User Information Account Name : <read from session> Account Domain: <Current Domain>
Network Information Client Address: <IP Address> Client Browser :< browser from which app is run>
Configuration Information
Name : <Value> Parent: <Value>
Network Information Client Address: <IP Address> Client Browser :<browser from which app is run>
Old value
Name : <Value>
New value
Parent: <Value>
Parent : <Value>
Name : <Value> Parent: <Value> Description: <Value>
Event Details: Rule <1> <event information here. >
Description: <Value>
Event Details: Rule <1> <event information here.>
User Information: Account Name: <Value> Account Domain: <Value>
Network Information: Client Address: <Value> Client Browser Version: <Value>
Configuration Information:
Rule Name: <Rule Name> Show For:<Value> Breakup Column Name: <Value> Breakup Display Name: <Value> Breakup Seperator: <Value> Breakup Terminator: <Value>
Process Rule <Rule Number> Process Column Name: <Value> Process Display Name:<Value> Seperator: <Value> Terminator: <Value>
Event Rule <Rule Number> Log Type: <Value> Event Type: <Value> Category: <Value> Event ID:<Value> Source: <Value> User: <Value> Description: <Value> Description Exception:<Value>
Old value Rule Name: <Value> Active: <Value>
New value Rule Name: <Value> Active: <Value>
Old value User Event Threshold : <Value> Purge user data older than : <Value> Behaviour Event Threshold : <Value> Behaviour Correlation Threshold : <Value> Behaviour Learning Period Value : <Value> Top activities displayed : <Value> Enterprise activity interval : <Value> DNS Url : <Value> ProcessLib : <Value> Monitor enterprise activity : Yes/No Select Purge user data older than : <Value> User Behaviour Correlation Monitoring : Yes/No Behaviour Learning Period : <Value> Select DNS : <Value> Select Process : <Value>
New value User Event Threshold : <Value> Purge user data older than : <Value> Behaviour Event Threshold : <Value> Behaviour Correlation Threshold : <Value> Behaviour Learning Period Value : <Value> Top activities displayed : <Value> Enterprise activity interval : <Value> DNS Url : <Value> ProcessLib : <Value> Monitor enterprise activity : Yes/No Select Purge user data older than : <Value> User Behaviour Correlation Monitoring : Yes/No Behaviour Learning Period : <Value> Select DNS : <Value> Select Process : <Value>
Configuration Information: Display Name:<Value> Url:<Value>
Configuration Information: Display Name: <Value> Url: <Value>
Rule Name: <Value>
Configuration Information: Behaviour baseline: Reset
Old Value Name : <Value> Weightage: <Value>
New Value Name : <Value> Weightage:<Value>
Name : <Value> Weightage: <Value>
Old value ArchiveFrequency: <Value> ArchivePath: <Value> ArchivePurgeFrequency: <Value>
New value ArchiveFrequency: <Value> ArchivePath: <Value> ArchivePurgeFrequency: <Value>
Configuration Information: Old configuration: SQL Server Enterprise: <Value> Max history count: <Value> New configuration: SQL Server Enterprise: <Value> Max history count: <Value>
Configuration Information: Report name: <Value> Purge From Datetime: <Value> Purge To Datetime: <Value>
New value Destination Name:<Value> PortNo:<Value> Description: Active: <Value> QueueCabs: <Value> Encrypt Data: <Value>
Configuration Information: Old value: Destination Name: <Value> PortNo: <Value> Description:: Active: <Value> Encrypt Data: <Value>
Collection Master:<Value>
Configuration Information: Collection Point Name: <Value> Collection Point Display Name: <Value>
Cab Name:<Value>
New value Behavior Type:<Value> Behavior Filter:<Value>
Old value Behavior Type:<Value> Behavior Filter:<Value> New value Behavior Type:<Value> Behavior Filter:<Value>
Behavior Type:<Value> Behavior filter:<Value>
Configuration Information: Configuration name: <Value> Field seperator: <Value> Logfile extension: <Value> Logfile folder: <Value> Log type: <Value>
Configuration Information: Configuration name Old value: <Value> New value: <Value>
Configuration Information: Port number: <Value> Drop rate: <Value> Decode packet: <Value> Record binary: <Value>
Configuration Information: Old Value Port number: <Value> Drop rate: <Value> Decode packet: <Value> Record binary: <Value> New Value Port number: <Value> Drop rate: <Value> Decode packet: <Value> Record binary: <Value>
Configuration Information: Deleted Port details Port number: <Value> Drop Rate: <Value> Decode Packet: <Value> Record Binary: <Value>
Configuration Information: A new syslog port is added Receiver port number: <Value> Description: <Value> Cache path: <Value> Override archive purge frequency: <Value>
Configuration Information: Old value Receiver port number: <Value> Description: <Value> Cache path: <Value> Override archive purge frequency: <Value> New value Receiver port number: <Value> Description: <Value> Cache path: <Value> Override archive purge frequency: <Value> Archive purge frequency: <Value>
Configuration Information: Deleted syslog port details Receiver port number: <Value> Description: <Value> Cache path: <Value> Override archive purge frequency: <Value> Archive purge frequency: <Value>
Configuration Information: A new VCP port is added Port number: <Value> Description: <Value> Cache path: <Value> Override archive purge frequency: <Value> Archive purge frequency: <Value>
Configuration Information: Deleted VCP port details Port number: <Value> Description: <Value> Cache path: <Value> Override archive purge frequency: <Value> Archive purge frequency: <Value>
Configuration Information: Netflow receiver Old value: <Value> New value: <Value>
Configuration Information: SMTP Server Old value: <Value> New value: <Value>
Configuration Information: Report header Old value: <Value> New value: <Value>
Name : <Value> Description: <Value> Group with Systems based on <System Type:/IP Subnet:/Selected Systems:> <values here>
Description: <Value> Systems: <Value>
New value Description: <Value> Systems: <Value>
Asset value: <Value>
Configuration Information Incident Name: <Value> Event ID:<Value> Event Time:<Value> Event Source:<Value> Log Type:<Value> Event Type: <Value> User:<Value> Description:<Value> Risk Value:<Value> Risk Description:<Value>
Actions:
E-mail <details here>
RSS: <details here>
Beep: <details here>
Net Message: <details here>
SNMP: <details here>
Syslog: <details here>
Agent Remedial Action: <details here>
Console Remedial Action: <details here>
Name : <Value> Status: Active/Inactive
Old Value
Actions: <E-mail:/RSS:/Beep:Net Message:/SNMP:/Syslog:/Agent Remedial Action:/Console Remedial Action:> <details here>
<E-mail:/RSS:/Beep:Net Message:/SNMP:/Syslog:/Agent Remedial Action:/Console Remedial Action:> <details here>
An Alert was modified in the EventTracker application User Information: Account Name: <Value> Account Domain: <Value>
Name : <Value> Thread level: <Value> Threshold level: <Value> Status: <Active/Inactive>
Event Details: Rule <Number> <event information here. Repeat for as many entered.>
Event Filters: Rule <Number> <event information here. Repeat for as many entered.>
Custom Details: <custom information here>
Groups/Systems: <Groups/systems selected here>
Console Remedial Action: <details here></td> </tr>
Also for Succesful creation of manual collection point
Also for Successful creation of manual collection point. Event Source will be EventTracker
Configuration Information Name : <Value> Old value Type: <Value> New value Type: <Value>
Account Name: <User Name> Account Domain: <Domain name>
Network Information:
Client Network Address: <Network Address> Client Browser Version: Gecko v1.0.
Failure Information:
Failure Reason: Invalid username or password
Account Name: <User name> Account Domain: <Domain name>
Client Network Address: <Network Address> Client Browser Version: IE v7.
Refine User: Refine Desc: Filter User: Filter Desc: Sort by:Computer Export type:PDF file RSS feed:None Report Header:EventLogCentral Report Footer:
OVALTransFilePath = C:\Program Files\Prism Microsystems\EventTracker\Agent\SCAP\NEMO\Output1270543003612\OVALResults.html, OVALResultPath = C:\Program Files\Prism Microsystems\EventTracker\Agent\SCAP\NEMO\Output1270543003612\OVAL_Result.xml, OVALSysCharPath = C:\Program Files\Prism Microsystems\EventTracker\Agent\SCAP\NEMO\Output1270543003612\OVALSysChar.xml, XCCDFResultPath = C:\Program Files\Prism Microsystems\EventTracker\Agent\SCAP\NEMO\Output1270543003612\XCCDFResults.xml.