Skip to main content
Skip table of contents

Pattern 6 : SMTP Conversation Syslog

Vendor Documentation

Classification

Rule NameRule TypeClassificationCommon Event
Pattern 6 : SMTP Conversation Syslog
Base RuleOps/InformationGeneral SMTP Information
SMTP EHLO AnnouncementSub RuleOps/InformationSMTP EHLO Announcement
SMTP Recipient DeclarationSub RuleOps/InformationGeneral Email Recipient Information
SMTP Sender DeclarationSub RuleOps/InformationGeneral Email Sender Message
SMTP Denied By ReputationSub RuleSecurity/Failed MisuseFailed Unauthorized E-mail
SMTP Connection ClosedSub RuleOps/Network TrafficConnection Closed
SMTP QUIT RequestedSub RuleOps/InformationSMTP QUIT Requested
SMTP Connection EstablishedSub RuleOps/Network TrafficConnection Established
SMTP Message AcceptedSub RuleAudit/Other Audit SuccessMessage Accepted

Mapping with LogRhythm Schema

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description

<sip>IP Address

<sname>Text\String

<domainorigin>Text\String
DCID<session>Number

<responsecode>Number

<sender>Text\String

<recipient>Text\String

<tag1>Text\String

<tag2>Text\String


JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.