V 2.0 : Inbound SEP Host Packet Events 1

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

V 2.0 : Inbound SEP Host Packet Events

Base Rule

General Traffic Log

Network Traffic

V 2.0 : Inbound SEP Host Packet Blocked

Sub Rule

Traffic Denied by Host Firewall

Network Deny

V 2.0 : Inbound SEP Host Packet Blocked

Sub Rule

Traffic Allowed by Host Firewall

Network Allow

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

Event Time

N/A

Text/String

Host Name

<dname>

Text/String

Local IP Address

<dip>

Number

Local Port

<dport>

Number

Remote IP Address

<sip>

Text/String

Remote Host Name

<sname>

Text/String

Remote Port

<sport>

Number

Traffic Direction

N/A

N/A

Application Name

<process>

Text/String

Action

<action>
<tag1>

Text/String