Skip to main content
Skip table of contents

Security and Compliance Center Messages

Vendor Documentation

Classification

Rule NameRule TypeCommon EventClassification
Security and Compliance Center MessagesBase RuleGeneral Security NoteInformation
Security and Compliance Center Error MessageSub RuleGeneral Security Center ErrorError
Security and Compliance Center : Case AddedSub RuleGeneral Security Center InformationInformation
Security and Compliance Center : Case UpdatedSub RuleGeneral Security Center InformationInformation
Security and Compliance Center : Case ViewedSub RuleGeneral Security Center InformationInformation
Security and Compliance Center : Hold CreatedSub RuleGeneral Security Center InformationInformation
Security and Compliance Center : Hold UpdatedSub RuleGeneral Security Center InformationInformation
Security and Compliance Center : Hold ViewedSub RuleGeneral Security Center InformationInformation
Security and Compliance Center : Search CreatedSub RuleGeneral Security Center InformationInformation
Security and Compliance Center : Search PreviewedSub RuleGeneral Security Center InformationInformation
Security and Compliance Center : Search RemovedSub RuleGeneral Security Center InformationInformation
Security and Compliance Center : Search StartedSub RuleGeneral Security Center InformationInformation
Security and Compliance Center : Search UpdatedSub RuleGeneral Security Center InformationInformation
Security and Compliance Center : Search ViewedSub RuleGeneral Security Center InformationInformation
Security and Compliance Center : Viewed SearchSub RuleGeneral Security Center InformationInformation
Security and Compliance Center : Search ReportSub RuleGeneral Security Center InformationInformation
Security and Compliance Center : AlertTriggeredSub RuleAlert Manager MessageInformation
Security and Compliance Center : AlertEntityGeneraSub RuleAlert Manager MessageInformation
Security and Compliance Center : InsightGeneratedSub RuleSever Generated MessageInformation

Mapping with LogRhythm Schema

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
TSN/A N/A N/A  
SESSID<session>Text/StringSession information
COMMAND<command>Text/StringCommand name
USERTYPEN/A  N/A Type of user
USERKEYN/A  N/A User key informations hexadecimal value
WORKLOAD

<process>

<vendorinfo>

Text/StringAudit log record type
RESULTCODE

<tag1>

<result>

Text/StringResults
OBJECT<object>Text/StringObject name
USER<login>
<domain>
Text/StringSource user name
SIP<sip>IP AddressSource IP address
VERSION<version>NumberVersion
ORGANIZATIONIDN/A  N/A Organization ID
STARTTIMEN/A  N/A Start time
CLIENTREQUESTIDN/A  N/A Request ID information
CMDLETVERSION<version>NumberCommand version
EFFECTIVEORGANIZATION<domainorigin>Text/StringN/A  
USERSERVICEPLANN/A  N/A N/A  
CLIENTAPPLICATION<parentprocessname>Text/StringN/A  
SECURITYCOMPLIANCECENTEREVENTTYPEN/A  N/A N/A  
PARAMETERSN/A  N/A N/A  
NONPIISPARAMETERSN/A  N/A N/A  
OBJECTTYPE<objecttype>Text/StringN/A 
From<sender>Text/StringN/A 
Subjecttitle<subject>Text/StringN/A 
F3u<account>Text/StringN/A 
Sev<severity>Text/StringN/A 
Name<subject>Text/StringN/A 

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.