User Logon
Field |
Description |
---|---|
Auth type password |
Indicates password authentication |
Auth type pubkey |
Indicates key based authentication |
Type login ssh |
Indicates that a user logged in via ssh |
Type login win batch |
Indicates windows batch login (Type 4, eg schtasks) |
Type login win cached |
Indicates logon via cached credentials (Type 11, CachedIntetractive) |
Type login win interactive |
Indicates interactive logon (Type 2, eg RDP) |
Type login win network cleartext |
Indicates logon via ssh (Type 8) |
Type login win network |
Indicates network login (Type 3, eg Psexec) |
Type login win new cred |
Indicates the usage of new credentials (Type 9, eg Runas command) |
Type login win remote interactive |
Indicates remote logon (Type 10, eg RDP) |
Type login win service |
Indicates that a service was started by SCM (Type 5) |
Type login win unlock |
Indicates that the workstation was unlocked (Type 7) |
Src IP |
The source IP from which the login event was generated |
Src Port |
The source port from which the login event was generated |
Username |
Username associated with the log in event |