LogRhythm Log Distribution Services parses logs in a structured way for compatibility with other LogRhythm components.
Device Details
|
Vendor |
LogRhythm |
|---|---|
|
Device Type |
Log Distribution Services |
|
Supported Model Name/Number |
N/A |
|
Supported Software Version |
N/A |
|
Collection Method |
Syslog |
|
Configurable Log Output |
Yes |
|
Log Source Type |
Syslog - LogRhythm Log Distribution Services |
|
Log Processing Policy |
LogRhythm Default |
|
Exceptions |
N/A |
|
Additional Information |
https://logrhythm.com/press-releases/logrhythm-extends-log-event-management-platform/ |
|
Document Status |
Currently Supported Log Types
|
Type |
Version |
Supported Schema Fields
|
|
Service Message |
N\A |
<severity>, <vmid>, <status>, <sname>, <object>, <reason>, <action> |
|
UAM Message |
N\A |
<severity>, <parentprocessname>, <action>, <domain>, <login>, <sname> |
|
PM Message |
N\A |
<severity>, <parentprocessname>, <action>, <processid>, <process>, <domain>, <login>, <sname>, <object> |
|
NCM Message |
N\A |
<severity>, <parentprocessname>, <action>, <sname>, <protname>, <sip>, <sport>, <dip>, <dport>, <processid>, <process>, <status>, <object> |
|
Event Id Message |
N\A |
<severity>, <vmid>, <process>, <vendorinfo>, <sname> |
|
CatchAll |
N\A |
<severity> |
Parsed Metadata Fields
|
Field Name |
LogRhythm Metadata Field |
Value/Data Type |
|
CODE |
VMID |
Number |
|
Computer |
SName |
Text |
|
DETAILS |
Object |
Text |
|
EVENT |
Action |
Text |
|
EventID |
VMID |
Number |
|
HOST |
SName |
Text |
|
Keywords |
VendorInfo |
Text |
|
localip |
SIP |
IP Address |
|
LOCALPORT |
SPort |
Number |
|
MESSAGE |
Status |
Text |
|
origin |
SName |
Text |
|
OWNER |
<domain>, <login> |
Text |
|
PID |
ProcessID |
Number |
|
PNAME |
Process |
Text |
|
protocol |
ProtName |
Text |
|
REMOTEIP |
DIP |
IP Address |
|
REMOTEPORT |
DPort |
Number |
|
SERVICENAME |
Object |
Text |
|
SEVERITY |
Severity |
Text |
|
STATE |
Status |
Text |
|
SUGGESTEDACTION |
Action |
Text |
|
Task |
Process |
Text |
|
TRIGGEREDWHEN |
Reason |
Text |
|
Value |
ParentProcessName |
Text |