Skip to main content
Skip table of contents

WebFilter Traffic

Vendor Documentation

Classification

Rule NameRule TypeCommon EventClassification
WebFilter TrafficBase RuleGeneral WebFilter EventInformation
EVID 12547 : Webfilter Invalid HostnameSub RuleUnknown HostnameWarning
EVID 12801 : Webfilter ErrorSub RuleUnknown HostnameWarning
EVID 13317 : Web Filter AllowedSub RuleTraffic Allowed by Network FirewallNetwork Allow
EVID 13312 : Web Filter AllowedSub RuleTraffic Allowed by Network FirewallNetwork Allow
EVID 12544 : URL Was BlockedSub RuleTraffic Denied by ProxyNetwork Deny
EVID 13057 : Web Filter BlockedSub RuleTraffic Denied by Network FirewallNetwork Deny
EVID 13056 : Web Filter BlockedSub RuleTraffic Denied by Network FirewallNetwork Deny

Mapping with LogRhythm Schema  

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
logid<vmid>NumberThe ID (logid) is a 10-digit field. It is a unique identifier for that specific log.
msg<vendorinfo>Text\StringN/A
level<severity>Text\StringEach log entry contains a Level (level) field that indicates the estimated severity of the event that caused the log entry.
srcip<sip>IP AddressIP address of the traffic’s origin.
dstip<dip>IP AddressDestination IP address for the web.
srcport<sport>NumberPort number of the traffic's origin
dstport<dport>NumberPort number of the traffic's destination.
srcintf<sinterface>Text\StringInterface name of the traffic's origin.
dstintf<dinterface>Text\StringInterface of the traffic's destination.
proto<protnum>NumberThe protocol used by web traffic (tcp by default).
service<protname>Text\StringName of the service.
user<login>Text\StringN/A
vd<domainorigin>Text\StringN/A
sessionid<session>NumberN/A
msg<object>Text\StringN/A
catdesc<subject>Text\StringN/A
url<url>Text\StringN/A
profile<group>Text\StringN/A
action<action>Text\StringN/A
eventtype<result>Text\StringN/A
method<reason>Text\StringN/A
rcvdbyte<bytesin>NumberN/A
sentbyte<bytesout>NumberN/A
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.