Catch All : ESENT Messages

Classification

Rule Name

Rule Type

Common Event

Classification

Catch All : ESENT Messages

Base Rule

Database Information

Information

VMID 102 : Database Engine Starting New Instance

Sub Rule

General ESENT Information

Information

VMID 103 : Database Engine Stopped An Instance

Sub Rule

General ESENT Information

Information

VMID 104 : Application Log Cleared

Sub Rule

Log Cleared

Access Success

VMID 105 : Database Engine Started New Instance

Sub Rule

General ESENT Information

Information

VMID 326 : Database Engine Attached A Database

Sub Rule

General ESENT Information

Information

VMID 327 : Database Engine Attached A Database

Sub Rule

General ESENT Information

Information

VMID 412 : DNS Bound High Number of IPs

Sub Rule

General DNS Error

Error

VMID 413 : Cannot Create New Log File

Sub Rule

Failed Audit Log Write

Other Audit Failure

VMID 428 : Failed To Update Database

Sub Rule

Update Failed

Error

VMID 454 : Multiple Mac Addresses Detected

Sub Rule

MAC Address Addition Failed

Error

VMID 455 : Failed To Open File

Sub Rule

Failed To Open File

Error

VMID 471 : Unable To Execute Rollback Operation

Sub Rule

Failed Rollback Command

Error

VMID 482 : Failed To Write Into File

Sub Rule

File Write Failure

Error

VMID 486 : File Move Failure

Sub Rule

Move Object Failure

Access Failure

VMID 492 : Logging Stopped

Sub Rule

Failed Audit Log Write

Other Audit Failure

VMID 507 : Abnormally Long Access Time - HW Error

Sub Rule

Hardware Problem

Warning

VMID 508 : Abnormally Long Access Time - HW Error

Sub Rule

Hardware Problem

Warning

Mapping with LogRhythm Schema  

Device Key in log message

LogRhythm Schema

Data Type

Provider Name

<vendorinfo>

Text/String

EventID Qualifiers

<vmid>

Number

Level

<severity>

Text/String

N/A

<process>

Text/String

Computer

<dname>

Text/String

N/A

<processid>

Number/Text/String