Skip to main content
Skip table of contents

V 2.0 : Spyware/Grayware Event

Vendor Documentation

Classification

Rule Name

Rule Type

Classification

Common Event

V 2.0 : Spyware/Grayware EventBase RuleMalwareDetected Spyware Activity
V 2.0 : Spyware/Grayware : UnknownSub RuleOther SecurityGeneral Security
V 2.0 : Spyware/Grayware : Not ApplicableSub RuleOther SecurityGeneral Security
V 2.0 : Spyware/Grayware : File CleanedSub RuleFailed MalwareFailed Spyware Activity
V 2.0 : Spyware/Grayware : File DeletedSub RuleFailed MalwareFailed Spyware Activity
V 2.0 : Spyware/Grayware : File QuarantinedSub RuleActivityQuarantine
V 2.0 : Spyware/Grayware : File RenamedSub RuleMalwareDetected Spyware Activity
V 2.0 : Spyware/Grayware : File PassedSub RuleMalwareDetected Spyware Activity
V 2.0 : Spyware/Grayware : Unable To Clean File, PassedSub RuleMalwareDetected Spyware Activity
V 2.0 : Spy/Grayware : Unable To Clean File, DeletedSub RuleFailed MalwareFailed Spyware Activity
V 2.0 : Spy/Grayware : Unable To Clean File, RenamedSub RuleMalwareDetected Spyware Activity
V 2.0 : Spy/Grayware : Unable To Clean File,QuarantineSub RuleActivityQuarantine
V 2.0 : Spyware/Grayware : File DroppedSub RuleFailed MalwareFailed Spyware Activity
V 2.0 : Spy/Grayware : Unable To Clean File, StrippedSub RuleFailed MalwareFailed Spyware Activity
V 2.0 : Spyware/Grayware : File ReplacedSub RuleFailed MalwareFailed Spyware Activity
V 2.0 : Spyware/Grayware : File DroppedSub RuleFailed MalwareFailed Spyware Activity
V 2.0 : Spyware/Grayware : File ArchivedSub RuleMalwareDetected Spyware Activity
V 2.0 : Spyware/Grayware : Blocked SuccessfullySub RuleFailed MalwareFailed Spyware Activity
V 2.0 : Spyware/Grayware : Quarantined SuccessfullySub RuleActivityQuarantine
V 2.0 : Spyware/Grayware : Stamped SuccessfullySub RuleMalwareDetected Spyware Activity
V 2.0 : Spyware/Grayware : File UploadedSub RuleMalwareDetected Spyware Activity
V 2.0 : Spyware/Grayware : Access DeniedSub RuleMalwareDetected Spyware Activity
V 2.0 : Spyware/ Grayware : No ActionSub RuleMalwareDetected Spyware Activity
V 2.0 : Spyware/ Grayware : Scan StoppedSub RuleInformationScan Stopped
V 2.0 : Spyware/ Grayware : EncryptedSub RuleActivityEncrypted Files Detected
V 2.0 : Spyware/ Grayware : UndefinedSub RuleActivityGeneral Activity
V 2.0 : Spyware/ Grayware : System RebootedSub RuleStartup and ShutdownSystem Restarted
V 2.0 : Spyware/Grayware : Action FailedSub RuleActivityGeneral Activity
V 2.0 : Spyware/Grayware : Action RequiredSub RuleActivityGeneral Activity

Mapping with LogRhythm Schema

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
Header (logVer)N/AN/ACEF format version
Header (vendor)N/AN/AAppliance vendor
Header (pname)N/AN/AAppliance product
Header (pver)N/AN/AAppliance version
Header (eventid)<vmid> Text/StringDevice event class ID
Header (eventName) N/AN/AEvent name
Header (severity)<severity>NumberSeverity
deviceExternalIdN/AN/AID
rtN/AN/ALog generation time in UTC
cnt<quantity>NumberNumber of detections
dhost<dname>Text/String/NumberEndpoint host name
cn1LabelN/AN/ACorresponding label for the "cn1" field
cn1N/AN/APattern type
cs1LabelN/AN/ACorresponding label for the "cs1" field
cs1<threatname>Text/StringSpyware/Grayware
cs2Label N/AN/ACorresponding label for the "cs2" field
cs2<verison>NumberEngine version
cs5Label N/AN/ACorresponding label for the "cs5" field
cs5<action>
<tag1>
Text/String/NumberAction
cs6LabelN/AN/ACorresponding label for the "cs6" field
cs6N/AN/APattern version
catN/AN/ALog type
dvchost N/AN/AEndpoint host name
fname<object>Text/String/NumberResource
filePath N/AN/AResource
dst<dip>IP AddressEndpoint IPv4 address
c6a3LabelN/AN/ACorresponding label for the "c6a3" field
c6a3N/AN/AEndpoint IPv6 address
deviceFacilityN/AN/AProduct
deviceNtDomainN/AN/AActive Directory domain
dntdomN/AN/AApex One domain hierarchy
TMCMLogDetectedHost<dname>Text/String/NumberEndpoint name where the log event occurred
TMCMLogDetectedIP<dip>IP AddressIP address where the log event occurred
fileHash<hash>Text/String/NumberFile SHA-1
duser<account>Text/String/NumberUser Name
cn2LabelN/AN/ACorresponding label for the "cn2" field
cn2N/AN/AScan type
cn3LabelN/AN/ACorresponding label for the "cn3" field
cn3N/AN/ASecurity Threat Type
ApexCentralHostN/AN/AApex Central host name
devicePayloadIdN/AN/AUnique message GUID
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.