LogRhythm KB Admin Service

Classification

Rule Name

Rule Type

Common Event

Classification

LogRhythm KB Admin Service

Base Rule

File Download

Information

EVID 1001 : KB Download Success

Sub Rule

Object Downloaded

Access Success

EVID 1002 : KB Download Success

Sub Rule

Object Downloaded

Access Success

EVID 1003 : No Deployment Record Found For License

Sub Rule

Download Object Failure

Access Failure

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

Provider Name

<vendorinfo>

Text/String

EventID Qualifiers

<vmid>

Number

Level

<severity>

Text/String

Computer

<dname>

Text/String

N/A

<object>

Text/String

N/A

<objectname>

Text/String