Skip to main content
Skip table of contents

Traffic Multicast Message

Vendor Documentation

Classification

Rule NameRule TypeCommon EventClassification
Traffic Multicast MessageBase RuleGeneral IP Multicast InformationInformation

Mapping with LogRhythm Schema  

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
N/A<severity>Text\StringEach log entry contains a Level (level) field that indicates the estimated severity of the event that caused the log entry.
srcip
<sip>IP AddressIP address of the traffic’s origin.
devname<sname>Text\StringN/A
dstip<dip>IP AddressDestination IP address for the web.
srcport<sport>NumberPort number of the traffic's origin.
dstport<dport>NumberPort number of the traffic's destination.
srcintf<sinterface>Text\StringInterface name of the traffic's origin.
dstintf<dinterface>Text\StringInterface of the traffic's destination.
proto<protnum>NumberThe protocol used by web traffic (tcp by default).
sessionid<session>NumberN/A
action<action>Text\StringN/A
rcvdbyte<bytesin>NumberN/A
sentbyte<bytesout>NumberN/A
rcvdpkt<packetsin>NumberN/A
sentpkt<packetsout>NumberN/A
duration<duration>NumberN/A
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.