Network Connection Ingress Event
Vendor Documentation
Classification
Rule Name | Rule Type | Common Event | Classification |
|---|---|---|---|
| Network Connection Ingress Event | Base Rule | General Connection Messages | Network Traffic |
| Network Connection Event : Inbound | Sub Rule | General Network Traffic | Network Traffic |
| Network Connection Event : Outbound | Sub Rule | General Network Traffic | Network Traffic |
Mapping with LogRhythm Schema
| Device Key in Log Message | LogRhythm Schema | Data Type |
| vmid | <vmid> | Text/String |
| direction | <tag1> | Text/String |
| domain | <url> | Text/String |
| dst | <dip> | IP Address |
| dstport | <dport> | Number |
| md5 | <objectname> <hash> | Text/String |
| pid | <processid> | Number |
| process_path | <process> | Text/String |
| proto | <protnum> | Number/Text/String |
| src | <sip> | IP Address |
| srcport | <sport> | Number |