Pattern 5 : FTP Syslog
Vendor Documentation
Classification
| Rule Name | Rule Type | Classification | Common Event |
|---|---|---|---|
| Pattern 5: FTP Syslog | Base Rule | Ops/Information | General FTP Information |
| FTP Anonymous Login | Sub Rule | Security/Suspicious | Suspicious User Activity |
| FTP Administrator Login | Sub Rule | Audit/Authentication Success | User Logon |
| FTP Successful Login | Sub Rule | Audit/Authentication Success | User Logon |
| FTP Failed Login | Sub Rule | Audit/Authentication Failure | User Logon Failure |
| FTP Incorrect Login | Sub Rule | Audit/Authentication Failure | Authentication Failure Activity |
| FTP Transfer Complete | Sub Rule | Audit/Other Audit Success | File Transfer Complete |
| FTP User Logout | Sub Rule | Audit/Authentication Success | User Logoff |
| FTP Directory Listing | Sub Rule | Audit/Access Success | Object Read |
| FTP Connection | Sub Rule | Ops/Network Traffic | Connection Established |
| FTP File Transfer Requested | Sub Rule | Ops/Information | Transfer Request |
| FTP User Login | Sub Rule | Audit/Authentication Success | User Logon |
Mapping with LogRhythm Schema
| Device Key in Log Message | LogRhythm Schema | Data Type | Schema Description |
| <dip> | IP Address | ||
| <sip> | IP Address | ||
| <session> | Text\String | ||
| <login> | Text\String | ||
| <tag1> | Text\String | ||
| <tag2> | Text\String | ||
| <tag3> | Text\String |