IP Source Lockdown Events
Vendor Documentation
https://www.arubanetworks.com/techdocs/AOS-CX/10.07/HTML/5200-8214/Content/fir-int.htm https://www.arubanetworks.com/techdocs/AOS-CX/10.07/PDF/5200-8214.pdf |
Classification
Rule Name | Rule Type | Common Event | Classification |
---|---|---|---|
IP Source Lockdown Events | Base Rule | General Information Log Message | Information |
Mapping with LogRhythm Schema
Device Key in Log Message | LogRhythm Schema | Data Type | Schema Description |
Event ID | <vmid> | Number | Event ID 9801, 9802, 9803, 9804, 9805, 9806, 9807 |
Severity | <severity> | Text/String | For All: Information |
Message | <subject> | Text/String | Event ID 9801: |
| <subject> | Text/String | Event ID 9802: |
| <subject> | Text/String | Event ID 9803: |
| <subject> | Text/String | Event ID 9804: |
| <subject> | Text/String | Event ID 9805: |
| <subject> | Text/String | Event ID 9806: |
| <subject> | Text/String | Event ID 9807: |