SFIMS General Messages

Classification

Rule Name

Rule Type

Common Event

Classification

SFIMS General Messages

Base Rule

General Cisco IPS/IDS Log Message

Information

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

N/A

<dip>

Number

N/A

<dport>

Number

N/A

<dmac>

Number

N/A

<protname>

Text/String

N/A

<objecttype>

Text/String

N/A

<subject>

Text/String

N/A

<hash>

Number/Text/String

N/A

<command>

Text/String

N/A

<sender>

Text/String

N/A

<recipient>

Text/String

N/A

<amount>

Number

N/A

<tag1>

Text/String

N/A

<tag2>

Text/String