V 2.0 IP Tag Messages 1

Log Fields and Parsing

This section details the log fields available in this log message type, along with values parsed for both LogRhythm Default and LogRhythm Default v2.0 policies. A value of "N/A" (not applicable) means that there is no value parsed for a specified log field.

Log Field

LogRhythm Default

LogRhythm Default v2.0

Type (type)

N/A

<vmid>

Threat/Content Type (subtype)

N/A

<vendorinfo>

Source IP (src)

N/A

<dip>

Tag Name (tag_name)

N/A

<subject>

Event ID (event_id)

N/A

<action>

Repeat Count (repeatcnt)

N/A

<quantity>

Data Source Name (datasourcename)

N/A

<object>

Data Source Type (datasource_type)

N/A

<objecttype>

Device Name (device_name)

N/A

<objectname>

Log Processing Settings

This section details log processing changes made from the LogRhythm Default policy to LogRhythm Default v2.0. In some cases, base rules are broken down into sub-rules to appropriately parse log message types by their event types.

LogRhythm Default

Regex ID

Rule Name

Rule Type

Common Events

Classifications

N/A

N/A

N/A

N/A

N/A

LogRhythm Default v2.0

Regex ID

Rule Name

Rule Type

Common Events

Classifications

1010889

V 2.0 IP Tag Messages

Base Rule

General Profile Detection

Information