USB Device Blocked

Log Fields and Parsing

This section details the log fields available in this log message type, along with values parsed for both LogRhythm Default and LogRhythm Default v2.0 policies. A value of "N/A" (not applicable) means that there is no value parsed for a specified log field.

Log Field

LogRhythm Default

LogRhythm Default v2.0

N/A

<severity>

N/A

Device Name

<dname>

<dname>

Event Name

<vmid>

<action>, <tag1>

Event Type

N/A

<vmid>

External Device Type

<group>

<object>

External Device Name

<objectname>

<objectname>

External Device Product ID

N/A

N/A

External Device Serial Number

<object>

<serialnumber>

External Device Vendor ID

N/A

N/A

Zone Names

<subject>

N/A

Log Processing Settings

This section details log processing changes made from the LogRhythm Default policy to LogRhythm Default v2.0. In some cases, base rules are broken down into sub-rules to appropriately parse log message types by their event types.

LogRhythm Default

Regex ID

Rule Name

Rule Type

Common Events

Classifications

1009046

USB Device Blocked

Base Rule

Device Blocked

Warning

Device Fully Accessible

Sub Rule

Access Granted Activity

Access Granted

Device Access Blocked

Sub Rule

Access Blocked

Information

LogRhythm Default v2.0

Regex ID

Rule Name

Rule Type

Common Events

Classifications

1011403

V 2.0 : Cylance Protect : Device Control Events

Base Rule

General Antivirus Information

Information

V 2.0 : Cylance Protect : Device Blocked

Sub Rule

Storage Device Detected

Activity

V 2.0 : Cylance Protect : Device Allowed

Sub Rule

Threat Blocked

Failed Activity