Skip to main content
Skip table of contents

Sudo Message

Classification

Rule Name

Rule Type

Common Event

Classification

Sudo MessageBase RuleGeneral Sudo CommandActivity
GDM Configuration System AccessedSub RuleObject AccessedAccess Success
User Modify Command ExecutedSub RuleUser Account Attribute ModifiedAccount Modified
BASH Shell ExecutedSub RuleCommand ExecutedAccess Success
Change Owner Command ExecutedSub RuleCommand ExecutedAccess Success
Passwd Command ExecutedSub RuleCommand ExecutedAccess Success
Change Mode Command ExecutedSub RuleCommand ExecutedAccess Success
User Delete Command ExecutedSub RuleUser Account DeletedAccount Deleted
User Add Command ExecutedSub RuleUser Account CreatedAccount Created
Service EnabledSub RuleProcess/Service StartedStartup and Shutdown
Service DisabledSub RuleProcess/Service StoppedStartup and Shutdown
Service RestartedSub RuleProcess/Service RestartedStartup and Shutdown

Mapping with LogRhythm Schema  

Device Key in Log MessageLogRhythm SchemaData Type
Host<sname>Text\String
N/A<dname>Text\String
N/A<login>Text\String
User<account>Number
COMMAND<object>Text\String
N/A<tag1>Text\String
N/A<tag2>Text\String
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.