User State Change

Classification

Rule Name

Rule Type

Classification

Common Event

User State Change

Base Rule

Access Success

Command Executed

Switch User

Sub Rule

Other Audit

Session State Changed

Superuser

Sub Rule

Access Granted

Privilege Granted

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

N/A

<severity>

Text/String

N/A

<dname>

Text/String

N/A

<command>

Text/String

N/A

<tag1>

Text/String