RADIUS Accounting

Vendor Documentation

Log Fields and Parsing

This section details the log fields available in this log message type, along with values parsed for both LogRhythm Default and LogRhythm Default v2.0 policies. A value of "N/A" (not applicable) means that there is no value parsed for a specified log field.

Log Field

LogRhythm Default

LogRhythm Default v2.0

pri_num

N/A

N/A

time

N/A

N/A

IP address/hostname

N/A

N/A

cat_name

N/A

<vendorinfo>

msg_id

N/A

N/A

total_seg

N/A

N/A

seg_num

N/A

N/A

timestamp

N/A

N/A

sequence_num

N/A

N/A

msg_code

N/A

<vmid>
<tag1>

msg_sev

N/A

<severity>

msg_class

<process>

<subject> 

msg_text

<status>
<tag1>

<action> 

ConfigVersionId

<version>

<version>

Device IP Address

<sip>

<sip>

UserName

N/A

<domainimpacted>/<account>

RequestLatency

N/A

N/A

NetworkDeviceName

<sname>

N/A

User-Name

<login>

<domainimpacted>/<account>

NAS-IP-Address

<snatip>

<snatip>

NAS-Port

N/A

<snatport>

Service-Type

<objecttype>

<objecttype>

Framed-IP-Address

<dip>

<dip>

Class

<object>

<object>

Called-Station-ID

<dmac>

<dmac>

Calling-Station-ID

<smac>

<smac>

NAS-Identifier

N/A

N/A

Acct-Status-Type

<subject> 

<status>

Acct-Delay-Time

N/A

N/A

Acct-Input-Octets

N/A

<bytesin>

Acct-Output-Octets

N/A

<bytesout>

Acct-Session-Id

<session>

<session>

Acct-Authentic

N/A

N/A

Acct-Session-Time

N/A

N/A

Acct-Input-Packets

N/A

<packetsin>

Acct-Output-Packets

<packetsout>

<packetsout>

Acct-Terminate-Cause

N/A

N/A

Event-Timestamp

N/A

N/A

NAS-Port-Type

N/A

N/A

NAS-Port-Id

N/A

N/A

attribute-151

N/A

N/A

Tunnel-Type

N/A

N/A

Tunnel-Medium-Type

N/A

N/A

Tunnel-Private-Group-ID

N/A

N/A

cisco-av-pair=audit-session-id

N/A

N/A

cisco-av-pair=nas-update

N/A

N/A

cisco-av-pair=disc-cause-ext

N/A

N/A

cisco-av-pair=connect-progress

N/A

N/A

cisco-av-pair=method

N/A

N/A

Airespace-Wlan-Id

N/A

N/A

AcsSessionID

<session>

N/A

SelectedAccessService

N/A

N/A

Step

N/A

N/A

Step

N/A

N/A

Step

N/A

N/A

NetworkDeviceGroups

N/A

N/A

NetworkDeviceGroups

N/A

N/A

ServiceSelectionMatchedRule

N/A

N/A

CPMSessionID

N/A

N/A

Device Type

N/A

N/A

Location

N/A

N/A

Model Name

N/A

N/A

Software Version

N/A

N/A

Key1

N/A

N/A

Key2

N/A

N/A

Log Processing Settings

This section details log processing changes made from the LogRhythm Default policy to LogRhythm Default v2.0. In some cases, base rules are broken down into sub-rules to appropriately parse log message types by their event types.

LogRhythm Default

Regex ID

Rule Name

Rule Type

Common Event

Classification

1010150

RADIUS Accounting

Base Rule

Accounting Request

Information

Accounting Stop Request

Sub Rule

Accounting Request

Information

Accounting Start Request

Sub Rule

RADIUS Accounting-Request Received

Information

Accounting Watchdog Update

Sub Rule

TACACS+ Accounting Watchdog

Information

LogRhythm Default v2.0

Regex ID

Rule Name

Rule Type

Common Event

Classification

1012914

V 2.0 RADIUS Accounting Event

Base Rule

RADIUS Information

Information

V 2.0 EVID  3000 RADIUS Accounting Request Start

Sub Rule

RADIUS Accounting-Request Received

Information

V 2.0 EVID  3001 RADIUS Accounting Request Stop

Sub Rule

RADIUS Accounting-Request Received

Information

V 2.0 EVID  3002 RADIUS Accounting Watchdog Updat

Sub Rule

General RADIUS Message

Information

V 2.0 EVID  3003 RADIUS Accounting On

Sub Rule

General RADIUS Message

Information

V 2.0 EVID  3004 RADIUS Accounting Off

Sub Rule

General RADIUS Message

Information

V 2.0 EVID  3005 RADIUS Accounting Tunnel Start

Sub Rule

RADIUS Accounting-Request Received

Information

V 2.0 EVID  3006 RADIUS Accounting Tunnel Stop

Sub Rule

RADIUS Accounting-Request Received

Information

V 2.0 EVID  3007 RADIUS Accounting Tunnel Reject

Sub Rule

General RADIUS Message

Information

V 2.0 EVID  3008 RADIUS Acc. Tunnel Link Start

Sub Rule

General RADIUS Message

Information

V 2.0 EVID  3009 RADIUS Acc. Tunnel Link Stop

Sub Rule

General RADIUS Message

Information

V 2.0 EVID  3010 RADIUS Acc. Tunnel Link Reject

Sub Rule

General RADIUS Message

Information