Skip to main content
Skip table of contents

V 2.0 : Cylance Protect : Device Events

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification
V 2.0 : Cylance Protect : Device EventsBase RuleGeneral Information Log MessageInformation
V 2.0 : Cylance Protect : Policy AssignedSub RulePolicy Enabled : ObjectPolicy
V 2.0 : Cylance Protect : Device RemovedSub RuleObject Deleted/RemovedAccess Success
V 2.0 : Cylance Protect : Device UpdatedSub RuleObject Attribute ModifiedAccess Success
V 2.0 : Cylance Protect : Zone AssignedSub RuleObject Attribute ModifiedAccess Success
V 2.0 : Cylance Protect : Device RegisteredSub RuleDevice RegisteredOther Audit Success
V 2.0 : Cylance Protect : System SecuritySub RuleGeneral Authentication EventOther Audit

Mapping with LogRhythm Schema

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
N/AN/AN/ADevice Product
Agent VersionN/AN/AThe version of the CylancePROTECT Agent installed on the device.
Device Message<vendorinfo>Text/StringThe message is populated when the Device Details are changed by the user. This can include: name change, policy change, zone changes, log level change, and self-protection level change.
Device NameN/AN/AThe name of the device.
Event Type<vmid>Text/StringDevice
Event Name<action>, <tag1>Text/StringPossible Values: Device Policy Assigned, Device Removed, Device Updated, Device Assigned to Zone, Registration, and System Security.
IP Address<dip>IP AddressThe IP address for the device.
Logged on Users<domainorigin>, <login>Text/StringThe users currently logged on to the device. This could be the email address and/or user’s name.
MAC Address<dmac>Text/StringThe MAC addresses for the device
OSN/AN/AThe operating system used on the device.
Policy ChangeN/AN/AThe previous policy and the new policy assigned to the device.
Policy NameN/AN/AThe name of the policy assigned to the device.
RenamedN/AN/A“device_name” to “device_name”
User<login>Text/StringThe name of the user updating the device.
Zones AddedN/AN/AThe zone names to which the device has been added.
Zone NameN/AN/AThe zone names to which the device is assigned.
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.