Skip to main content
Skip table of contents

V 2.0 : Query-database Events

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

V 2.0 : Query-database EventsBase RuleGeneral InformationInformation

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

Schema Description

Product<vmid>Text/StringProduct name
Originip<sip>IP AddressIP of the log origin 
originN/AN/AName of the first Security Gateway that reported this event
operationN/AN/AN/A
subject<subject>Text/StringN/A
status<status>Text/StringN/A
administrator<login>Text/StringN/A
clientN/AN/AN/A
performedon<object>Text/StringN/A
objecttableN/AN/AN/A
objecttype<objecttype>Text/StringN/A
generalinformationN/AN/AN/A
timeN/AN/AN/A
Action<action>Text/StringDescription of detected malware activity
ifdirectionN/AN/AConnection direction
ifname<sinterface>Text/StringThe name of the Security Gateway interface, through which a connection traverses
session_idN/AN/AN/A
alertN/AN/AAlert level of matched rule (for connection logs)
client_ip_hostN/AN/AN/A
flagsN/AN/ACheckpoint internal field
loguidN/AN/AUUID  of unified logs  
sequencenumN/AN/ANumber added to order logs with the same linux timestamp and origin
originsicnameN/AN/AN/A
sendtotrackerasadvancedauditlogN/AN/AN/A
admin_levelN/AN/AN/A
cma_nameN/AN/AN/A
operation_numberN/AN/AN/A
mds_nameN/AN/AN/A
uidN/AN/AN/A
fieldschangesN/AN/AN/A
customer_nameN/AN/AN/A
version<version>NumberN/A
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.