Skip to main content
Skip table of contents

UTM : IPS

Vendor Documentation

Classification

Rule Name

Rule Type

Classification

Common Event

UTM : IPSBase RuleOther OperationsGeneral IPS/IDS Message
IPS Signature ICMPSub RuleOther OperationsGeneral IPS/IDS Message
IPS Signature TCP UDPSub RuleAttackGeneral Attack Activity
IPS Signature TCP UDPSub RuleAttackGeneral Attack Activity

Mapping with LogRhythm Schema  

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
severity<severity>Text/Stringseverity
logid

<vmid>

<tag1>

NumberN/A
eventtype<object>TextN/A
severity<severity>Text/StringN/A
srcip<sip>IP AddressIP Address
dstip<dip>IP AddressIP Address
srcintf<sinterface>Text/StringN/A
dstintf<dinterface>Text/StringN/A
sessionid<session>Number/Text/StringN/A
action<action>Text/StringN/A
proto<protnum>NumberN/A
service<protname>Text/StringN/A
attack<threatname>Text/StringN/A
attackid<threatid>NumberN/A
user

<domainorigin>

<login>

Text/StringN/A
group<group>Text/StringN/A
msg<subject>Text/StringN/A
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.