Skip to main content
Skip table of contents

V 2.0 : Managed Product Logon/Logoff Events

Vendor Documentation

Classification

Rule Name

Rule Type

Classification

Common Event

V 2.0 : Managed Product Logon/Logoff EventsBase RuleOther AuditGeneral Authentication Event

Mapping with LogRhythm Schema

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
Header (logVer)N/AN/ACEF format version
Header (vendor)N/AN/AAppliance vendor
Header (pname)N/AN/AAppliance product
Header (pver)N/AN/AAppliance version
Header (eventid)N/AN/AEvent ID
Header (eventName)<vmid> Text/StringLog name
Header (severity)<severity>NumberSeverity
deviceExternalIdN/AN/AID
shost<dname>Text/String/NumberProduct server name
deviceFacilityN/AN/AProduct name
cs1LabelN/AN/ACorresponding label for the "cs1" field
cs1<version>NumberProduct version
cn1LabelN/AN/ACorresponding label for the "cn1" field
cn1<status>NumberCommand status
msg<subject>
<login>
<sip>

Text/String/Number
Text/String/Number
Ip Address

Detailed event information
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.