Syslog - Generic Linux OS: Gpasswd Messages

Vendor Documentation

N/A

Classification

Rule Name

Rule Type

Common Event

Classification

Gpasswd Messages

Base Rule

General Information

Information

Group Membership Set

Sub Rule

Group Membership Information

Information

User Removed From Group

Sub Rule

Account Removed From Group

Access Revoked

User Added To Group

Sub Rule

Account Added To Group

Access Granted

Gpasswd Emergency Message

Sub Rule

General Emergency Log Message

Critical

Gpasswd Alert Message

Sub Rule

General Alert

Critical

Gpasswd Critical Message

Sub Rule

General Critical

Critical

Gpasswd Error Message

Sub Rule

General Error

Error

Gpasswd Warning Message

Sub Rule

General Warning

Warning

Gpasswd Notice Message

Sub Rule

General Notice

Information

Gpasswd Information Message

Sub Rule

General Information

Information

Gpasswd Debug Message

Sub Rule

General Debug Message

Information

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

Schema Description

N/A

<severity>

Text/String

N/A

N/A

<tag1>

Text/String

N/A

N/A

<dip>

IP Address

N/A

N/A

<dname>

Text/String

N/A

N/A

<process>

Text/String

N/A

N/A

<processid>

Number

N/A

N/A

<subject>

Text/String

N/A

N/A

<account>

Text/String

N/A

N/A

<tag2>

Text/String

N/A

N/A

<login>

Text/String

N/A

N/A

<group>

Text/String

N/A