Pattern 8 : Encryption Syslog

Vendor Documentation

Classification

Rule Name

Rule Type

Classification

Common Event

Pattern 8 : Encryption Syslog

Base Rule

Ops/Information

General Encryption Information

Encryption Process Starting

Sub Rule

Audit/Startup and Shutdown

Process/Service Starting

Encryption Status Request Finished

Sub Rule

Ops/Information

Encryption Status Request Finished

Encryption Process Ending

Sub Rule

Ops/Information

Encryption Process Ending

Encryption Socket Closing

Sub Rule

Ops/Information

Encryption Socket Closing

Encryption Envelope Accepted Socket

Sub Rule

Audit/Authentication Success

Authentication Activity

Encryption Finished Building Envelope

Sub Rule

Ops/Information

Encryption Finished Building Envelope

Encryption Envelope Request Starting

Sub Rule

Audit/Startup and Shutdown

Process/Service Starting

Encryption Status Requested

Sub Rule

Ops/Information

Encryption Status Requested

Encryption Built Envelope Success

Sub Rule

Ops/Information

Encryption Built Envelope Success

Encryption Status Failed

Sub Rule

Ops/warning

Encryption Status Failed

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

Schema Description


<session>

Number



<tag1>

Text\String



<tag2>

Text\String