Skip to main content
Skip table of contents

VPN & Firewall

Vendor Documentation

Classification

Rule NameRule TypeCommon EventClassification
VPN & FirewallBase RuleGeneral Firewall LogNetwork Traffic
VPN & Firewall : Traffic RedirectedSub RuleTraffic RedirectedNetwork Traffic
VPN & Firewall : Traffic EncryptedSub RuleEncrypt PacketNetwork Traffic
VPN & Firewall : Traffic DecryptedSub RuleDecrypted PacketNetwork Traffic
VPN & Firewall : Traffic RejectedSub RuleTraffic Denied by Network FirewallNetwork Deny
VPN & Firewall : Traffic DroppedSub RuleTraffic Denied by Host FirewallNetwork Deny
VPN & Firewall : Traffic AcceptedSub RuleTraffic Allowed by Network FirewallNetwork Allow
VPN & Firewall : Traffic BlockedSub RuleTraffic Denied by Network FirewallNetwork Deny
VPN & Firewall : Traffic AllowedSub RuleTraffic Allowed by Network FirewallNetwork Allow

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

Product<version>Number/Text
Origin<sender>Number/Text
Action<action>Number/Text
Action<tag1>Number/Text
SIP<sip>Number
SPort<sport>Number
DIP<dip>Number
DPort<dport>Number
Protocol<protnum>Number
Protocol<protname>Number/Text
IFName<sinterface>Number/Text
IFDirection<tag2>Number/Text
Reason<reason>Number/Text
Rule<command>Number/Text
Info<vendorinfo>Number/Text
XlateSIP<snatip>Number/Text
XlateSport<snatport>Number/Text
XlateDIP<dnatip>Number/Text
XlateDPort<dnatport>Number/Text
user<login>Number/Text
matched_category<subject>Number/Text
rule_name<command>Number/Text
PolicyName<policy>Number/Text
Service<process>Number/Text
State<status>Text/String


JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.