Skip to main content
Skip table of contents

Traffic/UTM Messages

Vendor Documentation

Classification

Rule NameRule TypeCommon EventClassification
Traffic/UTM MessagesBase RuleGeneral Network TrafficNetwork Traffic
IPS TrafficSub RuleGeneral Attack Activity
Attack
Application Control MessageSub RuleGeneral Application Control MessageInformation
DLP MessageSub RuleGeneral DLP MessageInformation
General Forward MessageSub RuleForwarding DataInformation
Webfilter MessageSub RuleGeneral WebFilter EventInformation
Local Traffic InformationSub RuleLocal Mode RequestInformation
General Forward Message - DenySub RuleTraffic Denied by Network FirewallNetwork Deny
Webfilter Web Ftgd Cat AllowSub RuleGeneral WebFilter EventInformation

Mapping with LogRhythm Schema  

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
logid<vmid>NumberThe ID (logid) is a 10-digit field. It is a unique identifier for that specific log.
msg<vendorinfo>Text\StringN/A
level<severity>Text\StringEach log entry contains a Level (level) field that indicates the estimated severity of the event that caused the log entry.
srcip<sip>IP AddressIP address of the traffic’s origin.
dstip<dip>IP AddressDestination IP address for the web.
hostname<dname>Text\StringN/A
srcport<sport>NumberPort number of the traffic's origin
dstport<dport>NumberPort number of the traffic's destination.
srcintf<sinterface>Text\StringInterface name of the traffic's origin.
dstintf<dinterface>Text\StringInterface of the traffic's destination.
proto<protnum>NumberThe protocol used by web traffic (tcp by default).
service<protname>Text\StringName of the service.
vd<domainorigin>Text\String
Name of the virtual domain in which the log message was recorded.
sessionid<session>Number
ID for the session.
direction<object>Text\StringN/A
type<subject>Text\String
N/A
attack<threatname>Text\StringN/A
url\ref<url>Text\StringN/A
catdesc<group>Text\StringN/A
action

<command>

<action>

Text\StringN/A
rcvdbyte<bytesin>NumberN/A
sentbyte<bytesout>NumberN/A
subtype<tag5>Text\StringN/A
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.