Skip to main content
Skip table of contents

V 2.0 IP Tag Messages

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

V 2.0 IP Tag MessagesBase RuleGeneral Profile DetectionInformation

Mapping with LogRhythm Schema  

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
Type (type)<vmid>Text/StringSpecifies the type of log; value is IPTAG.
Threat/Content Type (subtype)<vendorinfo>NumberSubtype of the IPTAG log; unused.
Source IP (src)<dip>IP AddressThe IP address of the source user.
Tag Name (tag_name)<subject>Text/StringThe tag mapped to the source IP address.
Event ID (event_id)<action>Text/StringA string showing the name of the event.
Repeat Count (repeatcnt)<quantity>NumberThe number of sessions with the same Source IP, Destination IP, Application, and Subtype seen within 5 seconds.
Data Source Name (datasourcename)<object>Text/StringThe name of the source from which mapping information is collected.
Data Source Type (datasource_type)<objecttype>Text/StringThe source from which mapping information is collected.
Device Name (device_name)<objectname>Text/StringThe hostname of the firewall on which the session was logged
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.