Skip to main content
Skip table of contents

Syslog - Generic Linux OS: Login Messages

Vendor Documentation

N/A

Classification

Rule Name

Rule Type

Common Event

Classification

Login MessagesBase RuleLOGIN_INFORMATIONInformation
Logon FailureSub RuleUser Logon FailuredAuthentication Failure
Logon Session StartedSub RuleSession StartedOther Audit Success
Logon SuccessfulSub RuleUser LogonAuthentication Success
Login Emergency MessageSub RuleGeneral Emergency Log MessageCritical
Login Alert MessageSub RuleGeneral AlertCritical
Login Critical MessageSub RuleGeneral CriticalCritical
Login Error MessageSub RuleGeneral ErrorError
Login Warning MessageSub RuleGeneral WarningWarning
Login Notice MessageSub RuleGeneral NoticeInformation
Login Information MessageSub RuleGeneral InformationInformation
Login Debug MessageSub RuleGeneral Debug MessageInformation

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

Schema Description

N/A<severity>Text/StringN/A
N/A<tag1>Text/StringN/A
N/A<dip>IP AddressN/A
N/A<dname>Text/StringN/A
N/A<process>Text/StringN/A
N/A<processid>NumberN/A
N/A<subject>Text/StringN/A
N/A<tag2>Text/StringN/A
N/A<login>Text/StringN/A
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.