V 2.0 GlobalProtect 9.1.3 and Later Status Messages

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

V 2.0 GlobalProtect 9.1.3 & Later Status Messages

Base Rule

General Authentication Event

Information

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

N/A

<vmid>

Text/String

N/A

<vendorinfo>

Text/String

N/A

<sip>

Number

N/A

<sname>

Text/String

N/A

<snatip>

Number

N/A

<login>

Text/String

N/A

<domainorigin>

Text/String

N/A

<process>

Text/String

N/A

<subject>

Text/String

N/A

<serialnumber>

Number

N/A

<version>

Number

N/A

<action>

Text/String

N/A

<result>

Text/String

N/A

<reason>

Text/String

N/A

<status>

Text/String

N/A

<duration>

Number

N/A

<quantity>

Number