Skip to main content
Skip table of contents

IPSec Messages

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

IPSec MessagesBase RuleIPSec Connection InformationInformation
VMID 37124 : Preshared Key MismatchSub RuleIKE Proposal Match FailureError
VMID 37127 : IPSec Phase 1Sub RuleIKE Initiator: Phase 1 NegotiationActivity
VMID 37129 : IPSec Phase 2Sub RuleIKE Initiator: Phase 2 NegotiationActivity
VMID 37134 : IPSec Phase 1 DeleteSub RuleIKE Initiator: Phase 1 NegotiationActivity
VMID 37141 : IPSec Tunnel StatisticsSub RuleGeneral TUNNEL MessageInformation
VMID 37133 : IPSec SA InstallSub RuleGeneral IKE MessageInformation
VMID 37128 : IPSec Phase 2Sub RuleIKE TerminatedError
VMID 37122 : IPSec Phase 2Sub RuleIKE Initiator: Phase 2 NegotiationActivity
VMID 37204 : IPSec Tunnel StatisticsSub RuleGeneral TUNNEL MessageInformation
VMID 37135 : IPSec Phase 2 DeleteSub RuleIKE Initiator: Phase 2 NegotiationActivity
VMID 37191 : IPSec Phase 1Sub RuleIKE Initiator: Phase 1 NegotiationActivity
VMID 37121 : IPSec Phase 1 ErrorSub RuleAuthentication Failure ActivityAuthentication Failure
VMID 37130 : FailureSub RuleIKE Proposal Match FailureError
VMID 37188 : Not Match Local PolicySub RuleIKE Proposal Match FailureError

Mapping with LogRhythm Schema  

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
level<severity>Text/StringN/A
logid

<vmid>

<tag1>

NumberIt is a unique 10-digit identifier for that specific log.
remip<sip>IP AddressIP Address
locip<dip>IP AddressN/A
remport<sport>NumberN/A
locport<dport>NumberN/A
outintf<dinterface>Text/StringN/A
user<login>Text/StringN/A
vd<domainorigin>Text/StringN/A
action<process>Text/StringN/A
cookies<object>Text/StringN/A
vpntunnel<subject>Text/StringN/A
group<group>Text/StringN/A
status<command>Text/StringN/A
rcvdbyte<bytesin>NumberN/A
sentbyte<bytesout>NumberN/A
duration<duration>NumberN/A
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.