V 2.0 : Outbound SEP Host Traffic Events

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

V 2.0 : Outbound SEP Host Traffic Events

Base Rule

General Traffic Log

Network Traffic

V 2.0 : Outbound SEP Host Traffic Blocked

Sub Rule

Traffic Denied by Host Firewall

Network Deny

V 2.0 : Outbound SEP Host Traffic Allowed

Sub Rule

Traffic Allowed by Host Firewall

Network Allow

Mapping with LogRhythm Schema 

Device Key in Log Message

LogRhythm Schema

Data Type

SymantecServer

<sname>

Text/String

Local

<sip>

Number

Local

<sport>

Number

Local

<smac>

Text/String

Remote

<dip>

Number

Remote

<dname>

Text/String

Remote

<dport>

Number

Remote

<dmac>

Number

N/A

<protnum>

Number

N/A

<protname>

Text/String

Occurrences

<quantity>

Number

Application

<process>

Text/String

Rule

<policy>

Text/String

User

<login>

Text/String

Domain

<domainorigin>

Text/String

Action

<action>

Text/String

Action

<tag1>

Text/String

SHA-256:

MD-5:

<hash>

Number