Mail_logs : LDAP
Vendor Documentation
Classification
| Rule Name | Rule Type | Classification | Common Event |
|---|---|---|---|
| Mail_logs : LDAP | Base Rule | Ops/Information | General LDAP Message |
| Mail_logs : LDAP : Drop query | Sub Rule | Ops/Information | General LDAP Message |
| Mail_logs : LDAP : RAT-based Bypass Of Query | Sub Rule | Ops/Information | General LDAP Message |
Mapping with LogRhythm Schema
| Device Key in Log Message | LogRhythm Schema | Data Type | Schema Description |
| <severity> | Text\String | ||
| MID | <session> | Number | |
| <subject> | Text\String | ||
| <reason> | Text\String | ||
| RID | <responsecode> | Number | |
| <sender> | Text\String |