Skip to main content
Skip table of contents

V 2.0 Flood/Packet Threat Messages

Log Fields and Parsing

This section details the log fields available in this log message type, along with values parsed for both LogRhythm Default and LogRhythm Default v2.0 policies. A value of "N/A" (not applicable) means that there is no value parsed for a specified log field.

Log Field

LogRhythm Default

LogRhythm Default v2.0

Type (type)<vmid><vmid>
Threat/Content Type (subtype)<vendorinfo>


<tag1>
<vendorinfo>


<tag1>
Source address (src)<sip><sip>
Destination address (dst)<dip><dip>
NAT Source IP (natsrc)<snatip><snatip>
NAT Destination IP (natdst)<dnatip><dnatip>
Rule Name (rule)<policy><policy>
Source User (srcuser)<domainorigin>


<login>
N/A
Destination User (dstuser)

<account>

N/A
N/A<process>N/A
N/A<group>N/A
Inbound Interface (inbound_if)<sinterface><sinterface>
Outbound Interface (outbound_if)<dinterface><dinterface>
Session ID (sessionid)<session>N/A
Repeat Count (repeatcnt)<quantity>N/A
Source Port (sport)<sport>N/A
Destination Port (dport)<dport>N/A
NAT Source Port (natsport)<snatport>N/A
NAT Destination Port (natdport)<dnatport>N/A
IP Protocol (proto)<protname><protname>
Action (action)<action>


<tag4>


<command>
<action>


<tag2>
Threat/Content Name (threatid)<object>


<objecttype>
<threatname>
N/A<objectname>


<url>


<domainimpacted>


<domainorigin>
N/A
N/A<action>N/A
Threat/Content Name (threatid)<processid><threatid>
Category (category)<tag2>
<process>
N/A
Severity (severity)<severity><severity>
N/A<hash>N/A
Sender (sender)<sender>N/A
Subject (subject)<subject>N/A
Recipient (recipient)<recipient>N/A
Device Name (device_name)N/A<objectname>
Application Characteristic (characteristic_of_app)**N/A<result>

Log Processing Settings

This section details log processing changes made from the LogRhythm Default policy to LogRhythm Default v2.0. In some cases, base rules are broken down into sub-rules to appropriately parse log message types by their event types.

LogRhythm Default

Regex ID

Rule Name

Rule Type

Common Events

Classifications

1000722

































































































































THREAT MessagesBase RuleGeneral Attack ActivityAttack
Potentially Threatening URL AllowedSub RuleWeb Activity AllowedActivity
URL AllowedSub RuleTraffic Allowed by Network FirewallNetwork Allow
URL Denied - Flood DetectedSub RuleGeneral Attack ActivityAttack
URL Threat Detected - Session DroppedSub RuleGeneral Attack ActivityAttack
URL Threat Detected - Packets DroppedSub RuleGeneral Attack ActivityAttack
URL Threat Detected - Dropped - Reset SentSub RuleGeneral Attack ActivityAttack
URL BlockedSub RuleTraffic Denied by Network FirewallNetwork Deny
Potential Virus Content AllowedSub RuleDetected Virus ActivityMalware
Virus Content AllowedSub RuleDetected Virus ActivityMalware
Virus Traffic DeniedSub RuleFailed Virus ActivityFailed Malware
Virus Traffic Dropped - Session DroppedSub RuleFailed Virus ActivityFailed Malware
Virus Detected - Packets DroppedSub RuleFailed Virus ActivityFailed Malware
Virus Detected - Dropped - Reset SentSub RuleFailed Virus ActivityFailed Malware
Malicious URL BlockedSub RuleFailed Malware ActivityFailed Malware
Potential Spyware Content AllowedSub RuleDetected Spyware ActivityMalware
Spyware Content AllowedSub RuleDetected Spyware ActivityMalware
Spyware Traffic DeniedSub RuleFailed Spyware ActivityFailed Malware
Spyware Traffic Dropped - Session DroppedSub RuleFailed Spyware ActivityFailed Malware
Spyware Detected - Packets DroppedSub RuleFailed Spyware ActivityFailed Malware
Spyware Detected - Dropped - Reset SentSub RuleFailed Spyware ActivityFailed Malware
Spyware BlockedSub RuleFailed Spyware ActivityFailed Malware
Potential Vulnerability Exploit AllowedSub RuleVuln High Severity : GeneralVulnerability
Vulnerability Exploit AllowedSub RulePotential Vulnerability Exploit AllowedActivity
Vulnerability Exploit DeniedSub RuleFailed General Attack ActivityFailed Attack
Vulnerability Exploit Traffic Drop - Session DropSub RuleFailed General Attack ActivityFailed Attack
Vulnerability Exploit Traffic Drop - Packet DropSub RuleFailed General Attack ActivityFailed Attack
Vulnerability Exploit Traffic Dropped - Reset SentSub RuleFailed General Attack ActivityFailed Attack
Vulnerability Exploit DroppedSub RuleFailed General Attack ActivityFailed Attack
Potentially Threatening File Observed - AllowedSub RulePotentially Threatening File ObservedActivity
Threatening File AllowedSub RuleUnauthorized Program/ProcessMisuse
Threatening File Type DeniedSub RuleFailed Malware ActivityFailed Malware
Threatening File Dropped - Session DroppedSub RuleFailed Malware ActivityFailed Malware
Threatening File Dropped - Packets DroppedSub RuleFailed Malware ActivityFailed Malware
Threatening File Dropped - Reset SentSub RuleFailed Malware ActivityFailed Malware
Threatening File BlockedSub RuleFailed Malware ActivityFailed Malware
Scan DetectedSub RulePort ScanReconnaissance
DoS DetectedSub RuleHost Denial Of ServiceDenial Of Service
Data Pattern FilteredSub RuleData Pattern FilteredFailed Activity
Threat Allow - Dead-SitesSub RuleUnauthorized WebsiteMisuse
Threat Allow - DatingSub RuleSocial Media ActivityMisuse
Threat Allow - Cult-And-OccultSub RuleUnauthorized ActivityMisuse
Threat Allow - Computer-And-Internet-SecuritySub RuleUnauthorized WebsiteMisuse
Threat Allow - Computer-And-Internet-InfoSub RuleUnauthorized WebsiteMisuse
Threat Allow - Business-And-EconomySub RuleUnauthorized WebsiteMisuse
Threat Allow - AuctionsSub RuleUnauthorized ActivityMisuse
Threat Allow - AnySub RuleUnauthorized WebsiteMisuse
Threat Alert - Web-HostingSub RuleFailed Unauthorized ActivityFailed Misuse
Threat Alert - Web-Based-EmailSub RuleFailed Unauthorized ActivityFailed Misuse
Threat Alert - UnknownSub RuleFailed Unauthorized ActivityFailed Misuse
Threat Alert - TravelSub RuleFailed Unauthorized ActivityFailed Misuse
Threat Alert - Training-And-ToolsSub RuleFailed Unauthorized ActivityFailed Misuse
Threat Alert - Swimsuits-And-Intimate-ApparelSub RuleFailed Adult ContentFailed Misuse
Threat Alert - Streaming-MediaSub RuleFailed Streaming MediaFailed Misuse
Threat Alert - Spyware-And-AdwareSub RuleFailed Spyware ActivityFailed Malware
Threat Alert - SportsSub RuleFailed Unauthorized ActivityFailed Misuse
Threat Alert - Spam-URLsSub RuleFailed Unauthorized E-mailFailed Misuse
Threat Alert - SocietySub RuleFailed Social Media ActivityFailed Misuse
Threat Alert - ShoppingSub RuleFailed Unauthorized ActivityFailed Misuse
Threat Alert - Shareware-And-FreewareSub RuleFailed Unauthorized ActivityFailed Misuse
Threat Alert - Search-EnginesSub RuleFailed Unauthorized ActivityFailed Misuse
Threat Alert - ReligionSub RuleFailed Unauthorized ActivityFailed Misuse
Threat Alert - Reference-And-ResearchSub RuleFailed Unauthorized ActivityFailed Misuse
Threat Alert - Real-EstateSub RuleFailed Unauthorized ActivityFailed Misuse
Threat Alert - Private-IP-AddressesSub RuleFailed Unauthorized ActivityFailed Misuse
Threat Alert - Philosophy-And-Political-AdvocacySub RuleFailed Unauthorized ActivityFailed Misuse
Threat Alert - Personal-Sites-And-BlogsSub RuleFailed Unauthorized ActivityFailed Misuse
Threat Alert - Pay-To-SurfSub RuleFailed Unauthorized ActivityFailed Misuse
Threat Alert - Parked-DomainsSub RuleFailed Unauthorized ActivityFailed Misuse
Threat Alert - Online-Personal-StorageSub RuleFailed Unauthorized ActivityFailed Misuse
Threat Alert - News-And-MediaSub RuleFailed Unauthorized ActivityFailed Misuse
Threat Alert - Motor-VehiclesSub RuleFailed Unauthorized ActivityFailed Misuse
Threat Alert - Malware-SitesSub RulePossible Malware ActivityMalware
Threat Alert - Job-SearchSub RuleFailed Unauthorized ActivityFailed Misuse
Threat Alert - Internet-PortalsSub RuleFailed Unauthorized ActivityFailed Misuse
Threat Alert - Internet-CommunicationsSub RuleFailed IM/Chat ActivityFailed Misuse
Threat Alert - Individual-Stock-Advice-And-ToolsSub RuleFailed Unauthorized ActivityFailed Misuse
Threat Alert - Image-And-Video-SearchSub RuleFailed Unauthorized ActivityFailed Misuse
Threat Alert - Hunting-And-FishingSub RuleFailed Unauthorized ActivityFailed Misuse
Threat Alert - Health-And-MedicineSub RuleFailed Unauthorized ActivityFailed Misuse
Threat Alert - GovernmentSub RuleFailed Unauthorized ActivityFailed Misuse
Threat Alert - GamesSub RuleFailed Game ActivityFailed Misuse
Threat Alert - Financial-ServicesSub RuleFailed Unauthorized ActivityFailed Misuse
Threat Alert - Entertainment-And-ArtsSub RuleFailed Unauthorized ActivityFailed Misuse
Threat Alert - Educational-InstitutionsSub RuleFailed Unauthorized ActivityFailed Misuse
Threat Alert - Dead-SitesSub RuleFailed Unauthorized ActivityFailed Misuse
Threat Alert - DatingSub RuleFailed Social Media ActivityFailed Misuse
Threat Alert - Cult-And-OccultSub RuleFailed Adult ContentFailed Misuse
Threat Alert - Computer-And-Internet-SecuritySub RuleFailed Unauthorized ActivityFailed Misuse
Threat Alert - Computer-And-Internet-InfoSub RuleFailed Unauthorized ActivityFailed Misuse
Threat Alert - Business-And-EconomySub RuleFailed Unauthorized ActivityFailed Misuse
Threat Alert - AuctionsSub RuleFailed Unauthorized ActivityFailed Misuse
Threat Alert - AnySub RuleFailed Unauthorized ActivityFailed Misuse
Threat Alert - Content-Delivery-NetworksSub RuleFailed Unauthorized ActivityFailed Misuse
Threat Alert - Home And GardenSub RuleFailed Unauthorized ActivityFailed Misuse
Threat Alert - LegalSub RuleFailed Unauthorized ActivityFailed Misuse
Threat Alert - Local InformationSub RuleFailed Unauthorized ActivityFailed Misuse
Threat Alert - Online MusicSub RuleFailed Streaming MediaFailed Misuse
Threat Alert - Social NetworkingSub RuleFailed Social Media ActivityFailed Misuse
Threat Alert - TranslationSub RuleFailed Unauthorized ActivityFailed Misuse
Threat Alert - Web AdvertisementsSub RuleFailed Unauthorized ActivityFailed Misuse
URL Block-ContinueSub RuleTraffic Allowed by Network FirewallNetwork Allow
Threatening File ForwardedSub RuleFile InterceptedActivity
URL Allowed : ContinueSub RuleTraffic Allowed by Network FirewallNetwork Allow
Vulnerability Exploit Traffic Dropped - Reset BothSub RuleFailed General Attack ActivityFailed Attack
Wildfire Upload - SkipSub RuleMessage SubmissionInformation
Wildfire Upload - SuccessSub RuleMessage SubmissionInformation
Brute Force Attack : FTP LoginSub RuleVuln High Severity : Brute Force AttackVulnerability
Wildfire-Virus Detected - Reset BothSub RuleFailed Virus ActivityFailed Malware
Wildfire - Potential Virus Content AllowedSub RuleDetected Virus ActivityMalware
Wildfire-Virus Content AllowedSub RuleDetected Virus ActivityMalware
Wildfire-Virus Traffic DeniedSub RuleFailed Virus ActivityFailed Malware
Wildfire-Virus Traffic Dropped - Session DroppedSub RuleFailed Virus ActivityFailed Malware
Wildfire-Virus Detected - Packets DroppedSub RuleFailed Virus ActivityFailed Malware
Wildfire-Virus Detected - Dropped - Reset SentSub RuleFailed Virus ActivityFailed Malware
Wildfire-Malicious URL BlockedSub RuleFailed Malware ActivityFailed Malware
Virus Detected - Dropped - Reset BothSub RuleFailed Virus ActivityFailed Malware
Spyware Detected - Dropped - Reset BothSub RuleFailed Spyware ActivityFailed Malware
Vuln Exploit Traffic Dropped - Reset ServerSub RuleFailed General Attack ActivityFailed Attack
Vulnerability Exploit Detected : Low SeveritySub RuleVuln Low Severity : GeneralVulnerability
File DetectedSub RuleSuspicious File DownloadActivity
Vulnerability Exploit Detected : High SeveritySub RuleVuln High Severity : GeneralVulnerability
Wildfire : Benign DeterminationSub RuleVirus Scan Completed - No Viruses FoundInformation
Wildfire : Grayware DeterminationSub RulePotentially Threatening File ObservedActivity
Wildfire : Malware DeterminationSub RuleDetected Virus ActivityMalware
Potential Vulnerability Exploit Allowed : LowSub RuleVuln Low Severity : GeneralVulnerability
Potential Vulnerability Exploit Allowed : InfoSub RuleVuln Low Severity : Information GatheringVulnerability
Vulnerability Exploit Detected : Medium SeveritySub RuleVuln Medium Severity : GeneralVulnerability
Failed Attack : Packet DroppedSub RuleFailed General Attack ActivityFailed Attack
Spyware Detected - Dropped - Reset ServerSub RuleFailed Spyware ActivityFailed Malware
Spyware Sinkhole Activity MessagesSub RuleSuspicious Network ActivitySuspicious

LogRhythm Default v2.0

Regex ID

Rule Name

Rule Type

Common Events

Classifications

1010884

V 2.0 Flood/Packet Threat MessagesBase RuleGeneral Threat Message

Activity

V 2.0 Potential Denial Of Service DetectedSub RuleNetwork Denial Of ServiceDenial Of Service
V 2.0 Potential Denial Of Service BlockedSub RuleFailed Network Denial Of ServiceFailed Denial of Service
V 2.0 Potentially Threatening Packet DroppedSub RuleFailed General Attack ActivityFailed Attack
V 2.0 Potentially Threatening Packet AllowedSub RuleGeneral Attack ActivityAttack
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.