UTM : IPS

Vendor Documentation

Classification

Rule Name

Rule Type

Classification

Common Event

UTM : IPS

Base Rule

Other Operations

General IPS/IDS Message

IPS Signature ICMP

Sub Rule

Other Operations

General IPS/IDS Message

IPS Signature TCP UDP

Sub Rule

Attack

General Attack Activity

IPS Signature TCP UDP

Sub Rule

Attack

General Attack Activity

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

Schema Description

severity

<severity>

Text/String

severity

logid

<vmid>

<tag1>

Number

N/A

eventtype

<object>

Text

N/A

severity

<severity>

Text/String

N/A

srcip

<sip>

IP Address

IP Address

dstip

<dip>

IP Address

IP Address

srcintf

<sinterface>

Text/String

N/A

dstintf

<dinterface>

Text/String

N/A

sessionid

<session>

Number/Text/String

N/A

action

<action>

Text/String

N/A

proto

<protnum>

Number

N/A

service

<protname>

Text/String

N/A

attack

<threatname>

Text/String

N/A

attackid

<threatid>

Number

N/A

user

<domainorigin>

<login>

Text/String

N/A

group

<group>

Text/String

N/A

msg

<subject>

Text/String

N/A