Microsoft Windows Bits Client Messages

Log Fields and Parsing

This section details the log fields available in this log message type, along with values parsed for both LogRhythm Default and LogRhythm Default v2.0 policies. A value of "N/A" (not applicable) means that there is no value parsed for a specified log field.

Log Field

LogRhythm Default

LogRhythm Default v2.0

Provider

N/A

N/A

EventID

<vmid>

N/A

Version

<version>

N/A

Level

<severity>

N/A

Task

N/A

N/A

Opcode

N/A

N/A

Keywords

N/A

N/A

TimeCreated

N/A

N/A

EventRecordID

N/A

N/A

Correlation

N/A

N/A

Execution

<processid>
<session>

N/A

Channel

<group>

N/A

Computer

<dname>

N/A

Security

<domain>
<login>

N/A

url

<url>

N/A

Message

<subject>

N/A

Log Processing Settings

This section details log processing changes made from the LogRhythm Default policy to LogRhythm Default v2.0. In some cases, base rules are broken down into sub-rules to appropriately parse log message types by their event types.

LogRhythm Default

Regex ID

Rule Name

Rule Type

Common Event

Classification

1012375

Microsoft Windows Bits Client Messages

Base Rule

General BITS Information

Information

EVID 16403: CCM Message Upload

Sub Rule

General UploadM Information

Information

EVID 203: BITS Provided Job Credentials Accepted.

Sub Rule

General Access Accept

Other Audit Success

EVID 204: BITS  Provided Job Credentials Rejected

Sub Rule

Failed To Acquire Credentials

Error

EVID 209: High Performance Property For BITS Job

Sub Rule

General Performance Information

Information

EVID 3:  BITS Service Created A New Job

Sub Rule

Job Started

Other Audit Success

EVID 302: BITS Service Has Started Successfully

Sub Rule

Service Started

Information

EVID 306: BITS  Loaded The Job List From Disk

Sub Rule

Load Event

Information

EVID 310: Initialization Failed For Peer Modules

Sub Rule

Initialization Failed

Error

EVID 311: Error In BITS Peer Transfer

Sub Rule

General Transfer Error

Error

EVID 4: Job Completion

Sub Rule

Task Completed

Information

EVID 5: Job Cancelled

Sub Rule

Task Was Cancelled

Warning

EVID 59: BITS Is Starting To Transfer

Sub Rule

Transfer Started

Network Traffic

EVID 60: BITS Has Stopped Transferring

Sub Rule

Data Transfer Stalled

Warning

EVID 61: BITS Has Stopped Transferring

Sub Rule

Data Transfer Stalled

Warning

LogRhythm Default v2.0

N/A