Skip to main content
Skip table of contents

Pattern 13 : CLI Syslog

Vendor Documentation

Classification

Rule NameRule TypeClassificationCommon Event
Pattern 13 : CLI SyslogBase RuleOps/InformationGeneral Information
CLI ConversationSub RuleOps/InformationCLI Conversation
CLI LoginSub RuleAudit/Authentication Success
User Logon
LogoutSub RuleAudit/Authentication Success
User Logoff
Executed CommandSub RuleOps/InformationCLI Command Executed

Mapping with LogRhythm Schema

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description

<severity>Text\String

<sip>IP Address

<dip>IP Address

<login>Text\String
PID<session>Number

<subject>Text\String

<command>Text\String

<tag1>Text\String

<tag2>Text\String

<tag3>Text\String

<tag4>Text\String
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.