V 2.0 WPA Authentication/Deauthentication Event

Vendor Documentation

Classification

Rule Name

Rule Type

Classification

Common Event

V 2.0 WPA Authentication/Deauthentication Event

Base Rule

Information

General Access Point Activity

V 2.0 WPA Authentication

Sub Rule

Information

General Authentication Information

V 2.0 WPA Deauthentication

Sub Rule

Network Traffic

Disconnect Session

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

Schema Description

N/A

N/A

N/A

flow start time

N/A

N/A

N/A

flow stop time

N/A

<object>

Text/String

device

N/A

<vendorinfo>

Text/String

event type

type

<action>
<tag1>

Text/String
Text/String

description

radio

N/A

N/A

N/A

vap

N/A

N/A

N/A

client_mac

<dmac>

Text/String

N/A

last_known_client_ip/client_ip

<dip>

IP Address

N/A

aid

N/A

N/A

N/A