Logging Lost Messages
Classification
Rule Name | Rule Type | Classification | Common Event |
|---|---|---|---|
| Logging Lost Messages | Base Rule | Information | General Logging Information |
| Messages Lost | Sub Rule | Error | Log Data Lost |
| Began Losing Messages | Sub Rule | Error | Error Logging Information |
Mapping with LogRhythm Schema
Device Key in Log Message | LogRhythm Schema | Data Type |
|---|---|---|
| SLOG | <severity> | Text/String |
| Mar 20 17:50:17 | <dname> | Text/String |
| N/A | <command> | Text/String |
| N/A | <vmid> | Number |
| N/A | <process> | Text/String |
| messages from pid | <processid> | Number |
| N/A | <tag1> | Text/String |
| N/A | <amount> | Number |
| due to | <object> | Text/String |