Traffic : Sniffer 1

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

Traffic: Sniffer

Base Rule

General Network Traffic Log Message

Network Traffic

VMID 00017: Sniffer Traffic Accept

Sub Rule

Traffic Allowed by Network Firewall

Network Allow

VMID 00021: Sniffer Traffic Accept

Sub Rule

Traffic Allowed by Network Firewall

Network Allow

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

Schema Description

logid

<vmid>

Number

The ID (logid) is a 10-digit field. It is a unique identifier for that specific log.

apprisk

<severity>

Text\String

Each log entry contains a Level (level) field that indicates the estimated severity of the event that caused the log entry.

srcip

<sip>

IP Address

IP address of the traffic’s origin.

dstip

<dip>

IP Address

Destination IP address for the web.

srcport

<sport>

Number

Port number of the traffic's origin.

dstport

<dport>

Number

Port number of the traffic's destination.

transip

<snatip>

IP Address

N/A

srcintf

<sinterface>

Text\String

Interface name of the traffic's origin.

dstintf

<dinterface>

Text\String

Interface of the traffic's destination.

proto

<protnum>

Number

The protocol used by web traffic (tcp by default).

service

<protname>

Text\String

Name of the service.

vd

<domainorigin>

Text\String

Name of the virtual domain in which the log message was recorded.

sessionid

<session>

Number

ID for the session.

app

<object>

Text\String

Name of the application.

appcat

<objectname>

Text\String

Category of the application.

devname

<subject>

Text\String

N/A

policyid

<policy>

Number

N/A

action

<action>

Text\String

N/A

rcvdbyte

<bytesin>

Number

N/A

sentbyte

<bytesout>

Number

N/A

rcvdpkt

<itemsin>

Number

N/A

sentpkt

<itemout>

Number

N/A

logid

<tag1>

Number

N/A

action

<tag2>

Text\String

N/A

utmaction

<tag3>

Text\String

N/A