List of events
The table contains all events related to Linux as displayed in the DriveLock Control Center or the DriveLock Operations Center (DOC). All events below are triggered by DriveLock:
You can find a list of all events that are important in connection with DriveLock in the Events documentation at DriveLock Online Help..
The DriveLock Linux Agent sends the following events to the DES:
Event ID |
Event level (Information, Warning, Error) |
Event text |
Description |
---|---|---|---|
105 |
Information |
Service started |
The [name] service was started. |
108 |
Information |
Service stopped |
The service [name] was stopped. |
110 |
Audit |
Drive connected and unlocked |
The drive [name] ([category]) was added to the system. It is a [type] bus device. The drive is [locked/unlocked] for this event's user account. Device Id: [ID] [ID] (Rev. [rev]) (Serial number [number]) Applied whitelist rule: [rule] Screen state (keyboard [Win]-[L]): [state] |
111 |
Audit |
Drive connected and locked |
The drive [name] ([category]) was added to the system. It is controlled by {Product} because of company policy. As an ACL was applied to the drive, some users may no longer be able to access it. It is a [type] bus device. The drive is [locked/unlocked] for this event's user account. Device Id: [ID] [ID] (Rev. [rev]) (Serial number [number]) Applied whitelist rule: [rule] Screen state (keyboard [Win]-[L]): [state] |
129 |
Audit |
Device connected and locked |
The device [name] was connected to the computer. It was locked due to company policy. Device type: [type] Hardware ID: [ID] Class ID: [ID] Applied whitelist rule: [rule] Screen state (keyboard [Win]-[L]): [state] |
130 |
Audit |
Device connected and not locked |
The device [name] was connected to the computer. Device type: [type] Hardware ID: [ID] Class ID: [ID] Applied whitelist rule: [rule] Screen state (keyboard [Win]-[L]): [state] |
131 |
Audit |
Temporarily unlocked |
{Product} Agent was temporarily unlocked by an administrator. Administrator computer: [ComputerName] (unique ID [ComputerGuid]). Administrator account: [UserName] (domain [Domain], SID [SID]) |
132 |
Audit |
Temporary unlocked cancelled |
The temporary unlock mode of the {Product} Agent was canceled by an administrator. Administrator computer: [ComputerName] (unique ID [ComputerGuid]). Administrator account: [UserName] (domain [Domain], SID [SID] |
139 |
Warning |
Temporary unlock ended |
The temporary unlock mode of the {Product} Agent ended because the unlock time elapsed. |
152 |
Warning |
Policy storage extraction failed |
The policy storage container [name] cannot be unpacked to the local computer. Some functions relying on files stored in this container may fail. |
153 |
Warning |
Configuration file applied |
The configuration file [name] was successfully applied. |
154 |
Error |
Configuration file download error |
The configuration file [name] could not be downloaded. Error code: [code] Error: [error] |
158 |
Error |
Configuration file error |
The configuration file [name] could not be read. Error code: [code] Error: [error] |
191 |
Warning |
{PrefixEnterpriseService} selected |
The {PrefixEnterpriseService} [name] was selected by {Product}. Connection ID: [ID] Used for: [Inventory/Recovery/Events] |
192 |
Warning |
{PrefixEnterpriseService} not available |
No {PrefixEnterpriseService} is available because no valid server connection is configured. |
199 |
Warning |
Drive temporarily unlocked |
Drive types temporarily unlocked by administrative intervention are[DriveType1] [DriveType2] [DriveType3] [DriveType4] [DriveType5] [DriveType6] [DriveType7] [DriveType8] [DriveType9] [DriveType10] |
200 |
Warning |
Devices temporarily unlocked |
Device classes temporarily unlocked by administrative intervention are: [DeviceTypes] |
221 |
Warning |
Application hash database missing |
The application hash database [FileName] is missing from the policy file storage. Please check if the group policy or configuration file is correctly applied. Rule: [ObjectID] |
222 |
Warning |
Cannot open application hash database |
The application hash database [FileName] cannot be opened. Please verify the file using Management Console. The underlying application rule will not function. Rule: [ObjectID] |
235 |
Error |
SSL: Cannot set up |
The encrypted communications layer (SSL) could not be set up. Error: [error] |
236 |
Error |
Remote control: Cannot set up server |
The remote control server component coud not be set up. Agent remote control will be unavailable. Error: [error] |
237 |
Error |
Remote control: Internal error |
Agent remote control: An internal SOAP communications error occurred. Error: [error] |
238 |
SuccessAudit |
Remote control: Function called |
An Agent remote control function was called. Calling IP address: [IP address] Called function: [function] |
243 |
Error |
Cannot open database |
A database could not be opened. Database file: [name] Error code: [code] Error: [error] |
246 |
Error |
Cannot store configuration status |
The Agent cannot store the configuration status used by other {Product} components. Error code: [code] Error: [error] |
247 |
Error |
Cannot initialize configuration store |
{Product} Agent cannot initialize the configuration database stores. |
249 |
Error |
Configuration file: Fall-back configuration applied |
A configuration using configuration files was detected but no settings could be retrieved from a configuration database. {Product} will fall-back to a configuration where all removable drives are blocked. |
250 |
Warning |
Configuration file: Using cached copy |
The configuration file [name] could not be loaded from its original location. A locally cached copy was used. |
251 |
Error |
Configuration file: Cannot extract |
A {Product} configuration file could no be extracted.%rSettings from this file will not be applied. Database file: [name] Error code: [code] Error: [error] |
264 |
Error |
Cannot merge configuration database with RSoP |
Cannot merge the configuration database [name] into the resulting set of policy. |
287 |
Error |
No server defined for inventory |
No server is defined for uploading collected inventory data. |
288 |
Information |
Inventory collection successful |
Hard- and software inventory data was successfully collected and uploaded. DES server: [server name] Connection ID: [ID] |
289 |
Information |
Inventory collection failed |
An error occurred while collecting hard- and software inventory data.DES server: [server name] Connection ID: [ID] Error: [error] |
294 |
Error |
Cannot download centrally stored policy |
The centrally stored policy [name] could not be downloaded. Server: [name] Error: [error] |
295 |
Error |
Centrally stored policy: Cannot extract |
A centrally stored policy could no be extracted. Settings from this file will not be applied. Configuration ID: [ID] Error code: [code] Error: [error] |
297 |
Error |
Centrally stored policy: Fall-back configuration applied |
A configuration using centrally stored policies was detected but no settings could be retrieved from a server. {Product} will fall-back to a configuration where all removable drives are blocked. |
299 |
Information |
Centrally stored policy downloaded |
The centrally stored policy [name] was successfully downloaded. Configuration ID: [ID] Version: [version] |
443 |
Error |
Component start error |
A {Product} system component could not be started on this computer. Error code: [code] Error: [error] Component ID: [ID] |
473 |
Audit |
Process blocked |
The execution of a process was blocked by company policy. Process: [ProcessName] File Hash: [ProcessHash] Applied rule: [ObjectID] Rule type: [WlType] File owner (user name): [UserName] File owner (user sid): [SID] File version: [FileVersion] Certificate issuer: [CertIssuer] Certificate subject: [CertSubject] Certificate serial: [CertSerNo] Certificate thumb print: [CertThumbprint] Description: [VerDescription] Product: [VerProduct] Command line: [CmdLine] Parent Process: [ProcessName] ([ProcessGuid] |
474 |
Audit |
Process started |
A process was started. Process: [ProcessName] File Hash: [ProcessHash] Applied rule: [ObjectID] Rule type: [WlType] File owner (user name): [UserName] File owner (user sid): [SID] File version: [FileVersion] Certificate issuer: [CertIssuer] Certificate subject: [CertSubject] Certificate serial: [CertSerNo] Certificate thumb print: [CertThumbprint] Description: [VerDescription] Product: [VerProduct] Unique Process ID: [ProcessGuid] Command line: [CmdLine] Parent Process: [ProcessName] ([ProcessGuid] |
520 |
Error |
All {PrefixES} not reachable |
Cannot load company policy. All configured {PrefixEnterpriseService}s are not reachable. |
521 |
Error |
Cannot determine computer token |
Cannot determine the computer token. Error code: [code] Error: [error] |
522 |
Error |
Error loading policy assignments |
An error occurred while loading policy assignments from server [name]. Error: [error] |
523 |
Error |
Policy integrity check failed |
The integrity of an assigned policy could not be verified.%rPolicy ID: [ID] Policy name: [name] Actual hash: [value] Expected hash: [value] |
533 |
Warning |
No policy - wiped |
No valid policy available - the company policy was wiped because the computer was offline for a long period of time. |
546 |
Warning |
Application control temporarily disabled |
Application control was temporarily disabled by administrative intervention. Learn written files: [LearnWrittenFiles] Learn executed files: [LearnExecutedFiles] |
584 |
Information |
Inventory started |
Inventory generation was triggered by DES. |
593 |
Information |
Machine learning completed |
Machine learning for local application whitelist was completed. |
594 |
Error |
Error during machine learning |
An error occurred during machine learning of the local application whitelist. Step: [StepName] Error code: [ErrorCode] |
595 |
Error |
Error during machine learning |
An error occurred during machine learning of executable file "[FileName]". Error code: [ErrorCode] Error: [ErrorMessage] |
596 |
Information |
Machine learning completed |
Machine learning of executable file "[FileName]" completed. Reason: [AlfLearnReason] |
597 |
Error |
Application control license required |
The company policy contains settings for application control features requiring a special license which is not present on the system. Error: [ErrorMessage] |
639 |
Error |
Server certificate error |
Server certificate error detected. Certificate: [name]. Error message: [text] |
648 |
Audit |
DLL blocked |
The loading of a DLL was blocked by company policy. Process: [ProcessName] ([ProcessGuid]) Applied rule: [ObjectID] Rule type: [WlType] DLL File Name: [ProcessName] DLL File Hash: [ProcessHash] File owner (user name): [UserName] File owner (user sid): [SID] File version: [FileVersion] Certificate issuer: [CertIssuer] Certificate subject: [CertSubject] Certificate serial: [CertSerNo] Certificate thumb print: [CertThumbprint] Description: [VerDescription] Product: [VerProduct] |
649 |
Audit |
DLL loaded |
A DLL was loaded. Process: [ProcessName] ([ProcessGuid]) Applied rule: [ObjectID] Rule type: [WlType] DLL File Name: [ProcessName] DLL File Hash: [ProcessHash] File owner (user name): [UserName] File owner (user sid): [SID] File version: [FileVersion] Certificate issuer: [CertIssuer] Certificate subject: [CertSubject] Certificate serial: [CertSerNo] Certificate thumb print: [CertThumbprint] Description: [VerDescription] Product: [VerProduct] |
679 |
Information |
Machine learning started |
Machine learning for local application whitelist was started. |