V 2.0 : ADQuery Windows Events

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

V 2.0 : ADQuery Windows Events

Base Rule

Host Status Messages

Information

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

Schema Description

N/A

N/A

N/A

Vendor or Manufacturer Name

N/A

N/A

N/A

Product Name

N/A

N/A

N/A

Product Version

N/A

<vmid>

Text/String

EventID

Iswindows

<status>

Text/String

N/A

Count

<quantity>

Number

N/A