Skip to main content
Skip table of contents

NEI 08-09 Rev 6 – Reports

The following table provides a listing of all reports included in this compliance package. For each report, the targeted data source, the required classifications, and the required Log Source Lists are provided. If you are unable to implement the Data Management Settings, this table should be referred to so as to understand which reports will be impacted.

Reports with a data source of Log Manager will not populate in a fully collection-optimized deployment. Contact LogRhythm Support for additional details.

Report ID

Report Name

Data Source

Intelligent Indexing

Required Classifications

Required Log Source Lists

437

NEI: Account Lockout Summary

Log Mart

No

Account Modified, Access Revoked,

NEI: Production Servers, NEI: Workstations, NEI: Wireless Access Points, NEI: Remote Access Systems, NEI: Network Access Control Systems, NEI: Security Systems

438

NEI: Account Management Activity

Log Mart

No

Account Created, Account Deleted, Account Modified

NEI: Production Servers, NEI: Workstations, NEI: Wireless Access Points, NEI: Network Access Control Systems

439

NEI: Attacks Detected

Log Mart

No

Attack, Compromise, Denial of Service

NEI: Production Servers, NEI: Workstations, NEI: Network Access Control Systems, NEI: Security Systems

440

NEI: Audit Failure By Host

Log Mart

No

Access Failure, Authentication Failure, Other Audit Failure

NEI: Production Servers, NEI: Workstations, NEI: Wireless Access Points, NEI: Remote Access Systems, NEI: Network Access Control Systems

441

NEI: Audit Failure By User

Log Manager

Yes

Access Failure, Authentication Failure, Other Audit Failure

NEI: Production Servers, NEI: Workstations, NEI: Wireless Access Points, NEI: Remote Access Systems, NEI: Network Access Control Systems

442

NEI:

Compromises Detected

Log Mart

No

Compromise

NEI: Production Servers, NEI: Workstations, NEI: Network Access Control Systems, NEI: Security Systems

443

NEI:

Configuration Change Summary

Log Manager

Yes

Configuration

NEI: Production Servers, NEI: Workstations, NEI: Wireless Access Points, NEI: Remote Access Systems, NEI: Network Access Control Systems, NEI: Security Systems

444

NEI: Disabled Accounts

Log Mart

No

Account Modified, Access Revoked,

NEI: Production Servers, NEI: Workstations, NEI: Network Access Control Systems

445

NEI: Door Access Summary

Log Manager

Yes

Access Success, Authentication Success, Compromise

NEI: Security Systems

446

NEI: Failed Application Access

Log Mart

No

Access Failure, Authentication Failure

NEI: Production Servers, NEI: Workstations

447

NEI: Failed File Access

Log Manager

Yes

Access Failure

NEI: Production Servers, NEI: Workstations

448

NEI: Failed Host Access

Log Mart

No

Authentication Failure

NEI: Production Servers, NEI: Workstations, NEI: Wireless Access Points, NEI: Remote Access Systems, NEI: Network Access Control Systems, NEI: Security Systems

449

NEI: File Integrity Monitor Log Detail

Log Manager

No

Activity

NEI: File Integrity Monitoring Systems

450

NEI: File Integrity Monitor Log Detail

Log Manager

No

Activity

NEI: File Integrity Monitoring Systems

451

NEI: File Integrity Monitor Summary

Log Manager

No

Activity

NEI: File Integrity Monitoring Systems

452

NEI: Host Access Granted And Revoked

Log Mart

No

Access Granted, Access Revoked

NEI: Production Servers, NEI: Workstations, NEI: Network Access Control Systems

453

NEI: Host Authentication Summary

Log Mart

No

Authentication Success

NEI: Production Servers, NEI: Workstations, NEI: Network Access Control Systems

454

NEI: Network Connection Summary

Log Manager

No

Network Allow, Network Deny, Network Traffic

NEI: Network Access Control Systems

455

NEI: Network Service Summary

Log Manager

No

Network Allow, Network Deny, Network Traffic

NEI: Network Access Control Systems

456

NEI: New

Account Summary

Log Mart

No

Account Created

NEI: Production Servers, NEI: Workstations, NEI: Network Access Control Systems

457

NEI: Object Access Summary

Log Manager

No

Access Success

NEI: Production Servers

458

NEI: Policy Activity Summary

Log Mart

No

Access Granted, Access Revoked, Policy

NEI: Production Servers, NEI: Workstations, NEI: Wireless Access Points, NEI: Remote Access Systems, NEI: Network Access Control Systems, NEI: Security Systems

459

NEI: Processes By User

Log Manager

No

Startup and Shutdown

NEI: Production Servers, NEI: Workstations

460

NEI: Security Event Summary

Log Mart

No

Attack, Compromise, Denial of Service, Malware, Reconnaissance, Suspicious

NEI: Data Loss Prevention Systems, NEI: Network Access Control Systems, NEI: Security Systems, NEI: Production Servers, NEI: Workstations, NEI: Wireless Access Points, NEI: Remote Access Systems, NEI: File Integrity Monitoring Systems

461

NEI: Security Event Summary

Log Mart

No

Attack, Compromise, Denial of Service, Malware, Reconnaissance, Suspicious

NEI: Data Loss Prevention Systems, NEI: Network Access Control Systems, NEI: Security Systems, NEI: Production Servers, NEI: Workstations, NEI: Wireless Access Points, NEI: Remote Access Systems, NEI: File Integrity Monitoring Systems

462

NEI: Security Event Summary

Log Mart

No

Attack, Compromise, Denial of Service, Malware, Reconnaissance, Suspicious

NEI: Data Loss Prevention Systems, NEI: Network Access Control Systems, NEI: Security Systems, NEI: Production Servers, NEI: Workstations, NEI: Wireless Access Points, NEI: Remote Access Systems, NEI: File Integrity Monitoring Systems

463

NEI: Security Event Summary

Log Mart

No

Attack, Compromise, Denial of Service, Malware, Reconnaissance, Suspicious

NEI: Data Loss Prevention Systems, NEI: Network Access Control Systems, NEI: Security Systems, NEI: Production Servers, NEI: Workstations, NEI: Wireless Access Points, NEI: Remote Access Systems, NEI: File Integrity Monitoring Systems

464

NEI: Suspicious Activity By Host

Log Mart

No

Suspicious

NEI: Data Loss Prevention Systems, NEI: Network Access Control Systems, NEI: Security Systems, NEI: Production Servers, NEI: Workstations, NEI: Wireless Access Points, NEI: Remote Access Systems, NEI: File Integrity Monitoring Systems

465

NEI: Suspicious Activity By User

Log Mart

No

Suspicious

NEI: Data Loss Prevention Systems, NEI: Network Access Control Systems, NEI: Security Systems, NEI: Production Servers, NEI: Workstations, NEI: Wireless Access Points, NEI: Remote Access Systems, NEI: File Integrity Monitoring Systems

466

NEI: Terminated Account Summary

Log Mart

No

Account Deleted

NEI: Production Servers, NEI: Workstations, NEI: Network Access Control Systems

467

NEI: Top

Attackers

Log Mart

No

Attack, Compromise, Denial of Service, Failed Attack, Failed Denial of Service, Failed Malware, Failed Suspicious, Malware, Reconnaissance, Suspicious

NEI: Production Servers, NEI: Workstations, NEI: Wireless Access Points, NEI: Remote Access Systems, NEI: Network Access Control Systems, NEI: Security Systems

468

NEI: Top

Suspicious Users

Log Manager

Yes

Access Failure, Activity, Attack, Authentication Failure, Compromise, Denial of Service, Failed Activity, Failed Denial of Service, Failed Malware, Failed Misuse, Failed Suspicious, Malware, Misuse, Other Audit Failure, Reconnaissance, Suspicious

NEI: Production Servers, NEI: Workstations, NEI: Wireless Access Points, NEI: Remote Access Systems, NEI: Network Access Control Systems, NEI: Security Systems

469

NEI: Top

Targeted Applications

Log Mart

No

Attack, Compromise, Denial of Service, Failed Attack, Failed Denial of Service, Failed Malware, Failed Suspicious, Malware, Reconnaissance, Suspicious

NEI: Production Servers, NEI: Workstations, NEI: Network Access Control Systems, NEI: Security Systems

470

NEI: Top

Targeted Hosts

Log Mart

No

Attack, Compromise, Denial of Service, Failed Attack, Failed Denial of Service, Failed Malware, Failed Suspicious, Malware, Reconnaissance, Suspicious

NEI: Production Servers, NEI: Workstations, NEI: Network Access Control Systems, NEI: Security Systems

471

NEI: Usage Auditing Event Detail

Event Manager

N/A

N/A

NEI: Data Loss Prevention Systems, NEI: Network Access Control Systems, NEI: Security Systems, NEI: Production Servers, NEI: Workstations, NEI: Wireless Access Points, NEI: Remote Access Systems, NEI: File Integrity Monitoring Systems

472

NEI: Usage Auditing Event Detail

Event Manager

N/A

N/A

NEI: Data Loss Prevention Systems, NEI: Network Access Control Systems, NEI: Security Systems, NEI: Production Servers, NEI: Workstations, NEI: Wireless Access Points, NEI: Remote Access Systems, NEI: File Integrity Monitoring Systems

473

NEI: User Authentication Summary

Log Mart

No

Authentication Failure, Authentication Success

NEI: Production Servers, NEI: Workstations, NEI: Wireless Access Points, NEI: Remote Access Systems, NEI: Network Access Control Systems

474

NEI: User Misuse Summary

Log Manager

Yes

Misuse

NEI: Production Servers, NEI: Workstations, NEI: Wireless Access Points, NEI: Remote Access Systems, NEI: Data Loss Prevention Systems, NEI: Network Access Control Systems, NEI: Security Systems

475

NEI: User Object Access Summary

Log Manager

No

Access Success

NEI: Production Servers, NEI: Workstations

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.