Log Fields and Parsing

This section details the log fields available in this log message type, along with values parsed for both LogRhythm Default and LogRhythm Default v2.0 policies. A value of "N/A" (not applicable) means that there is no value parsed for a specified log field.

Log Field

LogRhythm Default

LogRhythm Default v2.0

N/AN/A<vmid>
N/A<severity><severity>
N/A<sip><sip>
N/A<sname>N/A
N/A<dip>N/A
N/AN/A<dname>
N/A<login><login>
N/A<domainorigin>N/A
N/A<object>N/A
N/AN/A <vendorinfo>
N/A<subject><subject>
N/A<version>N/A
N/A<reason><reason>
N/A<tag1><tag1>
N/A<tag5>N/A

Log Processing Settings

This section details log processing changes made from the LogRhythm Default policy to LogRhythm Default v2.0. In some cases, base rules are broken down into sub-rules to appropriately parse log message types by their event types.

LogRhythm Default

Regex ID

Rule Name

Rule Type

Common Events

Classifications

1001606

















SSL VPN & GlobalProtect EventsBase RuleGeneral Audit MessageOther Audit
GlobalProtect : Gateway Config SuccessSub RuleConfiguration SuccessfulInformation
GlobalProtect : Client SSL Tunnel SuccessSub RuleObject CreatedAccess Success
GlobalProtect : Client Config GeneratedSub RuleObject CreatedAccess Success
GlobalProtect : Gateway Regist FailureSub RuleRegistration FailureError
SSL VPN User Authentication SucceededSub RuleUser LogonAuthentication Success
SSL VPN User Login SucceededSub RuleUser LogonAuthentication Success
GlobalProtect : User Authentication SuccessSub RuleUser LogonAuthentication Success
GlobalProtect : Gateway User LoginSub RuleUser LogonAuthentication Success
GlobalProtect : Gateway User Auth SuccessSub RuleUser LogonAuthentication Success
SSL VPN User Logout SucceededSub RuleUser LogoffAuthentication Success
GlobalProtect : Gateway Client Config ReleasedSub RuleUser LogoffAuthentication Success
GlobalProtect : User LogoutSub RuleUser LogoffAuthentication Success
GlobalProtectportal-Auth-FailSub RuleUser Logon FailureAuthentication Failure
GlobalProtectGateway-Auth-FailSub RuleUser Logon FailureAuthentication Failure
SSL VPN Client Switch To SSL Tunnel SucceededSub RuleTrust Relationship EstablishedAccess Granted
SSL VPN Client Configuration GeneratedSub RuleConfiguration Loaded : SystemConfiguration
GlobalProtect : Gateway Config FailureSub RuleConfiguration FailureCritical
SSL VPN Client Configuration ReleasedSub RuleEnd ConfigurationInformation

LogRhythm Default v2.0 

Regex IDRule NameRule TypeCommon EventsClassifications
1010870

V 2.0 General GlobalProtect Messages

Base Rule

General VPN Information

Other Operations
V 2.0 GlobalProtect Gateway : Remote Logon FailureSub RuleUser Logon Failure
V 2.0 GlobalProtect Portal : Remote Logon FailureSub RuleUser Logon FailureAuthentication Failure
V 2.0 GlobalProtect Gateway : Remote Logon SuccessSub RuleUser LogonAuthentication Success
V 2.0 GlobalProtect Portal : Remote Logon SuccessSub RuleUser LogonAuthentication Success