Session Activity

Classification

Rule Name

Rule Type

Common Event

Classification

Session Activity

Base Rule

Authentication Activity

Authentication Success

GDM Session Ended

Sub Rule

Authentication Session Ended

Other Audit

Session Ended

Sub Rule

Authentication Session Ended

Other Audit

Administration Session Opened

Sub Rule

Administration Session Started

Other Audit Success

GDM Administration Session Opened

Sub Rule

User Logon

Authentication Success

GDM Session Opened

Sub Rule

User Logon

Authentication Success

Session Opened

Sub Rule

User Logon

Authentication Success

GDM Administration Session Closed

Sub Rule

Administration Session Ended

Other Audit

Administration Session Ended

Sub Rule

Administration Session Ended

Other Audit

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

N/A

<severity>

Text\String

N/A

<sessiontype>

Text\String

N/A

<login>

Text\String

N/A

<object>

Text\String

N/A

<process>

Text\String

N/A

<processid>

Number

N/A

<tag1>

Text\String

N/A

<tag2>

Text\String