Watchlist Hit Alert : Process Ingress

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

Watchlist Hit Alert : Process Ingress

Base Rule

Watchlist Hit

Activity

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

alert_severity

<severity>

Text/String/Number

feed_name

<sender>

Text/String

group

<group>

Text/String

hostname

<dname>

Text/String

interface_ip

<sip>

IP Address

ioc_type

<objecttype>

Text/String

ioc_value

<domainimpacted>

Text/String

ioc_value

<command>

Text/String

search_query

<command>

Text/String

ioc_value

<dip>

IP Address

ioc_value

<object>

Text/String

ioc_value

<hash>

Text/String

ioc_value

<url>

Text/String

md5

<hash>

Text/String

netconn_count

<quantity>

Number

process_name

<object>

Text/String

process_path

<process>

Text/String

status

<status>

Text/String

username

<domain>

Text/String

username

<login>

Text/String

watchlist_name

<vmid>

Text/String