TIBCO LogLogic Alerts for HIPAA
The LogLogic® Compliance Suite - HIPAA Edition allows for the continuous monitoring of the IT infrastructure using behavioral-based alerts.
Serial Number | TIBCO LogLogic Alert | Description |
---|---|---|
1 | HIPAA: Accounts Created | Alerts when a new account is created on servers. |
2 | HIPAA: Accounts Deleted | Alerts when an account is deleted on servers. |
3 | HIPAA: Accounts Enabled | Alerts when an account has been enabled on servers. |
4 | HIPAA: Accounts Locked | Alerts when an account has been locked on servers. |
5 | HIPAA: Accounts Modified | Alerts when an account is modified on servers. |
6 | HIPAA: Active Directory Changes | Alerts when changes are made within Active Directory. |
7 | HIPAA: Anomalous Firewall Traffic | Alerts when firewall traffic patterns are out of the norm. |
8 | HIPAA: Anomalous IDS Alerts | Alerts when IDS anomalies are above or below defined thresholds. |
9 | HIPAA: Anomalous Total Log Traffic | Alerts when log traffic volume is out of the norm compared to the baseline. |
10 | HIPAA: Check Point Policy Changed | Alerts when a Check Point firewall's policy has been modified. |
11 | HIPAA: Cisco ISE, ACS Configuration Changed | Alerts when configuration changes are made to the Cisco ISE or Cisco SecureACS. |
12 | HIPAA: Cisco ISE, ACS Passwords Changed | Alerts when a user changes their password via Cisco ISE or Cisco SecureACS. |
13 | HIPAA: Cisco PIX, ASA, FWSM Commands Executed | Alerts when a Cisco PIX, ASA, or FWSM commands are executed. |
14 | HIPAA: Cisco PIX, ASA, FWSM Failover Disabled | Alerts when a Cisco PIX, ASA, or FWSM HA configuration is disabled. |
15 | HIPAA: Cisco PIX, ASA, FWSM Failover Performed | Alerts when a failover has occurred on the Cisco PIX, ASA, or FWSM devices. |
16 | HIPAA: Cisco PIX, ASA, FWSM Policy Changed | Alerts when a Cisco PIX, ASA, or FWSM firewall policy has been modified. |
17 | HIPAA: System Restarted | Alerts when system has been restarted. |
18 | HIPAA: Cisco PIX, ASA, FWSM Routing Failure | Alerts when routing failure occurred in the Cisco PIX, ASA, or FWSM devices. |
19 | HIPAA: Cisco Switch Policy Changed | Alerts when Cisco router or switch configuration has been modified. |
20 | HIPAA: DB2 Database Configuration Change | Alerts when a configuration is changed on a DB2 database. |
21 | HIPAA: DB2 Database User Added or Dropped | Alerts when a user is added or dropped from a DB2 database. |
22 | HIPAA: DNS Server Shutdown | Alerts when DNS Server has been shutdown. |
23 | HIPAA: DNS Server Started | Alerts when DNS Server has been started. |
24 | HIPAA: Escalated Privileges | Alerts when a user or program has escalated the privileges. |
25 | HIPAA: F5 BIG-IP TMOS Risky Traffic | F5 BIG-IP TMOS traffic considered risky. |
26 | HIPAA: Firewall Traffic Considered Risky | Alerts on non HTTP, SSL, or SSH traffic passing through the firewall. |
27 | HIPAA: Group Members Added | Alerts when new members are added to user groups. |
28 | HIPAA: Group Members Deleted | Alerts when members are removed from user groups. |
29 | HIPAA: Groups Created | Alerts when new user groups are created. |
30 | HIPAA: Groups Deleted | Alerts when a user group is deleted. |
31 | HIPAA: Groups Modified | Alerts when a user group has been modified. |
32 | HIPAA: Guardium SQL Guard Config Changes | Alerts when a configuration is changed on Guardium SQL Database. |
33 | HIPAA: Guardium SQL Guard Data Access | Alerts when a select statement is made on Guardium SQL Database. |
34 | HIPAA: Guardium SQL Guard Logins | Alerts when a user logs into the Guardium SQL Database. |
35 | HIPAA: HP NonStop Audit Configuration Changed | Alerts when configuration changes are made to the HP NonStop Audit. |
36 | HIPAA: HP NonStop Audit Permission Changed | Alerts on HP NonStop Audit permission changed events. |
37 | HIPAA: i5/OS Network Profile Changes | Alerts when any changes are made to an i5/OS network profile. |
38 | HIPAA: i5/OS Permission or Policy Change | Alerts when policies or permissions are changed on the i5/OS. |
39 | HIPAA: i5/OS Server or Service Status Change | Alerts when the i5/OS is restarted or a service stops or starts. |
40 | HIPAA: i5/OS Software Updates | Alerts when events related to the i5/OS software updates. |
41 | HIPAA: i5/OS User Profile Changes | Alerts when a user profile is changed on the i5/OS. |
42 | HIPAA: IBM AIX Password Changed | Alerts when an account password is changed on IBM AIX servers. |
43 | HIPAA: Juniper Firewall HA State Change | Alerts when Juniper Firewall has changed its failover state. |
44 | HIPAA: Juniper Firewall Peer Missing | Alerts when a Juniper Firewall HA peer is missing. |
45 | HIPAA: Juniper Firewall Policy Changes | Alerts when Juniper Firewall configuration is changed. |
46 | HIPAA: Juniper Firewall Policy Out of Sync | Alerts when the Juniper Firewall's policy is out of sync. |
47 | HIPAA: Juniper Firewall System Reset | Alerts when the Juniper Firewall has been reset to system default. |
48 | HIPAA: Juniper VPN Policy Change | Alerts when Juniper VPN policy or configuration change. |
49 | HIPAA: Logins Failed | Alerts when login failures are over the defined threshold. |
50 | HIPAA: Logins Succeeded | Alerts when successful logins are over the defined threshold. |
51 | HIPAA: LogLogic Disk Full | Alerts when the LogLogic appliance's disk is near full. |
52 | HIPAA: LogLogic DSM Configuration Changes | Alerts when a configuration is changed on LogLogic DSM database. |
53 | HIPAA: LogLogic DSM Data Access | Alerts when a select statement is made on LogLogic DSM database. |
54 | HIPAA: LogLogic DSM Logins | Alerts when a user logs into the LogLogic DSM database. |
55 | HIPAA: LogLogic File Retrieval Errors | Alerts when problems are detected during log file retrieval. |
56 | HIPAA: LogLogic HA State Change | Alerts when the LogLogic appliance failover state changes. |
57 | HIPAA: LogLogic Management Center Passwords Changed | Alerts when users have changed their passwords. |
58 | HIPAA: LogLogic Management Center Upgrade Succeeded | Alerts for successful events related to the system's upgrade. |
59 | HIPAA: LogLogic Message Routing Errors | Alerts when problems are detected during message forwarding. |
60 | HIPAA: LogLogic Universal Collector Configuration Changed | Alerts when configuration changes are made to the LogLogic universal collector. |
61 | HIPAA: Microsoft Operations Manager - Permissions Changed | Alerts when user or group permissions have been changed. |
62 | HIPAA: Microsoft Operations Manager - Windows Passwords Changed | Alerts when users have changed their passwords. |
63 | HIPAA: Microsoft Operations Manager - Windows Policies Changed | Alerts when Windows policies changed. |
64 | HIPAA: Microsoft Sharepoint Content Deleted | Alerts on Microsoft Sharepoint content deleted events. |
65 | HIPAA: Microsoft Sharepoint Content Updated | Alerts on Microsoft Sharepoint content updated events. |
66 | HIPAA: Microsoft Sharepoint Permission Changed | Alerts on Microsoft Sharepoint permission changed events. |
67 | HIPAA: Microsoft Sharepoint Policies Added, Removed, Modified | Alerts on Microsoft Sharepoint policy additions, deletions, and modifications. |
68 | HIPAA: NetApp Authentication Failure | Alerts when NetApp authentication failure events occur. |
69 | HIPAA: NetApp Filer Audit Policies Changed | Alerts when NetApp Filer Audit policies changed. |
70 | HIPAA: NetApp Filer Disk Failure | Alerts when a disk fails on a NetApp Filer. |
71 | HIPAA: NetApp Filer Disk Inserted | Alerts when a disk is inserted into the NetApp Filer. |
72 | HIPAA: NetApp Filer Disk Missing | Alerts when a disk is missing on the NetApp Filer device. |
73 | HIPAA: NetApp Filer Disk Pulled | Alerts when a RAID disk has been pulled from the Filer device. |
74 | HIPAA: NetApp Filer Disk Scrub Suspended | Alerts when the disk scrubbing process has been suspended. |
75 | HIPAA: NetApp Filer File System Full | Alerts when the file system is full on the NetApp Filer device. |
76 | HIPAA: NetApp Filer NIS Group Update | Alerts when the NIS group has been updated on the Filer device. |
77 | HIPAA: NetApp Filer Snapshot Error | Alerts when an error has been detected during a NetApp Filer snapshot. |
78 | HIPAA: NetApp Filer Unauthorized Mounting | Alerts when an unauthorized mount event occurs. |
79 | HIPAA: Oracle Database Configuration Change | Alerts when a ALTER or UPDATE command is executed on Oracle DB’s. |
80 | HIPAA: Oracle Database Data Access | Alerts when Oracle tables are accessed. |
81 | HIPAA: Oracle Database Permissions Changed | Alerts when permissions are changed on Oracle databases. |
82 | HIPAA: Oracle Database User Added or Deleted | Alerts when a user is added or deleted from an Oracle database. |
83 | HIPAA: Pulse Connect Secure Policy Change | Alerts when Pulse Connect Secure policy or configuration change. |
84 | HIPAA: RACF Files Accessed | Alerts when files are accessed on the RACF servers. |
85 | HIPAA: RACF Passwords Changed | Alerts when users have changed their passwords. |
86 | HIPAA: RACF Permissions Changed | Alerts when user or group permissions have been changed. |
87 | HIPAA: RACF Process Started | Alerts whenever a process is run on a RACF server. |
88 | HIPAA: Sidewinder Configuration Changed | Alerts when configuration changes are made to the Sidewinder. |
89 | HIPAA: Sybase ASE Database Config Changes | Alerts on Sybase ASE Database configuration change events. |
90 | HIPAA: Sybase ASE Database Data Access | Alerts on Sybase ASE Database data access events. |
91 | HIPAA: Symantec Endpoint Protection Configuration Changed | Alerts when configuration changes are made to the Symantec Endpoint Protection. |
92 | HIPAA: Symantec Endpoint Protection Policy Add, Delete, Modify | Alerts on Symantec Endpoint Protection additions, deletions, and modifications. |
93 | HIPAA: TIBCO ActiveMatrix Administrator Permission Changed | Alerts on TIBCO ActiveMatrix Administrator permission changed events. |
94 | HIPAA: System Restarted | Alerts when systems such as routers and switches have restarted. |
95 | HIPAA: vCenter Create Virtual Machine | Alerts when virtual machine has been created from VMware vCenter console. |
96 | HIPAA: vCenter Data Move | Alerts when entity has been moved within the VMware vCenter infrastructure. |
97 | HIPAA: vCenter Datastore Event | Alerts on create, modify, and delete datastore events on VMware vCenter. |
98 | HIPAA: vCenter Delete Virtual Machine | Alerts when a virtual machine has been deleted or removed from VMware vCenter console. |
99 | HIPAA: vCenter Firewall Policy Change | Alerts when changes to the VMware ESX allowed services firewall policy. |
100 | HIPAA: vCenter Orchestrator Create Virtual Machine | Alerts when the virtual machine has been created from VMware vCenter Orchestrator console. |
101 | HIPAA: vCenter Orchestrator Data Move | Alerts when an entity is moved within the VMware vCenter Orchestrator infrastructure. |
102 | HIPAA: vCenter Orchestrator Datastore Events | Alerts on create, modify, and delete datastore events on VMware vCenter Orchestrator. |
103 | HIPAA: vCenter Orchestrator Delete Virtual Machine | Alerts when a virtual machine has been deleted or removed from VMware vCenter Orchestrator console. |
104 | HIPAA: vCenter Orchestrator Login Failed | Failed logins to the VMware vCenter Orchestrator console. |
105 | HIPAA: vCenter Orchestrator Virtual Machine Shutdown | Virtual machine has been shutdown or paused from VMware vCenter Orchestrator console. |
106 | HIPAA: vCenter Orchestrator Virtual Machine Started | Virtual machine has been started or resumed from VMware vCenter Orchestrator console. |
107 | HIPAA: vCenter Orchestrator vSwitch Add, Modify or Delete | vSwitch on VMware ESX server has been added, modified or removed from vCenter Orchestrator. |
108 | HIPAA: vCenter Permission Change | Alerts when a permission role has been added, changed, removed, or applied on VMware vCenter. |
109 | HIPAA: vCenter Restart ESX Services | Alerts when VMware vCenter restarted services running on VMware ESX Server. |
110 | HIPAA: vCenter Shutdown or Restart ESX | Alerts when VMware ESX Server is shutdown from vCenter console. |
111 | HIPAA: vCenter User Login Failed | Alerts on failed logins to the VMware vCenter console. |
112 | HIPAA: vCenter User Login Successful | Alerts on successful logins to the VMware vCenter console. |
113 | HIPAA: vCenter Virtual Machine Shutdown | Alerts when virtual machine has been shutdown or paused from VMware vCenter console. |
114 | HIPAA: vCenter Virtual Machine Started | Alerts when virtual machine has been started or resumed from VMware vCenter console. |
115 | HIPAA: vCenter vSwitch Add, Modify or Delete | Alerts when vSwitch on VMware ESX server has been added, modified or removed from vCenter. |
116 | HIPAA: vCloud Director Login Failed | Alerts on failed logins to the VMware vCloud Director console. |
117 | HIPAA: vCloud Director Login Success | Alerts on successful logins to the VMware vCloud Director console. |
118 | HIPAA: vCloud Organization Created | Alerts when organization successfully created on VMware vCloud Director. |
119 | HIPAA: vCloud Organization Deleted | Alerts when organization successfully deleted on VMware vCloud Director. |
120 | HIPAA: vCloud Organization Modified | Alerts when organization successfully modified on VMware vCloud Director. |
121 | HIPAA: vCloud User Created | Alerts when a user successfully created on VMware vCloud Director. |
122 | HIPAA: vCloud User, Group, or Role Modified | Alerts when VMware vCloud Director user, group, or role has been modified. |
123 | HIPAA: vCloud vApp Created, Deleted, or Modified | Alerts when VMware vCloud Director vApp has been created, deleted, or modified. |
124 | HIPAA: vCloud vDC Created, Modified, or Deleted | Alerts when VMware vCloud Director Virtual Datacenters have been created, deleted, or modified. |
125 | HIPAA: vShield Edge Configuration Change | Alerts when configuration changes to VMware vShield Edge policies. |
126 | HIPAA: vShield Risky Traffic | Alerts when VMware vShield Edge traffic considered risky. |
127 | HIPAA: Windows Audit Log Cleared | Alerts when audit logs on Windows servers have been cleared. |
128 | HIPAA: Windows Files Accessed | Show files accessed on the Windows servers. |
129 | HIPAA: Windows Objects Create/Delete | Alerts when system level objects have been created or deleted. |
130 | HIPAA: Windows Passwords Changed | Alerts when users have changed their passwords. |
131 | HIPAA: Windows Permissions Changed | Alerts when user or group permissions have been changed. |
132 | HIPAA: Windows Policies Changed | Alerts when Windows policies changed. |
133 | HIPAA: Windows Process Started | Alerts when a process has been started on a Windows server. |
134 | HIPAA: Windows Programs Accessed | Alerts when a program is accessed on a Windows server. |
135 | HIPAA: Windows Software Updates | Alerts when events related to the Windows' software updates. |
136 | HIPAA: Windows Software Updates Failed | Alerts when failed events related to the software updates. |
137 | HIPAA: Windows Software Updates Succeeded | Alerts for successful events related to the software updates. |
Copyright © Cloud Software Group, Inc. All rights reserved.