Network Connection Ingress Event
Vendor Documentation
Classification
Rule Name | Rule Type | Common Event | Classification |
---|---|---|---|
Network Connection Ingress Event | Base Rule | General Connection Messages | Network Traffic |
Network Connection Event : Inbound | Sub Rule | General Network Traffic | Network Traffic |
Network Connection Event : Outbound | Sub Rule | General Network Traffic | Network Traffic |
Mapping with LogRhythm Schema
Device Key in Log Message | LogRhythm Schema | Data Type |
vmid | <vmid> | Text/String |
direction | <tag1> | Text/String |
domain | <url> | Text/String |
dst | <dip> | IP Address |
dstport | <dport> | Number |
md5 | <objectname> <hash> | Text/String |
pid | <processid> | Number |
process_path | <process> | Text/String |
proto | <protnum> | Number/Text/String |
src | <sip> | IP Address |
srcport | <sport> | Number |