Log Fields and Parsing

This section details the log fields available in this log message type, along with values parsed for both LogRhythm Default and LogRhythm Default v2.0 policies. A value of "N/A" (not applicable) means that there is no value parsed for a specified log field.

Log FieldLogRhythm Default

LogRhythm Default v2.0

N/AN/AN/A
Event TypeN/A<vmid>
Event Name<vmid><action>, <tag1>
Message<object><vendorinfo>
User<login><login>

Log Processing Settings

This section details log processing changes made from the LogRhythm Default policy to LogRhythm Default v2.0. In some cases, base rules are broken down into sub-rules to appropriately parse log message types by their event types.

LogRhythm Default

Regex IDRule NameRule TypeCommon EventsClassifications
1008375Policy EditBase RulePolicy Modified : ObjectPolicy

LogRhythm Default v2.0

Regex IDRule NameRule TypeCommon EventsClassifications
1011399
V 2.0 : Cylance Protect : Audit EventBase RuleGeneral Auditing MessageOther Audit
V 2.0 : Cylance Protect : Agent UpdatedSub RuleSoftware UpdatedConfiguration
V 2.0 : Cylance Protect : App AddedSub RuleObject AddedAccess Success
V 2.0 : Cylance Protect : App ModifiedSub RuleObject ModifiedAccess Success
V 2.0 : Cylance Protect : App RemovedSub RuleObject Deleted/RemovedAccess Success
V 2.0 : Cylance Protect : Cert AddedSub RuleObject AddedAccess Success
V 2.0 : Cylance Protect : Cert DeletedSub RuleObject Deleted/RemovedAccess Success
V 2.0 : Cylance Protect : Cert ModifiedSub RuleObject ModifiedAccess Success
V 2.0 : Cylance Protect : Cert Added To Safe ListSub RuleConfiguration Modified : SecurityConfiguration
V 2.0 : Cylance Protect : Cert Rem. From Safe ListSub RuleConfiguration Modified : SecurityConfiguration
V 2.0 : Cylance Protect : Custom Auth DisabledSub RuleConfiguration Modified : SecurityConfiguration
V 2.0 : Cylance Protect : Custom Auth SavedSub RuleConfiguration Modified : SecurityConfiguration
V 2.0 : Cylance Protect : Device AddedSub RuleObject AddedAccess Success
V 2.0 : Cylance Protect : Device ModifiedSub RuleObject ModifiedAccess Success
V 2.0 : Cylance Protect : Device RemovedSub RuleObject Deleted/RemovedAccess Success
V 2.0 : Cylance Protect : Support Login ModifiedSub RuleConfiguration Modified : SecurityConfiguration
V 2.0 : Cylance Protect : File Added To Global LisSub RuleConfiguration Modified : SecurityConfiguration
V 2.0 : Cylance Protect : File Rem. From Global LiSub RuleConfiguration Modified : SecurityConfiguration
V 2.0 : Cylance Protect : User Logon FailureSub RuleUser Logon FailureAuthentication Failure
V 2.0 : Cylance Protect : User Logon SuccessSub RuleUser LogonAuthentication Success
V 2.0 : Cylance Protect : Policy AddedSub RuleObject AddedAccess Success
V 2.0 : Cylance Protect : Policy ModifiedSub RuleObject ModifiedAccess Success
V 2.0 : Cylance Protect : Policy RemovedSub RuleObject Deleted/RemovedAccess Success
V 2.0 : Cylance Protect : File Added To Safe ListSub RuleConfiguration Modified : SecurityConfiguration
V 2.0 : Cylance Protect : File Rem. From Safe ListSub RuleConfiguration Modified : SecurityConfiguration
V 2.0 : Cylance Protect : Script Added To Safe LisSub RuleConfiguration Modified : SecurityConfiguration
V 2.0 : Cylance Protect : Script Rem. From Safe LiSub RuleConfiguration Modified : SecurityConfiguration
V 2.0 : Cylance Protect : Syslog DisabledSub RuleConfiguration Modified : SecurityConfiguration
V 2.0 : Cylance Protect : Syslog Settings ModifiedSub RuleConfiguration Modified : SecurityConfiguration
V 2.0 : Cylance Protect : File Added To QuarantineSub RuleConfiguration Modified : SecurityConfiguration
V 2.0 : Cylance Protect : User Quarantined FileSub RuleQuarantined MessageFailed Activity
V 2.0 : Cylance Protect : File Added To Safe ListSub RuleConfiguration Modified : SecurityConfiguration
V 2.0 : Cylance Protect : User Waived File ThreatSub RuleGeneral SecurityOther Security
V 2.0 : Cylance Protect : User Account CreatedSub RuleUser Account CreatedAccount Created
V 2.0 : Cylance Protect : User Account ModifiedSub RuleUser Account Attribute ModifiedAccount Modified
V 2.0 : Cylance Protect : User Account RemovedSub RuleUser Account DeletedAccount Deleted
V 2.0 : Cylance Protect : Zone AddedSub RuleObject AddedAccess Success
V 2.0 : Cylance Protect : Device Added To ZoneSub RuleConfiguration Modified : SecurityConfiguration
V 2.0 : Cylance Protect : Zone ModifiedSub RuleObject ModifiedAccess Success
V 2.0 : Cylance Protect : Zone RemovedSub RuleProductionObject Deleted/Removed
V 2.0 : Cylance Protect : Device Removed From ZoneSub RuleProductionConfiguration Modified : Security
V 2.0 : Cylance Protect : Zone Rule AddedSub RuleProductionObject Added
V 2.0 : Cylance Protect : Zone Rule ModifiedSub RuleProductionObject Modified
V 2.0 : Cylance Protect : Zone Rule RemovedSub RuleProductionObject Deleted/Removed