Skip to main content
Skip table of contents

Identity Awareness

Vendor Documentation

Classification

Rule NameRule TypeCommon EventClassification
Identity AwarenessBase RuleGeneral Firewall LogNetwork Traffic
Identity Awareness : Control TrafficSub RuleGeneral Firewall LogNetwork Traffic
Identity Awareness : UpdateSub RuleSoftware UpdatedConfiguration
Identity Awareness : LogoutSub RuleUser LogoffAuthentication Success
Identity Awareness : AuthCrypt FailedSub RuleUser Logon FailureAuthentication Failure
Identity Awareness : Authcrypt SuccessSub RuleUser LogonAuthentication Success
Identity Awareness : LoginSub RuleUser LogonAuthentication Success
Identity Awareness : LogoffSub RuleUser LogoffAuthentication Success

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

Product<version>Number/Text
Origin<sender>Number/Text
Action<action>Number/Text
Action<tag1>Number/Text
SIP<sip>Number
SPort<sport>Number
DIP<dip>Number
DPort<dport>Number
Protocol<protname>Number/Text
IFName<sinterface>Number
IFDirection<tag2>Number/Text
Info<vendorinfo>Number/Text
XlateSIP<snatip>Number/Text
XlateDIP<dnatip>Number/Text
User<login>Number/Text
src_user_name<login>Number/Text
domain_name<domain>Number/Text
termination_reason<reason>Text/String
duration<milliseconds>Number
identity_type<objecttype>Text/String
description<vendorinfo>Number/Text
auth_status<status>Text/String
auth_method<sessiontype>Number/Text
src_user_group<group>Number/Text
src_machine_name<sname>Number/Text
PolicyName<policy>Number/Text


JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.