List of Event Types
The following table provides the types of JSON events generated and their description. For each of these events, the CEF/LEEF success or failure events generated are the event name followed by .success
or .failure
.
For example, the CEF/LEEF success event for agent.activate
is agent.activate.success
and the failure event is agent.activate.failure
.
Each event can generate a variety of notification messages. See Notification Messages in Events.
JSON Event Type | Description |
---|---|
| Access restriction created |
| Access restriction deleted |
| Access restriction updated |
| Agent paired |
| Agent clone activated |
| Agent clone detected |
| Agent unpaired |
| Generate maintenance token for any agent |
| Agent disconnected |
| Agent machine identifiers updated |
| Agent refreshed token |
| Success or failure to apply policy on VEN |
| VEN upgrade request sent |
| Agent reported a service not running |
| Agent suspended |
| Agent firewall tampered |
| Agent unsuspended |
| Agent properties updated. |
| Agent interactive users updated |
| Agent updated existing iptables href |
| Agent updated existing containers |
| Agent existing IP tables uploaded |
| Agent support report uploaded |
| Agent support report request created |
| Agent support report request deleted |
| Condition cleared from a list of VENs |
| Multiple agents unpaired |
| API key created |
| API key deleted |
| API key updated |
| RBAC auth security principal created |
| RBAC auth security principal deleted |
| RBAC auth security principal updated |
| Authentication settings updated |
| PCE cluster created |
| PCE cluster deleted |
| PCE cluster updated |
| Container workload updated |
| Container cluster created |
| Container cluster deleted |
| Container cluster updated |
| Container cluster label mappings updated all at once |
| Container cluster services updated, created, or deleted by Kubelink |
| Container workload profile created |
| Container workload profile deleted |
| Container workload profile updated |
| DB temp table cleanup started |
| DB temp table cleanup completed |
| Domain created |
| Domain deleted |
| Domain updated |
| Enforcement boundary created |
| Enforcement boundary deleted |
| Enforcement boundary updated |
| Event settings updated |
| Global policy settings updated |
| Group created |
| Group updated |
| IP list created |
| IP list deleted |
| IP list updated |
| IP lists deleted |
| IP tables rules created |
| IP tables rules deleted |
| IP tables rules updated |
| Job deleted |
| Label created |
| Label deleted |
| Label updated |
| Label group created |
| Label group deleted |
| Label group updated |
| Labels deleted |
| LDAP configuration created |
| LDAP configuration deleted |
| LDAP configuration updated |
| LDAP server connection verified |
| License deleted |
| License updated |
| Interservice call to login service to create LDAP config |
| Interservice call to login service to delete LDAP config |
| Interservice call to login service to update LDAP config |
| Interservice call to login service to verify connection to the LDAP server |
| New MSP tenant created |
| MSP tenant deleted |
| MSP tenant updated |
| New managed organization created |
| Managed organization deleted |
| Managed organization updated |
| Lost agent found |
| Network created |
| Network deleted |
| Network updated |
| Enforcement instruction applied to a network device |
| Existing or new unmanaged workload assigned to a network device |
| Network device created |
| Network device deleted |
| Network device updated |
| Enforcement instructions applied to multiple network devices |
| Network endpoint created |
| Network endpoint deleted |
| Network endpoint updated |
| Network enforcement node activated |
| Network enforcement node conditions cleared |
| Network enforcement node deactivated |
| Network enforcement node failed or primary lost connectivity to secondary |
| Network enforcement node did not heartbeat for more than 15 minutes |
| Network enforcement node missed heartbeats check |
| Workload added to network endpoint |
| Network enforcement node acknowledgment of policy |
| Network enforcement node policy requested |
| Updated the target PCE of the network enforcement node |
| Network enforcement node reports when switches are not reachable |
| A condition was cleared from a list of network enforcement nodes |
| Network function controller created |
| Network function controller deleted |
| Network function controller virtual servers discovered |
| Network function controller policy status |
| Network function controller SLB state updated |
| Organization created |
| Rules for organization recalculated |
| Organization information updated |
| Pairing profile created |
| Pairing profile pairing key created |
| Pairing profile deleted |
| Pairing profile updated |
| Pairing keys deleted from pairing profile |
| Pairing profiles deleted |
| Password policy created |
| Password policy deleted |
| Password policy updated |
| RBAC permission created |
| RBAC permission deleted |
| RBAC permission updated |
| Create domain RADIUS configuration |
| Delete domain RADIUS configuration |
| Update domain RADIUS configuration |
| Verify RADIUS shared secret |
| API request authentication failed |
| API request authorization failed |
| API request failed due to internal server error |
| API request failed due to unavailable service |
| API request failed due to unknown server error |
| Login resource created |
| Login resource deleted |
| Login resource updated |
| Rule set created |
| Rule set deleted |
| Rule set updated |
| Rule sets deleted |
| SAML assertion consumer services updated |
| SAML configuration created |
| SAML configuration deleted |
| Generate a new cert for signing SAML AuthN requests |
| SAML configuration updated |
| SAML Service Provider created |
| SAML Service Provider deleted |
| SAML Service Provider updated |
| Security policy created |
| Pending security policy deleted |
| Security policy restored |
| Security policy rules created |
| Security policy rules deleted |
| Security policy rules updated |
| SecureConnect gateway created |
| SecureConnect gateway deleted |
| SecureConnect gateway updated |
| RBAC security principal created |
| RBAC security principal bulk deleted |
| RBAC security principal bulk updated |
| RBAC security principals bulk created |
| Service created |
| Service deleted |
| Service updated |
| Service account created |
| Service account deleted |
| Service account updated |
| Service binding created |
| Service binding created |
| Service bindings deleted |
| Service binding deleted |
| Services deleted |
| Explorer settings updated |
| Server load balancer created |
| Server load balancer deleted |
| Server load balancer updated |
| Support report uploaded |
| syslog remote destination created |
| syslog remote destination deleted |
| syslog remote destination updated |
| Agent missed heartbeats |
| VEN missing heartbeat after upgrade |
| Agents marked offline |
| VEN self signed certificate housekeeping check |
| VEN settings invalidation error state check |
| VEN uninstall timeout |
| Clear VEN authentication recovery condition |
| Compute policy for unmanaged workloads |
| An expired service account api_key was successfully deleted |
| Delete old cached perspectives |
| Endpoint marked offline |
| Container cluster services provisioned |
| Event pruning completed |
| Stale zone subnets removed |
| Set server synced |
| Deactivated and deleted workloads have been vacuumed |
| Traffic collector setting created |
| Traffic collector setting deleted |
| Traffic collector setting updated |
| Trusted proxy IPs created or updated |
| User invitation accepted |
| User authenticated |
| User created |
| User deleted |
| User invited |
| User logged in |
| User login session terminated |
| User logged |
| User session terminated |
| User password reset |
| User session created |
| User session terminated |
| User information updated |
| User password updated |
| User entered expired password |
| User verified MFA |
| Auth token returned for user authentication on PCE |
| User local profile created |
| User local profile deleted |
| User local profile reinvited |
| User local password updated |
| VEN settings updated |
| VEN software release upgraded |
| VEN software release created |
| VEN software release deleted |
| VEN software release deployed |
| VEN software release updated |
| Default VEN software version set |
| Virtual server created |
| Virtual server created |
| Virtual server updated |
| Virtual service created |
| Virtual service deleted |
| Virtual service updated |
| Virtual services created in bulk |
| Virtual services updated in bulk |
| Vulnerability record created |
| Vulnerability record deleted |
| Vulnerability record updated |
| Vulnerability report deleted |
| Vulnerability report updated |
| Workload created |
| Workload deleted |
| Workload online |
| Workload policy recalculated |
| Workload network redetected |
| Workload undeleted |
| Workload settings updated |
| Workload upgraded |
| Workload interface created |
| Workload interface deleted |
| Workload interface updated |
| Workload interfaces updated For example, IP address changes, new interface added, and interface shut down. |
| Workload service report updated |
| Workload settings updated |
| Workloads policies applied |
| Workloads created in bulk |
| Workloads deleted in bulk |
| Workloads updated in bulk |
| Workloads labels removed |
| Workload flow reporting frequency changed |
| Workload labels applied |
| Workloads unpaired |
| Workloads updated |
Notification Messages in Events
Events can generate a variety of notifications that are appended after the event type:
agent.clone_detected
agent.fw_state_table_threshold_exceeded
agent.missed_heartbeats
agent.missing_heartbeats_after_upgrade
agent.policy_deploy_failed
agent.policy_deploy_succeeded
agent.process_failed
agent.service_not_available
agent.upgrade_requested
agent.upgrade_successful
agent.upgrade_time_out
container_cluster.duplicate_machine_id
container_cluster.region_mismatch
container_workload.invalid_pairing_config
container_workload.not_created
database.temp_table_autocleanup_completed
database.temp_table_autocleanup_started
hard_limit.exceeded
pce.application_started
pce.application_stopped
remote_syslog.reachable
remote_syslog.unreachable
request.authentication_failed
request.authorization_failed
request.internal_server_error
request.invalid
request.service_unavailable
request.unknown_server_error
sec_policy.restore
soft_limit.exceeded
system_task.event_pruning_completed
system_task.hard_limit_recovery_completed
user.csrf_validation_failed
user.login_failed
user.login_failure_count_exceeded
user.login_session_created
user.login_session_terminated
user.pce_session_created
user.pce_session_terminated
user.pw_change_failure
user.pw_changed
user.pw_complexity_not_met
user.pw_reset_completed
user.pw_reset_requested
virtual_service.not_created
workload.duplicate_interface_reported
workload.nat_rules_present
workload.offline_after_ven_goodbye
workload.online
workload.oob_policy_changes
workload.partial_policy_delivered
workload.update_mismatched_interfaces
workloads.flow_reporting_frequency_updated