Skip to main content
Skip table of contents

System Events (Syslog - Trend Micro Deep Discovery Analyzer CEF)

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

System Events

Base Rule

General Audit Messages

Information

System Setting Modification Log Message

SubRule

General System Message

Information

Authentication Activity Log Message

SubRule

General Authentication Event

Other Audit

System Update Log Message

SubRule

General System Message

Information

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

Schema Description

N/A

N/A

N/A

CEF format version

N/A

N/A

N/A

Appliance vendor

N/A

N/A

N/A

Appliance product

N/A

<version>

Numbers

Appliance version

N/A

<vmid>

Numbers

Event ID

  • 300102 (PRODUCT_UPDATE)

  • 300999 (SYSTEM_EVENT)

N/A

<vendorinfo>

Text/String

Description

N/A

<severity>

Number

Severity
3: Informational

rt

N/A

N/A

Analysis Time

dvc

<dip>

IP Address

Appliance IP address

dvchost

<dname>

Text/String

Appliance hostname

dvcmac

<dmac>

Text/String/Numbers

Appliance MAC address

deviceExternalId

N/A

N/A

Appliance GUID

cs1Label

N/A

N/A

Event Type Label

cs1

<objecttype>
<tag1>

Text/String

Event Type

outcome

<result>

Text/String

N/A

duser

<account>

Text/String

N/A

sip

<sip>

IP Address

N/A

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.