Sendmail Operations

Classification

Rule Name

Rule Type

Common Event

Classification

Sendmail Operations

Base Rule

General Sendmail Information

Information

Sendmail : Dangerous Permissions

Sub Rule

Vuln High Severity : Security Policy

Vulnerability

Sendmail : Cannot Change Directory

Sub Rule

Failed Change Working Directory

Error

Sendmail : Done

Sub Rule

General Sendmail Notice

Information

Sendmail : Start TLS Failed

Sub Rule

Failed Process Start

Error

Sendmail : Authorization Information

Sub Rule

Authentication Activity

Authentication Success

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

N/A

<severity>

Text\String

N/A

<dname>

Text\String

N/A

<sname>

Text\String

N/A

<session>

Text\String

N/A

<sip>

Number

N/A

<process>

Text\String

N/A

<processid>

Number

N/A

<command>

Text\String

N/A

<object>

Text\String

N/A

<objectname>

Text\String

N/A

<subject>

Text\String

N/A

<amount>

Number

N/A

<version>

Number

N/A

<quantity>

Number

N/A

<duration>

Number

N/A

<tag1>

Text\String

N/A

<tag2>

Text\String


Mapping of Sendmail Operations with LR Schema