Pattern 5 : FTP Syslog

Vendor Documentation

Classification

Rule Name

Rule Type

Classification

Common Event

Pattern 5: FTP Syslog

Base Rule

Ops/Information

General FTP Information

FTP Anonymous Login

Sub Rule

Security/Suspicious

Suspicious User Activity

FTP Administrator Login

Sub Rule

Audit/Authentication Success

User Logon

FTP Successful Login

Sub Rule

Audit/Authentication Success

User Logon

FTP Failed Login

Sub Rule

Audit/Authentication Failure

User Logon Failure

FTP Incorrect Login

Sub Rule

Audit/Authentication Failure

Authentication Failure Activity

FTP Transfer Complete

Sub Rule

Audit/Other Audit Success

File Transfer Complete

FTP User Logout

Sub Rule

Audit/Authentication Success

User Logoff

FTP Directory Listing

Sub Rule

Audit/Access Success

Object Read

FTP Connection

Sub Rule

Ops/Network Traffic

Connection Established

FTP File Transfer Requested

Sub Rule

Ops/Information

Transfer Request

FTP User Login

Sub Rule

Audit/Authentication Success

User Logon

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

Schema Description


<dip>

IP Address



<sip>

IP Address



<session>

Text\String



<login>

Text\String



<tag1>

Text\String



<tag2>

Text\String



<tag3>

Text\String