Catch All : ESENT Messages
Classification
Rule Name | Rule Type | Common Event | Classification |
|---|---|---|---|
| Catch All : ESENT Messages | Base Rule | Database Information | Information |
| VMID 102 : Database Engine Starting New Instance | Sub Rule | General ESENT Information | Information |
| VMID 103 : Database Engine Stopped An Instance | Sub Rule | General ESENT Information | Information |
| VMID 104 : Application Log Cleared | Sub Rule | Log Cleared | Access Success |
| VMID 105 : Database Engine Started New Instance | Sub Rule | General ESENT Information | Information |
| VMID 326 : Database Engine Attached A Database | Sub Rule | General ESENT Information | Information |
| VMID 327 : Database Engine Attached A Database | Sub Rule | General ESENT Information | Information |
| VMID 412 : DNS Bound High Number of IPs | Sub Rule | General DNS Error | Error |
| VMID 413 : Cannot Create New Log File | Sub Rule | Failed Audit Log Write | Other Audit Failure |
| VMID 428 : Failed To Update Database | Sub Rule | Update Failed | Error |
| VMID 454 : Multiple Mac Addresses Detected | Sub Rule | MAC Address Addition Failed | Error |
| VMID 455 : Failed To Open File | Sub Rule | Failed To Open File | Error |
| VMID 471 : Unable To Execute Rollback Operation | Sub Rule | Failed Rollback Command | Error |
| VMID 482 : Failed To Write Into File | Sub Rule | File Write Failure | Error |
| VMID 486 : File Move Failure | Sub Rule | Move Object Failure | Access Failure |
| VMID 492 : Logging Stopped | Sub Rule | Failed Audit Log Write | Other Audit Failure |
| VMID 507 : Abnormally Long Access Time - HW Error | Sub Rule | Hardware Problem | Warning |
| VMID 508 : Abnormally Long Access Time - HW Error | Sub Rule | Hardware Problem | Warning |
Mapping with LogRhythm Schema
Device Key in log message | LogRhythm Schema | Data Type |
|---|---|---|
| Provider Name | <vendorinfo> | Text/String |
| EventID Qualifiers | <vmid> | Number |
| Level | <severity> | Text/String |
| N/A | <process> | Text/String |
| Computer | <dname> | Text/String |
| N/A | <processid> | Number/Text/String |