Pattern 14 : CASE Anti-Spam

Vendor Documentation

Classification

Rule Name

Rule Type

Classification

Common Event

Pattern 14 : CASE Anti-Spam

Base Rule

Ops/Information

General Information

Stderr Method Removed

Sub Rule

Ops/Information

Stderr Method Removed

Case-Daemon Shutdown

Sub Rule

Audit/Startup and Shutdown

Process/Service Stopping

Case-Daemon Started

Sub Rule

Audit/Startup and Shutdown

Process/Service Started

Regional Profile Assignment

Sub Rule

Ops/Information

Regional Profile Assignment

Configuration Loaded

Sub Rule

Audit/Configuration

Configuration Modified : System

Spam Case Successful

Sub Rule

Ops/Information

CASE Operation Successful

CASE Operation Failed

Sub Rule

Ops/Warning

CASE Operation Failed

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

Schema Description

MID

<session>

Number



<process>

Text\String



<tag1>

Text\String



<tag2>

Text\String