SU Command Completed2

Classification

Rule Name

Rule Type

Classification

Common Event

SU Command Completed2

Base Rule

Audit : Authentication Success

User Logon

SU To Root

Sub Rule

Authentication Success

User Logon

Failed SU

Sub Rule

Authentication Failure

User Logon Failure

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

SAU1

<severity>

Text/String

Jun 30 18:33:36

<sname>

Text/String

N/A

<login>

Text/String

N/A

<account>

Text/String

on

<object>

Text/String

N/A

<result>

Text/String

N/A

<tag1>

Text/String