Skip to main content
Skip table of contents

Pattern 20 : Traffic

Classification

Rule NameRule TypeCommon EventClassification
Pattern 20 : TrafficBase RuleGeneral Firewall LogNetwork Traffic
ASA-4-338202 : Potential TCP Botnet TrafficSub RuleProtocol AnomalyAttack
ASA-4-338202 : Potential UDP Botnet TrafficSub RuleProtocol AnomalyAttack
ASA-4-338002 : Monitored Blacklisted TCP TrafficSub RuleProtocol AnomalyAttack
ASA-4-338002 : Monitored Blacklisted UDP TrafficSub RuleProtocol AnomalyAttack
ASA-4-338004 : Monitored Blacklisted TCP TrafficSub RuleProtocol AnomalyAttack
ASA-4-338003 : Monitored Blacklisted UDP TrafficSub RuleProtocol AnomalyAttack
ASA-4-338004 : Monitored Blacklisted UDP TrafficSub RuleProtocol AnomalyAttack
ASA-3-338005 : Trfc Denied From Blacklisted DomainSub RuleFailed Unauthorized WebsiteFailed Misuse
ASA-3-338006 : Trfc Denied To Blacklisted DomainSub RuleFailed Unauthorized WebsiteFailed Misuse
ASA-3-338005 : Malware TCP Traffic DroppedSub RuleFailed Malware ActivityFailed Malware
ASA-3-338006 : Malware TCP Traffic DroppedSub RuleFailed Malware ActivityFailed Malware
ASA-3-338005 : Spyware TCP Traffic DroppedSub RuleFailed Malware ActivityFailed Malware
ASA-3-338006 : Spyware TCP Traffic DroppedSub RuleFailed Malware ActivityFailed Malware
ASA-4-338008 : Malware TCP Traffic DroppedSub RuleFailed Malware ActivityFailed Malware
ASA-4-338204 : Malware TCP Traffic DroppedSub RuleFailed Malware ActivityFailed Malware
ASA-4-338008 : Botnet TCP Traffic DroppedSub RuleFailed Malware ActivityFailed Malware
ASA-4-338208 : Malware UDP Traffic DroppedSub RuleFailed Malware ActivityFailed Malware
ASA-4-338007 : Malware UDP Traffic DroppedSub RuleFailed Malware ActivityFailed Malware
ASA-4-338008 : Malware UDP Traffic DroppedSub RuleFailed Malware ActivityFailed Malware
ASA-4-338008 : Botnet UDP Traffic DroppedSub RuleFailed Malware ActivityFailed Malware

Mapping with LogRhythm Schema  

Device Key in Log MessageLogRhythm SchemaData Type
N/A<vmid>Number
N/A<sip>Number
N/A<dip>Number
N/A<dname>Text/String
N/A<sport>Number
N/A<dport>Number
N/A<protname>Text/String
N/A<object>Text/String
N/A<threatname>Text/String
N/A<threatid>Number
N/A<url>Text/String
N/A<tag1>Text/String
N/A<tag3>Text/String
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.