General Authentication 2

Classification

Rule Name

Rule Type

Common Event

Classification

General Authentication 2

Base Rule

Authentication Activity

Authentication Success

User Login Success

Sub Rule

User Logon

Authentication Success

Root Login Success

Sub Rule

User Logon

Authentication Success

Password Failed For User

Sub Rule

User Logon Failure : Bad Password

Authentication Failure

Password Failed For Superuser

Sub Rule

User Logon Failure : Bad Password

Authentication Failure


Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

N/A

<dname>

Number/Text

N/A

<process>

Text/String

N/A

<sname>

Text/String

N/A

<tag1>

Text/String

N/A

<login>

Text/String

N/A

<sip>

Number

N/A

<sport>

Number