UTM : App

Vendor Documentation

Classification

Rule Name

Rule Type

Classification

Common Event

UTM : App

Base Rule

Information

General Application Control Message

UTM App Ctrl IPS Reset

Sub Rule

Information

General IPS Message

UTM App Ctrl IPS Pass

Sub Rule

Network Allow

Traffic Allowed by IDS/IPS

UTM App Ctrl IPS Block

Sub Rule

Network Deny

Traffic Denied by IDS/IPS

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

Schema Description

severity

<severity>

Text/String

N/A

logid

<vmid>

<tag1>

Number

N/A

appid

<processid>

Number

N/A

user

<account>

Text/String

N/A

group

<group>

Text/String

N/A

srcip

<sip>

IP Address

IP Address

srcport

<sport>

Number

N/A

srcintf

<sinterface>

Text/String

N/A

dstip

<dip>

IP Address

IP Address

dstport

<dport>

Number

N/A

dstintf

<dinterface>

Text/String

N/A

proto

<protnum>

Text/String

N/A

sessionid

<session>

Number/Text/String

N/A

action

<action>

Text/String

N/A

appcat

<objectname>

Text/String

N/A

app

<object>

Text/String

N/A

url

<url>

Text/String

N/A

apprisk

<severity>

Text/String

N/A