Skip to main content
Skip table of contents

V 2.0 : Media Encryption & Port Protection Events

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

V 2.0 : Media Encryption & Port Protection EventsBase RuleGeneral InformationInformation

Mapping with LogRhythm Schema

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
Product<vmid>Text/StringProduct name
Originip<sip>IP AddressIP of the log origin 
originN/AN/AName of the first Security Gateway that reported this event
Action<action>Text/StringDescription of detected malware activity
SIP<sip>IP AddressSource IP
SPort<sport>NumberSource host port number
DIP<dip>IP AddressDestination IP
dport<dport>Number
protocol<protnum>Text/String/NumberProtocol detected on the connection
ifname<sinterface>Text/StringThe name of the Security Gateway interface, through which a connection traverses
ifdirectionN/AN/AN/A
reason<reason>Text/StringInformation on the error occurred
RuleN/AN/AN/A
InfoN/AN/AN/A
XlateSIP<snatip>IP AddressN/A
XlateSport<snatport>NumberN/A
XlateDIP<dnatip>IP AddressN/A
XlateDPort<dnatport>NumberN/A
userN/AN/ASource user name
alertN/AN/AN/A
icmp-codeN/AN/AN/A
icmp-typeN/AN/AN/A
matched_categoryN/AN/AN/A
rule_nameN/AN/AAccess rule name
UrlN/AN/AN/A
timeN/AN/AThe time stamp when the log was created.
src_machine_name<sname>Text/StringMachine name connected to source IP
src_user_name<login>Text/StringUser name connected to source IP
severity<severity>Text/String/NumberThreat severity determined by ThreatCloud
Possible values:
0 -Informational
1 - Low
2 -Medium
3 - High
4 - Critical
descriptionN/AN/AN/A
client_nameN/AN/AN/A
flagsN/AN/AN/A
loguidN/AN/AUUID  of unified logs 
sequencenumN/AN/ANumber added to order logs with the same linux timestamp and origin
__policy_id_tag<policy>Text/StringN/A
versionN/AN/AN/A
client_version<version>Text/String/NumberBuild version of SandBlast Agent client installed on the computer 
connectivity_state<status>Text/StringN/A
event_typeN/AN/AN/A
host_typeN/AN/AN/A
installed_productsN/AN/AN/A
is_scannedN/AN/AN/A
local_timeN/AN/AN/A
machine_guidN/AN/AN/A
media_authorizedN/AN/AN/A
media_class_id<object>Text/StringN/A
media_description<subject>Text/StringN/A
media_encryptedN/AN/AN/A
media_manufacturerN/AN/AN/A
media_type<objecttype>Text/StringN/A
os_nameN/AN/AName of the OS installed on the source endpoint computer 
os_versionN/AN/ABuild version of the OS installed on the source endpoint computer 
product_familyN/AN/AN/A
reading_data_accessN/AN/AN/A
user_nameN/AN/AN/A
user_sidN/AN/AN/A
writing_data_accessN/AN/AN/A
log_linkN/AN/AN/A
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.