Skip to main content
Skip table of contents

V 2.0 Posture And Client Provisioning Audit Event

Vendor Documentation

Classification

Rule NameRule TypeCommon EventClassification
V 2.0 Posture And Client Provisioning Audit EventBase RuleAudit MessageOther Audit
V 2.0 EVID 87000 Endpoint Posture Report ReceivedSub RuleGeneral Endpoint MessageInformation
V 2.0 EVID 87001 EP Reassessment Report ReceiveSub RuleGeneral Endpoint MessageInformation
V 2.0 EVID 87002 Endpoint Session TerminationSub RuleGeneral Endpoint MessageInformation
V 2.0 EVID 87004 EP USB-Check Report ReceivedSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 87500 Client Provisioning SuccessSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 87501 Client Provisioning Fail EventSub RuleProvisioning FailedWarning
V 2.0 EVID 87600 Supplicant Provisioning SuccessSub RuleSuccessful ActivityOther Audit Success
V 2.0 EVID 87601 Supplicant Provisioning FailSub RuleProvisioning FailedWarning
V 2.0 EVID 87602 Supplicant Provision InprogressSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 87603 Supplicant Provisioning DisableSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 87604 CA Server DownSub RuleThe Server Is DownInformation
V 2.0 EVID 87605 CA Server UpSub RuleServer Is UpInformation
V 2.0 EVID 87606 Certificate Request ForwardingSub RuleCertificate Verification FailureError
V 2.0 EVID 87607 OCSP Transactions High VolumeSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 87608 EST Service DownSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 87609 EST Service UpSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 87750 EP Protection Svc Perform Op.Sub RuleGeneral Endpoint MessageInformation
V 2.0 EVID 87751 EP Protection Svc Operation ResSub RuleGeneral Endpoint MessageInformation
V 2.0 EVID 87752 Provisioning Portal -Req SubmitSub RuleCertificate RequestActivity
V 2.0 EVID 87753 Provisioning Portal-Status UpdateSub RuleCertificate Update RequestActivity
V 2.0 EVID 87754 Provisioning Portal -User LoginSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 87901 EP Scripts Provisioned New JobSub RuleGeneral Endpoint MessageInformation
V 2.0 EVID 87921 EndPoint Scripts Execution ResSub RuleGeneral Endpoint MessageInformation
V 2.0 EVID 87005 PSN Posture Compliant StateSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 87006 Posture Queries For MNT SessionSub RuleGeneral Information Log MessageInformation

Mapping with LogRhythm Schema

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
pri_numN/AN/APriority value of the message, a combination of the facility value and the severity value of the message. Priority value = (facility value * 8) + severity value.
The facility code valid options are:
LOCAL0 (Code = 16)
LOCAL1 (Code = 17)
LOCAL2 (Code = 18)
LOCAL3 (Code = 19)
LOCAL4 (Code = 20)
LOCAL5 (Code = 21)
LOCAL6 (Code = 22; default)
LOCAL7 (Code = 23)
timeN/AN/ADate of the message generation, according to the local clock of the originating Cisco ISE server, in the format Mmm DD hh:mm:ss.
IP address/hostnameN/AN/AIP address of the originating Cisco ISE node, or the hostname.
cat_name<vendorinfo>Text/StringLogging category name preceded by the CSCOxxx string.
msg_idN/AN/AUnique message ID; 1 to 4294967295. The message ID increases by 1 with each new message. Message IDs restart at 1 each time the application is restarted.
total_segN/AN/ATotal number of segments in a log message. Long messages are divided into more than one segment.
Note : The total_seg depends on the Maximum Length setting in the remote logging targets page. See Remote Logging Target Settings.
seg_numN/AN/ASegment sequence number within a message. Use this number to determine what segment of the message you are viewing.
timestampN/AN/ADate of the message generation, according to the local clock of the originating the Cisco ISE node, in the following format :
YYYY-MM-DD hh:mm:ss:xxx +/-zh:zm.
sequence_numN/AN/AGlobal counter of each message. If one message is sent to the local store and the next to the syslog server target, the counter increments by 2. Possible values are 0000000001 to 999999999.
msg_code<vmid>
<tag1>
NumberMessage code as defined in the logging categories.
msg_sev<severity>Text/StringMessage severity level of a log message.
msg_class<subject> Text/StringMessage class, which identifies groups of messages with the same context.
msg_text<action> Text/StringEnglish language descriptive text message.
ConfigVersionIdN/AN/AN/A
NetworkDeviceGroupsN/AN/AN/A
RequestTimeN/AN/AN/A
ResponseTimeN/AN/AN/A
FailureReason<reason>Text/StringN/A
MacAddress<dmac>Text/StringN/A
OperatingSystemN/AN/AN/A
PostureAgentVersionN/AN/AN/A
PosturePolicyMatchedN/AN/AN/A
UserName<account>Text/StringN/A
SessionId<session>Text/StringN/A
IpAddress<dip>IP AddressN/A
SupplicantProfileN/AN/AN/A
AntiVirusInstalledN/AN/AN/A
AntiSpywareInstalledN/AN/AN/A
FeedUrl<url>Text/StringN/A
NumOfUpdatesN/AN/AN/A
Key1N/AN/AN/A
Key2N/AN/AN/A
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.