Skip to main content
Skip table of contents

Pattern Catch All : Level 3

Log Fields and Parsing

This section details the log fields available in this log message type, along with values parsed for both LogRhythm Default and LogRhythm Default v2.0 policies. A value of "N/A" (not applicable) means that there is no value parsed for a specified log field.

Log Field

LogRhythm DefaultLogRhythm Default v2.0
Provider<tag1>, <objectname>, <process>N/A
EventID Qualifiers<vmid>N/A
VersionN/AN/A
Level<severity>N/A
TaskN/AN/A
OpcodeN/AN/A
KeywordsN/AN/A
TimeCreatedN/AN/A
EventRecordIDN/AN/A
CorrelationN/AN/A
Execution ProcessID<processid>N/A
ThreadID<session>N/A
ChannelN/AN/A
Computer<dname>N/A
Security<domain>
<login>
N/A
Data<vendorinfo>N/A

Log Processing Settings

This section details log processing changes made from the LogRhythm Default policy to LogRhythm Default v2.0. In some cases, base rules are broken down into sub-rules to appropriately parse log message types by their event types.

LogRhythm Default

Regex IDRule NameRule TypeCommon EventClassification
1008171Pattern Catch All : Level 3Base RuleGeneral InformationInformation
EVID 57: Failed To Flush Data To Transaction LogSub RuleGeneral Maintenance WarningWarning
EVID 6005: Event Log Service StartedSub RuleGeneral Logging InformationInformation
EVID 6006: Event Log Service StoppedSub RuleGeneral Logging InformationInformation
EVID 6008: Previous Shutdown UnexpectedSub RuleUnclean ShutdownWarning
EVID 6009: System Boot InfoSub RuleSystem StartedStartup and Shutdown
Microsoft-Windows-WinRMSub RuleGeneral Administration Server InformationInformation
EVID 133: Optical Drive Locked - Exclusive AccessSub RuleAccess Object FailureAccess Failure
EVID 1001: SNMP Service Started SuccessfullySub RuleProcess/Service StartedStartup and Shutdown
EVID 13: System Shutting DownSub RuleSystem Shutting DownStartup and Shutdown
EVID 27: Windows Automatic Update Service PausedSub RuleProcess/Service StoppedStartup and Shutdown
EVID 51046: DHCPv6 Client Service StartedSub RuleProcess/Service StartedStartup and Shutdown
EVID 50036: DHCP Client Service StartingSub RuleProcess/Service StartingStartup and Shutdown
EVID 10016: COM Access DeniedSub RuleInitialize Object FailureAccess Failure
EVID 12: OS Started At TimeSub RuleSystem StartingStartup and Shutdown
EVID 129: NTPClient Unable To Set Domain PeerSub RuleNTP Server UnreachableError
EVID 1500: SNMP Traps Not ConfiguredSub RuleGeneral SNMPTRAP ErrorError
EVID 20001: Driver Install Process CompletedSub RuleSoftware InstalledConfiguration
EVID 20003: Service Install Process CompleteSub RuleSoftware InstalledConfiguration
EVID 20010: PnP Service State ChangeSub RuleProcess/Service Startup Or Shutdown ActivityStartup and Shutdown
EVID 2242: Patrol Read StartedSub RuleProcess/Service StartedStartup and Shutdown
EVID 2243: Patrol Read StoppedSub RuleProcess/Service StoppedStartup and Shutdown
EVID 26: Application PopupSub RuleGeneral Application Popup InformationInformation
EVID 26: Processor StateSub RuleProcessor InformationInformation
EVID 3: Virtual Disk Service StartedSub RuleProcess/Service StartedStartup and Shutdown
EVID 4: Virtual Disk Service StoppedSub RuleProcess/Service StoppedStartup and Shutdown
EVID 36885: Too Many Trusted Cert AuthoritiesSub RuleCertificate Services Denied Certificate RequestWarning
EVID 36888: Schannel Fatal AlertSub RuleGeneral Schannel ErrorError
EVID 50037: DHCPv4 Service StoppedSub RuleProcess/Service StoppedStartup and Shutdown
EVID 50037: DHCPv6 Service StoppedSub RuleProcess/Service StoppedStartup and Shutdown
EVID 5074: Worker Process Recycle RequestSub RuleProcess/Service Startup Or Shutdown ActivityStartup and Shutdown
EVID 5186: Inactive Worker Process ShutdownSub RuleProcess/Service StoppedStartup and Shutdown
EVID 5719: No DC Available For DomainSub RuleDomain Controller UnreachableError
EVID 10010: Server Registration With DCOM TimeoutSub RuleDevice TimeoutError
EVID 10020: Dynamic IPv6 Assigned To ServerSub RuleGeneral DHCPServer WarningWarning
EVID 10149: WinRM Is Not ListeningSub RuleListener FailedError
EVID 1:  CBA Filter Disk InfoSub RuleGeneral Disk InformationInformation
EVID 103: MSISCSI TimeoutSub RuleGeneral iSCSI ErrorError
EVID 41: System Did Not Shutdown ProperlySub RuleUnclean ShutdownWarning
EVID 14531: DFS Finished InitializationSub RuleProcess/Service StartingStartup and Shutdown
EVID 14533: DFS Finished Building Name SpaceSub RuleProcess/Service StartingStartup and Shutdown
EVID 14550: DFS Cross Forest Initialization ErrorSub RuleGeneral DfsSvc ErrorError
EVID 14551: DFS Cross Forest InitializationSub RuleGeneral DfsSvc InformationInformation
EVID 1: DataKeeper Driver StartedSub RuleProcess/Service StartedStartup and Shutdown
EVID 144: Error Locking VolumeSub RuleError Locking VolumeError
EVID 146: Volume Has Been LockedSub RuleObject ModifiedAccess Success
EVID 147: Volume Has Been UnlockedSub RuleObject ModifiedAccess Success
EVID 149: Open Handled Detected On VolumeSub RuleOpen Handles Detected On VolumeWarning
EVID 150: Invalid Attempt To Establish MirrorSub RuleCreate Object FailureAccess Failure
EVID 152: Media Is Now Write ProtectedSub RuleMedia Is Now Write ProtectedInformation
EVID 167 :Unable To Connect To VolumeSub RuleUnable To Connect To Volume PortError
EVID 23: Mirror Role ChangedSub RuleMirror Role ChangedInformation
EVID 58: Error Writing Keep-Alive PacketSub RuleError Writing Keep-Alive PacketError
Microsoft-Windows-Kernel-Boot MessageSub RuleProcess/Service Startup Or Shutdown ActivityStartup and Shutdown
EVID 1030: Username Or Password IncorrectSub RuleWindows Group Policy ProblemError
EVID 1: Power SetupSub RulePower Info MsgInformation
EVID 10001: Unable To Start DCOM ServerSub RuleServer Timed OutInformation
EVID 10006: Unable To Start DCOM ServerSub RuleServer Timed OutInformation
EVID 10009: Unable To Start DCOM ServerSub RuleServer Timed OutInformation
EVID 101: Group PolicySub RuleWindows Group Policy ProblemError
EVID 103: Group PolicySub RuleWindows Group Policy ProblemError
EVID 105: Group PolicySub RuleInstall FailedError
EVID 107: Group PolicySub RuleInstall FailedError
EVID 108: Group PolicySub RuleInstall FailedError
EVID 10028: DCOM Unable To CommunicateSub RuleUnable To Create ConnectionError
EVID 10029: DCOM Unable To CommunicateSub RuleUpdate StoppedInformation
EVID 10036: DCOM Unable To CommunicateSub RuleUpdate StoppedInformation
EVID 1129: Group PolicySub RuleICMP Flow EventsNetwork Traffic
EVID 1130: Group PolicySub RulePolicy NotificationInformation
EVID 13: Group PolicySub RuleWindows Group Policy ProblemError
EVID 130: Power SetupSub RulePower Failure Detected In Other Failover DeviceError
EVID 131: Power SetupSub RulePower Failure Detected In Other Failover DeviceError
EVID 137: Power SetupSub RulePower Info MsgInformation
EVID 15: General InformationSub RuleGeneral Information Log MessageInformation
EVID 1500: Group PolicySub RuleSuccessfully Loaded Policy From Policy ServerInformation
EVID 1501: Group PolicySub RuleSuccessfully Loaded Policy From Policy ServerInformation
EVID 16: Hardware IssueSub RuleHardware ProblemWarning
EVID 187: Power SetupSub RulePower Info MsgInformation
EVID 44: Windows UpdateSub RuleGeneral Windows Update Agent WarningWarning
EVID 7016: Windows ServiceSub RuleService Stop FailedError
EVID 2004: Windows MemorySub RuleSystem Memory LowWarning
EVID 23: Power SetupSub RulePower Failure Detected In Other Failover DeviceError
EVID 24: Power SetupSub RulePower Failure Detected In Other Failover DeviceError
EVID 292: Power SetupSub RulePower NotificationWarning
EVID 33: Ethernet InfoSub RuleEthernet Port DownWarning
EVID 34: Ethernet InfoSub RuleEthernet Port DownWarning
EVID 35: Group PolicySub RuleGeneral PolicyOther Audit
EVID 36874: Connection RequestSub RuleConnection RequestNetwork Traffic
EVID 36876: Certificate ErrorSub RuleServer Certificate IssuedInformation
EVID 36882: Certificate ErrorSub RuleUnknown CertificateInformation
EVID 36887: Certificate ErrorSub RuleSSL/VPN WarningWarning
EVID 37: Security CheckSub RuleGeneral System WarningWarning
EVID 40: Power SetupSub RulePower Failure Detected In Other Failover DeviceError
EVID 42: Kerberos KDC  Lacks Strong Account KeySub RuleGeneral Kerberos ErrorError
EVID 43: Installation Of Updated KBSub RuleKB Auto Sync CompletedInformation
EVID 4321: NBT Over TCPSub RuleGeneral NetBIOS ErrorError
EVID 5002: WirelessSub RuleWireless ActivityInformation
EVID 5009: SSD Not WorkingSub RuleGeneral TermServSessDir InformationInformation
EVID 506: Power SetupSub RuleDisplay Page FailureWarning
EVID 507: Power SetupSub RulePower Info MsgInformation
EVID 566: Power SetupSub RulePower Failure Detected In Other Failover DeviceError
EVID 6062: WirelessSub RuleWireless ActivityInformation
EVID 610: Smart CardSub RuleGeneral SCardSvr ErrorError
EVID 7003: WirelessSub RuleWireless ActivityInformation
EVID 7012: WirelessSub RuleWireless ActivityInformation
EVID 7021: WirelessSub RuleWireless ActivityInformation
EVID 7023: WirelessSub RuleWireless ActivityInformation
EVID 7024: Service ControlSub RuleService Stop FailedError
EVID 7025: Power SetupSub RulePower Failure Detected In Other Failover DeviceError
EVID 8012: DNS Client EventsSub RuleDNS Information-Only EventInformation
EVID 308: App Mgmt Group PolicySub RulePolicy NotificationInformation
EVID 57: Failed To Flush Data To Transaction LogSub RuleGeneral Maintenance WarningWarning
General: Service Control Manager InformationSub RuleGeneral Service Control Manager InformationInformation
General: DfsSvc InformationSub RuleGeneral DfsSvc InformationInformation
EVID 23: Change PasswordSub RulePassword ReminderInformation
EVID 23: UpdateSub RuleUpdate EventInformation

LogRhythm Default v2.0

N/A

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.