TCP Information

Classification

Rule Name

Rule Type

Common Event

Classification

TCP Information

Base Rule

General TCP/IP Information

Information

Connection Teardown

Sub Rule

Connection Teardown

Network Traffic

Connection Built

Sub Rule

Connection Built

Network Traffic

Mapping with LogRhythm Schema 

Device Key in Log Message

LogRhythm Schema

Data Type

N/A

<vmid>

Text/String

N/A

<severity>

Text/String

N/A

<sip>

IP Address

N/A

<dip>

IP Address

N/A

<sport>

Number

N/A

<dport>

Number

N/A

<sinterface>

Text/String

N/A

<dinterface>

Text/String

N/A

<session>

Number

N/A

<duration>

Number

N/A

<size>

Number

N/A

<tag1>

Text/String