Vendor Documentation
Classification
|
Rule Name |
Rule Type |
Common Event |
Classification |
|---|---|---|---|
|
REST Events |
Base Rule |
General Information Log Message |
Information |
Mapping with LogRhythm Schema
|
Device Key in Log Message |
LogRhythm Schema |
Data Type |
Schema Description |
|
Event ID |
<vmid> |
Number |
Event ID 4601, 4602, 4603, 4604, 4605, 4606, 4607, 4608, 4609, 4610, 4611, 4612, 4613, 4614, 4615, 4616, 4617, 4618, 4619, 4620, 4621, 4622, 4623, 4624, 4625, 4626, 4627, 4628, 4629, 4630, 4631, 4632, 4633, 4634, 4635, 4636, 4637, 4638, 4639, 4640, 4641, 4642, 4643, 4644, 4645, 4646, 4647, 4648, 4649, 4650, 4651, 4652, 4653, 4654 |
|
Severity |
<severity> |
Text/String |
For All: Information
|
|
Message |
<subject>
|
Text/String |
Event ID 4601:
|
|
|
<subject>
|
Text/String |
Event ID 4602:
|
|
|
<subject>
|
Text/String |
Event ID 4603:
|
|
|
<subject>
|
Text/String |
Event ID 4604:
|
|
|
<subject>
|
Text/String |
Event ID 4605:
|
|
|
<subject>
|
Text/String |
Event ID 4606:
|
|
|
<subject>
|
Text/String |
Event ID 4607:
|
|
|
<subject>
|
Text/String |
Event ID 4608:
|
|
|
<subject>
|
Text/String |
Event ID 4609:
|
|
|
<subject>
|
Text/String |
Event ID 4610:
|
|
|
<subject>
|
Text/String |
Event ID 4611:
|
|
|
<subject>
|
Text/String |
Event ID 4612:
|
|
|
<subject>
|
Text/String |
Event ID 4613:
|
|
|
<subject>
|
Text/String |
Event ID 4614:
|
|
|
<subject>
|
Text/String |
Event ID 4615:
|
|
|
<subject>
|
Text/String |
Event ID 4616:
|
|
|
<subject>
|
Text/String |
Event ID 4617:
|
|
|
<subject>
|
Text/String |
Event ID 4618:
|
|
|
<subject>
|
Text/String |
Event ID 4619:
|
|
|
<subject>
|
Text/String |
Event ID 4620:
|
|
|
<subject>
|
Text/String |
Event ID 4621:
|
|
|
<subject>
|
Text/String |
Event ID 4622:
|
|
|
<subject>
|
Text/String |
Event ID 4623:
|
|
|
<subject> |
Text/String |
Event ID 4624:
|
|
|
<subject>
|
Text/String |
Event ID 4625:
|
|
|
<subject>
|
Text/String |
Event ID 4626:
|
|
|
<subject>
|
Text/String |
Event ID 4627:
|
|
|
<subject>
|
Text/String |
Event ID 4628:
|
|
|
<subject>
|
Text/String |
Event ID 4629:
|
|
|
<subject>
|
Text/String |
Event ID 4630:
|
|
|
<subject>
|
Text/String |
Event ID 4631:
|
|
|
<subject>
|
Text/String/IP Address |
Event ID 4632:
|
|
|
<subject>
|
Text/String/IP Address |
Event ID 4633:
|
|
|
<subject>
|
Text/String/IP Address |
Event ID 4634:
|
|
|
<subject>
|
Text/String/IP Address |
Event ID 4635:
|
|
|
<subject>
|
Text/String/IP Address |
Event ID 4636:
|
|
|
<subject>
|
Text/String/IP Address |
Event ID 4637:
|
|
|
<subject> |
Text/String |
Event ID 4638:
|
|
|
<subject>
|
Text/String/IP Address |
Event ID 4639:
|
|
|
<subject>
|
Text/String/IP Address |
Event ID 4640:
|
|
|
<subject> |
Text/String |
Event ID 4641:
|
|
|
<subject>
|
Text/String/IP Address |
Event ID 4642:
|
|
|
<subject> |
Text/String |
Event ID 4643:
|
|
|
<subject>
|
Text/String/IP Address |
Event ID 4645:
|
|
|
<subject>
|
Text/String/IP Address |
Event ID 4646:
|
|
|
<subject> |
Text/String |
Event ID 4647:
|
|
|
<subject>
|
Text/String/IP Address |
Event ID 4648:
|
|
|
<subject>
|
Text/String/IP Address |
Event ID 4649:
|
|
|
<subject>
|
Text/String |
Event ID 4650:
|
|
|
<subject>
|
Text/String |
Event ID 4651:
|
|
|
<subject> |
Text/String |
Event ID 4652:
|
|
|
<subject>
|
Text/String |
Event ID 4653:
|
|
|
<subject>
|
Text/String |
Event ID 4654:
|