PortMapping And Firewall Config Messages
Classification
Rule Name | Rule Type | Common Event | Classification |
---|---|---|---|
PortMapping And Firewall Config Messages | Base Rule | General Information | Information |
Port Mapping Driver Deleted | Sub Rule | Object Deleted/Removed | Access Success |
Firewall Drop Disabled | Sub Rule | Configuration Disabled : Network Access | Configuration |
Mapping with LogRhythm Schema
Device Key in Log Message | LogRhythm Schema | Data Type |
N/A | <subject> | Text/String |
N/A | <vmid> | Number |
N/A | <object> | Text/String |
N/A | <tag1> | Text/String |
N/A | <login> | Text/String |
N/A | <sip> | IP Address |