Skip to main content
Skip table of contents

V 2.0 : Outbound SEP Host Traffic Events

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

V 2.0 : Outbound SEP Host Traffic EventsBase RuleGeneral Traffic LogNetwork Traffic
V 2.0 : Outbound SEP Host Traffic BlockedSub RuleTraffic Denied by Host FirewallNetwork Deny
V 2.0 : Outbound SEP Host Traffic AllowedSub RuleTraffic Allowed by Host FirewallNetwork Allow

Mapping with LogRhythm Schema 

Device Key in Log MessageLogRhythm SchemaData Type
SymantecServer

<sname>

Text/String
Local<sip>Number
Local<sport>Number
Local<smac>Text/String
Remote<dip>Number
Remote<dname>Text/String
Remote<dport>Number
Remote<dmac>Number
N/A<protnum>Number
N/A<protname>Text/String
Occurrences<quantity>Number
Application<process>Text/String
Rule<policy>Text/String
User<login>Text/String
Domain<domainorigin>Text/String
Action<action>Text/String
Action<tag1>Text/String

SHA-256:

MD-5:

<hash>Number
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.