Group Entry Messages

Classification

Rule Name

Rule Type

Classification

Common Event

Group Entry Messages

Base Rule

Information

Group Information

Missing GIDNumber Value

Sub Rule

Warning

Group Identification Message

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

SYSD

<severity>

Text/String

Mar 20 16:25:21

<dname>

Text/String

N/A

<process>

Text/String

12556:a8580e

<object>

Text/String

CN

<objectname>

Text/String

OU

<group>

Text/String

OU

N/A

N/A

OU

N/A

N/A

OU

N/A

N/A

DC

<domain>

Text/String

DC

<tag1>

Text/String