Unable To Establish Cred For ID

Classification

Rule Name

Rule Type

Classification

Common Event

Unable To Establish Cred For ID

Base Rule

Audit : Access Failure

Create Object Failure

Unable To Establish Cred For ID : Preauth Failed

Sub Rule

Access Failure

Create Object Failure

Unable To Establish Cred For ID : Princ Unknown

Sub Rule

Access Failure

Create Object Failure

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

N/A

<severity>

Text/String

N/A

<sname>

Text/String

N/A

<process>

Text/String

N/A

<account>

Text/String

N/A

<domainorigin>

Text/String

N/A

<login>

Text/String

N/A

<command>

Text/String

N/A

<object

Text/String

N/A

<dname>

Text/String

N/A

<vmid>

Text/String