Skip to main content
Skip table of contents

V 2.0 : Identity Logging Events

Vendor Documentation

Classification

Rule NameRule TypeCommon EventClassification
V 2.0 : Identity Logging EventsBase RuleGeneral InformationInformation

Mapping with LogRhythm Schema

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
virtuallogsourceN/AN/AN/A
subproductN/AN/AN/A
product<vmid>Text/StringProduct name
OriginipN/AN/AIP of the log origin 
originN/AN/AName of the first Security Gateway that reported this event
Action<action>Text/StringN/A
ifnameN/AN/AThe name of the Security Gateway interface through which a connection traverses
ifdirectionN/AN/AN/A
user<login>Text/StringSource user name
src_user_nameN/AN/AN/A
src_machine_name<sname>Text/StringN/A
SIP<sip>IP AddressSource IP
descriptionN/AN/AN/A
dst_machine_nameN/AN/AN/A
dst_user_nameN/AN/AN/A
domain_name<domainorigin>Text/StringN/A
termination_reason<reason>Text/StringN/A
duration<duration>NumbersN/A
identity_typeN/AN/AN/A
endpoint_ipN/AN/AN/A
identity_srcN/AN/AN/A
information<vendorinfo>Text/StringN/A
alertN/AN/AN/A
flagsN/AN/AN/A
logidN/AN/AN/A
loguidN/AN/AUUID of unified logs 
sequencenumN/AN/ANumber added to order logs with the same Linux timestamp and origin
versionN/AN/AN/A
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.