Watchlist Hit Alert : Feed Search Binary

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

Watchlist Hit Alert : Feed Search Binary

Base Rule

Watchlist Hit

Activity

Watchlist Feed Hit Alert : Unisigned Binary

Sub Rule

Watchlist Hit

Activity

Watchlist Feed Hit Alert : Signed Binary

Sub Rule

Watchlist Hit

Activity

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

N/A

<vmid>

Text/String

alert_severity

<severity>

Number

digsig_publisher/issuer

<subject>

Text/String

digsig_result

<result>

<tag1>

Text/String

feed_name

<sender>

Text/String

hostname

<dname>

Text/String

md5

<objectname>

<hash>

Text/String

observed_filename

<process>

Text/String

observed_filename_total_count

<quantity>

Number

status

<status>

Text/String