Session Activity 1
Vendor Documentation
Classification
Rule Name | Rule Type | Common Event | Classification |
|---|---|---|---|
| Session Activity | Base Rule | Authentication Activity | Authentication Success |
| GDM Session Ended | Sub Rule | Authentication Session Ended | Other Audit |
| Session Ended | Sub Rule | Authentication Session Ended | Other Audit |
| Administration Session Opened | Sub Rule | Administration Session Started | Other Audit Success |
| GDM Administration Session Opened | Sub Rule | User Logon | Authentication Success |
| GDM Session Opened | Sub Rule | User Logon | Authentication Success |
| Session Opened | Sub Rule | User Logon | Authentication Success |
| GDM Administration Session Closed | Sub Rule | Administration Session Ended | Other Audit |
| Administration Session Ended | Sub Rule | Administration Session Ended | Other Audit |
Mapping with LogRhythm Schema
| Device Key in Log Message | LogRhythm Schema | Data Type |
| N/A | <severity> | Text/String |
| N/A | <login> | Text/String |
| N/A | <sessiontype> | Text/String |
| N/A | <process> | Text/String |
| N/A | <processid> | Number |
| N/A | <object> | Text/String |
| N/A | <tag1> | Text/String |
| N/A | <tag2> | Text/String |