Vendor Documentation
Classification
|
Rule Name |
Rule Type |
Common Event |
Classification |
|---|---|---|---|
|
System Event Messages |
Base Rule |
General System Message |
Information |
Mapping with LogRhythm Schema
|
Device Key in Log Message |
LogRhythm Schema |
Data Type |
Schema Description |
|
N/A |
N/A |
N/A |
Common Event Format identifier: Default or unspecified severity level (can be replaced with specific severity levels such as 1-10). |
|
N/A |
N/A |
N/A |
Vendor or organization name. |
|
N/A |
N/A |
N/A |
Product or service name generating the event. |
|
N/A |
<version> |
Number |
Version number. |
|
N/A |
<vmid> |
Text/String |
log_id |
|
N/A |
<vendorinfo> |
Text/String |
Description. |
|
N/A |
<severity> |
Text/String |
Severity level of the event. |
|
id |
<session> |
Text/String |
N/A |
|
src |
<sip> |
IP Address |
N/A |
|
shost |
<sname> |
Text/String |
N/A |
|
msg |
<subject> |
Text/String |
N/A |
|
rawEvent |
N/A |
N/A |
N/A |