Skip to main content
Skip table of contents

Syslog - LogRhythm Log Distribution Services

LogRhythm Log Distribution Services parses logs in a structured way for compatibility with other LogRhythm components.

Device Details

Vendor

LogRhythm

Device Type

Log Distribution Services

Supported Model Name/Number

N/A

Supported Software Version

N/A

Collection Method

Syslog

Configurable Log Output

Yes

Log Source Type

Syslog - LogRhythm Log Distribution Services

Log Processing Policy

LogRhythm Default

Exceptions

N/A

Additional Information

https://logrhythm.com/press-releases/logrhythm-extends-log-event-management-platform/

Document Status

https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/10.10/en/Content/PTA/Configuring-LogRhythm-Forward-syslog-Messages.htm

Currently Supported Log Types

Type

Version

Supported Schema Fields

Service Message

N\A

<severity>, <vmid>, <status>, <sname>, <object>, <reason>, <action>

UAM Message

N\A

<severity>, <parentprocessname>, <action>, <domain>, <login>, <sname>

PM Message

N\A

<severity>, <parentprocessname>, <action>, <processid>, <process>, <domain>, <login>, <sname>, <object>

NCM Message

N\A

<severity>, <parentprocessname>, <action>, <sname>, <protname>, <sip>, <sport>, <dip>, <dport>, <processid>, <process>, <status>, <object>

Event Id Message

N\A

<severity>, <vmid>, <process>, <vendorinfo>, <sname>

CatchAll

N\A

<severity>

Parsed Metadata Fields

Field NameLogRhythm Metadata FieldValue/Data Type
CODEVMIDNumber
ComputerSNameText
DETAILSObjectText
EVENTActionText
EventIDVMIDNumber
HOSTSNameText
KeywordsVendorInfoText
localipSIPIP Address
LOCALPORTSPortNumber
MESSAGEStatusText
originSNameText
OWNER<domain>, <login>Text
PIDProcessIDNumber
PNAMEProcessText
protocolProtNameText
REMOTEIPDIPIP Address
REMOTEPORTDPortNumber
SERVICENAMEObjectText
SEVERITYSeverityText
STATEStatusText
SUGGESTEDACTIONActionText
TaskProcessText
TRIGGEREDWHENReasonText
ValueParentProcessNameText
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.