Login Messages

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

Login Messages

Base Rule

User Logon

Authentication Success

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

Schema Description

type

<vmid>

Text/String

Type of the record.

msg

<serialnumber>

Number

Records a time stamp and a unique ID of the record in the form audit(time_stamp:ID).

pid

<processid>

Number

Records the Process ID (PID).

uid

<login>

Number

Records the real user ID of the user who started the analyzed process.

old-auid

N/A

N/A

Records the prior Audit User ID (Audit ID) associated with the session.

auid

N/A

N/A

Records the current Audit user ID.

tty

N/A

N/A

Records the name of the controlling terminal. The value (none) is used if the process has no controlling terminal.

old-ses

N/A

N/A

Records the prior session ID.

ses

<session>

Number

Records the current session ID of the session from which the analyzed process was invoked.

res

<result>

Number

Records the result of the operation that triggered the Audit event.