Skip to main content
Skip table of contents

UTM : App

Vendor Documentation

Classification

Rule Name

Rule Type

Classification

Common Event

UTM : AppBase RuleInformationGeneral Application Control Message
UTM App Ctrl IPS ResetSub RuleInformationGeneral IPS Message
UTM App Ctrl IPS PassSub RuleNetwork AllowTraffic Allowed by IDS/IPS
UTM App Ctrl IPS BlockSub RuleNetwork DenyTraffic Denied by IDS/IPS

Mapping with LogRhythm Schema  

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
severity<severity>Text/StringN/A
logid

<vmid>

<tag1>

NumberN/A
appid<processid>NumberN/A
user<account>Text/StringN/A
group<group>Text/StringN/A
srcip<sip>IP AddressIP Address
srcport<sport>NumberN/A
srcintf<sinterface>Text/StringN/A
dstip<dip>IP AddressIP Address
dstport<dport>NumberN/A
dstintf<dinterface>Text/StringN/A
proto<protnum>Text/StringN/A
sessionid<session>Number/Text/StringN/A
action<action>Text/StringN/A
appcat<objectname>Text/StringN/A
app<object>Text/StringN/A
url<url>Text/StringN/A
apprisk<severity>Text/StringN/A
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.