List of events

The table contains all events related to Linux as displayed in the DriveLock Control Center or the DriveLock  Operations Center (DOC). All events below are triggered by DriveLock:

You can find a list of all events that are important in connection with DriveLock in the Events documentation at DriveLock Online Help..

The DriveLock Linux Agent sends the following events to the DES:

 

Event ID

Event level (Information, Warning, Error)

Event text

Description

105

Information

Service started

The [name] service was started.

108

Information

Service stopped

The service [name] was stopped.

110

Audit

Drive connected and unlocked

The drive [name] ([category]) was added to the system. It is a [type] bus device. The drive is [locked/unlocked] for this event's user account. Device Id: [ID] [ID] (Rev. [rev]) (Serial number [number]) Applied whitelist rule: [rule] Screen state (keyboard [Win]-[L]): [state]

111

Audit

Drive connected and locked

The drive [name] ([category]) was added to the system. It is controlled by {Product} because of company policy. As an ACL was applied to the drive, some users may no longer be able to access it. It is a [type] bus device. The drive is [locked/unlocked] for this event's user account. Device Id: [ID] [ID] (Rev. [rev]) (Serial number [number]) Applied whitelist rule: [rule] Screen state (keyboard [Win]-[L]): [state]

129

Audit

Device connected and locked

The device [name] was connected to the computer. It was locked due to company policy. Device type: [type] Hardware ID: [ID] Class ID: [ID] Applied whitelist rule: [rule] Screen state (keyboard [Win]-[L]): [state]

130

Audit

Device connected and not locked

The device [name] was connected to the computer. Device type: [type] Hardware ID: [ID] Class ID: [ID] Applied whitelist rule: [rule] Screen state (keyboard [Win]-[L]): [state]

131

Audit

Temporarily unlocked

{Product} Agent was temporarily unlocked by an administrator. Administrator computer: [ComputerName] (unique ID [ComputerGuid]). Administrator account: [UserName] (domain [Domain], SID [SID])

132

Audit

Temporary unlocked cancelled

The temporary unlock mode of the {Product} Agent was canceled by an administrator. Administrator computer: [ComputerName] (unique ID [ComputerGuid]). Administrator account: [UserName] (domain [Domain], SID [SID]

139

Warning

Temporary unlock ended

The temporary unlock mode of the {Product} Agent ended because the unlock time elapsed.

152

Warning

Policy storage extraction failed

The policy storage container [name] cannot be unpacked to the local computer. Some functions relying on files stored in this container may fail.

153

Warning

Configuration file applied

The configuration file [name] was successfully applied.

154

Error

Configuration file download error

The configuration file [name] could not be downloaded. Error code: [code] Error: [error]

158

Error

Configuration file error

The configuration file [name] could not be read. Error code: [code] Error: [error]

191

Warning

{PrefixEnterpriseService} selected

The {PrefixEnterpriseService} [name] was selected by {Product}. Connection ID: [ID] Used for: [Inventory/Recovery/Events]

192

Warning

{PrefixEnterpriseService} not available

No {PrefixEnterpriseService} is available because no valid server connection is configured.

199

Warning

Drive temporarily unlocked

Drive types temporarily unlocked by administrative intervention are[DriveType1] [DriveType2] [DriveType3] [DriveType4] [DriveType5] [DriveType6] [DriveType7] [DriveType8] [DriveType9] [DriveType10]

200

Warning

Devices temporarily unlocked

Device classes temporarily unlocked by administrative intervention are: [DeviceTypes]

221

Warning

Application hash database missing

The application hash database [FileName] is missing from the policy file storage. Please check if the group policy or configuration file is correctly applied. Rule: [ObjectID]

222

Warning

Cannot open application hash database

The application hash database [FileName] cannot be opened. Please verify the file using Management Console. The underlying application rule will not function. Rule: [ObjectID]

235

Error

SSL: Cannot set up

The encrypted communications layer (SSL) could not be set up. Error: [error]

236

Error

Remote control: Cannot set up server

The remote control server component coud not be set up. Agent remote control will be unavailable. Error: [error]

237

Error

Remote control: Internal error

Agent remote control: An internal SOAP communications error occurred. Error: [error]

238

SuccessAudit

Remote control: Function called

An Agent remote control function was called. Calling IP address: [IP address] Called function: [function]

243

Error

Cannot open database

A database could not be opened. Database file: [name] Error code: [code] Error: [error]

246

Error

Cannot store configuration status

The Agent cannot store the configuration status used by other {Product} components. Error code: [code] Error: [error]

247

Error

Cannot initialize configuration store

{Product} Agent cannot initialize the configuration database stores.

249

Error

Configuration file: Fall-back configuration applied

A configuration using configuration files was detected but no settings could be retrieved from a configuration database. {Product} will fall-back to a configuration where all removable drives are blocked.

250

Warning

Configuration file: Using cached copy

The configuration file [name] could not be loaded from its original location. A locally cached copy was used.

251

Error

Configuration file: Cannot extract

A {Product} configuration file could no be extracted.%rSettings from this file will not be applied. Database file: [name] Error code: [code] Error: [error]

264

Error

Cannot merge configuration database with RSoP

Cannot merge the configuration database [name] into the resulting set of policy.

287

Error

No server defined for inventory

No server is defined for uploading collected inventory data.

288

Information

Inventory collection successful

Hard- and software inventory data was successfully collected and uploaded. DES server: [server name] Connection ID: [ID]

289

Information

Inventory collection failed

An error occurred while collecting hard- and software inventory data.DES server: [server name] Connection ID: [ID] Error: [error]

294

Error

Cannot download centrally stored policy

The centrally stored policy [name] could not be downloaded. Server: [name] Error: [error]

295

Error

Centrally stored policy: Cannot extract

A centrally stored policy could no be extracted. Settings from this file will not be applied. Configuration ID: [ID] Error code: [code] Error: [error]

297

Error

Centrally stored policy: Fall-back configuration applied

A configuration using centrally stored policies was detected but no settings could be retrieved from a server. {Product} will fall-back to a configuration where all removable drives are blocked.

299

Information

Centrally stored policy downloaded

The centrally stored policy [name] was successfully downloaded. Configuration ID: [ID] Version: [version]

443

Error

Component start error

A {Product} system component could not be started on this computer. Error code: [code] Error: [error] Component ID: [ID]

473

Audit

Process blocked

The execution of a process was blocked by company policy. Process: [ProcessName] File Hash: [ProcessHash] Applied rule: [ObjectID] Rule type: [WlType] File owner (user name): [UserName] File owner (user sid): [SID] File version: [FileVersion] Certificate issuer: [CertIssuer] Certificate subject: [CertSubject] Certificate serial: [CertSerNo] Certificate thumb print: [CertThumbprint] Description: [VerDescription] Product: [VerProduct] Command line: [CmdLine] Parent Process: [ProcessName] ([ProcessGuid]

474

Audit

Process started

A process was started. Process: [ProcessName] File Hash: [ProcessHash] Applied rule: [ObjectID] Rule type: [WlType] File owner (user name): [UserName] File owner (user sid): [SID] File version: [FileVersion] Certificate issuer: [CertIssuer] Certificate subject: [CertSubject] Certificate serial: [CertSerNo] Certificate thumb print: [CertThumbprint] Description: [VerDescription] Product: [VerProduct] Unique Process ID: [ProcessGuid] Command line: [CmdLine] Parent Process: [ProcessName] ([ProcessGuid]

520

Error

All {PrefixES} not reachable

Cannot load company policy. All configured {PrefixEnterpriseService}s are not reachable.

521

Error

Cannot determine computer token

Cannot determine the computer token. Error code: [code] Error: [error]

522

Error

Error loading policy assignments

An error occurred while loading policy assignments from server [name]. Error: [error]

523

Error

Policy integrity check failed

The integrity of an assigned policy could not be verified.%rPolicy ID: [ID] Policy name: [name] Actual hash: [value] Expected hash: [value]

533

Warning

No policy - wiped

No valid policy available - the company policy was wiped because the computer was offline for a long period of time.

546

Warning

Application control temporarily disabled

Application control was temporarily disabled by administrative intervention. Learn written files: [LearnWrittenFiles] Learn executed files: [LearnExecutedFiles]

584

Information

Inventory started

Inventory generation was triggered by DES.

593

Information

Machine learning completed

Machine learning for local application whitelist was completed.

594

Error

Error during machine learning

An error occurred during machine learning of the local application whitelist. Step: [StepName] Error code: [ErrorCode]

595

Error

Error during machine learning

An error occurred during machine learning of executable file "[FileName]". Error code: [ErrorCode] Error: [ErrorMessage]

596

Information

Machine learning completed

Machine learning of executable file "[FileName]" completed. Reason: [AlfLearnReason]

597

Error

Application control license required

The company policy contains settings for application control features requiring a special license which is not present on the system. Error: [ErrorMessage]

639

Error

Server certificate error

Server certificate error detected. Certificate: [name]. Error message: [text]

648

Audit

DLL blocked

The loading of a DLL was blocked by company policy. Process: [ProcessName] ([ProcessGuid]) Applied rule: [ObjectID] Rule type: [WlType] DLL File Name: [ProcessName] DLL File Hash: [ProcessHash] File owner (user name): [UserName] File owner (user sid): [SID] File version: [FileVersion] Certificate issuer: [CertIssuer] Certificate subject: [CertSubject] Certificate serial: [CertSerNo] Certificate thumb print: [CertThumbprint] Description: [VerDescription] Product: [VerProduct]

649

Audit

DLL loaded

A DLL was loaded. Process: [ProcessName] ([ProcessGuid]) Applied rule: [ObjectID] Rule type: [WlType] DLL File Name: [ProcessName] DLL File Hash: [ProcessHash] File owner (user name): [UserName] File owner (user sid): [SID] File version: [FileVersion] Certificate issuer: [CertIssuer] Certificate subject: [CertSubject] Certificate serial: [CertSerNo] Certificate thumb print: [CertThumbprint] Description: [VerDescription] Product: [VerProduct]

679

Information

Machine learning started

Machine learning for local application whitelist was started.