Invalid User (Audit)

Classification

Rule Name

Rule Type

Classification

Common Event

Invalid User

Base Rule

Audit : Authentication Failure

User Logon Failure : Bad Username

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

N/A

<severity>

Text/String

N/A

<dname>

Text/String

N/A

<process>

Text/String

N/A

<sip>

IP address

N/A

<command>

Text/String

N/A

<login>

Text/String

N/A

<processid>

Number