Session State Changed

Classification

Rule Name

Rule Type

Common Event

Classification

Session Closed

Sub Rule

Session Ended

Other Audit Success

Session Closed

Sub Rule

Session Ended

Other Audit Success

Session State Changed

Base Rule

Session State Changed

Other Audit

New Session

Sub Rule

Start New Session Success

Other Audit Success

Session Removed

Sub Rule

Session Closed

Other Audit Success

Session Opened

Sub Rule

Begin Session

Other Audit Success

Session Opened

Sub Rule

Begin Session

Other Audit Success

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

N/A

<dname>

Text\String

N/A

<login>

Text\String

N/A

<process>

Text\String

N/A

<processid>

Number

N/A

<tag1>

Text\String