Log Fields and Parsing
This section details the log fields available in this log message type, along with values parsed for both LogRhythm Default and LogRhythm Default v2.0 policies. A value of "N/A" (not applicable) means that there is no value parsed for a specified log field.
|
Log Field |
LogRhythm Default |
LogRhythm Default v2.0 |
|---|---|---|
|
Type (type) |
<vmid> |
<vmid> |
|
Threat/Content Type (subtype) |
N/A |
<vendorinfo> |
|
Event ID (eventid) |
<subject> |
<action> |
|
Stage (stage) |
<status> |
<status>
|
|
Source User (srcuser) |
<domainorigin>
|
<domainorigin>
|
|
Machine Name (machinename) |
<sname> |
<sname> |
|
Public IP (public_ip) |
<sip> |
<sip> |
|
Private IP (private_ip) |
<snatip> |
<snatip> |
|
Host ID (hostid) |
<smac> |
N/A |
|
Serial Number (serialnumber) |
<serialnumber> |
<serialnumber> |
|
Client Version (client_ver) |
N/A |
<version> |
|
Repeat Count (repeatcnt) |
<quantity> |
<quantity> |
|
Reason (reason) |
<reason> |
<reason> |
|
Error (error) |
N/A |
<responsecode> |
|
Description (opaque) |
N/A |
<subject> |
|
Status (status) |
<result> |
<result>
|
|
Login Duration (login_duration) |
<seconds> |
<seconds> |
|
Device Name (device_name)** |
N/A |
<objectname> |
Log Processing Settings
This section details log processing changes made from the LogRhythm Default policy to LogRhythm Default v2.0. In some cases, base rules are broken down into sub-rules to appropriately parse log message types by their event types.
LogRhythm Default
|
Regex ID |
Rule Name |
Rule Type |
Common Events |
Classifications |
|---|---|---|---|---|
|
1011039 |
GlobalProtect Status Messages |
Base Rule |
General Authentication Event |
Other Audit |
LogRhythm Default v2.0
|
Regex ID |
Rule Name |
Rule Type |
Common Events |
Classifications |
|---|---|---|---|---|
|
1010892 |
V 2.0 GlobalProtect Status Messages
|
Base Rule |
General Authentication Event |
Other Audit |
|
V 2.0 Remote Authentication Success |
Sub Rule |
User Logon |
Authentication Success |
|
|
V 2.0 Remote Authentication Failure |
Sub Rule |
User Logon Failure |
Authentication Failure |
|
|
V 2.0 Remote Session Logoff |
Sub Rule |
User Logoff |
Authentication Success |