Gpasswd Messages 1
Classification
Rule Name | Rule Type | Common Event | Classification |
|---|---|---|---|
| Gpasswd Messages | Base Rule | Object Read | Access Success |
| Added User To Group | Sub Rule | Account Added To Group | Access Granted |
| Removed User From Group | Sub Rule | Account Removed From Group | Access Revoked |
Mapping with LogRhythm Schema
| Device Key in Log Message | LogRhythm Schema | Data Type |
| N/A | <process> | Text\String |
| N/A | <login> | Text\String |
| N/A | <account> | Text\String |
| N/A | <group> | Text\String |
| N/A | <tag1> | Text\String |