Skip to main content
Skip table of contents

V 2.0 General SAML Message 1

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

V 2.0 General SAML MessageBase RuleGeneral Authentication Event

Other Audit

V 2.0 User Logon Failure

Sub Rule

User Logon Failure

Authentication Failure
V 2.0 User Logon SuccessSub RuleUser LogonAuthentication Success

Mapping with LogRhythm Schema  

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
Type (type)<vmid>Text/StringSpecifies the type of log; the value is SYSTEM.
Content/Threat Type (subtype)<vendorinfo>Text/StringA subtype of the system log; refers to the system daemon generating the log
Event ID (eventid)

<result>

<tag1>

Text/StringThe string showing the name of the event.
Object (object)<object>Text/StringName of the object associated with the system event.
Severity (severity)<severity>Text/StringSeverity associated with the event; values are informational, low, medium, high, critical.

Description (opaque)

<subject>Text/StringDetailed description of the event, up to a maximum of 512 bytes.
<login>Text/String
<reason>Text/String
<sip>IP Address
Device Name (device_name)<objectname>Text/StringThe hostname of the firewall on which the session was logged.
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.