User State Change
Classification
Rule Name | Rule Type | Classification | Common Event |
---|---|---|---|
User State Change | Base Rule | Access Success | Command Executed |
Switch User | Sub Rule | Other Audit | Session State Changed |
Superuser | Sub Rule | Access Granted | Privilege Granted |
Mapping with LogRhythm Schema
Device Key in Log Message | LogRhythm Schema | Data Type |
---|---|---|
N/A | <severity> | Text/String |
N/A | <dname> | Text/String |
N/A | <command> | Text/String |
N/A | <tag1> | Text/String |