Skip to main content
Skip table of contents

V 2.0 Host Profile Messages 1

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

V 2.0 Host Profile MessagesBase RuleGeneral Profile DetectionInformation

Mapping with LogRhythm Schema  

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
Type (type)<vmid>Text/StringSpecifies the type of log; value is HIPMATCH.
Threat/Content Type (subtype)<vendorinfo>NumberSubtype of the HIP match log; unused.
Source User (srcuser)<domainorigin>
<login>
Text/StringUsername of the user who initiated the session
Machine Name (machinename)<sname>Text/StringThe name of the user’s machine.
Source Address (src)<sip>IP AddressIP address of the source user.
HIP (matchname)<object>Text/StringName of the HIP object or profile.
Repeat Count (repeatcnt)<quantity>NumberNumber of times the HIP profile matched.
HIP Type (matchtype)<objecttype>Text/StringWhether the hip field represents a HIP object or a HIP profile.
Device Name (device_name)<objectname>Text/StringThe hostname of the firewall on which the session was logged.
User Device Serial Number (serialnumber)<serialnumber>Text/StringSerial number of the user’s machine or device.
Device MAC Address (mac)*<smac>Text/StringThe MAC address of the user’s machine or device.
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.