SFlow Events
Vendor Documentation
https://www.arubanetworks.com/techdocs/AOS-CX/10.07/HTML/5200-8214/Content/fir-int.htm https://www.arubanetworks.com/techdocs/AOS-CX/10.07/PDF/5200-8214.pdf |
Classification
Rule Name | Rule Type | Common Event | Classification |
---|---|---|---|
SFlow Events | Base Rule | sFlow Virtual Information | Information |
Mapping with LogRhythm Schema
Device Key in Log Message | LogRhythm Schema | Data Type | Schema Description |
Event ID | <vmid> | Number | Event ID 1001, 1002, 1003, 1004, 1005, 1006, 1007, 1008, 1009, 1010, 1011, 1012, 1013, 1014, 1015, 1016, 1017, 1018, 1019, 1020, 1021, 1022, 1023, 1024, 1025, 1026, 1027, 1028, 1029, 1030, 1031, 1032 |
Severity | <severity> | Text/String | For 1023-1032: Information |
Message | <subject> | Text/String | Event ID 1001: |
<subject> | Text/String | Event ID 1002: | |
<subject> | Text/String | Event ID 1003: | |
<subject> | Text/String | Event ID 1004: | |
<subject> | Text/String/Number | Event ID 1005: | |
<subject> | Text/String | Event ID 1006: | |
<subject> | Text/String | Event ID 1007: | |
<subject> | Text/String | Event ID 1008: | |
<subject> | Text/String | Event ID 1009: | |
<subject> | Text/String | Event ID 1010: | |
<subject> | Text/String | Event ID 1011: | |
<subject> | Text/String | Event ID 1012: | |
<subject> | Text/String | Event ID 1013: | |
<subject> | Text/String/Number | Event ID 1014: | |
<subject> | Text/String/Number | Event ID 1015: | |
<subject> | Text/String | Event ID 1016: | |
<subject> | Text/String | Event ID 1017: | |
<subject> | Text/String/Number | Event ID 1018: | |
<subject> | Text/String/Number | Event ID 1019: | |
<subject> | Text/String/IP Address | Event ID 1020: | |
<subject> | Text/String/IP Address | Event ID 1021: | |
<subject> | Text/String/Number | Event ID 1022: | |
<subject> | Text/String | Event ID 1023: | |
<subject> | Text/String | Event ID 1024: | |
<subject> | Text/String/Number | Event ID 1025: | |
<subject> | Text/String/Number | Event ID 1026: | |
<subject> | Text/String/IP Address | Event ID 1027: | |
<subject> | Text/String/Number | Event ID 1028: | |
<subject> | Text/String/Number | Event ID 1029: | |
<subject> | Text/String | Event ID 1030: | |
<subject> | Text/String | Event ID 1031: | |
<subject> | Text/String | Event ID 1032: |