Vendor Documentation
Classification
|
Rule Name |
Rule Type |
Common Event |
Classification |
|---|---|---|---|
|
PIM Events |
Base Rule |
General PIM Information |
Information |
Mapping with LogRhythm Schema
|
Device Key in Log Message |
LogRhythm Schema |
Data Type |
Schema Description |
|
Event ID |
<vmid> |
Number |
Event ID 5101, 5102, 5103, 5104, 5105, 5106, 5107, 5108, 5109, 5110, 5111, 5112, 5113, 5114, 5115, 5116, 5117, 5118, 5119, 5120, 5121, 5122, 5123, 5124, 5125, 5126 |
|
Severity |
<severity> |
Text/String |
For All: Information
|
|
Message |
<subject>
|
Text/String |
Event ID 5101:
|
|
|
<subject>
|
Text/String/IP Address |
Event ID 5102:
|
|
|
<subject>
|
Text/String/IP Address |
Event ID 5103:
|
|
|
<subject>
|
Text/String/IP Address |
Event ID 5104:
|
|
|
<subject>
|
Text/String/IP Address/Number |
Event ID 5105:
|
|
|
<subject>
|
Text/String/IP Address/Number |
Event ID 5106:
|
|
|
<subject>
|
Text/String |
Event ID 5107:
|
|
|
<subject>
|
Text/String |
Event ID 5108:
|
|
|
<subject>
|
Text/String |
Event ID 5109:
|
|
|
<subject>
|
Text/String/Number |
Event ID 5110:
|
|
|
<subject>
|
Text/String |
Event ID 5111:
|
|
|
<subject>
|
Text/String |
Event ID 5112:
|
|
|
<subject>
|
Text/String |
Event ID 5113:
|
|
|
<subject>
|
Text/String/IP Address |
Event ID 5114:
|
|
|
<subject>
|
Text/String/IP Address |
Event ID 5115:
|
|
|
<subject>
|
Text/String |
Event ID 5116:
|
|
|
<subject>
|
Text/String |
Event ID 5117:
|
|
|
<subject>
|
Text/String |
Event ID 5118:
|
|
|
<subject>
|
Text/String |
Event ID 5119:
|
|
|
<subject>
|
Text/String/IP Address |
Event ID 5120:
|
|
|
<subject>
|
Text/String/Number |
Event ID 5121:
|
|
|
<subject>
|
Text/String |
Event ID 5122:
|
|
|
<subject>
|
Text/String |
Event ID 5123:
|
|
|
<subject>
|
Text/String/IP Address |
Event ID 5124:
|
|
|
<subject>
|
Text/String/IP Address |
Event ID 5125:
|
|
|
<subject>
|
Text/String/IP Address |
Event ID 5126:
|