Skip to main content
Skip table of contents

V 2.0 Passed Authentications Event

Vendor Documentation

Classification

Rule NameRule TypeCommon EventClassification
V 2.0 Passed Authentications EventBase RuleGeneral Authentication EventOther Audit
V 2.0 EVID 5200 Authentication SuccessSub RuleAuthentication ActivityAuthentication Success
V 2.0 EVID 5201 Authentication SuccessSub RuleAuthentication ActivityAuthentication Success
V 2.0 EVID 5202 Command Authorization SucceededSub RuleAuthorization SuccessOther Audit Success
V 2.0 EVID 5203 Session Authorization SucceededSub RuleAuthorization SuccessOther Audit Success
V 2.0 EVID 5204 Change Password SuccessSub RulePassword ModifiedAccount Modified
V 2.0 EVID 5205 Dynamic Authorization SuccessSub RuleAuthorization SuccessOther Audit Success
V 2.0 EVID 5206 PAC ProvisionedSub RulePAC ProvisionedInformation
V 2.0 EVID 5231 Guest Authentication PassedSub RuleAuthentication ActivityAuthentication Success
V 2.0 EVID 5232 DACL Download SucceededSub RuleConfiguration File DownloadedInformation
V 2.0 EVID 5233 TrustSec Data Download SucceededSub RuleConfiguration File DownloadedInformation
V 2.0 EVID 5234 Trust Sec Peer Policy Dwnd SuccSub RuleConfiguration File DownloadedInformation
V 2.0 EVID 5236 Authorize Only Ended SuccessSub RuleAuthorization SuccessOther Audit Success
V 2.0 EVID 5237 Device Reg Web Auth PassedSub RuleDevice RegisteredOther Audit Success
V 2.0 EVID 5238 Endpoint Auth Problem FixedSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 5239 NAS Problem FixedSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 5240 Rejected EP Released For AuthSub RuleGeneral RADIUS MessageInformation
V 2.0 EVID 5241 RADIUS DTLS Handshake SucceededSub RuleSuccessful ActivityOther Audit Success

Mapping with LogRhythm Schema

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
pri_numN/AN/AThe priority value of the message, is a combination of the facility value and the severity value of the message. Priority value = (facility value * 8) + severity value.
The facility code valid options are:
LOCAL0 (Code = 16)
LOCAL1 (Code = 17)
LOCAL2 (Code = 18)
LOCAL3 (Code = 19)
LOCAL4 (Code = 20)
LOCAL5 (Code = 21)
LOCAL6 (Code = 22; default)
LOCAL7 (Code = 23)
timeN/AN/ADate of the message generation, according to the local clock of the originating Cisco ISE server, in the format Mmm DD hh:mm:ss.
IP address/hostnameN/AN/AIP address of the originating Cisco ISE node, or the hostname.
cat_name<vendorinfo>Text/StringLogging category name preceded by the CSCOxxx string.
msg_idN/AN/AUnique message ID; 1 to 4294967295. The message ID increases by 1 with each new message. Message IDs restart at 1 each time the application is restarted.
total_segN/AN/ATotal number of segments in a log message. Long messages are divided into more than one segment.
Note : The total_seg depends on the Maximum Length setting in the remote logging targets page. See Remote Logging Target Settings.
seg_numN/AN/ASegment sequence number within a message. Use this number to determine what segment of the message you are viewing.
timestampN/AN/ADate of the message generation, according to the local clock of the originating Cisco ISE node, in the following format :
YYYY-MM-DD hh:mm:ss: xxx +/-zh:zm.
sequence_numN/AN/AGlobal counter of each message. If one message is sent to the local store and the next to the syslog server target, the counter increments by 2. Possible values are 0000000001 to 999999999.
msg_code<vmid>
<tag1>
NumberMessage code as defined in the logging categories.
msg_sev<severity>Text/StringMessage severity level of a log message.
msg_class<subject> Text/StringMessage class, which identifies groups of messages with the same context.
msg_text<action> Text/StringEnglish language descriptive text message.
ConfigVersionIdN/AN/AN/A
Device IP Address<sip>IP AddressN/A
DestinationIPAddress<dip>IP AddressN/A
DestinationPort<dport>NumberN/A
UserName<login>Text/StringN/A
CmdSet<command>Text/StringN/A
Protocol<protname>Text/StringN/A
MatchedCommandSetN/AN/AN/A
RequestLatencyN/AN/AN/A
NetworkDeviceNameN/AN/AN/A
User-NameN/AN/AN/A
NAS-IP-Address<sip>IP AddressN/A
NAS-PortN/AN/AN/A
NAS-Port-TypeN/AN/AN/A
Service-TypeN/AN/AN/A
Framed-IP-Address<dip>IP AddressN/A
Framed-ProtocolN/AN/AN/A
Called-Station-IDN/AN/AN/A
Calling-Station-IDN/AN/AN/A
Acct-Session-Id<session>Text/StringN/A
NAS-Port-TypeN/AN/AN/A
Connect-InfoN/AN/AN/A
Event-TimestampN/AN/AN/A
cisco-av-pair=subscriber:reauthenticate-typeN/AN/AN/A
cisco-av-pair=subscriber:command<command>Text/StringN/A
cisco-av-pair=audit-session-id<session>Text/StringN/A
cisco-av-pair=aaa:serviceN/AN/AN/A
cisco-av-pair=aaa:eventN/AN/AN/A
cisco-av-pair=coa-pushN/AN/AN/A
OriginalUserNameN/AN/AN/A
MisconfiguredClientFixReason<reason>Text/StringN/A
NetworkDeviceProfileNameN/AN/AN/A
NetworkDeviceProfileIdN/AN/AN/A
IsThirdPartyDeviceFlowN/AN/AN/A
RadiusFlowTypeN/AN/AN/A
SSIDN/AN/AN/A
TypeN/AN/AN/A
Action<status>Text/StringN/A
Privilege-LevelN/AN/AN/A
Authen-TypeN/AN/AN/A
Service<status>Text/StringN/A
UserN/AN/AN/A
PortN/AN/AN/A
Remote-Address<dnatip>IP AddressN/A
Authen-MethodN/AN/AN/A
Service-ArgumentN/AN/AN/A
Protocol-ArgumentN/AN/AN/A
NetworkDeviceProfileIdN/AN/AN/A
AcsSessionID<session>Text/StringN/A
UserTypeN/AN/AN/A
FirstnameN/AN/AN/A
LastnameN/AN/AN/A
EmailAddress<sender>Text/StringN/A
MacAddress<smac>Text/StringN/A
IpAddressN/AN/AN/A
AuthenticationIdentityStoreN/AN/AN/A
AuthenticationMethodN/AN/AN/A
SelectedAccessServiceN/AN/AN/A
SelectedCommandSetN/AN/AN/A
SelectedShellProfileN/AN/AN/A
PortalNameN/AN/AN/A
IdentityGroup<group>Text/StringN/A
PsnHostNameN/AN/AN/A
GuestUserNameN/AN/AN/A
EPMacAddressN/AN/AN/A
NADAddressN/AN/AN/A
AuditSessionId<session>Text/StringN/A
ResponseTimeN/AN/AN/A
StepN/AN/AN/A
StepN/AN/AN/A
StepN/AN/AN/A
StepN/AN/AN/A
NetworkDeviceGroups<group>Text/StringN/A
NetworkDeviceGroupsN/AN/AN/A
NetworkDeviceGroupsN/AN/AN/A
Key1N/AN/AN/A
Key2N/AN/AN/A
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.