Skip to main content
Skip table of contents

IPS Events

Vendor Documentation

Classification

Rule NameRule TypeCommon EventClassification
IPS EventsBase RuleGeneral IPS MessageInformation
TCP/UDP Attack SignatureSub RuleGeneral Attack ActivityAttack
ICMP Attack SignatureSub RuleGeneral Attack ActivityAttack
Other Attack SignatureSub RuleGeneral Attack ActivityAttack
ICMP Attack AnomalySub RuleProtocol AnomalyAttack
Attack AnomalySub RuleGeneral IDS Anomaly CriticalCritical
TCP/UDP Attack AnomalySub RuleProtocol AnomalyAttack
TCP/UDP Attack Signature DroppedSub RuleFailed General Attack ActivityFailed Attack
ICMP Attack Signature DroppedSub RuleFailed General Attack ActivityFailed Attack
Other Attack Signature DroppedSub RuleFailed General Attack ActivityFailed Attack
ICMP Attack Anomaly DroppedSub RuleFailed Protocol AnomalyFailed Attack
Attack Anomaly DroppedSub RuleFailed Protocol AnomalyFailed Attack
TCP/UDP Attack Anomaly DroppedSub RuleFailed Protocol AnomalyFailed Attack

Mapping with LogRhythm Schema  

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
logid<vmid>NumberThe ID (logid) is a 10-digit field. It is a unique identifier for that specific log.
level<severity>Text\StringEach log entry contains a Level (level) field that indicates the estimated severity of the event that caused the log entry.
srcip<sip>IP AddressIP address of the traffic’s origin.
dstip<dip>IP AddressDestination IP address for the web.
srcport<sport>NumberPort number of the traffic's origin.
dstport<dport>NumberPort number of the traffic's destination.
srcintf<sinterface>Text\StringInterface name of the traffic's origin.
dstintf<dinterface>Text\StringInterface of the traffic's destination.
proto<protnum>NumberThe protocol used by web traffic (tcp by default).
service<protname>Text\StringN/A
hostname<domainorigin>Text\StringN/A
vd<domainimpacted>Text\StringName of the virtual domain in which the log message was recorded.
sessionid<session>NumberID for the session.
subtype<process>Text\StringN/A
attack<object>Text\StringN/A
msg<subject>Text\StringN/A
attack<threatname>Text\StringN/A
attackid<threatid>NumberN/A
ref<url>Text\StringN/A
profile<group>Text\StringN/A
action<command>Text\StringN/A
action<tag1>Text\StringN/A
eventtype<tag2>NumberN/A
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.