100 |
DriveLock |
no |
Information |
Service installed |
The [Info.ServiceName] service was installed. |
101 |
DriveLock |
no |
Information |
Service removed |
The [Info.ServiceName] service was removed. |
102 |
DriveLock |
no |
Error |
Cannot remove service |
The [Info.ServiceName] service could not be removed. |
103 |
DriveLock |
no |
Error |
Control handler error |
The control handler could not be installed. |
104 |
DriveLock |
no |
Error |
Initialization failed |
The initialization process failed. |
105 |
DriveLock |
no |
Information |
Service started |
The [Info.ServiceName] service was started.
Version: [Info.InstalledVersion] |
106 |
DriveLock |
no |
Error |
Unsupported request |
The [Info.ServiceName] service received an unsupported request. |
107 |
DriveLock |
no |
Information |
Debug message |
Debug: [Info.DebugMsg] |
108 |
DriveLock |
no |
Information |
Service stopped |
The service [Info.ServiceName] was stopped. |
109 |
DriveLock |
no |
Information |
Trace message |
Trace: [Info.DebugMsg] |
110 |
DriveLock |
no |
SuccessAudit |
Drive connected and unlocked |
The drive [Info.DriveLetter] ([Drive.StorageType]) was added to the system.
It is a [Drive.StorageBus] bus device.
The drive is [Info.UserLockState] for this event's user account.
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Applied whitelist rule: [WhiteList.ObjectID]
Screen state (keyboard [Win]-[L]): [Info.SessionLockState]
Hardware Id: [Drive.HardwareID] |
111 |
DriveLock |
no |
Audit |
Drive connected and controlled |
The drive [Info.DriveLetter] ([Drive.StorageType]) was added to the system. It is controlled by DriveLock because of company policy.
As an ACL was applied to the drive, some users may no longer be able to access it.
It is a [Drive.StorageBus] bus device.
The drive is [Info.UserLockState] for this event's user account.
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Applied whitelist rule: [WhiteList.ObjectID]
Screen state (keyboard [Win]-[L]): [Info.SessionLockState]
Hardware Id: [Drive.HardwareID] |
112 |
DriveLock |
no |
Audit |
Drive connected, error locking drive |
The drive [Info.DriveLetter] ([Drive.StorageType]) was added to the system. It was not locked due to a system error.
It is a [Drive.StorageBus] bus device.
The drive should be [Info.UserLockState] for this event's user account.
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Applied whitelist rule: [WhiteList.ObjectID]
Screen state (keyboard [Win]-[L]): [Info.SessionLockState]
Hardware Id: [Drive.HardwareID] |
113 |
DriveLock |
no |
SuccessAudit |
Drive disconnected |
The drive [Info.DriveLetter] was disconnected from the system.
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Hardware Id: [Drive.HardwareID] |
114 |
DriveLock |
no |
Information |
Drive unlocked |
The drive [Info.DriveLetter] was unlocked on the system.
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Hardware Id: [Drive.HardwareID] |
115 |
DriveLock |
no |
Audit |
Drive state changed |
The drive [Info.DriveLetter] ([Drive.StorageType]) will be controlled by DriveLock.
As an ACL was applied to the drive, some users may no longer be able to access it.
It is a [Drive.StorageBus] bus device.
The drive is [Info.UserLockState] for this event's user account.
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Applied whitelist rule: [WhiteList.ObjectID]
Screen state (keyboard [Win]-[L]): [Info.SessionLockState]
Hardware Id: [Drive.HardwareID] |
116 |
DriveLock |
no |
Error |
Drive locking error |
Locking of drive [Info.DriveLetter] ([Drive.StorageType]) was attempted but the system reported an error.
It is a [Drive.StorageBus] bus device.
The drive should be [Info.UserLockState] for this event's user account.
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Applied whitelist rule: [WhiteList.ObjectID]
Screen state (keyboard [Win]-[L]): [Info.SessionLockState]
Hardware Id: [Drive.HardwareID] |
117 |
DriveLock |
no |
Information |
Licensing message |
Licensing: [Info.LicenseInfo] |
118 |
DriveLock |
no |
Error |
Account error |
Cannot add account [Info.UserName] (domain [Info.DomainName]) to the allow list. |
119 |
DriveLock |
no |
Error |
Configuration file error |
Configuration file error: [Info.FileName] |
120 |
DriveLock |
no |
Audit |
Serial port locked |
The serial port [Device.HardwareID] is controlled by DriveLock because of company policy.
As an ACL was applied to the port, some users may no longer be able to access it.
Friendly name: [Device.DisplayName]
Hardware Id: [Device.CompatibleID]
Class Id: [Device.ClassID] |
121 |
DriveLock |
no |
Error |
Error locking serial port |
Locking of serial port [Device.HardwareID] was attempted but the system reported an error.
Friendly name: [Device.DisplayName]
Hardware Id: [Device.CompatibleID]
Class Id: [Device.ClassID] |
122 |
DriveLock |
no |
Error |
Windows Firewall error |
Error while configuring the Windows Firewall. DriveLock remote control may not work on this agent.
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
123 |
DriveLock |
no |
Warning |
No GPO present |
Warning: No Group Policy configuration present. |
124 |
DriveLock |
no |
Information |
Device restarted |
The device [Device.DisplayName] is managed by DriveLock and was restarted due to a user change.
Hardware ID: [Device.HardwareID]
Class ID: [Device.ClassID] |
125 |
DriveLock |
no |
Error |
Device restart - Error |
The device [Device.DisplayName] is managed by DriveLock. The current user changed but there was an error restarting the device.
Hardware ID: [Device.HardwareID]
Class ID: [Device.ClassID] |
126 |
DriveLock |
no |
Warning |
Device restart - Needs reboot |
DriveLock attempted to restart the managed device [Device.DisplayName] due to a user change but the device does not support this. A reboot is required to re-enable the device.
Hardware ID: [Device.HardwareID]
Class ID: [Device.ClassID] |
127 |
DriveLock |
no |
Audit |
Parallel port locked |
The parallel port [Device.DisplayName] is controlled by DriveLock because of company policy.
As an ACL was applied to the port, some users may no longer be able to access it.
Friendly name: [Device.HardwareID]
Hardware Id: [Device.CompatibleID]
Class Id: [Device.ClassID] |
128 |
DriveLock |
no |
Error |
Error locking parallel port |
Locking of parallel port [Device.DisplayName] was attempted but the system reported an error.
Friendly name: [Device.HardwareID]
Hardware Id: [Device.CompatibleID]
Class Id: [Device.ClassID] |
129 |
DriveLock |
no |
FailureAudit |
Device connected and locked |
The device [Device.DisplayName] was connected to the computer. It was locked due to company policy.
Device type: [Device.DeviceType]
Hardware ID: [Device.HardwareID]
Class ID: [Device.ClassID]
Applied whitelist rule: [WhiteList.ObjectID]
Screen state (keyboard [Win]-[L]): [Info.SessionLockState] |
130 |
DriveLock |
no |
SuccessAudit |
Device connected and not locked |
The device [Device.DisplayName] was connected to the computer.
Device type: [Device.DeviceType]
Hardware ID: [Device.HardwareID]
Class ID: [Device.ClassID]
Applied whitelist rule: [WhiteList.ObjectID]
Screen state (keyboard [Win]-[L]): [Info.SessionLockState] |
131 |
DriveLock |
no |
SuccessAudit |
Temporarily unlocked |
DriveLock Agent was temporarily unlocked by an administrator.
Administrator computer: [Info.ComputerName] (unique ID [Info.ComputerGuid])
Administrator account: [Info.UserName2] (domain [Info.DomainName2], SID [Info.SID])
Unlock period: [Info.UnlockTime] [Info.UnlockUnit]
Reason: [Info.Reason] |
132 |
DriveLock |
no |
SuccessAudit |
Temporary unlocked cancelled |
The temporary unlock mode of the DriveLock Agent was canceled by an administrator.
Administrator computer: [Info.ComputerName] (unique ID [Info.ComputerGuid])
Administrator account: [Info.UserName2] (domain [Info.DomainName2], SID [Info.SID]) |
133 |
DriveLock |
no |
SuccessAudit |
File accessed |
File accessed.
File path: [File.Path]
File name: [File.FileName]
Drive: [File.DriveLetter]
File size: [File.Size]
File name hash: [File.MD5Hash]
File content hash: [FileContent.MD5Hash]
Access direction: [Info.AccessDirection]
Process: [Info.ProcessName]
Device identification: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber]) |
134 |
DriveLock |
no |
Error |
Agent not licensed |
DriveLock is not licensed to run on this computer. |
135 |
DriveLock |
no |
Error |
Logon error |
The user [Info.UserName] cannot be impersonated on this computer. Please check the user name and password in the configuration.
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
136 |
DriveLock |
no |
Error |
Shadow copy upload error |
Cannot upload shadow copy file [Info.FileName] to the central storage location [Info.UploadLocation].
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
137 |
DriveLock |
no |
Warning |
Conflicting policy detected |
A Microsoft policy that can conflict with a DriveLock policy was detected on this computer.
Refer to the DriveLock Manual for more information about this policy. It is recommended to disable the Microsoft policy. |
138 |
DriveLock |
no |
Error |
CD writer - Reboot required |
A CD writer ([Info.DriveLetter]) was restarted to change CD burning permissions.
Windows reported that a reboot is needed to complete the change. The drive may be disabled until the next reboot. |
139 |
DriveLock |
no |
Warning |
Temporary unlock ended |
The temporary unlock mode of the DriveLock Agent ended because the unlock time elapsed. |
140 |
DriveLock |
no |
SuccessAudit |
Volume mounted |
A DriveLock encrypted volume was mounted.
Status: [Info.CryptStatus]
Volume container: [EncryptedVolume.FileName]
Volume GUID: [EncryptedVolume.VolumeID]
Drive letter: [EncryptedVolume.DriveLetter]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber]) |
141 |
DriveLock |
no |
SuccessAudit |
Volume unmounted |
A DriveLock encrypted volume was unmounted.
Status: [Info.CryptStatus]
Volume container: [EncryptedVolume.FileName]
Volume GUID: [EncryptedVolume.VolumeID]
Drive letter: [EncryptedVolume.DriveLetter]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber]) |
142 |
DriveLock |
no |
SuccessAudit |
Volume created |
A DriveLock encrypted volume was created/formatted.
Status: [Info.CryptStatus]
Volume container: [EncryptedVolume.FileName]
Volume GUID: [EncryptedVolume.VolumeID]
File system: [EncryptedVolume.FileSystemType]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber]) |
143 |
DriveLock |
no |
SuccessAudit |
Password changed |
The password for a DriveLock encrypted volume was changed.
Status: [Info.CryptStatus]
Volume container: [EncryptedVolume.FileName]
Volume GUID: [EncryptedVolume.VolumeID]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber]) |
144 |
DriveLock |
no |
Information |
Network changed |
A network connection was changed.
Network adapter: [Info.NetAdapter]
Network location name: [Network.DisplayName]
Network location GUID: [Network.ObjectID] |
145 |
DriveLock |
no |
FailureAudit |
File blocked by content scanner |
File blocked by content scanner. Content does not match file extension.
File path: [File.Path]
File name: [File.FileName]
Drive: [File.DriveLetter]
File size: [File.Size]
File name hash: [File.MD5Hash]
File content hash: [FileContent.MD5Hash]
Access direction: [Info.AccessDirection]
Process: [Info.ProcessName]
Device ID: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Header: [Info.FileHeader] |
146 |
DriveLock |
no |
FailureAudit |
Process blocked |
The execution of a process was blocked by company policy.
Process: [Process.ProcessName]
File Hash: [Process.ProcessHash]
Applied rule: [WhiteList.ObjectID]
Rule type: [WhiteList.WlType] |
147 |
DriveLock |
no |
SuccessAudit |
Process started |
A process was started.
Process: [Process.ProcessName]
File Hash: [Process.ProcessHash]
Applied rule: [WhiteList.ObjectID]
Rule type: [WhiteList.WlType] |
148 |
DriveLock |
no |
FailureAudit |
File extension blocked |
File blocked by file filter. Access denied due to file type.
File path: [File.Path]
File name: [File.FileName]
Drive: [File.DriveLetter]
File size: [File.Size]
File name hash: [File.MD5Hash]
File content hash: [FileContent.MD5Hash]
Access direction: [Info.AccessDirection]
Process: [Info.ProcessName]
Device ID: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber]) |
149 |
DriveLock |
no |
Warning |
Network profile shutdown |
The computer is shut down because of a Network Profiles policy.
Network location GUID: [Network.ObjectID] |
150 |
DriveLock |
no |
Warning |
Network adapter disabled |
Network adapters are disabled because of a Network Profiles policy.
Network location GUID: [Network.ObjectID] |
151 |
DriveLock |
no |
Warning |
Windows Terminal Services disabled |
Windows Terminal Services are disabled on this computer.
DriveLock depends on Terminal Services to detect user changes in real-time.
Legacy functions are used to maintain DriveLock functionality, consider enabling Terminal Services. |
152 |
DriveLock |
no |
Warning |
Policy storage extraction failed |
The policy storage container [Info.PolicyStorageContainer] cannot be unpacked to the local computer.
Some functions relying on files stored in this container may fail. |
153 |
DriveLock |
no |
Warning |
Configuration file applied |
The configuration file [Info.FileName] was successfully applied. |
154 |
DriveLock |
no |
Error |
Configuration file download error |
The configuration file [Info.FileName] could not be downloaded.
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
155 |
DriveLock |
no |
Error |
Configuration file error |
The configuration file [Info.FileName] could not be loaded into the local registry.
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
156 |
DriveLock |
no |
Error |
Configuration file error |
A temporary copy of the configuration file [Info.FileName] could not be created.
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
157 |
DriveLock |
no |
Warning |
Configuration file error |
The configuration file [Info.FileName] is invalid or corrupt.
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
158 |
DriveLock |
no |
Warning |
Configuration file error |
The configuration file [Info.FileName] could not be read.
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
159 |
DriveLock |
no |
Warning |
Account error |
User account [Info.UserName] could not be impersonated to access the configuration file [Info.FileName].
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
160 |
DriveLock |
no |
Warning |
Disk Protection installation error |
Not enough disk space available to install and configure Disk Protection.
Required disk space: [Info.RequiredSpace] bytes
Available disk space: [Info.AvailableSpace] bytes |
161 |
DriveLock |
no |
Error |
Account error |
User account [Info.UserName] could not be impersonated to access the Disk Protection package.
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
162 |
DriveLock |
no |
Warning |
Disk Protection package download error |
The Disk Protection package could not be downloaded from [Info.URL]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
163 |
DriveLock |
no |
Warning |
Disk Protection installation error |
The Disk Protection package is not installed locally. |
164 |
DriveLock |
no |
Warning |
Disk Protection download successful |
The Disk Protection package was successfully downloaded. |
165 |
DriveLock |
no |
Warning |
Disk Protection installation error |
The Disk Protection package could not be extracted.
The file [Info.PackagePath] may be missing or corrupt. |
166 |
DriveLock |
no |
Warning |
Disk Protection installation error |
The Disk Protection configuration script [Info.ScriptFile] is missing in the DriveLock policy. |
167 |
DriveLock |
no |
Warning |
Disk Protection installation error |
The command line "[Info.CmdLine]" could not be executed.
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
168 |
DriveLock |
no |
Warning |
Disk Protection installation successful |
Disk Protection was successfully installed. |
169 |
DriveLock |
no |
Warning |
Disk Protection installation error |
Disk Protection installation failed. |
170 |
DriveLock |
no |
Warning |
Disk Protection installation error |
Disk Protection is configured on this computer but the installation failed. |
171 |
DriveLock |
no |
Warning |
Disk Protection installation error |
The status information file [Info.FileName] could not be created. |
172 |
DriveLock |
no |
Warning |
Disk Protection installation error |
The Disk Protection configuration script [Info.FileName] could not be copied to its target location.
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
173 |
DriveLock |
no |
SuccessAudit |
File created |
New file created.
File path: [File.Path]
File name: [File.FileName]
Drive: [File.DriveLetter]
File size: [File.Size]
File name hash: [File.MD5Hash]
File content hash: [FileContent.MD5Hash]
Access direction: [Info.AccessDirection]
Process: [Info.ProcessName]
Device identification: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber]) |
174 |
DriveLock |
no |
Warning |
Disk Protection installation prevented |
The Disk Protection should be installed but the installation is prevented by administrative intervention. |
175 |
DriveLock |
no |
Warning |
Disk Protection installation error |
The Disk Protection setup could not clean up installation files.
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
176 |
DriveLock |
no |
Warning |
Pre-boot authentication error |
Pre-boot authentication is configured on this computer but the initialization failed. |
179 |
DriveLock |
no |
Warning |
Disk Protection encryption started |
Disk Protection started encrypting local hard disks. |
181 |
DriveLock |
no |
Warning |
Disk Protection encryption successful |
Disk Protection successfully encrypted local hard disks. |
183 |
DriveLock |
no |
Warning |
Disk Protection decryption started |
Disk Protection started decrypting local hard disks. |
184 |
DriveLock |
no |
Warning |
Disk Protection decryption successful |
Disk Protection successfully decrypted local hard disks. |
185 |
DriveLock |
no |
Warning |
Disk Protection upload error |
The Disk Protection data [Info.LogFile] could not be uploaded to the DriveLock Enterprise Service.
Error [Info.ErrorMessage] |
186 |
DriveLock |
no |
Warning |
Disk Protection system error |
The log file [Info.LogArchive] could not be added to the log archive [Info.LogFile]. |
187 |
DriveLock |
no |
Warning |
Disk Protection system error |
Emergency Recovery Information could not be moved to [Info.TargetFolder].
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
188 |
DriveLock |
no |
Warning |
Disk Protection uninstallation successful |
Disk Protection was successfully uninstalled. |
189 |
DriveLock |
no |
Error |
Disk Protection installation - wrong package version |
Disk Protection installation or update was aborted because the wrong version of the installation package was detected.
Installed version: [Info.InstalledVersion]
Expected version: [Info.ExpectedVersion] |
190 |
DriveLock |
no |
Warning |
File already present |
The file [Info.PolicyStorageContainer] already existed in the temporary location when extracting Policy File storage from file [Info.FileName]. |
191 |
DriveLock |
no |
Warning |
DriveLock Enterprise Service selected |
The DriveLock Enterprise Service [Info.DesName] was selected by DriveLock.
Connection ID: [Info.ObjectID]
Used for: [Info.AgentServerType] |
192 |
DriveLock |
no |
Warning |
DriveLock Enterprise Service not available |
No DriveLock Enterprise Service is available because no valid server connection is configured. |
193 |
DriveLock |
no |
Warning |
Command line execution error |
The file [Info.CmdLine] does not exist while trying to execute an event command or script. |
194 |
DriveLock |
no |
Warning |
Command line execution error |
A process could not be created while executing an event command or script.
Command line: [Info.CmdLine]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
195 |
DriveLock |
no |
Warning |
Agent communication failed |
Internal agent communication failed while executing an event command or script with user permissions.
Command line: [Info.CmdLine]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
196 |
DriveLock |
no |
Warning |
Command line not executed |
No user is logged on. Therefore an event command or script could not be executed with user permissions.
Command line: [Info.CmdLine] |
197 |
DriveLock |
no |
Warning |
Command line executed (user) |
An event command or script was executed with user permissions.
Command line: [Info.CmdLine] |
198 |
DriveLock |
no |
Warning |
Command line executed |
An event command or script was executed with system permissions.
Command line: [Info.CmdLine] |
199 |
DriveLock |
no |
Warning |
Drive temporarily unlocked |
Drive types temporarily unlocked by administrative intervention are
[Info.DriveType1] [Info.DriveType2] [Info.DriveType3] [Info.DriveType4] [Info.DriveType5] [Info.DriveType6] [Info.DriveType7] [Info.DriveType8] [Info.DriveType9] [Info.DriveType10]
|
200 |
DriveLock |
no |
Warning |
Devices temporarily unlocked |
Device classes temporarily unlocked by administrative intervention are:
[Info.DeviceTypes]
|
202 |
DriveLock |
no |
Warning |
File copy error |
Copying existing files failed while encrypting volume [EncryptedVolume.FileName].
Volume GUID: [EncryptedVolume.VolumeID] |
203 |
DriveLock |
no |
Warning |
Files deleted |
Existing files were deleted from volume [EncryptedVolume.FileName].
Reason: [Info.AcDeleteReason]
Volume GUID: [EncryptedVolume.VolumeID] |
205 |
DriveLock |
no |
Warning |
File delete error |
Deleting existing files failed while encrypting volume [EncryptedVolume.FileName].
Volume GUID: [EncryptedVolume.VolumeID] |
206 |
DriveLock |
no |
Warning |
Disk Protection uninstallation failed |
Disk Protection uninstallation failed. |
207 |
DriveLock |
no |
Warning |
Disk Protection cannot apply configuration |
The Disk Protection configuration could not be applied. |
208 |
DriveLock |
no |
Warning |
Disk Protection key backup failed |
The Disk Protection key backup failed. |
209 |
DriveLock |
no |
Warning |
Disk Protection no license |
Disk Protection is configured to encrypt local hard disks but is not licensed on this computer. |
210 |
DriveLock |
no |
Warning |
Cannot enumerate PBA users |
Disk Protection cannot enumerate configured pre-boot authentication users. |
211 |
DriveLock |
no |
Warning |
Cannot add user to PBA |
Disk Protection cannot add user [Info.UserName] (domain [Info.DomainName]) to the pre-boot authentication user database. |
212 |
DriveLock |
no |
Warning |
Cannot remove user from PBA |
Disk Protection cannot remove user [Info.UserName] (domain [Info.DomainName]) from the pre-boot authentication user database. |
213 |
DriveLock |
no |
Warning |
Cannot deactivate PBA |
Pre-boot authentication cannot be deactivated while the hard disk is encrypted.
The DriveLock configuration is inconsistent and should be changed so that pre-boot authentication is active while hard disks are encrypted. |
214 |
DriveLock |
no |
Warning |
Could not read recovery information |
Encrypted container recovery information could not be read from file [Info.FileName] in order to upload this information to the server.
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
215 |
DriveLock |
no |
Warning |
Server or network error while uploading recovery information |
Uploading encrypted container recovery information from file [Info.FileName] failed with a server or network error.
Error: [Info.ErrorMessage] |
216 |
DriveLock |
no |
Warning |
Server or network error while uploading status file |
Uploading of status file [Info.FileName] failed with a server or network error.
Error: [Info.ErrorMessage] |
217 |
DriveLock |
no |
Warning |
Incompatible server version (needs update) |
The configured server is not compatible with this version of the agent. It must be upgraded in order to support all features of this version.
Missing method: [Info.MethodName] |
218 |
DriveLock |
no |
SuccessAudit |
File accessed |
File accessed.
File path: [File.Path]
File name: [File.FileName]
File name hash: [File.MD5Hash]
Access direction: [Info.AccessDirection]
Process: [Info.ProcessName] |
219 |
DriveLock |
no |
Warning |
File extension blocking |
File blocked. Access to file extension is not allowed.
File path: [File.Path]
File name: [File.FileName]
File name hash: [File.MD5Hash]
Access direction: [Info.AccessDirection]
Process: [Info.ProcessName] |
220 |
DriveLock |
no |
Warning |
Internal error with recovery information |
An internal error occurred while creating recovery information for encrypted volume [EncryptedVolume.FileName].
Volume GUID: [EncryptedVolume.VolumeID] |
221 |
DriveLock |
no |
Warning |
Application hash database missing |
The application hash database [Info.FileName] is missing from the policy file storage. Please check if the group policy or configuration file is correctly applied.
Rule: [WhiteList.ObjectID] |
222 |
DriveLock |
no |
Warning |
Cannot open application hash database |
The application hash database [Info.FileName] cannot be opened. Please verify the file using Management Console. The underlying application rule will not function.
Rule: [WhiteList.ObjectID] |
223 |
DriveLock |
no |
Warning |
Cannot apply application hash database |
The application hash database [Info.FileName] cannot be stored and applied to the Application Launch Filter driver. The underlying application rule will not function.
Rule: [WhiteList.ObjectID] |
224 |
DriveLock |
no |
Warning |
Encrypted volume password recovered |
A DriveLock Encrypted volume password was recovered.
Status: [Info.CryptStatus]
Volume container: [EncryptedVolume.FileName]
Volume GUID: [EncryptedVolume.VolumeID]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber]) |
225 |
DriveLock |
no |
Warning |
Illegal offline unlock attempt |
DriveLock detected an illegal attempt to unlock the agent using the offline unlock functionality. |
226 |
DriveLock |
no |
Warning |
Offline unlock requested |
An offline unlock request was initiated by the user. Request code: [Info.RequestCode] |
227 |
DriveLock |
no |
Error |
DriveLock program file tampered |
A DriveLock program file was tampered or changed or the digital signature could not be verified.
File: [Info.FileName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
228 |
DriveLock |
no |
Warning |
Event queue full |
The event queue was full and wrapped. Some older events were deleted and will not be forwarded to external targets. |
229 |
DriveLock |
no |
Warning |
Running in simulation mode |
DriveLock is running in simulation mode. Nothing will be locked or filtered. |
230 |
DriveLock |
no |
Warning |
SSL: Cannot create DH parameters |
The encrypted communications layer (SSL) could not create key exchange parameters (DH). Default values will be used resulting in weaker encryption. |
231 |
DriveLock |
no |
Error |
SSL: Cannot generate self-signed certificate |
The encrypted communications layer (SSL) could not create the self-signed certificate used for encryption. SSL will be unavailable.
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
232 |
DriveLock |
no |
Error |
SSL: Cannot open certificate file |
The encrypted communications layer (SSL) cannot open the certificate file used for encryption. SSL will be unavailable.
Certificate file: [Info.FileName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
233 |
DriveLock |
no |
Error |
SSL: Cannot convert certificate |
The encrypted communications layer (SSL) could not convert the certificate used for encryption to its internal format. SSL will be unavailable.
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
234 |
DriveLock |
no |
Error |
Cannot add port to Windows Firewall exceptions |
Error while adding a port exception to the Windows Firewall. DriveLock remote control may not work on this agent.
Port: [Info.Port]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
235 |
DriveLock |
no |
Error |
SSL: Cannot set up |
The encrypted communications layer (SSL) could not be set up.
Error: [Info.ErrorMessage] |
236 |
DriveLock |
no |
Error |
Remote control: Cannot set up server |
The remote control server component coud not be set up. Agent remote control will be unavailable.
Error: [Info.ErrorMessage] |
237 |
DriveLock |
no |
Error |
Remote control: Internal error |
Agent remote control: An internal SOAP communications error occurred.
Error: [Info.ErrorMessage] |
238 |
DriveLock |
no |
SuccessAudit |
Remote control: Function called |
An Agent remote control function was called.
Calling IP address: [Info.IPAddress]
Called function: [Info.FunctionName] |
239 |
DriveLock |
no |
SuccessAudit |
Remote control: HTTP-GET request |
A HTTP-GET request was sent to the Agent.
Requesting IP address: [Info.IPAddress]
Requested URL: [Info.URL] |
240 |
DriveLock |
no |
Warning |
GPO: Cannot cache locally |
A DriveLock group policy configuration database could not be cached locally.
GPO Object GUID: [Gpo.ObjectID]
GPO Name: [Gpo.GpoName]
Database file: [Info.FileName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
241 |
DriveLock |
no |
Error |
GPO: Cannot open and extract |
A DriveLock group policy configuration database could no opened and extracted.
Settings from this GPO object will not be applied.
GPO Object GUID: [Gpo.ObjectID]
GPO Name: [Gpo.GpoName]
Database file: [Info.FileName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
242 |
DriveLock |
no |
Error |
GPO: Fall-back configuration applied |
A group policy configuration was detected but no settings could be retrieved from the configuration databases.
DriveLock will fall-back to a configuration where all removable drives are blocked. |
243 |
DriveLock |
no |
Error |
GPO: Cannot open database |
A group policy configuration database could not be opened.
Database file: [Info.FileName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
244 |
DriveLock |
no |
Error |
GPO: Cannot access GPO |
DriveLock Agent cannot access Windows group policy configuration.
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
245 |
DriveLock |
no |
Information |
GPO: Configuration applied |
A group policy configuration was applied.
GPO Object GUID: [Gpo.ObjectID]
GPO Name: [Gpo.GpoName]
GPO Linked from: [Info.GpoLinkedFrom] |
246 |
DriveLock |
no |
Error |
Cannot store configuration status |
The Agent cannot store the configuration status used by other DriveLock components.
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
247 |
DriveLock |
no |
Error |
Cannot initialize configuration store |
DriveLock Agent cannot initialize the configuration database stores. |
248 |
DriveLock |
no |
Error |
DES: Queued file was deleted |
A file queued for uploading to the DriveLock Enterprise Service was deleted locally before it could be uploaded.
File name: [Info.FileName] |
249 |
DriveLock |
no |
Error |
Configuration file: Fall-back configuration applied |
A configuration using configuration files was detected but no settings could be retrieved from a configuration database.
DriveLock will fall-back to a configuration where all removable drives are blocked. |
250 |
DriveLock |
no |
Warning |
Configuration file: Using cached copy |
The configuration file [Info.FileName] could not be loaded from it's original location.
A locally cached copy was used. |
251 |
DriveLock |
no |
Error |
Configuration file: Cannot extract |
A DriveLock configuration file could no be extracted.
Settings from this file will not be applied.
Database file: [Info.FileName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
252 |
DriveLock |
no |
SuccessAudit |
Usage policy accepted |
Usage policy for drive [Info.DriveLetter] was accepted by the user.
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Hardware Id: [Drive.HardwareID] |
253 |
DriveLock |
no |
FailureAudit |
Usage policy declined |
Usage policy for drive [Info.DriveLetter] was declined by the user.
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Hardware Id: [Drive.HardwareID] |
254 |
DriveLock |
no |
Warning |
Usage policy: No user logged in |
Usage policy for drive [Info.DriveLetter] was not presented as no user is currently logged on. Proceeding as if the policy was declined. |
255 |
DriveLock |
no |
Information |
Deferred hash completed |
Deferred content hash generation completed.
File path: [File.Path]
File name: [File.FileName]
Drive: [File.DriveLetter]
File name hash: [File.MD5Hash]
File content hash: [FileContent.MD5Hash]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
|
256 |
DriveLock |
no |
Information |
File content changed |
File content changed.
File path: [File.Path]
File name: [File.FileName]
Drive: [File.DriveLetter]
Old file name hash: [File.MD5Hash]
Old file content hash: [FileContent.MD5Hash]
New file content hash: [Info.MD5Hash]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
|
257 |
DriveLock |
no |
SuccessAudit |
File deleted |
File deleted.
Process: [Info.ProcessName]
File path: [File.Path]
File name: [File.FileName]
Drive: [File.DriveLetter]
File name hash: [File.MD5Hash]
File content hash: [FileContent.MD5Hash]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
|
258 |
DriveLock |
no |
SuccessAudit |
File renamed |
File renamed.
Process: [Info.ProcessName]
Old file path: [File.Path]
Old file name: [File.FileName]
New file name: [Info.FileName]
Old file name hash: [File.MD5Hash]
File content hash: [FileContent.MD5Hash]
New file name hash: [Info.MD5Hash]
Drive: [File.DriveLetter]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
|
259 |
DriveLock |
no |
Information |
FIPS mode enabled |
DriveLock uses an embedded FIPS 140-2-validated cryptographic module (Certificate #1051) running on a Windows platform per FIPS 140-2 Implementation Guidance section G.5 guidelines.
FIPS mode was successfully enabled. |
260 |
DriveLock |
no |
Error |
FIPS mode activation failed |
DriveLock encryption: FIPS mode could not be activated due to error [Info.ErrorMessage]. |
261 |
DriveLock |
no |
Error |
Cannot start driver |
Cannot start the device driver [Info.DriverName].
DriveLock may not function correctly.
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
262 |
DriveLock |
no |
Error |
ALF driver communication error |
An error occurred while communicating with the Application Launch Filter device driver.
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
263 |
DriveLock |
no |
Error |
Error determining process details |
An error occurred while determining detailed information for a process.
Process: [Process.ProcessName]
File Hash: [Process.ProcessHash]
|
264 |
DriveLock |
no |
Error |
Cannot merge GPO into RSoP |
Cannot merge the GPO configuration database [Info.FileName] into the resulting set of policy. |
265 |
DriveLock |
no |
Error |
Cannot merge Registry into RSoP |
Cannot merge GPO registry information into the resulting set of policy. |
266 |
DriveLock |
no |
Error |
Cannot start encryption driver |
Cannot open or start the encryption device driver.
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
267 |
DriveLock |
no |
Error |
Cannot install encryption driver |
Cannot install the encryption device driver.
Function: [Info.Function]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
268 |
DriveLock |
no |
Error |
Cannot upgrade Mobile Encryption Application |
Mobile Encryption Application cannot be automatically updated.
Target location: [Info.FileName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
269 |
DriveLock |
no |
Error |
Cannot attach CD/DVD filtering driver |
The CD/DVD filtering driver cannot be attached to a drive.
Drive letter: [Info.DriveLetter]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
270 |
DriveLock |
no |
Error |
Cannot apply CD/DVD filtering configuration |
The drive filtering configuration cannot be applied to the CD/DVD filtering driver.
Incorrect access permissions / filtering may be set.
Drive letter: [Info.DriveLetter]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
271 |
DriveLock |
no |
SuccessAudit |
CD/DVD write operation started |
A CD/DVD write operation was started on drive [Info.DriveLetter].
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Process: [Info.ProcessName]
Hardware Id: [Drive.HardwareID] |
272 |
DriveLock |
no |
FailureAudit |
CD/DVD write operation blocked |
A CD/DVD write operation was blocked on drive [Info.DriveLetter].
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Process: [Info.ProcessName]
Hardware Id: [Drive.HardwareID] |
273 |
DriveLock |
no |
Information |
CD/DVD write operation finished |
A CD/DVD write operation was finished on drive [Info.DriveLetter].
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Process: [Info.ProcessName]
Bytes written: [Info.DataSize]
Hardware Id: [Drive.HardwareID] |
274 |
DriveLock |
no |
SuccessAudit |
CD/DVD media erase operation executed |
A CD/DVD media erase operation was executed on drive [Info.DriveLetter].
The media was [Info.BlankMethod]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Process: [Info.ProcessName]
Hardware Id: [Drive.HardwareID] |
275 |
DriveLock |
no |
SuccessAudit |
CD/DVD media erase operation blocked |
A CD/DVD media erase operation was blocked on drive [Info.DriveLetter].
The media should be [Info.BlankMethod]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Process: [Info.ProcessName]
Hardware Id: [Drive.HardwareID] |
276 |
DriveLock |
no |
Information |
System verification successfull |
A system verification operation on drive [Info.DriveLetter] was executed and succeeded.
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Status: [Info.ActionResult]
Hardware Id: [Drive.HardwareID] |
277 |
DriveLock |
no |
Error |
System verification failed |
A system verification operation on drive [Info.DriveLetter] was executed and reported a problem.
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Status: [Info.ActionResult]
Hardware Id: [Drive.HardwareID] |
278 |
DriveLock |
no |
Error |
No or wrong enforced encryption settings |
A drive is configured for enforced encryption but enforced encryption settings are either not present or you configured a FIPS-only mode for encryption and selected an incompatible algorithm for enforced encryption.
The drive will be blocked and no encryption is executed. |
279 |
DriveLock |
no |
Error |
Cannot send SNMP trap |
A SNMP trap could not be sent to the configured trap receiver.
Function name: [Info.ErrorMessage]
Error code: [Info.ErrorCode] |
280 |
DriveLock |
no |
Error |
Cannot load file filter DLL |
Cannot load a configured file filtering dynamic link library (DLL).
DLL file: [Info.FileName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
281 |
DriveLock |
no |
Error |
Cannot find function in DLL |
Cannot find the configured function [Info.FunctionName] in a filtering dynamic link library (DLL).
DLL file: [Info.FileName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
282 |
DriveLock |
yes |
SuccessAudit |
Temporarily unlocked (offline) |
DriveLock Agent was temporarily unlocked using offline unlocking.
Unlock period: [Info.UnlockTime] [Info.UnlockUnit] |
283 |
DriveLock |
no |
Information |
Drive connected to thin client |
The drive [Info.DriveLetter] (mounted as [Info.FileName]) was added to thin client [Info.ComputerName] (unique ID [Info.ComputerGuid]).
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
|
284 |
DriveLock |
no |
Information |
Drive disconnected from thin client |
The drive [Info.DriveLetter] (mounted as [Info.FileName]) was disconnected from thin client [Info.ComputerName] (unique ID [Info.ComputerGuid]).
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
|
285 |
DriveLock |
no |
Error |
Enforced encryption - Formatting error |
An error occurred while creating an encrypted volume during enforced encryption.
Container: [Info.DebugMsg]
Error text: [Info.FunctionName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
286 |
DriveLock |
no |
Error |
No server defined for recovery |
No server is defined for uploading encryption recovery information. |
287 |
DriveLock |
no |
Error |
No server defined for inventory |
No server is defined for uploading collected inventory data. |
288 |
DriveLock |
no |
Information |
Inventory collection successful |
Hard- and software inventory data was successfully collected and uploaded.
DES server: [Info.DesName]
Connection ID: [Info.ObjectID] |
289 |
DriveLock |
no |
Information |
Inventory collection failed |
An error occurred while collecting hard- and software inventory data.
DES server: [Info.DesName]
Connection ID: [Info.ObjectID]
Error: [Info.ErrorMessage] |
290 |
DriveLock |
no |
Warning |
Uninstallation password configured |
An uninstallation password is configured.
Please refer to the DriveLock manual if you want to update this Agent. |
291 |
DriveLock |
no |
Error |
Cannot start mDNS/DNS-SD responder |
The DriveLock mDNS/DNS-SD responder could not be started.
Zero-configuration functions will not be available
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
292 |
DriveLock |
no |
Error |
DNS-SD service registration failed |
DNS-SD service registration of the DriveLock Agent failed. |
293 |
DriveLock |
no |
Information |
Security awareness campaign element acknowledged |
A security awareness campaign element was acknowledged by the user.
Campaign element: [WhiteList.ObjectID]
Element description: [Info.DisplayName] |
294 |
DriveLock |
no |
Error |
Cannot download centrally stored policy |
The centrally stored policy [Info.ConfigId] could not be downloaded.
Server: [Info.ServerName]
Error: [Info.ErrorMessage] |
295 |
DriveLock |
no |
Error |
Centrally stored policy: Cannot extract |
A centrally stored policy could no be extracted.
Settings from this file will not be applied.
Configuration ID: [Info.ConfigId]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
296 |
DriveLock |
no |
Warning |
Centrally stored policy: Using cached copy |
The centrally stored policy [Info.ConfigId] could not be loaded from the server.
A locally cached copy was used. |
297 |
DriveLock |
no |
Error |
Centrally stored policy: Fall-back configuration applied |
A configuration using centrally stored policies was detected but no settings could be retrieved from a server.
DriveLock will fall-back to a configuration where all removable drives are blocked. |
298 |
DriveLock |
no |
Information |
Centrally stored policy applied |
The centrally stored policy [Info.ConfigId] was successfully applied. |
299 |
DriveLock |
no |
Information |
Centrally stored policy downloaded |
The centrally stored policy [Info.DisplayName] was successfully downloaded.
Configuration ID: [Info.ConfigId]
Version: [Info.InstalledVersion] |
300 |
DriveLock |
no |
Information |
iTunes-synchronized device connected |
An iTunes-synchronized device has been connected.
HardwareID: [Device.HardwareID]
Device: [Device.DisplayName]
Serial: [Info.Serial]
IMEI: [Info.IMEI]
Firmware: [Info.FirmwareVersion] |
301 |
DriveLock |
no |
Information |
iTunes-synchronized device disconnected |
An iTunes-synchronized device has been disconnected.
HardwareID: [Device.HardwareID]
Device: [Device.DisplayName]
Serial: [Info.Serial]
IMEI: [Info.IMEI]
Firmware: [Info.FirmwareVersion] |
302 |
DriveLock |
no |
Information |
File synchronized (iTunes-synchronized device) |
File synchronized with iTunes-synchronized device.
Process: [Info.ProcessName]
Device: [Device.DisplayName]
Rule: [WhiteList.ObjectID]
Blocked: [Info.UserLockState]
Filename: iDevice://[File.FileName]
Hash: [File.MD5Hash]
SyncType: [File.SyncType] |
303 |
DriveLock |
no |
Information |
Contacts synchronized (iTunes-synchronized device) |
Contacts synchronized with iTunes-synchronized device.
Process: [Info.ProcessName]
Device: [Device.DisplayName]
Rule: [WhiteList.ObjectID]
Blocked: [Info.UserLockState]
Filename: iDevice://[File.FileName]
Hash: [File.MD5Hash]
SyncType: [File.SyncType] |
304 |
DriveLock |
no |
Information |
Calendar synchronization (iTunes-synchronized device) |
Calendar synchronized with iTunes-synchronized device.
Process: [Info.ProcessName]
Device: [Device.DisplayName]
Rule: [WhiteList.ObjectID]
Blocked: [Info.UserLockState]
Filename: iDevice://[File.FileName]
Hash: [File.MD5Hash]
SyncType: [File.SyncType] |
305 |
DriveLock |
no |
Information |
Bookmarks synchronization (iTunes-synchronized device) |
Bookmarks synchronized with iTunes-synchronized device.
Process: [Info.ProcessName]
Device: [Device.DisplayName]
Rule: [WhiteList.ObjectID]
Blocked: [Info.UserLockState]
Filename: iDevice://[File.FileName]
Hash: [File.MD5Hash]
SyncType: [File.SyncType] |
306 |
DriveLock |
no |
Information |
Notes synchronized (iTunes-synchronized device) |
Notes synchronized with iTunes-synchronized device.
Process: [Info.ProcessName]
Device: [Device.DisplayName]
Rule: [WhiteList.ObjectID]
Blocked: [Info.UserLockState]
Filename: iDevice://[File.FileName]
Hash: [File.MD5Hash]
SyncType: [File.SyncType] |
307 |
DriveLock |
no |
Information |
Mail accounts synchronized (iTunes-synchronized device) |
Mail accounts synchronized with iTunes-synchronized device.
Process: [Info.ProcessName]
Device: [Device.DisplayName]
Rule: [WhiteList.ObjectID]
Blocked: [Info.UserLockState]
Filename: iDevice://[File.FileName]
Hash: [File.MD5Hash]
SyncType: [File.SyncType] |
308 |
DriveLock |
no |
Error |
Apple driver communication error |
An error occurred while communicating with the Apple filter device driver.
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
309 |
DriveLock |
no |
Error |
Cannot initialize apple filter device driver |
Apple filter device driver could not be initialized.
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
310 |
DriveLock |
no |
Error |
Antivirus installation failed |
Installation of Antivirus failed.
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
311 |
DriveLock |
no |
Error |
Initial Antivirus configuration failed |
Initial configuration of Antivirus failed.
Service: [Info.ServiceName] ([Info.FunctionName])
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
312 |
DriveLock |
no |
Error |
Antivirus uninstallation failed |
Uninstallation of Antivirus failed.
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
313 |
DriveLock |
no |
Error |
Antivirus initialization failed |
Initialization of Antivirus failed.
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
314 |
DriveLock |
no |
Error |
Antivirus configuration failed |
Configuration of Antivirus failed.
Setting: [Info.FunctionName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
315 |
DriveLock |
no |
Error |
Antivirus quarantine initialization failed |
Initialization of Antivirus quarantine failed.
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
316 |
DriveLock |
no |
FailureAudit |
Malware detected |
Virus or malware detected.
Detected malware: [Malware.DetectionName] ([Malware.DetectionType])
Scan result: [Info.ScanResult]
Detection accuracy: [Info.DetectionAccuracy]
Infected file: [File.Path][Info.ArchivePath]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Drive letter: [File.DriveLetter]
File name: [File.FileName]
File name hash: [File.MD5Hash] |
317 |
DriveLock |
no |
Error |
AV Definition: Copying failed |
Copying antivirus definitions from an UNC path failed.
Definition file: [Info.FileName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
318 |
DriveLock |
no |
Error |
AV Definition: Verification failed |
Verification of antivirus definitions failed.
Definition file: [Info.FileName] |
319 |
DriveLock |
no |
Error |
AV Definition: Reading/extracting failed |
Reading and extracting antivirus definitions failed.
Definition file: [Info.FileName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
320 |
DriveLock |
no |
Error |
AV Definition: Activating failed |
Activating antivirus definitions failed.
Definition file: [Info.FileName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
321 |
DriveLock |
no |
Error |
AV Definition: Caching failed |
Caching antivirus definitions failed.
Definition file: [Info.FileName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
322 |
DriveLock |
no |
Error |
AV Definition: Applying to scan engine failed |
Applying antivirus definitions to the scan engine failed.
Definition file: [Info.FileName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
323 |
DriveLock |
no |
Information |
Antivirus definitions updated |
Antivirus definitions updated.
Definition file: [Info.FileName] |
324 |
DriveLock |
no |
Error |
Quarantine: Deleting file failed |
Deleting a file from antivirus quarantine failed.
Quarantined file: [Info.FileName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
325 |
DriveLock |
no |
Information |
Quarantined file deleted |
A file was deleted from antivirus quarantine.
Quarantined file: [Info.FileName] |
326 |
DriveLock |
no |
Error |
Quarantine: Restoring file failed |
Restoring a file from antivirus quarantine failed.
Quarantined file: [Info.FileName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
327 |
DriveLock |
no |
Information |
Quarantined file restored |
A file was restored from antivirus quarantine.
Quarantined file: [Info.FileName] |
328 |
DriveLock |
no |
Warning |
Old antivirus definitions detected |
Antivirus definitions are [Info.AvDefAgeDays] days old.
For continued protection please update antivirus definitions. |
329 |
DriveLock |
no |
Warning |
Hard disk self-monitoring status could not be read |
Hard disk self-monitoring (S.M.A.R.T.) status could not be read.
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Drive letter: [Info.DriveLetter]
Hardware Id: [Drive.HardwareID] |
330 |
DriveLock |
no |
Warning |
Hard disk failed (Hard disk self-monitoring) |
Hard disk self-monitoring (S.M.A.R.T.) reported the drive failed.
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Drive letter: [Info.DriveLetter]
Hardware Id: [Drive.HardwareID] |
331 |
DriveLock |
no |
SuccessAudit |
Volume created (enforced encryption) |
A DriveLock encrypted volume was created/formatted by enforced encryption.
Status: [Info.CryptStatus]
Volume container: [EncryptedVolume.FileName]
Volume GUID: [EncryptedVolume.VolumeID]
File system: [EncryptedVolume.FileSystemType]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber]) |
332 |
DriveLock |
no |
Warning |
Volume mount error |
Mounting of the encrypted volume [EncryptedVolume.FileName] failed. Existing data will not be preserved.
Volume GUID: [EncryptedVolume.VolumeID] |
333 |
DriveLock |
no |
Error |
AV Definition: Manual update to older definition prevented |
The user tried to update to an antivirus definition older than the current definition. This is not supported.
Definition file: [Info.FileName] |
334 |
DriveLock |
no |
Error |
Server communication failed |
Communication with the DriveLock Enterprise Service failed.
Server: [Info.ServerName]
Error: [Info.ErrorMessage] |
335 |
DriveLock |
no |
Error |
AV Definition: Download failed |
Downloading antivirus definitions failed.
Definition file: [Info.FileName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage]
Additional information: [Info.ErrorMessage2] |
336 |
DriveLock |
no |
Error |
AV Definition: Merging incremental definitions failed |
Merging incremental antivirus definitions failed.
Definition file: [Info.FileName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
337 |
DriveLock |
no |
Information |
AV Definition: Incremental definitions successfully merged |
Incremental antivirus definitions successfully merged.
Definition file: [Info.FileName] |
338 |
DriveLock |
no |
Warning |
License expired. Grace period active |
Your subscription license is expired.
You will receive free updates and definitions until [Info.LicenseInfo]. |
339 |
DriveLock |
no |
Error |
License expired |
Your subscription license expired on [Info.LicenseInfo]. |
340 |
DriveLock |
no |
Error |
Scheduled job: Load failed |
Loading scheduled antivirus scan job failed.
Job ID: [Info.ConfigId]
Job description: [Info.DisplayName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
341 |
DriveLock |
no |
Error |
Scheduled job: Execution failed |
Executing a scheduled antivirus scan job failed.
Job ID: [Info.ConfigId]
Job description: [Info.DisplayName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
342 |
DriveLock |
no |
Information |
Scheduled job: Successfully executed |
Scheduled antivirus scan job successfully executed.
Job ID: [Info.ConfigId]
Job description: [Info.DisplayName]
Number of scanned files: [Info.NumFiles]
Number of detections: [Info.NumDetections] |
343 |
DriveLock |
no |
Warning |
Scheduled job: Running with standard scanning profile |
Application of the configured scanning profile failed. Scheduled antivirus scan job will run with default profile.
Job ID: [Info.ConfigId]
Job description: [Info.DisplayName] |
344 |
DriveLock |
no |
Error |
Scheduled job: Scanning failed |
Scanning a file in a scheduled antivirus scan job failed.
Job ID: [Info.ConfigId]
Job description: [Info.DisplayName]
Failed file: [Info.FileName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
345 |
DriveLock |
no |
Warning |
Scheduled job: Not executed due to manual reconfiguration |
A scheduled antivirus scan was not executed due to manual reconfiguration.
Job ID: [Info.ConfigId]
Job description: [Info.DisplayName] |
346 |
DriveLock |
no |
Warning |
AV Definition: No updates due to manual reconfiguration |
Antivirus definitions will not be updated due to manual reconfiguration. |
347 |
DriveLock |
no |
Warning |
Uninstall due to manual reconfiguration |
Antivirus will be uninstalled due to manual reconfiguration. |
348 |
DriveLock |
no |
Information |
Install due to manual reconfiguration |
Antivirus will be installed due to manual reconfiguration. |
349 |
DriveLock |
no |
Error |
Existing product uninstallation failed |
An existing antivirus product was detected but the configured automatic uninstallation failed.
Detected product: [Info.DisplayName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
350 |
DriveLock |
no |
Error |
Cannot load existing product update engine |
The engine for updating existing antivirus products could not be loaded.
Error code: [Info.DisplayName]
Error: [Info.ErrorCode] |
351 |
DriveLock |
no |
Information |
Existing product uninstalled |
An existing antivirus product was detected and uninstalled.
Detected product: [Info.DisplayName] |
352 |
DriveLock |
no |
Information |
Existing product detected |
An existing antivirus product was detected.
Detected product: [Info.DisplayName] |
353 |
DriveLock |
no |
Information |
Antivirus scan successfull |
An antivirus scan on drive [Info.DriveLetter] was executed and succeeded.
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Status: [Info.ActionResult]
Hardware Id: [Drive.HardwareID] |
354 |
DriveLock |
no |
Error |
Antivirus scan failed |
An antivirus scan on drive [Info.DriveLetter] was executed and reported a problem.
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Status: [Info.ActionResult]
Hardware Id: [Drive.HardwareID] |
355 |
DriveLock |
no |
Warning |
Realtime virus scanning temporarily disabled |
Realtime virus scanning was temporarily disabled by administrative intervention. |
356 |
DriveLock |
no |
Error |
Disk Protection installation error |
Installation of the Disk Protection package failed.
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
357 |
DriveLock |
no |
Error |
Disk Protection uninstallation error |
Uninstallation of the Disk Protection package failed.
Error code: [Info.UserName]
Error: [Info.ErrorCode] |
358 |
DriveLock |
no |
Information |
Disk Protection configuration change delayed |
A change in the Disk Protection configuration was detected, but the change is not applied due to the 'delay decryption' setting in the policy. |
359 |
DriveLock |
no |
Warning |
FDE: Manual reconfiguration |
Disk Protection is manually reconfigured. |
360 |
DriveLock |
no |
Warning |
Disk Protection integration module error |
The Disk Protection integration module could not be loaded.
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
361 |
DriveLock |
no |
Error |
Automatic updates: Load failed |
Loading the automatic updates job schedule failed.
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
362 |
DriveLock |
no |
Error |
Automatic updates: Retrieving data failed |
Retrieving automatic update information from server [Info.ServerName] failed.
Package type: [Info.ServiceName]
Error: [Info.ErrorMessage] |
363 |
DriveLock |
no |
Error |
Automatic updates: Download failed |
Downloading automatic updates failed.
Package file: [Info.URL]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
364 |
DriveLock |
no |
Error |
Automatic updates: Execution failed |
Executing an automatic update failed.
Package type: [Info.ServiceName]
Version: [Info.InstalledVersion]
Action: [Info.ActionName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
365 |
DriveLock |
no |
Information |
Automatic updates: Execution started |
Execution of an automatic update started.
Package type: [Info.ServiceName]
Version: [Info.InstalledVersion] |
366 |
DriveLock |
no |
Error |
Disk Protection Remote wipe request failed |
A Disk Protection remote wipe request was received but could not be executed
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
367 |
DriveLock |
no |
Information |
Disk Protection Remote wipe request executed |
A Disk Protection remote wipe request was executed. The system will now reboot.
User message: [Info.ActionName] |
368 |
DriveLock |
no |
Audit |
Network resource locked |
The network resource [NetDrive.NetDrivePath] ([NetDrive.NetDriveType]) will be controlled by DriveLock.
As an ACL was applied to the drive, some users may no longer be able to access it.
The drive is [Info.UserLockState] for this event's user account.
Applied whitelist rule: [WhiteList.ObjectID]
Screen state (keyboard [Win]-[L]): [Info.SessionLockState] |
369 |
DriveLock |
no |
SuccessAudit |
Network resource not locked |
The network resource [NetDrive.NetDrivePath] ([NetDrive.NetDriveType]) will be controlled by DriveLock.
As an ACL was applied to the drive, some users may no longer be able to access it.
The drive is [Info.UserLockState] for this event's user account.
Applied whitelist rule: [WhiteList.ObjectID]
Screen state (keyboard [Win]-[L]): [Info.SessionLockState] |
370 |
DriveLock |
no |
Audit |
Network resource not locked, error |
The network resource [NetDrive.NetDrivePath] ([NetDrive.NetDriveType]) will be controlled by DriveLock.
As an ACL was applied to the drive, some users may no longer be able to access it.
The drive is [Info.UserLockState] for this event's user account.
Applied whitelist rule: [WhiteList.ObjectID]
Screen state (keyboard [Win]-[L]): [Info.SessionLockState] |
371 |
DriveLock |
no |
SuccessAudit |
File accessed |
File accessed.
File path: [File.Path]
File name: [File.FileName]
Network resource: [NetDrive.NetDrivePath] ([NetDrive.NetDriveType])
File size: [File.Size]
File name hash: [File.MD5Hash]
File content hash: [FileContent.MD5Hash]
Access direction: [Info.AccessDirection]
Process: [Info.ProcessName] |
372 |
DriveLock |
no |
FailureAudit |
File blocked by content scanner |
File blocked by content scanner. Content does not match file extension.
File path: [File.Path]
File name: [File.FileName]
Network resource: [NetDrive.NetDrivePath] ([NetDrive.NetDriveType])
File size: [File.Size]
File name hash: [File.MD5Hash]
File content hash: [FileContent.MD5Hash]
Access direction: [Info.AccessDirection]
Process: [Info.ProcessName]
Header: [Info.FileHeader] |
373 |
DriveLock |
no |
FailureAudit |
File extension blocked |
File blocked by file filter. Access denied due to file type.
File path: [File.Path]
File name: [File.FileName]
Network resource: [NetDrive.NetDrivePath] ([NetDrive.NetDriveType])
File size: [File.Size]
File name hash: [File.MD5Hash]
File content hash: [FileContent.MD5Hash]
Access direction: [Info.AccessDirection]
Process: [Info.ProcessName] |
374 |
DriveLock |
no |
SuccessAudit |
File created |
New file created.
File path: [File.Path]
File name: [File.FileName]
Network resource: [NetDrive.NetDrivePath] ([NetDrive.NetDriveType])
File size: [File.Size]
File name hash: [File.MD5Hash]
File content hash: [FileContent.MD5Hash]
Access direction: [Info.AccessDirection]
Process: [Info.ProcessName] |
375 |
DriveLock |
no |
SuccessAudit |
File deleted |
File deleted.
Process: [File.FileName]
File path: [File.Path]
File name: [File.FileName]
Network resource: [NetDrive.NetDrivePath] ([NetDrive.NetDriveType])
File name hash: [File.MD5Hash]
File content hash: [FileContent.MD5Hash]
|
376 |
DriveLock |
no |
SuccessAudit |
File renamed |
File renamed.
Process: [Info.ProcessName]
Old file path: [File.Path]
Old file name: [File.FileName]
New file name: [Info.FileName]
Old file name hash: [File.MD5Hash]
File content hash: [FileContent.MD5Hash]
New file name hash: [Info.MD5Hash]
Network resource: [NetDrive.NetDrivePath] ([NetDrive.NetDriveType])
|
377 |
DriveLock |
no |
SuccessAudit |
Usage policy accepted |
Usage policy for network resource [NetDrive.NetDrivePath] ([NetDrive.NetDriveType]) was accepted by the user.
|
378 |
DriveLock |
no |
FailureAudit |
Usage policy declined |
Usage policy for network resource [NetDrive.NetDrivePath] ([NetDrive.NetDriveType]) was declined by the user.
|
379 |
DriveLock |
no |
Information |
System verification successfull |
A system verification operation on network resource [NetDrive.NetDrivePath] ([NetDrive.NetDriveType]) was executed and succeeded.
Status: [Info.ActionResult]
|
380 |
DriveLock |
no |
Error |
System verification failed |
A system verification operation on network resource [NetDrive.NetDrivePath] ([NetDrive.NetDriveType]) was executed and reported a problem.
Status: [Info.ActionResult]
|
381 |
DriveLock |
no |
Information |
Antivirus scan successfull |
An antivirus scan on drive [NetDrive.NetDrivePath] ([NetDrive.NetDriveType]) was executed and succeeded.
Status: [Info.ActionResult]
|
382 |
DriveLock |
no |
Error |
Antivirus scan failed |
An antivirus scan on drive [NetDrive.NetDrivePath] ([NetDrive.NetDriveType]) was executed and reported a problem.
Status: [Info.ActionResult] |
383 |
DriveLock |
no |
FailureAudit |
Malware detected |
Virus or malware detected.
Detected malware: [Malware.DetectionName] ([Malware.DetectionType])
Detection accuracy: [Info.DetectionAccuracy]
Infected file: [File.Path][Info.ArchivePath]
Network resource: ([NetDrive.NetDriveType]) [NetDrive.NetDrivePath]
File name: [File.FileName]
File name hash: [File.MD5Hash] |
384 |
DriveLock |
no |
Information |
Deferred hash completed |
Deferred content hash generation completed.
File path: [File.Path]
File name: [File.FileName]
Network resource: [NetDrive.NetDrivePath] ([NetDrive.NetDriveType])
File name hash: [File.MD5Hash]
File content hash: [FileContent.MD5Hash]
|
385 |
DriveLock |
no |
Information |
File content changed |
File content changed.
File path: [File.Path]
File name: [File.FileName]
Network resource: [NetDrive.NetDrivePath] ([NetDrive.NetDriveType])
File name hash: [File.MD5Hash]
Old file content hash: [FileContent.MD5Hash]
New file content hash: [Info.MD5Hash]
|
386 |
DriveLock |
no |
SuccessAudit |
Volume mounted |
A DriveLock encrypted volume was mounted.
Status: [Info.CryptStatus]
Volume container: [EncryptedVolume.FileName]
Volume GUID: [EncryptedVolume.VolumeID]
Drive letter: [EncryptedVolume.DriveLetter]
Network resource: [NetDrive.NetDrivePath] ([NetDrive.NetDriveType])
|
387 |
DriveLock |
no |
SuccessAudit |
Volume unmounted |
A DriveLock encrypted volume was unmounted.
Status: [Info.CryptStatus]
Volume container: [EncryptedVolume.FileName]
Volume GUID: [EncryptedVolume.VolumeID]
Drive letter: [EncryptedVolume.DriveLetter]
Network resource: [NetDrive.NetDrivePath] ([NetDrive.NetDriveType])
|
388 |
DriveLock |
no |
SuccessAudit |
Volume created |
A DriveLock encrypted volume was created/formatted.
Status: [Info.CryptStatus]
Volume container: [EncryptedVolume.FileName]
Volume GUID: [EncryptedVolume.VolumeID]
File system: [EncryptedVolume.FileSystemType]
Network resource: [NetDrive.NetDrivePath] ([NetDrive.NetDriveType])
|
389 |
DriveLock |
no |
SuccessAudit |
Password changed |
The password for a DriveLock encrypted volume was changed.
Status: [Info.CryptStatus]
Volume container: [EncryptedVolume.FileName]
Volume GUID: [EncryptedVolume.VolumeID]
Network resource: [NetDrive.NetDrivePath] ([NetDrive.NetDriveType])
|
390 |
DriveLock |
no |
Warning |
Encrypted volume password recovered |
A DriveLock Encrypted volume password was recovered.
Status: [Info.CryptStatus]
Volume container: [EncryptedVolume.FileName]
Volume GUID: [EncryptedVolume.VolumeID]
Network resource: [NetDrive.NetDrivePath] ([NetDrive.NetDriveType])
|
391 |
DriveLock |
no |
Warning |
Cannot send event by e-mail |
DriveLock cannot send an event to a defined e-mail target.
Error: [Info.ErrorMessage] |
392 |
DriveLock |
no |
Warning |
Internal event queue full |
The internal event queue was full.
[Info.EventCount] events were dropped during the last [Info.IntValue] msec. |
393 |
DriveLock |
no |
Warning |
External event queue full |
The external event queue was full.
[Info.EventCount] events were dropped since [Info.UnlockTime]. |
394 |
DriveLock |
no |
SuccessAudit |
File securely deleted |
A file was securely deleted.
File: [Info.FileName]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Method: [Info.SecureEraseAlgorithm] |
395 |
DriveLock |
no |
Warning |
File securely deleted |
A file was securely deleted.
File: [Info.FileName]
Network resource: [NetDrive.NetDrivePath] ([NetDrive.NetDriveType])
Algorithm: [Info.SecureEraseAlgorithm] |
396 |
DriveLock |
no |
Error |
Event data encryption failed |
Error while reading the certificate file [Info.FileName] for event data encryption.
Event data will be anonymized.
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
397 |
DriveLock |
no |
Error |
Event data encryption failed |
Error while encrypting event data.
Event data will be anonymized.
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
398 |
DriveLock |
no |
Error |
Secure deletion failed |
Secure deletion of a file failed.
File: [Info.FileName]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
399 |
DriveLock |
no |
Warning |
Secure deletion failed |
Secure deletion of a file failed.
File: [Info.FileName]
Network resource: [NetDrive.NetDrivePath] ([NetDrive.NetDriveType])
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
400 |
DriveLock |
no |
Information |
Required encryption cancelled |
Required encryption of a drive was cancelled by the user. |
401 |
DriveLock |
no |
Information |
Required encryption rule selected |
A rule for enforced / required encryption was selected by the user.
Rule ID: [Info.ConfigId]
Rule name: [Info.DisplayName] |
402 |
DriveLock |
no |
SuccessAudit |
User password removed |
The user password for a DriveLock encrypted volume was removed. The administrative password is needed to access the volume.
Status: [Info.CryptStatus]
Volume container: [EncryptedVolume.FileName]
Volume GUID: [EncryptedVolume.VolumeID]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber]) |
403 |
DriveLock |
no |
SuccessAudit |
User password removed |
The user password for a DriveLock encrypted volume was removed. The administrative password is needed to access the volume.
Status: [Info.CryptStatus]
Volume container: [EncryptedVolume.FileName]
Volume GUID: [EncryptedVolume.VolumeID]
Network resource: [NetDrive.NetDrivePath] ([NetDrive.NetDriveType])
|
404 |
DriveLock |
no |
SuccessAudit |
User password removed |
The administrative password for a DriveLock encrypted volume was removed. Only the user password can be used to access the volume.
Status: [Info.CryptStatus]
Volume container: [EncryptedVolume.FileName]
Volume GUID: [EncryptedVolume.VolumeID]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber]) |
405 |
DriveLock |
no |
SuccessAudit |
User password removed |
The administrative password for a DriveLock encrypted volume was removed. Only the user password can be used to access the volume.
Status: [Info.CryptStatus]
Volume container: [EncryptedVolume.FileName]
Volume GUID: [EncryptedVolume.VolumeID]
Network resource: [NetDrive.NetDrivePath] ([NetDrive.NetDriveType])
|
406 |
DriveLock |
no |
Information |
Encrypted folder created |
An encrypted folder was successfully created.
Folder path: [DfpEncryptedFolder.UncPath]
Folder ID: [DfpEncryptedFolder.DfpVolumeID]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Initial user ID: [DfpUser.UserID] |
407 |
DriveLock |
no |
Information |
Encrypted folder recovered |
An encrypted folder was successfully recovered.
Folder path: [DfpEncryptedFolder.UncPath]
Folder ID: [DfpEncryptedFolder.DfpVolumeID]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Recovered user ID: [DfpUser.UserID] |
408 |
DriveLock |
no |
Information |
Encrypted folder mounted |
An encrypted folder was successfully mounted.
Folder path: [DfpEncryptedFolder.UncPath]
Folder ID: [DfpEncryptedFolder.DfpVolumeID]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Authenticated user ID: [DfpUser.UserID] |
409 |
DriveLock |
no |
Information |
Encrypted folder unmounted |
An encrypted folder was successfully unmounted.
Folder path: [DfpEncryptedFolder.UncPath]
Folder ID: [DfpEncryptedFolder.DfpVolumeID]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Authenticated user ID: [DfpUser.UserID] |
410 |
DriveLock |
no |
Error |
Creation of an encrypted folder failed |
Creation of an encrypted folder failed.
Folder path: [DfpEncryptedFolder.UncPath]
Folder ID: [DfpEncryptedFolder.DfpVolumeID]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Initial user ID: [DfpUser.UserID]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
411 |
DriveLock |
no |
Error |
Recovery of an encrypted folder failed |
Recovery of an encrypted folder failed.
Folder path: [DfpEncryptedFolder.UncPath]
Folder ID: [DfpEncryptedFolder.DfpVolumeID]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Recovered user ID: [DfpUser.UserID]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
412 |
DriveLock |
no |
Error |
Mount of an encrypted folder failed |
Mount of an encrypted folder failed.
Folder path: [DfpEncryptedFolder.UncPath]
Folder ID: [DfpEncryptedFolder.DfpVolumeID]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Authenticated user ID: [DfpUser.UserID]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
413 |
DriveLock |
no |
Error |
Creation of recovery data failed |
The creation of folder recovery information failed.
Folder path: [DfpEncryptedFolder.UncPath]
Folder ID: [DfpEncryptedFolder.DfpVolumeID]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
414 |
DriveLock |
no |
Information |
User successfully authenticated |
An user was successfully authenticated against an encrypted folder.
Folder path: [DfpEncryptedFolder.UncPath]
Folder ID: [DfpEncryptedFolder.DfpVolumeID]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Authenticated user ID: [DfpUser.UserID]
Permissions: [Info.DfpUserPerms] [Info.DfpReadonlyPerms] |
415 |
DriveLock |
no |
Information |
User successfully added |
An user was successfully added to the encrypted folder users.
Folder path: [DfpEncryptedFolder.UncPath]
Folder ID: [DfpEncryptedFolder.DfpVolumeID]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Authenticated user ID: [DfpUser.UserID]
Added user ID: [Info.UserID]
Permissions: [Info.DfpUserPerms] [Info.DfpReadonlyPerms] |
416 |
DriveLock |
no |
Information |
User successfully deleted |
An user was successfully deleted from the encrypted folder users.
Folder path: [DfpEncryptedFolder.UncPath]
Folder ID: [DfpEncryptedFolder.DfpVolumeID]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Authenticated user ID: [DfpUser.UserID]
Deleted user ID: [Info.UserID] |
417 |
DriveLock |
no |
Error |
Authentication against encrypted folder failed |
Authentication against an encrypted folder failed.
Folder path: [DfpEncryptedFolder.UncPath]
Folder ID: [DfpEncryptedFolder.DfpVolumeID]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Authenticated user ID: [DfpUser.UserID]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage]
Authentication type: [Info.DfpAuthTypes] |
418 |
DriveLock |
no |
Information |
Offline encryption started |
An offline encryption operation was started for an encrypted folder.
Folder path: [DfpEncryptedFolder.UncPath]
Folder ID: [DfpEncryptedFolder.DfpVolumeID]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Authenticated user ID: [DfpUser.UserID]
Job ID: [Info.DfpJobID]
Job type: [Info.DfpJobType] - [Info.DfpJobDirection] |
419 |
DriveLock |
no |
Information |
Offline encryption completed |
An offline encryption operation was successfully completed.
Folder path: [DfpEncryptedFolder.UncPath]
Folder ID: [DfpEncryptedFolder.DfpVolumeID]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Authenticated user ID: [DfpUser.UserID]
Job ID: [Info.DfpJobID]
Number of processed files: [Info.IntValue] |
420 |
DriveLock |
no |
Warning |
Offline encryption cancelled |
An offline encryption operation was cancelled.
Folder path: [DfpEncryptedFolder.UncPath]
Folder ID: [DfpEncryptedFolder.DfpVolumeID]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Authenticated user ID: [DfpUser.UserID]
Job ID: [Info.DfpJobID]
Number of files: [Info.IntValue]
Number of incomplete files: [Info.IntValue2] |
421 |
DriveLock |
no |
Error |
Offline encryption: File error |
A file in an offline encryption operation could not be processed.
Folder path: [DfpEncryptedFolder.UncPath]
Folder ID: [DfpEncryptedFolder.DfpVolumeID]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Job ID: [Info.DfpJobID]
Processed file: [Info.FileName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage]
User action: [Info.DfpUserAction] |
422 |
DriveLock |
no |
Information |
User certificate requested |
An user certificate was requested.
Requesting user: [DfpUser.UserID]
Certificate serial number: [Info.CertSerNo] |
423 |
DriveLock |
no |
Information |
User certificate issued |
An user certificate was issued.
Requesting user: [DfpUser.UserID]
Certificate serial number: [Info.CertSerNo] |
424 |
DriveLock |
no |
Error |
User certificate request failed |
An error occurred while requesting an user certificate.
Requesting user: [DfpUser.UserID]
Certificate serial number: [Info.CertSerNo]
Server error: [Info.ErrorMessage]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage2] |
425 |
DriveLock |
no |
Error |
User certificate issued |
An error occurred while calling a File Protection web service.
Server URL: [Info.URL]
Server error: [Info.ErrorMessage]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage2] |
426 |
DriveLock |
no |
Information |
Encrypted folder created |
An encrypted folder was successfully created.
Folder path: [DfpEncryptedFolder.UncPath]
Folder ID: [DfpEncryptedFolder.DfpVolumeID]
Network resource: [NetDrive.NetDrivePath] ([NetDrive.NetDriveType])
Initial user ID: [DfpUser.UserID] |
427 |
DriveLock |
no |
Information |
Encrypted folder recovered |
An encrypted folder was successfully recovered.
Folder path: [DfpEncryptedFolder.UncPath]
Folder ID: [DfpEncryptedFolder.DfpVolumeID]
Network resource: [NetDrive.NetDrivePath] ([NetDrive.NetDriveType])
Recovered user ID: [DfpUser.UserID] |
428 |
DriveLock |
no |
Information |
Encrypted folder mounted |
An encrypted folder was successfully mounted.
Folder path: [DfpEncryptedFolder.UncPath]
Folder ID: [DfpEncryptedFolder.DfpVolumeID]
Network resource: [NetDrive.NetDrivePath] ([NetDrive.NetDriveType])
Authenticated user ID: [DfpUser.UserID] |
429 |
DriveLock |
no |
Information |
Encrypted folder unmounted |
An encrypted folder was successfully unmounted.
Folder path: [DfpEncryptedFolder.UncPath]
Folder ID: [DfpEncryptedFolder.DfpVolumeID]
Network resource: [NetDrive.NetDrivePath] ([NetDrive.NetDriveType])
Authenticated user ID: [DfpUser.UserID] |
430 |
DriveLock |
no |
Error |
Creation of an encrypted folder failed |
Creation of an encrypted folder failed.
Folder path: [Info.Path]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
431 |
DriveLock |
no |
Error |
Recovery of an encrypted folder failed |
Recovery of an encrypted folder failed.
Folder path: [DfpEncryptedFolder.UncPath]
Folder ID: [DfpEncryptedFolder.DfpVolumeID]
Network resource: [NetDrive.NetDrivePath] ([NetDrive.NetDriveType])
Recovered user ID: [DfpUser.UserID]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
432 |
DriveLock |
no |
Error |
Mount of an encrypted folder failed |
Mount of an encrypted folder failed.
Folder path: [DfpEncryptedFolder.UncPath]
Folder ID: [DfpEncryptedFolder.DfpVolumeID]
Network resource: [NetDrive.NetDrivePath] ([NetDrive.NetDriveType])
Authenticated user ID: [DfpUser.UserID]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
433 |
DriveLock |
no |
Error |
Creation of recovery data failed |
The creation of folder recovery information failed.
Folder path: [DfpEncryptedFolder.UncPath]
Folder ID: [DfpEncryptedFolder.DfpVolumeID]
Network resource: [NetDrive.NetDrivePath] ([NetDrive.NetDriveType])
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
434 |
DriveLock |
no |
Information |
User successfully authenticated |
An user was successfully authenticated against an encrypted folder.
Folder path: [DfpEncryptedFolder.UncPath]
Folder ID: [DfpEncryptedFolder.DfpVolumeID]
Network resource: [NetDrive.NetDrivePath] ([NetDrive.NetDriveType])
Authenticated user ID: [DfpUser.UserID]
Permissions: [Info.DfpUserPerms] [Info.DfpReadonlyPerms] |
435 |
DriveLock |
no |
Information |
User successfully added |
An user was successfully added to the encrypted folder users.
Folder path: [DfpEncryptedFolder.UncPath]
Folder ID: [DfpEncryptedFolder.DfpVolumeID]
Network resource: [NetDrive.NetDrivePath] ([NetDrive.NetDriveType])
Authenticated user ID: [DfpUser.UserID]
Added user ID: [Info.UserID]
Permissions: [Info.DfpUserPerms] [Info.DfpReadonlyPerms] |
436 |
DriveLock |
no |
Information |
User successfully deleted |
An user was successfully deleted from the encrypted folder users.
Folder path: [DfpEncryptedFolder.UncPath]
Folder ID: [DfpEncryptedFolder.DfpVolumeID]
Network resource: [NetDrive.NetDrivePath] ([NetDrive.NetDriveType])
Authenticated user ID: [DfpUser.UserID]
Deleted user ID: [Info.UserID] |
437 |
DriveLock |
no |
Error |
Authentication against encrypted folder failed |
Authentication against an encrypted folder failed.
Folder path: [DfpEncryptedFolder.UncPath]
Folder ID: [DfpEncryptedFolder.DfpVolumeID]
Network resource: [NetDrive.NetDrivePath] ([NetDrive.NetDriveType])
Authenticated user ID: [DfpUser.UserID]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage]
Authentication type: [Info.DfpAuthTypes] |
438 |
DriveLock |
no |
Information |
Offline encryption started |
An offline encryption operation was started for an encrypted folder.
Folder path: [DfpEncryptedFolder.UncPath]
Folder ID: [DfpEncryptedFolder.DfpVolumeID]
Network resource: [NetDrive.NetDrivePath] ([NetDrive.NetDriveType])
Authenticated user ID: [DfpUser.UserID]
Job ID: [Info.DfpJobID]
Job type: [Info.DfpJobType] - [Info.DfpJobDirection] |
439 |
DriveLock |
no |
Information |
Offline encryption completed |
An offline encryption operation was successfully completed.
Folder path: [DfpEncryptedFolder.UncPath]
Folder ID: [DfpEncryptedFolder.DfpVolumeID]
Network resource: [NetDrive.NetDrivePath] ([NetDrive.NetDriveType])
Authenticated user ID: [DfpUser.UserID]
Job ID: [Info.DfpJobID]
Number of processed files: [Info.IntValue] |
440 |
DriveLock |
no |
Warning |
Offline encryption cancelled |
An offline encryption operation was cancelled.
Folder path: [DfpEncryptedFolder.UncPath]
Folder ID: [DfpEncryptedFolder.DfpVolumeID]
Network resource: [NetDrive.NetDrivePath] ([NetDrive.NetDriveType])
Authenticated user ID: [DfpUser.UserID]
Job ID: [Info.DfpJobID]
Number of files: [Info.IntValue]
Number of incomplete files: [Info.IntValue2] |
441 |
DriveLock |
no |
Error |
Offline encryption: File error |
A file in an offline encryption operation could not be processed.
Folder path: [DfpEncryptedFolder.UncPath]
Folder ID: [DfpEncryptedFolder.DfpVolumeID]
Network resource: [NetDrive.NetDrivePath] ([NetDrive.NetDriveType])
Job ID: [Info.DfpJobID]
Processed file: [Info.FileName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage]
User action: [Info.DfpUserAction] |
442 |
DriveLock |
no |
Error |
Initialization error |
File Protection could not be initialized on this computer.
Error code: [Info.URL]
Error: [Info.ErrorCode] |
443 |
DriveLock |
no |
Error |
Component start error |
A DriveLock system component could not be started on this computer.
Error code: [Info.ErrorMessage]
Error: [Info.ErrorMessage]
Component ID: [Info.IntValue]
Name: [Info.ErrorCode] |
444 |
DriveLock |
no |
Warning |
Ignoring Group Policy settings |
Group Policy settings are ignored as a centrally stored policy or configuration file is applied which is configured to ignore GPO. |
445 |
DriveLock |
no |
Information |
User successfully changed |
An user was successfully changed in the encrypted folder users.
Folder path: [DfpEncryptedFolder.UncPath]
Folder ID: [DfpEncryptedFolder.DfpVolumeID]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Authenticated user ID: [DfpUser.UserID]
Changed user ID: [Info.UserID]
Permissions: [Info.DfpUserPerms] [Info.DfpReadonlyPerms] |
446 |
DriveLock |
no |
Information |
User successfully changed |
An user was successfully changed in the encrypted folder users.
Folder path: [DfpEncryptedFolder.UncPath]
Folder ID: [DfpEncryptedFolder.DfpVolumeID]
Network resource: [NetDrive.NetDrivePath] ([NetDrive.NetDriveType])
Authenticated user ID: [DfpUser.UserID]
Changed user ID: [Info.UserID]
Permissions: [Info.DfpUserPerms] [Info.DfpReadonlyPerms] |
447 |
DriveLock |
no |
Information |
Encrypted folder password changed |
An encrypted folder users password was successfully changed.
Folder path: [DfpEncryptedFolder.UncPath]
Folder ID: [DfpEncryptedFolder.DfpVolumeID]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Changed user ID: [DfpUser.UserID]
Changed by user ID: [Info.UserID] |
448 |
DriveLock |
no |
Information |
Encrypted folder password changed |
An encrypted folder users password was successfully changed.
Folder path: [DfpEncryptedFolder.UncPath]
Folder ID: [DfpEncryptedFolder.DfpVolumeID]
Network resource: [NetDrive.NetDrivePath] ([NetDrive.NetDriveType])
Changed user ID: [DfpUser.UserID]
Changed by user ID: [Info.UserID] |
449 |
DriveLock |
no |
Error |
Password change in an encrypted folder failed |
Changing a password in an encrypted folder failed.
Folder path: [DfpEncryptedFolder.UncPath]
Folder ID: [DfpEncryptedFolder.DfpVolumeID]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Changed user ID: [DfpUser.UserID]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
450 |
DriveLock |
no |
Error |
Password change in an encrypted folder failed |
Changing a password in an encrypted folder failed.
Folder path: [DfpEncryptedFolder.UncPath]
Folder ID: [DfpEncryptedFolder.DfpVolumeID]
Network resource: [NetDrive.NetDrivePath] ([NetDrive.NetDriveType])
Changed user ID: [DfpUser.UserID]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
451 |
DriveLock |
no |
Error |
No or wrong enforced encryption settings |
A drive is configured for enforced encryption using File Protection but enforced encryption settings are not present.
The drive will be blocked and no encryption is executed. |
452 |
DriveLock |
no |
Warning |
Wrong application hash database hash algorithm |
The application hash database [Info.FileName] uses an other hash algorithm than configured globally for application filtering. Applications in this database will not be detected.
Rule: [WhiteList.ObjectID] |
453 |
DriveLock |
no |
Information |
Installation successful, uninstalling update service |
The Agent Update service will be uninstalled as it detected a successfull installation. |
454 |
DriveLock |
no |
Information |
Update service started |
The Agent Update service was started. |
455 |
DriveLock |
no |
Information |
Update service stopped |
The Agent Update service was stopped. |
456 |
DriveLock |
no |
Error |
No server connection detected |
The Agent Update service was unable to find a DriveLock Enterprise Service. Installation and updates will not take place as expected. |
457 |
DriveLock |
no |
Information |
Missing service was registered |
The Agent Update service successfully registered a missing Agent service. |
458 |
DriveLock |
no |
Error |
Error registering missing service |
The Agent Update service was not able to register a missing Agent service. |
459 |
DriveLock |
no |
Warning |
Removed corrupted Agent installation |
The Agent Update service has removed a corrupted Agent installation. |
460 |
DriveLock |
no |
Warning |
Agent installation started |
The Agent Update service started installing the Agent. |
461 |
DriveLock |
no |
Warning |
Agent installation successful |
The Agent Update service successfully installed the Agent. |
462 |
DriveLock |
no |
Error |
Error starting process |
Error while starting Agent registration process.
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
463 |
DriveLock |
no |
Error |
Error starting update service |
Error while starting Agent update service.
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
464 |
DriveLock |
no |
Error |
Error installing agent |
Error while installing the Agent.
Package file: [Info.FileName]
Installation log: [Info.LogFile]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
465 |
DriveLock |
no |
Information |
Windows Firewall status change |
Client compliance status changed for Windows Firewall.
Firewall enabled: [Info.ComponentEnabled] |
466 |
DriveLock |
no |
Information |
Script status change |
Client compliance status changed for script [Info.ComplianceName].
Status: [Info.ComplianceValue] |
467 |
DriveLock |
no |
Information |
Windows Update status change |
Client compliance status changed for Windows Update.
Updates enabled: [Info.ComponentEnabled]
Available updates: [Info.AvblUpdates]
Last successful update: [Info.LastSuccessUpdate] |
468 |
DriveLock |
no |
Information |
WSC Firewall status change |
Client compliance status changed for Windows Security Center - Firewall.
Is installed: [Info.ComponentInstalled]
Is enabled: [Info.ComponentEnabled]
Is up-to-date: [Info.ComponentUptodate] |
469 |
DriveLock |
no |
Information |
WSC Antivirus status change |
Client compliance status changed for Windows Security Center - Antivirus.
Is installed: [Info.ComponentInstalled]
Is enabled: [Info.ComponentEnabled]
Is up-to-date: [Info.ComponentUptodate] |
470 |
DriveLock |
no |
Information |
WSC Anti-Spyware status change |
Client compliance status changed for Windows Security Center - Anti-Spyware.
Is installed: [Info.ComponentInstalled]
Is enabled: [Info.ComponentEnabled]
Is up-to-date: [Info.ComponentUptodate] |
471 |
DriveLock |
no |
Warning |
Remote control declined |
The user declined remote control access. |
472 |
DriveLock |
no |
Information |
Remote control accepted |
The user accepted remote control access. |
473 |
DriveLock |
no |
FailureAudit |
Process blocked |
The execution of a process was blocked by company policy.
Process: [AcProcess.ProcessName]
File Hash: [AcBinary.FileHash]
Applied rule: [WhiteList.ObjectID]
Rule type: [WhiteList.WlType]
File owner (user name): [AcFile.OwnerName]
File owner (user sid): [AcFile.OwnerSID]
File version: [AcBinary.VersionInfo]
Certificate issuer: [AcCertificate.CertIssuer]
Certificate subject: [AcCertificate.CertSubject]
Certificate serial: [AcCertificate.CertSerNo]
Certificate thumb print: [AcCertificate.CertThumbprint]
Description: [AcBinary.VerDescription]
Product: [AcBinary.Product]
Command line: [AcProcess.CmdLine]
Parent process: [Info.ParentProcessName] ([AcProcess.ParentAcProcessID])
Software: [Software.ProductName] [Software.Version] ([Software.ProductCode])
File size: [AcBinary.FileSize]
May start unblocked binaries: [AcProcess.IsTrusted]
Local learning active: [AcProcess.IsLearning]
Has admin priviledges: [AcProcess.IsAdmin]
System process: [AcProcess.IsSystemProcess]
Integrity level: [AcProcess.IntegrityLevel] |
474 |
DriveLock |
no |
SuccessAudit |
Process started |
A process was started.
Process: [AcProcess.ProcessName]
File Hash: [AcBinary.FileHash]
Applied rule: [WhiteList.ObjectID]
Rule type: [WhiteList.WlType]
File owner (user name): [AcFile.OwnerName]
File owner (user sid): [AcFile.OwnerSID]
File version: [AcBinary.VersionInfo]
Certificate issuer: [AcCertificate.CertIssuer]
Certificate subject: [AcCertificate.CertSubject]
Certificate serial: [AcCertificate.CertSerNo]
Certificate thumb print: [AcCertificate.CertThumbprint]
Description: [AcBinary.VerDescription]
Product: [AcBinary.Product]
Unique process ID: [AcProcess.AcProcessID]
Command line: [AcProcess.CmdLine]
Parent process: [Info.ParentProcessName] ([AcProcess.ParentAcProcessID])
Software: [Software.ProductName] [Software.Version] ([Software.ProductCode])
File size: [AcBinary.FileSize]
May start unblocked binaries: [AcProcess.IsTrusted]
Local learning active: [AcProcess.IsLearning]
Has admin priviledges: [AcProcess.IsAdmin]
System process: [AcProcess.IsSystemProcess]
Integrity level: [AcProcess.IntegrityLevel] |
475 |
DriveLock |
no |
Information |
PBA activated |
Pre-boot authentication was successfully activated. |
476 |
DriveLock |
no |
Information |
PBA deactivated |
Pre-boot authentication was successfully deactivated. |
477 |
DriveLock |
no |
Information |
EFS created |
Embedded file system (EFS) was successfully created in the SECURDSK folder. |
478 |
DriveLock |
no |
Error |
PBA activation failed |
Pre-boot authentication could not be activated.
EFS file: [Info.FileName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
479 |
DriveLock |
no |
Error |
PBA deactivation failed |
Pre-boot authentication could not be deactivated.
EFS file: [Info.FileName]
Error: [Info.ErrorMessage] |
480 |
DriveLock |
no |
Error |
EFS creation failed |
Embedded file system (EFS) could not be created.
EFS file: [Info.FileName]
Error: [Info.ErrorMessage] |
481 |
DriveLock |
no |
Error |
Exception occurred |
An exception occurred in a Disk Protection component.
Error: [Info.ErrorMessage] |
482 |
DriveLock |
no |
Information |
Encryption configuration changed |
Encryption configuration has changed.
Drive: [Info.DriveLetter]
Algorithm: [Info.EncryptionAlgorithm] |
483 |
DriveLock |
no |
Error |
Invalid XML configuration |
An invalid XML configuration was detected.
XML path: [Info.FileName] |
484 |
DriveLock |
no |
Information |
XML configuration imported |
A XML configuration was successfully imported.
XML path: [Info.FileName]
Imported data: [Info.ActionName] |
485 |
DriveLock |
no |
Error |
BitLocker-encrypted drive detected |
The drive [Info.DriveLetter] is encrypted with BitLocker drive encryption. It cannot be encrypted with Disk Protection. |
486 |
DriveLock |
no |
Error |
Failed to create disk key |
The random encryption key for the local system could not be generated.
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
487 |
DriveLock |
no |
Error |
Disk Protection Encryptor service error |
A general error occurred in the Disk Protection Encryptor service.
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
488 |
DriveLock |
no |
Error |
Disk Protection Management service error |
A general error occurred in the Disk Protection Management service.
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
489 |
DriveLock |
no |
Audit |
Cannot decrypt removable drive |
The removable drive [Info.DriveLetter] could not be unlocked / decrypted.
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
490 |
DriveLock |
no |
Error |
Encryption interoperation failed |
A storage encryption interoperation failed.
Operation: [Info.Function]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
491 |
DriveLock |
no |
Error |
User store operation failed |
A user store operation failed.
Store type: [Info.StoreType]
Operation: [Info.Function]
Step: [Info.StepName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
492 |
DriveLock |
no |
Error |
Data store operation failed |
A data store operation failed.
Store type: [Info.StoreType]
Operation: [Info.Function]
Step: [Info.StepName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
493 |
DriveLock |
no |
Error |
CD/DVD encryption failed |
An error occurred while encrypting a CD/DVD-ROM using Disk Protection.
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
494 |
DriveLock |
no |
Error |
Password complexity not met |
The password for user "[Info.UserName]" does not meet the password complexity requirements. |
495 |
DriveLock |
no |
Information |
Disk Protection information |
Disk Protection information:
[Info.DebugMsg] |
496 |
DriveLock |
no |
SuccessAudit |
Removable drive decrypted |
The removable drive [Info.DriveLetter] was successfully unlocked / decrypted. |
497 |
DriveLock |
no |
Information |
Encryption completed |
Encryption of drive [Info.DriveLetter] was successfully completed. |
498 |
DriveLock |
no |
Information |
Decryption completed |
Decryption of drive [Info.DriveLetter] was successfully completed. |
499 |
DriveLock |
no |
Information |
Encryption started |
Encryption of drive [Info.DriveLetter] was started with algorithm [Info.EncryptionAlgorithm].
[Info.EncPercent] of the drive are already encrypted. |
500 |
DriveLock |
no |
Information |
Decryption started |
Decryption of drive [Info.DriveLetter] was started.
[Info.EncPercent] of the drive are already encrypted. |
501 |
DriveLock |
no |
Information |
Error en-/decrypting disk sector |
A disk error occurred while en-/decrypting sector [Info.SectorNo] on drive [Info.DriveLetter].
The disk may be defective. |
502 |
DriveLock |
no |
SuccessAudit |
Successful pre-boot authentication |
Successful pre-boot authentication.
Logon type: [Info.LogonType]
User: [Info.UserName]
Logon time: [Info.LogonTime] |
503 |
DriveLock |
no |
SuccessAudit |
Successful emergency pre-boot authentication |
Successful emergency pre-boot authentication.
Logon type: [Info.LogonType]
User: [Info.UserName]
Logon time: [Info.LogonTime] |
504 |
DriveLock |
no |
FailureAudit |
Failed pre-boot authentication |
Failed pre-boot authentication.
Logon type: [Info.LogonType]
User: [Info.UserName]
Logon time: [Info.LogonTime] |
505 |
DriveLock |
no |
Error |
Empty pre-boot user store |
The pre-boot user store could not be saved as it would not contain any user after saving. |
506 |
DriveLock |
no |
Information |
Disk Protection encryptor service started |
The Disk Protection encryptor service was started. |
507 |
DriveLock |
no |
Information |
Disk Protection encryptor service stopped |
The Disk Protection encryptor service was stopped. |
508 |
DriveLock |
no |
Information |
Disk Protection management service started |
The Disk Protection management service was started. |
509 |
DriveLock |
no |
Information |
Disk Protection management service stopped |
The Disk Protection management service was stopped. |
510 |
DriveLock |
no |
Error |
Disk Protection installation failed |
An error occurred while installing Disk Protection.
Step: [Info.StepName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
511 |
DriveLock |
no |
Error |
Disk Protection uninstallation failed |
An error occurred while uninstalling Disk Protection.
Step: [Info.StepName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
512 |
DriveLock |
no |
Error |
Disk Protection upgrade failed |
An error occurred while upgrading Disk Protection.
Step: [Info.StepName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
513 |
DriveLock |
no |
Error |
Disk Protection policy failed |
An error occurred while applying Disk Protection policy.
Step: [Info.StepName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
514 |
DriveLock |
no |
Information |
Disk check succeeded |
Disk check (ChkDsk) on drive [Info.DriveLetter] ([Info.ObjectID]) succeeded. |
515 |
DriveLock |
no |
Error |
Disk check failed |
Disk check (ChkDsk) on drive [Info.DriveLetter] ([Info.ObjectID]) failed.
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
516 |
DriveLock |
no |
Warning |
Disk Protection self wipe |
This computer is offline for a long period. Disk Encryption self-wipe will be initiated in [Info.UnlockTime] days when this computer stays offline. |
517 |
DriveLock |
no |
Warning |
No license - decryption scheduled |
Company policy or licensing on this computer is configured to start decryption of all hard disks. Decryption is scheduled to start on [Info.StatisticTimeStamp]. |
518 |
DriveLock |
no |
Error |
EFS file update failed |
EFS file [Info.FileName] could not be updated as part of company policy.
Error: [Info.ErrorMessage] |
519 |
DriveLock |
no |
Error |
Invalid disk configuration |
Disk Protection installation is not possible on this computer. The disk / partition configuration does not allow installation ([Info.DebugMsg]). |
520 |
DriveLock |
no |
Error |
No policy - All DESs are offline |
Cannot load company policy. All configured DriveLock Enterprise Services are not reachable. |
521 |
DriveLock |
no |
Error |
Cannot determine computer token |
Cannot determine the computer token.
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
522 |
DriveLock |
no |
Error |
Error loading policy assignments |
An error occurred while loading policy assignments from server [Info.ServerName].
Error: [Info.ErrorMessage] |
523 |
DriveLock |
no |
Error |
Policy integrity check failed |
The integrity of an assigned policy could not be verified.
Policy ID: [Info.CspID]
Policy name: [Info.CspName] |
524 |
DriveLock |
no |
SuccessAudit |
File auditing |
File accessed.
DeviceName: [Device.DisplayName]
HardwareId: [Device.HardwareID]
ClassGuid: [Device.ClassID]
Process: [Info.ProcessName]
File size: [File.Size]
File path: [File.Path]
Access direction: [Info.AccessDirection]
File name hash: [File.MD5Hash]
File content hash: [FileContent.MD5Hash]
File name: [File.FileName]
|
525 |
DriveLock |
no |
FailureAudit |
File blocked by content scanner |
File blocked by content scanner. Content does not match file extension.
DeviceName: [Device.DisplayName]
HardwareId: [Device.HardwareID]
ClassGuid: [Device.ClassID]
Process: [Info.ProcessName]
File size: [File.Size]
File path: [File.Path]
Access direction: [Info.AccessDirection]
File name hash: [File.MD5Hash]
File content hash: [FileContent.MD5Hash]
File name: [File.FileName]
|
526 |
DriveLock |
no |
FailureAudit |
File extension blocked |
File blocked by file filter. Access denied due to file type.
DeviceName: [Device.DisplayName]
HardwareId: [Device.HardwareID]
ClassGuid: [Device.ClassID]
Process: [Info.ProcessName]
File size: [File.Size]
File path: [File.Path]
Access direction: [Info.AccessDirection]
File name hash: [File.MD5Hash]
File content hash: [FileContent.MD5Hash]
File name: [File.FileName]
|
527 |
DriveLock |
no |
SuccessAudit |
File deleted |
File deleted.
DeviceName: [Device.DisplayName]
HardwareId: [Device.HardwareID]
ClassGuid: [Device.ClassID]
Process: [Info.ProcessName]
File size: [File.Size]
File path: [File.Path]
File name hash: [File.MD5Hash]
File content hash: [FileContent.MD5Hash]
File name: [File.FileName]
|
528 |
DriveLock |
no |
SuccessAudit |
File created |
New file created.
DeviceName: [Device.DisplayName]
HardwareId: [Device.HardwareID]
ClassGuid: [Device.ClassID]
Process: [Info.ProcessName]
File size: [File.Size]
File path: [File.Path]
File name hash: [File.MD5Hash]
File content hash: [FileContent.MD5Hash]
File name: [File.FileName]
|
529 |
DriveLock |
no |
SuccessAudit |
File renamed |
File renamed.
DeviceName: [Device.DisplayName]
HardwareId: [Device.HardwareID]
ClassGuid: [Device.ClassID]
Process: [Info.ProcessName]
File size: [File.Size]
File path: [File.Path]
Old file name hash: [File.MD5Hash]
New file name: [Info.FileName]
New file name hash: [Info.MD5Hash]
File content hash: [FileContent.MD5Hash]
Old file name: [File.FileName]
|
530 |
DriveLock |
no |
Error |
Actual licensing |
Licensing is configured using ActiveDirectory objects. The actual licensing status is:
Device Control: [Info.LicDLock]
Disk Protection: [Info.LicFde]
Encryption 2-Go: [Info.LicDlv]
File Protection: [Info.LicFfe]
BitLocker Management: [Info.LicBitLock]
Application Control: [Info.LicALF]
Application Behavior Control: [Info.LicAppBehavior]
Security Awareness Content: [Info.LicAware]
Legacy OS Support: [Info.LicLegacy]
DriveLock PBA: [Info.LicPBA]
Vulnerability Scanner: [Info.LicVulScan]
Defender Management: [Info.LicDefender]
BitLocker 2 Go: [Info.LicBl2Go]
EDR: [Info.LicEDR]
Native Security: [Info.LicNatSec]
Detected without errors: [Info.LicSure] |
531 |
DriveLock |
no |
Information |
Scheduled job: Started |
Scheduled antivirus scan job was started.
Job ID: [Info.ConfigId]
Job description: [Info.DisplayName] |
532 |
DriveLock |
no |
Information |
Scheduled job: Initiated shutdown |
Scheduled antivirus scan job initiated system shutdown after execution.
Job ID: [Info.ConfigId]
Job description: [Info.DisplayName] |
533 |
DriveLock |
no |
Warning |
No policy - wiped |
No valid policy available - the company policy was wiped because the computer was offline for a long period of time. |
534 |
DriveLock |
no |
Warning |
Policy wipe - Warning |
The computer is offline for [Info.DisplayName] days. The company policy will be wiped soon. |
535 |
DriveLock |
no |
Error |
Company policy wiped |
The company policy was wiped because the computer was offline for a long period of time. |
536 |
DriveLock |
no |
Information |
Company policy in use again |
The company policy is in used again after it was wiped because the computer was offline for a long period of time. |
537 |
DriveLock |
no |
Error |
URL categorizer failed |
The URL categorizer returned an error while categorizing an URL.
Error: [Info.ErrorMessage] |
538 |
DriveLock |
no |
Error |
Network filter driver error |
An error occurred while communicating with the network filtering driver.
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
539 |
DriveLock |
no |
Error |
Network filter driver error |
An error occurred while setting up network filtering.
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
546 |
DriveLock |
no |
Warning |
Application Control temporarily disabled |
Application Control was temporarily disabled by administrative intervention.
Learn written files: [Info.LearnWrittenFiles]
Learn executed files: [Info.LearnExecutedFiles]
User has to approve files before learning: [Info.UserApprovalMode] |
547 |
DriveLock |
no |
Warning |
Web Security temporarily disabled |
Web Security was temporarily disabled by administrative intervention. |
550 |
DriveLock |
no |
Information |
PBA password change |
User [Info.UserName] (domain [Info.DomainName]) changed the password in pre-boot authentication. |
551 |
DriveLock |
no |
SuccessAudit |
Usage policy accepted by authorized user |
Usage policy for drive [Info.DriveLetter] was accepted by authorized user [Info.UserName]@[Info.DomainName].
Logged on user was [Info.UserName2]@[Info.DomainName2]
|
553 |
DriveLock |
no |
Information |
MTP/WPD/Android not supported on this platform |
Control of portable mobile and Android devices is not available on this platform.
Please refer to the DriveLock website for detailed information. |
554 |
DriveLock |
no |
Information |
Picture taken |
A picture was taken with camera [Info.CameraName] for event ID [Info.EventID] ([Info.EventNumber]). |
555 |
DriveLock |
no |
Information |
Scheduled action: Started |
Scheduled power action was started.
Job ID: [Info.ConfigId]
Job description: [Info.DisplayName] |
556 |
DriveLock |
no |
Error |
Scheduled action: Execution failed |
Executing a scheduled power action failed.
Job ID: [Info.ConfigId]
Job description: [Info.DisplayName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
557 |
DriveLock |
no |
Information |
Scheduled action: Successfully executed |
Scheduled power action successfully executed.
Job ID: [Info.ConfigId]
Job description: [Info.DisplayName] |
558 |
DriveLock |
no |
Error |
Scheduled action: Load failed |
Loading scheduled power action failed.
Job ID: [Info.ConfigId]
Job description: [Info.DisplayName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
559 |
DriveLock |
no |
Information |
Power scheme changed |
Computer power scheme successfully changed.
Rule ID: [Info.ConfigId]
Rule name: [Info.DisplayName]
Power scheme: [Info.FunctionName] |
560 |
DriveLock |
no |
Error |
Power scheme change failed |
Changing computer power scheme failed.
Rule ID: [Info.ConfigId]
Rule name: [Info.DisplayName]
Power scheme: [Info.FunctionName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
561 |
DriveLock |
no |
Error |
Cannot encrypt drives larger 2 TB |
The drive [Info.DriveLetter] is larger than 2 TB. It cannot be encrypted with Disk Protection. |
562 |
DriveLock |
no |
Warning |
Antivirus error |
An antivirus error occurred while scanning object [Info.FileName].
Error: [Info.ErrorMessage] |
563 |
DriveLock |
no |
Information |
Definition update started |
Antivirus definition update was started from source [Info.MethodName]. |
564 |
DriveLock |
no |
Error |
Error starting definition update |
Antivirus definition update could not be started from source [Info.MethodName].
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
565 |
DriveLock |
no |
Warning |
Package download error |
The [Info.PackageType] package could not be downloaded from [Info.URL]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
566 |
DriveLock |
no |
Information |
Package download successful |
The [Info.PackageType] package was successfully downloaded. |
567 |
DriveLock |
no |
Warning |
Package extraction error |
The [Info.PackageType] package could not be extracted.
The file [Info.PackagePath] may be missing or corrupt.
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
568 |
DriveLock |
no |
Warning |
Package installation prevented |
The [Info.PackageType] package should be installed but the installation is prevented by administrative intervention. |
569 |
DriveLock |
no |
Information |
Package installation successful |
[Info.PackageType] was successfully installed. |
570 |
DriveLock |
no |
Error |
Package installation error |
[Info.PackageType] installation failed.
Command line: [Info.CmdLine]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
571 |
DriveLock |
no |
Information |
Package uninstallation successful |
[Info.PackageType] was successfully uninstalled. |
572 |
DriveLock |
no |
Error |
Package uninstallation error |
[Info.PackageType] uninstallation failed.
Command line: [Info.CmdLine]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
573 |
DriveLock |
no |
Error |
Incremental definition update failed |
Incremental definition update failed to apply the patch package.
Old definition file: [Info.OldValue]
New definition file: [Info.NewValue]
Error: [Info.ErrorMessage] |
574 |
DriveLock |
no |
Error |
Definition update error |
An error occurred while updating antivirus definitions.
Error: [Info.ErrorMessage] |
575 |
DriveLock |
no |
Warning |
Real-time scanning stopped |
Real-time antivirus scanning was stopped. |
576 |
DriveLock |
no |
Warning |
Definition update requires reboot |
A previous Antivirus definition update required a system reboot. No further updates will be possible until the system is rebooted. |
577 |
DriveLock |
no |
Information |
Encrypted folder properties changed |
The Properties of an encrypted folder have changed.
Folder path: [DfpEncryptedFolder.UncPath]
Folder ID: [DfpEncryptedFolder.DfpVolumeID]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Authenticated user ID: [DfpUser.UserID]
[DfpEncryptedFolder.ExtendedAuditing]
Folder name: [DfpEncryptedFolder.FolderName] |
578 |
DriveLock |
no |
Information |
Encrypted folder properties changed |
The Properties of an encrypted folder have changed.
Folder path: [DfpEncryptedFolder.UncPath]
Folder ID: [DfpEncryptedFolder.DfpVolumeID]
Network resource: [NetDrive.NetDrivePath] ([NetDrive.NetDriveType])
Authenticated user ID: [DfpUser.UserID]
Folder name: [DfpEncryptedFolder.FolderName]
Remote Audit activated: [DfpEncryptedFolder.ExtendedAuditing] |
579 |
DriveLock |
no |
SuccessAudit |
Network pre-boot authentication succeeded |
The network pre-boot authentication succeeded. |
580 |
DriveLock |
no |
Error |
Error during network pre-boot authentication |
An error occurred during network pre-boot authentication.
Error: [Info.ErrorMessage] |
581 |
DriveLock |
no |
Error |
Error during network pre-boot authentication (1) |
An error occurred during network pre-boot authentication.
Error: [Info.ErrorMessage]
Parameter: [Info.ErrorMessage2] |
582 |
DriveLock |
no |
Error |
Error retrieving custom computer name |
An error occurred while retrieving the custom computer name.
Step: [Info.StepName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
583 |
DriveLock |
no |
Error |
Error with Active Directory inventory |
An error occurred while generating Active Directory inventory.
Step: [Info.StepName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
584 |
DriveLock |
no |
Information |
Active Directory inventory started |
Active Directory inventory generation was triggered by DES. |
585 |
DriveLock |
no |
Information |
Network pre-boot authentication disabled |
Network pre-boot authentication was disabled. |
586 |
DriveLock |
no |
Information |
Network pre-boot authentication enabled |
Network pre-boot authentication was enabled. |
587 |
DriveLock |
no |
Error |
Error reading Windows netword configuration |
An error occurred while reading the Windows network configuration (for network pre-boot configuration).
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
588 |
DriveLock |
no |
Error |
Cannot load configuration from EFS |
Cannot load network pre-boot configuration from embedded file system (EFS). |
589 |
DriveLock |
no |
Error |
Cannot write configuration to EFS |
Cannot write network pre-boot configuration to embedded file system (EFS). |
590 |
DriveLock |
no |
Error |
Error installing network pre-boot authentication |
An error occurred while installing the network pre-boot authentication.
Step: [Info.StepName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
591 |
DriveLock |
no |
Error |
Error registering network pre-boot authentication |
An error occurred while registering the network pre-boot authentication with the server.
Step: [Info.StepName]
Error: [Info.ErrorMessage] |
592 |
DriveLock |
no |
Error |
Error uninstalling network pre-boot authentication |
An error occurred while uninstalling the network pre-boot authentication.
Step: [Info.StepName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
593 |
DriveLock |
no |
Information |
Local whitelist created |
Learning the local application whitelist was completed. |
594 |
DriveLock |
no |
Error |
Error creating local whitelist |
An error occurred while learning the local application whitelist.
Step: [Info.StepName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
595 |
DriveLock |
no |
Error |
Error learning a file |
An error occurred while learning the executable file "[Info.FileName]".
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
596 |
DriveLock |
no |
Information |
File added to local whitelist |
Learning executable file "[Info.FileName]" completed.
Reason: [Info.AlfLearnReason]
File hash: [AcBinary.FileHash]
File size: [AcBinary.FileSize]
Product: [AcBinary.Product]
Description: [AcBinary.VerDescription]
File version: [AcBinary.VersionInfo]
Certificate issuer: [AcCertificate.CertIssuer]
Certificate subject: [AcCertificate.CertSubject]
Certificate serial: [AcCertificate.CertSerNo]
Certificate thumb print: [AcCertificate.CertThumbprint] |
597 |
DriveLock |
no |
Error |
Application Control license required |
The company policy contains settings for application control features requiring a special license which is not present on the system.
Error: [Info.ErrorMessage] |
598 |
DriveLock |
no |
Information |
Security awareness campaign presented |
A security awareness campaign was presented to the user.
Campaign: [WhiteList.ObjectID]
Description: [Info.DisplayName] |
599 |
DriveLock |
no |
Information |
Security awareness campaign completed |
A security awareness campaign was completed by the user.
Module: [WhiteList.ObjectID]
Description: [Info.DisplayName] |
600 |
DriveLock |
no |
Information |
Program start approved |
Start of executable file [Info.FileName] was approved by the user.
|
601 |
DriveLock |
no |
Error |
Invalid policy signing certificate |
The configured policy signing certificate cannot be read.
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
602 |
DriveLock |
no |
Information |
Program start declined by user |
Start of executable file [Info.FileName] was declined by the user.
|
603 |
DriveLock |
no |
Information |
Security awareness skill test closed |
The user did not pass a security awareness test.
Module: [WhiteList.ObjectID]
Description: [Info.DisplayName]
Result: [Info.ErrorCode] |
604 |
DriveLock |
no |
Information |
Security awareness test successful |
A security awareness test was successfully completed by the user.
Module: [WhiteList.ObjectID]
Description: [Info.DisplayName]
Result: [Info.ErrorCode] |
605 |
DriveLock |
no |
Warning |
Security awareness campaign cancelled |
A security awareness campaign was cancelled by the user.
Module: [WhiteList.ObjectID]
Description: [Info.DisplayName]
Progress: [Info.ErrorCode] |
606 |
DriveLock |
no |
Error |
Policy integrity check failed |
The digital signature of an assigned policy could not be verified using the configured policy signing certificate.
Policy ID: [Info.ServerName]
Policy name: [Info.ErrorMessage] |
607 |
DriveLock |
no |
Error |
Security awareness campaign: Retrieving data failed |
Retrieving security awareness campaign content from server [Info.ServerName] failed.
Package type: [Info.SecAwPackageType]
Error: [Info.ErrorMessage] |
608 |
DriveLock |
no |
Error |
Security awareness campaign: Download failed |
Downloading security awareness campaign content failed.
Package file download URL: [Info.URL]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
609 |
DriveLock |
no |
Error |
BitLocker key backup failed |
The BitLocker recovery key backup failed.
Step: [Info.StepName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
610 |
DriveLock |
no |
Warning |
BitLocker cannot apply configuration |
The BitLocker configuration could not be applied. |
611 |
DriveLock |
no |
Warning |
BitLocker not licensed |
BitLocker is configured to encrypt local hard disks but is not licensed on this computer. |
612 |
DriveLock |
no |
Information |
BitLocker will not be installed or uninstalled |
A change in the BitLocker configuration was detected, but the change is not applied due to the 'delay decryption' setting in the policy. |
613 |
DriveLock |
no |
Warning |
BitLocker manually reconfigured |
BitLocker is manually reconfigured. |
614 |
DriveLock |
no |
Warning |
Decryption scheduled |
Company policy or licensing on this computer is configured to start decryption of all hard disks. Decryption is scheduled to start on [Info.StatisticTimeStamp]. |
615 |
DriveLock |
no |
Information |
BitLocker encryption successful |
BitLocker successfully encrypted hard disk: [Info.DriveLetter]. |
616 |
DriveLock |
no |
Information |
BitLocker decryption successful |
BitLocker successfully decrypted local hard disk: [Info.DriveLetter]. |
617 |
DriveLock |
no |
Error |
BitLocker key backup creation failed |
The BitLocker key backup creation failed. |
618 |
DriveLock |
no |
Information |
BitLocker encryption started |
BitLocker started encrypting local hard disk: [Info.DriveLetter]. |
619 |
DriveLock |
no |
Information |
BitLocker decryption started |
BitLocker started decrypting local hard disk: [Info.DriveLetter]. |
620 |
DriveLock |
no |
Error |
BitLocker system error |
BitLocker Emergency Recovery Information could not be moved to [Info.TargetFolder].
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
621 |
DriveLock |
no |
Information |
BitLocker login succeeded |
BitLocker login succeeded. |
622 |
DriveLock |
no |
Warning |
BitLocker login failed |
BitLocker login failed. |
623 |
DriveLock |
no |
Warning |
BitLocker password reset dialog cancelled |
The BitLocker password reset dialog was cancelled. |
624 |
DriveLock |
no |
Information |
BitLocker password dialog finished |
The BitLocker password dialog was finished. |
625 |
DriveLock |
no |
Error |
BitLocker encryption failed |
The BitLocker encryption failed. Error: [Info.ErrorMessage]. |
626 |
DriveLock |
no |
Information |
BitLocker protectors applied |
The BitLocker protectors [Info.Protectors] were applied for drive [Info.DriveLetter]. |
627 |
DriveLock |
no |
Information |
BitLocker encryption algorithm applied |
The encryption algorithm [Info.EncryptionAlgorithm] is used to encrypt drive [Info.DriveLetter]. |
628 |
DriveLock |
no |
Information |
BitLocker recovery data upload |
BitLocker recovery data was uploaded to the server. |
629 |
DriveLock |
no |
Error |
BitLocker recovery data upload failed |
BitLocker recovery data upload failed. Error: [Info.ErrorMessage] |
630 |
DriveLock |
no |
Warning |
BitLocker not controlled by DriveLock detected |
Drive [Info.DriveLetter] is already encrypted with BitLocker but not controlled by DriveLock. |
631 |
DriveLock |
no |
Warning |
Locked drive detected |
BitLocker: locked drive [Info.DriveLetter] detected. |
632 |
DriveLock |
no |
Information |
BitLocker configuration succeeded |
BitLocker configuration succeeded. |
633 |
DriveLock |
no |
Information |
BitLocker configuration failed |
BitLocker configuration failed. Error: [Info.ErrorMessage]. |
634 |
DriveLock |
no |
Information |
BitLocker password set |
BitLocker password was set by the user for drive: [Info.DriveLetter]. |
635 |
DriveLock |
no |
Information |
BitLocker password set failed |
Setting BitLocker password failed for drive: [Info.DriveLetter]. Error message: [Info.ErrorMessage]. |
636 |
DriveLock |
no |
Warning |
BitLocker drive not compliant |
DriveLock detected changes on drive [Info.DriveLetter] that do not match the configuration. Actions will be taken to modify the configuration. |
637 |
DriveLock |
no |
Information |
BitLocker recovery key replaced |
The recovery key of drive [Info.DriveLetter] was recreated after recovery process. |
638 |
DriveLock |
no |
Information |
BitLocker internal message |
BitLocker Management internal message: [Info.DebugMsg] |
639 |
DriveLock |
no |
Error |
Server certificate error |
Server certificate error detected. Certificate: [Info.CertSubject]. Error message: [Info.ErrorMessage] |
640 |
DriveLock |
no |
Information |
Security awareness campaign presented |
The security awareness campaign '[Info.SecAwPackageDisplayName]' was presented to the user.
Content type: [Info.SecAwPackageContentType]
Language: [Info.SecAwPackageLanguage]
Version: [Info.SecAwPackageVersion]
Applied rule: [WhiteList.ObjectID] |
641 |
DriveLock |
no |
Information |
Security awareness campaign element acknowledged |
The security awareness campaign element '[Info.SecAwPackageDisplayName]' was acknowledged by the user.
Content type: [Info.SecAwPackageContentType]
Language: [Info.SecAwPackageLanguage]
Version: [Info.SecAwPackageVersion]
Applied rule: [WhiteList.ObjectID] |
642 |
DriveLock |
no |
Information |
Security awareness campaign completed |
The security awareness campaign '[Info.SecAwPackageDisplayName]' was completed by the user.
Content type: [Info.SecAwPackageContentType]
Language: [Info.SecAwPackageLanguage]
Version: [Info.SecAwPackageVersion]
Applied rule: [WhiteList.ObjectID] |
643 |
DriveLock |
no |
Warning |
Security awareness campaign cancelled |
The security awareness campaign '[Info.SecAwPackageDisplayName]' was cancelled by the user.
Content type: [Info.SecAwPackageContentType]
Language: [Info.SecAwPackageLanguage]
Version: [Info.SecAwPackageVersion]
Progress: [Info.SecAwResultScorePassed] passed / [Info.SecAwResultScoreFailed] failed
Applied rule: [WhiteList.ObjectID] |
644 |
DriveLock |
no |
Information |
Security awareness test failed |
The user did not pass the security awareness test '[Info.SecAwPackageDisplayName]'.
Content type: [Info.SecAwPackageContentType]
Language: [Info.SecAwPackageLanguage]
Version: [Info.SecAwPackageVersion]
Result: [Info.SecAwResultScorePassed] passed / [Info.SecAwResultScoreFailed] failed
Applied rule: [WhiteList.ObjectID] |
645 |
DriveLock |
no |
Information |
Security awareness test successful |
The security awareness test '[Info.SecAwPackageDisplayName]' was successfully completed by the user.
Content type: [Info.SecAwPackageContentType]
Language: [Info.SecAwPackageLanguage]
Version: [Info.SecAwPackageVersion]
Result: [Info.SecAwResultScorePassed] passed / [Info.SecAwResultScoreFailed] failed
Applied rule: [WhiteList.ObjectID] |
646 |
DriveLock |
no |
Information |
Security awareness campaign in progress |
The security awareness campaign '[Info.SecAwPackageDisplayName]' is in progress.
Content type: [Info.SecAwPackageContentType]
Language: [Info.SecAwPackageLanguage]
Version: [Info.SecAwPackageVersion]
Currently: [Info.SecAwSessionProgress] %% completed
Applied rule: [WhiteList.ObjectID] |
647 |
DriveLock |
no |
Information |
Security awareness test in progress |
The security awareness test '[Info.SecAwPackageDisplayName]' is in progress.
Content type: [Info.SecAwPackageContentType]
Language: [Info.SecAwPackageLanguage]
Version: [Info.SecAwPackageVersion]
Current result: [Info.SecAwResultScorePassed] passed / [Info.SecAwResultScoreFailed] failed
Applied rule: [WhiteList.ObjectID] |
648 |
DriveLock |
no |
FailureAudit |
DLL blocked |
The loading of a DLL was blocked by company policy.
Process: [AcProcess.ProcessName] ([AcProcess.AcProcessID])
Applied rule: [WhiteList.ObjectID]
Rule type: [WhiteList.WlType]
DLL File Name: [AcFile.FilePath]
DLL File Hash: [AcBinary.FileHash]
File owner (user name): [AcFile.OwnerName]
File owner (user sid): [AcFile.OwnerSID]
File version: [AcBinary.VersionInfo]
Certificate issuer: [AcCertificate.CertIssuer]
Certificate subject: [AcCertificate.CertSubject]
Certificate serial: [AcCertificate.CertSerNo]
Certificate thumb print: [AcCertificate.CertThumbprint]
Description: [AcBinary.VerDescription]
Product: [AcBinary.Product]
Software: [Software.ProductName] [Software.Version] ([Software.ProductCode]) |
649 |
DriveLock |
no |
SuccessAudit |
DLL loaded |
A DLL was loaded.
Process: [AcProcess.ProcessName] ([AcProcess.AcProcessID])
Applied rule: [WhiteList.ObjectID]
Rule type: [WhiteList.WlType]
DLL File Name: [AcFile.FilePath]
DLL File Hash: [AcBinary.FileHash]
File owner (user name): [AcFile.OwnerName]
File owner (user sid): [AcFile.OwnerSID]
File version: [AcBinary.VersionInfo]
Certificate issuer: [AcCertificate.CertIssuer]
Certificate subject: [AcCertificate.CertSubject]
Certificate serial: [AcCertificate.CertSerNo]
Certificate thumb print: [AcCertificate.CertThumbprint]
Description: [AcBinary.VerDescription]
Product: [AcBinary.Product]
Software: [Software.ProductName] [Software.Version] ([Software.ProductCode]) |
650 |
DriveLock |
no |
FailureAudit |
File Access blocked |
The Access to a File was blocked by company policy.
Process: [AcProcess.ProcessName] ([AcProcess.AcProcessID])
Applied rule: [WhiteList.ObjectID]
Rule type: [WhiteList.WlType]
File Name: [Info.FileName]
AccessDirection: [Info.AccessDirection] |
651 |
DriveLock |
no |
SuccessAudit |
File Access |
A File was accessed.
Process: [AcProcess.ProcessName] ([AcProcess.AcProcessID])
Applied rule: [WhiteList.ObjectID]
Rule type: [WhiteList.WlType]
File Name: [Info.FileName]
AccessDirection: [Info.AccessDirection] |
652 |
DriveLock |
no |
FailureAudit |
Registry Access blocked |
The Access to the Registry was blocked by company policy.
Process: [AcProcess.ProcessName] ([AcProcess.AcProcessID])
Applied rule: [WhiteList.ObjectID]
Rule type: [WhiteList.WlType]
Path: [Info.RegistryPath]
AccessDirection: [Info.AccessDirection] |
653 |
DriveLock |
no |
SuccessAudit |
Registry Access |
The Registry was accessed.
Process: [AcProcess.ProcessName] ([AcProcess.AcProcessID])
Applied rule: [WhiteList.ObjectID]
Rule type: [WhiteList.WlType]
Path: [Info.RegistryPath]
AccessDirection: [Info.AccessDirection] |
654 |
DriveLock |
no |
SuccessAudit |
File Access approved |
The Access to a File was approved by the user.
Process: [AcProcess.ProcessName] ([AcProcess.AcProcessID])
File Name: [Info.FileName] |
655 |
DriveLock |
no |
FailureAudit |
File Access denied |
The Access to a File was denied by the user.
Process: [AcProcess.ProcessName] ([AcProcess.AcProcessID])
File Name: [Info.FileName] |
656 |
DriveLock |
no |
SuccessAudit |
Registry Access approved |
The Access to the Registry was approved by the user.
Process: [AcProcess.ProcessName] ([AcProcess.AcProcessID])
Path: [Info.RegistryPath] |
657 |
DriveLock |
no |
FailureAudit |
Registry Access denied |
The Access to the Registry was denied by the user.
Process: [AcProcess.ProcessName] ([AcProcess.AcProcessID])
Path: [Info.RegistryPath] |
660 |
DriveLock |
no |
Error |
BitLocker is missing |
BitLocker is missing |
661 |
DriveLock |
no |
Error |
BitLocker Management detected BIOS |
BitLocker Management detected BIOS. DriveLock PBA is only supported on UEFI. |
662 |
DriveLock |
no |
Error |
BitLocker system drive not prepared |
BitLocker Management: BitLocker doesn't seem to be prepared for the system drive: [Info.DriveLetter]. The drive can be prepared using 'bdehdcfg.exe -target default -restart' |
663 |
DriveLock |
no |
Information |
Disk Protection recovery data upload |
Disk Protection recovery data was uploaded to the server. |
664 |
DriveLock |
no |
Error |
Disk Protection recovery data upload failed |
Disk Protection recovery data upload failed. Error: [Info.ErrorMessage] |
665 |
DriveLock |
no |
SuccessAudit |
The DES transmitted authorization data to the PBA |
The DES transmitted authorization data to the PBA. |
666 |
DriveLock |
no |
Error |
Invalid network PBA key registration |
Recorded attempt to register the PBA network key a second time. |
667 |
DriveLock |
no |
Error |
Invalid network PBA authorization data registration |
Recorded attempt to register the PBA authorization data a second time. |
668 |
DriveLock |
no |
Error |
Cannot decrypt message from network PBA |
Cannot decrypt message from network PBA. Error: [Info.ErrorMessage]. |
669 |
DriveLock |
no |
Error |
Invalid network PBA message |
An invalid message from the network PBA has been received. Error: [Info.ErrorMessage]. |
670 |
DriveLock |
no |
FailureAudit |
Computer not registered for network PBA |
The server received an network PBA connect request for a not registered computer. |
671 |
DriveLock |
no |
FailureAudit |
No authorization data for network PBA |
Unable to authorize network PBA because the computer has not registerd authorization data. |
672 |
DriveLock |
no |
Error |
PBA network issues |
The PBA has problems to connect to the network. Error: [Info.ErrorMessage]. |
673 |
DriveLock |
no |
Error |
Network PBA cannot connect to the server |
An error occurred while the network PBA tried to connect to the server. Info: [Info.IPAddress]. Error: [Info.ErrorMessage]. |
674 |
DriveLock |
no |
Error |
Invalid network PBA server response |
The network PBA received an invalid server response. Error: [Info.ErrorMessage]. |
675 |
DriveLock |
no |
Error |
Network PBA authorization data decryption failed |
The network PBA is unable to decrypt the authorization data. Error: [Info.ErrorMessage]. |
676 |
DriveLock |
no |
Error |
Network PBA cannot unlock disk |
The network PBA is unable unlock the disk using the authorization data. Error: [Info.ErrorMessage]. Details: [Info.ErrorMessage2]. |
677 |
DriveLock |
no |
FailureAudit |
Network PBA logon failed |
Network PBA logon failed. User: [Info.UserName]. |
678 |
DriveLock |
no |
FailureAudit |
Automatic logon via network PBA failed. |
Automatic logon via network PBA failed. |
679 |
DriveLock |
no |
Information |
Learning of local whitelist started |
Learning of local application whitelist was started. |
680 |
DriveLock |
no |
Information |
Application behavior recording started |
Recording of application behavior was started. |
681 |
DriveLock |
no |
Error |
Configuration of Microsoft Defender failed |
Error configuring Microsoft Defender.
Error code: [Info.ErrorCode].
Error: [Info.ErrorMessage]. |
682 |
DriveLock |
no |
Information |
Microsoft Defender configuration changes reverted |
Detected Microsoft Defender configuration changes by a third party. The changes have been reverted. Details: [Info.Details]. |
683 |
DriveLock |
no |
Error |
Failed to revert Microsoft Defender configuration changes |
Detected Microsoft Defender configuration changes by a third party. The changes cannot be reverted. Details: [Info.Details].
Error code: [Info.ErrorCode].
Error: [Info.ErrorMessage]. |
684 |
DriveLock |
no |
Warning |
Microsoft Defender detected a threat |
Microsoft Defender detected the threat [Malware.DetectionName] ([Malware.DetectionType]).
Infected file: [File.Path]
Drive letter: [File.DriveLetter]
File name: [File.FileName]
File name hash: [File.MD5Hash] |
685 |
DriveLock |
no |
Warning |
Microsoft Defender threat allowed |
A user has allowed a threat detected by Microsoft Defender.
Threat: [Malware.DetectionName]
Category: [Malware.DetectionType] |
686 |
DriveLock |
no |
Warning |
Microsoft Defender threat restored from quarantine |
A user has restored a quarantined threat detected by Microsoft Defender.
Threat: [Malware.DetectionName]
Category: [Malware.DetectionType] |
687 |
DriveLock |
no |
Error |
Microsoft Defender signature update failed |
Unable to update Microsoft Defender signature definition. Details: [Info.Details]. |
688 |
DriveLock |
no |
SuccessAudit |
Encrypted volume connected |
Encrypted volume [Info.DriveLetter] was added to the system.
It is encrypted with [Info.EncryptionType].
Mobile Encryption Application: [Info.FileVersion]
Has unencrypted part: [Info.UnencryptedPartPresent], size: [Info.DataSize], permission: [Info.UserLockState]
|
689 |
DriveLock |
no |
SuccessAudit |
Application behavior control changed |
Application behavior control for [Info.ProcessName] changed:
Execute: [Info.LocalBehaviorExecute]
DLL load: [Info.LocalBehaviorDllLoad]
Write Files: [Info.LocalBehaviorFileWrite] |
690 |
DriveLock |
no |
Information |
Vulnerability scan successful |
Vulnerability scan was successfully executed and results were uploaded.
DES server: [Info.DesName]
Connection ID: [Info.ObjectID] |
691 |
DriveLock |
no |
Error |
Vulnerability catalog not downloaded |
Vulnerability scan could not be executed because the vulnerabilities catalog was not yet downloaded from the server. |
692 |
DriveLock |
no |
Error |
Vulnerability scan failed |
The vulnerability scanner failed scanning.
Error: [Info.ErrorMessage] |
693 |
DriveLock |
no |
Error |
Error starting vulnerability scan |
Error while starting a vulnerability scan.
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
694 |
DriveLock |
no |
Error |
Error downloading vulnerability catalog |
Error while downloading the vulnerability catalog.
Server: [Info.ServerName]
Step: [Info.StepName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
695 |
DriveLock |
no |
Error |
Error creating vulnerability scan result |
Error while creating the vulnerability scan result.
Step: [Info.StepName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
696 |
DriveLock |
no |
Warning |
Microsoft Defender detected a threat on a network resource |
Microsoft Defender detected the threat [Malware.DetectionName] ([Malware.DetectionType]).
Infected network file: [File.Path]
Network resource: [NetDrive.NetDrivePath] ([NetDrive.NetDriveType])
File name: [File.FileName]
File name hash: [File.MD5Hash] |
697 |
DriveLock |
no |
Warning |
Microsoft Defender detected a threat |
Microsoft Defender detected the threat [Malware.DetectionName] ([Malware.DetectionType]).
Infected file: [File.Path]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Drive letter: [File.DriveLetter]
File name: [File.FileName]
File name hash: [File.MD5Hash]
Hardware Id: [Drive.HardwareID] |
698 |
DriveLock |
no |
Error |
Microsoft Defender is disabled |
Microsoft Defender is disabled and cannot be enabled by DriveLock. |
699 |
DriveLock |
no |
Information |
Applied Microsoft Defender configuration |
Microsoft Defender configuration was successfully applied. |
700 |
DriveLock |
no |
Warning |
Microsoft Defender blocked an operation |
Microsoft Defender blocked an operation of type: [Info.ASRRuleType]
Detection time: [Info.TimeStamp]
Path: [Info.FileName]
Process: [Info.ProcessName]
Signature version: [Info.SignatureVersion]
Engine version[Info.EngineVersion]
Product version: [Info.ProductVersion]
User: [Info.UserName] |
701 |
DriveLock |
no |
SuccessAudit |
Microsoft Defender audited an operation |
Microsoft Defender audited an operation of type: [Info.ASRRuleType]
Detection time: [Info.TimeStamp]
Path: [Info.FileName]
Process: [Info.ProcessName]
Signature version: [Info.SignatureVersion]
Engine version[Info.EngineVersion]
Product version: [Info.ProductVersion]
User: [Info.UserName] |
702 |
DriveLock |
no |
Error |
Error uploading data to DES |
An error occurred while uploading data to DriveLock Enterprise Service.
Upload URL: [Info.StepName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
703 |
DriveLock |
no |
Information |
Vulnerability scan started |
Vulnerability scan was triggered by DES. |
704 |
DriveLock |
no |
Error |
Error reading volume identification file |
An error occurred while reading the volume identification file from drive [Info.DriveLetter].
Bus type: [Drive.StorageBus]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage]
Hardware Id: [Drive.HardwareID] |
705 |
DriveLock |
no |
Error |
Error reading volume identification hash list file |
An error occurred while reading the volume identification hash list file from drive [Info.DriveLetter].
Bus type: [Drive.StorageBus]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage]
Hardware Id: [Drive.HardwareID] |
706 |
DriveLock |
no |
Error |
Volume identification file is expired |
An error occurred while reading the volume identification file from drive [Info.DriveLetter]: the file is expired.
Bus type: [Drive.StorageBus]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Hardware Id: [Drive.HardwareID] |
707 |
DriveLock |
no |
Warning |
Unsecure transport protocol |
Agent is using the unsecure HTTP protocol. |
708 |
DriveLock |
no |
Error |
Error enumerating local user accounts |
An error occurred while enumerating local user accounts.
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
709 |
DriveLock |
no |
Error |
Error enumerating local groups |
An error occurred while enumerating local groups.
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
710 |
DriveLock |
no |
Error |
Error changing local group information |
An error occurred while changing local group information.
Group: [Info.GroupName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
711 |
DriveLock |
no |
Error |
Error reading local group members |
An error occurred while reading local group members.
Group: [Info.GroupName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
712 |
DriveLock |
no |
Error |
Error removing local group member |
An error occurred while removing a local group member.
Group: [Info.GroupName]
User: [Info.UserName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
713 |
DriveLock |
no |
Error |
Error adding local group member |
An error occurred while adding a local group member.
Group: [Info.GroupName]
User: [Info.UserName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
714 |
DriveLock |
no |
Information |
Local group member removed |
A local group member was successfully removed.
Group: [Info.GroupName]
User: [Info.UserName] |
715 |
DriveLock |
no |
Information |
Local group member added |
A local group member was successfully added.
Group: [Info.GroupName]
User: [Info.UserName] |
716 |
DriveLock |
no |
Error |
Error adding local group |
An error occurred while adding a local group.
Group: [Info.GroupName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
717 |
DriveLock |
no |
Information |
Local group added |
A local group was successfully added.
Group: [Info.GroupName] |
718 |
DriveLock |
no |
Error |
Error removing local group |
An error occurred while removing a local group.
Group: [Info.GroupName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
719 |
DriveLock |
no |
Information |
Local group removed |
A local group was successfully removed.
Group: [Info.GroupName] |
720 |
DriveLock |
no |
Error |
Error adding local user |
An error occurred while adding a local user.
User: [Info.UserName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
721 |
DriveLock |
no |
Information |
Local user added |
A local user was successfully added.
User: [Info.UserName] |
722 |
DriveLock |
no |
Error |
Error removing local user |
An error occurred while removing a local user.
User: [Info.UserName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
723 |
DriveLock |
no |
Information |
Local user removed |
A local user was successfully removed.
User: [Info.UserName] |
724 |
DriveLock |
no |
Error |
Error changing local user information |
An error occurred while changing local user information.
User: [Info.UserName]
Step: [Info.StepName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
725 |
DriveLock |
no |
Error |
Error saving password protected user information |
An error occurred while saving password protected local user information.
User: [Info.UserName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
726 |
DriveLock |
no |
Error |
Error saving certificate protected user information |
An error occurred while saving certificate protected local user information.
User: [Info.UserName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
727 |
DriveLock |
no |
Information |
Local user name changed |
A local user name was changed.
Old user name: [Info.UserName]
New user name: [Info.NewValue] |
728 |
DriveLock |
no |
Information |
Local password changed |
A local password name was changed.
User name: [Info.UserName]
New password: [Info.NewValue] |
729 |
DriveLock |
no |
Information |
Windows Firewall enabled |
Windows Firewall was enabled for firewall profile [Info.FirewallProfile]. |
730 |
DriveLock |
no |
Information |
Windows Firewall disabled |
Windows Firewall was disabled for firewall profile [Info.FirewallProfile]. |
731 |
DriveLock |
no |
Information |
Firewall rule deleted |
A Windows Firewall rule was deleted.
Rule name: [Info.RuleName]
Rule ID: [Info.RuleGuid]
Direction: [Info.FirewallRuleDirection] |
732 |
DriveLock |
no |
Information |
Firewall rule (unmanaged) deleted |
An unmanaged Windows Firewall rule was deleted.
Rule name: [Info.RuleName]
Rule group: [Info.RuleGroup]
Direction: [Info.FirewallRuleDirection] |
733 |
DriveLock |
no |
Error |
Firewall rule could not be deleted |
A Windows Firewall rule could not be deleted.
Rule name: [Info.RuleName]
Rule ID: [Info.RuleGuid]
Direction: [Info.FirewallRuleDirection]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
734 |
DriveLock |
no |
Error |
Firewall rule (unmanaged) could not be deleted |
An unmanaged Windows Firewall rule could not be deleted.
Rule name: [Info.RuleName]
Rule group: [Info.RuleGroup]
Direction: [Info.FirewallRuleDirection]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
735 |
DriveLock |
no |
Information |
Firewall rule (managed) created |
A Windows Firewall rule managed by DriveLock was created.
Rule name: [Info.RuleName]
Rule ID: [Info.RuleGuid]
Direction: [Info.FirewallRuleDirection] |
736 |
DriveLock |
no |
Error |
Firewall rule (managed) could not be created |
A Windows Firewall rule managed by DriveLock could not be created.
Rule name: [Info.RuleName]
Rule ID: [Info.RuleGuid]
Direction: [Info.FirewallRuleDirection]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
737 |
DriveLock |
no |
Error |
Firewall rule could not be configured |
A Windows Firewall rule could not be configured.
Rule name: [Info.RuleName]
Rule ID: [Info.RuleGuid]
Property: [Info.StepName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
738 |
DriveLock |
no |
Warning |
Firewall group policy override active |
Changing or adding a firewall rule (or group) to the current profiles will not take effect because group policy overrides it on [Info.Details] current profiles. |
739 |
DriveLock |
no |
Error |
Error managing firewall settings |
An error occurred while managing Windows Firewall settings.
Action: [Info.StepName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
740 |
DriveLock |
no |
Warning |
Error reading firewall rules |
An error occurred while reading Windows Firewall rules.
Action: [Info.StepName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
741 |
DriveLock |
no |
Error |
Error configuring global firewall settings |
An error occurred while configuring global Windows Firewall settings.
Property: [Info.StepName]
Profile: [Info.FirewallProfile]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
742 |
DriveLock |
no |
Error |
Error configuring firewall logging |
An error occurred while configuring Windows Firewall logging.
NetSh command: [Info.StepName]
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
743 |
DriveLock |
no |
Error |
Error reading firewall logs |
An error occurred while reading Windows Firewall log data.
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
744 |
DriveLock |
no |
Error |
Failed to register as Windows Firewall application |
Failed to register DriveLock as a Windows Firewall application.
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
745 |
DriveLock |
no |
FailureAudit |
Incoming connection dropped |
An incoming connection was dropped.
Source IP: [Info.SrcIp]
Source Port: [Info.SrcPort]
Destination IP: [Info.DstIp]
Destination Port: [Info.DstPort]
Communication partner: [Info.PartnerName]
Protocol: [Info.Protocol] |
746 |
DriveLock |
no |
SuccessAudit |
Incoming connection allowed |
An incoming connection was allowed.
Source IP: [Info.SrcIp]
Source Port: [Info.SrcPort]
Destination IP: [Info.DstIp]
Destination Port: [Info.DstPort]
Communication partner: [Info.PartnerName]
Protocol: [Info.Protocol] |
747 |
DriveLock |
no |
FailureAudit |
Outgoing connection dropped |
An outgoing connection was dropped.
Source IP: [Info.SrcIp]
Source Port: [Info.SrcPort]
Destination IP: [Info.DstIp]
Destination Port: [Info.DstPort]
Communication partner: [Info.PartnerName]
Protocol: [Info.Protocol] |
748 |
DriveLock |
no |
SuccessAudit |
Outgoing connection allowed |
An outgoing connection was allowed.
Source IP: [Info.SrcIp]
Source Port: [Info.SrcPort]
Destination IP: [Info.DstIp]
Destination Port: [Info.DstPort]
Communication partner: [Info.PartnerName]
Protocol: [Info.Protocol] |
749 |
DriveLock |
no |
SuccessAudit |
Retrieved user password |
Password (and user name) for account [Info.UserName] were successfully retrieved. |
750 |
DriveLock |
no |
FailureAudit |
Failed to retrieve user password |
Password (and user name) for account [Info.UserName] could not be retrieved.
Error code: [Info.ErrorCode]
Error: [Info.ErrorMessage] |
751 |
DriveLock |
no |
FailureAudit |
Deeply nested archive blocked |
File blocked by content scanner. Deeply nested archives are not allowed.
File path: [File.Path]
File name: [File.FileName]
Drive: [File.DriveLetter]
File size: [File.Size]
File name hash: [File.MD5Hash]
File content hash: [FileContent.MD5Hash]
Access direction: [Info.AccessDirection]
Process: [Info.ProcessName]
Device ID: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber]) |
752 |
DriveLock |
no |
FailureAudit |
Deeply nested archive blocked |
File blocked by content scanner. Deeply nested archives are not allowed.
File path: [File.Path]
File name: [File.FileName]
Network resource: [NetDrive.NetDrivePath] ([NetDrive.NetDriveType])
File size: [File.Size]
File name hash: [File.MD5Hash]
File content hash: [FileContent.MD5Hash]
Access direction: [Info.AccessDirection]
Process: [Info.ProcessName] |
753 |
DriveLock |
no |
SuccessAudit |
Process stopped |
The process [AcProcess.ProcessName] was stopped. Process ID: [AcProcess.AcProcessID] |
754 |
DriveLock |
no |
Information |
User requests unlock of drive |
User requests unlock of drive [Info.DriveLetter].
The stated reason is: [Info.Reason]
Hardware ID: [Drive.HardwareID]
Device ID: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber])
Serial number: [Drive.HWSerialNumber]
Bus: [Drive.StorageBus]
Type: [Drive.StorageType]
Applied whitelist rule: [WhiteList.ObjectID] |
755 |
DriveLock |
no |
FailureAudit |
Bluetooth device connected and locked |
The device [Device.DisplayName] was connected to the computer. It was locked due to company policy.
Device type: [Device.DeviceType]
Hardware ID: [Device.HardwareID]
Class ID: [Device.ClassID]
Vendor ID: [Info.BthVendorID]
Product ID: [Info.BthProductID]
Major class: [Info.BthMajorClass]
Minor class: [Info.BthMinorClass]
Address: [Info.BthAddress]
Applied whitelist rule: [WhiteList.ObjectID]
Screen state (keyboard [Win]-[L]): [Info.SessionLockState] |
756 |
DriveLock |
no |
SuccessAudit |
Bluetooth device connected and not locked |
The device [Device.DisplayName] was connected to the computer.
Device type: [Device.DeviceType]
Hardware ID: [Device.HardwareID]
Class ID: [Device.ClassID]
Vendor ID: [Info.BthVendorID]
Product ID: [Info.BthProductID]
Major class: [Info.BthMajorClass]
Minor class: [Info.BthMinorClass]
Address: [Info.BthAddress]
Applied whitelist rule: [WhiteList.ObjectID]
Screen state (keyboard [Win]-[L]): [Info.SessionLockState] |
757 |
DriveLock |
no |
Error |
PBA activation failed due to Secure Boot issues |
SecureBoot is active but the Microsoft Corporation UEFI CA 2011 Certificate is missing. |
758 |
DriveLock |
no |
Information |
Removable media encrypted |
Removable drive [Info.DriveLetter] encrypted with BitLocker To Go.
Encryption algorithm: [Info.EncryptionAlgorithm]
Volume ID: [EncryptedVolume.VolumeID]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Hardware d: [Drive.HardwareID] |
759 |
DriveLock |
no |
Information |
Password changed |
The password for a BitLocker To Go encrypted media was changed.
Drive: [Info.DriveLetter]
Volume ID: [EncryptedVolume.VolumeID]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Hardware ID: [Drive.HardwareID] |
760 |
DriveLock |
no |
Warning |
Encrypted drive password recovered |
The password for a BitLocker To Go encrypted media was recovered.
Drive: [Info.DriveLetter]
Volume ID: [EncryptedVolume.VolumeID]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Hardware ID: [Drive.HardwareID] |
761 |
DriveLock |
no |
Information |
BitLocker To Go drive unlocked |
BitLocker To Go encrypted drive unlocked.
Drive: [Info.DriveLetter]
Volume ID: [EncryptedVolume.VolumeID]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Hardware ID: [Drive.HardwareID] |
762 |
DriveLock |
no |
Information |
Drive locked |
BitLocker To Go encrypted drive locked.
Drive: [Info.DriveLetter]
Volume ID: [EncryptedVolume.VolumeID]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Hardware ID: [Drive.HardwareID] |
763 |
DriveLock |
no |
Information |
BitLocker To Go recovery data uploaded |
BitLocker To Go recovery data was uploaded to the server.
Drive: [Info.DriveLetter]
Volume ID: [EncryptedVolume.VolumeID]
Device ID: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Hardware ID: [Drive.HardwareID] |
764 |
DriveLock |
no |
Error |
Encryption failed |
Encryption of the removable drive [Info.DriveLetter] with BitLocker To Go failed.
Encryption algorithm: [Info.EncryptionAlgorithm]
Volume ID: [EncryptedVolume.VolumeID]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Hardware ID: [Drive.HardwareID] |
765 |
DriveLock |
no |
Error |
Password change for a BitLocker To Go encrypted media failed |
The password change for a BitLocker To Go encrypted media failed.
Drive: [Info.DriveLetter]
Volume ID: [EncryptedVolume.VolumeID]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Hardware Id: [Drive.HardwareID] |
766 |
DriveLock |
no |
Error |
Recovery of a BitLocker To Go media failed |
Recovery of a BitLocker To Go encrypted media failed.
Drive: [Info.DriveLetter]
Volume ID: [EncryptedVolume.VolumeID]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Hardware Id: [Drive.HardwareID] |
767 |
DriveLock |
no |
Error |
Unlocking a BitLocker To Go volume failed |
Unlocking a BitLocker To Go volume failed.
Drive: [Info.DriveLetter]
Volume ID: [EncryptedVolume.VolumeID]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Hardware Id: [Drive.HardwareID] |
768 |
DriveLock |
no |
Error |
Locking a BitLocker To Go volume failed |
Locking a BitLocker To Go volume failed.
Drive: [Info.DriveLetter]
Volume ID: [EncryptedVolume.VolumeID]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Hardware Id: [Drive.HardwareID] |
769 |
DriveLock |
no |
Error |
Upload of BitLocker To Go recovery data failed |
Upload of BitLocker To Go recovery data failed.
Drive: [Info.DriveLetter]
Volume ID: [EncryptedVolume.VolumeID]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Hardware Id: [Drive.HardwareID] |
770 |
DriveLock |
no |
Warning |
Upload of BitLocker To Go recovery data is disabled by policy |
Upload of BitLocker To Go recovery data is disabled by policy.
Drive: [Info.DriveLetter]
Volume ID: [EncryptedVolume.VolumeID]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Hardware Id: [Drive.HardwareID]
Applied enforced encryption rule: [Info.ObjectID] |
771 |
DriveLock |
no |
Information |
BitLocker To Go recovery key was replaced |
BitLocker To Go recovery key [Info.OldValue] was replaced by [Info.NewValue].
Drive: [Info.DriveLetter]
Volume ID: [EncryptedVolume.VolumeID]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Hardware Id: [Drive.HardwareID] |
772 |
DriveLock |
no |
Error |
BitLocker To Go recovery key could not be replaced |
BitLocker To Go recovery key could not be replaced.
Drive: [Info.DriveLetter]
Volume ID: [EncryptedVolume.VolumeID]
Device Id: [Drive.HWVendorID] [Drive.HWProductID] (Rev. [Drive.HWRevisionNumber]) (Serial number [Drive.HWSerialNumber])
Hardware Id: [Drive.HardwareID] |
773 |
DriveLock |
no |
Information |
User requests unlock of device |
User requests unlock of device [Info.DisplayName].
The stated reason is: [Info.Reason]
Hardware ID: [Device.HardwareID]
Class ID: [Device.ClassID] |
774 |
DriveLock |
no |
Information |
User requests unlock of portable device |
User requests unlock of a portable device [Info.DisplayName].
The stated reason is: [Info.Reason]
Hardware ID: [Device.HardwareID]
Serialnumber: [Device.SerialNumber] |
775 |
DriveLock |
no |
FailureAudit |
Portable device connected and locked |
The portable device [Device.DisplayName] was connected to the computer. It was locked due to company policy.
Device type: [Device.DeviceType]
Hardware ID: [Device.HardwareID]
Serial Number: [Device.SerialNumber]
Class ID: [Device.ClassID]
Applied whitelist rule: [WhiteList.ObjectID]
Screen state (keyboard [Win]-[L]): [Info.SessionLockState] |
776 |
DriveLock |
no |
SuccessAudit |
Portable device connected and not blocked |
The portable device [Device.DisplayName] was connected to the computer.
Device type: [Device.DeviceType]
Hardware ID: [Device.HardwareID]
Serial Number: [Device.SerialNumber]
Class ID: [Device.ClassID]
Applied whitelist rule: [WhiteList.ObjectID]
Screen state (keyboard [Win]-[L]): [Info.SessionLockState] |
777 |
DriveLock |
no |
SuccessAudit |
Usage policy accepted |
User accepted usage policy for device [Device.DisplayName].
Hardware ID: [Device.HardwareID]
Serial Number: [Device.SerialNumber]
Class ID: [Device.ClassID] |
778 |
DriveLock |
no |
FailureAudit |
Usage policy declined |
User declined usage policy for device [Device.DisplayName].
Hardware ID: [Device.HardwareID]
Serial Number: [Device.SerialNumber]
Class ID: [Device.ClassID] |
779 |
DriveLock |
no |
Information |
User requests unlock of composite device |
User requests unlocking a composite device [Info.DisplayName] consisting of [Info.DeviceCount] devices.
The stated reason is: [Info.Reason] |
800 |
DCC |
no |
Information |
Control Center started |
The DriveLock Control Center has been started.
Connected to: [Info.DesName]. |
801 |
DCC |
no |
Information |
Control Center terminated |
The DriveLock Control Center has been terminated. |
802 |
DCC |
no |
Information |
DriveLock Enterprise Service changed |
The DriveLock Enterprise Service has been changed.
The DriveLock Control Center is now connected to: [Info.DesName]. |
803 |
DCC |
no |
Information |
Added user account |
For the user ([Info.AccountName]) an user account has been added. |
804 |
DCC |
no |
Information |
Removed user account |
The account for the user ([Info.AccountName]) has been removed. |
805 |
DCC |
no |
Information |
Changed permission |
The permissions from the user account ([Info.AccountName]) has been changed.
Tenants: [Info.Tenants]
Home:%t%t[Info.PermissionHome]
Helpdesk:%t%t[Info.PermissionHelpdesk]
Forensics:%t[Info.PermissionForensics]
Report:%t%t[Info.PermissionReport]
Inventory:%t[Info.PermissionInventory]
Configuration:%t[Info.PermissionConfiguration]
A = allow, N = not set, D = deny |
806 |
DCC |
no |
Information |
Start decrypting personal data |
Start decrypting personal data |
807 |
DCC |
no |
Information |
Stop decrypting personal data |
Stop decrypting personal data |
808 |
DCC |
no |
Information |
Open connection to remote desktop |
Open connection to remote desktop: [Info.DisplayName] |
809 |
DCC |
no |
Information |
Close connection to remote desktop |
Close connection to remote desktop: [Info.DisplayName] |
810 |
DCC |
no |
Information |
New initial BitLocker password |
Set new initial BitLocker password for client [Info.DisplayName] |
811 |
DCC |
no |
Information |
Sent agent action to change BitLocker password |
Sent agent action to change BitLocker password to client(s) [Info.DisplayName] |
900 |
DriveLock |
yes |
SuccessAudit |
DriveLock configuration element changed |
A DriveLock configuration element was changed.
Object type: [Gpo.ObjectType]
Object path: [Gpo.Path]
Object unique ID: [Gpo.ObjectID]
Configuration element: [Info.ConfigElement]
Data type: [Info.DataType]
New value: [Info.NewValue]
Old value: [Info.OldValue]
|
901 |
DriveLock |
yes |
SuccessAudit |
DriveLock configuration element added |
A DriveLock configuration element was added.
Object type: [Gpo.ObjectType]
Object path: [Gpo.Path]
Object unique ID: [Gpo.ObjectID]
Configuration element: [Info.ConfigElement]
Data type: [Info.DataType]
New value: [Info.NewValue]
|
902 |
DriveLock |
yes |
SuccessAudit |
DriveLock configuration element deleted |
A DriveLock configuration element was deleted.
Object type: [Gpo.ObjectType]
Object path: [Gpo.Path]
Object unique ID: [Gpo.ObjectID]
Configuration element: [Info.ConfigElement]
Data type: [Info.DataType]
|
910 |
DriveLock |
yes |
Information |
DriveLock Management Console started |
DriveLock Management Console was started.
Object type: [Gpo.ObjectType]
Object path: [Gpo.Path]
Object unique ID: [Gpo.ObjectID]
|
911 |
DriveLock |
yes |
Information |
DriveLock Management Console stopped |
DriveLock Management Console was stopped. |
912 |
DriveLock |
yes |
Information |
Device scanner executed |
Device scanner was executed.
Scanned computers: [Info.Computers]
|
920 |
DriveLock |
yes |
Information |
Remote agent connection established |
Remote agent connection established.
Agent computer: [Info.ComputerName] (unique ID [Info.ComputerGuid])
|
921 |
DriveLock |
yes |
Information |
Remote agent connection disconnected |
Remote agent connection disconnected.
Agent computer: [Info.ComputerName] (unique ID [Info.ComputerGuid])
|
922 |
DriveLock |
yes |
Information |
Remote agent action executed |
Remote agent action was executed.
Agent computer: [Info.ComputerName] (unique ID [Info.ComputerGuid])
Action: [Info.ActionName]
Result: [Info.ActionResult]
|
923 |
DriveLock |
yes |
Information |
Shadow files viewer connected remotely |
Shadowed files viewer was connected to network location.
Location: [Info.Computers]
|
924 |
DriveLock |
yes |
Information |
Offline unlock wizard failed |
The offline unlock wizard was executed and failed.
Request code: [Info.RequestCode]
Request computer name: [Info.AgentComputerName]
|
925 |
DriveLock |
yes |
Information |
Offline unlock succeeded |
The offline unlock wizard was executed and succeeded.
Request code: [Info.RequestCode]
Request computer name: [Info.AgentComputerName]
Unlocked drives: [Info.UnlockDrives]
Unlocked devices: [Info.UnlockDevices]
Unlock time: [Info.UnlockTime]
Unlock code: [Info.UnlockCode]
Reason: [Info.Reason]
|
926 |
DriveLock |
yes |
Information |
Disk Protection Emergency logon succeeded |
A Full Disc Encryption emergency logon was executed and succeeded.
Recovery code: [Info.RequestCode]
Recovery user name: [Info.UserName]
Recovery computer name: [Info.ComputerName]
Response code: [Info.UnlockCode] |
927 |
DriveLock |
yes |
Information |
Disk Protection Emergency logon succeeded |
A Full Disc Encryption emergency logon was executed and succeeded.
Recovery code: [Info.RequestCode]
Recovery user name: [Info.UserName]
Recovery data file: [Info.FileName]
Response code: [Info.UnlockCode] |
928 |
DriveLock |
yes |
Information |
Disk Protection Recovery Disk Key created |
A Full Disc Encryption recovery disk key was created.
Recovery computer name: [Info.ComputerName] (unique ID [Info.ComputerGuid])
Disk key file: [Info.UnlockCode] |
929 |
DriveLock |
yes |
Information |
Disk Protection Recovery Disk Key created |
A Full Disc Encryption recovery disk key was created.
Recovery data file: [Info.FileName]
Disk key file: [Info.UnlockCode] |
930 |
DriveLock |
yes |
Information |
DriveLock Enterprise Service selected |
The DriveLock Enterprise Service [Info.DesName] was selected by DriveLock MMC.
Connection ID: [Info.ObjectID] |
931 |
DriveLock |
yes |
Warning |
DriveLock Enterprise Service not available |
No DriveLock Enterprise Service is available because no valid server connection is configured. |
932 |
DriveLock |
yes |
Error |
Disk Protection Recovery failed |
A Full Disc Encryption recovery process failed.
Recovery computer name: [Info.ComputerName] (unique ID [Info.ComputerGuid])
Error: [Info.ErrorMessage] |
933 |
DriveLock |
yes |
Error |
Disk Protection Recovery failed |
A Full Disc Encryption recovery process failed.
Recovery data file: [Info.FileName]
Error: [Info.ErrorMessage] |
934 |
DriveLock |
yes |
Information |
Disk Protection installation package uploaded |
A Full Disc Encryption installation package was uploaded to the server.
Package version: [Info.FileName]
Server: [Info.ServerName] |
935 |
DriveLock |
yes |
Information |
Disk Protection installation package upload failed |
A Full Disc Encryption installation package upload failed.
Package version: [Info.FileName]
Server: [Info.ServerName]
Error: [Info.ErrorMessage] |
936 |
DriveLock |
yes |
Information |
BitLocker Management Emergency logon succeeded |
A BitLocker Management emergency logon was executed and succeeded.
Recovery code: [Info.RequestCode]
Recovery user name: [Info.UserName]
Recovery computer name: [Info.ComputerName]
Response code: [Info.UnlockCode] |
937 |
DriveLock |
yes |
Information |
BitLocker Management Emergency logon succeeded |
A BitLocker Management emergency logon was executed and succeeded.
Recovery code: [Info.RequestCode]
Recovery user name: [Info.UserName]
Recovery data file: [Info.FileName]
Response code: [Info.UnlockCode] |
2000 |
DES |
yes |
Error |
Push installation failed |
The push installation of the agent failed on computer [Info.ComputerName].
Error message: ([Info.PiErrorCode]) [Info.PiErrorMessage]
Installation step: [Info.PiErrorStep]
Attempt number: #[Info.PiAttempts] |
2001 |
DES |
yes |
Information |
Push installation successful |
The push installation of the agent on computer [Info.ComputerName] was successful. |
2002 |
DES |
no |
Error |
AV pattern download failed |
The download of AV pattern file [Info.FileName] from the DriveLock cloud has failed. Error message: [Info.ErrorMessage]. |
2003 |
DES |
no |
Information |
AV pattern download successful |
The download of AV pattern file [Info.FileName] from the DriveLock cloud was successful. |
2004 |
DES |
no |
Error |
File download failed |
The download of file [Info.FileName] from the DriveLock cloud has failed. Error message: [Info.ErrorMessage]. |
2005 |
DES |
no |
Information |
File download successful |
The download of file [Info.FileName] from the DriveLock cloud was successful. |
2006 |
DES |
no |
Information |
Disk Protection recovery data saved |
The Disk Protection Recovery Data ( [Info.FdeRecoveryDataType] ) from Computer [Info.ComputerName] has been saved. |
2007 |
DES |
no |
Information |
Encryption 2-Go recovery data saved |
The recovery data for encrypted volume ( path: '[EncryptedVolume.FilePath][EncryptedVolume.FileName]' , VolumeID: [EncryptedVolume.VolumeID]) has been saved. |
2008 |
DES |
no |
Information |
DFP recovery data saved |
The recovery data for encrypted folder ( path: '[DfpEncryptedFolder.UncPath]' , VolumeID: [DfpEncryptedFolder.DfpVolumeID]) has been saved. |
2009 |
DES |
no |
Information |
DB maintenance successful |
The database maintenance for '[Info.DisplayName]' finished successfully. |
2010 |
DES |
no |
Error |
DB maintenance aborted |
The database maintenance for '[Info.DisplayName]' aborted with an error: '[Info.ErrorMessage]'. |
2011 |
DES |
no |
Information |
DB eventgrooming successful |
The database event grooming for '[Info.DisplayName]' finished successfully. Deleted event count: [Info.EventCount] |
2012 |
DES |
no |
Error |
DB event grooming aborted |
The database event grooming for '[Info.DisplayName]' aborted with an error: '[Info.ErrorMessage]'. |
2013 |
DES |
no |
Information |
DB backup successful |
The database backup for '[Info.DisplayName]' finished successfully. |
2014 |
DES |
no |
Error |
DB backup aborted |
The database backup for '[Info.DisplayName]' aborted with an error: '[Info.ErrorMessage]'. |
2015 |
DES |
no |
Information |
DB shrinked successful |
The database '[Info.DisplayName]' was shrinked successfully. |
2016 |
DES |
no |
Error |
Error shrinking database |
Error on shrinking database '[Info.DisplayName]': '[Info.ErrorMessage]'. |
2017 |
DES |
no |
Error |
AV pattern sync failed |
The download of AV pattern file [Info.FileName] from the central DES has failed. Error message: [Info.ErrorMessage]. |
2018 |
DES |
no |
Information |
AV pattern sync successful |
The download of AV pattern file [Info.FileName] from the central DES was successful. |
2019 |
DES |
no |
Error |
File download failed |
The download of file [Info.FileName] from the central DES has failed. Error message: [Info.ErrorMessage]. |
2020 |
DES |
no |
Information |
File download successful |
The download of file [Info.FileName] from the central DES was successful. |
2021 |
DES |
no |
Information |
The DES was started |
The DES was started. |
2022 |
DES |
no |
Information |
CSP active |
The centrally stored policy [Info.CspName], version [Info.CspVersion], ID: [Info.CspID] is now available on the DES. |
2023 |
DES |
no |
Information |
CSP inactive |
The centrally stored policy [Info.CspName], version [Info.CspVersion], ID: [Info.CspID] is not available on the DES. |
2024 |
DES |
yes |
Information |
Policy deleted |
The centrally stored policy [Info.CspName], ID: [Info.CspID] was deleted. |
2025 |
DES |
yes |
Information |
Policy assignment activated |
The policy assignment (centrally stored policy) was activated. Target: [Info.CspAssignmentName], order: [Info.CspAssignmentOrder], policy: [Info.CspName] (ID: [Info.CspID]). |
2026 |
DES |
yes |
Information |
Policy assignment deleted |
The assignment of policy [Info.CspAssignmentName] was deleted. |
2027 |
DES |
yes |
SuccessAudit |
Group created |
The [Info.GroupMemberType] group [Info.GroupName] (identifier: [Info.GroupIdentifier]) was created. |
2028 |
DES |
yes |
SuccessAudit |
Group deleted |
The [Info.GroupMemberType] group [Info.GroupName] (identifier: [Info.GroupIdentifier]) was deleted. |
2029 |
DES |
yes |
SuccessAudit |
Group member added |
The group member [Info.GroupMemberName] (identifier: [Info.GroupMemberIdentifier]) was added to the [Info.GroupMemberType] group: [Info.GroupName] (identifier: [Info.GroupIdentifier]). Type: [Info.GroupChildType] |
2030 |
DES |
yes |
SuccessAudit |
Group member removed |
The group member [Info.GroupMemberName] (identifier: [Info.GroupMemberIdentifier]) was removed from the [Info.GroupMemberType] group: [Info.GroupName] (identifier: [Info.GroupIdentifier]). Type: [Info.GroupChildType] |
2031 |
DES |
yes |
SuccessAudit |
Group member updated |
The group member [Info.GroupMemberName] (identifier: [Info.GroupMemberIdentifier]) was updated in the [Info.GroupMemberType] group: [Info.GroupName] (identifier: [Info.GroupIdentifier]). Exclude status is: [Info.GroupMemberExclude]. |
2032 |
DES |
yes |
SuccessAudit |
Group updated |
The group with identifier [Info.GroupIdentifier] was updated. Name: [Info.GroupName], Description: [Info.GroupDescription] |
2033 |
DES |
yes |
SuccessAudit |
Dynamic group created |
The dynamic group [Info.GroupName] (identifier: [Info.GroupIdentifier]), type: [Info.GroupMemberType] was created. |
2034 |
DES |
yes |
SuccessAudit |
Dynamic group deleted |
The dynamic group [Info.GroupName] (identifier: [Info.GroupIdentifier]), type: [Info.GroupMemberType] was deleted. |
2035 |
DES |
yes |
SuccessAudit |
Dynamic group updated |
The dynamic group with identifier [Info.GroupIdentifier] was updated. Name: [Info.GroupName], Description: [Info.GroupDescription] |
2036 |
DES |
yes |
SuccessAudit |
Dynamic group changed |
The dynamic group [Info.GroupName] (identifier: [Info.GroupIdentifier]) was changed.
group definition (old): [Info.GroupDynDefinitionOld]
group definition (new): [Info.GroupDynDefinitionNew] |
2037 |
DES |
yes |
Information |
Policy assignment deactivated |
The policy assignment (centrally stored policy) was deactivated. Target: [Info.CspAssignmentName], order: [Info.CspAssignmentOrder], Policy: [Info.CspName] (ID: [Info.CspID]). |
2038 |
DES |
no |
Information |
Audit event cleanup successful |
Audit event cleanup for database '[Info.DisplayName]' finished successfully. Deleted audit event count: [Info.EventCount] |
2039 |
DES |
no |
Error |
Audit event cleanup aborted |
Audit event cleanup for database '[Info.DisplayName]' aborted with an error: '[Info.ErrorMessage]'. |
2040 |
DES |
yes |
Information |
Policy assignment created |
The policy assignment (centrally stored policy) was created. Target: [Info.CspAssignmentName], order: [Info.CspAssignmentOrder], Policy: [Info.CspName] (ID: [Info.CspID]). |
2041 |
DES |
yes |
Information |
Policy assignment changed |
The policy assignment (centrally stored policy) was changed. Target: [Info.CspAssignmentName], order: [Info.CspAssignmentOrder], Policy: [Info.CspName] (ID: [Info.CspID]). |
2100 |
DOC |
yes |
SuccessAudit |
Account created |
The account [Info.AccountDisplayName] (identifier: [Info.AccountIdentifier]) was created |
2101 |
DOC |
yes |
SuccessAudit |
Account deleted |
The account [Info.AccountDisplayName] (identifier: [Info.AccountIdentifier]) was deleted |
2102 |
DOC |
yes |
SuccessAudit |
Role assignment created |
The role [Info.RoleDisplayName] (id: [Info.RoleID]) was assigned to the account [Info.AccountDisplayName] (identifier: [Info.AccountIdentifier]). OU Restrictions: ([Info.OuRestriction]), Group [Info.GroupName] (identifier: [Info.GroupIdentifier]) |
2103 |
DOC |
yes |
SuccessAudit |
Role assignment deleted |
The role assignment [Info.RoleDisplayName] (id: [Info.RoleID]) was removed from the account [Info.AccountDisplayName] (identifier: [Info.AccountIdentifier]) |
2104 |
DOC |
yes |
SuccessAudit |
Account email changed |
The email of account '[Info.AccountDisplayName]' was changed from [Info.AccountIdentifier] to [Info.AccountIdentifier2]' |
2105 |
DES |
no |
SuccessAudit |
Agent successfully registered |
An agent successfully registered |
2106 |
DES |
no |
FailureAudit |
Attempt to register with invalid join token |
The agent tried to register with the invalid join token '[Info.JoinToken]' |
2107 |
DES |
no |
FailureAudit |
Rejected attempt to change agent ID |
The agent tried to update its agent ID to the new value '[Info.IdToken]'. This is not permitted. Please reset the agent registration via DOC if this change is intended |
2108 |
DES |
no |
FailureAudit |
Rejected agent access because of not existing agent ID |
Rejected access to DES for agent. The agent sent the not existing agent ID '[Info.IdToken]' |
2109 |
DES |
no |
FailureAudit |
Rejected agent access because of improper agent ID |
Rejected access to DES for agent. The agent sent the agent ID '[Info.IdToken]' which does not belong to it. The conflicting data (name/ID) is: [Info.AgentRejectedReason] |
2110 |
DES |
yes |
Information |
Uploaded trace files to DriveLock support |
Uploaded trace files from agent to DriveLock support for further analysis |
2111 |
DES |
yes |
Information |
Default data masking enabled |
Default data masking is enabled. All relevant user data is masked according to the settings. |
2112 |
DES |
yes |
Information |
Default data masking disabled |
Default data masking is disabled. The relevant user data is shown in the original text. |
2113 |
DES |
yes |
Information |
Data masking configuration changed |
Data masking configuration has been changed |
2114 |
DES |
yes |
Information |
Request for unmasking data generated |
Request for unmasking data of '[Info.PiiObjectType]' for [Info.Duration] minutes has been generated. Reason for unmasking: [Info.Reason] |
2115 |
DES |
yes |
SuccessAudit |
Request for unmasking data accepted |
Request from '[Info.UserName]' for unmasking data of '[Info.PiiObjectType]' for [Info.Duration] minutes has been accepted. Reason for unmasking: [Info.Reason] |
2116 |
DES |
yes |
FailureAudit |
Request for unmasking data denied |
Request from '[Info.UserName]' for unmasking data of '[Info.PiiObjectType]' for [Info.Duration] minutes has been denied. Reason for unmasking: [Info.Reason] |
2117 |
DES |
yes |
SuccessAudit |
Started showing unmasked data |
Unmasking data has started. |
2118 |
DES |
yes |
SuccessAudit |
Stopped showing unmasked data |
Showing unmasked data has ended |
2119 |
DES |
yes |
SuccessAudit |
Custom data masking settings changed |
Custom data masking settings have been changed |
2120 |
DES |
yes |
SuccessAudit |
Custom data masking settings reset |
Custom data masking settings have been reset |
2121 |
DES |
yes |
SuccessAudit |
Started showing masked data |
Masking data has started |
2122 |
DES |
yes |
SuccessAudit |
Stopped showing masked data |
Showing masked data has ended |
2123 |
DES |
yes |
FailureAudit |
Request for unmasking with wrong or invalid code |
Request for unmasking data of '[Info.PiiObjectType]' for [Info.Duration] minutes with wrong or invalid code. Reason for unmasking: [Info.Reason] |
2150 |
DES |
yes |
Information |
Tenant created |
A tenant was created |
2151 |
DES |
yes |
Information |
Tenant attached |
A tenant was attached |
2152 |
DES |
yes |
Information |
Tenant detached |
A tenant was detached |
2153 |
DES |
yes |
Information |
Global tenant configuration modified |
The global configuration of the tenant has been modified |
2160 |
DES |
yes |
Information |
Certificate was created |
Certificate '[Info.FileName]' was created |
2161 |
DES |
yes |
Information |
Certificate was deleted |
Certificate '[Info.FileName]' was deleted |
2162 |
DES |
yes |
Information |
Certificate was changed |
Certificate '[Info.FileName]' was changed |
2170 |
DES |
yes |
Information |
API key added |
Added an API key '[Info.DisplayName]' holding the permissions '[Info.Details]' which is valid until [Info.TimeStamp] |
2171 |
DES |
yes |
Information |
API key added (no expiration) |
Added an API key '[Info.DisplayName]' holding the permissions '[Info.Details]'. The key does not expire. |
2172 |
DES |
yes |
Information |
Deleted API key |
Deleted the API key '[Info.DisplayName]'. |
2173 |
DES |
yes |
Information |
Modified API key |
Modified API key '[Info.DisplayName]'. New permissions are: [Info.Details] |
2180 |
DES |
yes |
Information |
Microsoft Entra ID Sync Configuration was added |
Microsoft Entra ID Sync Configuration for Entra tenant ID '[Info.DisplayName]' was added |
2181 |
DES |
yes |
Information |
Microsoft Entra ID Sync Configuration was deleted |
Microsoft Entra ID Sync Configuration for Entra tenant ID '[Info.DisplayName]' was deleted |
2182 |
DES |
yes |
Information |
Microsoft Entra ID Sync was triggered |
Microsoft Entra ID Sync for Entra tenant ID '[Info.DisplayName]' was triggered |
2183 |
DES |
yes |
Information |
Microsoft Entra ID Sync Config updated |
Microsoft Entra ID Sync config for Entra tenant ID '[Info.DisplayName]' was updated |
2200 |
DES |
yes |
Information |
Windows authentication enabled |
Logon via Windows authentication enabled. |
2201 |
DES |
yes |
Information |
Windows authentication disabled |
Logon via Windows authentication disabled |
2210 |
DES |
yes |
Information |
SAML authentication configuration created |
SAML authentication configuration '[Info.DisplayName]' created. |
2211 |
DES |
yes |
Information |
SAML authentication configuration deleted |
SAML authentication configuration '[Info.DisplayName]' deleted |
2212 |
DES |
yes |
Information |
SAML authentication configuration modified |
SAML authentication configuration '[Info.DisplayName]' modified. Changes: [Info.Details]. |
2213 |
DES |
yes |
Information |
SAML authentication configuration enabled |
SAML authentication configuration '[Info.DisplayName]' enabled. |
2214 |
DES |
yes |
Information |
SAML authentication configuration disabled |
SAML authentication configuration '[Info.DisplayName]' disabled. |
2215 |
DES |
yes |
Information |
Mandatory SSO login enabled |
Mandatory login via single sign on (SSO) enabled. The following users may bypass this setting: [Info.Details] |
2216 |
DES |
yes |
Information |
Mandatory SSO login disabled |
Mandatory login via single sign on (SSO) disabled. |
2217 |
DES |
yes |
Information |
SSO user exclude list changed |
The list of users which may login bypassing single sign on (SSO) has changed: [Info.Details]. |
2220 |
DES |
yes |
Information |
Role created |
Role created: [Info.RoleDisplayName] |
2221 |
DES |
yes |
Information |
Role deleted |
Role deleted: [Info.RoleDisplayName] |
2222 |
DES |
yes |
Information |
Role modified |
Role modified: [Info.RoleDisplayName] |
2223 |
DES |
yes |
Information |
Role permission modified |
Role permission modified: [Info.RoleDisplayName] |
2230 |
DES |
yes |
Information |
Dashboard widget template added |
A dashboard widget template was added |
2231 |
DES |
yes |
Information |
Dashboard widget template deleted |
A dashboard widget template was deleted |
2232 |
DES |
yes |
Information |
Dashboard widget template modified |
A dashboard widget template was modified |
2240 |
DES |
yes |
Information |
Computer deleted |
Computer [Info.Computers] deleted with options: DeleteComputerEvents: [Info.DeleteComputerEvents], DeleteComputerGroupDefinitions: [Info.DeleteComputerGroupDefinitions], DeleteComputerRecoveryData: [Info.DeleteComputerRecoveryData] |
2241 |
DES |
yes |
Information |
Agent action added |
Added agent action [Info.Type] for computer [Info.ComputerName] |
2242 |
DES |
yes |
Information |
Agent action updated |
Updated agent action [Info.Type] for computer [Info.ComputerName] |
2243 |
DES |
yes |
Information |
Agent action deleted |
Deleted agent action [Info.Type] for computer [Info.ComputerName] |
2244 |
DES |
yes |
Information |
Resetted agent ID token |
Resetted agent ID token computer [Info.ComputerName] |
2245 |
DES |
yes |
Information |
Prepared computer for reinstallation |
Prepared computer [Info.ComputerName] for reinstallation. The agent ID may now be changed once |
2246 |
DES |
yes |
Information |
Saved agent identity security settings |
Saved agent identity security settings. Details: [Info.Details] |
2247 |
DES |
yes |
Information |
Tenant join token refreshed |
The tenant join token has been refreshed. The previous token is no longer valid |
2248 |
DES |
no |
Information |
Computer automatically deleted |
Computer ([Info.Count]) automatically deleted with options: delete from group definitions: [Info.DeleteComputerGroupDefinitions] |
2290 |
DES |
yes |
Information |
Alert state changed |
Alert '[Info.DisplayName]' (identifier: [Info.ObjectID]) state was changed from [Info.IntValue] to [Info.IntValue2] |
2330 |
DES |
yes |
Information |
Threat was suppressed in general |
Threat '[Info.DisplayName]' was suppressed for all computers |
2331 |
DES |
yes |
Information |
Threat is no longer suppressed in general |
Threat '[Info.DisplayName]' is no longer suppressed for all computers |
2332 |
DES |
yes |
Information |
Threat was suppressed for a computer |
Threat '[Info.DisplayName]' was suppressed for a computer |
2333 |
DES |
yes |
Information |
Threat is no longer suppressed for a computer |
Threat '[Info.DisplayName]' is no longer suppressed for a computer. |
2320 |
DES |
yes |
Information |
Vulnerability was suppressed in general |
Vulnerability '[Info.DisplayName]' was suppressed for all computers |
2321 |
DES |
yes |
Information |
Vulnerability is no longer suppressed in general |
Vulnerability '[Info.DisplayName]' is no longer suppressed for all computers. |
2322 |
DES |
yes |
Information |
Vulnerability was suppressed for a computer |
Vulnerability '[Info.DisplayName]' was suppressed for a computer |
2323 |
DES |
yes |
Information |
Vulnerability is no longer suppressed for a computer |
Vulnerability '[Info.DisplayName]' is no longer suppressed for a computer |
2340 |
DES |
yes |
Information |
File Protecion recovery executed |
File Protecion recovery was executed |
2341 |
DES |
yes |
Information |
Encryption 2-Go recovery executed |
Encryption 2-Go recovery was executed |
2342 |
DES |
yes |
Information |
BitLocker To Go recovery executed |
BitLocker To Go recovery was executed |
2343 |
DES |
yes |
Information |
BitLocker recovery executed |
BitLocker recovery was executed |
2344 |
DES |
yes |
Information |
Local user account recovery executed |
Local user account recovery was executed |
2349 |
DES |
yes |
Information |
User added to centrally managed folder |
User '[Info.UserName]' was added to the centrally managed folder '[Info.DisplayName]' |
2350 |
DES |
yes |
Information |
User removed from centrally managed folder |
User '[Info.UserName]' was removed from the centrally managed folder '[Info.DisplayName]' |
2351 |
DES |
yes |
Information |
Permission for centrally managed folder changed |
Changed permssions for user '[Info.UserName]' on centrally managed folder '[Info.DisplayName]':
Administrative permissions: [Info.BoolValue],
Write permissions: [Info.BoolValue2] |
2380 |
DES |
yes |
Information |
Report created |
Report created: [Info.DisplayName] |
2381 |
DES |
yes |
Information |
Report deleted |
Report deleted: [Info.DisplayName] |
2382 |
DES |
yes |
Information |
Report modified |
Report modified: [Info.DisplayName] |
2400 |
DES |
yes |
Information |
Drive rule created |
Drive rule [Info.RuleName] was created in policy [Info.CspName], version [Info.CspVersion] |
2401 |
DES |
yes |
Information |
Drive rule deleted |
Drive rule [Info.RuleName] was deleted in policy [Info.CspName], version [Info.CspVersion] |
2402 |
DES |
yes |
Information |
Drive rule changed |
Drive rule [Info.RuleName] was changed in policy [Info.CspName], version [Info.CspVersion] |
2403 |
DES |
yes |
Information |
Application rule created |
Application rule [Info.RuleName] was created in policy [Info.CspName], version [Info.CspVersion] |
2404 |
DES |
yes |
Information |
Application rule deleted |
Application rule [Info.RuleName] was deleted in policy [Info.CspName], version [Info.CspVersion] |
2405 |
DES |
yes |
Information |
Application rule changed |
Application rule [Info.RuleName] was changed in policy [Info.CspName], version [Info.CspVersion] |
2406 |
DES |
yes |
Information |
Security awareness rule created |
Security awareness rule [Info.RuleName] was created in policy [Info.CspName], version [Info.CspVersion] |
2407 |
DES |
yes |
Information |
Security awareness rule deleted |
Security awareness rule [Info.RuleName] was deleted in policy [Info.CspName], version [Info.CspVersion] |
2408 |
DES |
yes |
Information |
Security awareness rule changed |
Security awareness rule [Info.RuleName] was changed in policy [Info.CspName], version [Info.CspVersion] |
2409 |
DES |
yes |
Information |
Drive added to rule |
A drive was added to rule [Info.RuleName] in policy [Info.CspName], version [Info.CspVersion].
Device Id: [Drive.HWVendorID] [Drive.HWProductID]
Serial number [Drive.HWSerialNumber]
Hardware Id: [Drive.HardwareID] |
2410 |
DES |
yes |
Information |
Drive removed from rule |
A drive was removed from rule [Info.RuleName] in policy [Info.CspName], version [Info.CspVersion].
Device Id: [Drive.HWVendorID] [Drive.HWProductID]
Serial number [Drive.HWSerialNumber]
Hardware Id: [Drive.HardwareID] |
2411 |
DES |
yes |
Information |
Device rule created |
Device rule [Info.RuleName] was created in policy [Info.CspName], version [Info.CspVersion] |
2412 |
DES |
yes |
Information |
Device rule deleted |
Device rule [Info.RuleName] was deleted in policy [Info.CspName], version [Info.CspVersion] |
2413 |
DES |
yes |
Information |
Device rule changed |
Device rule [Info.RuleName] was changed in policy [Info.CspName], version [Info.CspVersion] |
2414 |
DES |
yes |
Information |
Device added to rule |
A device was added to rule [Info.RuleName] in policy [Info.CspName], version [Info.CspVersion].
Hardware ID: [Device.HardwareID]
Class ID: [Device.ClassID]
Serial number: [Device.SerialNumber] |
2415 |
DES |
yes |
Information |
Device removed from rule |
A device was removed from rule [Info.RuleName] in policy [Info.CspName], version [Info.CspVersion].
Hardware ID: [Device.HardwareID]
Class ID: [Device.ClassID]
Serial number: [Device.SerialNumber] |
2416 |
DES |
yes |
Information |
Application behavior rule created |
Application behavior rule [Info.RuleName] was created in policy [Info.CspName], version [Info.CspVersion] |
2417 |
DES |
yes |
Information |
Application behavior rule deleted |
Application behavior rule [Info.RuleName] was deleted in policy [Info.CspName], version [Info.CspVersion] |
2418 |
DES |
yes |
Information |
Application behavior rule changed |
Application behavior rule [Info.RuleName] was changed in policy [Info.CspName], version [Info.CspVersion] |
2500 |
DES |
yes |
Information |
Policy created |
Policy created: [Info.CspName], ID: [Info.ConfigId] |
2501 |
DES |
yes |
Information |
Policy saved |
Policy saved: [Info.CspName] (ID: [Info.ConfigId]) |
2502 |
DES |
yes |
Information |
Policy published |
Policy published: [Info.CspName], version: [Info.CspVersion] (ID: [Info.ConfigId]), publish comment: [Info.CspPublishComment] |
2503 |
DES |
yes |
Information |
Policy unpublished |
Policy unpublished: [Info.CspName], version: [Info.CspVersion] (ID: [Info.ConfigId]) |
2504 |
DES |
yes |
Information |
Policy history deleted |
Policy history deleted: [Info.CspName], version: [Info.CspVersion] (ID: [Info.ConfigId]), deleted previous versions: [Info.BoolValue] |
2513 |
DES |
yes |
Information |
Policy assignment rearranged |
Policy assignment rearranged: [Info.CspAssignmentName] |
2540 |
DES |
yes |
Information |
Policy collection created |
The [Info.GroupMemberType] policy collection [Info.GroupName] (identifier: [Info.GroupIdentifier]) was created. |
2541 |
DES |
yes |
Information |
Policy collection deleted |
The [Info.GroupMemberType] policy collection [Info.GroupName] (identifier: [Info.GroupIdentifier]) was deleted. |
2542 |
DES |
yes |
Information |
Policy collection updated |
The policy collection with identifier [Info.GroupIdentifier] was updated. Name: [Info.GroupName], Description: [Info.GroupDescription] |
2543 |
DES |
yes |
Information |
Added policy to policy collection |
The policy [Info.GroupMemberName] (identifier: [Info.GroupMemberIdentifier]) was added to the [Info.GroupMemberType] policy collection: [Info.GroupName] (identifier: [Info.GroupIdentifier]). Type: [Info.GroupChildType] |
2544 |
DES |
yes |
Information |
Removed policy from policy collection |
The policy [Info.GroupMemberName] (identifier: [Info.GroupMemberIdentifier]) was removed from the [Info.GroupMemberType] policy collection: [Info.GroupName] (identifier: [Info.GroupIdentifier]). Type: [Info.GroupChildType] |
2545 |
DES |
yes |
Information |
Policy collection member updated |
The policy collection member [Info.GroupMemberName] (identifier: [Info.GroupMemberIdentifier]) was updated in the [Info.GroupMemberType] policy collection: [Info.GroupName] (identifier: [Info.GroupIdentifier]). Exclude status is: [Info.GroupMemberExclude]. |
2550 |
DES |
yes |
Information |
Enabled network PBA interface |
Enabled the network PBA interface on DES '[Info.DesName]'. |
2551 |
DES |
yes |
Information |
Disabled network PBA interface |
Disabled the network PBA interface on DES '[Info.DesName]'. |
2680 |
DES |
yes |
Information |
Successful login at DOC |
A user successfully logged in to the DriveLock Operations Center (DOC) using the authentication method '[Info.LogonMethod]'. |
2681 |
DES |
yes |
Error |
Failed login at DOC |
A user failed to login to the DriveLock Operations Center (DOC) using the authentication method '[Info.LogonMethod]'. Reason: [Info.LogonError]. |
2702 |
DES |
yes |
Information |
Account modified |
The account [Info.AccountDisplayName] (identifier: [Info.AccountIdentifier]) has been modified |
2710 |
DES |
yes |
Information |
Computer selected for AD inventory |
The computer was selected by the server to collect AD inventory data. |
2720 |
DES |
yes |
Information |
MFA method added |
The MFA method '[Info.DisplayName]' has been added |
2721 |
DES |
yes |
Information |
MFA method deleted |
The MFA method '[Info.DisplayName]' has been deleted |
2722 |
DES |
yes |
Information |
MFA method disabled |
The MFA method '[Info.DisplayName]' has been disabled |
2723 |
DES |
yes |
Information |
MFA logon requirements changed |
The logon methods that require MFA have been changed to: '[Info.Details]' |
2724 |
DES |
yes |
Information |
Admin diabled MFA |
MFA has been disabled for user '[Info.UserName]' |
2725 |
DES |
yes |
Warning |
MFA code rejected |
The MFA code has not been accepted |
2730 |
DES |
yes |
Information |
License added |
The license was added: [Info.LicInfo] ([Info.LicGuid]) It expires on: [Info.LicExpiryDate] |
2731 |
DES |
yes |
Information |
License deleted |
The license was deleted: [Info.LicInfo] ([Info.LicGuid]) |