Skip to main content
Skip table of contents

UTM : Virus

Vendor Documentation

Classification

Rule Name

Rule Type

Classification

Common Event

UTM : VirusBase RuleCriticalGeneral Virus Filename Critical
Virus Infect WarningSub RuleCriticalGeneral Virus Filename Critical
Malware Traffic Allowed By AntiVirusSub RuleMalwareDetected Malware Activity

Mapping with LogRhythm Schema  

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
severity<severity>Text/Stringseverity
logid

<vmid>

<tag1>

NumberN/A
msg<subject>Text/StringN/A
action<reason>Text/StringN/A
sessionid<session>Number/Text/StringN/A
srcip<sip>IP AddressN/A
dstip<dip>IP AddressN/A
srcport<sport>NumberN/A
dstport<dport>NumberN/A
srcintf<sinterface>Text/String/NumberN/A
dstintf<dinterface>Text/String/NumberN/A
proto<protnum>NumberN/A
filename<object>Text/StringN/A
virus<threatname>Text/StringN/A
dtype<objecttype>Text/StringN/A
url<url>Text/StringN/A
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.