LSO - MS Windows Event Logging : Français - Security
This document explains the changes required to switch over and upgrade to MS Windows Event Logging XML - Security log source type to enable new Message Processing Engine (MPE) rules developed during the Log Source Optimization (LSO) project.
Log Source Stabilization (LSS) does not support ADFS Events with the updated MPE rules and log processing policy (LogRhythm Default v2.0). ADFS Events are supported separately with MS Windows Event Logging XML - ADFS. If you are using Microsoft Active Directory Federation Services (ADFS) and streaming ADFS logs through Windows Security log source types, we recommend using log source virtualization to stream MS Windows Event Logging XML - ADFS log messages.
The following table lists the log message types supported in the current MPE rules. Each linked page contains detailed information on parsing changes and new log processing settings.
This section details log processing policy updates made to AIE Rules, system reports and templates, tails, and investigations as part of LSO.
Changes made for LSO may impact downstream analytical components in LogRhythm. It is recommended that you review MPE policies, parsing rules, and log processing settings to assess the potential impact to your environment and custom analytical components, including saved investigations, dashboards, and fields mapped with SmartResponse Plugins.
Updates to AIE Rules
The table below indicates changes made to AIE Rules using the new policy LogRhythm Default v2.0 with log source type MS Windows Event Logging XML - Security. The Change Details column indicates where the new log source type was added.
AIE Rules
Change Details
NERC-CIP : Account Locked or Disabled Rule
Removed Group by of Host (Origin)
Updates to System Reports
The table below indicates changes made to System Reports using the new policy LogRhythm Default v2.0 with log source type MS Windows Event Logging XML - Security.
Report Name
Change Details
FISMA : Processes By User
Added a new line to the Include Filter:
Operator. Or Previous
Field. Process Name
Filter Mode. Is Not
Filtered Values. NOTHING
NEI : Processes By User
Added a new line to the Include Filter:
Operator. Or Previous
Field. Process Name
Filter Mode. Is Not
Filtered Values. NOTHING
NRC : Processes By User
Added a new line to the Include Filter:
Operator. Or Previous
Field. Process Name
Filter Mode. Is Not
Filtered Values. NOTHING
PCI-DSS : Invalid CDE => Internet Comm Details
Added a new line to the Include Filter:
Operator. Or Previous
Field. IP Address (Impacted)
Filter Mode. Is Not
Filtered Values. NOTHING
PCI-DSS : Invalid DMZ => Internal Comm Details
Added a new line to the Include Filter:
Operator. Or Previous
Field. IP Address (Impacted)
Filter Mode. Is Not
Filtered Values. NOTHING
PCI-DSS : Invalid Internet => Internal Comm Details
Added a new line to the Include Filter:
Operator. Or Previous
Field. IP Address (Impacted)
Filter Mode. Is Not
Filtered Values. NOTHING
PCI-DSS : Invalid Internet => CDE Comm Details
Added a new line to the Include Filter:
Operator. Or Previous
Field. IP Address (Impacted)
Filter Mode. Is Not
Filtered Values. NOTHING
PCI-DSS : Invalid Internet => DMZ Comm Details
Added a new line to the Include Filter:
Operator. Or Previous
Field. IP Address (Impacted)
Filter Mode. Is Not
Filtered Values. NOTHING
Updates to System Report Templates
The table below indicates changes made to Report Templates using the new policy LogRhythm Default v2.0 with log source type MS Windows Event Logging XML - Security.
Template Name
Change Details
Log Summary by Entity, Log Host, iApp, Event, Login, Object
Added Process field after Object.
New Report name: Log Summary by Entity, Log Host, iApp, Event, Login, Object, Process
Updates to System Tails
No changes
Updates to System Investigations
No changes
JavaScript errors detected
Please note, these errors can depend on your browser setup.
If this problem persists, please contact our support.