Vendor Documentation
Classification
|
Rule Name |
Rule Type |
Classification |
Common Event |
|---|---|---|---|
|
Pattern 14 : CASE Anti-Spam
|
Base Rule |
Ops/Information |
General Information |
|
Stderr Method Removed |
Sub Rule |
Ops/Information |
Stderr Method Removed |
|
Case-Daemon Shutdown |
Sub Rule |
Audit/Startup and Shutdown |
Process/Service Stopping |
|
Case-Daemon Started |
Sub Rule |
Audit/Startup and Shutdown |
Process/Service Started |
|
Regional Profile Assignment |
Sub Rule |
Ops/Information |
Regional Profile Assignment |
|
Configuration Loaded |
Sub Rule |
Audit/Configuration |
Configuration Modified : System |
|
Spam Case Successful |
Sub Rule |
Ops/Information |
CASE Operation Successful |
|
CASE Operation Failed |
Sub Rule |
Ops/Warning |
CASE Operation Failed |
Mapping with LogRhythm Schema
|
Device Key in Log Message |
LogRhythm Schema |
Data Type |
Schema Description |
|
MID |
<session> |
Number |
|
|
|
<process> |
Text\String |
|
|
|
<tag1> |
Text\String |
|
|
|
<tag2> |
Text\String |
|