V 2.0 : SEP Policy Information 1

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

V 2.0 : SEP Policy Information

Base Rule

General POLICY Information

Information

V 2.0 : SEP Policy Modified

Sub Rule

Policy Modified : System

Policy

V 2.0 : SEP Policy Deleted

Sub Rule

Policy Disabled : System

Policy

V 2.0 : SEP Policy Created

Sub Rule

Policy Created : System

Policy

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

Time Stamp

N/A

N/A

Site Name

N/A

N/A

Server Name

<dname>

Text/String

Domain Name

N/A

N/A

Admin Name

<login>

Text/String

Event ID\Description

<subject>
<tag1>

Text/String

Policy Name

<policy>

Text/String