy IP<snatip>IP Address
user<login>Text/String
Transaction<action>Text/String
Address<dip>IP Address
Device Name:<sname>Text/String
User Group<group>Text/String
Port<sport>Number
Access/Protocol<protname>Number
Details

<subject>

Text/String
N/A<tag1>Text/String
Services<useragent>Text/String
object<object>Text/String
kilobytes<kilobytes>Number
url<url>Text/String
dname<dname>Text/String
dc<domainorigin>Text/String
policy<policy>Text/String
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.