V 2.0 : Outbound SEP Host Packet Events 1

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

V 2.0 : Outbound SEP Host Packet Events

Base Rule

General Traffic Log

Network Traffic

V 2.0 : Outbound SEP Host Packet Blocked

Sub Rule

Traffic Denied by Host Firewall

Network Deny

V 2.0 : Outbound SEP Host Packet Allowed

Sub Rule

Traffic Allowed by Host Firewall

Network Allow

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

Time Stamp

N/A

N/A

SymantecServer

 <sname>

Text/String

Local

<sip>

Number

N/A

<dip>

Number

Local

<sport>

Number

N/A

<dname>

Text/String

Remote

<dport>

Text/String

Application

<process>

Text/String

Action

<action>

Text/String