PAM_Unix : General Messages

Classification

Rule Name

Rule Type

Classification

Common Event

PAM_Unix : General Messages

Base Rule

Authentication Success

Authentication Activity

PAM_unix : Authentication Success

Sub Rule

Authentication Success

User Logon

PAM_unix : Authentication Failure

Sub Rule

Authentication Failure

Authentication Failure Activity

PAM_unix : Authentication Failure

Sub Rule

Authentication Failure

Authentication Failure Activity

PAM_unix : Authentication Attempt

Sub Rule

Authentication Success

Authentication Activity

PAM_unix : SSH Authentication Attempt

Sub Rule

Authentication Success

Authentication Activity

Cannot Get Password For User

Sub Rule

Authentication Failure

User Logon Failure : Bad Password

No Default Project For User

Sub Rule

Access Failure

Access Object Failure

Username Not Found

Sub Rule

Authentication Failure

User Logon Failure : Bad Username

User Cannot Join Project

Sub Rule

Access Failure

Access Object Failure

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

N/A

<sip>

IP Address

N/A

<login>

Text/String

N/A

<sessiontype>

Text/String

N/A

<process>

Text/String

N/A

<object>

Text/String

N/A

<tag1>

Text/String

N/A

<tag2>

Text/String