Network Connection Ingress Event

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

Network Connection Ingress Event

Base Rule

General Connection Messages

Network Traffic

Network Connection Event : Inbound

Sub Rule

General Network Traffic

Network Traffic

Network Connection Event : Outbound

Sub Rule

General Network Traffic

Network Traffic

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

vmid

<vmid>

Text/String

direction

<tag1>

Text/String

domain

<url>

Text/String

dst

<dip>

IP Address

dstport

<dport>

Number

md5

<objectname>

<hash>

Text/String

pid

<processid>

Number

process_path

<process>

Text/String

proto

<protnum>

Number/Text/String

src

<sip>

IP Address

srcport

<sport>

Number