Session Information

Classification

Rule Name

Rule Type

Common Event

Classification

Session Information

Base Rule

Session Opened For User

Other Audit Success

Session Opened

Sub Rule

Session Opened

Information

Session Closed

Sub Rule

Session Closed

Other Audit Success

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

N/A

<severity>

Text/String

N/A

<login>

Text/String

N/A

<account>

Text/String

N/A

<sname>

Text/String

N/A

<process>

Text/String

N/A

<processid>

Number

N/A

<tag1>

Text/String