Skip to main content
Skip table of contents

Administrative And Operational Audit

Vendor Documentation

Log Fields and Parsing

This section details the log fields available in this log message type, along with values parsed for both LogRhythm Default and LogRhythm Default v2.0 policies. A value of "N/A" (not applicable) means that there is no value parsed for a specified log field.

Log FieldLogRhythm DefaultLogRhythm Default v2.0
pri_numN/AN/A
timeN/AN/A
IP address/hostnameN/AN/A
cat_nameN/A<vendorinfo>
msg_idN/AN/A
total_segN/AN/A
seg_numN/AN/A
timestampN/AN/A
sequence_numN/AN/A
msg_code<vmid><vmid>
<tag1>
msg_sev<severity><severity>
msg_class<subject>
<process>
<subject> 
msg_text<status>
<tag1>
<action> 
ConfigVersionId<version><version>
ConnectionStatus<subject><status>
adminInterface<sinterface>N/A
adminIPAddress<sip><sip>
adminSession<session><session>
adminName<login><login>
UserName<login><login>
<domainorigin>
FailureReason<reason><reason>
ShutdownReason<reason><reason>
ObjectTypeN/A<objecttype>
ObjectName<objectname><object>
OperationMessageText

<subject>

<sip>

<sport>

<dip>

<result>
acsinstance<object>N/A
FeedServicePortN/A<sport>
PortNumberN/A<sport>
FeedServiceHostN/A<sname>
FeedUrlN/A<url>
AccountNameN/A<account>
ISELocalAddress<sip>
<sport>
N/A
ISEModuleName<objectname>N/A
ISEServiceName<object>N/A
PeerAddress<smacN/A
PeerName<login>N/A
Key1N/AN/A
Key2N/AN/A

Log Processing Settings

This section details log processing changes made from the LogRhythm Default policy to LogRhythm Default v2.0. In some cases, base rules are broken down into sub-rules to appropriately parse log message types by their event types.

LogRhythm Default

Regex ID

Rule Name

Rule Type

Common Event

Classification

1010149Administrative And Operational AuditBase RuleGeneral AuditOther Audit Success
Administrator Authentication FailedSub RuleAuthentication Failure ActivityAuthentication Failure
A Malformed SSH Requested Has Been DetectedSub RuleFailed to Establish SSH SessionWarning
An Attempted SSH Connection Has FailedSub RuleFailed to Establish SSH SessionWarning
A SSH CLI User Has Attempted Unsuccessfully LoginSub RuleDenied SSH SessionWarning
Shutdown Secure Connection With TLS PeerSub RuleConnection TerminatedNetwork Traffic
Open Secure Connection With TLS PeerSub RuleConnection EstablishedNetwork Traffic
Administrator Authentication SucceededSub RuleAuthentication ActivityAuthentication Success

LogRhythm Default v2.0

Regex IDRule NameRule TypeCommon EventClassification
1012850V 2.0 Admin And Operational Audit EventBase RuleGeneral Administration EventOther Audit
V 2.0 EVID 51000: Admin Authentication FailureSub RuleAuthentication Failure ActivityAuthentication Failure
V 2.0 EVID 51001: Admin Authentication SuccessSub RuleAuthentication ActivityAuthentication Success
V 2.0 EVID 51002: Admin Logged OffSub RuleLogin Or Logout Event ExecutedOther Audit
V 2.0 EVID 51003: Session TimeoutSub RuleSession TimeoutWarning
V 2.0 EVID 51004: Rejected Admin SessionSub RuleFailed Unauthorized ActivityFailed Misuse
V 2.0 EVID 51005: Admin Account DisabledSub RuleAuthentication Provisioning FailedWarning
V 2.0 EVID 51006: Inactivity Admin Acct DisabledSub RuleAccount DisabledAccess Revoked
V 2.0 EVID 51007: Password ExpirationSub RuleLOGIN_PASSWORD_EXPIREDInformation
V 2.0 EVID 51008: Excessive Failed Auth AttemptsSub RuleAccount Passwords DisabledWarning
V 2.0 EVID 51009: ISE Runtime Is Not RunningSub RuleAuthentication Failure ActivityAuthentication Failure
V 2.0 EVID 51020: Login Username Does Not ExistSub RuleUser Logon Failure: Bad UsernameAuthentication Failure
V 2.0 EVID 51021: Invalid PasswordSub RuleInfo: LOGIN_FAILED_INCORRECT_PASSWORDInformation
V 2.0 EVID 51022: System ErrorSub RuleGeneral System Error WarningWarning
V 2.0 EVID 51023: Administrator Account UnlockedSub RuleAccount UnlockedAccess Granted
V 2.0 EVID 51100: Password Changed SuccessSub RulePerforming Password ChangeInformation
V 2.0 EVID 51101: Invalid New PW - PW Too ShortSub RulePassword Too ShortError
V 2.0 EVID 51102: Invalid New PW - Repeating CharSub RulePassword Change FailedError
V 2.0 EVID 51103: Invalid New PW- Missing Req CharSub RulePassword Change FailedError
V 2.0 EVID 51104: Invalid New PW - Contains U/NSub RulePassword Change FailedError
V 2.0 EVID 51105: Invalid New PW- Contain Res WordSub RulePassword Change FailedError
V 2.0 EVID 51106: Auth For Web Services FailureSub RuleFailures Occurred For Web Or MAC AuthenticationInformation
V 2.0 EVID 51107: Invalid New PasswordSub RulePassword Change FailedError
V 2.0 EVID 51115: New PW Invalid Previously UsedSub RulePassword Change FailedError
V 2.0 EVID 51116: Invalid New PW- Reverse Order PWSub RulePassword Change FailedError
V 2.0 EVID 52000: Configuration AddedSub RuleConfiguration InformationInformation
V 2.0 EVID 52001: Configuration ChangedSub RuleConfiguration InformationInformation
V 2.0 EVID 52002: Configuration DeletedSub RuleConfiguration InformationInformation
V 2.0 EVID 52003: ISE Instances Node DeregisteredSub RuleDevice UnregisteredWarning
V 2.0 EVID 52004: ISE Instances Node Register EvtSub RuleRegister NodeInformation
V 2.0 EVID 52005: ISE Instances Node ActivatedSub RuleActivate NodeInformation
V 2.0 EVID 52006: ISE Node DeactivatedSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 52007: Force Full ReplicationSub RuleForce Full ReplicationOther Audit Success
V 2.0 EVID 52008: H/W Replacement Register HandlerSub RuleHardware ReplacementInformation
V 2.0 EVID 52009: Promote NodeSub RulePromote NodeInformation
V 2.0 EVID 52010: Promote Node HandlerSub RulePromote Node HandlerInformation
V 2.0 EVID 52011: Local ModeSub RuleLocal Mode HandlerInformation
V 2.0 EVID 52012: Local Mode HandlerSub RuleLocal Mode HandlerInformation
V 2.0 EVID 52013: Hardware ReplacementSub RuleHardware ReplacementInformation
V 2.0 EVID 52014: Deregister HandlerSub RuleDeregister HandlerInformation
V 2.0 EVID 52015: Enable LogCollector TargetSub RuleLog Collector ResumedInformation
V 2.0 EVID 52016: Select LogCollector NodeSub RuleLog Collector SetInformation
V 2.0 EVID 52017: Software UpdatedSub RuleSoftware Update RequestInformation
V 2.0 EVID 52018: Overriding ISE Instances Log CatSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 52019: Restoring ISE Instances Log CatSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 52020: Prim Requested Full ReplicationSub RuleReplication InformationInformation
V 2.0 EVID 52021: Sec Requested Full ReplicationSub RuleReplication InformationInformation
V 2.0 EVID 52022: Full ReplicationSub RuleFull Replication SucceededOther Audit Success
V 2.0 EVID 52023: Failed To Create A LinkSub RuleFull Replication FailedError
V 2.0 EVID 52024: Local Credential FileSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 52025: Remote Database KeySub RuleRetrieve Database ObjectInformation
V 2.0 EVID 52026: Retrieving DatabaseSub RuleRetrieve Database ObjectInformation
V 2.0 EVID 52027: Heartbeat Channel StopSub RuleHeartbeat StatusInformation
V 2.0 EVID 52028: Deleting Backup FilesSub RuleGeneral Backup InformationInformation
V 2.0 EVID 52029: Cleanup Script & Restarting ISESub RulePerforming CleanupInformation
V 2.0 EVID 52030: Full Replication SuccessSub RuleFull Replication SucceededOther Audit Success
V 2.0 EVID 52031: Full Replication FailureSub RuleFull Replication FailedError
V 2.0 EVID 52032: Req To Join Distributed EnvironSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 52033: Registration SuccessSub RuleRegistration CompleteInformation
V 2.0 EVID 52034: Registration RequestedSub RuleRegistration RequestInformation
V 2.0 EVID 52035: Registration FailureSub RuleRegistration FailureError
V 2.0 EVID 52036: Changing InstanceSub RuleInstance InformationInformation
V 2.0 EVID 52037: Updating Instance In DatabaseSub RuleInstance InformationInformation
V 2.0 EVID 52038: Distr ISE Deployment Join SuccSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 52039: Distr ISE Deployment Join FailSub RuleGeneral Action FailureError
V 2.0 EVID 52040: Promotion Req To Sec InstanceSub RulePromotion RequestInformation
V 2.0 EVID 52041: Promotion Req To Prim InstanceSub RulePromotion RequestInformation
V 2.0 EVID 52042: Demotion SuccessSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 52043: Demotion FailureSub RuleDemotion FailedError
V 2.0 EVID 52044: Global Deployment Update SuccessSub RuleUpdate SuccessfulInformation
V 2.0 EVID 52045: Promotion SuccessSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 52046: Promotion FailureSub RulePromotion FailedError
V 2.0 EVID 52047: Local Mode Reconnect RequestSub RuleLocal Mode Reconnect RequestInformation
V 2.0 EVID 52048: Local Mode Remote Call To ReconSub RuleLocal Mode Reconnect RequestInformation
V 2.0 EVID 52049: Replication In Local ModeSub RuleReplication InformationInformation
V 2.0 EVID 52050: Changing ISE Instance StatusSub RuleInstance InformationInformation
V 2.0 EVID 52051: Updating Instance StatusSub RuleInstance InformationInformation
V 2.0 EVID 52052: Local Mode Reconnect SuccessSub RuleLocal Mode Reconnect SucceededInformation
V 2.0 EVID 52053:  Local Mode Reconnect FailureSub RuleLocal Mode Reconnect FailedError
V 2.0 EVID 52054: Issue Request Local ModeSub RuleLocal Mode Reconnect RequestInformation
V 2.0 EVID 52055: Replace Request To Sec InstanceSub RuleInstance InformationInformation
V 2.0 EVID 52056: Changing ISE Instance StatusSub RuleInstance InformationInformation
V 2.0 EVID 52057: Updating Instance StatusSub RuleInstance InformationInformation
V 2.0 EVID 52058: Local Mode SuccessSub RuleLocal Mode Reconnect SucceededInformation
V 2.0 EVID 52059: Local Mode FailedSub RuleLocal Mode FailedError
V 2.0 EVID 52060: Req To Deregister Prim To SecSub RuleDeregister RequestInformation
V 2.0 EVID 52061: Deregister Secondary RequestSub RuleDeregister RequestInformation
V 2.0 EVID 52062: Conn Removing Of Prim & SecSub RuleConnection Removed Or DisabledInformation
V 2.0 EVID 52063: Restarting Reg HeartbeatSub RuleHeartbeat StatusInformation
V 2.0 EVID 52070: Sec Request To Deregister PrimSub RuleDeregister RequestInformation
V 2.0 EVID 52071: Primary Deleted Secondary CertSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 52072: Deregistration SuccessSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 52073: Deregistration FailureSub RuleDeregistration FailedError
V 2.0 EVID 52074: Request To Disconnect SecondarySub RuleDisconnect Request ReceivedInformation
V 2.0 EVID 52075: Req To Disconnect Sec From PrimSub RuleDisconnect Request ReceivedInformation
V 2.0 EVID 52076: Prim Request To Delete Sec NodeSub RuleDelete Node RequestInformation
V 2.0 EVID 52077: Sec Instance Disconnection SuccSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 52078: Sec Instance Disconnection FailSub RuleDelete Node FailedError
V 2.0 EVID 52079: Prim Delete Sec Instance SuccesSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 52080: Sec Instance Deletion FailureSub RuleDelete Node FailedError
V 2.0 EVID 52081: Priamry Backup RequestSub RuleBackup RequestInformation
V 2.0 EVID 52082: Primary Backup FailureSub RuleBackup FailureError
V 2.0 EVID 52083: Secondary Backup RequestSub RuleBackup RequestInformation
V 2.0 EVID 52084: Primary Backup SuccessSub RuleBackup SucceededInformation
V 2.0 EVID 52085: Secondary Backup FailureSub RuleBackup FailureError
V 2.0 EVID 52086: Software Update RequestSub RuleSoftware Update RequestInformation
V 2.0 EVID 52088: Software UpdateSub RuleSoftware UpdatedConfiguration
V 2.0 EVID 52089: Software Update Required BackupSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 52090: Software Update Download BundleSub RuleDownloading BundleInformation
V 2.0 EVID 52091: Software Update FailureSub RuleSoftware Update FailedError
V 2.0 EVID 52092: Software Update SuccessSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 52093: S/W Update Download Bundle FailSub RuleSoftware Update FailedError
V 2.0 EVID 52094: Activate RequestSub RuleActivate RequestInformation
V 2.0 EVID 52095: H/W Replacement Register ReqSub RuleHardware ReplacementInformation
V 2.0 EVID 52096: Unable To Retrieve Prim InstanceSub RuleInstance InformationInformation
V 2.0 EVID 52097: Sec To Initiate Full ReplicationSub RuleFull Replication RequestInformation
V 2.0 EVID 52098: Sec Instance Activate SuccessSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 52099: Secondary Instance Activate FailSub RuleGeneral Action FailureError
V 2.0 EVID 52100: Process Status On Sec InstanceSub RuleProcess StatusInformation
V 2.0 EVID 52101: Process Status On Prim InstanceSub RuleProcess StatusInformation
V 2.0 EVID 52102: Scheduled BackupSub RuleScheduled BackupInformation
V 2.0 EVID 52103: Sched Backup Fail- Invalid CharSub RuleScheduled BackupInformation
V 2.0 EVID 52104: Sched Backup Fail- Invalid RepoSub RuleScheduled BackupInformation
V 2.0 EVID 52105: Scheduled Backup FailedSub RuleScheduled BackupInformation
V 2.0 EVID 52106: Scheduled Backup SuccessSub RuleScheduled BackupInformation
V 2.0 EVID 57000: Deleted RolledOver Loc Log FileSub RuleFile DeletedInformation
V 2.0 EVID 58001: ISE Process StartedSub RuleProcess/Service StartedStartup and Shutdown
V 2.0 EVID 58002: ISE Process StoppedSub RuleProcess/Service StoppedStartup and Shutdown
V 2.0 EVID 58003: ISE Processes StartedSub RuleProcess/Service StartedStartup and Shutdown
V 2.0 EVID 58004: ISE Processes StoppedSub RuleProcess/Service StoppedStartup and Shutdown
V 2.0 EVID 58005: ISE Process Restart By WatchdogSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 58006: Watchdog Configuration ReloadedSub RuleConfiguration InformationInformation
V 2.0 EVID 58007: ISE Process Reported Start/StopSub RuleFailed Process StartError
V 2.0 EVID 58008: CARS Backup CompletedSub RuleCARS Backup CompleteInformation
V 2.0 EVID 58009: CARS Restore CompletedSub RuleCARS Restore CompleteInformation
V 2.0 EVID 58010: ISE DB BackupSub RuleDatabase InformationInformation
V 2.0 EVID 58011: ISE DB RestoreSub RuleDatabase InformationInformation
V 2.0 EVID 58012: ISE Support Bundle CollectedSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 58013: ISE DB ResetSub RuleDatabase InformationInformation
V 2.0 EVID 58014: ISE Core Files DeleteSub RuleFile DeletedInformation
V 2.0 EVID 58015: ISE Log Files DeletedSub RuleFile DeletedInformation
V 2.0 EVID 58016: ISE Upgrade CompletedSub RuleUpgrade CompleteInformation
V 2.0 EVID 58017: ISE Patch InstalledSub RuleSoftware Patching InformationInformation
V 2.0 EVID 58018: ISE Migration Interface EnabledSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 58019: ISE Admin Password ResetSub RulePassword ModifiedAccount Modified
V 2.0 EVID 58020: Clock SetSub RuleSystem Clock Has Been UpdatedInformation
V 2.0 EVID 58021: Time Zone SetSub RuleLocal Time ZoneInformation
V 2.0 EVID 58022: NTP Server SetSub RuleGeneral NTP InformationInformation
V 2.0 EVID 58023: Hostname SetSub RuleLocal Machine Host NameInformation
V 2.0 EVID 58024: IP Address SetSub RuleIP Address AssignedInformation
V 2.0 EVID 58025: IP Address StateSub RuleIP Address AssignedInformation
V 2.0 EVID 58026: Default Gateway SetSub RuleGateway Is UpInformation
V 2.0 EVID 58027: Name Server SetSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 58028: ADE OS Xfer Library ErrorSub RuleADE OS Xfer Library ErrorError
V 2.0 EVID 58029: ADE OS Install Library ErrorSub RuleADE OS Install Library ErrorError
V 2.0 EVID 58030: ISE Upgrade Schema ChangedSub RuleSchema InformationInformation
V 2.0 EVID 58031: ISE Upgrade DictionarySub RuleUpgrade CompleteInformation
V 2.0 EVID 58032: ISE Upgrade Data ManipulationSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 58033: ISE Upgrade AAC EventSub RuleUpgrade CompleteInformation
V 2.0 EVID 58034: ISE Upgrade PKI EventSub RuleUpgrade CompleteInformation
V 2.0 EVID 58035: ISE Upgrade MnT EventSub RuleUpgrade CompleteInformation
V 2.0 EVID 58036: ISE Upgrade EventSub RuleUpgrade StartedInformation
V 2.0 EVID 58037: ISE Install EventSub RuleInstall StartedInformation
V 2.0 EVID 58038: Failed To Join AD EventSub RuleGeneral Active Directory InformationInformation
V 2.0 EVID 58039: AD Join EventSub RuleGeneral Active Directory InformationInformation
V 2.0 EVID 58040: AD Leave EventSub RuleGeneral Active Directory InformationInformation
V 2.0 EVID 58041: Import/Export Process AbortedSub RuleImport Process AbortedInformation
V 2.0 EVID 58042: Import/Export Process StartedSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 58043: Import/Export Process CompletedSub RuleImport Process CompleteInformation
V 2.0 EVID 58044: Import/Export Process ErrorSub RuleManagement Process ErrorError
V 2.0 EVID 58045: Single Network Interface AllowedSub RuleOnly Single Network Interface Is AllowedWarning
V 2.0 EVID 59000: Received Req To Revoke All PACsSub RuleRequest ReceivedOther Audit Success
V 2.0 EVID 59001: Generated New EAP-FAST Seed KeySub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 59002: Successfully Updated EAP-FASTSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 59003: User Not Authorized To RevokeSub RuleUnauthorized ActivityMisuse
V 2.0 EVID 59004: Timed Out Attempt To Revoke EAPSub RuleTimeout ErrorError
V 2.0 EVID 59005: Rcvd Req To Generate Tunnel PACSub RuleRequest ReceivedOther Audit Success
V 2.0 EVID 59006: Rcvd Req To Generate Machine PACSub RuleRequest ReceivedOther Audit Success
V 2.0 EVID 59007: Failed To Generate PACSub RuleUnsuccessful ActivityOther Audit Failure
V 2.0 EVID 59008: Successfully Generated PACSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 59009: Rcvd Req To Generate TrustSecPACSub RuleRequest ReceivedOther Audit Success
V 2.0 EVID 59010: Failed To Generate TrustSec PACSub RuleUnsuccessful ActivityOther Audit Failure
V 2.0 EVID 59011: Successfully Generated TrustSecSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 59050: Rcvd Req To Revoke All TicketsSub RuleRequest ReceivedOther Audit Success
V 2.0 EVID 59051: Generated New EAP-TLS Seed KeySub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 59052: Successfully Updated EAP-TLSSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 59100: Admin Req To Delete Loc StoreSub RuleObject Handle RequestedOther Audit Success
V 2.0 EVID 59101: Successful Deletion Of Loc StoreSub RuleFile Monitoring Event - DeleteAccess Success
V 2.0 EVID 59102: Successful Deletion Of MultipleSub RuleFile Monitoring Event - DeleteAccess Success
V 2.0 EVID 59103: Failed To Delete Local Store LogSub RuleFile Monitoring Event - Delete FailedAccess Failure
V 2.0 EVID 59200: Admin Req To Set Log CollectorSub RuleObject Handle RequestedOther Audit Success
V 2.0 EVID 59201: Set Log Collector SuccessfulSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 59202: Set Log Collector ErrorSub RuleUnsuccessful ActivityOther Audit Failure
V 2.0 EVID 59203:Admin Req To Resume Log CollectorSub RuleObject Handle RequestedOther Audit Success
V 2.0 EVID 59204: Resume Log Collector SuccessfulSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 59205: Resume Log Collector ErrorSub RuleUnsuccessful ActivityOther Audit Failure
V 2.0 EVID 59206: Admin Req To Suspend Log CollecSub RuleObject Handle RequestedOther Audit Success
V 2.0 EVID 59207: Suspend Log Collector SuccessfulSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 59208: Suspend Log Collector ErrorSub RuleUnsuccessful ActivityOther Audit Failure
V 2.0 EVID 59250: Adm Reset Access Setting Frm CLISub RuleAction Performed By AdminOther Audit Success
V 2.0 EVID 59251: Admin Activated/Deactivated ADSub RuleAction Performed By AdminOther Audit Success
V 2.0 EVID 59252: Adm Changed Component Debug LogSub RuleAction Performed By AdminOther Audit Success
V 2.0 EVID 59253: Admin Started Export Config DataSub RuleAction Performed By AdminOther Audit Success
V 2.0 EVID 59254: Admin Started Export Config DataSub RuleAction Performed By AdminOther Audit Success
V 2.0 EVID 59255: Adm Aborted Import/Export ConfigSub RuleAction Performed By AdminOther Audit Success
V 2.0 EVID 59256: Adm Started Replication ProcessSub RuleAction Performed By AdminOther Audit Success
V 2.0 EVID 59257: Admin Reset Mgmt Interface CertSub RuleAction Performed By AdminOther Audit Success
V 2.0 EVID 59258: Admin Decrypted Support BundleSub RuleAction Performed By AdminOther Audit Success
V 2.0 EVID 59259: Replication FailedSub RuleReplication FailedError
V 2.0 EVID 60000: Patch Installation CompletedSub RuleSoftware Patching InformationInformation
V 2.0 EVID 60001: Patch Installation FailedSub RuleSoftware Patching InformationInformation
V 2.0 EVID 60002: Patch Rollback CompletedSub RuleSoftware Patching InformationInformation
V 2.0 EVID 60003: Patch Rollback FailureSub RuleSoftware Patching InformationInformation
V 2.0 EVID 60050: Node Added To Deployment SuccessSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 60051: Failed To Add Node To DeploymentSub RuleUnsuccessful ActivityOther Audit Failure
V 2.0 EVID 60052: Node Removed From DeploymentSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 60053: Failed To Remove Node Frm DeploySub RuleDelete Node FailedError
V 2.0 EVID 60054: Node Updated SuccessSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 60055: Failed To Update NodeSub RuleUpdate UnsuccessfulWarning
V 2.0 EVID 60056: Node Group Runtime Status ChangeSub RuleRuntimeChange EventOther Audit Success
V 2.0 EVID 60057: PSN Node Went DownSub RuleHost Is DownError
V 2.0 EVID 60058: System Heartbeat Initial StatusSub RuleStarted Sending Heartbeats To PeerInformation
V 2.0 EVID 60059: Successfully Reg Node With MnTSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 60060: Admin Invoked OCSP Clear CacheSub RuleApplication InvokedInformation
V 2.0 EVID 60061: OCSP Clear Cache O/P CompletedSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 60062: OCSP Clear Cache O/P TerminationSub RuleDelete Node FailedError
V 2.0 EVID 60063: Replication To Node CompletedSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 60064: Node Replication FailureSub RuleReplication FailedError
V 2.0 EVID 60065: Max No Of Admin Sessions ExceedSub RuleConnection Limit ExceededWarning
V 2.0 EVID 60066: Not Matched Delta B/W Old & NewSub RuleGeneral Audit MessageOther Audit
V 2.0 EVID 60067: Profiler Feed Service AutomaticSub RuleEndpoint Profiling ActivityInformation
V 2.0 EVID 60068: Profiler Feed Service ManualSub RuleEndpoint Profiling ActivityInformation
V 2.0 EVID 60069: Profiler Feed Service ProfilesSub RuleEndpoint Profiling ActivityInformation
V 2.0 EVID 60070: Profiler Feed Service No ProfileSub RuleEndpoint Profiling ActivityInformation
V 2.0 EVID 60071: Feed Server Communication IssuedSub RuleCommunication FailureError
V 2.0 EVID 60072: Profiler Feed Svc Feed UnavailaSub RuleService UnavailableError
V 2.0 EVID 60073: Querying Profiler Feed Svc ErrSub RuleCommunication FailureError
V 2.0 EVID 60074: Profiler Feed Service ImportingSub RuleEndpoint Profiling ActivityInformation
V 2.0 EVID 60075: Sponsor Successfully AuthSub RuleAuthentication ActivityAuthentication Success
V 2.0 EVID 60076: Sponsor Authentication FailureSub RuleAuthentication Failure ActivityAuthentication Failure
V 2.0 EVID 60077: MyDevices User Auth FailureSub RuleAuthentication Failure ActivityAuthentication Failure
V 2.0 EVID 60078: MyDevices User Successfully AuthSub RuleAuthentication ActivityAuthentication Success
V 2.0 EVID 60079: Failed To Establish SSL SessionSub RuleUnsuccessful ActivityOther Audit Failure
V 2.0 EVID 60080: SSH CLI User Successfully Log InSub RuleAuthentication ActivityAuthentication Success
V 2.0 EVID 60081: SSH CLI User Login Attempt UnsucSub RuleAuthentication Failure ActivityAuthentication Failure
V 2.0 EVID 60082: SSH CLI User Login Attempts LockSub RuleUser Logon Failure: Account Locked OutAuthentication Failure
V 2.0 EVID 60083: Syslog Server Config ChangedSub RuleConfiguration Modified: SystemConfiguration
V 2.0 EVID 60084: ADEOS CLI User Config ChangedSub RuleConfiguration Modified: SystemConfiguration
V 2.0 EVID 60085: ADEOS Repository Config ChangedSub RuleConfiguration Modified: SystemConfiguration
V 2.0 EVID 60086: ADEOS SSH Svc Config ChangedSub RuleConfiguration Modified: SystemConfiguration
V 2.0 EVID 60087:ADEOS Max SSH CLI Sess Config ChgSub RuleConfiguration Modified: SystemConfiguration
V 2.0 EVID 60088: ADEOS SNMP Agent Config ChangedSub RuleConfiguration Modified: SystemConfiguration
V 2.0 EVID 60089: ADEOS CLI Kron Scheduler PolicySub RuleConfiguration Modified: SystemConfiguration
V 2.0 EVID 60090: ADEOS CLI Kron Scheduler OccurSub RuleConfiguration Modified: SystemConfiguration
V 2.0 EVID 60091:ADEOS CLI Pre-Login Banner ConfigSub RuleConfiguration Modified: SystemConfiguration
V 2.0 EVID 60092:ADEOS CLI Post-Login Banner ConfiSub RuleConfiguration Modified: SystemConfiguration
V 2.0 EVID 60093: ISE Backup StartedSub RuleBackup Job StartedInformation
V 2.0 EVID 60094: ISE Backup CompletedSub RuleBackup Job CompletedInformation
V 2.0 EVID 60095: ISE Backup FailureSub RuleBackup FailedError
V 2.0 EVID 60096: ISE Log Backup StartedSub RuleBackup Job StartedInformation
V 2.0 EVID 60097: ISE Log Backup Completed SuccessSub RuleBackup Job CompletedInformation
V 2.0 EVID 60098: ISE Log Backup FailureSub RuleBackup FailedError
V 2.0 EVID 60099: ISE Restore StartedSub RuleBackup Or Restore SQL CommandInformation
V 2.0 EVID 60100: ISE Restore CompletedSub RuleBackup RestoredInformation
V 2.0 EVID 60101: ISE Restore FailureSub RuleRestore FailureError
V 2.0 EVID 60102: Application Install. CompletedSub RuleUpgrade CompleteInformation
V 2.0 EVID 60103: Application Installation FailureSub RuleApplication ErrorError
V 2.0 EVID 60104: Application Remove StartedSub RuleJob StartedOther Audit Success
V 2.0 EVID 60105: Application Remove CompletedSub RuleObject Deleted/RemovedAccess Success
V 2.0 EVID 60106: Application Remove FailureSub RuleApplication ErrorError
V 2.0 EVID 60107: Application Upgrade FailureSub RuleApplication ErrorError
V 2.0 EVID 60108: Application Patch StartedSub RuleSoftware Patching InformationInformation
V 2.0 EVID 60109: Application Patch Remove StartedSub RuleSoftware Patching InformationInformation
V 2.0 EVID 60111: Application Patch Remove CompletSub RuleSoftware Patching InformationInformation
V 2.0 EVID 60112: Application Patch Remove FailureSub RuleApplication ErrorError
V 2.0 EVID 60113: ISE Server Reload InitiatedSub RuleGeneral Server WarningWarning
V 2.0 EVID 60114: ISE Server Shutdown InitiatedSub RuleGeneral Server WarningWarning
V 2.0 EVID 60115: CLI User Logged In Via SSHSub RuleAuthentication ActivityAuthentication Success
V 2.0 EVID 60116: CLI User Logged Out From SSHSub RuleLogin Or Logout Event ExecutedOther Audit
V 2.0 EVID 60117: ADEOS CLI User Forced Logged OutSub RuleGeneral User Activity Monitor EventOther Audit
V 2.0 EVID 60118: ADEOS CLI User Used Delete CLISub RuleGeneral User Activity Monitor EventOther Audit
V 2.0 EVID 60119: ADEOS CLI User Used Copy CLISub RuleGeneral User Activity Monitor EventOther Audit
V 2.0 EVID 60120: ADEOS CLI User Used MKDIR CLISub RuleGeneral User Activity Monitor EventOther Audit
V 2.0 EVID 60121:ADEOS CLI User Copied Out RunningSub RuleGeneral User Activity Monitor EventOther Audit
V 2.0 EVID 60122: ADEOS CLI User Copied SystemSub RuleGeneral User Activity Monitor EventOther Audit
V 2.0 EVID 60123: ADEOS CLI User Saved RunningSub RuleGeneral User Activity Monitor EventOther Audit
V 2.0 EVID 60124: ADEOS CLI User Login FailureSub RuleLOGIN_PASSWORD_EXPIREDInformation
V 2.0 EVID 60125: Detected Malformed SSH RequestedSub RuleDetected Malware ActivityMalware
V 2.0 EVID 60126: Application Patch Install. FailSub RuleApplication ErrorError
V 2.0 EVID 60127: Max No Of Concurrent CLI SessionSub RuleGeneral Server WarningWarning
V 2.0 EVID 60128: Copy File In From ADEOS CLI FailSub RuleGeneral User Activity Monitor EventOther Audit
V 2.0 EVID 60129:Copy File Out From ADEOS CLI FailSub RuleGeneral User Activity Monitor EventOther Audit
V 2.0 EVID 60130: ISE Scheduled Backup ConfiguredSub RuleScheduled BackupInformation
V 2.0 EVID 60131: ISE Support Bundle CreatedSub RuleObject CreatedAccess Success
V 2.0 EVID 60132: ISE Support Bundle DeletedSub RuleObject Deleted/RemovedAccess Success
V 2.0 EVID 60133: ISE Support Bundle GenerationSub RuleUnsuccessful ActivityOther Audit Failure
V 2.0 EVID 60134: DNS Resolution FailureSub RuleUnsuccessful ActivityOther Audit Failure
V 2.0 EVID 60135: MyDevices User SSO Logout FailSub RuleUnsuccessful ActivityOther Audit Failure
V 2.0 EVID 60136: Sponsor User SSO Logout FailureSub RuleUnsuccessful ActivityOther Audit Failure
V 2.0 EVID 60150: Slow Replication InfoSub RuleReplication InformationInformation
V 2.0 EVID 60151: Slow Replication WarningSub RuleReplication WarningWarning
V 2.0 EVID 60152: Slow Replication ErrorSub RuleReplication ErrorError
V 2.0 EVID 60153: Certificate ExportedSub RuleCertificate Services InformationInformation
V 2.0 EVID 60154: Application Patch Install CompleSub RuleSoftware Patching InformationInformation
V 2.0 EVID 60155: Secure Comm With Syslog Svr EstSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 60156: Secure Comm Establishment FailSub RuleUnsuccessful ActivityOther Audit Failure
V 2.0 EVID 60157: Failed To Copy Exported ReportSub RuleUnsuccessful ActivityOther Audit Failure
V 2.0 EVID 60158: All XGrid Admin Actions LoggedSub RuleGeneral User Logged EventInformation
V 2.0 EVID 60159: Posture Req Update StartedSub RuleUpdate Process StartedInformation
V 2.0 EVID 60160: Finished Updating Posture ReqSub RuleContent Successfully UpdatedInformation
V 2.0 EVID 60161: Failed Update Posture ReqSub RuleUpdate FailedError
V 2.0 EVID 60162: Checking Updated Posture ReqSub RuleContent Successfully UpdatedInformation
V 2.0 EVID 60163: Processing Updated Posture ReqSub RuleProcessing NotificationInformation
V 2.0 EVID 60164: NTP Service Down On NodeSub RuleNTPD ErrorError
V 2.0 EVID 60165: NTP Failed To Sync With ConfigSub RuleNTPD ErrorError
V 2.0 EVID 60166: Certificate Expiring SoonSub RuleCertificate Services InformationInformation
V 2.0 EVID 60167: Certificate ExpiredSub RuleCertificate ExpiredWarning
V 2.0 EVID 60168: Session Repeat Count Reset SuccSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 60169: Session Repeat Count Reset FailSub RuleUnsuccessful ActivityOther Audit Failure
V 2.0 EVID 60170: Resetting Repeat Cnt SuccessfulSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 60171: Resetting Repeat Count FailedSub RuleUnsuccessful ActivityOther Audit Failure
V 2.0 EVID 60172: Alarms AcknowledgeSub RuleAlarm ClearedInformation
V 2.0 EVID 60173: Outdated Alarms PurgedSub RuleOver Max Date PurgedInformation
V 2.0 EVID 60174: Could Not Add Cert RevocationSub RuleCertificate Services InformationInformation
V 2.0 EVID 60175: Could Not Download Cert RevocatSub RuleCertificate Services InformationInformation
V 2.0 EVID 60176: Posture UpdatedSub RuleContent Successfully UpdatedInformation
V 2.0 EVID 60177: App Upgrade Preparation FailureSub RuleApplication ErrorError
V 2.0 EVID 60178: App Upgrade Preparation SuccessSub RuleUpgrade InformationInformation
V 2.0 EVID 60179: App Upgrade Preparation StartSub RuleUpgrade StartedInformation
V 2.0 EVID 60180: Syslog Server Identity Chk FailSub RuleDevice Communication FailureError
V 2.0 EVID 60184: Console CLI User Success LoginSub RuleAuthentication ActivityAuthentication Success
V 2.0 EVID 60185: Console CLI User UnsuccessfulSub RuleAuthentication Failure ActivityAuthentication Failure
V 2.0 EVID 60186: Console CLI User Login AttemptSub RuleUser Logon Failure: Account Locked OutAuthentication Failure
V 2.0 EVID 60187: Application Upgrade SuccessSub RuleUpgrade CompleteInformation
V 2.0 EVID 60188: SSH Connection Attempt FailSub RuleConnection Authentication FailedAuthentication Failure
V 2.0 EVID 60189:Terminal Session Timeout ModifiedSub RuleConfiguration Modified: SystemConfiguration
V 2.0 EVID 60190: XGrid Administrator ActionSub RuleAction Performed By AdminOther Audit Success
V 2.0 EVID 60191: Insufficient Virtual Mac ResourcSub RuleInsufficient ResourcesCritical
V 2.0 EVID 60192: Firmware Update Required On NodeSub RuleUpdate RequiredInformation
V 2.0 EVID 60193: RSA Key Configuration ModifiedSub RuleConfiguration Modified: SystemConfiguration
V 2.0 EVID 60194: Host Key Configuration ModifiedSub RuleConfiguration Modified: SystemConfiguration
V 2.0 EVID 60195: CA Service StartedSub RuleProcess/Service StartedStartup and Shutdown
V 2.0 EVID 60196: CA Service StoppedSub RuleProcess/Service StoppedStartup and Shutdown
V 2.0 EVID 60197: Revoked ISE CA Issued CertSub RuleCertificate Services InformationInformation
V 2.0 EVID 60198: MnT Purge Event OccurredSub RuleCleanup CompletedInformation
V 2.0 EVID 60199: IP-SGT Mapping Deployed SuccessSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 60200: IP-SGT Mapping Failed DeployingSub RuleUnsuccessful ActivityOther Audit Failure
V 2.0 EVID 60201: IP-SGT Deployment SuccessfulSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 60202: IP-SGT Deployment FailureSub RuleUnsuccessful ActivityOther Audit Failure
V 2.0 EVID 60203: IP-SGT Deployment FinishedSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 60204: System Root CLI Account SuccessSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 60205: CLI User Logged In Via ConsoleSub RuleLogin Or Logout Event ExecutedOther Audit
V 2.0 EVID 60206: CLI User Logged Out Via ConsoleSub RuleLogin Or Logout Event ExecutedOther Audit
V 2.0 EVID 60207: Logging Loglevel Config ModifiedSub RuleConfiguration Modified: SystemConfiguration
V 2.0 EVID 60208: Root CA Certificate ReplacedSub RuleCertificate Services InformationInformation
V 2.0 EVID 60209: CA Service EnabledSub RuleSecurity Mode Enabled Or DisabledInformation
V 2.0 EVID 60210: CA Service DisabledSub RuleSecurity Mode Enabled Or DisabledInformation
V 2.0 EVID 60211: ISE Acquired Subordinate CASub RuleCertificate Services InformationInformation
V 2.0 EVID 60212: Portal Could Not Start On NodeSub RuleCertificate Services InformationInformation
V 2.0 EVID 60213: CA Keys Replaced By Import O/PSub RuleCertificate Services InformationInformation
V 2.0 EVID 60214: CA Keys ExportedSub RuleCertificate Services InformationInformation
V 2.0 EVID 60215: Endpoint Certs Marked ExpiredSub RuleCertificate ExpiredWarning
V 2.0 EVID 60216: Endpoint Certs PurgedSub RuleCleaning FilesOther Audit Success
V 2.0 EVID 60217: Certificate Replication FailedSub RuleReplication FailedError
V 2.0 EVID 60218: Certificate Replication FailureSub RuleReplication FailedError
V 2.0 EVID 60219: Admin Node Not Received PAN HASub RuleGeneral Information Log MessageInformation
V 2.0 EVID 60221: Misconfig PAN HA MonitoringSub RuleConfiguration Changes FailedCritical
V 2.0 EVID 60222: PAN Not Reachable Or UnhealthySub RuleHost UnreachableInformation
V 2.0 EVID 60223: PAN HA Promotion Request FailureSub RuleProcess Request FailedError
V 2.0 EVID 60224: Automatic Failover To Sec PANSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 60225: Unable To Build Cert ChainSub RuleCertificate Services InformationInformation
V 2.0 EVID 60226: Successfully Performed CoA TermSub RuleCertificate Services InformationInformation
V 2.0 EVID 60227:Failed To Perform CoA TerminationSub RuleUnsuccessful ActivityOther Audit Failure
V 2.0 EVID 60228: MSE Server UnreachableSub RuleHost UnreachableInformation
V 2.0 EVID 60229: MSE Server Back OnlineSub RulePreviously Failed Device Back OnlineWarning
V 2.0 EVID 60231: Queried MSE ServerSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 60232: Started Ongoing Sessions CheckSub RuleCertificate RetrievedInformation
V 2.0 EVID 60233: Endpoint Session TerminatedSub RuleCertificate Services InformationInformation
V 2.0 EVID 60234: SXP Connection DisconnectedSub RuleSession DisconnectedOther Audit Success
V 2.0 EVID 60235: SXP Connection SuccessSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 60236: SXP Connection FailureSub RuleUnsuccessful ActivityOther Audit Failure
V 2.0 EVID 60237: SXP Binding SuccessSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 60238: SXP Binding FailureSub RuleUnsuccessful ActivityOther Audit Failure
V 2.0 EVID 60239: SXP Binding Conflict OccurredSub RuleBind InformationInformation
V 2.0 EVID 60400: Policy Elements Generated BasedSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 60401: Reminder Assign NAD ProfilesSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 60451: Telemetry Enabled On DeploymentSub RulePolicy Enabled: AuditingPolicy
V 2.0 EVID 60452: Telemetry Disabled On DeploymentSub RulePolicy Disabled: AuditingPolicy
V 2.0 EVID 60453: Telemetry Messages Sent SuccessSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 60454: Telemetry Msg Not Sent SuccessSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 60501: ERS XML Input Is Suspect For XSSSub RuleGeneral Attack ActivityAttack
V 2.0 EVID 60502: ERS Identified Deprecated URLSub RuleDeprecation AnnouncementInformation
V 2.0 EVID 60503: ERS Identified Out-Dated URLSub RuleURL InformationInformation
V 2.0 EVID 60504: ERS Request Content-Type HeaderSub RuleContent Type Does Not Match The Accept TypeWarning
V 2.0 EVID 11319: TrustSec Works On TLS 1.0Sub RuleTLS MessageInformation
V 2.0 EVID 60455: Easy Wired Selected On AllowedSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 60456: Started CRL/OCSP Periodic CertSub RuleCertificate Services InformationInformation
V 2.0 EVID 60457: Successful Message For Auth TypeSub RuleAuthentication ActivityAuthentication Success
V 2.0 EVID 60458: Unsuccessful Msg For Auth TypeSub RuleAuthentication Failure ActivityAuthentication Failure
V 2.0 EVID 60459: SXP Binding Not PropagatedSub RuleFalling Threshold CrossedError
V 2.0 EVID 60460: Inactivity Account DisabledSub RuleAccount DisabledAccess Revoked
V 2.0 EVID 60461: User Lvl Date Expiry Acc DisableSub RuleAccount DisabledAccess Revoked
V 2.0 EVID 60462: Global Lvl Date Expiry DisabledSub RuleAccount DisabledAccess Revoked
V 2.0 EVID 60463: Global Lvl Days Expiry DisabledSub RuleAccount DisabledAccess Revoked
V 2.0 EVID 60464: Smart Call Home Msg Sent SuccessSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 60465: Smart Call Home Msg Not Sent SucSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 61001: Used APIC Self Signed CertSub RuleSelf-Generated Certificate LoadedOther Audit Success
V 2.0 EVID 61002: ISE Learned New SGT From IEPGSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 61003: ISE Propagated New EEPG To APICSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 61004: ISE Learned New SXP MappingSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 61005: ISE Propagated New EndpointSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 61006: ISE Removed SGT Due To DeletedSub RuleObject Deleted/RemovedAccess Success
V 2.0 EVID 61007: ISE Removed EEPG From APICSub RuleObject Deleted/RemovedAccess Success
V 2.0 EVID 61008: ISE Removed SXP MappingSub RuleObject Deleted/RemovedAccess Success
V 2.0 EVID 61009: ISE Removed Endpoint APICSub RuleObject Deleted/RemovedAccess Success
V 2.0 EVID 61010: ISE Established Conn To APICSub RuleConnectedInformation
V 2.0 EVID 61011: ISE Disconnected From APICSub RuleSession DisconnectedOther Audit Success
V 2.0 EVID 61012: ISE Auth Against APIC SuccessSub RuleAuthentication ActivityAuthentication Success
V 2.0 EVID 61013: ISE Failed To Auth Against APICSub RuleAuthentication Failure ActivityAuthentication Failure
V 2.0 EVID 61014 ISE Successfully Refreshed AuthSub RuleAuthentication ActivityAuthentication Success
V 2.0 EVID 61015 ISE Failed To Refresh AuthSub RuleAuthentication Failure ActivityAuthentication Failure
V 2.0 EVID 61016 ISE Failed To Refresh EPG SubscSub RuleAuthentication Failure ActivityAuthentication Failure
V 2.0 EVID 61017 ISE Failed To Refresh EndpointSub RuleAuthentication Failure ActivityAuthentication Failure
V 2.0 EVID 61018 ISE Failed To Refresh EEPG SubsSub RuleAuthentication Failure ActivityAuthentication Failure
V 2.0 EVID 61020 ISE Failed To Refresh L3EXTOUTSub RuleAuthentication Failure ActivityAuthentication Failure
V 2.0 EVID 61021 ISE Rcvd EPG With Any Class IdSub RuleGeneral Audit MessageOther Audit
V 2.0 EVID 61022 ISE Failed To Propagate SGTSub RuleGeneral Failed ActivityFailed Activity
V 2.0 EVID 61023 ISE Failed To Learn IEPGSub RuleGeneral Failed ActivityFailed Activity
V 2.0 EVID 61024 ISE Failed To Parse VRF For EPGSub RuleGeneral Failed ActivityFailed Activity
V 2.0 EVID 61025 Secure Connection EstablishedSub RuleConnection EstablishedNetwork Traffic
V 2.0 EVID 61026 Secure Connection With TLS PeerSub RuleConnection InformationInformation
V 2.0 EVID 60505 ERS Req Rejected-Invalid I/PSub RuleRequest RejectedError
V 2.0 EVID 60506 ERS Req Suspicious Of Mal AttackSub RuleSuspicious ActivitySuspicious
V 2.0 EVID 60507 ERS Req Rejected- Unauth UserSub RuleRequest RejectedError
V 2.0 EVID 60508 ERS Req Rejected- Illegal ReqSub RuleRequest RejectedError
V 2.0 EVID 60509 ERS Req Denied As Max PossibleSub RuleConnection Limit ExceededWarning
V 2.0 EVID 61027 Invalid/Bad HTTP Request RcvdSub RuleBad RequestWarning
V 2.0 EVID 61028 TrustSec Deploy Ver. StartedSub RuleGeneral Audit MessageOther Audit
V 2.0 EVID 61029 TrustSec Deploy Ver. FinishedSub RuleGeneral Audit MessageOther Audit
V 2.0 EVID 61030 TrustSec Deploy Ver. CancelledSub RuleGeneral Audit MessageOther Audit
V 2.0 EVID 61031 TrustSec Deploy Ver. FailedSub RuleGeneral Audit MessageOther Audit
V 2.0 EVID 61032 TrustSec Deploy Ver-Policy DiffSub RuleGeneral Audit MessageOther Audit
V 2.0 EVID 61033 TrustSec Deploy Ver Process SucSub RuleGeneral Audit MessageOther Audit
V 2.0 EVID 61034 Maximum Resource Limit ReachedSub RuleResource ShortageWarning
V 2.0 EVID 61035 IP SGT Static Mapping SentSub RuleGeneral Audit MessageOther Audit
V 2.0 EVID 61051 Synflood Limit ConfiguredSub RuleGeneral Audit MessageOther Audit
V 2.0 EVID 61052 Rate Limit ConfiguredSub RuleGeneral Audit MessageOther Audit
V 2.0 EVID 61053 Invalid User Input DetectedSub RuleInvalid Input ValueError
V 2.0 EVID 61054 ISE Found Invalid Auth ProfileSub RuleGeneral Audit MessageOther Audit
V 2.0 EVID 61055 Queue Consumed High MemorySub RuleMemory Statistics InformationInformation
V 2.0 EVID 61056 Federation Link DownSub RuleGeneral Audit MessageOther Audit
V 2.0 EVID 61057 Low Space Available To QueueSub RuleMemory Statistics InformationInformation
V 2.0 EVID 61058 APIC Server Update FailedSub RuleUpdate FailedError
V 2.0 EVID 61059 Req From Customer Success N/WSub RuleGeneral Audit MessageOther Audit
V 2.0 EVID 61060 ISE Server Registered To CiscoSub RuleDevice RegisteredInformation
V 2.0 EVID 61061 ISE Svr De-Registered Frm CiscoSub RuleDevice UnregisteredWarning
V 2.0 EVID 61062 Bi Dir. Connectivity EnabledSub RuleGeneral Audit MessageOther Audit
V 2.0 EVID 61063 Bi Dir. Connectivity DisabledSub RuleGeneral Audit MessageOther Audit
V 2.0 EVID 61064 Bi Dir. Connectivity EstablishSub RuleConnection EstablishedNetwork Traffic
V 2.0 EVID 61065 Bi Dir. Connectivity BrokenSub RuleGeneral Audit MessageOther Audit
V 2.0 EVID 61066 ISE SSE Services EnrolledSub RuleGeneral Audit MessageOther Audit
V 2.0 EVID 61067 ISE SSE Services Un-EnrolledSub RuleGeneral Audit MessageOther Audit
V 2.0 EVID 61068 ACI Integration PerformanceSub RuleGeneral Performance StatisticsInformation
V 2.0 EVID 61069 Rest Req To Ctsmatrix SucceededSub RuleOperation SucceededInformation
V 2.0 EVID 61070 Rest Req To Ctssgacls SuccededSub RuleOperation SucceededInformation
V 2.0 EVID 61071 Rest Req To Ctsenvdata SuccdedSub RuleOperation SucceededInformation
V 2.0 EVID 61072 Error Processing REST RequestSub RuleProcess ErrorError
V 2.0 EVID 61073 Cisco Support Diag Bi-dir ConnSub RuleGeneral Audit MessageOther Audit
V 2.0 EVID 61074 Node Out Of Sync Due To ExpiredSub RuleCertificate ExpiredWarning
V 2.0 EVID 61075 ACI Integration Cannot ContactSub RuleGeneral Audit MessageOther Audit
V 2.0 EVID 51025 Web Services Auth FailedSub RuleAuthentication Failure ActivityAuthentication Failure
V 2.0 EVID 61076 Sponsor Successfully Logged OutSub RuleOperation SucceededInformation
V 2.0 EVID 61077 MyDevices Successfully LogoutSub RuleOperation SucceededInformation
V 2.0 EVID 61078 Rest Req To Ctsreportconfig SucSub RuleOperation SucceededInformation
V 2.0 EVID 61079 NAD TrustSec Propagation StatusSub RuleGeneral Audit MessageOther Audit
V 2.0 EVID 61100 ISE Learned New Tenant From ACISub RuleGeneral Audit MessageOther Audit
V 2.0 EVID 61101 ACI Tenant Removed From ISESub RuleObject Deleted/RemovedAccess Success
V 2.0 EVID 61102 ISE Failed To Learn New TenantSub RuleGeneral Failed ActivityFailed Activity
V 2.0 EVID 61103 ISE Failed To Remove ACI TenantSub RuleGeneral Failed ActivityFailed Activity
V 2.0 EVID 61104 ISE Learned New Tenant From SDASub RuleGeneral Audit MessageOther Audit
V 2.0 EVID 61105 ISE Learned A New VN InfoSub RuleGeneral Audit MessageOther Audit
V 2.0 EVID 61106 Failed To Create VN Info In ISESub RuleGeneral Failed ActivityFailed Activity
V 2.0 EVID 61107 VN Info Updated In ISESub RuleObject ModifiedAccess Success
V 2.0 EVID 61108 Failed To Update VN Info In ISESub RuleGeneral Failed ActivityFailed Activity
V 2.0 EVID 61109 VN Info Deleted In ISESub RuleObject Deleted/RemovedAccess Success
V 2.0 EVID 61110 Failed To Delete VN Info In ISESub RuleGeneral Failed ActivityFailed Activity
V 2.0 EVID 61111 Domain Registration Process FailSub RuleProcess FailedError
V 2.0 EVID 61112 SPHUB Domain Reg Process StartSub RuleProcess/Service StartedStartup and Shutdown
V 2.0 EVID 61113 Cert Req Sent To Domain ManagerSub RuleCertificate RequestActivity
V 2.0 EVID 61114 Domain Registration CompletedSub RuleRegistration CompleteInformation
V 2.0 EVID 61115 Domain Registration FailedSub RuleRegistration FailureWarning
V 2.0 EVID 61116  Unable To Store ACI CertSub RuleGeneral Audit MessageOther Audit
V 2.0 EVID 61117 ACI Connector Started SuccessSub RuleOperation SucceededInformation
V 2.0 EVID 61118 Failed To Start ACI ConnectorSub RuleGeneral Failed ActivityFailed Activity
V 2.0 EVID 61119 Domain De Reg Process StartedSub RuleProcess/Service StartedStartup and Shutdown
V 2.0 EVID 61120 ACI Cert Frm ISE Success DeletdSub RuleObject Deleted/RemovedAccess Success
V 2.0 EVID 61121 Failed To Delete ACI CertSub RuleGeneral Failed ActivityFailed Activity
V 2.0 EVID 61122 Failed To Delete ACI KeystoreSub RuleGeneral Failed ActivityFailed Activity
V 2.0 EVID 61123 ISE Learned A New ACI DomainSub RuleGeneral Audit MessageOther Audit
V 2.0 EVID 61124 ISE Failed To Learn New ACI DomSub RuleGeneral Failed ActivityFailed Activity
V 2.0 EVID 61125 ISE Removed ACI DomainSub RuleObject Deleted/RemovedAccess Success
V 2.0 EVID 61126 Failed To Remove ACI DomainSub RuleGeneral Failed ActivityFailed Activity
V 2.0 EVID 61127 ISE Learned A New SDA DomainSub RuleGeneral Audit MessageOther Audit
V 2.0 EVID 61128 ISE Failed Learn New SDA DomainSub RuleGeneral Failed ActivityFailed Activity
V 2.0 EVID 61129 ISE Removed SDA DomainSub RuleObject Deleted/RemovedAccess Success
V 2.0 EVID 61130 Failed To Remove SDA DomainSub RuleGeneral Failed ActivityFailed Activity
V 2.0 EVID 61131 ISE Domain Reg Rsp UnsuccessfulSub RuleUnsuccessful ActivityOther Audit Failure
V 2.0 EVID 61132 SDA Peering Initiation FailedSub RuleGeneral Failed ActivityFailed Activity
V 2.0 EVID 61133 SDA Successfully Initiated PeerSub RuleProcess/Service StartedStartup and Shutdown
V 2.0 EVID 61134 SDA Domain Advertisement FailedSub RuleGeneral Failed ActivityFailed Activity
V 2.0 EVID 61135 SDA Domain Advertisement FailedSub RuleGeneral Failed ActivityFailed Activity
V 2.0 EVID 61136 Successful SDA Domain AdvertiseSub RuleOperation SucceededInformation
V 2.0 EVID 61137 SDA Publishing SXP InformationSub RulePublish InformationInformation
V 2.0 EVID 61138 Error Processing MdpGatewayAdvSub RuleGeneral ErrorError
V 2.0 EVID 61139 Publishing SDA Gateway AdvertisSub RulePublish InformationInformation
V 2.0 EVID 61140 SDA Gateway Advertisement InfoSub RulePublish ErrorError
V 2.0 EVID 61141 Publishing SDA's VN InformationSub RulePublish InformationInformation
V 2.0 EVID 61142 Failed To Publish SDA's VN InfoSub RulePublish WarningWarning
V 2.0 EVID 61143 Publishing SDA's VN InformationSub RulePublish InformationInformation
V 2.0 EVID 61144 Failed Handling SDA's VN InfoSub RuleGeneral Failed ActivityFailed Activity
V 2.0 EVID 61145 Publishing SDA Extend VN RspSub RulePublish InformationInformation
V 2.0 EVID 61146 Failed To Publish SDA Extend VNSub RulePublish WarningWarning
V 2.0 EVID 61147 Message Cannot Publish To ACISub RulePublish WarningWarning
V 2.0 EVID 61148 Failed Parsing/Storing SDASub RuleGeneral Failed ActivityFailed Activity
V 2.0 EVID 61149 Failed Parsing/Storing SDA AckSub RuleGeneral Failed ActivityFailed Activity
V 2.0 EVID 61150 Publishing ACI Extend VN RspSub RulePublish InformationInformation
V 2.0 EVID 61151 Failed To Publish ACI Extend VNSub RulePublish WarningWarning
V 2.0 EVID 61152 ACI Notified ISE Received SDASub RuleGeneral Audit MessageOther Audit
V 2.0 EVID 61153 SDA Not Responded To ACI MsgSub RuleGeneral Audit MessageOther Audit
V 2.0 EVID 61154 ISE Successfully Rsp To PeeringSub RuleOperation SucceededInformation
V 2.0 EVID 61156 SDA Published SXP ConfigurationSub RulePublish InformationInformation
V 2.0 EVID 61157 SDA SXP Config Successfully RcvSub RuleConfiguration InformationInformation
V 2.0 EVID 61158 ISE Failed In Receiving SDA SXPSub RuleGeneral Failed ActivityFailed Activity
V 2.0 EVID 61159 ISE Publishing Gateway AdvertisSub RulePublish InformationInformation
V 2.0 EVID 61160 ISE Failed To Publish GatewaySub RulePublish WarningWarning
V 2.0 EVID 61161 ISE Learned New SXP ListenerSub RuleGeneral Audit MessageOther Audit
V 2.0 EVID 61162 ISE Updates VN Defined For SXPSub RuleObject ModifiedAccess Success
V 2.0 EVID 61163 ISE Learned New VN Defined ForSub RuleGeneral Audit MessageOther Audit
V 2.0 EVID 61164 ISE Updates SXP ListenerSub RuleObject ModifiedAccess Success
V 2.0 EVID 61165 ISE Removed All SXP ConnectionsSub RuleObject Deleted/RemovedAccess Success
V 2.0 EVID 61166 ACI Published Gateway AdvertiseSub RulePublish InformationInformation
V 2.0 EVID 61167 Send ACI Gateway AdvertisementSub RuleMessage SentInformation
V 2.0 EVID 61168 Failed To Send ACI Gateway AdvtSub RuleGeneral Failed ActivityFailed Activity
V 2.0 EVID 61169 Successfully Send ACI GatewaySub RuleMessage SentInformation
V 2.0 EVID 61170 SDA Published Peer Domain ReqSub RulePublish InformationInformation
V 2.0 EVID 61171 SDA Failed To Publish Peer DomSub RuleGeneral Failed ActivityFailed Activity
V 2.0 EVID 61172 SDA Published Peer Domain RspSub RulePublish InformationInformation
V 2.0 EVID 61173 SDA Failed To Publish Peer DomSub RulePublish WarningWarning
V 2.0 EVID 61174 Process Peer Domain RequestSub RuleGeneral Audit MessageOther Audit
V 2.0 EVID 61175 Process Peer Domain ResponseSub RuleGeneral Audit MessageOther Audit
V 2.0 EVID 61176 SDA Initiate Peering ProcessSub RuleGeneral Audit MessageOther Audit
V 2.0 EVID 61177 ACI Initiate Peering ProcessSub RuleGeneral Audit MessageOther Audit
V 2.0 EVID 61178 Peering Already ExistSub RuleGeneral Audit MessageOther Audit
V 2.0 EVID 61179 Peering Process Failed ACI DomSub RuleProcess FailedError
V 2.0 EVID 61180 Peering Process Failed SDA DomSub RuleProcess FailedError
V 2.0 EVID 61181 Peering Estab B/W SDA & ACISub RuleGeneral Audit MessageOther Audit
V 2.0 EVID 61182 SDA-ACI Peering Process FailedSub RuleProcess FailedError
V 2.0 EVID 61183 Received Peer Domain RequestSub RuleRequest ReceivedOther Audit Success
V 2.0 EVID 61184 Failed To Receive Peer DomainSub RuleGeneral Failed ActivityFailed Activity
V 2.0 EVID 61185 Publish Peer Domain RequestSub RulePublish InformationInformation
V 2.0 EVID 61186 Failed To Publish Peer DomainSub RulePublish WarningWarning
V 2.0 EVID 61187 Peering Status Created B/W ACISub RuleObject CreatedAccess Success
V 2.0 EVID 61188 Peering Status Removed B/W ACISub RuleObject Deleted/RemovedAccess Success
V 2.0 EVID 61189 Publishing Consumer To ACISub RulePublish InformationInformation
V 2.0 EVID 61190 Fail To Publish Consumer To ACISub RuleGeneral Failed ActivityFailed Activity
V 2.0 EVID 61191 Publishing Consumer Service ReqSub RulePublish InformationInformation
V 2.0 EVID 61192 Failed To Publish Consumer SvcSub RulePublish WarningWarning
V 2.0 EVID 61193 Consumer Service Frm ISE DeleteSub RuleObject Deleted/RemovedAccess Success
V 2.0 EVID 61194 Consumer Service Frm ISE DeleteSub RuleObject Deleted/RemovedAccess Success
V 2.0 EVID 61195 ISE Learned New SGACL From ACISub RuleGeneral Audit MessageOther Audit
V 2.0 EVID 61196 Failed To Learn New SGACL FromSub RuleGeneral Failed ActivityFailed Activity
V 2.0 EVID 61197 Successfully Updated SGACLSub RuleObject ModifiedAccess Success
V 2.0 EVID 61198 Failed To Update SGACL LearnedSub RuleGeneral Failed ActivityFailed Activity
V 2.0 EVID 61199 ACI Äôs SGACL Deleted From ISESub RuleObject Deleted/RemovedAccess Success
V 2.0 EVID 61200 Failed To Delete ACI Äôs SGACLSub RuleGeneral Failed ActivityFailed Activity
V 2.0 EVID 61201 Stored ACI Service In ISESub RuleGeneral Audit MessageOther Audit
V 2.0 EVID 61202 Failed To Store ACI ServiceSub RuleGeneral Failed ActivityFailed Activity
V 2.0 EVID 61203 ISE ACI Service UpdatedSub RuleObject ModifiedAccess Success
V 2.0 EVID 61204 Failed To Update ACI ServiceSub RuleGeneral Failed ActivityFailed Activity
V 2.0 EVID 61205 ISE ACI Service DeletedSub RuleObject Deleted/RemovedAccess Success
V 2.0 EVID 61206 Failed To Delete ACI ServiceSub RuleGeneral Failed ActivityFailed Activity
V 2.0 EVID 61207 Published MdpConsumerServiceReqSub RulePublish InformationInformation
V 2.0 EVID 61208 Failed To Publish MdpConsumerSeSub RulePublish WarningWarning
V 2.0 EVID 61209 ISE Propagated New EEPG To ACISub RuleGeneral Audit MessageOther Audit
V 2.0 EVID 61210 ISE Fail To Propagate New EEPGSub RuleGeneral Failed ActivityFailed Activity
V 2.0 EVID 61211 Received Endpoint Msg Frm ISESub RuleGeneral Endpoint MessageInformation
V 2.0 EVID 61212 Published Endpoint To ACISub RulePublish InformationInformation
V 2.0 EVID 61213 Fail To Publish Endpoint To ACISub RuleGeneral Failed ActivityFailed Activity
V 2.0 EVID 61214 Publishing Endpoints AdditionSub RulePublish InformationInformation
V 2.0 EVID 61215 Publishing Endpoints DeletionSub RulePublish InformationInformation
V 2.0 EVID 61216 Failed To Publish ACI BindingSub RulePublish WarningWarning
V 2.0 EVID 61217 Failed To Publish Msg To SXPSub RulePublish WarningWarning
V 2.0 EVID 61218 Published ACI Binding To SXPSub RulePublish InformationInformation
V 2.0 EVID 61219 Failed To Publish ACI BindingSub RulePublish WarningWarning
V 2.0 EVID 61220 Published SXP Binding From SXPSub RulePublish InformationInformation
V 2.0 EVID 61221 Failed To Published SXP BindingSub RulePublish WarningWarning
V 2.0 EVID 61222 Received EndPointGroup MessageSub RuleGeneral Endpoint MessageInformation
V 2.0 EVID 61223 ISE Failed To Store New SGTSub RuleGeneral Audit MessageOther Audit
V 2.0 EVID 61224 Received EndPointGroup MessageSub RuleGeneral Endpoint MessageInformation
V 2.0 EVID 61225 SGT Already Published To ACISub RulePublish InformationInformation
V 2.0 EVID 61226 Published SGT To ACISub RulePublish InformationInformation
V 2.0 EVID 61227 Failed Publishing SGT To ACISub RulePublish WarningWarning
V 2.0 EVID 61228 ISE Created New SGT BasedSub RuleObject CreatedAccess Success
V 2.0 EVID 61229 ISE Updated New SGT BasedSub RuleObject ModifiedAccess Success
V 2.0 EVID 61230 ISE Removed New SGT BasedSub RuleObject Deleted/RemovedAccess Success
V 2.0 EVID 61231 Kafka Connection To ACI ErrorSub RuleGeneral ErrorError
V 2.0 EVID 61232 Kafka Connection To ACI ErrorSub RuleGeneral ErrorError
V 2.0 EVID 61233 Handling ACI Message FailureSub RuleGeneral Failed ActivityFailed Activity
V 2.0 EVID 61234 Got Evt With Unknown PropertiesSub RuleGeneral Audit MessageOther Audit
V 2.0 EVID 61235 SDA Auth Against ACI SuccessfulSub RuleAuthentication ActivityAuthentication Success
V 2.0 EVID 61236 SDA Failed To Auth Against ACISub RuleAuthentication Failure ActivityAuthentication Failure
V 2.0 EVID 62000 Agentless Script Execute CompleSub RuleScript InformationInformation
V 2.0 EVID 62001 Agentless Script Execute FailedSub RuleScript InformationInformation
V 2.0 EVID 62002 Agentless Script Upload CompletSub RuleScript InformationInformation
V 2.0 EVID 62003 Agentless Script Upload FailedSub RuleScript InformationInformation
V 2.0 EVID 60181 PxGrid Cloud Device Cleanup ReqSub RuleCleanup CompletedInformation
V 2.0 EVID 61080 High Database Tablespace UsageSub RuleDatabase InformationInformation
V 2.0 EVID 61237 ACI Rejected SDA Peering ReqSub RuleRequest RejectedError
V 2.0 EVID 61238 SDA Rejected ACI Peering ReqSub RuleRequest RejectedError
V 2.0 EVID 61239 ACI Rejected SDA Delete PeeringSub RuleRequest RejectedError
V 2.0 EVID 61240 SDA Rejected ACI Delete PeeringSub RuleRequest RejectedError
V 2.0 EVID 61241 ACI Rejected SDA Extend VN ReqSub RuleRequest RejectedError
V 2.0 EVID 61242 ACI Rejected SDA Delete ExtendSub RuleRequest RejectedError
V 2.0 EVID 61243 ACI Rejected SDA Consume SvcSub RuleRequest RejectedError
V 2.0 EVID 61246 ACI Rejected SDA Delete ConsumeSub RuleRequest RejectedError
V 2.0 EVID 61244 PxGrid Not Enabled & ConnectedSub RulePublish WarningWarning
V 2.0 EVID 61245 PxGrid Failed To Publish BindingSub RuleGeneral Failed ActivityFailed Activity
V 2.0 EVID 62004 Posture Remediation Event RcvdSub RuleGeneral Audit MessageOther Audit
V 2.0 EVID 62005 Vulnerability Scan FailureSub RuleGeneral Failed ActivityFailed Activity
V 2.0 EVID 61300 Network Access Policy RequestSub RuleGeneral POLICY InformationInformation
V 2.0 EVID 61301 Device Admin Policy RequestSub RuleGeneral POLICY InformationInformation
V 2.0 EVID 61302 Policy Pomponent RequestSub RuleGeneral POLICY InformationInformation
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.