Skip to main content
Skip table of contents

V 2.0 Internal MDM Event

Vendor Documentation

Classification

Rule NameRule TypeCommon EventClassification
V 2.0 Internal MDM EventBase RuleGeneral MDM InformationInformation
V 2.0 EVID 89050 Administrative Action SubmittedSub RuleGeneral Administrative OperationInformation
V 2.0 EVID 89051 Administrative Action DeliveredSub RuleGeneral Administrative OperationInformation
V 2.0 EVID 89052 Administrative Action FailedSub RuleAction FailureError
V 2.0 EVID 89100 Device Enrollment InitiatedSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 89101 Device Enrollment FailedSub RuleDevice Initialization FailedCritical
V 2.0 EVID 89102 Device Enrolled SuccessfullySub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 89103 Device DeregisteredSub RuleDevice UnregisteredWarning
V 2.0 EVID 89104 Device Service InitializedSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 89105 Device Svc Initialization FailSub RuleGeneral Failed ActivityFailed Activity
V 2.0 EVID 89106 Device Service StoppedSub RuleProcess/Service StoppedStartup and Shutdown
V 2.0 EVID 89107 Unable To Send NotificationsSub RuleGeneral NotificationInformation
V 2.0 EVID 89108 APNS Certificate ExpiredSub RuleCertificate ExpiredWarning
V 2.0 EVID 89109 Endpoint Certificate ExpireSub RuleCertificate ExpiredWarning
V 2.0 EVID 89110 Dev Check Not Auth. Expired CertSub RuleCertificate ExpiredWarning
V 2.0 EVID 89111 Device Check AuthorizedSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 89112 Certificate RenewedSub RuleCertificate Renewal RequestActivity
V 2.0 EVID 89113 Inactive Device DetectedSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 89114 GeoLocation Coordinates ReceiveSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 89115 Profile InstalledSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 89116 Profile RemovedSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 89117 Application InstalledSub RuleGeneral Application InformationInformation
V 2.0 EVID 89118 Application RemovedSub RuleGeneral Application InformationInformation
V 2.0 EVID 89119 Device Reassessment FailedSub RuleGeneral Failed ActivityFailed Activity
V 2.0 EVID 89132 Endpoint Cert Going To ExpiredSub RuleGeneral Endpoint MessageInformation
V 2.0 EVID 89133 Endpoint Certificate ExpiredSub RuleGeneral Endpoint MessageInformation
V 2.0 EVID 89142  Provisioning Operation FailedSub RuleProvisioning FailedWarning
V 2.0 EVID 89143 Device UpdatedSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 89144 Certificate Renewal FailedSub RuleGeneral Failed ActivityFailed Activity
V 2.0 EVID 89149 Device CompliantSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 89150 Device Not CompliantSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 89151 Cert Issued Can Be RevokedSub RuleRevoke Certificate RequestActivity
V 2.0 EVID 89152 Mob Dev Unenrollment InitiatedSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 89153 Cert Missing For NotifificationSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 89154 Invalid Token TO Apple VPPSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 89155 Access Failed To Apple VPPSub RuleAccess Object FailureAccess Failure
V 2.0 EVID 89156 CMCS Server UnreachableSub RuleDestination UnreachableError
V 2.0 EVID 89157 CMCS Authentication FailureSub RuleAuthentication Failure ActivityAuthentication Failure
V 2.0 EVID 89158 APNS Server UnreachableSub RuleDestination UnreachableError
V 2.0 EVID 89159 APNS Authentication FailureSub RuleAuthentication Failure ActivityAuthentication Failure
V 2.0 EVID 89160 MDM User Auth CompletedSub RuleAuthentication CompleteInformation

Mapping with LogRhythm Schema

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
pri_numN/AN/APriority value of the message, a combination of the facility value and the severity value of the message. Priority value = (facility value * 8) + severity value.
The facility code valid options are:
LOCAL0 (Code = 16)
LOCAL1 (Code = 17)
LOCAL2 (Code = 18)
LOCAL3 (Code = 19)
LOCAL4 (Code = 20)
LOCAL5 (Code = 21)
LOCAL6 (Code = 22; default)
LOCAL7 (Code = 23)
timeN/AN/ADate of the message generation, according to the local clock of the originating Cisco ISE server, in the format Mmm DD hh:mm:ss.
IP address/hostnameN/AN/AIP address of the originating Cisco ISE node, or the hostname.
cat_name<vendorinfo>Text/StringLogging category name preceded by the CSCOxxx string.
msg_idN/AN/AUnique message ID; 1 to 4294967295. The message ID increases by 1 with each new message. Message IDs restart at 1 each time the application is restarted.
total_segN/AN/ATotal number of segments in a log message. Long messages are divided into more than one segment.
Note: The total_seg depends on the Maximum Length setting in the remote logging targets page. See Remote Logging Target Settings.
seg_numN/AN/ASegment sequence number within a message. Use this number to determine what segment of the message you are viewing.
timestampN/AN/ADate of the message generation, according to the local clock of the originating the Cisco ISE node, in the following format: 
YYYY-MM-DD hh:mm:ss:xxx +/-zh:zm.
sequence_numN/AN/AGlobal counter of each message. If one message is sent to the local store and the next to the syslog server target, the counter increments by 2. Possible values are 0000000001 to 999999999.
msg_code<vmid>
<tag1>
NumberMessage code as defined in the logging categories.
msg_sev<severity>Text/StringMessage severity level of a log message.
msg_class<subject> Text/StringMessage class, which identifies groups of messages with the same context.
msg_text<action> Text/StringEnglish language descriptive text message.
key1N/AN/AN/A
key2N/AN/AN/A
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.