Syslog - LogRhythm Network Monitor (NetMon)
Device Details
Device Name | Syslog - LogRhythm Network Monitor |
Vendor | LogRhythm |
Device Type | Network Monitor |
Supported Model Name/Number | N/A |
Supported Software Version | N/A |
Collection Method | Syslog |
Configurable Log Output | N/A |
Log Source Type | Syslog - LogRhythm Network Monitor |
Log Processing Policy | LogRhythm Default V 2.0 |
Exceptions | N/A |
Additional Information |
Supported Log Messages
(List of LR tags used to parse the log information for each message type)
Type | Product Version | Supported Schema Fields |
---|---|---|
V 2.0 : Diagnostics Event | N/A | <severity>, <vmid>, <action> |
V 2.0 : End Of Flow Event | N/A | <severity>, <vmid>, <session>, <sip>, <dip>, <sport>, <dport>, <smac>, <dmac>, <protnum>, <processid>, <bytesin>, <bytesout>, <packetsin>, <seconds>, <command>, <group>, <dname>, <version>, <subject>, <domainimpacted>, <process>, <object>, <objectname> |
V 2.0 : Incremental Flow Event | N/A | <severity>, <vmid>, <session>, <sip>, <dip>, <sport>, <dport>, <smac>, <dmac>, <protnum>, <processid>, <bytesin>, <bytesout>, <packetsin>, <seconds>, <command>, <group>, <version>, <subject>, <domainimpacted>, <process>, <object>, <objectname>, <dname> |
Revision History
KB Version | Log Type | Change Type | Details |
---|---|---|---|
KB 7.1.671.0 | Syslog - LogRhythm Network Monitor | New Log Source Optimization (LSO) policy: LogRhythm Default v2.0 | Optimized new log processing policy for Syslog - LogRhythm Network Monitor. |