Skip to main content
Skip table of contents

Watchlist Hit Alert : Feed Search Binary

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification
Watchlist Hit Alert : Feed Search BinaryBase RuleWatchlist HitActivity
Watchlist Feed Hit Alert : Unisigned BinarySub RuleWatchlist HitActivity
Watchlist Feed Hit Alert : Signed BinarySub RuleWatchlist HitActivity

Mapping with LogRhythm Schema

Device Key in Log MessageLogRhythm SchemaData Type
N/A<vmid>Text/String
alert_severity<severity>Number
digsig_publisher/issuer

<subject>

Text/String
digsig_result

<result>

<tag1>

Text/String
feed_name

<sender>

Text/String
hostname<dname>Text/String
md5

<objectname>

<hash>

Text/String
observed_filename<process>Text/String
observed_filename_total_count<quantity>Number
status<status>Text/String



JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.