MsiInstaller : Installer Close Messages
Classification
Rule Name | Rule Type | Common Event | Classification |
---|---|---|---|
MsiInstaller : Installer Close Messages | Base Rule | General INSTALLER Message | Information |
EVID 11308 : Installer Source File Not Found | Sub Rule | General MsiInstaller Error | Error |
EVID 11707 : Install Completed Successfully | Sub Rule | Software Installed | Configuration |
EVID 11708 : Install Failure | Sub Rule | Add Object Failure | Access Failure |
EVID 11724 : Uninstall Complete | Sub Rule | Object Deleted/Removed | Access Success |
EVID 11728 : Configuration Completed | Sub Rule | Object Attribute Modified | Access Success |
Mapping with LogRhythm Schema
Device Key in Log Message | LogRhythm Schema | Data Type |
---|---|---|
Provider name | <vendorinfo> | Text/String |
Eventid | <vmid> | Number |
Level | <severity> | Text/String |
Computer | <dname> | Text/String |
userid | <domain> | Text/String |
N/A | <login> | Text/String |
product | <process> | Text/String |
N/A | <subject> | Text/String |
N/A | <object> | Text/String |