Skip to main content
Skip table of contents

V 2.0 : Pattern Update Status Event

Vendor Documentation


Rule Name

Rule Type


Common Event

V 2.0 : Pattern Update Status EventBase RuleInformationGeneral Information

Mapping with LogRhythm Schema

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
Header (logVer)N/AN/ACEF format version
Header (vendor)N/AN/AProduct vendor
Header (pname)N/AN/AProduct name
Header (pver)N/AN/AProduct version
Header (eventid)N/AN/AEvent ID
Header (eventName)<vmid> Text/StringLog name
Header (severity)<severity>NumberSeverity
rtN/AN/ALog generation time in UTC
shost<dname>Text/String/NumberProduct Entity/Endpoint
cs1LabelN/AN/ACorresponding label for the "cs1" field
cs1N/AN/AOperating system
cs2LabelN/AN/ACorresponding label for the "cs2" field
cs2<dip>IP AddressProduct/Endpoint IP
cs3LabelN/AN/ACorresponding label for the "cs3" field
cs3N/AN/AUpdate Agent
cs4LabelN/AN/ACorresponding label for the "cs4" field
cn1LabelN/AN/ACorresponding label for the "cn1" field
cn1<status>Number0: Unable to connect
1: Active
2: Inactive
100: Product active
101: Product inactive but agent is active
102: Roaming
cn2LabelN/AN/ACorresponding label for the "cn2" field
cs5LabelN/AN/ACorresponding label for the "cs5" field
cs5N/AN/APattern/Rule version
cn3LabelN/AN/ACorresponding label for the "cn3" field
cn3N/AN/A0: Up-to-date
1: 1 version old
2: 2 versions old
3: 3 versions old
4: 4 versions old
5: 5 versions old
6: 6 versions old
7: 7 or more versions old
cs6LabelN/AN/ACorresponding label for the "cs6" field
cs6N/AN/A2: Pattern
deviceFacilityN/AN/AManaged product name
msgN/AN/APattern type display name
ApexCentralHostN/AN/AApex Central host name
deviceNtDomainN/AN/AActive Directory domain

Apex One domain hierarchy

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.