Skip to main content
Skip table of contents

Posture Check

Vendor Documentation

Log Fields and Parsing

This section details the log fields available in this log message type, along with values parsed for both LogRhythm Default and LogRhythm Default v2.0 policies. A value of "N/A" (not applicable) means that there is no value parsed for a specified log field.

Log FieldLogRhythm DefaultLogRhythm Default v2.0
pri_numN/AN/A
timeN/AN/A
IP address/hostnameN/AN/A
cat_nameN/A<vendorinfo>
msg_id<object>N/A
total_segN/AN/A
seg_numN/AN/A
timestampN/AN/A
sequence_numN/AN/A
msg_codeN/A<vmid>
<tag1>
msg_sev<severity><severity>
msg_classN/A<subject> 
msg_text<subject> <action> 
ConfigVersionIdN/AN/A
NetworkDeviceGroupsN/AN/A
RequestTimeN/AN/A
ResponseTimeN/AN/A
FailureReasonN/A<reason>
MacAddress<smac><dmac>
OperatingSystemN/AN/A
PRAAction<action>N/A
PostureAgentVersion<version>N/A
PostureStatus<status>
<tag1>
N/A
PosturePolicyMatchedN/AN/A
SystemName<sname>N/A
SystemUser<account>N/A
SystemUserDomain<domain>N/A
UserName<login><account>
SessionId<session><session>
IpAddress<sip><dip>
SupplicantProfileN/AN/A
AntiVirusInstalledN/AN/A
AntiSpywareInstalledN/AN/A
FeedUrlN/A<url>
NumOfUpdatesN/AN/A
Key1N/AN/A
Key2N/AN/A

Log Processing Settings

This section details log processing changes made from the LogRhythm Default policy to LogRhythm Default v2.0. In some cases, base rules are broken down into sub-rules to appropriately parse log message types by their event types.

LogRhythm Default

Regex ID

Rule Name

Rule Type

Common Event

Classification

1004765Posture CheckBase RuleGeneral Policy Compliance InformationOther Audit
Posture Is CompliantSub RulePolicy ComplianceOther Audit
Posture Is Not CompliantSub RuleCompliance FailureError
Posture UnknownSub RuleNoncompliant AttributesWarning

LogRhythm Default v2.0

Regex IDRule NameRule TypeCommon EventClassification
1012625V 2.0 Posture And Client Provisioning Audit EventBase RuleAudit MessageOther Audit
V 2.0 EVID 87000 Endpoint Posture Report ReceivedSub RuleGeneral Endpoint MessageInformation
V 2.0 EVID 87001 EP Reassessment Report ReceiveSub RuleGeneral Endpoint MessageInformation
V 2.0 EVID 87002 Endpoint Session TerminationSub RuleGeneral Endpoint MessageInformation
V 2.0 EVID 87004 EP USB-Check Report ReceivedSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 87500 Client Provisioning SuccessSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 87501 Client Provisioning Fail EventSub RuleProvisioning FailedWarning
V 2.0 EVID 87600 Supplicant Provisioning SuccessSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 87601 Supplicant Provisioning FailSub RuleProvisioning FailedWarning
V 2.0 EVID 87602 Supplicant Provision InprogressSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 87603 Supplicant Provisioning DisableSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 87604 CA Server DownSub RuleThe Server Is DownInformation
V 2.0 EVID 87605 CA Server UpSub RuleServer Is UpInformation
V 2.0 EVID 87606 Certificate Request ForwardingSub RuleCertificate Verification FailureError
V 2.0 EVID 87607 OCSP Transactions High VolumeSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 87608 EST Service DownSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 87609 EST Service UpSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 87750 EP Protection Svc Perform Op.Sub RuleGeneral Endpoint MessageInformation
V 2.0 EVID 87751 EP Protection Svc Operation ResSub RuleGeneral Endpoint MessageInformation
V 2.0 EVID 87752 Provisioning Portal -Req SubmitSub RuleCertificate RequestActivity
V 2.0 EVID 87753 Provisioning Portal-Status UpdateSub RuleCertificate Update RequestActivity
V 2.0 EVID 87754 Provisioning Portal -User LoginSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 87901 EP Scripts Provisioned New JobSub RuleGeneral Endpoint MessageInformation
V 2.0 EVID 87921 EndPoint Scripts Execution ResSub RuleGeneral Endpoint MessageInformation
V 2.0 EVID 87005 PSN Posture Compliant StateSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 87006 Posture Queries For MNT SessionSub RuleGeneral Information Log MessageInformation
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.