Metric Login Messages

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

Metric Login Messages

Base Rule

LOGIN_INFORMATION

Information

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

severity

<severity>

Text/String

originatingIPAddress

<sip>

IP Address

originatingHostNam

<sname>

Text/String

userID

<login>

Text/String

type

<action>

Text/String