Usermod Messages (Shell)

Classification

Rule Name

Rule Type

Common Event

Classification

Usermod Messages

Base Rule

User Account Attribute Modified

Account Modified

Changed Superuser Shell

Sub Rule

Configuration Modified : Security

Configuration

Changed User Shell

Sub Rule

Configuration Modified : Security

Configuration

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

N/A

<process>

Text\String

N/A

<account>

Text\String

N/A

<tag1>

Text\String

N/A

<tag2>

Text\String