Skip to main content
Skip table of contents

Traffic : Forward 1

Vendor Documentation

Classification

Rule Name

Rule Type

Classification

Common Event

Traffic: ForwardBase RuleNetwork TrafficNetwork Traffic
Sniffer Traffic AcceptSub RuleNetwork AllowTraffic Allowed by Network Firewall
Forwarded Traffic BlockedSub RuleNetwork DenyTraffic Denied by Network Firewall
Local Traffic AcceptSub RuleNetwork AllowTraffic Allowed by Network Firewall
Local Traffic DeniedSub RuleNetwork DenyTraffic Denied by Network Firewall
Local Traffic AcceptedSub RuleNetwork AllowTraffic Allowed by Network Firewall
Forwarded Traffic TimeoutSub RuleInformationUser Session Timeout
Forwarded Traffic CloseSub RuleNetwork TrafficConnection Closed
Forwarded Traffic Accept - ResetSub RuleNetwork TrafficConnection Reset
Local Traffic DeniedSub RuleNetwork DenyTraffic Denied by Network Firewall
Forwarded Traffic DeniedSub RuleNetwork DenyTraffic Denied by Network Firewall
Local Traffic DenySub RuleNetwork DenyTraffic Denied by Network Firewall
Forwarded Traffic DenySub RuleNetwork DenyTraffic Denied by Network Firewall
Forward Traffic DenySub RuleNetwork DenyTraffic Denied by Network Firewall
ICMP Traffic AllowSub RuleNetwork AllowTraffic Allowed by Network Firewall
Invalid TrafficSub RuleNetwork TrafficConnection Failed
Malware Activity BlockedSub RuleFailed MalwareFailed Botnet Activity
Forwarded Traffic AllowedSub RuleNetwork AllowTraffic Allowed by Network Firewall
Forwarded Traffic StartSub RuleNetwork AllowTraffic Allowed by Network Firewall
Local Traffic AcceptedSub RuleNetwork AllowTraffic Allowed by Network Firewall
Forwarded TrafficSub RuleNetwork AllowTraffic Allowed by Network Firewall
Forwarded Traffic Session ClosedSub RuleNetwork TrafficConnection Closed
Forwarded Traffic AcceptSub RuleNetwork AllowTraffic Allowed by Network Firewall
Forwarded Traffic Timed OutSub RuleOther Audit SuccessSession Disconnected
Local Traffic AcceptSub RuleNetwork AllowTraffic Allowed by Network Firewall
Local Traffic TimeoutSub RuleOther Audit SuccessSession Disconnected
Network/Traffic Allowed MessagesSub RuleNetwork AllowTraffic Allowed by Network Firewall

Mapping with LogRhythm Schema  

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
devname<subject>Text/Stringseverity
logid

<vmid>

<tag1>

NumberN/A
level<severity>Number/TextN/A
srcip<sip>IP AddressIP Address
srcport<sport>NumberN/A
srcintf<sinterface>Text/String/NumberN/A
dstip<dip>IP AddressIP Address
dstport<dport>NumberN/A
dstintf<dinterface>Text/String/NumberN/A
sessionid<session>Number/Text/StringN/A
proto<protnum>NumberN/A
action

<action>

<tag2>

Text/StringN/A
user<login>Text/StringN/A
group<group>Text/StringN/A
policyid<policy>NumberN/A
tranip<dnatip>IP AddressIP Address
transip<snatip>IP AddressIP Address
appid<processid>NumberN/A
app<object>Text/StringN/A
appcat<objectname>Text/StringN/A

appact

<status>Text/StringN/A
apprisk<severity>Text/StringN/A
url<url>Text/StringN/A
duration<duration>NumberN/A
sentbyte<bytesout>NumberN/A
rcvdbyte<bytesin>NumberN/A
utmaction

<result>

<tag3>

Text/StringN/A
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.