PortMapping Messages

Classification

Rule Name

Rule Type

Common Event

Classification

PortMapping Messages

Base Rule

General Information

Information

PortMapping Connection Disconnected

Sub Rule

Session Disconnected

Information

PortMapping Connection Timeout

Sub Rule

Session Timeout

Warning

PortMapping Incoming Connection Established

Sub Rule

Connection Established

Network Traffic

PortMapping Outgoing Connection Established

Sub Rule

Connection Established

Network Traffic

PortMapping Connection Connected

Sub Rule

Session Connected

Network Traffic

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

N/A

<vmid>

Text\String

N/A

<sip>

IP Address

N/A

<dip>

IP Address

N/A

<login>

Text\String

N/A

<subject>

Text\String

N/A

<object>

Text\String

N/A

<tag1>

Text\String

N/A

<tag3>

Text\String