Watchlist Hit Alert : Binary Ingress

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

Watchlist Hit Alert : Binary Ingress

Base Rule

Watchlist Hit

Activity

Watchlist Hit Alert : Signed Binary Ingress

Sub Rule

Watchlist Hit

Activity

Watchlist Hit Alert : Unsigned Binary Ingress

Sub Rule

Watchlist Hit

Activity

Mapping with LogRhythm Schema

Device Key in log message

LogRhythm Schema

Data Type

alert_severity

<severity>

Number

digsig_publisher/issuer

<subject>

Text/String

digsig_result

<result>

Text/String

digsig_result

<tag1>

Text/String

feed_name

<sender>

Text/String

hostname

<dname>

Text/String

md5

<objectname>

Text/String

md5

<hash>

Text/String

observed_filename

<process>

Text/String

observed_filename_total_count

<quantity>

Number

status

<status>

Text/String