Skip to main content
Skip table of contents

SmartDefense

Vendor Documentation

Log Fields and Parsing

This section details the log fields available in this log message type, along with values parsed for both LogRhythm Default and LogRhythm Default v2.0 policies. A value of "N/A" (not applicable) means that there is no value parsed for a specified log field.

Log FieldLogRhythm DefaultLogRhythm Default v2.0
Product<version><vmid>
Origin<sender>N/A
Action<action>
<tag3>
<action>
<tag2>
SIP<sip><sip>
SPort<sport><sport>
DIP<dip><dip>
DPort<dport><dport>
Protocol<protnum>\<protname><protnum>
IFName<sinterface><sinterface>
IFDirection<tag4>N/A
Reason<reason><reason>
Rule<command>N/A
PolicyName<policy>N/A
XlateSIP<snatip><snatip>
XlateSportN/A<snatport>
XlateDIP<dnatip><dnatip>
XlateDportN/A<dnatport>
User<login>N/A
src_user_name<login><login>
dst_user_name<account><account>
to<recipient><recipient>
from<sender><sender>
web_client_type<useragent>N/A
Url<url><url>
dst_machine_name<dname><dname>
src_machine_name<sname><sname>
Attack<threatname>
<tag2>
<vendorinfo>
<tag1>
AttackInfoN/A<threatname>
Protection_Name<object>N/A
Severity<severity><severity>
Confidence_Level<responsecode>N/A
Industry_Reference<cve><cve>
Protection_Type<objecttype>
<tag1>
N/A
rule_name<command>N/A
Info<vendorinfo>N/A
__policy_id_tagN/A<policy>

Log Processing Settings

This section details log processing changes made from the LogRhythm Default policy to LogRhythm Default v2.0. In some cases, base rules are broken down into sub-rules to appropriately parse log message types by their event types.

LogRhythm Default

Rule ID

Rule Name

Rule Type

Common Event

Classification

1010513SmartDefenseBase RuleGeneral Firewall LogNetwork Traffic
SmartDefense : Block HTTP Non Compliant : MonitorSub RuleTraffic Allowed by IDS/IPSNetwork Allow
SmartDefense : Block Non HTTP Traffic : MonitorSub RuleTraffic Allowed by IDS/IPSNetwork Allow
SmartDefense : IP Fragments : DropSub RuleIP MicrofragmentActivity
SmartDefense : Protection : OutboundSub RuleEstablished Outbound ConnectionInformation
SmartDefense : Geo_protection: OutboundSub RuleEstablished Outbound ConnectionInformation
SmartDefense : Geo_protection: InboundSub RuleEstablished Inbound ConnectionInformation
SmartDefense : Adobe Reader Violation : MonitorSub RuleTraffic Allowed by IDS/IPSNetwork Allow
SmartDefense : Attempt To Open Audio Con : MonitorSub RuleTraffic Allowed by IDS/IPSNetwork Allow
SmartDefense : Anomaly_http : OutboundSub RuleEstablished Outbound ConnectionInformation
SmartDefense : Block HTTP Non Compliant : RejectSub RuleTraffic Denied by IDS/IPSNetwork Deny
SmartDefense : Anomaly : InboundSub RuleEstablished Inbound ConnectionInformation
SmartDefense : Anomaly : OutboundSub RuleEstablished Outbound ConnectionInformation
SmartDefense : Anomaly : DropSub RuleTraffic Denied by IDS/IPSNetwork Deny
SmartDefense : Apache Svr Protection Viol : DropSub RuleGeneral Failed ActivityFailed Activity
SmartDefense : Apache Svr Protection Viol : DropSub RuleGeneral Failed ActivityFailed Activity
SmartDefense : Content Protection Violation : DropSub RuleGeneral Failed ActivityFailed Activity
SmartDefense : DNS Reserved Header Bit : DropSub RuleFailed Protocol AnomalyFailed Attack
SmartDefense : Geo-Location Enforcement : DropSub RuleTraffic Denied by IDS/IPSNetwork Deny
SmartDefense : HTTP Protocol Inspection : DropSub RuleGeneral Failed ActivityFailed Activity
SmartDefense : HTTP Trfc Ovr Bad Port Viol : DropSub RuleTraffic Denied by IDS/IPSNetwork Deny
SmartDefense : Malformed HTTP : DropSub RuleFailed Malformed ObjectFailed Suspicious
SmartDefense : Malformed Packet : DropSub RuleMalformed PacketNetwork Traffic
SmartDefense : Port Scan : DropSub RuleGeneral Failed ActivityFailed Activity
SmartDefense : SSL Enforcement Violation : DropSub RuleGeneral Failed ActivityFailed Activity
SmartDefense : SSL Tunneling : DropSub RuleFailed Anonymizing ActivityFailed Misuse
SmartDefense : Potl Network Config Problem : DropSub RuleConfiguration FailureWarning
SmartDefense : TCP Segment Limit Enfrcm : DropSub RuleTraffic Denied by IDS/IPSNetwork Deny
SmartDefense : TCP Urgent Data Enforcement : DropSub RuleTraffic Denied by IDS/IPSNetwork Deny
SmartDefense : SYN : DropSub RuleFailed Network Denial Of ServiceFailed Denial of Service
SmartDefense : TCP Enforcement Violation : DropSub RuleTraffic Denied by IDS/IPSNetwork Deny
SmartDefense : Instant Messengers : DropSub RuleFailed IM/Chat ActivityFailed Misuse
SmartDefense : Large Ping : DropSub RuleGeneral Failed ActivityFailed Activity
SmartDefense : Apache Svr Protection Viol : MonSub RuleSecurity ViolationOther Security
SmartDefense : Apache Svr Protection Viol : MonSub RuleSecurity ViolationOther Security
SmartDefense : Content Protection Violation : MonSub RuleSecurity ViolationOther Security
SmartDefense : DNS Reserved Header Bit : MonitorSub RuleProtocol AnomalyAttack
SmartDefense : Geo-Location Enforcement : MonitorSub RuleTraffic Allowed by IDS/IPSNetwork Allow
SmartDefense : HTTP Protocol Inspection : MonitorSub RuleProtocol AnomalyAttack
SmartDefense : HTTP Trfc Ovr Bad Port Viol : MonSub RuleTraffic Allowed by IDS/IPSNetwork Allow
SmartDefense : Malformed HTTP : MonitorSub RuleMalformed ObjectSuspicious
SmartDefense : Malformed Packet : MonitorSub RuleMalformed ObjectSuspicious
SmartDefense : Port Scan : MonitorSub RulePort ScanReconnaissance
SmartDefense : SSL Enforcement Violation : MonitorSub RuleGeneral Failed ActivityFailed Activity
SmartDefense : SSL Tunneling : MonitorSub RuleAnonymizing ActivityMisuse
SmartDefense : Potl Net Config Problem : MonitorSub RuleConfiguration FailureWarning
SmartDefense : TCP Segment Limit Enfrcm : MonitorSub RuleTraffic Allowed by IDS/IPSNetwork Allow
SmartDefense : TCP Urgent Data Enfrcm : MonitorSub RuleTraffic Allowed by IDS/IPSNetwork Allow
SmartDefense : SYN : MonitorSub RuleNetwork Denial Of ServiceDenial Of Service
SmartDefense : TCP Enforcement Violation : MonitorSub RuleTraffic Allowed by IDS/IPSNetwork Allow
SmartDefense : Instant Messengers : MonitorSub RuleIM/Chat ActivityMisuse
SmartDefense : Large Ping : MonitorSub RulePing SweepReconnaissance
SmartDefense : Anomaly : MonitorSub RuleProtocol AnomalyAttack
SmartDefense : Content Protection Violation DetectSub RuleGeneral ActivityActivity
SmartDefense : Non Compliant DNS : DetectSub RuleNon Compliant DNSActivity
SmartDefense : Block HTTP Non CompliantSub RuleBlocked Non-Compliant HTTP FormatActivity
SmartDefense : TCP Segment Limit : AcceptSub RuleGeneral Traffic AllowedNetwork Traffic
Attack FailedSub RuleFailed General Attack ActivityFailed Attack

LogRhythm Default v2.0

Rule IDRule NameRule TypeCommon EventClassification
1012010V 2.0 : Smart Defense EventsBase RuleGeneral Threat MessageActivity
V 2.0 : SmartDefense : Accept ActionSub RuleGeneral Attack ActivityAttack
V 2.0 : SmartDefense : Detect ActionSub RuleGeneral Attack ActivityAttack
V 2.0 : SmartDefense : Drop ActionSub RuleThreat BlockedFailed Activity
V 2.0 : Adobe Reader Violation : MonitorSub RuleAdobe Reader ViolationActivity
V 2.0 : Apache Server Protection Violation : DropSub RuleFailed General Attack ActivityFailed Attack
V 2.0 : Apache Srvr Protection Violation : MonitorSub RuleApache Web Server MessageInformation
V 2.0 : Audio Connection Attempt : MonitorSub RuleConnection AttemptNetwork Traffic
V 2.0 : Block HTTP Non-Compliant : MonitorSub RuleNoncompliant AttributesWarning
V 2.0 : Block HTTP Non Compliant : RejectSub RuleBlocked Non-Compliant HTTP FormatActivity
V 2.0 : Block Non HTTP Traffic : MonitorSub RuleGeneral Network TrafficNetwork Traffic
V 2.0 : Content Protection Violation : MonitorSub RuleSecurity Policy ViolationWarning
V 2.0 : Content Protection Violation : DropSub RuleGeneral Failed ActivityFailed Activity
V 2.0 : DNS Reserved Header Bit : MonitorSub RuleProtocol AnomalyAttack
V 2.0 : DNS Reserved Header Bit : DropSub RuleFailed Protocol AnomalyFailed Attack
V 2.0 : Geo-location Enforcement : MonitorSub RuleGeo-Location EnforcementOther Operations
V 2.0 : Geo-location Enforcement : DropSub RuleFailed General Attack ActivityFailed Attack
V 2.0 : HTTP Protocol Inspection : MonitorSub RuleHTTP Message Violates Inspection RuleInformation
V 2.0 : HTTP Protocol Inspection : DropSub RuleGeneral Failed ActivityFailed Activity
V 2.0 : Non-Standard Port HTTP Violation : MonitorSub RuleHTTP Security ViolationOther Security
V 2.0 : Non-Standard Port HTTP Violation : DropSub RuleFailed Protocol AnomalyFailed Attack
V 2.0 : Instant Messengers : MonitorSub RuleIM/Chat ActivityMisuse
V 2.0 : Instant Messengers : DropSub RuleFailed IM/Chat ActivityFailed Misuse
V 2.0 : IP Fragments : DropSub RuleThreat BlockedFailed Activity
V 2.0 : Large Ping : MonitorSub RulePing RequestNetwork Traffic
V 2.0 : Large Ping : DropSub RuleGeneral Failed ActivityFailed Activity
V 2.0 : Malformed HTTP : MonitorSub RuleMalformed ObjectSuspicious
V 2.0 : Malformed HTTP : DropSub RuleFailed Malformed ObjectFailed Suspicious
V 2.0 : Malformed Packet : MonitorSub RuleMalformed / Bad Packet DetectedNetwork Traffic
V 2.0 : Malformed Packet : DropSub RuleFailed Malformed ObjectFailed Suspicious
V 2.0 : Non Compliant DNS : DetectSub RuleNon Compliant DNSActivity
V 2.0 : Port Scan : MonitorSub RulePort ScanReconnaissance
V 2.0 : Port Scan : DropSub RulePort Scan Activity DroppedFailed Activity
V 2.0 : SSL Enforcement Violation : MonitorSub RuleSSL EnforcementActivity
V 2.0 : SSL Enforcement Violation : DropSub RuleDrop VPN - SSL EnforcementFailed Activity
V 2.0 : SSL Tunneling : MonitorSub RuleGeneral TUNNEL MessageInformation
V 2.0 : SSL Tunneling : DropSub RuleSecure Tunnel DeletedInformation
V 2.0 : Stream Engine : Net Conf Problem : MonitorSub RuleGeneral Configuration ErrorError
V 2.0 : Stream Engine : Network Conf Problem: DropSub RuleConfiguration FailureNetwork Traffic
V 2 : Stream Engine : TCP Seg Limit Enf : MonitorSub RuleGeneral TCP/IP InformationInformation
V 2.0 : Stream Engine : TCP Seg Limit Enf : DropSub RuleTCP Packet DroppedInformation
V 2.0 : Stream Engine : TCP Seg Limit Enf : AcceptSub RulePermitted TCP PacketNetwork Traffic
V 2.0 : Stream Engine : TCP Urg Data Enf : MonitorSub RuleTCP Urgent Data EnforcementNetwork Traffic
V 2.0 : Stream Engine : TCP Urg Data Enf : DropSub RuleTCP Packet DroppedInformation
V 2.0 : SmartDefense : SYN : MonitorSub RulePacket ReceivedNetwork Traffic
V 2.0 : SmartDefense : SYN : DropSub RulePacket DroppedWarning
V 2.0 : TCP Enforcement Violation : MonitorSub RuleGeneral Protocol ViolationError
V 2.0 : TCP Enforcement Violation : DropSub RuleGeneral Failed ActivityFailed Activity
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.