UTM : DLP

Vendor Documentation

Classification

Rule Name

Rule Type

Classification

Common Event

UTM : DLP

Base Rule

Information

General DLP Message

UTM DLP Notif

Sub Rule

Information

Data Leak Detected

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

Schema Description

severity

<severity>

Text/String

severity

logid

<vmid>

<tag1>

Number

N/A

sessionid

<session>

Number/Text/String

N/A

user

<account>

Text/String

N/A

group

<group>

Text/String

N/A

srcip

<sip>

IP Address

IP Address

srcport

<sport>

Number

N/A

srcintf

<sinterface>

Text/String/Number

N/A

dstip

<dip>

IP Address

IP Address

dstport

<dport>

Number

N/A

dstintf

<dinterface>

Text/String/Number

N/A

proto

<protnum>

Number

N/A

filetype

<objecttype>

Text/String

N/A

action

<action>

Text/String

N/A

hostname

<sname>

Text/String

N/A

url

<url>

Text/String

N/A

agent

<useragent>

Text/String

N/A

filename

<object>

Text/String

N/A

sender

<sender>

Text/String

N/A

recipient

<recipient>

Text/String

N/A

subject

<subject>

Text/String

N/A