Syslog - Generic Linux OS

Device Details

Device NameSyslog - Generic Linux OS
Device TypeLinux OS
Supported Model Name/NumberN/A
Supported Software VersionN/A
Collection MethodSyslog
Configurable Log OutputN/A
Log Source TypeSyslog - Generic Linux OS
Log Processing PolicyLogRhythm Default V 2.0
Additional Information

Support for Linux Application Logs

This new Linux LST does not support Linux application logs. Linux application logs are supported separately with respective log source types. If you are streaming Linux application logs through Syslog - Generic Linux OS, we recommend using log source virtualization to stream application logs

For more information, see Log Source Virtualization.

Supported Log Messages

(List of LR tags used to parse the log information for each message type)

TypeProduct VersionSupported Schema Fields
Account ModifiedN/A<severity>, <tag1>, <dip>, <dname>, <process>, <processid>, <account>, <tag2>, <group>
Account Password ChangedN/A<severity>, <dip>, <dname>, <process>, <processid>, <account>
Anacron MessagesN/A<severity>, <tag1>, <dip>, <dname>, <process>, <processid>, <object>, <tag2>
Apparmor MessagesN/A<severity>, <tag1>, <dip>, <dname>, <process>, <processid>
Apport MessagesN/A<severity>, <tag1>, <dip>, <dname>, <process>, <processid>
Auditd MessagesN/A<severity>, <tag1>, <dip>, <dname>, <process>, <processid>
Augenrules MessagesN/A<severity>, <tag1>, <dip>, <dname>, <process>, <processid>
Catch All : Level 1N/A<severity>, <tag1>
CHFN MessagesN/A<severity>, <tag1>, <dip>, <dname>, <process>, <processid>
Chronyd MessagesN/A<severity>, <tag1>, <dip>, <sname>, <dname>, <process>, <processid>, <tag2>, <amount>
Crond MessagesN/A<severity>, <tag1>, <dip>, <dname>, <process>, <processid>, <tag2>, <login>, <command>, <object>
Dbus Broker MessageN/A<severity>, <tag1>, <dip>, <dname>, <process>, <processid>
Dbus Daemon MessageN/A<severity>, <tag1>, <dip>, <dname>, <process>, <processid>
DNF MessagesN/A<severity>, <tag1>, <dip>, <dname>, <process>, <processid>
Dracut MessagesN/A<severity>, <tag1>, <dip>, <dname>, <process>, <processid>
FSCK MessagesN/A<severity>, <tag1>, <dip>, <dname>, <process>, <processid>
Gpasswd MessagesN/A<severity>, <tag1>, <dip>, <dname>, <process>, <processid>, <account>, <tag2>, <login>, <group>
Group CreatedN/A<severity>, <tag1>, <dip>, <dname>, <process>, <processid>, <group>
Group DeletedN/A<severity>, <tag1>, <dip>, <dname>, <process>, <processid>, <group>
Group ModifiedN/A<severity>, <tag1>, <dip>, <dname>, <process>, <processid>, <group>, <tag2>
Hibernate MessagesN/A<severity>, <tag1>, <dip>, <dname>, <process>, <processid>
Hostname ChangedN/A<severity>, <tag1>, <dip>, <dname>, <process>, <processid>, <objectname>
Journal Daemon MessagesN/A<severity>, <tag1>, <dip>, <dname>, <process>, <processid>, <tag2>
Journal MessagesN/A<severity>, <tag1>, <dip>, <dname>, <process>, <processid>
Kdump MessagesN/A<severity>, <tag1>, <dip>, <dname>, <process>, <processid>
Kernel MessagesN/A<severity>, <tag1>, <dip>, <dname>, <process>
Login Daemon MessagesN/A<severity>, <tag1>, <dip>, <dname>, <process>, <processid>
Login MessagesN/A<severity>, <dip>, <dname>, <process>, <processid>, <tag1>, <login>
LVM MessagesN/A<severity>, <tag1>, <dip>, <dname>, <process>, <processid>
ModemManager MessagesN/A<severity>, <tag1>, <dip>, <dname>, <process>, <processid>
Modules Daemon MessagesN/A<severity>, <tag1>, <dip>, <dname>, <process>, <processid>
MOTD MessagesN/A<severity>, <tag1>, <dip>, <dname>, <process>, <processid>
Multipathd MessagesN/A<severity>, <tag1>, <dip>, <dname>, <process>, <processid>
Network Daemon MessagesN/A<severity>, <tag1>, <dip>, <dname>, <process>, <processid>, <dinterface>, <status>, <tag2>, <dip>, <sip>
Network Daemon Messages - Wait OnlineN/A<severity>, <tag1>, <dip>, <dname>, <process>, <processid>
Networkd MessagesN/A<severity>, <tag1>, <dip>, <dname>, <process>, <processid>
NetworkManager MessagesN/A<severity>, <tag1>, <dip>, <dname>, <process>, <processid>, <tag2>, <dinterface>
PAM Helper MessagesN/A<severity>, <tag1>, <dip>, <dname>, <process>, <processid>, <tag2>, <login>
Polkitd MessagesN/A<severity>, <tag1>, <dip>, <dname>, <process>, <processid>
Rc.local MessagesN/A<severity>, <tag1>, <dip>, <dname>, <process>, <processid>
Resolve Daemon MessagesN/A<severity>, <tag1>, <dip>, <dname>, <process>, <processid>
Rsyslogd MessagesN/A<severity>, <tag1>, <dip>, <dname>, <process>, <processid>
Run-parts MessagesN/A<severity>, <tag1>, <dip>, <dname>, <process>, <processid>, <object>, <tag2>
SETroubleshoot MessagesN/A<severity>, <tag1>, <dip>, <dname>, <process>, <processid>
Snapd MessagesN/A<severity>, <tag1>, <dip>, <dname>, <process>, <processid>
SSHD MessagesN/A<severity>, <tag1>, <dip>, <dname>, <process>, <processid>, <tag2>, <login>, <sip>, <sport>
SU MessagesN/A<severity>, <dip>, <dname>, <process>, <account>, <login>
Sudo MessagesN/A<severity>, <dip>, <dname>, <process>, <tag1>, <account>, <login>, <command>
System Daemon General MessagesN/A<severity>, <tag1>, <dip>, <dname>, <process>, <processid>
Udev Admin MessagesN/A<severity>, <tag1>, <dip>, <dname>, <process>, <processid>
Udev Daemon MessagesN/A<severity>, <tag1>, <dip>, <dname>, <process>, <processid>
Udisk Daemon MessagesN/A<severity>, <tag1>, <dip>, <dname>, <process>, <processid>
User Account CreatedN/A<severity>, <tag1>, <dip>, <dname>, <process>, <processid>, <tag2>, <account>, <group>
User Account DeletedN/A<severity>, <tag1>, <dip>, <dname>, <process>, <processid>, <tag2>, <account>, <group>

Revision History

KB Version

Log Type

Change Type


KB 7.1.672.0Syslog - Generic Linux OSNew Device DocumentationN/A
