Pattern 7 : PIX Connections

Classification

Rule Name

Rule Type

Common Event

Classification

Pattern 7 : PIX Connections

Base Rule

General Firewall Log

Network Traffic

PIX-6-302009 : Rebuilt TCP Connection

Sub Rule

Rebuilt TCP Connection ID

Network Traffic

PIX-6-302021 : Teardown ICMP Connection

Sub Rule

Connection Teardown

Network Traffic

PIX-6-302004 : Pre-Alloc H323 UDP BackCon

Sub Rule

Pre-Allocate H323 Backconnection

Information

PIX-6-302005 : Built UDP Connection

Sub Rule

Built UDP Connection

Network Traffic

PIX-4-405101 : H225 Connection Alloc Failure

Sub Rule

Unable to Allocate New UDP Connections

Error

PIX-6-302012 : Pre-Alloc H225 Connection

Sub Rule

Pre-Allocated H225 Connection

Information

PIX-6-314001 : Pre-Alloc RTSP Connection

Sub Rule

Pre-Allocated RTSP Connection

Information

PIX-4-405102 : Unable to Alloc H245 Conn

Sub Rule

Unable to Pre-Allocate H245 Connection

Information

PIX-6-302003 : Built H245 Connection

Sub Rule

Connection Built

Network Traffic

PIX-6-302020 : Built ICMP Connection

Sub Rule

Connection Built

Network Traffic

PIX-6-302020 : Built Inbound ICMP Connection

Sub Rule

Inbound Connection Established

Network Traffic

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

N/A

<severity>

Number

N/A

<vmid>

Number

N/A

<sip>

Number

N/A

<dip>

Number

N/A

<sport>

Number

N/A

<dport>

Number

N/A

<dnatip>

Number

N/A

<dnatport>

Number

N/A

<protname>

Text/String

N/A

<login>

Text/String

N/A

<object>

Text/String

N/A

<responsecode>

Number

N/A

<tag1>

Text/String