Traffic Log 1

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification


Traffic Log

Base Rule

Network Traffic

Network Traffic

Traffic Allowed

Sub Rule

Traffic Allowed by Network Firewall

Network Allow

Traffic Denied

Sub Rule

Traffic Denied by Network Firewall

Network Deny

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

N/A

<vmid>

Text/String

N/A

<sip>

IP Address

N/A

<dip>

IP Address

N/A

<dname>

Text/String

N/A

<sport>

Number

N/A

<dport>

Number

N/A

<protnum>

Number

N/A

<object>

Text/String

N/A

<tag1>

Text/String