Log Fields and Parsing

This section details the log fields available in this log message type, along with values parsed for both LogRhythm Default and LogRhythm Default v2.0 policies. A value of "N/A" (not applicable) means that there is no value parsed for a specified log field.

Log Field

LogRhythm Default

LogRhythm Default v2.0

N/AN/A<vmid>
N/A<severity><severity>
N/AN/A<vendorinfo>
N/A<tag1><tag1>
N/AN/A<subject>
N/A<result>N/A
N/A<dname>N/A
N/A<reason>N/A
N/A<dip>N/A

Log Processing Settings

This section details log processing changes made from the LogRhythm Default policy to LogRhythm Default v2.0. In some cases, base rules are broken down into sub-rules to appropriately parse log message types by their event types.

LogRhythm Default

Regex IDRule NameRule TypeCommon EventsClassifications
1004488User Connection InformationBase RuleConnection EstablishedNetwork Traffic
Success - connect-server-monitorSub RuleConnection EstablishedNetwork Traffic
Failure - connect-server-monitor-failureSub RuleConnection FailedNetwork Traffic

LogRhythm Default v2.0

Regex ID

Rule Name

Rule Type

Common Events

Classifications

1010859V 2.0 General User Profile System MessagesBase RuleGeneral System Message

Information