General Connection Messages

Vendor Documentation

Classification

Rule Name

Rule Type

Classification

Common Event

General Connection Messages

Base Rule

Operations : Network Traffic

General Connection Messages

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

N/A

<sip>

Ip Address

N/A

<dip>

Ip Address

N/A

<sport>

Number

N/A

<vmid>

Text/String/Number

N/A

<dport>

Number

N/A

<snatip>

Number

N/A

<dnatip>

Number

N/A

<protname>

Text/String

N/A

<login>

Text/String

N/A

<parentprocesspath>

Text/String

N/A

<object>

Text/String

N/A

<useragent>

Text/String

N/A

<url>

Text/String

N/A

<group>

Text/String

N/A

<action>

Text/String

N/A

<result>

Text/String

N/A

<status>

Text/String/Number

N/A

<bytesin>

Number

N/A

<bytesout>

Number