Shun Activity

Classification

Rule Name

Rule Type

Common Event

Classification

Shun Activity

Base Rule

Traffic Denied by Network Firewall

Network Deny

EVID 401002 : Shun Added

Sub Rule

Traffic Denied by Network Firewall

Network Deny

EVID 401003 : Shun Deleted

Sub Rule

Configuration Modified : Network Access

Configuration

EVID 401004 : Outside Packet Shunned

Sub Rule

Traffic Denied by Network Firewall

Network Deny

Mapping with LogRhythm Schema 

Device Key in Log Message

LogRhythm Schema

Data Type

N/A

<vmid>

Number

N/A

<Severity>

Number

N/A

<sip>

IP Address

N/A

<sname>

Text/String

N/A

<dip>

IP Address

N/A

<dname>

Text/String

N/A

<sport>

Number

N/A

<dport>

Number

N/A

<process>

Text/String

N/A

<object>

Text/String