PAM UNIX User Check Pass

Classification

Rule Name

Rule Type

Classification

Common Event

PAM UNIX User Check Pass

Base Rule

Authentication Success

Authentication Activity

PAM UNIX User Check Pass : Unknown Login

Sub Rule

Authentication Failure

Authentication Failure Activity

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

N/A

<severity>

Text/String

N/A

<process>

Text/String

N/A

<processid>

Number

pam_unix

<subject>

Text/String

user

<login>

Text/String