V 2.0 General SAML Message 1
Vendor Documentation
Classification
Rule Name | Rule Type | Common Event | Classification |
---|---|---|---|
V 2.0 General SAML Message | Base Rule | General Authentication Event | Other Audit |
V 2.0 User Logon Failure | Sub Rule | User Logon Failure | Authentication Failure |
V 2.0 User Logon Success | Sub Rule | User Logon | Authentication Success |
Mapping with LogRhythm Schema
Device Key in Log Message | LogRhythm Schema | Data Type | Schema Description |
Type (type) | <vmid> | Text/String | Specifies the type of log; the value is SYSTEM. |
Content/Threat Type (subtype) | <vendorinfo> | Text/String | A subtype of the system log; refers to the system daemon generating the log |
Event ID (eventid) | <result> <tag1> | Text/String | The string showing the name of the event. |
Object (object) | <object> | Text/String | Name of the object associated with the system event. |
Severity (severity) | <severity> | Text/String | Severity associated with the event; values are informational, low, medium, high, critical. |
Description (opaque) | <subject> | Text/String | Detailed description of the event, up to a maximum of 512 bytes. |
<login> | Text/String | ||
<reason> | Text/String | ||
<sip> | IP Address | ||
Device Name (device_name) | <objectname> | Text/String | The hostname of the firewall on which the session was logged. |