Skip to main content
Skip table of contents

V 2.0 AD Connector Event

Vendor Documentation


Rule NameRule TypeCommon EventClassification
V 2.0 AD Connector EventBase RuleGeneral Information Log MessageInformation
V 2.0 EVID 25000: ISE Server Pwd Update SuccessSub RulePerforming Password ChangeInformation
V 2.0 EVID 25001: ISE Server Pwd Update FailureSub RulePassword Change FailedError
V 2.0 EVID 25002: ISE Server TGT Refresh SuccessSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 25003: Machine TGT Refresh FailureSub RuleGeneral Action FailureError
V 2.0 EVID 25004: AD Connector StartSub RuleProcess/Service StartedStartup and Shutdown
V 2.0 EVID 25005: AD Connector StoppedSub RuleProcess/Service StoppedStartup and Shutdown
V 2.0 EVID 25006: AD Connector RestartSub RuleProcess/Service StoppedStartup and Shutdown
V 2.0 EVID 25007: Join Point Connector StartSub RuleProcess/Service StoppedStartup and Shutdown
V 2.0 EVID 25008: Join Point Connector StopSub RuleProcess/Service StoppedStartup and Shutdown
V 2.0 EVID 25009: Trusted Domain Discovery SuccessSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 25010: Trusted Domain Discovery FailureSub RuleGeneral Action FailureError
V 2.0 EVID 25011: Domain Join SuccessSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 25012: Domain Join FailureSub RuleGeneral Action FailureError
V 2.0 EVID 25013: Domain Leave SuccessSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 25014:  Domain Leave FailureSub RuleGeneral Action FailureError
V 2.0 EVID 25015: DNS SRV Query SuccessSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 25016: DNS SRV Query FailureSub RuleDNS Query FailedError
V 2.0 EVID 25017: DC Discovery SuccessSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 25018: DC Discovery FailureSub RuleDomain Controller UnreachableError
V 2.0 EVID 25019: KDC Discovery SuccessSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 25020: KDC Discovery FailureSub RuleGeneral Action FailureError
V 2.0 EVID 25021: GC Discovery SuccessSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 25022: GC Discovery FailureSub RuleGeneral Action FailureError
V 2.0 EVID 25023: LDAP Connect To DC SuccessSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 25024: LDAP Connect To DC FailureSub RuleGeneral Action FailureError
V 2.0 EVID 25025: LDAP Connect To GC SuccessSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 25026: LDAP Connect To GC FailureSub RuleGeneral Action FailureError
V 2.0 EVID 25027: RPC Connect To DC SuccessSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 25028: RPC Connect To DC FailureSub RuleGeneral Action FailureError
V 2.0 EVID 25029: KDC Connect To DC SuccessSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 25030: KDC Connect To DC FailureSub RuleGeneral Action FailureError
V 2.0 EVID 25031: AD Provider Failed To StartSub RuleServer Failed To StartError
V 2.0 EVID 25032: Trusted Domain DiscoveredSub RuleDomain Trust InformationInformation
V 2.0 EVID 25033: DNS A/AAAA Query SuccessSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 25034: DNS A/AAAA Query FailureSub RuleDNS Query FailedError
V 2.0 EVID 25035: Writeable DC Discovery SuccessSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 25036: Writeable DC Discovery FailureSub RuleGeneral Action FailureError
V 2.0 EVID 25037: DC Record CachedSub RuleCache InformationInformation
V 2.0 EVID 25038: GC Record CachedSub RuleCache InformationInformation
V 2.0 EVID 25039: LDAP SASL Bind FailureSub RuleSASLAUTHD ErrorError
V 2.0 EVID 25040: RPC SC Establishment FailureSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 25041: ISE Server Site DiscoveredSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 25042: ISE Server Not Assigned To ADSub RuleGeneral Active Directory WarningWarning
V 2.0 EVID 25043: No DC Found In ISE Server SiteSub RuleTime Service Couldn't Find Domain ControllerWarning
V 2.0 EVID 25044: Communication To Domain FailureSub RuleCommunications FailedError
V 2.0 EVID 25045: Configured NameServer DownSub RuleThe Server Is DownInformation
V 2.0 EVID 25046: Joined Domain Is UnavailableSub RuleRADIUS Domain UnavailableError
V 2.0 EVID 25047: Auth Domain Is UnavailableSub RuleRADIUS Domain UnavailableError
V 2.0 EVID 25048: AD Forest Is UnavailableSub RuleGeneral Active Directory InformationInformation
V 2.0 EVID 25049: Machine Account Not FoundSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 25050: Machine Account Deleted From ADSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 25051: Machine Account Deletion FailedSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 25052: Periodic Trusts Discovery StartSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 25053: Detected Offline ForestSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 25054: Trust Removed By DiscoverySub RuleGeneral Information Log MessageInformation
V 2.0 EVID 25055: DC Added To BlacklistSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 25056: DC Removed From BlacklistSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 25057: No Privileges For ISE Mac Acc.Sub RuleInsufficient PrivilegesError
V 2.0 EVID 25058: ISE Is Not Joined To AD DCSub RuleGeneral Active Directory ErrorError
V 2.0 EVID 25100: Connecting To External REST IDSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 25101: Successful Connect To Ext RESTSub RuleConnection EstablishedNetwork Traffic
V 2.0 EVID 25102: Connection To Ext REST DB FailSub RuleGeneral Database ErrorError
V 2.0 EVID 25103: Plain Text Pwd Auth In Ext RESTSub RuleGeneral Authentication InformationInformation
V 2.0 EVID 25104: Plain Text Pwd Auth SuccessSub RuleAuthentication ActivityAuthentication Success
V 2.0 EVID 25105: Plain Text Pwd Auth FailureSub RuleAuthentication Failure ActivityAuthentication Failure
V 2.0 EVID 25106: REST Indicated Pwd Auth FailureSub RuleAuthentication Failure ActivityAuthentication Failure
V 2.0 EVID 25107: REST ID Store Server RespondSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 25108: No User Groups Included To RESTSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 25109: ISE Starts Set User GroupsSub RuleCache InformationInformation
V 2.0 EVID 25110: User Grp Insert To Session CacheSub RuleCache InformationInformation
V 2.0 EVID 25111: Failed To Set User GroupsSub RuleCache InformationInformation
V 2.0 EVID 25112: REST DB Indicated Pwd Auth FailSub RuleAuthentication Failure ActivityAuthentication Failure
V 2.0 EVID 25113: Skipping AD AuthenticationSub RuleGeneral Active Directory WarningWarning
V 2.0 EVID 25114: Low Bad Password For AD InstanceSub RuleGeneral Active Directory ErrorError
V 2.0 EVID 25115: Fail To Fetch User Attr From ADSub RuleGeneral Active Directory ErrorError
V 2.0 EVID 25116: No Bad Pwd Count Attribute In ADSub RuleGeneral Active Directory ErrorError
V 2.0 EVID 25117: AD Is Part Of ID SequenceSub RuleGeneral Active Directory WarningWarning

Mapping with LogRhythm Schema

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
pri_numN/AN/APriority value of the message, a combination of the facility value and the severity value of the message. Priority value = (facility value * 8) + severity value.
The facility code valid options are:
LOCAL0 (Code = 16)
LOCAL1 (Code = 17)
LOCAL2 (Code = 18)
LOCAL3 (Code = 19)
LOCAL4 (Code = 20)
LOCAL5 (Code = 21)
LOCAL6 (Code = 22; default)
LOCAL7 (Code = 23)
timeN/AN/ADate of the message generation, according to the local clock of the originating Cisco ISE server, in the format Mmm DD hh:mm:ss.
IP address/hostnameN/AN/AIP address of the originating Cisco ISE node, or the hostname.
cat_name<vendorinfo>Text/StringLogging category name preceded by the CSCOxxx string.
msg_idN/AN/AUnique message ID; 1 to 4294967295. The message ID increases by 1 with each new message. Message IDs restart at 1 each time the application is restarted.
total_segN/AN/ATotal number of segments in a log message. Long messages are divided into more than one segment.
Note: The total_seg depends on the Maximum Length setting in the remote logging targets page. See Remote Logging Target Settings.
seg_numN/AN/ASegment sequence number within a message. Use this number to determine what segment of the message you are viewing.
timestampN/AN/ADate of the message generation, according to the local clock of the originating the Cisco ISE node, in the following format: YYYY-MM-DD hh:mm:ss:xxx +/-zh:zm.
sequence_numN/AN/AGlobal counter of each message. If one message is sent to the local store and the next to the syslog server target, the counter increments by 2. Possible values are 0000000001 to 999999999.
NumberMessage code as defined in the logging categories.
msg_sev<severity>Text/StringMessage severity level of a log message.
msg_class<subject> Text/StringMessage class, which identifies groups of messages with the same context.
msg_text<action> Text/StringEnglish language descriptive text message.
AD-IP-Address<sip>IP AddressN/A
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.