Skip to main content
Skip table of contents

V 2.0 : System Monitor Events

Vendor Documentation

Classification

Rule NameRule TypeCommon EventClassification
V 2.0 : System Monitor EventsBase RuleHealth Monitor MessageInformation
V 2.0 : System Monitor : Problem DetectedSub RuleHealth WarningWarning
V 2.0 : System Monitor : Problem ResolvedSub RuleDevice In Good HealthInformation


Mapping with LogRhythm Schema

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
virtuallogsourceN/AN/AN/A
subproductN/AN/ACan be VPN or non-VPN
Product<vmid>Text/StringProduct name
Originip<dip>IP AddressIP of the log origin 
originN/AN/AName of the first Security Gateway that reported this event
ActionN/AN/AN/A
SIPN/AN/ASource IP
SPortN/AN/ASource host port number
DIPN/AN/ADestination IP
dportN/AN/ADestination host port number
protocolN/AN/AProtocol detected on the connection
ifnameN/AN/AThe name of the Security Gateway interface through which a connection traverses
ifdirectionN/AN/AConnection direction
ReasonN/AN/AInformation on the error occurred
RuleN/AN/AMatched rule number
InfoN/AN/ARule information on the blocked diameter CMD
XlateSIPN/AN/ASource ipv4 after applying NAT
XlateSportN/AN/ASource port after applying hide NAT on source IP
XlateDIPN/AN/ADestination ipv4 after applying NAT
XlateDPortN/AN/ADestination port after applying NAT
UserN/AN/ASource user name
alertN/AN/AAlert level of matched rule (for connection logs)
icmp-codeN/AN/AN/A
icmp-typeN/AN/AN/A
matched_categoryN/AN/AName of matched category
rule_nameN/AN/AAccess rule name
UrlN/AN/AMatched URL
timeN/AN/AThe time stamp when the log was created
Severity<severity>NumberThreat severity determined by ThreatCloud
Possible values:
0 - Informational
1 - Low
2 - Medium
3 - High
4 - Critical
flagsN/AN/ACheckpoint internal field
loguidN/AN/AUUID of unified logs 
sequencenumN/AN/ANumber added to order logs with the same Linux timestamp and origin
versionN/AN/AN/A
log_idN/AN/AUnique identity for logs includes: Type, Family, Product/Blade, or Category
sensor_alert_bladeN/AN/AN/A
sensor_alert_categoryN/AN/AN/A
sensor_alert_durationN/AN/AN/A
sensor_alert_idN/AN/AN/A
sensor_alert_message<vendorinfo>Text/StringN/A
sensor_alert_module<object>Text/StringN/A
sensor_alert_solutionN/AN/AN/A
sensor_alert_solution_skN/AN/AN/A
sensor_alert_source<dname>Text/StringN/A
sensor_alert_title<subject>Text/StringN/A
sensor_alert_type<tag1>Text/StringN/A
sensor_test_name<policy>Text/StringN/A
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.