SSH Server Events
Vendor Documentation
https://www.arubanetworks.com/techdocs/AOS-CX/10.07/HTML/5200-8214/Content/fir-int.htm https://www.arubanetworks.com/techdocs/AOS-CX/10.07/PDF/5200-8214.pdf |
Classification
Rule Name | Rule Type | Common Event | Classification |
|---|---|---|---|
SSH Server Events | Base Rule | General Information Log Message | Information |
Mapping with LogRhythm Schema
Device Key in Log Message | LogRhythm Schema | Data Type | Schema Description |
Event ID | <vmid> | Number | Event ID 5201, 5202, 5203, 5204, 5205, 5207, 5208, 5209, 5210, 5211, 5212, 5213, 5214, 5215, 5216, 5217, 5218, 5219, 5220, 5221, 5222, 5223 |
Severity | <severity> | Text/String | For 5201, 5202, 5203, 5204, 5205, 5207, 5209, 5211, 5218: Information |
Message | <subject> | Text/String | Event ID 5201: |
<subject> | Text/String | Event ID 5202: | |
<subject> | Text/String | Event ID 5203: | |
<subject> | Text/String | Event ID 5204: | |
<subject> | Text/String | Event ID 5205: | |
<subject> | Text/String | Event ID 5207: | |
<subject> | Text/String | Event ID 5208: | |
<subject> | Text/String/IP Address | Event ID 5209: | |
<subject> | Text/String/IP Address | Event ID 5210: | |
<subject> | Text/String/IP Address | Event ID 5211: | |
<subject> | Text/String/IP Address | Event ID 5212: | |
<subject> | Text/String/IP Address | Event ID 5214: |