Skip to main content
Skip table of contents

V 2.0 : Cylance Protect : AppControl Events

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification
V 2.0 : Cylance Protect : AppControl EventsBase RuleApplication Control DetectionActivity
V 2.0 : Cylance Protect : Application AllowedSub RuleApplication Control DetectionActivity
V 2.0 : Cylance Protect : Application BlockedSub RuleApplication BlockedFailed Activity

Mapping with LogRhythm Schema

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
N/AN/AN/ADevice Product
Action<result>, <tag1>Text/StringPossible Values: Allow, Deny.
Action TypeN/AN/APossible Values: Execution, ExecutionFromExternalDrive, PEFileChange, Unknown (Unable to determine the action type).
Device Name<dname>Text/StringThe name of the device.
Event Name<action>Text/StringPossible Values: Execution, ExecutionFromExternalDrive, PEFileChange, Unknown (Unable to determine the action type).
Event Type<vmid>Text/StringAppControl (This is an Application Control event.)
File Path<object>Text/StringThe path to the file.
IP Address<dip>IP AddressThe IP address for the device. Multiple IP addresses are comma-separated values.
SHA256<hash>Text/StringThe SHA256 hash for the file.
Zone NamesN/AN/AThe zones to which the device belongs.
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.