Vendor Documentation
Classification
|
Rule Name |
Rule Type |
Common Event |
Classification |
|---|---|---|---|
|
MGMD Events |
Base Rule |
General Information Log Message |
Information |
Mapping with LogRhythm Schema
|
Device Key in Log Message |
LogRhythm Schema |
Data Type |
Schema Description |
|---|---|---|---|
|
Event ID |
<vmid> |
Number |
Event ID 2601, 2602, 2603, 2604, 2605, 2606, 2607, 2608, 2609, 2610, 2611, 2612, 2613, 2614, 2615, 2616, 2617, 2618, 2619, 2620, 2621, 2622 |
|
Severity |
<severity> |
Text/String |
For All: Information
|
|
Message |
<subject>
|
Text/String |
Event ID 2601:
|
|
|
<subject>
|
Text/String/IP Address |
Event ID 2602:
|
|
|
<subject>
|
Text/String/Number |
Event ID 2603:
|
|
|
<subject>
|
Text/String |
Event ID 2604:
|
|
|
<subject>
|
Text/String/IP Address |
Event ID 2605:
|
|
|
<subject>
|
Text/String |
Event ID 2606:
|
|
|
<subject>
|
Text/String/IP Address |
Event ID 2607:
|
|
|
<subject>
|
Text/String/Number/IP Address |
Event ID 2608:
|
|
|
<subject>
|
Text/String/IP Address |
Event ID 2609:
|
|
|
<subject>
|
Text/String/IP Address |
Event ID 2610:
|
|
|
<subject>
|
Text/String |
Event ID 2611:
|
|
|
<subject>
|
Text/String |
Event ID 2612:
|
|
|
<subject>
|
Text/String/Number |
Event ID 2613:
|
|
|
<subject>
|
Text/String |
Event ID 2614:
|
|
|
<subject>
|
Text/String/Number |
Event ID 2615:
|
|
|
<subject> |
Text/String |
Event ID 2616:
|
|
|
<subject> |
Text/String |
Event ID 2617:
|
|
|
<subject>
|
Text/String |
Event ID 2618:
|
|
|
<subject>
|
Text/String/IP Address |
Event ID 2619:
|
|
|
<subject>
|
Text/String/IP Address |
Event ID 2620:
|
|
|
<subject>
|
Text/String/IP Address |
Event ID 2621:
|
|
|
<subject>
|
Text/String/Number |
Event ID 2622:
|