The following table lists the information contained in audit events related to various Logger functions and configuration changes on it. The Severity for all Logger application events is 2.
|
Device Event |
Device Event |
Message |
Additional Fields |
|---|---|---|---|
|
Alerts |
|
|
|
|
logger:610 |
/Logger/Component |
Alert [name] has been added |
fname=AlertName |
|
logger:611 |
/Logger/Component |
Alert [name] has been deleted |
fname=AlertName |
|
logger:612 |
/Logger/Component |
Alert [name] has been updated |
fname=AlertName |
|
logger:613 |
/Logger/Component |
Alert [name] has |
fname=AlertName |
|
logger:614 |
/Logger/Component |
Alert [name] has been disabled |
fname=AlertName |
|
logger:615 |
/Logger/Alert |
Alert [name] has been sent |
fname=AlertName |
|
logger:800 |
/Logger/Component/Search/Stats/Started |
Search [Search ID] has started |
dst=destinationAddress |
|
logger:801 |
/Logger/Component/Search/Stats/Finished |
Search [Search ID] has finished |
dst=destinationAddress |
|
logger:802 |
/Logger/Component/Search/Stats/Final |
Peer [IP] Final Search Status |
dst=destinationAddress |
|
logger:803 |
/Logger/Component/Search/Stats/Intermediate |
Peer [IP] Intermediate Search Status |
dst=destinationAddress |
|
Certificates |
|
|
|
|
logger:643 |
/Logger/Component/ |
Certificate [name] has been added |
fname=alias |
|
logger:650 |
/Logger/Component/ |
Certificate [name] has been deleted |
fname=alias |
|
logger:651 |
/Logger/Component/ |
Certificate [name] has been updated |
fname=alias |
|
Configuration Backup |
|
|
|
|
logger:660 |
/Logger/Component/ |
Configuration backup has been updated |
fname=Configuration Backup |
|
logger:661 |
/Logger/Component/ |
Configuration backup has been enabled |
fname=Configuration Backup |
|
logger:662 |
/Logger/Component/ |
Configuration backup has been disabled |
fname=Configuration Backup |
|
logger:665 |
/Logger/Component |
Configuration backup succeeded. Transfer process finished. |
fname=Configuration Backup |
|
ESM Destinations |
|
|
|
|
logger:640 |
/Logger/Component/ |
ESM destination [name] has been added |
fname=esmDestinationName |
|
logger:641 |
/Logger/Component/ |
ESM destination [name] has been deleted |
fname=esmDestinationName |
|
TH Destinations |
|
|
|
|
logger:730 |
/Logger/Component/KafkaDestination/Configuration/Add |
Kafka destination [name] has been added |
fname=kafkaDestinationName
|
|
logger:731 |
/Logger/Component/ KafkaDestination/ Configuration/Delete |
Kafka destination [name] has been deleted |
fname=kafkaDestinationName
|
|
Forwarders |
|
|
|
|
logger:605 |
/Logger/Component |
Forwarder [name] has been added |
fname=forwarderName |
|
logger:606 |
/Logger/Component/ |
Forwarder [name] has been deleted |
fname=forwarderName |
|
logger:607 |
/Logger/Component/ |
Forwarder [name] has been updated |
fname=forwarderName |
|
logger:608 |
/Logger/Component/ |
Forwarder [name] has been enabled |
fname=forwarderName |
|
logger:609 |
/Logger/Component/ |
Forwarder [name] has been disabled |
fname=forwarderName |
|
logger:663 |
/Logger/Component/ |
Forwarder [name] has been paused |
fname=forwarderName |
|
logger:664 |
/Logger/Component/ |
Forwarder [name] has been resumed |
fname=forwarderName |
|
Receivers |
|
|
|
|
logger:600 |
/Logger/Component/ |
Receiver [name] has been added |
fname=receiverName |
|
logger:601 |
/Logger/Component/ |
Receiver [name] has been deleted |
fname=receiverName |
|
logger:602 |
/Logger/Component/ |
Receiver [name] has been updated |
fname=receiverName |
|
logger:603 |
/Logger/Component/ |
Receiver [name] has been enabled |
fname=receiverName |
|
logger:604 |
/Logger/Component/ |
Receiver [name] has been disabled |
fname=receiverName |
|
SNMP Destinations |
|
|
|
|
logger:644 |
/Logger/Component/ |
SNMP destination [name] has been added |
fname=snmpDestinationName |
|
logger:645 |
/Logger/Component/ |
SNMP destination [name] has been deleted |
fname=snmpDestinationName |
|
Syslog Destinations |
|
|
|
|
logger:647 |
/Logger/Resource/ |
Syslog destination [name] has been added |
fname=syslogDestinationName |
|
logger:648 |
/Logger/Component/ |
Syslog destination [name] has been deleted |
fname=syslogDestinationName |
|
logger:649 |
/Logger/Component |
Syslog destination [name] has been updated |
fname=syslogDestinationName |
|
Archives |
|
|
|
|
logger:520, Manually added |
/Logger/Resource/Archive/ Add |
Event Archive Added ManualArchive [Date] [Internal Event Storage Group] |
cat=/Resource/Archive/Add |
|
logger:520, Added with schedule |
/Logger/Resource/Archive/Add |
Event Archive Added ManualArchive [Date] [Internal Event Storage Group] |
cat=/Resource/Archive/Add |
|
logger:521 |
/Logger/Resource |
Archive [archiveName] has been deleted |
fname=archiveName |
|
logger:523 |
/Logger/Resource |
Archive [archiveName] has been loaded |
fname=archiveName |
|
logger:524 |
/Logger/Resource |
Archive [archiveName] has been unloaded |
fname=archiveName |
| logger:525, Manually added | /Logger/Resource/Archive/ Archive | Event Archive Archived ManualArchive [date] [Internal Event Storage Group] |
dst=127.0.0.1 |
| logger:525, Added with schedule | /Logger/Resource/Archive/ Archive | Event Archive Archived archive [date] [Internal Event Storage Group] |
dst=127.0.0.1 |
|
logger:526 |
/Logger/Resource |
Event archive settings added |
duser=UserName |
|
logger:527 |
/Logger/Resource |
Daily archive task settings updated |
duser= UserName |
|
logger:528 |
/Logger/Resource |
Event archive failed |
fname=archiveName |
|
logger:529 |
/Logger/Resource/Archive/Index |
Event Archive [archiveName] has been indexed |
fname=archiveName |
|
Dashboards |
|
|
|
|
logger:580 |
/Logger/Resource |
Dashboard [name] has been added |
fname=dashboardName |
|
logger:581 |
/Logger/Resource |
Dashboard [name] has been deleted |
fname=dashboardName |
|
logger:582 |
/Logger/Resource |
Dashboard [name] has been updated |
fname=dashboardName |
|
Devices |
|
|
|
|
logger:510 |
/Logger/Resource |
Device [deviceName] has been added |
fname=deviceName |
|
logger:511 |
/Logger/Resource |
Device [deviceName] has been deleted |
fname=deviceName |
|
logger:512 |
/Logger/Resource |
Device [deviceName] has been updated |
fname=deviceName |
|
Filters |
|
|
|
|
logger:500 |
/Logger/Resource/Filter |
Filter [filterName] has been added |
fname=filterName |
|
logger:501 |
/Logger/Resource/Filter |
Filter [filterName] has been deleted |
fname=filterName |
|
logger:502 |
/Logger/Resource/Filter |
Filter [filterName] has been updated |
fname=filterName |
|
Groups |
|
|
|
|
logger:513 |
/Logger/Resource |
Group [groupName] has been added |
fname=groupName |
|
logger:514 |
/Logger/Resource |
Group [groupName] has been deleted |
fname=groupName |
|
logger:515 |
/Logger/Resource |
Group [groupName] has been updated |
fname=groupName |
|
Peer Loggers |
|
|
|
|
logger:550 |
/Logger/Resource |
Peer Logger [name] has been added |
fname=Name |
|
logger:551 |
/Logger/Resource |
Peer Logger [name] has been deleted |
fname=Name |
|
logger:570 |
/Logger/Resource |
Peer Logger authorization [name] has been added |
fname=Name |
|
logger:571 |
/Logger/Resource |
Peer Logger authorization [name] has been deleted |
fname=Name |
|
Parsers |
|||
|
logger:590 |
/Logger/Resource |
Parser Description [name] has been added |
fileType=Parser Description |
|
logger:591 |
/Logger/Resource |
Parser Description [name] has been deleted |
fileType=Parser Description |
|
logger:592 |
/Logger/Resource |
Parser Description [name] has been updated |
fileType=Parser Description |
|
Saved Searches |
|
|
|
|
logger:540 |
/Logger/Resource/ |
Saved search [name] has been added |
fname=savedSearchName |
|
logger:541 |
/Logger/Resource/ |
Saved search [name] has been deleted |
fname=savedSearchName |
|
logger:542 |
/Logger/Resource/ |
Saved search [name] has been updated |
fname=savedSearchName |
|
Source Types |
|||
|
logger:596 |
/Logger/Resource/ |
Source Type [name] has been added |
cs4=sessionIdfile |
|
logger:597 |
/Logger/Resource |
Source Type [name] has been deleted |
fileType=Source Type |
|
logger:598 |
/Logger/Resource |
Source Type [name] has been updated |
fileType=Source Type |
|
Storage Groups |
|
|
|
|
logger:530 |
/Logger/Resource/ |
Storage group [storageGroupName] has been added |
fname=storageGroupName |
|
logger:532 |
/Logger/Resource/ |
Storage group [storageGroupName] has been updated |
fname=storageGroupName |
|
Storage Rules |
|
|
|
|
logger:533 |
/Logger/Resource/ |
Storage rule [name] has been added |
fname=storageRuleName |
|
logger:535 |
/Logger/Resource/ |
Storage rule [name] has been updated |
fname=storageRuleName |
|
Storage Volume |
|
|
|
|
logger:536 |
/Logger/Resource |
Storage volume [name] has been added |
fname=storageVolumeName |
|
Search |
|
|
|
|
logger:680 |
/Logger/Search/Index |
Search indices have been added OR Search index has been added |
cs4=sessionId |
|
logger:690 |
/Logger/Search/Options |
Search options have been updated |
cs6=false |
|
logger:710 |
/Logger/Search |
Search session [sessionID] has been canceled by [user] |
cs1Label=Session ID |
|
Maintenance Mode |
|
|
|
|
logger:700 |
/Logger/Server |
Maintenance mode entered |
fname=Maintenance Mode |