Session Activity 1
Vendor Documentation
Classification
Rule Name | Rule Type | Common Event | Classification |
---|---|---|---|
Session Activity | Base Rule | Authentication Activity | Authentication Success |
GDM Session Ended | Sub Rule | Authentication Session Ended | Other Audit |
Session Ended | Sub Rule | Authentication Session Ended | Other Audit |
Administration Session Opened | Sub Rule | Administration Session Started | Other Audit Success |
GDM Administration Session Opened | Sub Rule | User Logon | Authentication Success |
GDM Session Opened | Sub Rule | User Logon | Authentication Success |
Session Opened | Sub Rule | User Logon | Authentication Success |
GDM Administration Session Closed | Sub Rule | Administration Session Ended | Other Audit |
Administration Session Ended | Sub Rule | Administration Session Ended | Other Audit |
Mapping with LogRhythm Schema
Device Key in Log Message | LogRhythm Schema | Data Type |
N/A | <severity> | Text/String |
N/A | <login> | Text/String |
N/A | <sessiontype> | Text/String |
N/A | <process> | Text/String |
N/A | <processid> | Number |
N/A | <object> | Text/String |
N/A | <tag1> | Text/String |
N/A | <tag2> | Text/String |