Trellix DLP Network - SaaS event reporting

Prev Next

A number of Trellix DLP Network - SaaS events are available in the Client Events page in ePO - SaaS. You can get additional information from the on-box syslog and a remote logging server if you have one enabled. The Client Events page also displays Appliance Management events.

Client Events

Go to the System Tree, and select the appliance for which you want to see the events. Select Actions, then go to AgentShow Client Events. Some events include reason codes that you can use to search log files.

Tip

Regularly purge the Client Events page to stop it from becoming full.

Event ID

UI event text

Description

15001

LDAP query failure

The query failed. Reasons are provided in the event descriptions.

15007

LDAP directory synchronization

Directory synchronization status.

185001

DLP scanning policy

Policy scanning events with reason codes:

  • 197 - Unable to load policy.

  • 258 - Unable to load rules.

  • 982 - Failed to load configuration.

210003

Resource usage reached critical level

Trellix DLP Network Prevent – SaaS can't analyze a message because the directory is critically full.

210900

Appliance ISO upgrade success

Appliance ISO upgrade failed

Appliance downgrading to lower version

Internal install image updated successfully

Failed to update internal install image

Appliance upgrade events with reason codes:

  • 983 — Appliance ISO upgrade failed. Detailed logs can be found under /rescue/logs/.

  • 984 — Appliance ISO upgrade success. The appliance was successfully upgraded to a higher version.

  • 985 — Appliance downgrading to a lower version. This event is sent when the downgrade attempt is initiated. Upgrade success or failure events are sent after the upgrade is complete.

    If a clean upgrade or downgrade is requested, the success or failure event is sent after the ePO - SaaS connection is established.

Internal installation image updates using SCP events:

  • 986 — Internal installation image was updated successfully.

  • 987 — Failed to update the internal installation image.

220000

User logon

User log-on events with reason codes:

  • 354 — GUI logon successful.

  • 355 — GUI logon failed.

  • 424 — SSH logon successful

  • 425 — SSH logon failed.

  • 426 — Appliance console logon successful.

  • 427 — Appliance console logon failed.

  • 430 — User switch successful.

  • 431 — User switch failed.

220001

User logoff

User log off events with reason codes:

  • 356 — GUI user logged off.

  • 357 — The session has expired.

  • 428 — The SSH user logged off.

  • 429 — The appliance console user logged off.

  • 432 — The user logged off.

220900

Certificate Install

  • Certificate installation success

  • Certificate installation failed: <reason>

A certificate might not get installed due to one of the following reasons:

  • Bad passphrase

  • No private key

  • Chain error

  • Bad certificate

  • Expired certificate

  • Not yet valid

  • Bad signature

  • Bad CA certificate

  • Chain too long

  • Wrong purpose

  • Revoked

  • Bad or missing CRL

The reason is also reported in the syslog. If the reason does not match any of the available reasons, it gives the default Certificate installation failed event.

240155

Capture PII Deletion

Personal data deletion succeeded.

244005

Misconfigured Trellix Logon Collector

Trellix Logon Collector client has an invalid configuration.

244006

Certificate rejected by MLC Server

Certificate rejected by Trellix Logon Collector.

244007

MLC client has started

Trellix Logon Collector client has started.

244008

MLC client has stopped

Trellix Logon Collector client has stopped.

244009

MLC client has been restarted

Trellix Logon Collector client has restarted.

244010

Invalid MLC certificate BER/DER data

The certificate is not base64 encoded.

244011

Illegal MLC Certificate footer

The certificate footer is not valid.

244012

Illegal MLC Certificate header

The certificate header is not valid.

244013

Extra data given to DerValue constructor

SSL error using certificate file.

244014

MLC

Trellix Logon Collector synchronization complete.

300000

Channel Event

Send a heartbeat signal to all channels.