Skip to main content
Skip table of contents

V 2.0 : Application Control Events

Vendor Documentation

Classification

Rule NameRule TypeCommon EventClassification
V 2.0 : Application Control EventsBase RuleGeneral Application Control MessageInformation
V 2.0 : Application Control : Traffic AcceptedSub RuleTraffic Allowed by Network FirewallNetwork Allow
V 2.0 : Application Control : Traffic AllowedSub RuleTraffic Allowed by Network FirewallNetwork Allow
V 2.0 : Application Control : Traffic BlockedSub RuleTraffic Denied by Network FirewallNetwork Deny
V 2.0 : Application Control : Traffic EncryptedSub RuleEncrypt PacketNetwork Traffic
V 2.0 : Application Control : Traffic DecryptedSub RuleDecrypted PacketNetwork Traffic

Mapping with LogRhythm Schema

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
virtuallogsourceN/AN/AN/A
subproductN/AN/AN/A
Product<vmid>Text/StringProduct name
OriginipN/AN/AIP of the log origin 
originN/AN/AName of the first Security Gateway that reported this event
Action<action>
<tag1>
Text/StringN/A
SIP<sip>Ip AddressSource IP
SPort<sport>NumberSource host port number
DIP<dip>Ip AddressDestination IP
dport<dport>NumberDestination host port number
protocol<protnum>NumberProtocol detected on the connection
ifname<sinterface>Text/StringThe name of the Security Gateway interface through which a connection traverses
ifdirectionN/AN/AConnection direction
reason<reason>Text/StringDescription of log's reason
RuleN/AN/AN/A
Info<vendorinfo>Text/StringN/A
XlateSIP<snatip>Ip AddressSource ipv4 after applying NAT
XlateSport<snatport>NumberSource host port number after applying NAT
XlateDIP<dnatip>Ip AddressDestination ipv4 after applying NAT
XlateDPort<dnatport>NumberDestination host port number after applying NAT
UrlN/AN/AMatched URL 
userN/AN/ASource user name
PolicyNameN/AN/AN/A
appi_name<process>Text/StringApplication name
app_descN/AN/AApplication description
app_idN/AN/AApplication ID
app_categoryN/AN/AN/A
matched_categoryN/AN/AN/A
app_properties<subject>Text/StringApplication categories
app_risk<severity>NumberApplication risk
Possible values:
0 - Unknown
1 - Very Low
2 - Low
3 - Medium
4 - High
5 - Critical
app_rule_nameN/AN/ARule name
web_client_typeN/AN/AN/A
web_server_typeN/AN/AN/A
proxy_src_ipN/AN/ASender source IP (even when using proxy)
received_bytes<bytesout>NumberNumber of bytes received during connection
sent_bytes<bytesin>NumberNumber of bytes sent during the connection
src_machine_name<sname>NumberMachine name connected to source IP
src_user_name<login>Text/StringUser name connected to source IP
timeN/AN/AThe time stamp when the log was created.
alertN/AN/AN/A
flagsN/AN/AN/A
loguidN/AN/AUUID  of unified logs 
sequencenumN/AN/ANumber added to order logs with the same linux timestamp and origin
versionN/AN/AN/A
__policy_id_tag<policy>Text/StringN/A
browse_timeN/AN/AN/A
bytesN/AN/AN/A
origin_sic_nameN/AN/AMachine SIC 
suppressed_logsN/AN/AAmount of connections\HTTP sessions that were aggregated in this application session log
resource<url>N/AResource from the HTTP request
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.