Skip to main content
Skip table of contents

V 2.0 : SEP General Object Access Message 1

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

V 2.0 : SEP Device Information MessageSub RuleGeneral InformationInformation
V 2.0 : SEP General Object Access MessageBase RuleGeneral InformationInformation
V 2.0 : SEP File Transfer To Removable Media AllowSub RuleFile Transfer CompleteOther Audit Success
V 2.0 : SEP Object Access AllowedSub RuleObject AccessedAccess Success
V 2.0 : SEP File Transfer To Removable Media BlockSub RuleFile Transfer BlockedOther Audit Failure
V 2.0 : SEP File Read AllowedSub RuleObject ReadAccess Success
V 2.0 : SEP Process Creation AllowedSub RuleRule AllowedOther Audit Success
V 2.0 : SEP File Read BlockedSub RuleRead Object FailureAccess Failure
V 2.0 : SEP Object Access BlockedSub RuleAccess Object FailureAccess Failure
V 2.0 : SEP Process Creation BlockedSub RuleProcess BlockedFailed Activity

Mapping with LogRhythm Schema  

Device Key in Log MessageLogRhythm SchemaData Type
Event Time N/AN/A
Severity N/AN/A
Host Name<sname>Text/String
IP Address<sip>Number
Action Description<action>
<tag1>
Text/String
Event Description<subject>Text/String
API Name<command>
<tag2>
Text/String
Begin Time N/AN/A
End Time N/AN/A
Security Rule Name<policy>Text/String
Caller Process ID<processid>Number
Caller Process Name<process>Text/String
Caller Return Address N/AN/A
Caller Return Module Name N/AN/A
Parameters<object>Text/String
User Name<login>Text/String
Domain Name<domainorigin>Text/String
Action Type N/AN/A
File Size<size>Number
Device ID<objecttype>Text/String
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.