Syslog - LogRhythm Log Distribution Services
LogRhythm Log Distribution Services parses logs in a structured way for compatibility with other LogRhythm components.
Device Details
Vendor | LogRhythm |
|---|---|
Device Type | Log Distribution Services |
Supported Model Name/Number | N/A |
Supported Software Version | N/A |
Collection Method | Syslog |
Configurable Log Output | Yes |
Log Source Type | Syslog - LogRhythm Log Distribution Services |
Log Processing Policy | LogRhythm Default |
Exceptions | N/A |
Additional Information | https://logrhythm.com/press-releases/logrhythm-extends-log-event-management-platform/ |
Document Status |
Currently Supported Log Types
Type | Version | Supported Schema Fields |
Service Message | N\A | <severity>, <vmid>, <status>, <sname>, <object>, <reason>, <action> |
UAM Message | N\A | <severity>, <parentprocessname>, <action>, <domain>, <login>, <sname> |
PM Message | N\A | <severity>, <parentprocessname>, <action>, <processid>, <process>, <domain>, <login>, <sname>, <object> |
NCM Message | N\A | <severity>, <parentprocessname>, <action>, <sname>, <protname>, <sip>, <sport>, <dip>, <dport>, <processid>, <process>, <status>, <object> |
Event Id Message | N\A | <severity>, <vmid>, <process>, <vendorinfo>, <sname> |
CatchAll | N\A | <severity> |
Parsed Metadata Fields
| Field Name | LogRhythm Metadata Field | Value/Data Type |
| CODE | VMID | Number |
| Computer | SName | Text |
| DETAILS | Object | Text |
| EVENT | Action | Text |
| EventID | VMID | Number |
| HOST | SName | Text |
| Keywords | VendorInfo | Text |
| localip | SIP | IP Address |
| LOCALPORT | SPort | Number |
| MESSAGE | Status | Text |
| origin | SName | Text |
| OWNER | <domain>, <login> | Text |
| PID | ProcessID | Number |
| PNAME | Process | Text |
| protocol | ProtName | Text |
| REMOTEIP | DIP | IP Address |
| REMOTEPORT | DPort | Number |
| SERVICENAME | Object | Text |
| SEVERITY | Severity | Text |
| STATE | Status | Text |
| SUGGESTEDACTION | Action | Text |
| Task | Process | Text |
| TRIGGEREDWHEN | Reason | Text |
| Value | ParentProcessName | Text |