Su Session Opened/Closed

Classification

Rule Name

Rule Type

Common Event

Classification

Su Session Opened/Closed

Base Rule

Authentication Activity

Authentication Success

Switch User Opened

Sub Rule

Session Initialization

Information

Switch User Closed

Sub Rule

Session Closed

Other Audit Success

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

N/A

<severity>

Text\String

N/A

<dname>

Text\String

N/A

<login>

Text\String

N/A

<account>

Text\String

N/A

<process>

Text\String

N/A

<parentprocessname>

Text\String

N/A

<parentprocessid>

Number

N/A

<object>

Number

N/A

<subject>

Text\String

N/A

<tag1>

Text\String