Skip to main content
Skip table of contents

V 2.0 User ID Messages

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

V 2.0 User ID MessagesBase Rule

General Authentication Event

Other Audit

V 2.0 User Logon

Sub RuleUser LogonAuthentication Success
V 2.0 User LogoffSub RuleUser LogoffAuthentication Success
V 2.0 User Registration EventSub RuleRegistrationInformation

Mapping with LogRhythm Schema  

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
Type (type)<vmid>Text/StringSpecifies the type of log; value is USERID.
Threat/Content Type (subtype)<action>
<tag1>
Text/StringSubtype of User-ID log; values are login, logout, register-tag, and unregister-tag.
login—User logged in.
logout—User logged out.
register-tag—Indicates a tag or tags were registered for the user.
unregister-tag—Indicates a tag or tags were unregistered for the user.
Source IP (ip)<sip>IP AddressOriginal session source IP address
User (user)<domainorigin>
<login>
Text/StringIdentifies the end user.
Repeat Count (repeatcnt)<quantity>NumberNumber of sessions with same Source IP, Destination IP, Application, and Subtype seen within 5 seconds
Data Source (datasource)<subject>Text/StringSource from which mapping information is collected.
Device Name (device_name)<objectname>Text/StringThe hostname of the firewall on which the session was logged.
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.