Gksyslog Messages
Vendor Documentation
Classification
Rule Name | Rule Type | Common Event | Classification |
---|---|---|---|
Gksyslog Messages | Base Rule | Session Information | Information |
Mapping with LogRhythm Schema
Device Key in Log Message | LogRhythm Schema | Data Type |
---|---|---|
severity | <severity> | Text/String |
processid | <processid> | Number |
CN | <login> | Text/String |
ou | <useragent> | Text/String |
dc | <domainorigin> | Text/String |
sname | <sname> | Text/String |
action | <action> | Text/String |
subject | <subject> | Text/String |