Skip to main content
Skip table of contents

V 2.0 : Outbound SEP Malicious Activity Detected

Log Fields and Parsing

This section details the log fields available in this log message type, along with values parsed for both LogRhythm Default and LogRhythm Default v2.0 policies. A value of "N/A" (not applicable) means that there is no value parsed for a specified log field.

Log FieldLogRhythm DefaultLogRhythm Default v2.0
N/A<severity><sname>
N/A<sip><sip>
N/A<dip><dip>
N/A<vendorinfo><dname>
N/A<dname><sport>
N/A<sport>N/A
N/A<dport><dport>
N/A<login><login>
N/A<domainorigin><domainorigin>
N/A<process><subject>
N/A<smac><smac>
N/A<dmac><dmac>
N/A<protname><protname>
N/A<threatname><threatname>
N/A<threatid><threatid>
N/A<url><hash>
N/A<quantity><quantity>
N/A<group><tag1>
N/A<duration><tag2>
N/A<tag1>N/A

Log Processing Settings

This section details log processing changes made from the LogRhythm Default policy to LogRhythm Default v2.0. In some cases, base rules are broken down into sub-rules to appropriately parse log message types by their event types.

LogRhythm Default

Regex IDRule NameRule TypeCommon EventsClassifications
1001595










Suspicious ActivityBase RuleSuspicious Network ActivitySuspicious
Port Scan DetectedSub RulePort ScanReconnaissance
Unsolicited Incoming ARP Reply DetectedSub RuleSuspicious ActivitySuspicious
Brute Force Remote LoginSub RuleBrute Force ActivityAttack
CategorySub RuleURL Logged - CategoryActivity
Web AttackSub RuleGeneral Attack ActivityAttack
System InfectedSub RuleGeneral Virus Infected AlertCritical
OS AttackSub RuleGeneral Attack ActivityAttack
AttackSub RuleGeneral Attack ActivityAttack
Denial Of Service AttackSub RuleNetwork Denial Of ServiceDenial Of Service
Blocked AttackSub RuleThreat BlockedFailed Activity
Device Manager Allowed DeviceSub RuleDevice AllocatedOther Audit Success

LogRhythm Default v2.0 

Regex IDRule NameRule TypeCommon EventsClassifications
1011181V 2.0 : Outbound SEP Malcious Activity DetectedBase RuleGeneral Attack ActivityAttack
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.