Web Server Access
Vendor Documentation
Classification
Rule Name | Rule Type | Common Event | Classification |
---|---|---|---|
Web Server Access | Base Rule | Object Accessed | Access Success |
HTTP - GET - 200 : Success Reply - OK | Sub Rule | HTTP 200 : Success Reply - OK | Information |
HTTP GET - 304 Redirect - Not Modified | Sub Rule | HTTP 304 : Redirect - Not Modified | Information |
HTTP GET - 400 - Req Error - Bad Request | Sub Rule | HTTP 400 : Request Error - Bad Request | Error |
HTTP POST - 400 - Req Error - Bad Request | Sub Rule | HTTP 400 : Request Error - Bad Request | Error |
HTTP - 400 - Req Error - Bad Request | Sub Rule | HTTP 400 : Request Error - Bad Request | Error |
HTTP GET - 401 - Req Error - Unauthorized | Sub Rule | HTTP 401 : Request Error - Unauthorized | Error |
HTTP POST - 401 - Req Error - Unauthorized | Sub Rule | HTTP 401 : Request Error - Unauthorized | Error |
HTTP - 401 - Req Error - Unauthorized | Sub Rule | HTTP 401 : Request Error - Unauthorized | Error |
HTTP - 402 - Req Error - Payment Required | Sub Rule | HTTP 402 : Request Error - Payment Required | Error |
HTTP GET - 403 - Req Error - Forbidden | Sub Rule | HTTP 403 : Request Error - Forbidden | Error |
HTTP POST - 403 - Req Error - Forbidden | Sub Rule | HTTP 403 : Request Error - Forbidden | Error |
HTTP - 403 - Req Error - Forbidden | Sub Rule | HTTP 403 : Request Error - Forbidden | Error |
HTTP GET - 404 - Req Error - Not Found | Sub Rule | HTTP 404 : Request Error - Not Found | Error |
HTTP POST - 404 - Req Error - Not Found | Sub Rule | HTTP 404 : Request Error - Not Found | Error |
HTTP - 404 - Req Error - Not Found | Sub Rule | HTTP 404 : Request Error - Not Found | Error |
HTTP POST - 405 - Req Error - Method Not Allowed | Sub Rule | HTTP 405 : Request Error - Method Not Allowed | Error |
HTTP - 405 - Req Error - Method Not Allowed | Sub Rule | HTTP 405 : Request Error - Method Not Allowed | Error |
HTTP GET - 500 - Svr Error - Internal Server Error | Sub Rule | HTTP 500 : Server Error - Internal Server Error | Error |
HTTP POST- 500 - Svr Error - Internal Server Error | Sub Rule | HTTP 500 : Server Error - Internal Server Error | Error |
HTTP - 500 - Svr Error - Internal Server Error | Sub Rule | HTTP 500 : Server Error - Internal Server Error | Error |
HTTP - 502 - Svr Error - Bad Gateway | Sub Rule | HTTP 502 : Server Error - Bad Gateway | Error |
HTTP - 502 - Svr Error - Bad Gateway | Sub Rule | HTTP 502 : Server Error - Bad Gateway | Error |
HTTP GET - 503 - Svr Error - Service Unavailable | Sub Rule | HTTP 503 : Server Error - Service Unavailable | Error |
HTTP POST - 503 - Svr Error - Service Unavailable | Sub Rule | HTTP 503 : Server Error - Service Unavailable | Error |
HTTP - 503 - Svr Error - Service Unavailable | Sub Rule | HTTP 503 : Server Error - Service Unavailable | Error |
Remote Procedure Call Over HTTP : OUT | Sub Rule | Remote Procedure Call Attempt | Network Traffic |
Remote Procedure Call Over HTTP : IN | Sub Rule | Remote Procedure Call Attempt | Network Traffic |
PROPFIND Method | Sub Rule | Object Accessed | Access Success |
HEAD Method | Sub Rule | Object Accessed | Access Success |
File Post | Sub Rule | Object Added | Access Success |
File Download | Sub Rule | Object Downloaded | Access Success |
Mapping with LogRhythm Schema
Device Key in Log Message | LogRhythm Schema | Data Type |
---|---|---|
N/A | <dip> | Number |
N/A | <tag1> | Text/String |
N/A | <command> | Text/String |
N/A | <url> | Text/String |
N/A | <dport> | Number |
N/A | <domain> | Text/String |
N/A | <login> | Number/Text |
N/A | <snatip> | Number |
N/A | <useragent> | Number/Text |
N/A | <object> | Number/Text |
N/A | <sender> | Number/Text |
N/A | <responsecode> | Number |
N/A | <vmid> | Number |
N/A | <milliseconds> | Number |
N/A | <bytesin> | Number |
N/A | <bytesout> | Number |
N/A | <sinterface> | Number |
N/A | <sip> | Number |