V 2.0 General SAML Message 1

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

V 2.0 General SAML Message

Base Rule

General Authentication Event

Other Audit

V 2.0 User Logon Failure

Sub Rule

User Logon Failure

Authentication Failure

V 2.0 User Logon Success

Sub Rule

User Logon

Authentication Success

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

Schema Description

Type (type)

<vmid>

Text/String

Specifies the type of log; the value is SYSTEM.

Content/Threat Type (subtype)

<vendorinfo>

Text/String

A subtype of the system log; refers to the system daemon generating the log

Event ID (eventid)

<result>

<tag1>

Text/String

The string showing the name of the event.

Object (object)

<object>

Text/String

Name of the object associated with the system event.

Severity (severity)

<severity>

Text/String

Severity associated with the event; values are informational, low, medium, high, critical.

Description (opaque)

<subject>

Text/String

Detailed description of the event, up to a maximum of 512 bytes.

<login>

Text/String

<reason>

Text/String

<sip>

IP Address

Device Name (device_name)

<objectname>

Text/String

The hostname of the firewall on which the session was logged.