Skip to main content
Skip table of contents

AppLocker Events

Vendor Documentation

Classification

Rule NameRule TypeCommon EventClassification
AppLocker EventsBase RuleProductionGeneral Logging InformationInformation
EVID 8001 : Policy Successfully AppliedSub RuleProductionConfiguration Enabled : ApplicationConfiguration
EVID 8002 : EXE Or DLL Allowed To RunSub RuleProductionProcess/Service StartedStartup and Shutdown
EVID 8003 : Process Allowed But Would Be BlockedSub RuleProductionProcess/Service StartedStartup and Shutdown
EVID 8004 : Process Not Allowed To RunSub RuleProductionProcess FailedError
EVID 8005 : Script Or MSI Allowed To RunSub RuleProductionProcess/Service StartedStartup and Shutdown
EVID 8006 : Process Allowed But Would Be BlockedSub RuleProductionProcess/Service StartedStartup and Shutdown
EVID 8007 : Process Not Allowed To RunSub RuleProductionProcess FailedError
EVID 8008 : AppLocker Disabled On The SKUSub RuleProductionFeature DisabledInformation
EVID 8020 : Packaged App AllowedSub RuleProductionGeneral Application InformationInformation
EVID 8021 : Packaged App AuditedSub RuleProductionGeneral Audit MessageOther Audit
EVID 8022 : Packaged App DisabledSub RuleProductionDisabledInformation
EVID 8023 : Packaged App Installation AllowedSub RuleProductionGeneral Application InformationInformation
EVID 8024 : Packaged App Installation AuditedSub RuleProductionGeneral Audit MessageOther Audit
EVID 8025 : Packaged App Installation DisabledSub RuleProductionDisabledInformation
EVID 8027 : No Packaged App Rule ConfiguredSub RuleProductionFailed ConfigurationOther Audit Failure

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

<eventid><vmid>Number
execution processid<processid>Number
<channel><tag1>Text/String
<computer><sname>Text/String
<security userid><domain>Text/String
<security userid><login>Text/String
<UserData><vendorinfo>Text/String
<UserData><object>Text/String
<UserData><objectname>Text/String
was<tag2>Text/String


JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.