MCPD Messages

Classification

Rule Name

Rule Type

Common Event

Classification

MCPD Messages

Base Rule

General Information

Information

Invalid Node

Sub Rule

Unknown Host

Information

Invalid Url

Sub Rule

URL Information

Information

Policy Referenced By Multiple Virtuals

Sub Rule

General POLICY Information

Information

Password Changed

Sub Rule

Performing Password Change

Information

Subscription Removed

Sub Rule

General Information

Information

Setting Master Key

Sub Rule

General Information

Information

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

N/A

<severity>

Text/String

N/A

<vmid>

Number/Text/String

N/A

<session>

Text/String/Number

N/A

<process>

Text/String

N/A

<processid>

Number

N/A

<action>

Text/String

N/A

<object>

Text/String

N/A

<subject>

Text/String

N/A

<login>

Text/String

N/A

<parentprocesspath>

Text/String

N/A

<result>

Text/String

N/A

<tag1>

Text/String

N/A

<sname>

Text/String

N/A

<sip>

Number

N/A

<status>

Text/String