Log Fields and Parsing
This section details the log fields available in this log message type, along with values parsed for both LogRhythm Default and LogRhythm Default v2.0 policies. A value of "N/A" (not applicable) means that there is no value parsed for a specified log field.
Log Field | LogRhythm Default | LogRhythm Default v2.0
|
---|
N/A | <severity> | N/A |
Device Name | <dname> | <dname> |
Event Name | <vmid> | <action>, <tag1> |
Event Type | N/A | <vmid> |
External Device Type | <group> | <object> |
External Device Name | <objectname> | <objectname> |
External Device Product ID | N/A | N/A |
External Device Serial Number | <object> | <serialnumber> |
External Device Vendor ID | N/A | N/A |
Zone Names | <subject> | N/A |
Log Processing Settings
This section details log processing changes made from the LogRhythm Default policy to LogRhythm Default v2.0. In some cases, base rules are broken down into sub-rules to appropriately parse log message types by their event types.
LogRhythm Default
Regex ID | Rule Name | Rule Type | Common Events | Classifications |
---|
1009046
| USB Device Blocked | Base Rule | Device Blocked | Warning |
Device Fully Accessible | Sub Rule | Access Granted Activity | Access Granted |
Device Access Blocked | Sub Rule | Access Blocked | Information |
LogRhythm Default v2.0
Regex ID | Rule Name | Rule Type | Common Events | Classifications |
---|
1011403 | V 2.0 : Cylance Protect : Device Control Events | Base Rule | General Antivirus Information | Information |
V 2.0 : Cylance Protect : Device Blocked | Sub Rule | Storage Device Detected | Activity |
V 2.0 : Cylance Protect : Device Allowed | Sub Rule | Threat Blocked | Failed Activity |