User Activity Events

Vendor Documentation

Classification

Rule Name

Rule Type

Classification

Common Event

User Activity Events

Base Rule

Other Audit

General User Activity Monitor Event

Packet Forwarded

Sub Rule

Information

Forwarding Data

Packet Dropped

Sub Rule

Warning

Request Dropped

Management Packet

Sub Rule

Information

Management Pack Received

No Packet Associated

Sub Rule

Information

General Information Log Message

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhthm Schema

Data Type

Schema Description

id

N/A

N/A

N/A

sn

<serialnumber>

Number

Indicates the device serial number

time

N/A

N/A

Reports the time of event

fw

N/A

N/A

Indicates the WAN IP Address

pri

<severity>

Number

Displays the event priority level (0=emergency, 7=debug)

c

<vmid>

Number

Indicates the legacy category number (Note: SonicOS/X does not currently send new category information)

gcat

N/A

N/A

Display event group category when using Enhanced Syslog

m

N/A

N/A

Provides the message ID number

msg

<vendorinfo>

Text/String

Displays the message which is composed of either or both a predefined message and a dynamic message containing a string %s or numeric %d argument

src

<sip>
<sport>
<sinterface>

IP Address
Number
Text/String

Indicates the source IP address, and optionally, port, network interface, and resolved name

dst

<dip>
<dport>
<dinterface>

IP Address
Number
Text/String

Destination IP address, and optionally, port, network interface, and resolved name

proto

<protname>

Number

Displays the protocol information (rendered as “proto=[protocol]” or just “[proto]/[service]”)

dur

<duration>

Number

Displays the connection duration in seconds; pertains to the activity time of an authenticated user session (such as logout messages)

note

<subject>

Text/String

Additional information that is application-dependent

n

<quantity>

Number

Indicates the number of times event occurs

fw_action

<action>
<tag1>

Text/String

The explicit action performed on network traffic (packets) encountered by the firewall based on built-in or user-configured policies that may allow or drop packets.

Possible values are:

    • forward - packet is forwarded due to a matching policy or rule set

    • drop - packet is dropped due to a matching policy or rule set

    • mgmt - packet is a management packet, management policy will be applied

    • NA - not associated with a packet, firewall action is Not Applicable