Skip to main content
Skip table of contents

V 2.0 : Inbound SEP Host Traffic Events

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

V 2.0 : Inbound SEP Host Traffic EventsBase RuleGeneral Traffic LogNetwork Traffic
V 2.0 : Inbound SEP Host Traffic BlockedSub RuleTraffic Denied by Host FirewallNetwork Deny
V 2.0 : Inbound SEP Host Traffic AllowedSub RuleTraffic Allowed by Host FirewallNetwork Allow

Mapping with LogRhythm Schema  

Device Key in Log MessageLogRhythm SchemaData Type
Remote

<sname>

Text/String
Remote

<sip>

Number
SymantecServer<dname>Text/String
Rule<policy>Text/String
action<tag1>Text/String
N/A<protnum>Number

SHA-256

MD-5

<hash>Text/String
Remote

<sport>

Number
Remote<smac>Text/String
Local<dip>Number
Local<dport>Number
Occurrences<quantity>Number
Application<process>Text/String
N/A<protname>Text/String
Local<dmac>Text/String
N/A<action>Text/String
User<account>Text/String
Domain<domainimpacted>Text/String
Rule<policy>Text/String
Action<action>Text/String
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.