Watchlist Hit Alert : Host Ingress

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

Watchlist Hit Alert : Host Ingress

Base Rule

Watchlist Hit

Activity

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

alert_severity

<severity>

Number

feed_name

<sender>

Text/String

group

<group>

Text/String

hostname

<dname>

Text/String

status

<status>

Text/String

watchlist_name

<vmid>

Text/String