Watchlist Hit : Storage Process

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

Watchlist Hit : Storage Process

Base Rule

Watchlist Hit

Activity

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

cb_version

<version>

Number

host_type

<useragent>

Text/String

parent_name

<parentprocessname>

Text/String

parent_id

<parentprocessid>

Number

path

<process>

Text/String

process_md5

<objectname>

Text/String

process_md5

<hash>

Text/String

process_name

<object>

Text/String

process_pid

<processid>

Number

server_name

<sname>

Text/String

type

<objecttype>

Text/String

watchlist_name

<vmid>

Text/String