Pattern 10 : User Modifications
Classification
Rule Name | Rule Type | Common Event | Classification |
---|---|---|---|
Pattern 10 : User Modifications | Base Rule | User Account Attribute Modified | Account Modified |
User Added To Group | Sub Rule | Account Added To Group | Access Granted |
User Removed From Group | Sub Rule | Account Removed From Group | Access Revoked |
User Password Locked | Sub Rule | Account Locked | Access Revoked |
User Password Unlocked | Sub Rule | Account Unlocked | Access Granted |
Mapping with LogRhythm Schema
Device Key in Log Message | LogRhythm Schema | Data Type |
N/A | <account> | Text\String |
N/A | <object> | Text\String |
N/A | <group> | Text\String |
N/A | <tag1> | Text\String |