Skip to main content
Skip table of contents

Pattern 15 : CASE Updates

Vendor Documentation

Classification

Rule NameRule TypeClassificationCommon Event
Pattern 15 : CASE UpdatesBase RuleOps/InformationGeneral Information
Starting UpdateSub RuleAudit/Access Success
Command Executed
Update Not NeededSub RuleOps/Information
Update Not Needed
Nothing To DoSub RuleOps/Information
General Information
Status UpdateSub RuleOps/InformationStatus Log
Update FinishedSub RuleOps/InformationUpdate
Restarting DaemonsSub RuleAudit/Startup and Shutdown
Process/Service Restarted
Update ResumedSub RuleOps/InformationUpdate Resumed
Checking For UpdateSub RuleOps/InformationChecking For Update
Execute ProcessSub RuleAudit/Access SuccessCommand Executed
Created DirectorySub RuleAudit/Access SuccessObject Created
Post-Update Cleanup StartedSub RuleOps/InformationPost-Update Cleanup Started
Post-Update Cleanup CompletedSub RuleOps/InformationPost-Update Cleanup Completed
Execute Case MonitorSub RuleAudit/Startup and ShutdownProcess/Service Started
Dequeue StatusSub RuleOps/InformationGeneral Information
Case Monitor Ping ResultSub RuleOps/Network TrafficPing Response
Case Transfer ErrorSub RuleOps/ErrorCase Transfer Error

Mapping with LogRhythm Schema

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description

<seconds>Number

<tag1>Text\String

<tag2>

Text\String

<tag3>

Text\String
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.