Vendor Documentation
Classification
|
Rule Name |
Rule Type |
Classification |
Common Event |
|---|---|---|---|
|
Pattern 5: FTP Syslog |
Base Rule |
Ops/Information |
General FTP Information |
|
FTP Anonymous Login |
Sub Rule |
Security/Suspicious |
Suspicious User Activity |
|
FTP Administrator Login |
Sub Rule |
Audit/Authentication Success
|
User Logon |
|
FTP Successful Login |
Sub Rule |
Audit/Authentication Success |
User Logon |
|
FTP Failed Login |
Sub Rule |
Audit/Authentication Failure
|
User Logon Failure |
|
FTP Incorrect Login |
Sub Rule |
Audit/Authentication Failure
|
Authentication Failure Activity |
|
FTP Transfer Complete |
Sub Rule |
Audit/Other Audit Success |
File Transfer Complete |
|
FTP User Logout |
Sub Rule |
Audit/Authentication Success |
User Logoff |
|
FTP Directory Listing |
Sub Rule |
Audit/Access Success |
Object Read |
|
FTP Connection |
Sub Rule |
Ops/Network Traffic |
Connection Established |
|
FTP File Transfer Requested |
Sub Rule |
Ops/Information |
Transfer Request |
|
FTP User Login |
Sub Rule |
Audit/Authentication Success |
User Logon |
Mapping with LogRhythm Schema
|
Device Key in Log Message |
LogRhythm Schema |
Data Type |
Schema Description |
|
|
<dip> |
IP Address |
|
|
|
<sip> |
IP Address |
|
|
|
<session> |
Text\String |
|
|
|
<login> |
Text\String |
|
|
|
<tag1> |
Text\String |
|
|
|
<tag2> |
Text\String |
|
|
|
<tag3> |
Text\String |
|