V 2.0 General DHCP Messages

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

V 2.0 General DHCP Messages

Base Rule

General DHCP

Information

V 2.0 DHCP Lease Renewed

Sub Rule

DHCP Lease Renewed

Information

V 2.0 DHCP Lease Issued

Sub Rule

DHCP Lease Obtained

Information

V 2.0 DHCP Lease Ended

Sub Rule

DHCP Lease Expired

Information

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

Schema Description

Type (type)

<vmid>

Text/String

Specifies the type of log; the value is SYSTEM.

Content/Threat Type (subtype)

<vendorinfo>

Text/String

A subtype of the system log; refers to the system daemon generating the log

Event ID (eventid)

<action>

<tag1>

Text/String

The string shows the name of the event.

Severity (severity)

<severity>

Text/String

Severity associated with the event; values are informational, low, medium, high, critical.

Description (opaque)

<subject>

Text/String

Detailed description of the event, up to a maximum of 512 bytes.

<sip>

IP Address

<smac>

Text/String

<sname>

Text/String

<dinterface>

Text/String

<dip>

IP Address

Device Name (device_name)

<objectname>

Text/String

The hostname of the firewall on which the session was logged.