RPC Handler Messages
Classification
Rule Name | Rule Type | Common Event | Classification |
|---|---|---|---|
| RPC Handler Messages | Base Rule | HTTP RPC Connect | Activity |
| Policy Builder Applied Security Policy | Sub Rule | Policy Enabled : System | Policy |
| User Policy Applied | Sub Rule | Policy Enabled : User/Password | Policy |
Mapping with LogRhythm Schema
Device Key in Log Message | LogRhythm Schema | Data Type |
|---|---|---|
| LOC3 | <severity> | Text/String |
| N/A | <process> | Text/String |
| N/A | <processid> | Number |
| N/A | <object> | Text/String |
| N/A | <policy> | Text/String |
| N/A | <group> | Text/String |
| N/A | <command> | Text/String |
| N/A | <tag1> | Text/String |