Pattern 10 : User Modifications

Classification

Rule Name

Rule Type

Common Event

Classification

Pattern 10 : User Modifications

Base Rule

User Account Attribute Modified

Account Modified

User Added To Group

Sub Rule

Account Added To Group

Access Granted

User Removed From Group

Sub Rule

Account Removed From Group

Access Revoked

User Password Locked

Sub Rule

Account Locked

Access Revoked

User Password Unlocked

Sub Rule

Account Unlocked

Access Granted

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

N/A

<account>

Text\String

N/A

<object>

Text\String

N/A

<group>

Text\String

N/A

<tag1>

Text\String