V 2.0 General Authentication Event 1

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

V 2.0 General Authentication Event

Base Rule

General Authentication Event

Other Audit

V 2.0 User Logon Success

Sub Rule

User Logon

Authentication Success

V 2.0 User Logoff

Sub Rule

User Logoff

Authentication Success

V 2.0 User Session Timed Out

Sub Rule

User Session Timeout

Information

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

N/A

<vmid>

Text/String

N/A

<severity>

String/Number/Text

N/A

<vendorinfo>

Text/String

N/A

<sip>

Number

N/A

<login>

Text/String

N/A

<sessiontype>

Text/String

N/A

<subject>

Text/String

N/A

<tag1>

Text/String

N/A

<tag2>

Text/String