Skip to main content
Skip table of contents

Traffic Events - Deprecated

Vendor Documentation

Classification

Rule NameRule TypeCommon EventClassification
Traffic Events - DeprecatedBase RuleNetwork TrafficNetwork Traffic
Local Traffic TimeoutSub RuleSession DisconnectedOther Audit Success
Local Traffic AcceptSub RuleTraffic Allowed by Network FirewallNetwork Allow
Forwarded Traffic Timed OutSub RuleSession DisconnectedOther Audit Success
Forwarded Traffic AcceptSub RuleTraffic Allowed by Network FirewallNetwork Allow
Forwarded Traffic Session ClosedSub RuleConnection ClosedNetwork Traffic
Forwarded TrafficSub RuleTraffic Allowed by Network FirewallNetwork Allow
Local Traffic AcceptedSub RuleTraffic Allowed by Network FirewallNetwork Allow
Forwarded Traffic StartSub RuleTraffic Allowed by Network FirewallNetwork Allow
Forwarded Traffic AllowedSub RuleTraffic Allowed by Network FirewallNetwork Allow
Malware Activity BlockedSub RuleFailed Botnet ActivityFailed Malware
Invalid TrafficSub RuleConnection FailedNetwork Traffic
ICMP Traffic AllowSub RuleTraffic Allowed by Network FirewallNetwork Allow
Forward Traffic DenySub RuleTraffic Denied by Network FirewallNetwork Deny
Forwarded Traffic DenySub RuleTraffic Denied by Network FirewallNetwork Deny
Local Traffic DenySub RuleTraffic Denied by Network FirewallNetwork Deny
Forwarded Traffic DeniedSub RuleTraffic Denied by Network FirewallNetwork Deny
Local Traffic DeniedSub RuleTraffic Denied by Network FirewallNetwork Deny
Forwarded Traffic Accept - ResetSub RuleConnection ResetNetwork Traffic
Forwarded Traffic CloseSub RuleConnection ClosedNetwork Traffic
Forwarded Traffic TimeoutSub RuleUser Session TimeoutInformation
Local Traffic AcceptedSub RuleTraffic Allowed by Network FirewallNetwork Allow
Local Traffic DeniedSub RuleTraffic Denied by Network FirewallNetwork Deny
Local Traffic AcceptSub RuleTraffic Allowed by Network FirewallNetwork Allow
Forwarded Traffic BlockedSub RuleTraffic Denied by Network FirewallNetwork Deny
Sniffer Traffic AcceptSub RuleTraffic Allowed by Network FirewallNetwork Allow

Mapping with LogRhythm Schema  

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
logid<vmid>NumberThe ID (logid) is a 10-digit field. It is a unique identifier for that specific log.
level<severity>Text\StringEach log entry contains a Level (level) field that indicates the estimated severity of the event that caused the log entry.
srcip<sip>IP AddressIP address of the traffic’s origin.
srcname<sname>Text\StringN/A
dstip<dip>IP AddressDestination IP address for the web.
dstname<dname>Text\StringN/A
srcport<sport>NumberPort number of the traffic's origin
dstport<dport>NumberPort number of the traffic's destination.
transip<snatip>IP AddressN/A
srcintf<sinterface>Text\StringInterface name of the traffic's origin.
dstintf<dinterface>Text\StringInterface of the traffic's destination.
proto<protnum>NumberThe protocol used by web traffic (tcp by default).
service<protname>Text\StringName of the service.
user<login>Text\StringN/A
vd<domainorigin>Text\StringName of the virtual domain in which the log message was recorded.
sessionid<session>NumberID for the session.
app<object>Text\StringN/A
policyid<policy>NumberN/A
group<group>Text\StringN/A
action

<action>

<tag1>

Text\StringN/A
rcvdbyte<bytesin>NumberN/A
sentbyte<bytesout>NumberN/A
rcvdpkt<itemsin>NumberN/A
sentpkt<itemsout>NumberN/A
duration<duration>NumberN/A
status<tag1>Text\StringN/A
subtype<tag2>Text\StringN/A
utmaction<tag3>Text\StringN/A
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.