Metric Login Messages
Vendor Documentation
Classification
| Rule Name | Rule Type | Common Event | Classification |
|---|---|---|---|
| Metric Login Messages | Base Rule | LOGIN_INFORMATION | Information |
Mapping with LogRhythm Schema
| Device Key in Log Message | LogRhythm Schema | Data Type |
|---|---|---|
| severity | <severity> | Text/String |
| originatingIPAddress | <sip> | IP Address |
| originatingHostNam | <sname> | Text/String |
| userID | <login> | Text/String |
| type | <action> | Text/String |