Skip to main content
Skip table of contents

Linux User And Group Addition Or Deletion

Classification

Rule Name

Rule Type

Classification

Common Event

Linux User And Group Addition Or DeletionBase RuleAccess GrantedAccess Granted Activity
Linux : User Account DeletedSub RuleAccount DeletedUser Account Deleted
Linux : User Account CreatedSub RuleAccount CreatedUser Account Created
Linux : User Password ModifiedSub RuleAccount ModifiedPassword Modified
Linux : Group CreatedSub RuleAccount CreatedGroup Created
Linux : Account Added To GroupSub RuleAccess GrantedAccount Added To Group
Linux : User Account Removed From GroupSub RuleAccess RevokedAccount Removed From Group
Linux : User Removed From GroupSub RuleAccess RevokedAccount Removed From Group
Linux : Group RemovedSub RuleAccount DeletedGroup Deleted
Linux : Group File UpdateSub RuleAccount ModifiedGroup Attribute Modified

Mapping with LogRhythm Schema  

Device Key in Log MessageLogRhythm SchemaData Type
N/A<severity>Text\String
N/A<sname>Text\String
N/A<login>Text\String
N/A

<account>

Text\String
N/A<processid>Number
N/A<process>Text\String
N/A

<object>

Text\String

N/A<objectname>Text\String
N/A<group>Text\String
N/A<tag1>Text\String
N/A<tag2>Text\String
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.