Skip to main content
Skip table of contents

SmartDefense 1

Vendor Documentation

Classification

Rule NameRule TypeCommon EventClassification
SmartDefenseBase RuleGeneral Firewall LogNetwork Traffic
SmartDefense : Block HTTP Non Compliant : MonitorSub RuleTraffic Allowed by IDS/IPSNetwork Allow
SmartDefense : Block Non HTTP Traffic : MonitorSub RuleTraffic Allowed by IDS/IPSNetwork Allow
SmartDefense : IP Fragments : DropSub RuleIP MicrofragmentActivity
SmartDefense : Protection : OutboundSub RuleEstablished Outbound ConnectionInformation
SmartDefense : Geo_protection: OutboundSub RuleEstablished Outbound ConnectionInformation
SmartDefense : Geo_protection: InboundSub RuleEstablished Inbound ConnectionInformation
SmartDefense : Adobe Reader Violation : MonitorSub RuleTraffic Allowed by IDS/IPSNetwork Allow
SmartDefense : Attempt To Open Audio Con : MonitorSub RuleTraffic Allowed by IDS/IPSNetwork Allow
SmartDefense : Anomaly_http : OutboundSub RuleEstablished Outbound ConnectionInformation
SmartDefense : Block HTTP Non Compliant : RejectSub RuleTraffic Denied by IDS/IPSNetwork Deny
SmartDefense : Anomaly : InboundSub RuleEstablished Inbound ConnectionInformation
SmartDefense : Anomaly : OutboundSub RuleEstablished Outbound ConnectionInformation
SmartDefense : Anomaly : DropSub RuleTraffic Denied by IDS/IPSNetwork Deny
SmartDefense : Apache Svr Protection Viol : DropSub RuleGeneral Failed ActivityFailed Activity
SmartDefense : Apache Svr Protection Viol : DropSub RuleGeneral Failed ActivityFailed Activity
SmartDefense : Content Protection Violation : DropSub RuleGeneral Failed ActivityFailed Activity
SmartDefense : DNS Reserved Header Bit : DropSub RuleFailed Protocol AnomalyFailed Attack
SmartDefense : Geo-Location Enforcement : DropSub RuleTraffic Denied by IDS/IPSNetwork Deny
SmartDefense : HTTP Protocol Inspection : DropSub RuleGeneral Failed ActivityFailed Activity
SmartDefense : HTTP Trfc Ovr Bad Port Viol : DropSub RuleTraffic Denied by IDS/IPSNetwork Deny
SmartDefense : Malformed HTTP : DropSub RuleFailed Malformed ObjectFailed Suspicious
SmartDefense : Malformed Packet : DropSub RuleMalformed PacketNetwork Traffic
SmartDefense : Port Scan : DropSub RuleGeneral Failed ActivityFailed Activity
SmartDefense : SSL Enforcement Violation : DropSub RuleGeneral Failed ActivityFailed Activity
SmartDefense : SSL Tunneling : DropSub RuleFailed Anonymizing ActivityFailed Misuse
SmartDefense : Potl Network Config Problem : DropSub RuleConfiguration FailureWarning
SmartDefense : TCP Segment Limit Enfrcm : DropSub RuleTraffic Denied by IDS/IPSNetwork Deny
SmartDefense : TCP Urgent Data Enforcement : DropSub RuleTraffic Denied by IDS/IPSNetwork Deny
SmartDefense : SYN : DropSub RuleFailed Network Denial Of ServiceFailed Denial of Service
SmartDefense : TCP Enforcement Violation : DropSub RuleTraffic Denied by IDS/IPSNetwork Deny
SmartDefense : Instant Messengers : DropSub RuleFailed IM/Chat ActivityFailed Misuse
SmartDefense : Large Ping : DropSub RuleGeneral Failed ActivityFailed Activity
SmartDefense : Apache Svr Protection Viol : MonSub RuleSecurity ViolationOther Security
SmartDefense : Apache Svr Protection Viol : MonSub RuleSecurity ViolationOther Security
SmartDefense : Content Protection Violation : MonSub RuleSecurity ViolationOther Security
SmartDefense : DNS Reserved Header Bit : MonitorSub RuleProtocol AnomalyAttack
SmartDefense : Geo-Location Enforcement : MonitorSub RuleTraffic Allowed by IDS/IPSNetwork Allow
SmartDefense : HTTP Protocol Inspection : MonitorSub RuleProtocol AnomalyAttack
SmartDefense : HTTP Trfc Ovr Bad Port Viol : MonSub RuleTraffic Allowed by IDS/IPSNetwork Allow
SmartDefense : Malformed HTTP : MonitorSub RuleMalformed ObjectSuspicious
SmartDefense : Malformed Packet : MonitorSub RuleMalformed ObjectSuspicious
SmartDefense : Port Scan : MonitorSub RulePort ScanReconnaissance
SmartDefense : SSL Enforcement Violation : MonitorSub RuleGeneral Failed ActivityFailed Activity
SmartDefense : SSL Tunneling : MonitorSub RuleAnonymizing ActivityMisuse
SmartDefense : Potl Net Config Problem : MonitorSub RuleConfiguration FailureWarning
SmartDefense : TCP Segment Limit Enfrcm : MonitorSub RuleTraffic Allowed by IDS/IPSNetwork Allow
SmartDefense : TCP Urgent Data Enfrcm : MonitorSub RuleTraffic Allowed by IDS/IPSNetwork Allow
SmartDefense : SYN : MonitorSub RuleNetwork Denial Of ServiceDenial Of Service
SmartDefense : TCP Enforcement Violation : MonitorSub RuleTraffic Allowed by IDS/IPSNetwork Allow
SmartDefense : Instant Messengers : MonitorSub RuleIM/Chat ActivityMisuse
SmartDefense : Large Ping : MonitorSub RulePing SweepReconnaissance
SmartDefense : Geo Protection : DroppedSub RuleTraffic Denied by IDS/IPSNetwork Deny
SmartDefense : Geo Protection : MonitorSub RuleTraffic Allowed by IDS/IPSNetwork Allow
SmartDefense : Anomaly : MonitorSub RuleProtocol AnomalyAttack
SmartDefense : Content Protection Violation DetectSub RuleGeneral ActivityActivity
SmartDefense : Non Compliant DNS : DetectSub RuleNon Compliant DNSActivity
SmartDefense : Block HTTP Non CompliantSub RuleBlocked Non-Compliant HTTP FormatActivity
SmartDefense : TCP Segment Limit : AcceptSub RuleGeneral Traffic AllowedNetwork Traffic

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

Product<version>Number/Text
Origin<sender>Number/Text
Action<action>Number/Text
Action<tag3>Number/Text
SIP<sip>Number
SPort<sport>Number
DIP<dip>Number
DPort<dport>Number
Protocol<protnum>Number
Protocol<protname>Number/Text
IFName<sinterface>Text/String
IFDirection<tag4>Number/Text
Reason<reason>Number/Text
Rule<command>Number/Text
PolicyName<policy>Number/Text
XlateSIP<snatip>Number
XlateDIP<dnatip>Number
User<login>Number/Text
src_user_name<login>Number/Text
dst_user_name<account>Number/Text
to<recipient>Number/Text
from<sender>Number/Text
web_client_type<useragent>Number/Text
Url<url>Number/Text
dst_machine_name<dname>Text/String
src_machine_name<sname>Text/String
Attack<tag2>Number/Text
Attack<threatname>Number/Text
Protection_Name<object>Number/Text
Severity<severity>Number/Text
Confidence_Level<responsecode>Number/Text
Industry_Reference<cve>Number/Text
Protection_Type<objecttype>Number/Text
Protection_Type<tag1>Number/Text
rule_name<command>Number/Text
Info<vendorinfo>Number/Text


JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.