V 2.0 : Zero Phishing Events

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

V 2.0 : Zero Phishing Events

Base Rule

General Threat Message

Activity

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

Schema Description

virtuallogsource

N/A

N/A

N/A

subproduct

N/A

N/A

N/A

Product

<vmid>

Text/String

Product name

Originip

N/A

N/A

IP of the log origin 

origin

N/A

N/A

Name of the first Security Gateway that reported this event

Action

<action>

Text/String

Description of detected malware activity

SIP

<sip>

IP Address

Source IP

SPort

<sport>

Number

Source host port number

DIP

<dip>

IP Address

Destination IP

dport

<dport>

Number

Destination host port number

protocol

<protnum>

Number

Protocol detected on the connection

ifname

<sinterface>

Text/String

The name of the Security Gateway interface through which a connection traverses

ifdirection

N/A

N/A

Connection direction

reason

N/A

N/A

Information on the error occurred

Rule

N/A

N/A

N/A

Info

N/A

N/A

N/A

XlateSIP

N/A

N/A

N/A

XlateSport

N/A

N/A

N/A

XlateDIP

N/A

N/A

N/A

XlateDPort

N/A

N/A

N/A

user

N/A

N/A

Source user name

alert

N/A

N/A

N/A

icmp-code

N/A

N/A

N/A

icmp-type

N/A

N/A

N/A

matched_category

N/A

N/A

N/A

rule_name

N/A

N/A

Access rule name

Url

<url>

Text/String

Matched URL

time

N/A

N/A

The time stamp when the log was created

src_machine_name

<sname>

Text/String

Machine name connected to source IP 

src_user_name

<login>

Text/String

User name connected to source IP 

Confidence_Level

N/A

N/A

Confidence level determined by ThreatCloud
Possible values:
0 - N/A
1 - Low
2 - Medium-Low
3 - Medium
4 - Medium-High
5 - High

Severity

<severity>

Number

Threat severity determined by ThreatCloud
Possible values:
0 - Informational
1 - Low
2 - Medium
3 - High
4 - Critical

web_client_type

<useragent>

Text/String

Web client detected in the HTTP request (e.g., Chrome) 

malware_action

<vendorinfo>

Text/String

Description of detected malware activity 

Protection_name

<threatname>

Text/String

Specific signature name of the attack 

description

<vendorinfo>

Text/String

Additional explanation how the security gateway enforced the connection 

PolicyName

<policy>

Text/String

N/A

Protection_Type

N/A

N/A

Type of protection used to detect the attack 

client_name

N/A

N/A

N/A

generalinformation

<result>

Text/String

N/A

flags

N/A

N/A

Checkpoint internal field

loguid

N/A

N/A

UUID of unified logs  

sequencenum

N/A

N/A

Number added to order logs with the same Linux timestamp and origin

version

N/A

N/A

N/A

client_version

N/A

N/A

N/A

event_type

N/A

N/A

N/A

extension_version

N/A

N/A

N/A

host_type

N/A

N/A

N/A

installed_products

N/A

N/A

N/A

local_time

N/A

N/A

N/A

machine_guid

N/A

N/A

N/A

os_name

N/A

N/A

N/A

os_version

N/A

N/A

N/A

policy_date

N/A

N/A

N/A

policy_number

N/A

N/A

N/A

product_family

N/A

N/A

N/A

trusted_domain

N/A

N/A

N/A

user_name

N/A

N/A

N/A

user_sid

N/A

N/A

N/A