Documenti di Didattica
Documenti di Professioni
Documenti di Cultura
AGENT_CONNECTION_REFUSED Manager
agent:009 rejected a connection attempt from an Agent for Host/Application Access Nothing Application Informational/Error Failure
reasons other than authentication failure
AGENT_UPGRADE_SUCCESS Agent upgrade
agent:010 Host/Application Modify/Content Nothing Application Normal Success
succeeded
AGENT_UPGRADE_FAILURE Agent upgrade
agent:011 Host/Application Modify/Content Nothing Application Informational/Error Failure
failed
AGENT_TIME_DEVICE_FAILURE Agent
Informational/Warn
agent:012 detected source events from a sensor device Host/Application Execute/Response Application Success
ing
containing incorrect time stamps
AGENT_DEVICE_FOUND Agent noted that a
agent:013 Host/Application Communicate/Query Nothing Application Normal Success
new sensor device is sending events
AGENT_SYSLOG_AGGREGATION_FAILURE
agent:014 Agent could not find a base event referenced in a Host/Application Execute/Query Nothing Application Informational/Error Failure
syslog aggregate event
AGENT_CONNECTION_DEVICE_FAILURE
agent:015 Host/Application Access/Start Nothing Application Informational/Error Failure
Agent could not connect to the sensor device's log
AGENT_CONNECTION_DEVICE_SUCCESS
agent:016 Agent successfully connected to the sensor Host/Application Access/Start Nothing Application Normal Success
device's log
AGENT_COMMAND_SUCCESS Agent
agent:017 Host/Application Execute/Query Application Normal Success
successfully executed a command
AGENT_COMMAND_FAILURE Agent could
agent:018 Host/Application Execute/Query Application Informational/Error Failure
not execute a command
AGENT_CACHE_CACHING Agent is caching
Informational/Warn
agent:019 events because they could not be immediately Host/Application Execute/Response Application Success
ing
transmitted to the Manager
AGENT_CACHE_EMPTY Agent has emptied its
agent:020 Host/Application/Service Execute/Response Nothing Application Normal Success
cache of events
AGENT_NTCOLLECTOR_ERROR Agent could
agent:021 Host/Application Communicate/Query Nothing Application Informational/Error Failure
not communicate with an NT collector sensor
ArcSight Specific Device Event Class IDs
DeviceEventClassId Description Object Behavior Technique Device Group Significance Outcome
AGENT_CONFIGURATION_FAILURE Agent
agent:022 Host/Application Modify/Configuration Nothing Application Informational/Error Failure
could not process a reconfiguration request
AGENT_CHECKPOINT_ERROR Agent could
agent:023 Host/Application Execute Nothing Application Informational/Error Failure
not communicate with a CheckPoint sensor
AGENT_CHECKPOINT_WARN Agent is having Informational/Warn
agent:024 Host/Application Execute Nothing Application Failure
difficulty communicating with CheckPoint ing
AGENT_UPDATE_SUCCESS Agent content was
agent:025 Host/Application Modify/Configuration Nothing Application Normal Success
successfully updated
AGENT_UPDATE_FAILURE Agent content
agent:026 Host/Application Modify/Configuration Nothing Application Informational/Error Failure
update failed
agent:027 AGENT_ACS_ERROR Host/Application/Service Execute/Query Nothing Application Informational/Error Failure
AGENT_UNEXPECTED_ERROR Agent
agent:028 Host/Application/Service Execute/Query Nothing Application Informational/Error Failure
experienced an unexpected problem
AGENT_CACHE_DROPPED Agent was forced Informational/Warn
agent:029 Host/Resource Execute/Query Nothing Application Failure
to drop some of its cached data ing
agent:030 AGENT_STARTED Agent started Host/Application/Service Execute/Start Nothing Application Normal Success
agent:031 AGENT_SHUTTINGDOWN Agent shutdown Host/Application/Service Execute/Stop Nothing Application Normal Success
AGENT_CONFIGURATION_CHANGED Agent
agent:032 Host/Application/Service Modify/Configuration Nothing Application Informational Success
configuration was successfully changed
AGENT_DATABASE_PASSWORD_CHANGE
Authentication/Modif
agent:033 D The password used by an Agent to access a Host/Application Application Informational Success
y
database has changed
AGENT_DEVICE_UPDATED The Agent has
agent:034 Host/Application Modify/Configuration Application Informational Success
been directed to monitor a different device (sensor)
AGENT_TIME_FAILURE The Agent has
Informational/Warn
agent:035 detected event time stamps that fall outside the Host/Application Execute/Response Application Success
ing
valid range
agent:036 AGENT_UPGRADE_STARTED Host/Application Modify/Content Application Informational Attempt
agent:037 AGENT_UPGRADE_ROLLBACK_STARTED Host/Application Modify/Content Application Informational Attempt
agent:038 AGENT_UPGRADE_ROLLBACK_SUCCESS Host/Application Modify/Content Application Informational Success
ArcSight Specific Device Event Class IDs
DeviceEventClassId Description Object Behavior Technique Device Group Significance Outcome
DATABASE_TABLESPACE_AVALIABLE
database:103 Database has more tablespace available after Host/Application/Database Check/Resource Application Informational Success
detecting a low tablespace condition
database:104 DATABASE_EVENT_DISCARDED Host/Application/Database/Data Delete Application Informational Success
Security
datamonitor:000 DATA_MONITOR Host/Application Nothing Nothing Information Informational Nothing
Manager
Security
datamonitor:100 DATA_MONITOR_MOVING_AVERAGE Host/Application Execute/Response Nothing Information Informational Success
Manager
Security
DATA_MONITOR_MOVING_AVERAGE_THR
datamonitor:101 Host/Application Execute/Response Nothing Information Informational Success
ESHOLD
Manager
DATA_MONITOR_MOVING_AVERAGE_THR Security
datamonitor:102 ESHOLD_FALLING Moving Average Data Host/Application Execute/Response Nothing Information Informational Success
Monitor detected a rapidly falling moving average Manager
DATA_MONITOR_MOVING_AVERAGE_THR Security
datamonitor:103 ESHOLD_RISING Moving Average Data Monitor Host/Application Execute/Response Nothing Information Informational Success
detected a rapidly rising moving average Manager
DATA_MONITOR_MOVING_AVERAGE_STA Security
datamonitor:104 TUS Moving Average Data Monitor reporting the Host/Application Execute/Response Nothing Information Informational Success
current moving average Manager
DATA_MONITOR_MOVING_AVERAGE_VAL Security
datamonitor:105 UE_ADD Moving Average Data Monitor started Host/Application Execute/Response Information Informational Success
tracking a new key value Manager
DATA_MONITOR_MOVING_AVERAGE_VAL Security
datamonitor:106 UE_REMOVE Moving Average Data Monitor Host/Application Execute/Response Information Informational Success
stopped tracking a key value Manager
Security
DATA_MONITOR_STATISTICS Statistical Data
datamonitor:200 Host/Application Execute/Response Nothing Information Informational Success
Monitor reporting a change in status
Manager
ArcSight Specific Device Event Class IDs
DeviceEventClassId Description Object Behavior Technique Device Group Significance Outcome
DATA_MONITOR_STATISTICS_VALUE_ADD Security
datamonitor:201 Statistical Data Monitor started tracking a new key Host/Application Execute/Response Information Informational Success
value Manager
DATA_MONITOR_STATISTICS_VALUE_REM Security
datamonitor:202 OVE Statistical Data Monitor stopped tracking a Host/Application Execute/Response Information Informational Success
key value Manager
DATA_MONITOR_CORRELATION Correlation Security
datamonitor:300 Data Monitor reporting a correlated or non- Host/Application Execute/Response Nothing Information Informational Success
correlated event Manager
Security
DATA_MONITOR_SET_VALUE State changed
datamonitor:400 Host/Application Execute/Query Information Normal Success
in Last State Data Monitor
Manager
Security
DATA_MONITOR_SET_VALUE_USER State
datamonitor:401 Host/Application Execute/Query Information Normal Success
changed manually in Last State Data Monitor
Manager
DATA_MONITOR_REMOVE_VALUE_USER Security
datamonitor:402 Key value removed manually in Last State Data Host/Application Execute/Response Information Informational Success
Monitor Manager
Security
datamonitor:500 DATA_MONITOR_TOP_VALUE_COUNT Host/Application Execute/Response Information Informational Success
Manager
Security
DATA_MONITOR_TOP_VALUE_COUNT_VA
datamonitor:501 Host/Application Execute/Response Information Informational Success
LUE_ADD
Manager
Security
DATA_MONITOR_TOP_VALUE_COUNT_VA
datamonitor:502 Host/Application Execute/Response Information Informational Success
LUE_REMOVE
Manager
Per disk read Linux /Monitor/Disk/drive/Read
disk:102 Host/Application Execute/Response Application Informational Success
/proc/diskstats
Per disk write Linux /Monitor/Disk/drive/Write
disk:103 Host/Application Execute/Response Application Informational Success
/proc/diskstats
domain:000 DOMAIN Host/Application Execute/Response Application Informational Success
ArcSight Specific Device Event Class IDs
DeviceEventClassId Description Object Behavior Technique Device Group Significance Outcome
MONITOR_DATAMONITORS_ACTIVE_PROB
monitor:101 Host/Application Execute/Response Application Informational Success
ES
monitor:102 MONITOR_EVENT_BROKER_INSERT_TIME Host/Application Execute/Response Application Informational Success
monitor:103 MONITOR_EVENT_BROKER_LOAD Host/Application Execute/Response Application Informational Success
monitor:104 MONITOR_AGENTS_EVENTS_OUTPUT Host/Application Execute/Response Application Informational Success
monitor:105 MONITOR_AGENTS_EVENTS_INPUT Host/Application Execute/Response Application Informational Success
monitor:106 MONITOR_AGENTS_EVENTS_FILTERED Host/Application Execute/Response Application Informational Success
MONITOR_AGENTS_EVENTS_AGGREGATE
monitor:107 Host/Application Execute/Response Application Informational Success
D
monitor:108 MONITOR_AGENTS_EPS Host/Application Execute/Response Application Informational Success
monitor:109 MONITOR_AGENTS_EPS_OUTPUT Host/Application Execute/Response Application Informational Success
monitor:110 MONITOR_AGENTS_EPS_INPUT Host/Application Execute/Response Application Informational Success
monitor:111 MONITOR_AGENTS_EPS_FILTERED Host/Application Execute/Response Application Informational Success
monitor:112 MONITOR_AGENTS_EPS_AGGREGATED Host/Application Execute/Response Application Informational Success
monitor:113 MONITOR_AGENTS_CACHE_SIZE Host/Resource/Memory Execute/Response Application Informational Success
monitor:114 MONITOR_ACTIVE_LISTS_ENTRIES Host/Application Execute/Response Application Informational Success
MONITOR_ACTIVE_LISTS_TEMPORARY_LI
monitor:115 Host/Application Execute/Response Application Informational Success
STS
monitor:116 MONITOR_ACTIVE_LISTS_USAGE Host/Application Execute/Response Application Informational Success
MONITOR_ACTIVE_LISTS_ENTRY_PERCEN
monitor:117 Host/Application Execute/Response Application Informational Success
T_USED
MONITOR_ACTIVE_LISTS_TEMPORARY_LI
monitor:118 Host/Application Execute/Response Application Informational Success
ST_COUNT
MONITOR_ACTIVE_LISTS_TEMPORARY_LI
monitor:119 Host/Application Execute/Response Application Informational Success
ST_ENTRY_COUNT
monitor:120 MONITOR_TOTAL_EVENTS_OUTPUT Host/Application Execute/Response Application Informational Success
monitor:121 MONITOR_TOTAL_EVENTS_INPUT Host/Application Execute/Response Application Informational Success
monitor:122 MONITOR_TOTAL_EVENTS_FILTERED Host/Application Execute/Response Application Informational Success
ArcSight Specific Device Event Class IDs
DeviceEventClassId Description Object Behavior Technique Device Group Significance Outcome
MONITOR_RULES_GENERATED_EVENT_CO
monitor:153 Host/Application Execute/Response Application Informational Success
UNT
MONITOR_RULES_PARTIAL_MATCH_COUN
monitor:154 Host/Application Execute/Response Application Informational Success
T
monitor:155 MONITOR_RULES_GC_EVENT_COUNT Host/Application Execute/Response Application Informational Success
monitor:156 MONITOR_RULES_GROUPBY_CELLS_SIZE Host/Application Execute/Response Application Informational Success
monitor:157 MONITOR_RULES_ACTIVE_RULES_COUNT Host/Application Execute/Response Application Informational Success
MONITOR_RULES_ACTIONS_TAKEN_COUN
monitor:158 Host/Application Execute/Response Application Informational Success
T
MONITOR_RULES_GENERATED_EVENT_CO
monitor:159 Host/Application Execute/Response Application Informational Success
UNT
monitor:160 MONITOR_SESSIONS_ACTIVE_TOTAL Host/Application Execute/Response Application Informational Success
monitor:161 MONITOR_ZONE_EVAL_COUNT Host/Application Execute/Response Application Informational Success
monitor:171 MONITOR_RESOURCES_ACTIVITY_INSERT Host/Resource Execute/Response Application Informational Success
MONITOR_RESOURCES_ACTIVITY_UPDAT
monitor:172 Host/Resource Execute/Response Application Informational Success
E
monitor:173 MONITOR_RESOURCES_ACTIVITY_DELETE Host/Resource Execute/Response Application Informational Success
MONITOR_ACTIVE_CHANNELS_EVENTS_IN
monitor:174 Host/Application Execute/Response Application Informational Success
SERT
MONITOR_ACTIVE_CHANNELS_EVENTS_C
monitor:175 Host/Application Execute/Response Application Informational Success
HANGE
monitor:180 MONITOR_NOTIFICATION_NEW_COUNT Host/Application Execute/Response Application Informational Success
MONITOR_NOTIFICATION_ESCALATED_CO
monitor:181 Host/Application Execute/Response Application Informational Success
UNT
monitor:190 MONITOR_PATTERNS_RUN_COUNT Host/Application Execute/Response Application Informational Success
monitor:191 MONITOR_PATTERNS_RUN_QUEUED Host/Application Execute/Response Application Informational Success
monitor:200 MONITOR_ASSETS_TOTAL_COUNT Host/Application Execute/Response Application Informational Success
monitor:201 MONITOR_ASSETS_SCANNER_EPS Host/Application Execute/Response Application Informational Success
ArcSight Specific Device Event Class IDs
DeviceEventClassId Description Object Behavior Technique Device Group Significance Outcome
MONITOR_ASSETS_RESOLUTIONS_PER_SE
monitor:202 Host/Application Execute/Response Application Informational Success
COND
MONITOR_ASSETS_AVERAGE_TIME_SCAN
monitor:203 Host/Application Execute/Response Application Informational Success
NER_EVENTS
MONITOR_ASSETS_RESOLUTIONS_AVERA
monitor:204 Host/Application Execute/Response Application Informational Success
GE_TIME
MONITOR_ASSETS_RESOLUTIONS_AVERA
monitor:205 Host/Application Execute/Response Application Informational Success
GE_TIME_SOURCE
MONITOR_ASSETS_RESOLUTIONS_AVERA
monitor:206 Host/Application Execute/Response Application Informational Success
GE_TIME_DESTINATION
MONITOR_SIDETABLE_GEO_INFO_HIT_RA
monitor:210 Host/Application/Database Execute/Response Application Informational Success
TE
monitor:211 MONITOR_SIDETABLE_GEO_INFO_INSERTS Host/Application/Database Execute/Response Application Informational Success
MONITOR_SIDETABLE_GEO_INFO_CACHE_
monitor:212 Host/Application/Database Execute/Response Application Informational Success
MISSES
monitor:213 MONITOR_SIDETABLE_GEO_INFO_SIZE Host/Application/Database Execute/Response Application Informational Success
MONITOR_SIDETABLE_CATEGORY_HIT_R
monitor:214 Host/Application/Database Execute/Response Application Informational Success
ATE
MONITOR_SIDETABLE_CATEGORY_INSERT
monitor:215 Host/Application/Database Execute/Response Application Informational Success
S
MONITOR_SIDETABLE_CATEGORY_CACHE
monitor:216 Host/Application/Database Execute/Response Application Informational Success
_MISSES
monitor:217 MONITOR_SIDETABLE_CATEGORY_SIZE Host/Application/Database Execute/Response Application Informational Success
monitor:218 MONITOR_SIDETABLE_AGENT_HIT_RATE Host/Application/Database Execute/Response Application Informational Success
monitor:219 MONITOR_SIDETABLE_AGENT_INSERTS Host/Application/Database Execute/Response Application Informational Success
MONITOR_SIDETABLE_AGENT_CACHE_MI
monitor:220 Host/Application/Database Execute/Response Application Informational Success
SSES
monitor:221 MONITOR_SIDETABLE_AGENT_SIZE Host/Application/Database Execute/Response Application Informational Success
monitor:222 MONITOR_SIDETABLE_DEVICE_HIT_RATE Host/Application/Database Execute/Response Application Informational Success
monitor:223 MONITOR_SIDETABLE_DEVICE_INSERTS Host/Application/Database Execute/Response Application Informational Success
ArcSight Specific Device Event Class IDs
DeviceEventClassId Description Object Behavior Technique Device Group Significance Outcome
MONITOR_SIDETABLE_DEVICE_CACHE_MI
monitor:224 Host/Application/Database Execute/Response Application Informational Success
SSES
monitor:225 MONITOR_SIDETABLE_DEVICE_SIZE Host/Application/Database Execute/Response Application Informational Success
monitor:226 MONITOR_SIDETABLE_LABELS_HIT_RATE Host/Application/Database Execute/Response Application Informational Success
monitor:227 MONITOR_SIDETABLE_LABELS_INSERTS Host/Application/Database Execute/Response Application Informational Success
MONITOR_SIDETABLE_LABELS_CACHE_MI
monitor:228 Host/Application/Database Execute/Response Application Informational Success
SSES
monitor:229 MONITOR_SIDETABLE_LABELS_SIZE Host/Application/Database Execute/Response Application Informational Success
monitor:230 MONITOR_FLOW_EVENT_RATE Host/Application Execute/Response Application Informational Success
monitor:231 MONITOR_FLOW_EVENT_COUNT Host/Application Execute/Response Application Informational Success
MONITOR_RULES_EVENTS_MATCHING_AN
monitor:232 Host/Application Execute/Response Application Informational Success
Y_RULE_COUNT
MONITOR_RULES_EVENTS_MATCHING_FIL
monitor:233 Host/Application Execute/Response Application Informational Success
TER_RULE_COUNT
MONITOR_RULES_EVENTS_MATCHING_JOI
monitor:234 Host/Application Execute/Response Application Informational Success
N_RULE_COUNT
monitor:235 MONITOR_RULES_MATCH_COUNT Host/Application Execute/Response Application Informational Success
monitor:240 MONITOR_TC_SIZE Host/Application Execute/Response Application Informational Success
monitor:260 MONITOR_SESSION_LISTS_LIST_COUNT Host/Application Execute/Response Application Informational Success
monitor:261 MONITOR_SESSION_LISTS_ENTRY_COUNT Host/Application Execute/Response Application Informational Success
MONITOR_SESSION_LISTS_ENTRY_CAPACI
monitor:262 Host/Application Execute/Response Application Informational Success
TY
MONITOR_SESSION_LISTS_ENTRY_PERCE
monitor:263 Host/Application Execute/Response Application Informational Success
NT_USED
MONITOR_SESSION_LISTS_QUERIES_PER_S
monitor:264 Host/Application Execute/Response Application Informational Success
ECOND
MONITOR_SESSION_LISTS_CHANGES_PER_
monitor:265 Host/Application Execute/Response Application Informational Success
SECOND
monitor:270 MONITOR_DB_FREESPACE_ARC_EVENT Host/Application Execute/Response Application Informational Success
ArcSight Specific Device Event Class IDs
DeviceEventClassId Description Object Behavior Technique Device Group Significance Outcome
MONITOR_DB_FREESPACE_ARC_EVENT_IN
monitor:271 Host/Application Execute/Response Application Informational Success
DEX
monitor:272 MONITOR_DB_FREESPACE_ARC_SYSTEM Host/Application Execute/Response Application Informational Success
MONITOR_DB_FREESPACE_ARC_SYSTEM_I
monitor:273 Host/Application Execute/Response Application Informational Success
NDEX
MONITOR_DB_FREESPACE_ARC_DBSM_TE
monitor:274 Host/Application Execute/Response Application Informational Success
ST
MONITOR_DB_FREESPACE_ARC_EVENT_P
monitor:275 Host/Application Execute/Response Application Informational Success
CT
MONITOR_DB_FREESPACE_ARC_EVENT_IN
monitor:276 Host/Application Execute/Response Application Informational Success
DEX_PCT
MONITOR_DB_FREESPACE_ARC_SYSTEM_
monitor:277 Host/Application Execute/Response Application Informational Success
PCT
MONITOR_DB_FREESPACE_ARC_SYSTEM_I
monitor:278 Host/Application Execute/Response Application Informational Success
NDEX_PCT
MONITOR_DB_FREESPACE_ARC_DBSM_TE
monitor:279 Host/Application Execute/Response Application Informational Success
ST_PCT
Per interface network input Linux
network:100 Host/Application Execute/Response Application Informational Success
/Monitor/Network/Usage/iface/In /proc/net/dev
Per interface network output Linux
network:101 Host/Application Execute/Response Application Informational Success
/Monitor/Network/Usage/iface/Out /proc/net/dev
Per interface network packet input Linux
network:102 /Monitor/Network/Usage/iface/PacketsIn Host/Application Execute/Response Application Informational Success
/proc/net/dev
Per interface network packet output Linux
network:103 /Monitor/Network/Usage/iface/PacketsOut Host/Application Execute/Response Application Informational Success
/proc/net/dev
notification:000 NOTIFICATION Host/Application Modify/Configuration Nothing Application Normal Nothing
NOTIFICATION_TRANSPORT_DISABLE
notification:100 Host/Application Modify/Configuration Nothing Application Informational/Alert Success
Notification has been disabled
ArcSight Specific Device Event Class IDs
DeviceEventClassId Description Object Behavior Technique Device Group Significance Outcome
NOTIFICATION_DISABLE_QUEUE_OVERFL
notification:101 OW Notification has been disabled because the Host/Application Modify/Configuration Nothing Application Informational/Alert Success
queue of notifications to be sent is too large
NOTIFICATION_TRANSPORT_ENABLE
notification:102 Host/Application Modify/Configuration Nothing Application Normal Success
Notification has been enabled
NOTIFICATION_ENABLE_QUEUE Notification
notification:103 has been enabled because the queue of Host/Application Modify/Configuration Nothing Application Normal Success
notifications is back under control
NOTIFICATION_DESTINATION_DISABLE A
notification:104 particular Notification Destination has been Host/Application Modify/Configuration Nothing Application Normal Success
disabled
NOTIFICATION_DESTINATION_DISABLE_T
RAFFIC A particular Notification Destination has
notification:105 Host/Application Modify/Configuration Nothing Application Normal Success
been disabled because too much traffic has been
directed at that Destination
NOTIFICATION_DESTINATION_ENABLE A
notification:106 particular Notification Destination has been Host/Application Modify/Configuration Nothing Application Normal Success
enabled
NOTIFICATION_EXPIRED A Notification
notification:107 Host/Application Execute/Response Nothing Application Informational/Error Failure
expired without being acknowledged
NOTIFICATION_UNDELIVERABLE No
notification:108 functioning Destination could be located for this Host/Application Execute/Response Nothing Application Informational/Error Failure
Notification
NOTIFICATION_PURGED Old Notification has
notification:109 Host/Application Modify/Configuration Nothing Application Normal Success
been purged
NOTIFICATION_ESCALATED Notification has
notification:110 Host/Application/Service Execute/Query Nothing Application Informational Success
been escelated to the next Destination level
NOTIFICATION_SENT_REQUIRES_ACKNOW
notification:111 LEDGMENT A Notification that requires Host/Application Execute/Query Application Informational Success
acknowledgement has been sent
notification:111v null Host/Application/Service Execute/Response Nothing Application Informational Success
ArcSight Specific Device Event Class IDs
DeviceEventClassId Description Object Behavior Technique Device Group Significance Outcome
PARTITION_MANAGER_TOTAL_FAILURE
partitionmanager:500 Host/Application/Service Execute/Response Nothing Application Informational/Error Failure
Partitions could not be managed
PARTITION_MANAGER_UNEXPECTED_ERR
partitionmanager:600 OR There was an unexpected error while Host/Application/Service Execute/Response Nothing Application Informational/Error Failure
managing partitions
NEW_PATTERN_DISCOVERED A previously
pattern:001 Host/Application Execute/Response Application Informational Success
unknown pattern of events was discovered
PATTERN_REDISCOVERED A previously
pattern:002 discovered pattern of events was observed once Host/Application Execute/Response Application Informational Success
again
queryviewer:100 QUERY_VIEWER_QUERY_SUCCEEDED Nothing Nothing Nothing Nothing Nothing Nothing
queryviewer:101 QUERY_VIEWER_QUERY_FAILED Nothing Nothing Nothing Nothing Nothing Nothing
quota:000 QUOTA Host/Resource Execute/Response Nothing Application Informational Attempt
QUOTA_MET resource usage has fallen below the
quota:100 Host/Resource Check/Resource Nothing Application Normal Success
fixed quota level
QUOTA_EXCEED resource usage has exceeded Informational/Warn
quota:101 Host/Resource Check/Resource Nothing Application Failure
the fixed quota level ing
QUOTA_ASSET_AUTOCREATION Asset
quota:102 Host/Application Execute/Response Application Informational/Alert Success
autocreation has exceeded a fixed quota
QUOTA_ASSET_AUTOCREATION_RATE Informational/Warn
quota:103 Host/Application Execute/Response Application Success
Asset autocreation is proceeding too rapidly ing
report:000 REPORT Host/Application Nothing Nothing Application Normal Nothing
REPORT_GENERATE Generated a new Archived
report:100 Host/Application Execute/Response Nothing Application Normal Success
Report configuration resource
REPORT_GENERATE_FAIL Failed to generate a
report:101 Host/Application Execute/Response Nothing Application Informational/Error Failure
new Archived Report configuration resource
REPORT_DELTA Generated a new delta
report:102 Host/Application Execute/Response Nothing Application Normal Success
Archived Report configuration resource
REPORT_CANCELLED This Report run was
report:103 Host/Application Execute/Response Application Informational Failure
cancelled by a user
ArcSight Specific Device Event Class IDs
DeviceEventClassId Description Object Behavior Technique Device Group Significance Outcome
RESOURCE_REFERENCE_UNRESOLVED_UR
resourcereference:100
I Could not locate a configuration resource using Host/Application Execute/Query Nothing Application Informational/Error Failure
the given universal resource identifer (URI)
rule:000 RULE Nothing Nothing Nothing Application Nothing Nothing
rule:100 RULE_FIRE Host/Application Execute/Query Application Normal Success
rule:101 RULE_MATCH Rule fired OnEveryEvent Host/Application Execute/Query Application Normal Success
rule:102 RULE_FIRST_MATCH Rule fired OnFirstEvent Host/Application Execute/Query Application Normal Success
RULE_SUBSEQUENT_MATCH Rule fired
rule:103 Host/Application Execute/Query Application Normal Success
OnSubsequentEvents
RULE_AGGREGATE Rule fired
rule:104 Host/Application Execute/Query Nothing Application Normal Success
OnEveryThreshold
RULE_FIRST_AGGREGATE Rule fired
rule:105 Host/Application Execute/Query Nothing Application Normal Success
OnFirstThreshold
RULE_SUBSEQUENT_AGGREGATE Rule fired
rule:106 Host/Application Execute/Query Nothing Application Normal Success
OnSubsequentThresholds
ArcSight Specific Device Event Class IDs
DeviceEventClassId Description Object Behavior Technique Device Group Significance Outcome