V 2.0 User ID Messages 1

Log Fields and Parsing

This section details the log fields available in this log message type, along with values parsed for both LogRhythm Default and LogRhythm Default v2.0 policies. A value of "N/A" (not applicable) means that there is no value parsed for a specified log field.

Log Field

LogRhythm Default

LogRhythm Default v2.0

Header : Severity

<severity>

N/A

Type (type)

<vmid>

<vmid>

Threat/Content Type (subtype)

<objectname>

<action>
<tag1>

N/A

<tag2>

N/A


<dname>

N/A

Virtual System (vsys)

<sinterface>

N/A

Source IP (ip)

<sip>

<sip>

User (user)

<domainorigin>
<login>

<domainorigin>
<login>

Data Source Name (datasourcename)

<object>

N/A

Repeat Count (repeatcnt)

N/A

<quantity>

Data Source (datasource)

<subject>

<subject>

Device Name (device_name)

N/A

<objectname>

Log Processing Settings

This section details log processing changes made from the LogRhythm Default policy to LogRhythm Default v2.0. In some cases, base rules are broken down into sub-rules to appropriately parse log message types by their event types.

LogRhythm Default

Regex ID

Rule Name

Rule Type

Common Events

Classifications

1009495

USER ID Messages : Login

Sub Rule

User Logon

Authentication Success

USER ID Messages : Logout

Sub Rule

User Logoff

Authentication Success

USERID Messages

Base Rule

Authentication Activity

Authentication Success

LogRhythm Default v2.0

Regex ID

Rule Name

Rule Type

Common Events

Classifications

1010883


V 2.0 User ID Messages

Base Rule

General Authentication Event

Other Audit

V 2.0 User Logon

Sub Rule

User Logon

Authentication Success

V 2.0 User Logoff

Sub Rule

User Logoff

Authentication Success

V 2.0 User Registration Event

Sub Rule

Registration

Information