V 2.0 Catch All : System Messages
Vendor Documentation
Classification
Rule Name | Rule Type | Common Event | Classification |
|---|---|---|---|
| V 2.0 Catch All : System Messages | Base Rule | General System Message | Information |
Mapping with LogRhythm Schema
| Device Key in Log Message | LogRhythm Schema | Data Type | Schema Description |
|---|---|---|---|
| Type (type) | <vmid> | Text/String | Specifies the type of log; value is SYSTEM. |
| Content/Threat Type (subtype) | <vendorinfo> | Text/String | Subtype of the system log; refers to the system daemon generating the log. |
| Severity (severity) | <severity> | Text/String | Severity associated with the event; values are informational, low, medium, high, critical. |
| Description (opaque) | <subject> | Text/String | Detailed description of the event, up to a maximum of 512 bytes. |
| Device Name (device_name) | <objectname> | Text/String | The hostname of the firewall on which the session was logged. |