Skip to main content
Skip table of contents

SSH_CLIENT Events

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

SSH_CLIENT Events

Base Rule

General Information Log Message

Information

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

Schema Description

Event ID

<vmid>

Number

Event ID 9001, 9002, 9003

Severity

<severity>

Text/String

For All: Information
For 9002: Error

Message

<subject>
<dip>
<object>
<account>
<dport>

Text/String/Number/IP Address

Event ID 9001:
SSH client session is successful.

<subject>
<dip>
<object>
<dport>

Text/String/Number/IP Address

Event ID 9002:
SSH client session is denied

<subject>
<dip>
<object>
<account>
<dport>

Text/String/Number/IP Address

Event ID 9003:
SSH client session is successful.

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.