V 2.0 File Issued Retro Malicious Disposition Evt

Vendor Documentation

Classification

Rule Name

Rule Type

Classification

Common Event

V 2.0 File Issued Retro Malicious Disposition Evt

Base Rule

Other Security

Security Event Occurred

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

Schema Description

name

<subject>

Text/String

name

sha256

<hash>

Text/String

sha256_hash

disposition

<result>

Text/String

disposition

action

<action>

Text/String

action