Skip to main content
Skip table of contents

Syslog - Imperva SecureSphere: V 2.0 : System Events

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

V 2.0 : System Events

Base Rule

General System Event

Information

V 2.0 : User Logged In

Sub Rule

User Logon

Authentication Success

V 2.0 : Agent Status Changed

Sub Rule

Service Status Change

Other Audit Success

V 2.0 : Audit Error

Sub Rule

Audit Record Error

Error

V 2.0 : Agent Disk Quota Exceeded

Sub Rule

Limit Exceeded

Warning

V 2.0 : User Logged Out

Sub Rule

User Logoff

Authentication Success

V 2.0 : Gateway Throughput

Sub Rule

Gateway Message

Information

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

Schema Description

CEF:Version

N/A

N/A

N/A

N/A

N/A

N/A

Device Vendor

N/A

N/A

N/A

Device Product

N/A

<version>

Text/Stirng/Number

Device Version

N/A

<vmid>
<tag1>

Text/Stirng

deviceEventClassId

N/A

<subject>
<tag2>

Text/Stirng

Name

N/A

<severity>

Text/Stirng

Severity

suser

<login>

Text/Stirng

The system user who caused the event. It can
be a specific user who logged into the system or a system user.

rt

N/A

N/A

The system event time

cat

<objecttype>

Text/Stirng

The type of the event

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.