Sophos Anti-Virus Message
Vendor Documentation
Classification
| Rule Name | Rule Type | Classification | Common Event |
|---|---|---|---|
| Sophos Anti-Virus Message | Base Rule | Ops/Warning | General Anti-Virus Warning |
Mapping with LogRhythm Schema
| Device Key in Log Message | LogRhythm Schema | Data Type | Schema Description |
| <vmid> | Number | ||
<severity> | Text\String | ||
| <process> | Text\String | ||
| <processid> | Number | ||
| <objectname> | Text\String | ||
| <subject> | Text\String | ||
| <threatname> | Text\String |