Syslog - Generic Linux OS: Group Modified

Vendor Documentation

N/A

Classification

Rule Name

Rule Type

Common Event

Classification

Group Modified

Base Rule

Group Attribute Modified

Account Modified

Group Name Changed

Sub Rule

Group Name Modified

Account Modified

Group ID Changed

Sub Rule

Group Attribute Modified

Account Modified

Groupmod Emergency Message

Sub Rule

General Emergency Log Message

Critical

Groupmod Alert Message

Sub Rule

General Alert

Critical

Groupmod Critical Message

Sub Rule

General Critical

Critical

Groupmod Error Message

Sub Rule

General Error

Error

Groupmod Warning Message

Sub Rule

General Warning

Warning

Groupmod Notice Message

Sub Rule

General Notice

Information

Groupmod Information Message

Sub Rule

General Information

Information

Groupmod Debug Message

Sub Rule

General Debug Message

Information

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

Schema Description

N/A

<severity>

Text/String

N/A

N/A

<tag1>

Text/String

N/A

N/A

<dip>

IP Address

N/A

N/A

<dname>

Text/String

N/A

N/A

<process>

Text/String

N/A

N/A

<processid>

Number

N/A

N/A

<subject>

Text/String

N/A

N/A

<group>

Text/String

N/A

N/A

<tag2

Text/String

N/A