Skip to main content
Skip table of contents

Watchlist Hit Alert: Query Process

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification
Watchlist Hit Alert: Query ProcessBase RuleWatchlist HitActivity
Watchlist Hit Alert: Query Process: UnresolvedSub RuleWatchlist HitActivity
Watchlist Hit Alert: Query Process: ResolvedSub RuleWatchlist HitActivity

Mapping with LogRhythm Schema

Device Key in Log MessageLogRhythm SchemaData Type
N/A<vmid>Text/String
hostname<dname>Text/String
interface_ip<sip>IP Address
md5

<objectname>

<hash>

Text/String
process_name<process>Text/String
status

<status>

<tag1>

Text/String
username<account>Text/String



JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.