SFIMS : Catch All Level 1

Classification

Rule Name

Rule Type

Common Event

Classification

SFIMS : Catch All Level 1

Base Rule

Network Traffic

Network Traffic

SFIMS : dcerpc2 Messages

Sub Rule

Network Traffic

Network Traffic

SFIMS : http_inspect Messages

Sub Rule

Network Traffic

Network Traffic

SFIMS : ppm Messages

Sub Rule

Network Traffic

Network Traffic

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

NA

<process>

Number/Text

NA

<subject>

Text/String

NA

<object>

Text/String

NA

<dname>

Number/Text

NA

<objectname>

Text/String

NA

<severity>

Number/Text

NA

<protname>

Number/Text

NA

<sip>

IP Address

NA

<sport>

Number

NA

<dip>

IP Address

NA

<dport>

Number