Skip to main content
Skip table of contents

V 2.0 Distributed Management Event

Vendor Documentation

Classification

Rule NameRule TypeCommon EventClassification
V 2.0 Distributed Management EventBase RuleGeneral Application Management InformationInformation
V 2.0 EVID: 41000 Memory Statistics Not FoundSub RuleMemory Statistics Not FoundWarning
V 2.0 EVID: 41001 Total Memory Not FoundSub RuleTotal Memory Not FoundWarning
V 2.0 EVID: 41002 Total Swap Not FoundSub RuleTotal Swap Not FoundWarning
V 2.0 EVID: 41003 Disk Size Not FoundSub RuleDisk Size Not FoundError
V 2.0 EVID: 41004 Disk Device Not FoundSub RuleDisk Device Not FoundError
V 2.0 EVID: 41005 ISE Version Not FoundSub RuleSoftware Version Not FoundError
V 2.0 EVID: 41007 ISE Node Record FoundSub RuleGeneric RecordInformation
V 2.0 EVID: 41008 ISE Node Record OverrideSub RuleObject OverriddenInformation
V 2.0 EVID: 41009 Default ISE Deployment CreatedSub RuleObject CreatedAccess Success
V 2.0 EVID: 41010 Default ISE Node CreatedSub RuleObject CreatedAccess Success
V 2.0 EVID: 41011 Node Status InitializedSub RuleNode Status InitializedInformation
V 2.0 EVID: 41012 Secondary ISE RegisteredSub RuleDevice RegisteredOther Audit Success
V 2.0 EVID: 41013 ISE Node DeregisteredSub RuleDevice UnregisteredWarning
V 2.0 EVID: 41014 Software Version Not FoundSub RuleSoftware Version Not FoundError
V 2.0 EVID: 41015 System Call Could Not RunSub RuleFailed System CallError
V 2.0 EVID: 41016 System Call Could Not Run StdoutSub RuleFailed System CallError
V 2.0 EVID: 41017 Hostname Not FoundSub RuleHostname Not FoundWarning
V 2.0 EVID: 41018 Svc Selection Policy Update FailSub RuleUpdate FailedError
V 2.0 EVID: 41019 Relation Not AddedSub RuleCould Not Add Relation To Service Selection PolicyError
V 2.0 EVID: 41020 Svc Selection Policy Init. FailSub RuleInitialization FailedError
V 2.0 EVID: 41021 ISE Node Object Not UpdatedSub RuleObject Update FailedError
V 2.0 EVID: 41022 NodeInfo Collection Error OccurSub RuleNodeInfo Collection ErrorError
V 2.0 EVID: 41023 Replication Status Collec ErrorSub RuleReplication Status ErrorError
V 2.0 EVID: 41024 Error Loading NodeinfoSub RuleNodeInfo Loading ErrorError
V 2.0 EVID: 41025 NodeInfo Incomplete InformationSub RuleNodeInfo File IncompleteError
V 2.0 EVID: 41026 Mgmt Config Directory Not CreateSub RuleDirectory Not FoundOther Operations
V 2.0 EVID: 41027 Nodinfo Could Not Be CreatedSub RuleACSNodeInfo Could Not Be CreatedError
V 2.0 EVID: 41028 MAC Address Not FoundSub RuleMAC Address Not FoundWarning
V 2.0 EVID: 41029 ISE Not Start As Record UnfoundSub RuleError Retrieving RecordError
V 2.0 EVID: 41030 MAC ID Not Found In ACSNodeInfoSub RuleInvalid MAC AddressError
V 2.0 EVID: 41031 Secondary Hostname Already ExistSub RuleHostname Already ExistsWarning
V 2.0 EVID: 41032 Secondary MAC Addr Already ExistSub RuleMAC Address Already ExistsWarning
V 2.0 EVID: 41033 Deregistration FailedSub RuleDeregister FailedError
V 2.0 EVID: 41034 Activation FailedSub RuleActivation FailedError
V 2.0 EVID: 41035 Connection FailedSub RuleConnection FailureError
V 2.0 EVID: 41036 ISE Node Deregistration FailedSub RuleDeregister FailedError
V 2.0 EVID: 41037 Initialization FailedSub RuleInitialization FailedError
V 2.0 EVID: 41038 Interface Config Not FoundSub RuleConfiguration Notification Message ErrorError
V 2.0 EVID: 41039 Interface Eth0 Not FoundSub RuleInterface Not FoundWarning
V 2.0 EVID: 41040 Eth0 Hardware Address Not FoundSub RuleDefault Address Not FoundError
V 2.0 EVID: 41041 Eth0 Inet Address Not FoundSub RuleDefault Address Not FoundError
V 2.0 EVID: 41042 Eth0 Mask Not FoundSub RuleInvalid MaskWarning
V 2.0 EVID: 41043 ACSNodeInfo Not CreatedSub RuleACSNodeInfo Could Not Be CreatedError
V 2.0 EVID: 41044 ACS Instance Reconnection FailedSub RuleReconnection ACS Instance Could Not Be FoundError
V 2.0 EVID: 41045 Replacement Keyword Already RegSub RuleKeyword Associated With InstanceError
V 2.0 EVID: 41046 ISE Instance Reg To Primary NodeSub RuleInstance InformationInformation
V 2.0 EVID: 41047 Primary Node Full Data SyncSub RuleSync StartedInformation
V 2.0 EVID: 41048 ACSNode Replace SuccessSub RuleACSNode ReplacedInformation
V 2.0 EVID: 41049 ACSNode Reg To Primary NodeSub RuleRegister NodeInformation
V 2.0 EVID: 41050 ACSNode Activated On PrimarySub RuleActivating ACSNodeInformation
V 2.0 EVID: 41051 ACSNode Deactivated On PrimarySub RuleACS Node DeregisteredInformation
V 2.0 EVID: 41053 ISE Inst Promoted To Prim. NodeSub RuleInstance InformationInformation
V 2.0 EVID: 41054 ISE Inst Swtiching To Local ModeSub RuleInstance InformationInformation
V 2.0 EVID: 41055 Node Upgrading To New VersionSub RuleUpgrade StartedInformation
V 2.0 EVID: 41056 Software Upgared Applied To ISESub RuleUpgrade InformationInformation
V 2.0 EVID: 41057 Automatic Backup Being CreatedSub RuleCreating Automatic BackupOther Audit Success
V 2.0 EVID: 41058 Downloading Bundle For PrimarySub RuleDownloading BundleInformation
V 2.0 EVID: 41059 Node Upgrade CompleteSub RuleUpgrade CompleteInformation
V 2.0 EVID: 41060 Enabling Log Collector TargetSub RuleEnabledInformation
V 2.0 EVID: 41061 Disabling Log Collector TargetSub RuleDisabling Log Collector TargetInformation
V 2.0 EVID: 41062 Log Collector Node SelectedSub RuleLog Collector SetInformation
V 2.0 EVID: 41063 Remote Syslog Target CreatedSub RuleGeneral Syslog InformationInformation
V 2.0 EVID: 41064 Log Collector Deregister FailedSub RuleDeregister FailedError
V 2.0 EVID: 41065 Apply Upgrade Diagnostic MessageSub RuleApply Upgrade Diagnostic MessageInformation

Mapping with LogRhythm Schema

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
pri_numN/AN/APriority value of the message, a combination of the facility value and the severity value of the message. Priority value = (facility value * 8) + severity value.
The facility code valid options are:
LOCAL0 (Code = 16)
LOCAL1 (Code = 17)
LOCAL2 (Code = 18)
LOCAL3 (Code = 19)
LOCAL4 (Code = 20)
LOCAL5 (Code = 21)
LOCAL6 (Code = 22; default)
LOCAL7 (Code = 23)
timeN/AN/ADate of the message generation, according to the local clock of the originating Cisco ISE server, in the format Mmm DD hh:mm:ss.
IP address/hostnameN/AN/AIP address of the originating Cisco ISE node, or the hostname.
cat_name<vendorinfo>Text/StringLogging category name preceded by the CSCOxxx string.
msg_idN/AN/AUnique message ID; 1 to 4294967295. The message ID increases by 1 with each new message. Message IDs restart at 1 each time the application is restarted.
total_segN/AN/ATotal number of segments in a log message. Long messages are divided into more than one segment.
Note: The total_seg depends on the Maximum Length setting in the remote logging targets page. See Remote Logging Target Settings.
seg_numN/AN/ASegment sequence number within a message. Use this number to determine what segment of the message you are viewing.
timestampN/AN/ADate of the message generation, according to the local clock of the originating the Cisco ISE node, in the following format: 
YYYY-MM-DD hh:mm:ss:xxx +/-zh:zm.
sequence_numN/AN/AGlobal counter of each message. If one message is sent to the local store and the next to the syslog server target, the counter increments by 2. Possible values are 0000000001 to 999999999.
msg_code<vmid>
<tag1>
NumberMessage code as defined in the logging categories.
msg_sev<severity>Text/StringMessage severity level of a log message.
msg_class<subject> Text/StringMessage class, which identifies groups of messages with the same context.
msg_text<action> Text/StringEnglish language descriptive text message.
Key1N/AN/AN/A
Key2N/AN/AN/A
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.