Generic Blade Catch All

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

Generic Blade Catch All

Base Rule

General Traffic Log

Network Traffic

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

Product

<version>

Number/Text

Origin

<sender>

Number/Text

Action

<action>

Number/Text

Action

<tag1>

Number/Text

SIP

<sip>

Number

SPort

<sport>

Number

DIP

<dip>

Number

DPort

<dport>

Number

Protocol

<protname>

Number/Text

IFName

<sinterface>

Number

IFDirection

<tag2>

Number/Text

Reason

<reason>

Text/String

Rule

<command>

Number/Text

Info

<vendorinfo>

Number/Text

XlateSIP

<snatip>

Number/Text

XlateSport

<snatport>

Number/Text

XlateDIP

<dnatip>

Number/Text

XlateDPort

<dnatport>

Number/Text

User

<login>

Number/Text

matched_category

<subject>

Text/String

URL

<url>

Number/Text