Skip to main content
Skip table of contents

System Call Activity

Classification

Rule Name

Rule Type

Common Event

Classification

System Call ActivityBase RuleSystem CallOther Audit Success
x64 File Open Permission DeniedSub RuleAccess Object FailureAccess Failure
x64 File Delete FailedSub RuleFile Delete FailureError
CHMOD Filesystem ObjectSub RuleObject ModifiedAccess Success
CHOWN Filesystem ObjectSub RuleObject ModifiedAccess Success
Signal ReturnSub RuleReturn Status IgnoreInformation
FCHMOD Filesystem ObjectSub RuleObject ModifiedAccess Success
CHMOD Filesystem ObjectSub RuleObject ModifiedAccess Success
x64 File Open Permission DeniedSub RuleAccess Object FailureAccess Failure
Unmount VolumeSub RuleFile System UnmountedInformation
Mount VolumeSub RuleFile System MountedInformation
Program ExecutedSub RuleProgram ExecutedInformation
CHMOD Filesystem Object x64Sub RuleObject ModifiedAccess Success
CHMOD Filesystem Object x32Sub RuleObject ModifiedAccess Success
CHMOD Filesystem Object x32Sub RuleObject ModifiedAccess Success
CHMOD Filesystem Object x32Sub RuleObject ModifiedAccess Success
CHOWN Filesystem Object x64Sub RuleObject ModifiedAccess Success
CHOWN Filesystem Object x64Sub RuleObject ModifiedAccess Success
CHOWN Filesystem Object x64Sub RuleObject ModifiedAccess Success
CHOWN Filesystem Object x32Sub RuleObject ModifiedAccess Success
CHOWN Filesystem Object x32Sub RuleObject ModifiedAccess Success
CHOWN Filesystem Object x32Sub RuleObject ModifiedAccess Success
CHOWN Filesystem Object x32Sub RuleObject ModifiedAccess Success
Mount Volume x32Sub RuleFile System MountedInformation
Unmount Volume x32Sub RuleFile System UnmountedInformation
Program Executed x32Sub RuleProgram ExecutedInformation

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

N/A<severity>Text/String
type<vmid>Text/String
arch<version>Number/String
syscall<command>Number
success<result>, <tag2>Text/String
exit<subject>Number
ppid<parentprocessid>Number
pid<processid>Number
auid<login>Number
uid<account>Number
gid<group>Number
ses<session>Number
comm<process>Text/String
exe<object>Text/String
key<objectname>Number/Text
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.