Skip to main content
Skip table of contents

V 2.0 IP Flow Events

Vendor Documentation

Classification

Rule Name

Rule Type

Classification

Common Event

V 2.0 IP Flow Events

Base Rule

Network Traffic

Flow Activity

V 2.0 IP flow end

Sub Rule

Network Traffic

IP Flow Events

V 2.0 IP flow start

Sub Rule

Network Traffic

IP Flow Events

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

Schema Description

N/A

N/A

N/A

Flow start time.

N/A

N/A

N/A

Flow stop time.

N/A

<object>

Text/String

Device name.

type

<vendorinfo>
tag1

Text/String

N/A

src

<sip>

IP Address

N/A

dst

<dip>

IP Address

N/A

protocol

<protname>

Text/String

N/A

sport

<sport>

Number

N/A

dport

<dport>

Number

N/A

translated_src_ip

<snatip>

IP Address

N/A

translated_dst_ip

<dnatip>

IP Address

N/A

translated_port

<snatport>

Number

N/A

translated_port

<dnatport>

Number

N/A

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.