V 2.0 : Inbound SEP Host Traffic Events

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

V 2.0 : Inbound SEP Host Traffic Events

Base Rule

General Traffic Log

Network Traffic

V 2.0 : Inbound SEP Host Traffic Blocked

Sub Rule

Traffic Denied by Host Firewall

Network Deny

V 2.0 : Inbound SEP Host Traffic Allowed

Sub Rule

Traffic Allowed by Host Firewall

Network Allow

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

Remote

<sname>

Text/String

Remote

<sip>

Number

SymantecServer

<dname>

Text/String

Rule

<policy>

Text/String

action

<tag1>

Text/String

N/A

<protnum>

Number

SHA-256

MD-5

<hash>

Text/String

Remote

<sport>

Number

Remote

<smac>

Text/String

Local

<dip>

Number

Local

<dport>

Number

Occurrences

<quantity>

Number

Application

<process>

Text/String

N/A

<protname>

Text/String

Local

<dmac>

Text/String

N/A

<action>

Text/String

User

<account>

Text/String

Domain

<domainimpacted>

Text/String

Rule

<policy>

Text/String

Action

<action>

Text/String