Skip to main content
Skip table of contents

V 2.0 My Devices Event

Vendor Documentation

Classification

Rule NameRule TypeCommon EventClassification
V 2.0 My Devices EventBase RuleGeneral Information Log MessageInformation
V 2.0 EVID  88000 Successfully Added A DeviceSub RuleObject AddedAccess Success
V 2.0 EVID  88001 Failed To Added A DeviceSub RuleDevice Communication FailureError
V 2.0 EVID  88002 Successfully Modified The Dev.Sub RuleObject ModifiedAccess Success
V 2.0 EVID  88003 Failed To Modify The DeviceSub RuleDevice Communication FailureError
V 2.0 EVID  88004 Successfully Deleted The DeviceSub RuleObject Deleted/RemovedAccess Success
V 2.0 EVID  88005 Failed To Delete The DeviceSub RuleDevice Communication FailureError
V 2.0 EVID  88006 Successfully Blacklisted DeviceSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID  88007 Failed To Blacklist The DeviceSub RuleDevice Communication FailureError
V 2.0 EVID  88008 Successfully Reinstated The DevSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID  88009 Failed To Reinstate The DeviceSub RuleDevice Communication FailureError
V 2.0 EVID 88010 Successfully Reg/Prov The DeviceSub RuleDevice RegisteredOther Audit Success
V 2.0 EVID  88011 Failed To Reg/Prov The DeviceSub RuleDevice Communication FailureError
V 2.0 EVID  88012 Successfully Performed CoA TermSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID  88013 Failed To Perform CoA Terminat.Sub RuleDevice Communication FailureError
V 2.0 EVID  88014 Success Performed CoA Re-AuthSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID  88015 Failed To Perform A CoA Re-authSub RuleDevice Communication FailureError

Mapping with LogRhythm Schema

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
pri_numN/AN/APriority value of the message, a combination of the facility value and the severity value of the message. Priority value = (facility value * 8) + severity value.
The facility code valid options are:
LOCAL0 (Code = 16)
LOCAL1 (Code = 17)
LOCAL2 (Code = 18)
LOCAL3 (Code = 19)
LOCAL4 (Code = 20)
LOCAL5 (Code = 21)
LOCAL6 (Code = 22; default)
LOCAL7 (Code = 23)
timeN/AN/ADate of the message generation, according to the local clock of the originating Cisco ISE server, in the format Mmm DD hh:mm:ss.
IP address/hostnameN/AN/AIP address of the originating Cisco ISE node, or the hostname.
cat_name<vendorinfo>Text/StringLogging category name preceded by the CSCOxxx string.
msg_idN/AN/AUnique message ID; 1 to 4294967295. The message ID increases by 1 with each new message. Message IDs restart at 1 each time the application is restarted.
total_segN/AN/ATotal number of segments in a log message. Long messages are divided into more than one segment.
Note: The total_seg depends on the Maximum Length setting in the remote logging targets page. See Remote Logging Target Settings.
seg_numN/AN/ASegment sequence number within a message. Use this number to determine what segment of the message you are viewing.
timestampN/AN/ADate of the message generation, according to the local clock of the originating the Cisco ISE node, in the following format: YYYY-MM-DD hh:mm:ss:xxx +/-zh:zm.
sequence_numN/AN/AGlobal counter of each message. If one message is sent to the local store and the next to the syslog server target, the counter increments by 2. Possible values are 0000000001 to 999999999.
msg_code<vmid>
<tag1>
NumberMessage code as defined in the logging categories.
msg_sev<severity>Text/StringMessage severity level of a log message.
msg_class<subject> Text/StringMessage class, which identifies groups of messages with the same context.
msg_text<action> Text/StringEnglish language descriptive text message.
ConfigVersionIdN/AN/AN/A
UserName<login>Text/StringN/A
FirstnameN/AN/AN/A
LastnameN/AN/AN/A
PhoneNumberN/AN/AN/A
MacAddress<smac>Text/StringN/A
IpAddress<sip>IP AddressN/A
AuthenticationIdentityStoreN/AN/AN/A
PortalNameN/AN/AN/A
IdentityGroup<group>Text/StringN/A
PsnHostName<sname>Text/StringN/A
GuestUserNameN/AN/AN/A
EPMacAddress<smac>Text/StringN/A
NADAddress<sip>IP AddressN/A
EPIdentityGroupN/AN/AN/A
StaticassignmentN/AN/AN/A
EndPointProfilerN/AN/AN/A
EndPointPolicyN/AN/AN/A
DeviceNameN/AN/AN/A
DeviceRegistrationStatus<status>Text/StringN/A
AuditSessionId<session>Text/StringN/A
ResponseTimeN/AN/AN/A
cisco-av-pair=audit-session-idN/AN/AN/A
EndpointCoAN/AN/AN/A
CPMSessionID<session>Text/StringN/A
Key1N/AN/AN/A
Key2N/AN/AN/A
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.