Sudo Messages

Classification

Rule Name

Rule Type

Common Event

Classification

Sudo Messages

Production

General Sudo Command

Activity

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

N/A

<tag1>

Text/String

N/A

<login>

Number/Text

N/A

<account>

Text/String

N/A

<object>

Text/Number