Skip to main content
Skip table of contents

Traffic : Local 1

Vendor Documentation

Classification

Rule NameRule TypeCommon EventClassification
Traffic : LocalBase RuleGeneral Traffic LogNetwork Traffic
Traffic Local ClosedSub RuleGeneral Traffic Other NoticeInformation
Local Traffic TimeoutSub RuleSession DisconnectedInformation
Traffic Local AcceptedSub RuleTraffic Allowed by Network FirewallNetwork Allow
Local Traffic AcceptedSub RuleTraffic Allowed by Network FirewallNetwork Allow
Traffic Local DenySub RuleTraffic Denied by Network FirewallNetwork Deny
Forward Traffic DenySub RuleTraffic Denied by Network FirewallNetwork Deny

Mapping with LogRhythm Schema  

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
logid

<vmid>

<tag1>

NumberThe ID (logid) is a 10-digit field. It is a unique identifier for that specific log.
srcip<sip>IP AddressIP address of the traffic’s origin.
dstip<dip>IP AddressDestination IP address for the web.
srcport<sport>NumberPort number of the traffic's origin.
dstport<dport>NumberPort number of the traffic's destination.
srcintf<sinterface>Text\StringInterface name of the traffic's origin.
dstintf<dinterface>Text\StringInterface of the traffic's destination.
proto<protnum>NumberThe protocol used by web traffic (tcp by default),
sessionid<session>NumberID for the session.
appcat<objectname>Text\StringCategory of the application.
devname<subject>Text\StringN/A
policyid<policy>Number
N/A
action

<action>

<tag2>

Text\StringN/A
rcvdbyte<bytesin>NumberN/A
sentbyte<bytesout>NumberN/A
rcvdpkt<packetsin>NumberN/A
sentpkt<packetsout>NumberN/A
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.