Skip to main content
Skip table of contents

V 2.0 : Zero Phishing Events

Vendor Documentation

Classification

Rule NameRule TypeCommon EventClassification
V 2.0 : Zero Phishing EventsBase RuleGeneral Threat MessageActivity

Mapping with LogRhythm Schema

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
virtuallogsourceN/AN/AN/A
subproductN/AN/AN/A
Product<vmid>Text/StringProduct name
OriginipN/AN/AIP of the log origin 
originN/AN/AName of the first Security Gateway that reported this event
Action<action>Text/StringDescription of detected malware activity
SIP<sip>IP AddressSource IP
SPort<sport>NumberSource host port number
DIP<dip>IP AddressDestination IP
dport<dport>NumberDestination host port number
protocol<protnum>NumberProtocol detected on the connection
ifname<sinterface>Text/StringThe name of the Security Gateway interface through which a connection traverses
ifdirectionN/AN/AConnection direction
reasonN/AN/AInformation on the error occurred
RuleN/AN/AN/A
InfoN/AN/AN/A
XlateSIPN/AN/AN/A
XlateSportN/AN/AN/A
XlateDIPN/AN/AN/A
XlateDPortN/AN/AN/A
userN/AN/ASource user name
alertN/AN/AN/A
icmp-codeN/AN/AN/A
icmp-typeN/AN/AN/A
matched_categoryN/AN/AN/A
rule_nameN/AN/AAccess rule name
Url<url>Text/StringMatched URL
timeN/AN/AThe time stamp when the log was created
src_machine_name<sname>Text/StringMachine name connected to source IP 
src_user_name<login>Text/StringUser name connected to source IP 
Confidence_LevelN/AN/AConfidence level determined by ThreatCloud
Possible values:
0 - N/A
1 - Low
2 - Medium-Low
3 - Medium
4 - Medium-High
5 - High
Severity<severity>NumberThreat severity determined by ThreatCloud
Possible values:
0 - Informational
1 - Low
2 - Medium
3 - High
4 - Critical
web_client_type<useragent>Text/StringWeb client detected in the HTTP request (e.g., Chrome) 
malware_action<vendorinfo>Text/StringDescription of detected malware activity 
Protection_name<threatname>Text/StringSpecific signature name of the attack 
description<vendorinfo>Text/StringAdditional explanation how the security gateway enforced the connection 
PolicyName<policy>Text/StringN/A
Protection_TypeN/AN/AType of protection used to detect the attack 
client_nameN/AN/AN/A
generalinformation<result>Text/StringN/A
flagsN/AN/ACheckpoint internal field
loguidN/AN/AUUID of unified logs  
sequencenumN/AN/ANumber added to order logs with the same Linux timestamp and origin
versionN/AN/AN/A
client_versionN/AN/AN/A
event_typeN/AN/AN/A
extension_versionN/AN/AN/A
host_typeN/AN/AN/A
installed_productsN/AN/AN/A
local_timeN/AN/AN/A
machine_guidN/AN/AN/A
os_nameN/AN/AN/A
os_versionN/AN/AN/A
policy_dateN/AN/AN/A
policy_numberN/AN/AN/A
product_familyN/AN/AN/A
trusted_domainN/AN/AN/A
user_nameN/AN/AN/A
user_sidN/AN/AN/A
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.