IKE Initiator Quick Mode Message

Classification

Rule Name

Rule Type

Common Event

Classification

IKE Initiator Quick Mode Message

Base Rule

IKE Information-Only Event

Information

IKE Initiator: Starting QM

Sub Rule

IKE Initiator: Start Quick Mode (Phase 2)

Information

IKE Initiator: 1st QM

Sub Rule

IKE Initiator: Start Quick Mode (Phase 2)

Information

IKE Initiator: 2nd QM

Sub Rule

IKE Initiator: Start Quick Mode (Phase 2)

Information

IKE Initiator: 3rd QM

Sub Rule

IKE Initiator: Start Quick Mode (Phase 2)

Information

Mapping with LogRhythm Schema 

Device Key in Log Message

LogRhythm Schema

Data Type

N/A

<vmid>

Number

group

<group>

Number

IP

<sip>

Number

N/A

<protname>

Text/String

2nd QM

<tag1>

Text/String/Number

msg id

<session>

Number/Text