Syslog - Generic Linux OS: Journal Daemon Messages

Vendor Documentation

N/A

Classification

Rule Name

Rule Type

Common Event

Classification

Journal Daemon Messages

Base Rule

General Information

Information

Journal Daemon Started

Sub Rule

Service Started

Information

Journal Daemon Stopped

Sub Rule

Process Stopping

Information

Journal Emergency Message

Sub Rule

General Emergency Log Message

Critical

Journal Alert Message

Sub Rule

General Alert

Critical

Journal Critical Message

Sub Rule

General Critical

Critical

Journal Error Message

Sub Rule

General Error

Error

Journal Warning Message

Sub Rule

General Warning

Warning

Journal Notice Message

Sub Rule

General Notice

Information

Journal Information Message

Sub Rule

General Information

Information

Journal Debug Message

Sub Rule

General Debug Message

Information

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

Schema Description

N/A

<severity>

Text/String

N/A

N/A

<tag1>

Text/String

N/A

N/A

<dip>

IP Address

N/A

N/A

<dname>

Text/String

N/A

N/A

<process>

Text/String

N/A

N/A

<processid>

Number

N/A

N/A

<subject>

Text/String

N/A

N/A

<tag2>

Text/String

N/A