Skip to main content
Skip table of contents

MS Windows Log Messages

Classification

Rule Name

Rule Type

Common Event

Classification

MS Windows Log MessagesBase RuleWindows Informational EventInformation
EVID 64 : Windows Certificate MessagesSub RuleWindows Warning EventWarning
EVID 257 : Defrag MessagesSub RuleGeneral O&O Defrag ErrorError
EVID 258 : Defarg InformationSub RuleGeneral O&O Defrag InformationInformation
EVID 1008 : Perflib Event MessageSub RuleGeneral Perflib ErrorError
EVID 4005 : Logon Process TerminatedSub RuleGeneral Winlogon InformationInformation
EVID 6000 : Winlogon InformationSub RuleGeneral Winlogon InformationInformation
EVID 6003 : Winlogon Information MessagesSub RuleGeneral Winlogon InformationInformation

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

Name<vendorinfo>Text/String
Eventid<vmid>Number
Level<severity>Text/String
Computer<dname>Text/String
ThreadID<session>Number
N/A<process>Text/String
ProcessID<processid>Number
N/A<object>Text/String
N/A<objectname>Text/String
N/A<subject>Text/String
Version<version>Number
N/A<useragent>Text/String
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.