Skip to main content
Skip table of contents

V 2.0 : Eventia Analyzer Events

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

V 2.0 : Eventia Analyzer EventsBase RuleGeneral Information Information

Mapping with LogRhythm Schema

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
virtuallogsourceN/AN/AN/A
subproductN/AN/ACan be VPN or non-VPN
Product<vmid>Text/StringProduct name
OriginipN/AN/AIP of the log origin 
originN/AN/AName of the first Security Gateway that reported this event
Action<action>Text/StringN/A
SIP<sip>IP AddressSource IP
SPort<sport>NumberSource host port number
DIP<dip>IP AddressDestination IP
dport<dport>NumberDestination host port number
protocol<protnum>NumberProtocol detected on the connection
ifname<sinterface>Text/StringThe name of the Security Gateway interface through which a connection traverses
ifdirectionN/AN/AConnection direction
Reason<reason>Text/StringInformation on the error occurred
RuleN/AN/AMatched rule number
InfoN/AN/ASpecial log message
XlateSIP<snatip>IP AddressSource ipv4 after applying NAT
XlateSport<snatport>NumberSource port after applying hide NAT on source IP
XlateDIP<dnatip>IP AddressDestination ipv4 after applying NAT
XlateDPort<dnatport>NumberDestination port after applying NAT
UserN/AN/ASource user name
alertN/AN/AAlert level of matched rule (for connection logs)
icmp-codeN/AN/AN/A
icmp-typeN/AN/AN/A
matched_categoryN/AN/AName of matched category
rule_nameN/AN/AAccess rule name
Url<url>Text/StringMatched URL
timeN/AN/AThe time stamp when the log was created
Severity<severity>NumberThreat severity determined by ThreatCloud
Possible values:
0 - Informational
1 - Low
2 - Medium
3 - High
4 - Critical
administrator<login>Text/StringUser who performed the operation
performedonN/AN/AN/A
generalinformation<vendorinfo>Text/StringN/A
flagsN/AN/ACheckpoint internal field
logidN/AN/AN/A
loguidN/AN/AUUID of unified logs  
sequencenumN/AN/ANumber added to order logs with the same Linux timestamp and origin
versionN/AN/AN/A
cu_detected_byN/AN/AN/A
cu_detection_timeN/AN/AN/A
cu_last_update_timeN/AN/AN/A
cu_log_countN/AN/AN/A
cu_rule_categoryN/AN/AN/A
cu_rule_idN/AN/AN/A
domain<domainimpacted>Text/StringN/A
event_end_timeN/AN/AN/A
event_nameN/AN/AN/A
event_start_timeN/AN/AN/A
hostname<dname>Text/StringN/A
is_correlatedN/AN/AN/A
is_lastN/AN/AN/A
log_idN/AN/AUnique identity for logs includes: Type, Family, Product/Blade, Category 
max_num_count_detectedN/AN/AN/A
num_of_updatesN/AN/AN/A
origin_repetitionsN/AN/AN/A
source_repetitionsN/AN/AN/A
time_intervalN/AN/AN/A
users_repetitionsN/AN/AN/A
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.