Groupmod Changed GID

Classification

Rule Name

Rule Type

Common Event

Classification

Groupmod Changed GID

Base Rule

Group Attribute Modified

Account Modified

Changed Group GID To Root

Sub Rule

Group Attribute Modified

Account Modified

Changed Group GID

Sub Rule

Group Attribute Modified

Account Modified

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

N/A

<process>

Text\String

N/A

<group>

Text\String

N/A

<tag1>

Text\String