Pattern 3 : SELinux Preventing Access To Object

Classification

Rule Name

Rule Type

Common Event

Classification

Pattern 3 : SELinux Preventing Access To Object

Base Rule

Access Object Failure

Access Failure

SELinux Blocked Access To Device

Sub Rule

Access Object Failure

Access Failure

SELinux Blocked Access To Device

Sub Rule

Access Object Failure

Access Failure

SELinux Blocked Access To Device

Sub Rule

Access Object Failure

Access Failure

SELinux Blocked Access To Object

Sub Rule

Access Object Failure

Access Failure

SELinux Blocked Access To Object

Sub Rule

Access Object Failure

Access Failure

SELinux Blocked Access To Object

Sub Rule

Access Object Failure

Access Failure

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

N/A

<severity>

Text\String

N/A

<dname>

Text\String

N/A

<process>

Text\String

N/A

<object>

Text\String

N/A

<tag1>

Text\String

N/A

<tag2>

Text\String