TIBCO LogLogic Reports for NERC

The following table lists the reports included in the LogLogic® Compliance Suite - NERC Edition.

Serial Number TIBCO LogLogic Report Description
1 NERC: Account Activities on UNIX Servers Displays all account activities on UNIX servers to ensure authorized and appropriate access.
2 NERC: Account Activities on Windows Servers Displays all account activities on Windows servers to ensure authorized and appropriate access.
3 NERC: Accounts Changed on NetApp Filer Displays all accounts changed on NetApp Filer to ensure authorized and appropriate access.
4 NERC: Accounts Changed on TIBCO Administrator Displays all accounts changed on TIBCO Administrator to ensure authorized and appropriate access.
5 NERC: Accounts Changed on TIBCO ActiveMatrix Administrator Displays all accounts changed on TIBCO ActiveMatrix Administrator to ensure authorized and appropriate access.
6 NERC: Accounts Changed on UNIX Servers Displays all accounts changed on UNIX servers to ensure authorized and appropriate access.
7 NERC: Accounts Changed on Windows Servers Displays all accounts changed on Windows servers to ensure authorized and appropriate access.
8 NERC: Accounts Created on NetApp Filer Displays all accounts created on NetApp Filer to ensure authorized and appropriate access.
9 NERC: Accounts Created on NetApp Filer Audit Displays all accounts created on NetApp Filer Audit to ensure authorized and appropriate access.
10 NERC: Accounts Created on Symantec Endpoint Protection Displays all accounts created on Symantec Endpoint Protection to ensure authorized and appropriate access.
11 NERC: Accounts Created on TIBCO Administrator Displays all accounts created on TIBCO Administrator to ensure authorized and appropriate access.
12 NERC: Accounts Created on TIBCO ActiveMatrix Administrator Displays all accounts created on TIBCO ActiveMatrix Administrator to ensure authorized and appropriate access.
13 NERC: Accounts Created on Sidewinder Displays all accounts created on Sidewinder to ensure authorized and appropriate access.
14 NERC: Accounts Created on UNIX Servers Displays all accounts created on UNIX servers to ensure authorized and appropriate access.
15 NERC: Accounts Created on Windows Servers Displays all accounts created on Windows servers to ensure authorized and appropriate access.
16 NERC: Accounts Deleted on NetApp Filer Displays all accounts deleted on NetApp Filer to ensure authorized and appropriate access.
17 NERC: Accounts Deleted on NetApp Filer Audit Displays all accounts deleted on NetApp Filer Audit to ensure authorized and appropriate access.
18 NERC: Accounts Deleted on Sidewinder Displays all accounts deleted on Sidewinder to ensure authorized and appropriate access.
19 NERC: Accounts Deleted on Symantec Endpoint Protection Displays all accounts deleted on Symantec Endpoint Protection to ensure authorized and appropriate access.
20 NERC: Accounts Deleted on TIBCO Administrator Displays all accounts deleted on TIBCO Administrator to ensure authorized and appropriate access.
21 NERC: Accounts Deleted on TIBCO ActiveMatrix Administrator Displays all accounts deleted on TIBCO ActiveMatrix Administrator to ensure authorized and appropriate access.
22 NERC: Accounts Deleted on UNIX Servers Displays all accounts deleted on UNIX servers to ensure authorized and appropriate access.
23 NERC: Accounts Deleted on Windows Servers Displays all accounts deleted on Windows servers to ensure authorized and appropriate access.
24 NERC: Active Connections for Cisco ASA Displays all currently active firewall connections for Cisco ASA.
25 NERC: Active Connections for Cisco FWSM Displays all currently active firewall connections for Cisco FWSM.
26 NERC: Active Connections for Cisco PIX Displays all currently active firewall connections for Cisco PIX.
27 NERC: Active Directory System Changes Displays changes made within Active Directory.
28 NERC: Active VPN Connections for Cisco VPN Concentrators Displays all currently active VPN connections for Cisco VPN Concentrators.
29 NERC: Active VPN Connections for Nortel Contivity Displays all currently active VPN connections for Nortel Contivity VPN devices.
30 NERC: Active VPN Connections for RADIUS Displays all currently active VPN connections for RADIUS Acct Client.
31 NERC: Administrator Logins on Windows Servers Displays all logins with the administrator account on Windows servers.
32 NERC: Allowed URLs by Source IPs Displays successful access to URLs by source IP addresses.
33 NERC: Allowed URLs by Source IPs - F5 BIG-IP TMOS Displays successful access to URLs by source IP addresses on F5 BIG-IP TMOS.
34 NERC: Allowed URLs by Source IPs - Microsoft IIS Displays successful access to URLs by source IP addresses on Microsoft IIS.
35 NERC: Allowed URLs by Source Users - F5 BIG-IP TMOS Displays successful access to URLs by source users on F5 BIG-IP TMOS.
36 NERC: Allowed URLs by Source Users - Microsoft IIS Displays successful access to URLs by source users on Microsoft IIS.
37 NERC: Allowed URLs by Source Users Displays successful access to URLs by source users.
38 NERC: Attackers by Service Displays all attack source IP address and service ports.
39 NERC: Attackers by Service - Cisco IOS Displays all attack source IP address and service ports by Cisco IOS.
40 NERC: Attackers by Service - FireEye MPS Displays all attack source IP address and service ports by FireEye MPS.
41 NERC: Attackers by Service - ISS SiteProtector Displays all attack source IP address and service ports by ISS SiteProtector.
42 NERC: Attackers by Service - SiteProtector Displays all attack source IP address and service ports by SiteProtector.
43 NERC: Attackers by Service - Sourcefire Defense Center Displays all attack source IP address and service ports by Sourcefire Defense Center.
44 NERC: Attackers by Signature - ISS SiteProtector Displays all attack source IP address and signatures by ISS SiteProtector.
45 NERC: Attackers by Signature - SiteProtector Displays all attack source IP address and signatures by SiteProtector.
46 NERC: Attackers by Signature Displays all attack source IP address and signatures.
47 NERC: Attackers by Signature - Cisco IOS Displays all attack source IP address and signatures by Cisco IOS.
48 NERC: Attackers by Signature - Sourcefire Defense Center Displays all attack source IP address and signatures by Sourcefire Defense Center.
49 NERC: Attackers by Signature - FireEye MPS Displays all attack source IP address and signatures by FireEye MPS.
50 NERC: Attacks Detected Displays all IDS attacks detected against servers and applications.
51 NERC: Attacks Detected - Cisco IOS Displays all IDS attacks detected against servers and applications by Cisco IOS.
52 NERC: Attacks Detected - HIPS Displays all IPS attacks detected against servers and applications.
53 NERC: Attacks Detected - ISS SiteProtector Displays all IDS attacks detected against servers and applications by ISS SiteProtector.
54 NERC: Attacks Detected - SiteProtector Displays all IDS attacks detected against servers and applications by SiteProtector.
55 NERC: Attacks Detected - Sourcefire Defense Center Displays all IDS attacks detected against servers and applications by Sourcefire Defense Center.
56 NERC: Bandwidth Usage by User Displays users who are using the most bandwidth.
57 NERC: Blocked URLs by Source IPs Displays URLs that have been blocked by source IP addresses.
58 NERC: Blocked URLs by Source IPs - F5 BIG-IP TMOS Displays URLs that have been blocked by source IP addresses on F5 BIG-IP TMOS.
59 NERC: Blocked URLs by Source IPs - Microsoft IIS Displays URLs that have been blocked by source IP addresses on Microsoft IIS.
60 NERC: Blocked URLs by Source Users Displays URLs that have been blocked by source users.
61 NERC: Blocked URLs by Source Users - F5 BIG-IP TMOS Displays URLs that have been blocked by source users on F5 BIG-IP TMOS.
62 NERC: Blocked URLs by Source Users - Microsoft IIS Displays URLs that have been blocked by source users on Microsoft IIS.
63 NERC: Check Point Configuration Changes Displays all Check Point audit events related to configuration changes.
64 NERC: Cisco ESA: Attacks by Event ID Displays Cisco ESA attacks by Event ID.
65 NERC: Cisco ESA: Attacks Detected Displays attacks detected by Cisco ESA.
66 NERC: Cisco ESA: Attacks by Threat Name Displays Cisco ESA Attacks by threat name.
67 NERC: Cisco ESA: Scans Displays scans using Cisco ESA.
68 NERC: Cisco ESA: Updated Displays updates to Cisco ESA.
69 NERC: Cisco ISE, ACS Accounts Created Displays all accounts created on Cisco ISE and Cisco SecureACS to ensure authorized and appropriate access.
70 NERC: Cisco ISE, ACS Accounts Removed Displays all accounts removed on Cisco ISE and Cisco SecureACS to ensure authorized and appropriate access.
71 NERC: Cisco ISE, ACS Configuration Changes Displays Cisco ISE and Cisco SecureACS configuration changes.
72 NERC: Cisco ISE, ACS Password Changes Displays all password change activities on Cisco ISE and Cisco SecureACS to ensure authorized and appropriate access.
73 NERC: Cisco PIX, ASA, FWSM Policy Changed Displays all configuration changes made to the Cisco PIX, ASA, and FWSM devices.
74 NERC: Cisco PIX, ASA, FWSM Failover Disabled Displays all logs related to disabling Cisco PIX, ASA, and FWSM failover capability.
75 NERC: Cisco PIX, ASA, FWSM Failover Performed Displays all logs related to performing a Cisco PIX, ASA, or FWSM failover.
76 NERC: Cisco PIX, ASA, FWSM Restarted Displays all Cisco PIX, ASA, or FWSM restart activities to detect unusual activities.
77 NERC: Cisco Switch Policy Changes Displays all configuration changes to the Cisco router and switch policies.
78 NERC: DB2 Database Configuration Changes Displays DB2 database configuration changes.
79 NERC: DB2 Database Failed Logins Displays all failed login attempts to review any access violations or unusual activity.
80 NERC: DB2 Database Successful Logins Displays successful DB2 database logins.
81 NERC: DB2 Database User Additions and Deletions Displays IBM DB2 Database events related to creation and deletion of database users.
82 NERC: Denied Connections by IP Addresses Displays remote IP addresses with the most denied connections.
83 NERC: Denied Connections - Cisco IOS Displays all connections that have been denied by the Cisco IOS devices.
84 NERC: Denied Connections - Cisco NXOS Displays all connections that have been denied by the Cisco NXOS devices.
85 NERC: Denied Connections - F5 BIG-IP TMOS Displays all connections that have been denied by the F5 BIG-IP TMOS devices.
86 NERC: Denied Connections - Cisco Router Displays all connections that have been denied by the Cisco Router devices.
87 NERC: Denied Connections - Sidewinder Displays all connections that have been denied by the Sidewinder devices.
88 NERC: Denied Connections - VMware vShield Displays all connections that have been denied by the VMware vShield devices.
89 NERC: Denied Inbound Connections - Check Point Displays all inbound connections that have been denied by the Check Point devices.
90 NERC: Denied Inbound Connections - Cisco ASA Displays all inbound connections that have been denied by the Cisco ASA devices.
91 NERC: Denied Inbound Connections - Cisco FWSM Displays all inbound connections that have been denied by the Cisco FWSM devices.
92 NERC: Denied Inbound Connections - Cisco PIX Displays all inbound connections that have been denied by the Cisco PIX devices.
93 NERC: Denied Inbound Connections - Juniper Firewall Displays all inbound connections that have been denied by the Juniper Firewalls.
94 NERC: Denied Outbound Connections - Check Point Displays all outbound connections that have been denied by the Check Point.
95 NERC: Denied Outbound Connections - Cisco ASA Displays all outbound connections that have been denied by the Cisco ASA.
96 NERC: Denied Outbound Connections - Cisco FWSM Displays all outbound connections that have been denied by the Cisco FWSM.
97 NERC: Denied Outbound Connections - Cisco PIX Displays all outbound connections that have been denied by the Cisco PIX.
98 NERC: Denied Outbound Connections - Juniper Firewall Displays all outbound connections that have been denied by the Juniper Firewall.
99 NERC: DHCP Activities on Microsoft DHCP Displays all DHCP activities on Microsoft DHCP Server.
100 NERC: DHCP Activities on VMware vShield Displays all DHCP activities on VMware vShield Edge.
101 NERC: DNS Server Error Displays all events when DNS server has errors.
102 NERC: Domain activities on Symantec Endpoint Protection Displays all domain activities on Symantec Endpoint Protection.
103 NERC: Escalated Privilege Activities on Servers Displays all privilege escalation activities performed on servers to ensure appropriate access.
104 NERC: ESX Accounts Activities Displays all account activities on VMware ESX servers to ensure authorized and appropriate access.
105 NERC: ESX Accounts Created Displays all accounts created on VMware ESX servers to ensure authorized and appropriate access.
106 NERC: ESX Accounts Deleted Displays all accounts deleted on VMware ESX servers to ensure authorized and appropriate access.
107 NERC: ESX Failed Logins Failed VMware ESX logins for known user.
108 NERC: ESX Group Activities Displays all group activities on VMware ESX servers to ensure authorized and appropriate access.
109 NERC: ESX Kernel log daemon terminating Displays all VMware ESX kernel log daemon terminating.
110 NERC: ESX Kernel logging Stop Displays all VMware ESX kernel logging stops.
111 NERC: ESX Logins Failed Unknown User Failed VMware ESX logins for unknown user.
112 NERC: ESX Logins Succeeded Displays successful logins to VMware ESX to ensure only authorized personnel have access.
113 NERC: F5 BIG-IP TMOS Login Failed Displays all F5 BIG-IP TMOS login events that have failed.
114 NERC: F5 BIG-IP TMOS Login Successful Displays all F5 BIG-IP TMOS login events that have succeeded.
115 NERC: F5 BIG-IP TMOS Password Changes Displays all password change activities on F5 BIG-IP TMOS to ensure authorized and appropriate access.
116 NERC: F5 BIG-IP TMOS Restarted Displays all events when the F5 BIG-IP TMOS is restarted.
117 NERC: ESX Syslogd Restart Displays all VMware ESX syslogd restarts.
118 NERC: Files Accessed on NetApp Filer Audit Displays all files accessed on NetApp Filer Audit to ensure appropriate access.
119 NERC: Files Downloaded via Proxy - Microsoft IIS Displays all proxy-based downloads to ensure authorized and appropriate access on Microsoft IIS.
120 NERC: Failed Logins Displays all failed login attempts to review any access violations or unusual activity.
121 NERC: Files Accessed on Servers Displays all files accessed on servers to ensure appropriate access.
122 NERC: Files Accessed through Juniper SSL VPN (Secure Access) Displays all files Accessed through Juniper SSL VPN (Secure Access).
123 NERC: Files Accessed through PANOS Displays all files Accessed through Palo Alto Networks.
124 NERC: Files Downloaded via Proxy Displays all proxy-based downloads to ensure authorized and appropriate access.
125 NERC: Files Downloaded via Proxy - Blue Coat Proxy Displays all proxy-based downloads to ensure authorized and appropriate access on Blue Coat Proxy.
126 NERC: Files Downloaded via Proxy - Cisco WSA Displays all proxy-based downloads to ensure authorized and appropriate access on Cisco WSA.
127 NERC: Files Downloaded via the Web Displays all web-based downloads to ensure authorized and appropriate access.
128 NERC: Files Downloaded via the Web - F5 BIG-IP TMOS Displays all web-based downloads to ensure authorized and appropriate access on F5 BIG-IP TMOS.
129 NERC: Files Downloaded via the Web - Microsoft IIS Displays all web-based downloads ensure authorized and appropriate access on Microsoft IIS.
130 NERC: Files Uploaded via Proxy Displays all proxy-based uploads to ensure only authorized data can be uploaded.
131 NERC: Files Uploaded via Proxy - Blue Coat Proxy Displays all proxy-based uploads to ensure only authorized data can be uploaded on Blue Coat Proxy.
132 NERC: Files Uploaded via Proxy - Cisco WSA Displays all proxy-based uploads to ensure only authorized data can be uploaded on Cisco WSA.
133 NERC: Files Uploaded via Proxy - Microsoft IIS Displays all proxy-based uploads to ensure only authorized data can be uploaded on Microsoft IIS.
134 NERC: Files Uploaded via the Web Displays all web-based uploads to ensure only authorized data can be uploaded.
135 NERC: Files Uploaded via the Web - F5 BIG-IP TMOS Displays all web-based uploads to ensure only authorized data can be uploaded on F5 BIG-IP TMOS.
136 NERC: Files Uploaded via the Web - Microsoft IIS Displays all web-based uploads to ensure only authorized data can be uploaded on Microsoft IIS.
137 NERC: FortiOS: Attacks Detected Displays attacks detected by FortiOS.
138 NERC: FortiOS: Attacks by Event ID Displays FortiOS attacks by Event ID.
139 NERC: FortiOS: Attacks by Threat Name Displays FortiOS attacks by threat name.
140 NERC: FortiOS DLP Attacks Detected Displays all DLP attacks detected by FortiOS.
141 NERC: Group Activities on NetApp Filer Audit Displays all group activities on NetApp Filer Audit to ensure authorized and appropriate access.
142 NERC: Group Activities on Symantec Endpoint Protection Displays all group activities on Symantec Endpoint Protection to ensure authorized and appropriate access.
143 NERC: Group Activities on TIBCO ActiveMatrix Administrator Displays all group activities on TIBCO ActiveMatrix Administrator to ensure authorized and appropriate access.
144 NERC: Group Activities on UNIX Servers Displays all group activities on UNIX servers to ensure authorized and appropriate access.
145 NERC: Group Activities on Windows Servers Displays all group activities on Windows servers to ensure authorized and appropriate access.
146 NERC: Guardium SQL Guard Audit Configuration Changes Displays all configuration changes on the Guardium SQL Guard Audit database.
147 NERC: Guardium SQL Guard Audit Logins Displays all login attempts to the Guardium SQL Server Audit database.
148 NERC: Guardium SQL Guard Configuration Changes Displays all configuration changes on the Guardium SQL Guard database.
149 NERC: Guardium SQL Guard Logins Displays all login attempts to the Guardium SQL Server database.
150 NERC: HP NonStop Audit Configuration Changes Displays all audit configuration changes on HP NonStop.
151 NERC: HP NonStop Audit Login Failed Displays all HP NonStop Audit login events that have failed.
152 NERC: HP NonStop Audit Login Successful Displays all HP NonStop Audit login events that have succeeded.
153 NERC: HP NonStop Audit Object Access Displays HP NonStop Audit events related to object access.
154 NERC: HP NonStop Audit Object Changes Displays HP NonStop Audit events related to object changes.
155 NERC: HP NonStop Audit Permissions Changed Displays all permission modification activities on HP NonStop Audit to ensure authorized access.
156 NERC: Files Accessed through Pulse Connect Secure Displays all files accessed through Pulse Connect Secure.
157 NERC: i5/OS Access Control List Modifications Displays i5/OS events related to access control list modification.
158 NERC: i5/OS Audit Configuration Changes Displays all audit configuration changes on i5/OS.
159 NERC: i5/OS DST Password Reset Displays i5/OS events related to the reset of the DST (Dedicated Service Tools) password.
160 NERC: i5/OS Object Access Displays i5/OS events related to object access.
161 NERC: i5/OS Restore Events Displays i5/OS events related to object, program, and profile restoration.
162 NERC: i5/OS System Management Changes Displays i5/OS events related to system management changes.
163 NERC: i5/OS User Profile Creation, Modification, or Restoration Displays i5/OS events related to user profile creation, modification, or restoration.
164 NERC: Juniper Firewall HA State Changed Displays all Juniper Firewall failover state change events.
165 NERC: Juniper Firewall Policy Changed Displays all configuration changes to the Juniper Firewall policies.
166 NERC: Juniper Firewall Policy Out of Sync Displays events indicating that the Juniper Firewall's HA policies are out of sync.
167 NERC: Juniper Firewall Reset Accepted Displays events indicating that the Juniper Firewall is reset to its factory default state.
168 NERC: Juniper Firewall Reset Imminent Displays events that indicate the Juniper Firewall will be reset to its factory default state.
169 NERC: FireEye MPS: Attacks by Event ID Displays FireEye MPS attacks by Event ID.
170 NERC: FireEye MPS: Attacks by Threat Name Displays FireEye MPS attacks by threat name.
171 NERC: FireEye MPS: Attacks Detected Displays attacks detected by FireEye MPS.
172 NERC: Last Activities Performed by Administrators Displays the latest activities performed by administrators and root users to ensure appropriate access.
173 NERC: Last Activities Performed by All Users Displays the latest activities performed by all users to ensure appropriate access.
174 NERC: Logins by Authentication Type Displays all logins categorized by the authentication type.
175 NERC: LogLogic DSM Configuration Changes Displays all configuration changes on the LogLogic DSM database.
176 NERC: LogLogic DSM Logins Displays all login attempts to the LogLogic DSM database.
177 NERC: LogLogic Management Center Account Activities Displays all account activities on LogLogic management center to ensure authorized and appropriate access.
178 NERC: LogLogic Management Center Login Displays all login events to the LogLogic management center.
179 NERC: LogLogic Management Center Password Changes Displays all password change activities on LogLogic management center to ensure authorized and appropriate access.
180 NERC: LogLogic Management Center Restore Activities Displays all restore activities on LogLogic management center.
181 NERC: LogLogic Universal Collector Configuration Changes Displays LogLogic universal collector configuration changes.
182 NERC: McAfee Antivirus: Attacks Detected Displays attacks detected by McAfee AntiVirus.
183 NERC: McAfee AntiVirus: Attacks by Event ID Displays McAfee AntiVirus attacks by Event ID.
184 NERC: McAfee AntiVirus: Attacks by Threat Name Displays McAfee AntiVirus Attacks by threat name.
185 NERC: Microsoft Operations Manager - Windows Accounts Activities Displays all account activities on Windows servers to ensure authorized and appropriate access.
186 NERC: Microsoft Operations Manager - Windows Accounts Changed Displays all accounts changed on Windows servers to ensure authorized and appropriate access.
187 NERC: Microsoft Operations Manager - Windows Accounts Created Displays all accounts created on Windows servers to ensure authorized and appropriate access.
188 NERC: Microsoft Operations Manager - Windows Accounts Enabled Displays all accounts enabled on Windows servers to ensure authorized and appropriate access.
189 NERC: Microsoft Operations Manager - Windows Events by Users Displays a summary of access-related Windows events by source and target users.
190 NERC: Microsoft Operations Manager - Windows Password Changes Displays all password change activities on Windows servers to ensure authorized and appropriate access.
191 NERC: Microsoft Operations Manager - Windows Permissions Modified Displays all permission modification activities on Windows servers to ensure authorized access.
192 NERC: Microsoft Operations Manager - Windows Policies Modified Displays all policy modification activities on Windows servers to ensure authorized and appropriate access.
193 NERC: Microsoft Sharepoint Content Deleted Displays all events when content is deleted from Microsoft SharePoint.
194 NERC: Microsoft Sharepoint Content Updates Displays all events when content is updated within Microsoft SharePoint.
195 NERC: Microsoft Sharepoint Permissions Changed Displays all user/group permission events to Microsoft SharePoint.
196 NERC: Microsoft Sharepoint Policy Add, Remove, or Modify Displays all events when a Microsoft SharePoint policy is added, removed, or modified.
197 NERC: Microsoft SQL Server Configuration Changes Displays Microsoft SQL database configuration changes.
198 NERC: Microsoft SQL Server Database Failed Logins Displays failed Microsoft SQL Server database logins.
199 NERC: Microsoft SQL Server Database Successful Logins Displays successful Microsoft SQL Server database logins.
200 NERC: Microsoft SQL Server Database Permission Events Displays events related to Microsoft SQL Server database permission modifications.
201 NERC: Microsoft SQL Server Database User Additions and Deletions Displays Microsoft SQL Server events related to creation and deletion of database users.
202 NERC: Microsoft SQL Server Password Changes Displays password changes for Microsoft SQL Server database accounts.
203 NERC: Most Active Ports Through Firewall - Check Point Displays the most active ports used through the Check Point firewall.
204 NERC: Most Active Ports Through Firewall - Cisco ASA Displays the most active ports used through the Cisco ASA firewall.
205 NERC: Most Active Ports Through Firewall - Cisco FWSM Displays the most active ports used through the Cisco FWSM firewall.
206 NERC: Most Active Ports Through Firewall - Cisco PIX Displays the most active ports used through the Cisco PIX firewall.
207 NERC: Most Active Ports Through Firewall - Fortinet Displays the most active ports used through the Fortinet firewall.
208 NERC: Most Active Ports Through Firewall - Juniper Firewall Displays the most active ports used through the Juniper Firewall.
209 NERC: Most Active Ports Through Firewall - Nortel Displays the most active ports used through the Nortel firewall.
210 NERC: NetApp Filer Accounts Locked Displays all accounts locked out of NetApp Filer to detect access violations or unusual activities.
211 NERC: NetApp Filer Audit Accounts Enabled Displays all accounts enabled on NetApp Filer Audit to ensure authorized and appropriate access.
212 NERC: NetApp Filer Audit Group Members Added Displays all accounts added to groups on NetApp Filer Audit to ensure appropriate access.
213 NERC: NetApp Filer Audit Group Members Deleted Displays all accounts removed from groups on NetApp Filer Audit to ensure appropriate access.
214 NERC: NetApp Filer File Activity Displays all file activities on NetApp Filer.
215 NERC: NetApp Filer Login Failed Displays all NetApp Filer login events that have failed.
216 NERC: NetApp Filer Login Successful Displays all NetApp Filer login events that have succeeded.
217 NERC: NetApp Filer Password Changes Displays all password change activities on NetApp Filer to ensure authorized and appropriate access.
218 NERC: NetApp Filer Audit Login Failed Displays all NetApp Filer Audit login events that have failed.
219 NERC: NetApp Filer Audit Login Successful Displays all NetApp Filer Audit login events that have succeeded.
220 NERC: NetApp Filer Audit Policies Modified Displays all policy modification activities on NetApp Filer Audit to ensure authorized and appropriate access.
221 NERC: Novell eDirectory Password Changes Password changes on Novell eDirectory.
222 NERC: Oracle Database Configuration Changes Displays Oracle database configuration changes.
223 NERC: Oracle Database Failed Logins Displays failed login attempts to the Oracle database.
224 NERC: Oracle Database Successful Logins Displays successful Oracle database login attempts.
225 NERC: Oracle Database Permission Events Displays events related to Oracle Server database role and privilege management.
226 NERC: Oracle Database User Additions and Deletions Displays Oracle database events related to creation and deletion of database users.
227 NERC: Password Changes on Windows Servers Displays all password change activities on Windows servers to ensure authorized and appropriate access.
228 NERC: PANOS: Attacks Detected Displays attacks detected by Palo Alto Networks.
229 NERC: PANOS: Attacks by Event ID Displays Palo Alto Networks attacks by Event ID.
230 NERC: PANOS: Attacks by Threat Name Displays Palo Alto Networks attacks by threat name.
231 NERC: Periodic Review of Log Reports Displays all review activities performed by administrators to ensure review for any access violations.
232 NERC: Periodic Review of User Access Logs Displays all review activities performed by administrators to ensure review for any access violations.
233 NERC: Permissions Modified on Windows Servers Displays all permission modification activities on Windows Servers to ensure authorized access.
234 NERC: Policies Modified on Windows Servers Displays all policy modification activities on Windows servers to ensure authorized and appropriate access.
235 NERC: Ports Allowed Access - Check Point Displays all connections passed through the Check Point by port.
236 NERC: Ports Allowed Access - Cisco ASA Displays all connections passed through the Cisco ASA by port.
237 NERC: Ports Allowed Access - Cisco IOS Displays all connections passed through the Cisco IOS by port.
238 NERC: Ports Allowed Access - Cisco FWSM Displays all connections passed through the Cisco FWSM by port.
239 NERC: Ports Allowed Access - Cisco Netflow Displays all connections passed through the Cisco Netflow by port.
240 NERC: Ports Allowed Access - Cisco PIX Displays all connections passed through the Cisco PIX by port.
241 NERC: Ports Allowed Access - F5 BIG-IP TMOS Displays all connections passed through the F5 BIG-IP TMOS by port.
242 NERC: Ports Allowed Access - Fortinet Displays all connections passed through the Fortinet by port.
243 NERC: Ports Allowed Access - Juniper Firewall Displays all connections passed through the Juniper Firewall by port.
244 NERC: Ports Allowed Access - Juniper JunOS Displays all connections passed through the Juniper JunOS by port.
245 NERC: Ports Allowed Access - Juniper RT Flow Displays all connections passed through the Juniper RT Flow by port.
246 NERC: Ports Allowed Access - Nortel Displays all connections passed through the Nortel by port.
247 NERC: Ports Allowed Access - PANOS Displays all connections passed through the Palo Alto Networks by port.
248 NERC: Ports Allowed Access - Sidewinder Displays all connections passed through the Sidewinder by port.
249 NERC: Ports Allowed Access - VMware vShield Displays all connections passed through the VMware vShield by port.
250 NERC: Ports Denied Access - Check Point Displays the applications that have been denied access the most by the Check Point.
251 NERC: Ports Denied Access - Cisco ASA Displays the applications that have been denied access the most by the Cisco ASA.
252 NERC: Ports Denied Access - Cisco FWSM Displays the applications that have been denied access the most by the Cisco FWSM.
253 NERC: Ports Denied Access - Cisco IOS Displays the applications that have been denied access the most by the Cisco IOS.
254 NERC: Ports Denied Access - Cisco PIX Displays the applications that have been denied access the most by the Cisco PIX.
255 NERC: Ports Denied Access - Cisco Router Displays the applications that have been denied access the most by the Cisco Router.
256 NERC: Ports Denied Access - F5 BIG-IP TMOS Displays the applications that have been denied access the most by the F5 BIG-IP TMOS.
257 NERC: Ports Denied Access - Fortinet Displays the applications that have been denied access the most by the Fortinet.
258 NERC: Ports Denied Access - Juniper Firewall Displays the applications that have been denied access the most by the Juniper Firewall.
259 NERC: Ports Denied Access - Juniper JunOS Displays the applications that have been denied access the most by the Juniper JunOS.
260 NERC: Ports Denied Access - Juniper RT Flow Displays the applications that have been denied access the most by the Juniper RT Flow.
261 NERC: Ports Denied Access - Nortel Displays the applications that have been denied access the most by the Nortel.
262 NERC: Ports Denied Access - PANOS Displays the applications that have been denied access the most by the Palo Alto Networks.
263 NERC: Ports Denied Access - Sidewinder Displays the applications that have been denied access the most by the Sidewinder.
264 NERC: Ports Denied Access - VMware vShield Displays the applications that have been denied access the most by the VMware vShield Edge.
265 NERC: RACF Accounts Created Displays all accounts created on RACF servers to ensure authorized and appropriate access.
266 NERC: RACF Accounts Deleted Displays all accounts deleted on RACF servers to ensure authorized and appropriate access.
267 NERC: RACF Accounts Modified Displays all events when a network user profile is modified.
268 NERC: RACF Failed Logins Displays all failed login attempts to review any access violations or unusual activity.
269 NERC: RACF Files Accessed Displays all files accessed on RACF servers to ensure appropriate access.
270 NERC: RACF Password Changed Displays all password change activities on RACF servers to ensure authorized and appropriate access.
271 NERC: RACF Permissions Changed Displays all permission modification activities on RACF to ensure authorized access.
272 NERC: RACF Successful Logins Displays successful logins to ensure only authorized personnel have access.
273 NERC: Root Logins Displays root logins.
274 NERC: Sensors Generating Alerts Displays the IDS sensors that generated the most alerts.
275 NERC: Sensors Generating Alerts - FireEye MPS Displays the IDS sensors that generated the most alerts by FireEye MPS.
276 NERC: Sensors Generating Alerts - Cisco IOS Displays the IDS sensors that generated the most alerts by Cisco IOS.
277 NERC: Sensors Generating Alerts - ISS SiteProtector Displays the IDS sensors that generated the most alerts by ISS SiteProtector.
278 NERC: Sensors Generating Alerts - SiteProtector Displays the IDS sensors that generated the most alerts by SiteProtector.
279 NERC: Sensors Generating Alerts - Sourcefire Defense Center Displays the IDS sensors that generated the most alerts by Sourcefire Defense Center.
280 NERC: Sidewinder Configuration Changes Displays Sidewinder configuration changes.
281 NERC: Successful Logins Displays successful logins to ensure only authorized personnel have access.
282 NERC: Sybase ASE Database Configuration Changes Displays configuration changes to the Sybase database.
283 NERC: Sybase ASE Database User Additions and Deletions Displays Sybase database events related to creation and deletion of database users.
284 NERC: Sybase ASE Failed Logins Displays failed Sybase ASE database logins.
285 NERC: Sybase ASE Successful Logins Displays successful Sybase ASE database logins.
286 NERC: Symantec AntiVirus: Attacks by Event ID Displays all Symantec AntiVirus Attacks by Event ID events.
287 NERC: Symantec AntiVirus: Attacks by Threat Name Displays Symantec AntiVirus attacks by threat name.
288 NERC: Symantec AntiVirus: Attacks Detected Displays attacks detected by Symantec AntiVirus.
289 NERC: Symantec AntiVirus: Scans Displays scans using Symantec AntiVirus.
290 NERC: Symantec AntiVirus: Updated Displays updates to Symantec AntiVirus.
291 NERC: Symantec Endpoint Protection: Attacks Detected Displays attacks detected by Symantec Endpoint Protection.
292 NERC: Symantec Endpoint Protection: Attacks by Threat Name Displays Symantec Endpoint Protection attacks by threat name.
293 NERC: Symantec Endpoint Protection Configuration Changes Displays Symantec Endpoint Protection configuration changes.
294 NERC: Symantec Endpoint Protection Password Changes Displays all password change activities on Symantec Endpoint Protection to ensure authorized and appropriate access.
295 NERC: Symantec Endpoint Protection Policy Add, Remove, or Modify Displays all events when a Symantec Endpoint Protection policy is added, removed, or modified.
296 NERC: Symantec Endpoint Protection: Scans Displays scans using Symantec Endpoint Protection.
297 NERC: Symantec Endpoint Protection: Updated Displays updates to Symantec Endpoint Protection.
298 NERC: TIBCO ActiveMatrix Administrator Failed Logins Displays all TIBCO ActiveMatrix Administrator login events that have failed.
299 NERC: TIBCO ActiveMatrix Administrator Permission Changes Displays all TIBCO ActiveMatrix Administrator permission modifications.
300 NERC: TIBCO ActiveMatrix Administrator Successful Logins Displays successful logins to TIBCO ActiveMatrix Administrator to ensure only authorized personnel have access.
301 NERC: TIBCO Administrator Password Changes Displays all password change activities on TIBCO Administrator to ensure authorized and appropriate access.
302 NERC: TIBCO Administrator Permission Changes Displays events related to TIBCO Administrator permission modifications.
303 NERC: TrendMicro Control Manager: Attacks Detected Displays attacks detected by TrendMicro Control Manager.
304 NERC: TrendMicro Control Manager: Attacks Detected by Threat Name Displays attacks detected by TrendMicro Control Manager by threat name.
305 NERC: TrendMicro OfficeScan: Attacks Detected Displays attacks detected by TrendMicro OfficeScan.
306 NERC: TrendMicro OfficeScan: Attacks Detected by Threat Name Displays attacks detected by TrendMicro OfficeScan by threat name.
307 NERC: Trusted Domain Created on Windows Servers Displays all trusted domains created on Windows servers to ensure authorized and appropriate access.
308 NERC: Trusted Domain Deleted on Windows Servers Displays all trusted domains deleted on Windows servers to ensure authorized and appropriate access.
309 NERC: Unauthorized Logins Displays all logins from unauthorized users to ensure appropriate access to data.
310 NERC: Unencrypted Logins Displays all unencrypted logins to ensure secure access to data.
311 NERC: Unix Password Changes Password changes on UNIX servers.
312 NERC: Users Created on Servers Displays all users created on servers to ensure authorized and appropriate access.
313 NERC: Users Removed from Servers Displays all users removed from servers to ensure timely removal of terminated users.
314 NERC: Users Using the Proxies Displays users who have been surfing the web through the proxy servers.
315 NERC: Users Using the Proxies - Blue Coat Proxy Displays users who have been surfing the web through the proxy servers on Blue Coat Proxy.
316 NERC: Users Using the Proxies - Cisco WSA Displays users who have been surfing the web through the proxy servers on Cisco WSA.
317 NERC: Users Using the Proxies - Microsoft IIS Displays users who have been surfing the web through the proxy servers on Microsoft IIS.
318 NERC: vCenter Change Attributes Modification of VMware vCenter and VMware ESX properties.
319 NERC: vCenter Data Move Entity is moved within the VMware vCenter infrastructure.
320 NERC: vCenter Datastore Events Displays create, modify, and delete datastore events on VMware vCenter.
321 NERC: vCenter Failed Logins Failed logins to the VMware vCenter console.
322 NERC: vCenter Modify Firewall Policy Displays changes to the VMware ESX allowed services firewall policy.
323 NERC: vCenter Orchestrator Change Attributes Modification of VMware vCenter Orchestrator properties.
324 NERC: vCenter Orchestrator Datastore Events Displays create, modify, and delete datastore events on VMware vCenter Orchestrator.
325 NERC: vCenter Orchestrator Data Move Entity is moved within the VMware vCenter Orchestrator infrastructure.
326 NERC: vCenter Orchestrator Failed Logins Displays all failed logins for VMware vCenter Orchestrator.
327 NERC: vCenter Orchestrator Virtual Machine Created Virtual machine is created from VMware vCenter Orchestrator.
328 NERC: vCenter Orchestrator Virtual Machine Deleted Virtual machine is deleted from VMware vCenter Orchestrator.
329 NERC: vCenter Orchestrator Virtual Machine Shutdown Virtual machine is shut down or paused from VMware vCenter Orchestrator console.
330 NERC: vCenter Orchestrator Virtual Machine Started Virtual machine is started or resumed from VMware vCenter Orchestrator console.
331 NERC: vCenter Orchestrator vSwitch Added, Changed or Removed vSwitch is added, modified or removed from VMware vCenter Orchestrator console.
332 NERC: vCenter Resource Usage Change Resources have changed on VMware vCenter.
333 NERC: vCenter Restart ESX Services VMware vCenter restarted services running on VMware ESX Server.
334 NERC: vCenter Shutdown or Restart of ESX Server VMware ESX Server is shutdown or restarted from VMware vCenter console.
335 NERC: vCenter Successful Logins Successful logins to the VMware vCenter console.
336 NERC: vCenter User Permission Change A permission role is added, changed, removed, or applied to a user on VMware vCenter server.
337 NERC: vCenter Virtual Machine Created Virtual machine is created from VMware vCenter console.
338 NERC: vCenter Virtual Machine Deleted Virtual machine is deleted or removed from VMware vCenter console.
339 NERC: vCenter Virtual Machine Shutdown Virtual machine is shutdown or paused from VMware vCenter console.
340 NERC: vCenter Virtual Machine Started Virtual machine is started or resumed from VMware vCenter console.
341 NERC: vCenter vSwitch Added, Changed or Removed vSwitch on VMware ESX server is added, modified or removed from the VMware vCenter console.
342 NERC: vCloud Failed Logins Failed logins to the VMware vCloud Director console.
343 NERC: vCloud Organization Created VMware vCloud Director organization created events.
344 NERC: vCloud Organization Deleted VMware vCloud Director organization deleted events.
345 NERC: vCloud Organization Modified VMware vCloud Director organization modified events.
346 NERC: vCloud Successful Logins Successful logins to the VMware vCloud Director console.
347 NERC: vCloud User Created VMware vCloud Director user-created events.
348 NERC: vCloud User Deleted or Removed VMware vCloud Director users have been deleted or removed from the system.
349 NERC: vCloud vApp Created, Modified, or Deleted VMware vCloud Director vApp created, deleted, and modified events.
350 NERC: vCloud vDC Created, Modified, or Deleted VMware vCloud Director virtual datacenter created, modified, or deleted events.
351 NERC: VPN Connections by Users Displays users who are made the most connections.
352 NERC: VPN Denied Connections by Users Displays users with the most number of denied connections.
353 NERC: VPN Sessions by Destination IPs Displays all VPN sessions categorized by destination IP addresses.
354 NERC: VPN Sessions by Source IPs Displays all VPN sessions categorized by source IP addresses.
355 NERC: VPN Sessions by Users Displays all VPN sessions categorized by authenticated users.
356 NERC: VPN Users Accessing Corporate Network Displays all users logging in to the corporate network via Virtual Private Network to ensure appropriate access.
357 NERC: vShield Edge Configuration Changes Displays changes to the VMware vShield Edge policies.
358 NERC: vShield Risky Firewall Traffic Displays all allowed VMware vShield Edge firewall traffic that are considered risky.
359 NERC: Web Access from All Users Displays all web-based access by all users for regular reviews and updates.
360 NERC: Web Access from All Users - Fortinet Displays all web-based access by all users for regular reviews and updates on Fortinet.
361 NERC: Web Access from All Users - F5 BIG-IP TMOS Displays all web-based access by all users for regular reviews and updates on F5 BIG-IP TMOS.
362 NERC: Web Access from All Users - Microsoft IIS Displays all web-based access by all users for regular reviews and updates on Microsoft IIS.
363 NERC: Web Access from All Users - PANOS Displays all web-based access by all users for regular reviews and updates on Palo Alto Networks.
364 NERC: Web Access to Applications - F5 BIG-IP TMOS Displays all web-based access to applications to ensure appropriate and authorized access on F5 BIG-IP TMOS.
365 NERC: Web Access to Applications - Fortinet Displays all web-based access to applications to ensure appropriate and authorized access on Fortinet.
366 NERC: Web Access to Applications - Microsoft IIS Displays all web-based access to applications to ensure appropriate and authorized access on Microsoft IIS.
367 NERC: Web Access to Applications - PANOS Displays all web-based access to applications to ensure appropriate and authorized access on Palo Alto Networks.
368 NERC: Web Access to Applications Displays all web-based access to applications to ensure appropriate and authorized access.
369 NERC: Windows Accounts Enabled Displays all accounts enabled on Windows servers to ensure authorized and appropriate access.
370 NERC: Windows Accounts Locked Displays all accounts locked out of Windows servers to detect access violations or unusual activities.
371 NERC: Windows Events by Users Displays a summary of access-related Windows events by source and target users.
372 NERC: Windows Group Members Added Displays all accounts added to groups on the Windows servers to ensure appropriate access.
373 NERC: Windows Group Members Deleted Displays all accounts removed from groups on the Windows servers to ensure appropriate access.