Skip to main content
Skip table of contents

Traffic : Forward

Vendor Documentation

Classification

Rule NameRule TypeCommon EventClassification
Traffic: ForwardBase RuleNetwork TrafficNetwork Traffic
Network/Traffic Allowed MessagesSub RuleTraffic Allowed by Network FirewallNetwork Allow
Sniffer Traffic AcceptSub RuleTraffic Allowed by Network FirewallNetwork Allow
Forwarded Traffic BlockedSub RuleTraffic Denied by Network FirewallNetwork Deny
Forwarded Traffic TimeoutSub RuleUser Session TimeoutInformation
Forwarded Traffic CloseSub RuleConnection ClosedNetwork Traffic
Forwarded Traffic Accept - ResetSub RuleConnection ResetNetwork Traffic
Local Traffic DeniedSub RuleTraffic Denied by Network FirewallNetwork Deny
Forwarded Traffic DeniedSub RuleTraffic Denied by Network FirewallNetwork Deny
Forward Traffic DenySub RuleTraffic Denied by Network FirewallNetwork Deny
ICMP Traffic AllowSub RuleTraffic Allowed by Network FirewallNetwork Allow
Invalid TrafficSub RuleConnection FailedNetwork Traffic
Malware Activity BlockedSub RuleFailed Botnet ActivityFailed Malware
Forwarded Traffic AllowedSub RuleTraffic Allowed by Network FirewallNetwork Allow
Forwarded Traffic StartSub RuleTraffic Allowed by Network FirewallNetwork Allow
Local Traffic AcceptedSub RuleTraffic Allowed by Network FirewallNetwork Allow
Forwarded TrafficSub RuleTraffic Allowed by Network FirewallNetwork Allow
Forwarded Traffic Session ClosedSub RuleConnection ClosedNetwork Traffic
Forwarded Traffic AcceptSub RuleTraffic Allowed by Network FirewallNetwork Allow
Local Traffic AcceptSub RuleTraffic Allowed by Network FirewallNetwork Allow
Local Traffic TimeoutSub RuleSession DisconnectedOther Audit Success

Mapping with LogRhythm Schema  

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
logid

<vmid>

<tag1>

NumberThe ID (logid) is a 10-digit field. It is a unique identifier for that specific log.
apprisk<severity>Text\StringEach log entry contains a Level (level) field that indicates the estimated severity of the event that caused the log entry.
srcip<sip>IP AddressIP address of the traffic’s origin.
dstip<dip>IP AddressDestination IP address for the web.
srcport<sport>NumberPort number of the traffic's origin.
dstport<dport>NumberPort number of the traffic's destination.
transip<snatip>IP AddressN/A
tranip<dnatip>IP AddressN/A
srcintf<sinterface>Text\StringInterface name of the traffic's origin.
dstintf<dinterface>Text\StringInterface of the traffic's destination.
proto<protnum>NumberThe protocol used by web traffic (tcp by default).
user<login>Text\StringN/A
sessionid<session>NumberID for the session.
appid<processid>NumberID of the application.
app<object>Text\StringName of the application.
appcat<objectname>Text\StringCategory of the application.
devname<subject>Text\StringN/A
url<url>Text\StringN/A
policyid<policy>Number
N/A
group<group>Text\StringN/A
action

<action>

<tag2>

Text\StringN/A
utmaction<result>Text\StringN/A
appact<status>Text\StringN/A
rcvdbyte<bytesin>NumberN/A
sentbyte<bytesout>NumberN/A
duration<duration>NumberN/A
utmaction<tag3>Text\StringN/A
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.