Network Firewall Flow Logs

Classification

Rule Name

Rule Type

Classification

Common Event

Network Firewall Flow Logs

Base Rule

Operations :Network Traffic

General Firewall Log

Traffic Accepted

Sub Rule

Network Allow

Traffic Allowed by Network Firewall

Traffic Denied

Sub Rule

Network Deny

Traffic Denied by Network Firewall

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

N/A

<severity>

Text/String

N/A

<policy>

Text/String

N/A

<command>

Text/String

N/A

<sinterface>

Text/String

N/A

<dinterface>

Text/String

N/A

<smac>

Text/String

N/A

<sip>

IP Address

N/A

<dip>

IP Address

N/A

<protname>

Text/String

N/A

<sport>

Number

N/A

<dport>

Number