Pattern 5 : PIX Traffic

Classification

Rule Name

Rule Type

Common Event

Classification

Pattern 5 : PIX Traffic

Base Rule

General Firewall Log

Network Traffic

PIX-4-209003 : Fragment Database Limit Exceeded

Sub Rule

Fragment Database Limit Exceeded

Warning

PIX-X-713172 : Nat Issues

Sub Rule

NAT Detection Status

Network Traffic

PIX-6-109024 : Authorization Denied

Sub Rule

Access Object Failure

Access Failure

PIX-4-209004 : Invalid IP Fragment

Sub Rule

Protocol Anomaly

Attack

PIX-X-111007 : Begin Configuration

Sub Rule

Configuration Loaded : Network Access

Configuration

PIX-4-209005 : Discard IP Fragment

Sub Rule

Failed Suspicious Network Activity

Failed Suspicious

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

N/A

<vmid>

Number

N/A

<sip>

Number

N/A

<dip>

Number

N/A

<sport>

Number

N/A

<dport>

Number

N/A

<login>

Text/String

N/A

<protname>

Text/String

N/A

<group>

Text/String