Skip to main content
Skip table of contents

V 2.0 : IPS Events

Vendor Documentation

Classification

Rule NameRule TypeCommon EventClassification
V 2.0 : IPS EventsBase RuleGeneral InformationInformation
V 2.0 : IPS : Action FailedSub RuleAction FailureError
V 2.0 : IPS : Action StartedSub RuleStart ActionInformation

Mapping with LogRhythm Schema

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
virtuallogsourceN/AN/AN/A
subproductN/AN/AN/A
product<vmid>Text/StringProduct name
Originip<dip>IP AddressIP of the log origin 
originN/AN/AName of the first Security Gateway that reported this event
ActionN/AN/AN/A
SIPN/AN/ASource IP
SPortN/AN/ASource host port number
DIPN/AN/ADestination IP
dportN/AN/AN/A
protocolN/AN/AProtocol detected on the connection
ifnameN/AN/AThe name of the Security Gateway interface through which a connection traverses
ifdirectionN/AN/AN/A
reason<reason>Text/StringInformation on the error occurred
RuleN/AN/AN/A
InfoN/AN/AN/A
XlateSIPN/AN/AN/A
XlateSportN/AN/AN/A
XlateDIPN/AN/AN/A
XlateDPortN/AN/AN/A
userN/AN/ASource user name
alertN/AN/AN/A
icmp-codeN/AN/AN/A
icmp-typeN/AN/AN/A
matched_categoryN/AN/AN/A
rule_nameN/AN/AAccess rule name
UrlN/AN/AN/A
timeN/AN/AThe time stamp when the log was created
severityN/AN/AN/A
description<vendorinfo>Text/StringN/A
update_status<status>
<tag1>
Text/StringN/A
flagsN/AN/AN/A
loguidN/AN/AUUID of unified logs 
sequencenumN/AN/ANumber added to order logs with the same Linux timestamp and origin
versionN/AN/AN/A
db_verN/AN/AN/A
subs_expN/AN/AN/A
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.