Pattern 10 : User Modifications
Classification
Rule Name | Rule Type | Common Event | Classification |
|---|---|---|---|
| Pattern 10 : User Modifications | Base Rule | User Account Attribute Modified | Account Modified |
| User Added To Group | Sub Rule | Account Added To Group | Access Granted |
| User Removed From Group | Sub Rule | Account Removed From Group | Access Revoked |
| User Password Locked | Sub Rule | Account Locked | Access Revoked |
| User Password Unlocked | Sub Rule | Account Unlocked | Access Granted |
Mapping with LogRhythm Schema
| Device Key in Log Message | LogRhythm Schema | Data Type |
| N/A | <account> | Text\String |
| N/A | <object> | Text\String |
| N/A | <group> | Text\String |
| N/A | <tag1> | Text\String |