Skip to main content
Skip table of contents

Syslog - Generic Linux OS: SU Messages

Vendor Documentation

N/A

Classification

Rule Name

Rule Type

Common Event

Classification

SU Messages

Base Rule

User Logon

Authentication Success

Failed SU Message

Sub Rule

Authentication Failure Activity

Authentication Failure

Session Opened Message

Sub Rule

Session Opened

Information

Session Closed Message

Sub Rule

Session Closed

Information

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

Schema Description

N/A

<severity>

Text/String

N/A

N/A

<dip>

IP Address

N/A

N/A

<dname>

Text/String

N/A

N/A

<process>

Text/String

N/A

N/A

<processid>

Number

N/A

N/A

<subject>

Text/String

N/A

N/A

<tag1>

Text/String

N/A

N/A

<account>

Text/String

N/A

N/A

<login>

Text/String

N/A

N/A

<object>

Text/String

N/A

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.