Syslog - LogRhythm Log Distribution Services
LogRhythm Log Distribution Services parses logs in a structured way for compatibility with other LogRhythm components.
Device Details
Vendor | LogRhythm |
---|---|
Device Type | Log Distribution Services |
Supported Model Name/Number | N/A |
Supported Software Version | N/A |
Collection Method | Syslog |
Configurable Log Output | Yes |
Log Source Type | Syslog - LogRhythm Log Distribution Services |
Log Processing Policy | LogRhythm Default |
Exceptions | N/A |
Additional Information | https://logrhythm.com/press-releases/logrhythm-extends-log-event-management-platform/ |
Document Status |
Currently Supported Log Types
Type | Version | Supported Schema Fields |
Service Message | N\A | <severity>, <vmid>, <status>, <sname>, <object>, <reason>, <action> |
UAM Message | N\A | <severity>, <parentprocessname>, <action>, <domain>, <login>, <sname> |
PM Message | N\A | <severity>, <parentprocessname>, <action>, <processid>, <process>, <domain>, <login>, <sname>, <object> |
NCM Message | N\A | <severity>, <parentprocessname>, <action>, <sname>, <protname>, <sip>, <sport>, <dip>, <dport>, <processid>, <process>, <status>, <object> |
Event Id Message | N\A | <severity>, <vmid>, <process>, <vendorinfo>, <sname> |
CatchAll | N\A | <severity> |
Parsed Metadata Fields
Field Name | LogRhythm Metadata Field | Value/Data Type |
CODE | VMID | Number |
Computer | SName | Text |
DETAILS | Object | Text |
EVENT | Action | Text |
EventID | VMID | Number |
HOST | SName | Text |
Keywords | VendorInfo | Text |
localip | SIP | IP Address |
LOCALPORT | SPort | Number |
MESSAGE | Status | Text |
origin | SName | Text |
OWNER | <domain>, <login> | Text |
PID | ProcessID | Number |
PNAME | Process | Text |
protocol | ProtName | Text |
REMOTEIP | DIP | IP Address |
REMOTEPORT | DPort | Number |
SERVICENAME | Object | Text |
SEVERITY | Severity | Text |
STATE | Status | Text |
SUGGESTEDACTION | Action | Text |
Task | Process | Text |
TRIGGEREDWHEN | Reason | Text |
Value | ParentProcessName | Text |