Skip to main content
Skip table of contents

V 2.0 Guest Event

Vendor Documentation

Classification

Rule NameRule TypeCommon EventClassification
V 2.0 Guest EventBase RuleGeneral Information Log MessageInformation
V 2.0 EVID: 86001 Guest User Logged InSub RuleUser LogonAuthentication Success
V 2.0 EVID: 86002 Guest Account SuspendedSub RuleAccess Revoked ActivityAccess Revoked
V 2.0 EVID: 86003 Guest Account EnabledSub RuleAccount EnabledAccess Granted
V 2.0 EVID: 86004 Password Changed By Guest UserSub RulePassword ModifiedAccount Modified
V 2.0 EVID: 86005 Policy Accepted By Guest UserSub RulePolicy Created: User/PasswordPolicy
V 2.0 EVID: 86006 Guest Account CreatedSub RuleUser Account CreatedAccount Created
V 2.0 EVID: 86007 Guest Account UpdatedSub RuleUser Account Attribute ModifiedAccount Modified
V 2.0 EVID: 86008 Guest Account DeletedSub RuleUser Account DeletedAccount Deleted
V 2.0 EVID: 86009 Guest Account Not FoundSub RuleUser Not FoundError
V 2.0 EVID: 86010 Guest User Auth FailureSub RuleUser Logon FailureAuthentication Failure
V 2.0 EVID: 86011 Guest User Not EnabledSub RuleUser Logon Failure: Account DisabledAuthentication Failure
V 2.0 EVID: 86012 Access Policy Declined By GuestSub RulePolicy Disabled: User/PasswordPolicy
V 2.0 EVID: 86013 Portal Not FoundSub RuleDefault Address Not FoundError
V 2.0 EVID: 86014 User Account SuspendedSub RuleAccess Revoked ActivityAccess Revoked
V 2.0 EVID: 86015 Invalid Password ChangeSub RulePassword ModifiedAccount Modified
V 2.0 EVID: 86016 Guest Timout ExceededSub RuleUser Disconnected Due To Time OutInformation
V 2.0 EVID: 86017 SessionID MissingSub RuleSession Could Not Be EstablishedWarning
V 2.0 EVID: 86018 Guest CoA FailedSub RuleAuthorization FailedWarning
V 2.0 EVID: 86019 Guest User RestrictedSub RuleAccess Revoked ActivityAccess Revoked
V 2.0 EVID: 86020 Guest Unknown ErrorSub RuleUnknown ErrorError
V 2.0 EVID: 86021 Entering Device Reg Web AuthSub RuleDevice RegisteredInformation
V 2.0 EVID: 86022 Device Reg Web Auth AUP AcceptSub RuleDevice RegisteredOther Audit Success
V 2.0 EVID: 86023 Device Re Web Auth AUP DeclinedSub RulePolicy Disabled: DomainPolicy
V 2.0 EVID: 86024 Dev Reg WAP EP Creation PassedSub RuleDevice RegisteredOther Audit Success
V 2.0 EVID: 86025 Dev Reg WAP EP Creation FailedSub RuleCommunication Endpoint Creation FailureError
V 2.0 EVID: 86026 Dev Reg WAP CoA Termination FailSub RuleProcess Termination FailedError
V 2.0 EVID: 86027 Dev Reg WAP Send CoA TerminationSub RuleRegistrationInformation
V 2.0 EVID: 86028 CoA Termination SuccessSub RuleUser Session TerminatedInformation
V 2.0 EVID: 86029 CoA Termination FailedSub RuleProcess Termination FailedError
V 2.0 EVID: 86030 Policy Accepted By Sponsor UserSub RuleUser Account CreatedAccount Created
V 2.0 EVID: 86031 Policy Declined By Sponsor UserSub RulePolicy Disabled: User/PasswordPolicy

Mapping with LogRhythm Schema

Rule NameRule TypeCommon EventClassification
pri_numN/AN/APriority value of the message, a combination of the facility value and the severity value of the message. Priority value = (facility value * 8) + severity value.
The facility code valid options are:
LOCAL0 (Code = 16)
LOCAL1 (Code = 17)
LOCAL2 (Code = 18)
LOCAL3 (Code = 19)
LOCAL4 (Code = 20)
LOCAL5 (Code = 21)
LOCAL6 (Code = 22; default)
LOCAL7 (Code = 23)
timeN/AN/ADate of the message generation, according to the local clock of the originating Cisco ISE server, in the format Mmm DD hh:mm:ss.
IP address/hostnameN/AN/AIP address of the originating Cisco ISE node, or the hostname.
cat_name<vendorinfo>Text/StringLogging category name preceded by the CSCOxxx string.
msg_idN/AN/AUnique message ID; 1 to 4294967295. The message ID increases by 1 with each new message. Message IDs restart at 1 each time the application is restarted.
total_segN/AN/ATotal number of segments in a log message. Long messages are divided into more than one segment.
Note: The total_seg depends on the Maximum Length setting in the remote logging targets page. See Remote Logging Target Settings.
seg_numN/AN/ASegment sequence number within a message. Use this number to determine what segment of the message you are viewing.
timestampN/AN/ADate of the message generation, according to the local clock of the originating the Cisco ISE node, in the following format: 
YYYY-MM-DD hh:mm:ss:xxx +/-zh:zm.
sequence_numN/AN/AGlobal counter of each message. If one message is sent to the local store and the next to the syslog server target, the counter increments by 2. Possible values are 0000000001 to 999999999.
msg_code<vmid>
<tag1>
NumberMessage code as defined in the logging categories.
msg_sev<severity>Text/StringMessage severity level of a log message.
msg_class<subject> Text/StringMessage class, which identifies groups of messages with the same context.
msg_text<action> Text/StringEnglish language descriptive text message.
ConfigVersionIdN/AN/AN/A
UserTypeN/AN/AN/A
UserName<account>Text/StringN/A
FirstnameN/AN/AN/A
LastnameN/AN/AN/A
PhoneNumberN/AN/AN/A
MacAddress<smac>Text/StringN/A
IpAddress<sip>IP AddressN/A
AuthenticationIdentityStoreN/AN/AN/A
PortalNameN/AN/AN/A
SponsorUserN/AN/AN/A
IdentityGroupN/AN/AN/A
PsnHostNameN/AN/AN/A
GuestUserN/AN/AN/A
GuestUserNameN/AN/AN/A
GuestFirstnameN/AN/AN/A
GuestLastnameN/AN/AN/A
GuestEmailAddressN/AN/AN/A
GuestAuthenticationIdentityStoreN/AN/AN/A
GuestTypeN/AN/AN/A
GuestValidDaysN/AN/AN/A
GuestLocationN/AN/AN/A
GuestStatusN/AN/AN/A
EPMacAddressN/AN/AN/A
NADAddressN/AN/AN/A
ResponseTimeN/AN/AN/A
ETSN/AN/AN/A
Key1N/AN/AN/A
Key2N/AN/AN/A
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.