Shell Access

Classification

Rule Name

Rule Type

Classification

Common Event

Shell Access

Base Rule

Audit : Access Success

Object Initialized

Volatile Shell Access

Sub Rule

Access Success

Object Initialized

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

LOC0

<severity>

Text/String

N/A

<process>

Text/String

N/A

<processid>

Number

N/A

<account>

Text/String

N/A

<dname>

Text/String

t

<tag1>

Text/String

clish

<login>

Text/String