Pattern 1 : Status Code Messages

Classification

Rule Name

Rule Type

Common Event

Classification

Pattern 1 : Status Code Messages

Base Rule

General Information

Information

Session Deleted Due To Inactivity Or Errors

Sub Rule

Session Error

Error

Failed To Read Assigned IP

Sub Rule

Read Failure

Error

Session Deleted Due To User Logout Request

Sub Rule

Session Ended

Information

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

N/A

<vmid>

Number

N/A

<severity>

Text/String

N/A

<process>

Text/String

N/A

<processid>

Number