Skip to main content
Skip table of contents

Notable Characteristics Event

Vendor Documentation

Classification

Rule Name

Rule Type

Classification

Common Event

Notable Characteristics EventBase Rule Information  General Information

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

Schema Description

Header (logVer)N/AN/ACEF format version
Header (vendor)N/AN/AAppliance vendor
Header (pname)N/AN/AAppliance product
Header (pver)N/AN/AAppliance version
Header (eventid)N/AN/ASignature ID
Header (eventName)<vendorinfo>Text/StringDescription
Header (severity)<severity>NumberSeverity
cs1N/AN/AViolated policy name
cs1LabelN/AN/AViolated policy name label
cs2<policy>Text/StringViolated event analysis
cs2LabelN/AN/AViolated event analysis label
deviceExternalIdN/AN/AAppliance GUID
dvcN/AN/AAppliance IP address
dvchostN/AN/AAppliance host name
dvcmacN/AN/AAppliance MAC address
fileHash<hash>Text/String/NumberSHA1
fileType<objecttype>Text/String/NumberReal file type
fname<object>Text/String/NumberFile name
fsize<size>NumberFile size
msg<subject>Text/String/NumberDetails
rtN/AN/ALog generation time
Format: Unix time stamp (number of milliseconds since Jan 01 1970 UTC)
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.