Skip to main content
Skip table of contents

V 2.0 : Product Auditing Event

Vendor Documentation

Classification


Rule Name Rule TypeClassificationCommon Event
V 2.0 : Product Auditing EventBase RuleOther AuditGeneral Auditing Message
V 2.0 : Product Auditing : ErrorSub RuleErrorGeneral Error Message
V 2.0 : Product Auditing : WarningSub RuleWarningGeneral Warning Log Message
V 2.0 : Product Auditing : InformationSub RuleInformationGeneral Information Log Message
V 2.0 : Product Auditing : Failure AuditSub RuleFailure AuditAuditing Failed

Mapping with LogRhythm Schema


Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
Header (logVer)N/AN/ACEF format version
Header (vendor)<vendorinfo>Text/stringProduct vendor
Header (pname)N/AN/AProduct name
Header (pver)N/AN/AProduct version
Header (eventid)N/AN/AEvent ID
Header (eventName)<vmid>Text/stringLog name
Header (severity)N/AN/ASeverity
catN/AN/ALog type
deviceFacilityN/AN/AManaged product
dvchostN/AN/ADisplay name of the managed endpoint
rtN/AN/ALog generation time in UTC
cn1LabelN/AN/ACorresponding label for the "cn1" field
cn1N/AN/ACategory ID Example: "536,870,912"
cn2LabelN/AN/ACorresponding label for the "cn2" field
cn2

<severity>

<tag1>

NumberSeverity level
Example: "4"
1 = ERROR

2 = WARNING

4 = INFORMATION

16 = FAILURE AUDIT
suser<login>Text/string

The name of the user on whose behalf the event occurred

deviceNtDomainN/AN/AActive Directory domain
Example: APEXTMCM
dntdomN/AN/AApex One domain hierarchy
ApexCentralHostN/AN/AApex Central host name
devicePayloadIdN/AN/AUnique message GUID
act<action>Text/stringAction
src<sip>Number/Ip addressSource IP
dst<dip>Number/Ip addressDestiantion IP
smac<smac>Text/stringSource MAC
spt<sport>NumberSource Port
dmac<dmac>Text/stringDestination MAC
dpt<dport>NumberDestination Port
deviceDirectionN/AN/ADirection
cn3LabelN/AN/AN/A
cn3N/AN/AN/A
cn4LabelN/AN/AN/A
cn4N/AN/AN/A
proto<protnum>NumberN/A
cs2LabelN/AN/AN/A
cs2N/AN/AN/A
cs1LabelN/AN/AN/A
cs1N/AN/AN/A
cntN/AN/AN/A
cn2LabelN/AN/AN/A
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.