Pattern 13 : General Linux Host Messages

Classification

Rule Name

Rule Type

Common Event

Classification

Pattern 13 : General Linux Host Messages

Base Rule

General Operations

Other Operations

Linux Command Executed

Sub Rule

Command Executed

Access Success

Logged On As Root

Sub Rule

User Logon

Authentication Success

Logged In

Sub Rule

User Logon

Authentication Success

Logged On

Sub Rule

User Logon

Authentication Success

Access Denied

Sub Rule

Access Object Failure

Access Failure

Cannot Open File

Sub Rule

Read Object Failure

Access Failure

Cannot Bind User

Sub Rule

Cannot Bind As User

Error

Last Message Repeated

Sub Rule

Last Message Repeated

Information

Server Listening

Sub Rule

Server Listening On IP And Port

Information

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

N/A

<severity>

Text/String

N/A

<dname>

Number/String

N/A

<process>

Text/String

N/A

<tag1>

Text/String

N/A

<login>

Text/String

N/A

<sname>

Text/String

N/A

<account>

Text/String

N/A

<object>

Text/String

N/A

<processid>

Number

N/A

<group>

Text/String

N/A

<domain>

Text/String

N/A

<sip>

Number

N/A

<sport>

Number

N/A

<domainorigin>

Text/String