Pattern 16 : Authentication Logs (VMWare vSphere 8.0, formerly ESX/ESXi Server)

Classification

Rule Name

Rule Type

Common Event

Classification

Pattern 16 : Authentication Logs

Base Rule

Authentication Activity

Authentication Success

User Logon

Sub Rule

User Logon

Authentication Success

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

tag1

<tag1>

Text/String

tag2

<tag2>

Text/String

dname

<dname>

Text/String

tag3

<tag3>

Text/String

object

<object>

Text/String

login

<login>

Text/String

account

<account>

Text/String

protname

<protname>

Text/String