Login Denied and Permitted

Classification

Rule Name

Rule Type

Common Event

Classification

Login Denied and Permitted

Base Rule

Authentication Activity

Authentication Success

ASA-6-605005 : Logon Successful

Sub Rule

User Logon

Authentication Success

ASA-6-605004 : Logon Failure

Sub Rule

User Logon Failure

Authentication Failure

FWSM-4-605005 : Logon Successful

Sub Rule

User Logon

Authentication Success

FWSM-6-605004 : Logon Failure

Sub Rule

User Logon Failure

Authentication Failure

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

N/A

<vmid>

Number

N/A

<severity>

Number

N/A

<sip>

Number

N/A

<sname>

Text/String

N/A

<dip>

Number

N/A

<dname>

Text/String

N/A

<sport>

Number

N/A

<dport>

Number

N/A

<protname>

Text/String

N/A

<login>

Text/String

N/A

<tag1>

Text/String