TIBCO LogLogic Reports for NERC
The following table lists the reports included in the LogLogic® Compliance Suite - NERC Edition.
| Serial Number | TIBCO LogLogic Report | Description |
|---|---|---|
| 1 | NERC: Account Activities on UNIX Servers | Displays all account activities on UNIX servers to ensure authorized and appropriate access. |
| 2 | NERC: Account Activities on Windows Servers | Displays all account activities on Windows servers to ensure authorized and appropriate access. |
| 3 | NERC: Accounts Changed on NetApp Filer | Displays all accounts changed on NetApp Filer to ensure authorized and appropriate access. |
| 4 | NERC: Accounts Changed on TIBCO Administrator | Displays all accounts changed on TIBCO Administrator to ensure authorized and appropriate access. |
| 5 | NERC: Accounts Changed on TIBCO ActiveMatrix Administrator | Displays all accounts changed on TIBCO ActiveMatrix Administrator to ensure authorized and appropriate access. |
| 6 | NERC: Accounts Changed on UNIX Servers | Displays all accounts changed on UNIX servers to ensure authorized and appropriate access. |
| 7 | NERC: Accounts Changed on Windows Servers | Displays all accounts changed on Windows servers to ensure authorized and appropriate access. |
| 8 | NERC: Accounts Created on NetApp Filer | Displays all accounts created on NetApp Filer to ensure authorized and appropriate access. |
| 9 | NERC: Accounts Created on NetApp Filer Audit | Displays all accounts created on NetApp Filer Audit to ensure authorized and appropriate access. |
| 10 | NERC: Accounts Created on Symantec Endpoint Protection | Displays all accounts created on Symantec Endpoint Protection to ensure authorized and appropriate access. |
| 11 | NERC: Accounts Created on TIBCO Administrator | Displays all accounts created on TIBCO Administrator to ensure authorized and appropriate access. |
| 12 | NERC: Accounts Created on TIBCO ActiveMatrix Administrator | Displays all accounts created on TIBCO ActiveMatrix Administrator to ensure authorized and appropriate access. |
| 13 | NERC: Accounts Created on Sidewinder | Displays all accounts created on Sidewinder to ensure authorized and appropriate access. |
| 14 | NERC: Accounts Created on UNIX Servers | Displays all accounts created on UNIX servers to ensure authorized and appropriate access. |
| 15 | NERC: Accounts Created on Windows Servers | Displays all accounts created on Windows servers to ensure authorized and appropriate access. |
| 16 | NERC: Accounts Deleted on NetApp Filer | Displays all accounts deleted on NetApp Filer to ensure authorized and appropriate access. |
| 17 | NERC: Accounts Deleted on NetApp Filer Audit | Displays all accounts deleted on NetApp Filer Audit to ensure authorized and appropriate access. |
| 18 | NERC: Accounts Deleted on Sidewinder | Displays all accounts deleted on Sidewinder to ensure authorized and appropriate access. |
| 19 | NERC: Accounts Deleted on Symantec Endpoint Protection | Displays all accounts deleted on Symantec Endpoint Protection to ensure authorized and appropriate access. |
| 20 | NERC: Accounts Deleted on TIBCO Administrator | Displays all accounts deleted on TIBCO Administrator to ensure authorized and appropriate access. |
| 21 | NERC: Accounts Deleted on TIBCO ActiveMatrix Administrator | Displays all accounts deleted on TIBCO ActiveMatrix Administrator to ensure authorized and appropriate access. |
| 22 | NERC: Accounts Deleted on UNIX Servers | Displays all accounts deleted on UNIX servers to ensure authorized and appropriate access. |
| 23 | NERC: Accounts Deleted on Windows Servers | Displays all accounts deleted on Windows servers to ensure authorized and appropriate access. |
| 24 | NERC: Active Connections for Cisco ASA | Displays all currently active firewall connections for Cisco ASA. |
| 25 | NERC: Active Connections for Cisco FWSM | Displays all currently active firewall connections for Cisco FWSM. |
| 26 | NERC: Active Connections for Cisco PIX | Displays all currently active firewall connections for Cisco PIX. |
| 27 | NERC: Active Directory System Changes | Displays changes made within Active Directory. |
| 28 | NERC: Active VPN Connections for Cisco VPN Concentrators | Displays all currently active VPN connections for Cisco VPN Concentrators. |
| 29 | NERC: Active VPN Connections for Nortel Contivity | Displays all currently active VPN connections for Nortel Contivity VPN devices. |
| 30 | NERC: Active VPN Connections for RADIUS | Displays all currently active VPN connections for RADIUS Acct Client. |
| 31 | NERC: Administrator Logins on Windows Servers | Displays all logins with the administrator account on Windows servers. |
| 32 | NERC: Allowed URLs by Source IPs | Displays successful access to URLs by source IP addresses. |
| 33 | NERC: Allowed URLs by Source IPs - F5 BIG-IP TMOS | Displays successful access to URLs by source IP addresses on F5 BIG-IP TMOS. |
| 34 | NERC: Allowed URLs by Source IPs - Microsoft IIS | Displays successful access to URLs by source IP addresses on Microsoft IIS. |
| 35 | NERC: Allowed URLs by Source Users - F5 BIG-IP TMOS | Displays successful access to URLs by source users on F5 BIG-IP TMOS. |
| 36 | NERC: Allowed URLs by Source Users - Microsoft IIS | Displays successful access to URLs by source users on Microsoft IIS. |
| 37 | NERC: Allowed URLs by Source Users | Displays successful access to URLs by source users. |
| 38 | NERC: Attackers by Service | Displays all attack source IP address and service ports. |
| 39 | NERC: Attackers by Service - Cisco IOS | Displays all attack source IP address and service ports by Cisco IOS. |
| 40 | NERC: Attackers by Service - FireEye MPS | Displays all attack source IP address and service ports by FireEye MPS. |
| 41 | NERC: Attackers by Service - ISS SiteProtector | Displays all attack source IP address and service ports by ISS SiteProtector. |
| 42 | NERC: Attackers by Service - SiteProtector | Displays all attack source IP address and service ports by SiteProtector. |
| 43 | NERC: Attackers by Service - Sourcefire Defense Center | Displays all attack source IP address and service ports by Sourcefire Defense Center. |
| 44 | NERC: Attackers by Signature - ISS SiteProtector | Displays all attack source IP address and signatures by ISS SiteProtector. |
| 45 | NERC: Attackers by Signature - SiteProtector | Displays all attack source IP address and signatures by SiteProtector. |
| 46 | NERC: Attackers by Signature | Displays all attack source IP address and signatures. |
| 47 | NERC: Attackers by Signature - Cisco IOS | Displays all attack source IP address and signatures by Cisco IOS. |
| 48 | NERC: Attackers by Signature - Sourcefire Defense Center | Displays all attack source IP address and signatures by Sourcefire Defense Center. |
| 49 | NERC: Attackers by Signature - FireEye MPS | Displays all attack source IP address and signatures by FireEye MPS. |
| 50 | NERC: Attacks Detected | Displays all IDS attacks detected against servers and applications. |
| 51 | NERC: Attacks Detected - Cisco IOS | Displays all IDS attacks detected against servers and applications by Cisco IOS. |
| 52 | NERC: Attacks Detected - HIPS | Displays all IPS attacks detected against servers and applications. |
| 53 | NERC: Attacks Detected - ISS SiteProtector | Displays all IDS attacks detected against servers and applications by ISS SiteProtector. |
| 54 | NERC: Attacks Detected - SiteProtector | Displays all IDS attacks detected against servers and applications by SiteProtector. |
| 55 | NERC: Attacks Detected - Sourcefire Defense Center | Displays all IDS attacks detected against servers and applications by Sourcefire Defense Center. |
| 56 | NERC: Bandwidth Usage by User | Displays users who are using the most bandwidth. |
| 57 | NERC: Blocked URLs by Source IPs | Displays URLs that have been blocked by source IP addresses. |
| 58 | NERC: Blocked URLs by Source IPs - F5 BIG-IP TMOS | Displays URLs that have been blocked by source IP addresses on F5 BIG-IP TMOS. |
| 59 | NERC: Blocked URLs by Source IPs - Microsoft IIS | Displays URLs that have been blocked by source IP addresses on Microsoft IIS. |
| 60 | NERC: Blocked URLs by Source Users | Displays URLs that have been blocked by source users. |
| 61 | NERC: Blocked URLs by Source Users - F5 BIG-IP TMOS | Displays URLs that have been blocked by source users on F5 BIG-IP TMOS. |
| 62 | NERC: Blocked URLs by Source Users - Microsoft IIS | Displays URLs that have been blocked by source users on Microsoft IIS. |
| 63 | NERC: Check Point Configuration Changes | Displays all Check Point audit events related to configuration changes. |
| 64 | NERC: Cisco ESA: Attacks by Event ID | Displays Cisco ESA attacks by Event ID. |
| 65 | NERC: Cisco ESA: Attacks Detected | Displays attacks detected by Cisco ESA. |
| 66 | NERC: Cisco ESA: Attacks by Threat Name | Displays Cisco ESA Attacks by threat name. |
| 67 | NERC: Cisco ESA: Scans | Displays scans using Cisco ESA. |
| 68 | NERC: Cisco ESA: Updated | Displays updates to Cisco ESA. |
| 69 | NERC: Cisco ISE, ACS Accounts Created | Displays all accounts created on Cisco ISE and Cisco SecureACS to ensure authorized and appropriate access. |
| 70 | NERC: Cisco ISE, ACS Accounts Removed | Displays all accounts removed on Cisco ISE and Cisco SecureACS to ensure authorized and appropriate access. |
| 71 | NERC: Cisco ISE, ACS Configuration Changes | Displays Cisco ISE and Cisco SecureACS configuration changes. |
| 72 | NERC: Cisco ISE, ACS Password Changes | Displays all password change activities on Cisco ISE and Cisco SecureACS to ensure authorized and appropriate access. |
| 73 | NERC: Cisco PIX, ASA, FWSM Policy Changed | Displays all configuration changes made to the Cisco PIX, ASA, and FWSM devices. |
| 74 | NERC: Cisco PIX, ASA, FWSM Failover Disabled | Displays all logs related to disabling Cisco PIX, ASA, and FWSM failover capability. |
| 75 | NERC: Cisco PIX, ASA, FWSM Failover Performed | Displays all logs related to performing a Cisco PIX, ASA, or FWSM failover. |
| 76 | NERC: Cisco PIX, ASA, FWSM Restarted | Displays all Cisco PIX, ASA, or FWSM restart activities to detect unusual activities. |
| 77 | NERC: Cisco Switch Policy Changes | Displays all configuration changes to the Cisco router and switch policies. |
| 78 | NERC: DB2 Database Configuration Changes | Displays DB2 database configuration changes. |
| 79 | NERC: DB2 Database Failed Logins | Displays all failed login attempts to review any access violations or unusual activity. |
| 80 | NERC: DB2 Database Successful Logins | Displays successful DB2 database logins. |
| 81 | NERC: DB2 Database User Additions and Deletions | Displays IBM DB2 Database events related to creation and deletion of database users. |
| 82 | NERC: Denied Connections by IP Addresses | Displays remote IP addresses with the most denied connections. |
| 83 | NERC: Denied Connections - Cisco IOS | Displays all connections that have been denied by the Cisco IOS devices. |
| 84 | NERC: Denied Connections - Cisco NXOS | Displays all connections that have been denied by the Cisco NXOS devices. |
| 85 | NERC: Denied Connections - F5 BIG-IP TMOS | Displays all connections that have been denied by the F5 BIG-IP TMOS devices. |
| 86 | NERC: Denied Connections - Cisco Router | Displays all connections that have been denied by the Cisco Router devices. |
| 87 | NERC: Denied Connections - Sidewinder | Displays all connections that have been denied by the Sidewinder devices. |
| 88 | NERC: Denied Connections - VMware vShield | Displays all connections that have been denied by the VMware vShield devices. |
| 89 | NERC: Denied Inbound Connections - Check Point | Displays all inbound connections that have been denied by the Check Point devices. |
| 90 | NERC: Denied Inbound Connections - Cisco ASA | Displays all inbound connections that have been denied by the Cisco ASA devices. |
| 91 | NERC: Denied Inbound Connections - Cisco FWSM | Displays all inbound connections that have been denied by the Cisco FWSM devices. |
| 92 | NERC: Denied Inbound Connections - Cisco PIX | Displays all inbound connections that have been denied by the Cisco PIX devices. |
| 93 | NERC: Denied Inbound Connections - Juniper Firewall | Displays all inbound connections that have been denied by the Juniper Firewalls. |
| 94 | NERC: Denied Outbound Connections - Check Point | Displays all outbound connections that have been denied by the Check Point. |
| 95 | NERC: Denied Outbound Connections - Cisco ASA | Displays all outbound connections that have been denied by the Cisco ASA. |
| 96 | NERC: Denied Outbound Connections - Cisco FWSM | Displays all outbound connections that have been denied by the Cisco FWSM. |
| 97 | NERC: Denied Outbound Connections - Cisco PIX | Displays all outbound connections that have been denied by the Cisco PIX. |
| 98 | NERC: Denied Outbound Connections - Juniper Firewall | Displays all outbound connections that have been denied by the Juniper Firewall. |
| 99 | NERC: DHCP Activities on Microsoft DHCP | Displays all DHCP activities on Microsoft DHCP Server. |
| 100 | NERC: DHCP Activities on VMware vShield | Displays all DHCP activities on VMware vShield Edge. |
| 101 | NERC: DNS Server Error | Displays all events when DNS server has errors. |
| 102 | NERC: Domain activities on Symantec Endpoint Protection | Displays all domain activities on Symantec Endpoint Protection. |
| 103 | NERC: Escalated Privilege Activities on Servers | Displays all privilege escalation activities performed on servers to ensure appropriate access. |
| 104 | NERC: ESX Accounts Activities | Displays all account activities on VMware ESX servers to ensure authorized and appropriate access. |
| 105 | NERC: ESX Accounts Created | Displays all accounts created on VMware ESX servers to ensure authorized and appropriate access. |
| 106 | NERC: ESX Accounts Deleted | Displays all accounts deleted on VMware ESX servers to ensure authorized and appropriate access. |
| 107 | NERC: ESX Failed Logins | Failed VMware ESX logins for known user. |
| 108 | NERC: ESX Group Activities | Displays all group activities on VMware ESX servers to ensure authorized and appropriate access. |
| 109 | NERC: ESX Kernel log daemon terminating | Displays all VMware ESX kernel log daemon terminating. |
| 110 | NERC: ESX Kernel logging Stop | Displays all VMware ESX kernel logging stops. |
| 111 | NERC: ESX Logins Failed Unknown User | Failed VMware ESX logins for unknown user. |
| 112 | NERC: ESX Logins Succeeded | Displays successful logins to VMware ESX to ensure only authorized personnel have access. |
| 113 | NERC: F5 BIG-IP TMOS Login Failed | Displays all F5 BIG-IP TMOS login events that have failed. |
| 114 | NERC: F5 BIG-IP TMOS Login Successful | Displays all F5 BIG-IP TMOS login events that have succeeded. |
| 115 | NERC: F5 BIG-IP TMOS Password Changes | Displays all password change activities on F5 BIG-IP TMOS to ensure authorized and appropriate access. |
| 116 | NERC: F5 BIG-IP TMOS Restarted | Displays all events when the F5 BIG-IP TMOS is restarted. |
| 117 | NERC: ESX Syslogd Restart | Displays all VMware ESX syslogd restarts. |
| 118 | NERC: Files Accessed on NetApp Filer Audit | Displays all files accessed on NetApp Filer Audit to ensure appropriate access. |
| 119 | NERC: Files Downloaded via Proxy - Microsoft IIS | Displays all proxy-based downloads to ensure authorized and appropriate access on Microsoft IIS. |
| 120 | NERC: Failed Logins | Displays all failed login attempts to review any access violations or unusual activity. |
| 121 | NERC: Files Accessed on Servers | Displays all files accessed on servers to ensure appropriate access. |
| 122 | NERC: Files Accessed through Juniper SSL VPN (Secure Access) | Displays all files Accessed through Juniper SSL VPN (Secure Access). |
| 123 | NERC: Files Accessed through PANOS | Displays all files Accessed through Palo Alto Networks. |
| 124 | NERC: Files Downloaded via Proxy | Displays all proxy-based downloads to ensure authorized and appropriate access. |
| 125 | NERC: Files Downloaded via Proxy - Blue Coat Proxy | Displays all proxy-based downloads to ensure authorized and appropriate access on Blue Coat Proxy. |
| 126 | NERC: Files Downloaded via Proxy - Cisco WSA | Displays all proxy-based downloads to ensure authorized and appropriate access on Cisco WSA. |
| 127 | NERC: Files Downloaded via the Web | Displays all web-based downloads to ensure authorized and appropriate access. |
| 128 | NERC: Files Downloaded via the Web - F5 BIG-IP TMOS | Displays all web-based downloads to ensure authorized and appropriate access on F5 BIG-IP TMOS. |
| 129 | NERC: Files Downloaded via the Web - Microsoft IIS | Displays all web-based downloads ensure authorized and appropriate access on Microsoft IIS. |
| 130 | NERC: Files Uploaded via Proxy | Displays all proxy-based uploads to ensure only authorized data can be uploaded. |
| 131 | NERC: Files Uploaded via Proxy - Blue Coat Proxy | Displays all proxy-based uploads to ensure only authorized data can be uploaded on Blue Coat Proxy. |
| 132 | NERC: Files Uploaded via Proxy - Cisco WSA | Displays all proxy-based uploads to ensure only authorized data can be uploaded on Cisco WSA. |
| 133 | NERC: Files Uploaded via Proxy - Microsoft IIS | Displays all proxy-based uploads to ensure only authorized data can be uploaded on Microsoft IIS. |
| 134 | NERC: Files Uploaded via the Web | Displays all web-based uploads to ensure only authorized data can be uploaded. |
| 135 | NERC: Files Uploaded via the Web - F5 BIG-IP TMOS | Displays all web-based uploads to ensure only authorized data can be uploaded on F5 BIG-IP TMOS. |
| 136 | NERC: Files Uploaded via the Web - Microsoft IIS | Displays all web-based uploads to ensure only authorized data can be uploaded on Microsoft IIS. |
| 137 | NERC: FortiOS: Attacks Detected | Displays attacks detected by FortiOS. |
| 138 | NERC: FortiOS: Attacks by Event ID | Displays FortiOS attacks by Event ID. |
| 139 | NERC: FortiOS: Attacks by Threat Name | Displays FortiOS attacks by threat name. |
| 140 | NERC: FortiOS DLP Attacks Detected | Displays all DLP attacks detected by FortiOS. |
| 141 | NERC: Group Activities on NetApp Filer Audit | Displays all group activities on NetApp Filer Audit to ensure authorized and appropriate access. |
| 142 | NERC: Group Activities on Symantec Endpoint Protection | Displays all group activities on Symantec Endpoint Protection to ensure authorized and appropriate access. |
| 143 | NERC: Group Activities on TIBCO ActiveMatrix Administrator | Displays all group activities on TIBCO ActiveMatrix Administrator to ensure authorized and appropriate access. |
| 144 | NERC: Group Activities on UNIX Servers | Displays all group activities on UNIX servers to ensure authorized and appropriate access. |
| 145 | NERC: Group Activities on Windows Servers | Displays all group activities on Windows servers to ensure authorized and appropriate access. |
| 146 | NERC: Guardium SQL Guard Audit Configuration Changes | Displays all configuration changes on the Guardium SQL Guard Audit database. |
| 147 | NERC: Guardium SQL Guard Audit Logins | Displays all login attempts to the Guardium SQL Server Audit database. |
| 148 | NERC: Guardium SQL Guard Configuration Changes | Displays all configuration changes on the Guardium SQL Guard database. |
| 149 | NERC: Guardium SQL Guard Logins | Displays all login attempts to the Guardium SQL Server database. |
| 150 | NERC: HP NonStop Audit Configuration Changes | Displays all audit configuration changes on HP NonStop. |
| 151 | NERC: HP NonStop Audit Login Failed | Displays all HP NonStop Audit login events that have failed. |
| 152 | NERC: HP NonStop Audit Login Successful | Displays all HP NonStop Audit login events that have succeeded. |
| 153 | NERC: HP NonStop Audit Object Access | Displays HP NonStop Audit events related to object access. |
| 154 | NERC: HP NonStop Audit Object Changes | Displays HP NonStop Audit events related to object changes. |
| 155 | NERC: HP NonStop Audit Permissions Changed | Displays all permission modification activities on HP NonStop Audit to ensure authorized access. |
| 156 | NERC: Files Accessed through Pulse Connect Secure | Displays all files accessed through Pulse Connect Secure. |
| 157 | NERC: i5/OS Access Control List Modifications | Displays i5/OS events related to access control list modification. |
| 158 | NERC: i5/OS Audit Configuration Changes | Displays all audit configuration changes on i5/OS. |
| 159 | NERC: i5/OS DST Password Reset | Displays i5/OS events related to the reset of the DST (Dedicated Service Tools) password. |
| 160 | NERC: i5/OS Object Access | Displays i5/OS events related to object access. |
| 161 | NERC: i5/OS Restore Events | Displays i5/OS events related to object, program, and profile restoration. |
| 162 | NERC: i5/OS System Management Changes | Displays i5/OS events related to system management changes. |
| 163 | NERC: i5/OS User Profile Creation, Modification, or Restoration | Displays i5/OS events related to user profile creation, modification, or restoration. |
| 164 | NERC: Juniper Firewall HA State Changed | Displays all Juniper Firewall failover state change events. |
| 165 | NERC: Juniper Firewall Policy Changed | Displays all configuration changes to the Juniper Firewall policies. |
| 166 | NERC: Juniper Firewall Policy Out of Sync | Displays events indicating that the Juniper Firewall's HA policies are out of sync. |
| 167 | NERC: Juniper Firewall Reset Accepted | Displays events indicating that the Juniper Firewall is reset to its factory default state. |
| 168 | NERC: Juniper Firewall Reset Imminent | Displays events that indicate the Juniper Firewall will be reset to its factory default state. |
| 169 | NERC: FireEye MPS: Attacks by Event ID | Displays FireEye MPS attacks by Event ID. |
| 170 | NERC: FireEye MPS: Attacks by Threat Name | Displays FireEye MPS attacks by threat name. |
| 171 | NERC: FireEye MPS: Attacks Detected | Displays attacks detected by FireEye MPS. |
| 172 | NERC: Last Activities Performed by Administrators | Displays the latest activities performed by administrators and root users to ensure appropriate access. |
| 173 | NERC: Last Activities Performed by All Users | Displays the latest activities performed by all users to ensure appropriate access. |
| 174 | NERC: Logins by Authentication Type | Displays all logins categorized by the authentication type. |
| 175 | NERC: LogLogic DSM Configuration Changes | Displays all configuration changes on the LogLogic DSM database. |
| 176 | NERC: LogLogic DSM Logins | Displays all login attempts to the LogLogic DSM database. |
| 177 | NERC: LogLogic Management Center Account Activities | Displays all account activities on LogLogic management center to ensure authorized and appropriate access. |
| 178 | NERC: LogLogic Management Center Login | Displays all login events to the LogLogic management center. |
| 179 | NERC: LogLogic Management Center Password Changes | Displays all password change activities on LogLogic management center to ensure authorized and appropriate access. |
| 180 | NERC: LogLogic Management Center Restore Activities | Displays all restore activities on LogLogic management center. |
| 181 | NERC: LogLogic Universal Collector Configuration Changes | Displays LogLogic universal collector configuration changes. |
| 182 | NERC: McAfee Antivirus: Attacks Detected | Displays attacks detected by McAfee AntiVirus. |
| 183 | NERC: McAfee AntiVirus: Attacks by Event ID | Displays McAfee AntiVirus attacks by Event ID. |
| 184 | NERC: McAfee AntiVirus: Attacks by Threat Name | Displays McAfee AntiVirus Attacks by threat name. |
| 185 | NERC: Microsoft Operations Manager - Windows Accounts Activities | Displays all account activities on Windows servers to ensure authorized and appropriate access. |
| 186 | NERC: Microsoft Operations Manager - Windows Accounts Changed | Displays all accounts changed on Windows servers to ensure authorized and appropriate access. |
| 187 | NERC: Microsoft Operations Manager - Windows Accounts Created | Displays all accounts created on Windows servers to ensure authorized and appropriate access. |
| 188 | NERC: Microsoft Operations Manager - Windows Accounts Enabled | Displays all accounts enabled on Windows servers to ensure authorized and appropriate access. |
| 189 | NERC: Microsoft Operations Manager - Windows Events by Users | Displays a summary of access-related Windows events by source and target users. |
| 190 | NERC: Microsoft Operations Manager - Windows Password Changes | Displays all password change activities on Windows servers to ensure authorized and appropriate access. |
| 191 | NERC: Microsoft Operations Manager - Windows Permissions Modified | Displays all permission modification activities on Windows servers to ensure authorized access. |
| 192 | NERC: Microsoft Operations Manager - Windows Policies Modified | Displays all policy modification activities on Windows servers to ensure authorized and appropriate access. |
| 193 | NERC: Microsoft Sharepoint Content Deleted | Displays all events when content is deleted from Microsoft SharePoint. |
| 194 | NERC: Microsoft Sharepoint Content Updates | Displays all events when content is updated within Microsoft SharePoint. |
| 195 | NERC: Microsoft Sharepoint Permissions Changed | Displays all user/group permission events to Microsoft SharePoint. |
| 196 | NERC: Microsoft Sharepoint Policy Add, Remove, or Modify | Displays all events when a Microsoft SharePoint policy is added, removed, or modified. |
| 197 | NERC: Microsoft SQL Server Configuration Changes | Displays Microsoft SQL database configuration changes. |
| 198 | NERC: Microsoft SQL Server Database Failed Logins | Displays failed Microsoft SQL Server database logins. |
| 199 | NERC: Microsoft SQL Server Database Successful Logins | Displays successful Microsoft SQL Server database logins. |
| 200 | NERC: Microsoft SQL Server Database Permission Events | Displays events related to Microsoft SQL Server database permission modifications. |
| 201 | NERC: Microsoft SQL Server Database User Additions and Deletions | Displays Microsoft SQL Server events related to creation and deletion of database users. |
| 202 | NERC: Microsoft SQL Server Password Changes | Displays password changes for Microsoft SQL Server database accounts. |
| 203 | NERC: Most Active Ports Through Firewall - Check Point | Displays the most active ports used through the Check Point firewall. |
| 204 | NERC: Most Active Ports Through Firewall - Cisco ASA | Displays the most active ports used through the Cisco ASA firewall. |
| 205 | NERC: Most Active Ports Through Firewall - Cisco FWSM | Displays the most active ports used through the Cisco FWSM firewall. |
| 206 | NERC: Most Active Ports Through Firewall - Cisco PIX | Displays the most active ports used through the Cisco PIX firewall. |
| 207 | NERC: Most Active Ports Through Firewall - Fortinet | Displays the most active ports used through the Fortinet firewall. |
| 208 | NERC: Most Active Ports Through Firewall - Juniper Firewall | Displays the most active ports used through the Juniper Firewall. |
| 209 | NERC: Most Active Ports Through Firewall - Nortel | Displays the most active ports used through the Nortel firewall. |
| 210 | NERC: NetApp Filer Accounts Locked | Displays all accounts locked out of NetApp Filer to detect access violations or unusual activities. |
| 211 | NERC: NetApp Filer Audit Accounts Enabled | Displays all accounts enabled on NetApp Filer Audit to ensure authorized and appropriate access. |
| 212 | NERC: NetApp Filer Audit Group Members Added | Displays all accounts added to groups on NetApp Filer Audit to ensure appropriate access. |
| 213 | NERC: NetApp Filer Audit Group Members Deleted | Displays all accounts removed from groups on NetApp Filer Audit to ensure appropriate access. |
| 214 | NERC: NetApp Filer File Activity | Displays all file activities on NetApp Filer. |
| 215 | NERC: NetApp Filer Login Failed | Displays all NetApp Filer login events that have failed. |
| 216 | NERC: NetApp Filer Login Successful | Displays all NetApp Filer login events that have succeeded. |
| 217 | NERC: NetApp Filer Password Changes | Displays all password change activities on NetApp Filer to ensure authorized and appropriate access. |
| 218 | NERC: NetApp Filer Audit Login Failed | Displays all NetApp Filer Audit login events that have failed. |
| 219 | NERC: NetApp Filer Audit Login Successful | Displays all NetApp Filer Audit login events that have succeeded. |
| 220 | NERC: NetApp Filer Audit Policies Modified | Displays all policy modification activities on NetApp Filer Audit to ensure authorized and appropriate access. |
| 221 | NERC: Novell eDirectory Password Changes | Password changes on Novell eDirectory. |
| 222 | NERC: Oracle Database Configuration Changes | Displays Oracle database configuration changes. |
| 223 | NERC: Oracle Database Failed Logins | Displays failed login attempts to the Oracle database. |
| 224 | NERC: Oracle Database Successful Logins | Displays successful Oracle database login attempts. |
| 225 | NERC: Oracle Database Permission Events | Displays events related to Oracle Server database role and privilege management. |
| 226 | NERC: Oracle Database User Additions and Deletions | Displays Oracle database events related to creation and deletion of database users. |
| 227 | NERC: Password Changes on Windows Servers | Displays all password change activities on Windows servers to ensure authorized and appropriate access. |
| 228 | NERC: PANOS: Attacks Detected | Displays attacks detected by Palo Alto Networks. |
| 229 | NERC: PANOS: Attacks by Event ID | Displays Palo Alto Networks attacks by Event ID. |
| 230 | NERC: PANOS: Attacks by Threat Name | Displays Palo Alto Networks attacks by threat name. |
| 231 | NERC: Periodic Review of Log Reports | Displays all review activities performed by administrators to ensure review for any access violations. |
| 232 | NERC: Periodic Review of User Access Logs | Displays all review activities performed by administrators to ensure review for any access violations. |
| 233 | NERC: Permissions Modified on Windows Servers | Displays all permission modification activities on Windows Servers to ensure authorized access. |
| 234 | NERC: Policies Modified on Windows Servers | Displays all policy modification activities on Windows servers to ensure authorized and appropriate access. |
| 235 | NERC: Ports Allowed Access - Check Point | Displays all connections passed through the Check Point by port. |
| 236 | NERC: Ports Allowed Access - Cisco ASA | Displays all connections passed through the Cisco ASA by port. |
| 237 | NERC: Ports Allowed Access - Cisco IOS | Displays all connections passed through the Cisco IOS by port. |
| 238 | NERC: Ports Allowed Access - Cisco FWSM | Displays all connections passed through the Cisco FWSM by port. |
| 239 | NERC: Ports Allowed Access - Cisco Netflow | Displays all connections passed through the Cisco Netflow by port. |
| 240 | NERC: Ports Allowed Access - Cisco PIX | Displays all connections passed through the Cisco PIX by port. |
| 241 | NERC: Ports Allowed Access - F5 BIG-IP TMOS | Displays all connections passed through the F5 BIG-IP TMOS by port. |
| 242 | NERC: Ports Allowed Access - Fortinet | Displays all connections passed through the Fortinet by port. |
| 243 | NERC: Ports Allowed Access - Juniper Firewall | Displays all connections passed through the Juniper Firewall by port. |
| 244 | NERC: Ports Allowed Access - Juniper JunOS | Displays all connections passed through the Juniper JunOS by port. |
| 245 | NERC: Ports Allowed Access - Juniper RT Flow | Displays all connections passed through the Juniper RT Flow by port. |
| 246 | NERC: Ports Allowed Access - Nortel | Displays all connections passed through the Nortel by port. |
| 247 | NERC: Ports Allowed Access - PANOS | Displays all connections passed through the Palo Alto Networks by port. |
| 248 | NERC: Ports Allowed Access - Sidewinder | Displays all connections passed through the Sidewinder by port. |
| 249 | NERC: Ports Allowed Access - VMware vShield | Displays all connections passed through the VMware vShield by port. |
| 250 | NERC: Ports Denied Access - Check Point | Displays the applications that have been denied access the most by the Check Point. |
| 251 | NERC: Ports Denied Access - Cisco ASA | Displays the applications that have been denied access the most by the Cisco ASA. |
| 252 | NERC: Ports Denied Access - Cisco FWSM | Displays the applications that have been denied access the most by the Cisco FWSM. |
| 253 | NERC: Ports Denied Access - Cisco IOS | Displays the applications that have been denied access the most by the Cisco IOS. |
| 254 | NERC: Ports Denied Access - Cisco PIX | Displays the applications that have been denied access the most by the Cisco PIX. |
| 255 | NERC: Ports Denied Access - Cisco Router | Displays the applications that have been denied access the most by the Cisco Router. |
| 256 | NERC: Ports Denied Access - F5 BIG-IP TMOS | Displays the applications that have been denied access the most by the F5 BIG-IP TMOS. |
| 257 | NERC: Ports Denied Access - Fortinet | Displays the applications that have been denied access the most by the Fortinet. |
| 258 | NERC: Ports Denied Access - Juniper Firewall | Displays the applications that have been denied access the most by the Juniper Firewall. |
| 259 | NERC: Ports Denied Access - Juniper JunOS | Displays the applications that have been denied access the most by the Juniper JunOS. |
| 260 | NERC: Ports Denied Access - Juniper RT Flow | Displays the applications that have been denied access the most by the Juniper RT Flow. |
| 261 | NERC: Ports Denied Access - Nortel | Displays the applications that have been denied access the most by the Nortel. |
| 262 | NERC: Ports Denied Access - PANOS | Displays the applications that have been denied access the most by the Palo Alto Networks. |
| 263 | NERC: Ports Denied Access - Sidewinder | Displays the applications that have been denied access the most by the Sidewinder. |
| 264 | NERC: Ports Denied Access - VMware vShield | Displays the applications that have been denied access the most by the VMware vShield Edge. |
| 265 | NERC: RACF Accounts Created | Displays all accounts created on RACF servers to ensure authorized and appropriate access. |
| 266 | NERC: RACF Accounts Deleted | Displays all accounts deleted on RACF servers to ensure authorized and appropriate access. |
| 267 | NERC: RACF Accounts Modified | Displays all events when a network user profile is modified. |
| 268 | NERC: RACF Failed Logins | Displays all failed login attempts to review any access violations or unusual activity. |
| 269 | NERC: RACF Files Accessed | Displays all files accessed on RACF servers to ensure appropriate access. |
| 270 | NERC: RACF Password Changed | Displays all password change activities on RACF servers to ensure authorized and appropriate access. |
| 271 | NERC: RACF Permissions Changed | Displays all permission modification activities on RACF to ensure authorized access. |
| 272 | NERC: RACF Successful Logins | Displays successful logins to ensure only authorized personnel have access. |
| 273 | NERC: Root Logins | Displays root logins. |
| 274 | NERC: Sensors Generating Alerts | Displays the IDS sensors that generated the most alerts. |
| 275 | NERC: Sensors Generating Alerts - FireEye MPS | Displays the IDS sensors that generated the most alerts by FireEye MPS. |
| 276 | NERC: Sensors Generating Alerts - Cisco IOS | Displays the IDS sensors that generated the most alerts by Cisco IOS. |
| 277 | NERC: Sensors Generating Alerts - ISS SiteProtector | Displays the IDS sensors that generated the most alerts by ISS SiteProtector. |
| 278 | NERC: Sensors Generating Alerts - SiteProtector | Displays the IDS sensors that generated the most alerts by SiteProtector. |
| 279 | NERC: Sensors Generating Alerts - Sourcefire Defense Center | Displays the IDS sensors that generated the most alerts by Sourcefire Defense Center. |
| 280 | NERC: Sidewinder Configuration Changes | Displays Sidewinder configuration changes. |
| 281 | NERC: Successful Logins | Displays successful logins to ensure only authorized personnel have access. |
| 282 | NERC: Sybase ASE Database Configuration Changes | Displays configuration changes to the Sybase database. |
| 283 | NERC: Sybase ASE Database User Additions and Deletions | Displays Sybase database events related to creation and deletion of database users. |
| 284 | NERC: Sybase ASE Failed Logins | Displays failed Sybase ASE database logins. |
| 285 | NERC: Sybase ASE Successful Logins | Displays successful Sybase ASE database logins. |
| 286 | NERC: Symantec AntiVirus: Attacks by Event ID | Displays all Symantec AntiVirus Attacks by Event ID events. |
| 287 | NERC: Symantec AntiVirus: Attacks by Threat Name | Displays Symantec AntiVirus attacks by threat name. |
| 288 | NERC: Symantec AntiVirus: Attacks Detected | Displays attacks detected by Symantec AntiVirus. |
| 289 | NERC: Symantec AntiVirus: Scans | Displays scans using Symantec AntiVirus. |
| 290 | NERC: Symantec AntiVirus: Updated | Displays updates to Symantec AntiVirus. |
| 291 | NERC: Symantec Endpoint Protection: Attacks Detected | Displays attacks detected by Symantec Endpoint Protection. |
| 292 | NERC: Symantec Endpoint Protection: Attacks by Threat Name | Displays Symantec Endpoint Protection attacks by threat name. |
| 293 | NERC: Symantec Endpoint Protection Configuration Changes | Displays Symantec Endpoint Protection configuration changes. |
| 294 | NERC: Symantec Endpoint Protection Password Changes | Displays all password change activities on Symantec Endpoint Protection to ensure authorized and appropriate access. |
| 295 | NERC: Symantec Endpoint Protection Policy Add, Remove, or Modify | Displays all events when a Symantec Endpoint Protection policy is added, removed, or modified. |
| 296 | NERC: Symantec Endpoint Protection: Scans | Displays scans using Symantec Endpoint Protection. |
| 297 | NERC: Symantec Endpoint Protection: Updated | Displays updates to Symantec Endpoint Protection. |
| 298 | NERC: TIBCO ActiveMatrix Administrator Failed Logins | Displays all TIBCO ActiveMatrix Administrator login events that have failed. |
| 299 | NERC: TIBCO ActiveMatrix Administrator Permission Changes | Displays all TIBCO ActiveMatrix Administrator permission modifications. |
| 300 | NERC: TIBCO ActiveMatrix Administrator Successful Logins | Displays successful logins to TIBCO ActiveMatrix Administrator to ensure only authorized personnel have access. |
| 301 | NERC: TIBCO Administrator Password Changes | Displays all password change activities on TIBCO Administrator to ensure authorized and appropriate access. |
| 302 | NERC: TIBCO Administrator Permission Changes | Displays events related to TIBCO Administrator permission modifications. |
| 303 | NERC: TrendMicro Control Manager: Attacks Detected | Displays attacks detected by TrendMicro Control Manager. |
| 304 | NERC: TrendMicro Control Manager: Attacks Detected by Threat Name | Displays attacks detected by TrendMicro Control Manager by threat name. |
| 305 | NERC: TrendMicro OfficeScan: Attacks Detected | Displays attacks detected by TrendMicro OfficeScan. |
| 306 | NERC: TrendMicro OfficeScan: Attacks Detected by Threat Name | Displays attacks detected by TrendMicro OfficeScan by threat name. |
| 307 | NERC: Trusted Domain Created on Windows Servers | Displays all trusted domains created on Windows servers to ensure authorized and appropriate access. |
| 308 | NERC: Trusted Domain Deleted on Windows Servers | Displays all trusted domains deleted on Windows servers to ensure authorized and appropriate access. |
| 309 | NERC: Unauthorized Logins | Displays all logins from unauthorized users to ensure appropriate access to data. |
| 310 | NERC: Unencrypted Logins | Displays all unencrypted logins to ensure secure access to data. |
| 311 | NERC: Unix Password Changes | Password changes on UNIX servers. |
| 312 | NERC: Users Created on Servers | Displays all users created on servers to ensure authorized and appropriate access. |
| 313 | NERC: Users Removed from Servers | Displays all users removed from servers to ensure timely removal of terminated users. |
| 314 | NERC: Users Using the Proxies | Displays users who have been surfing the web through the proxy servers. |
| 315 | NERC: Users Using the Proxies - Blue Coat Proxy | Displays users who have been surfing the web through the proxy servers on Blue Coat Proxy. |
| 316 | NERC: Users Using the Proxies - Cisco WSA | Displays users who have been surfing the web through the proxy servers on Cisco WSA. |
| 317 | NERC: Users Using the Proxies - Microsoft IIS | Displays users who have been surfing the web through the proxy servers on Microsoft IIS. |
| 318 | NERC: vCenter Change Attributes | Modification of VMware vCenter and VMware ESX properties. |
| 319 | NERC: vCenter Data Move | Entity is moved within the VMware vCenter infrastructure. |
| 320 | NERC: vCenter Datastore Events | Displays create, modify, and delete datastore events on VMware vCenter. |
| 321 | NERC: vCenter Failed Logins | Failed logins to the VMware vCenter console. |
| 322 | NERC: vCenter Modify Firewall Policy | Displays changes to the VMware ESX allowed services firewall policy. |
| 323 | NERC: vCenter Orchestrator Change Attributes | Modification of VMware vCenter Orchestrator properties. |
| 324 | NERC: vCenter Orchestrator Datastore Events | Displays create, modify, and delete datastore events on VMware vCenter Orchestrator. |
| 325 | NERC: vCenter Orchestrator Data Move | Entity is moved within the VMware vCenter Orchestrator infrastructure. |
| 326 | NERC: vCenter Orchestrator Failed Logins | Displays all failed logins for VMware vCenter Orchestrator. |
| 327 | NERC: vCenter Orchestrator Virtual Machine Created | Virtual machine is created from VMware vCenter Orchestrator. |
| 328 | NERC: vCenter Orchestrator Virtual Machine Deleted | Virtual machine is deleted from VMware vCenter Orchestrator. |
| 329 | NERC: vCenter Orchestrator Virtual Machine Shutdown | Virtual machine is shut down or paused from VMware vCenter Orchestrator console. |
| 330 | NERC: vCenter Orchestrator Virtual Machine Started | Virtual machine is started or resumed from VMware vCenter Orchestrator console. |
| 331 | NERC: vCenter Orchestrator vSwitch Added, Changed or Removed | vSwitch is added, modified or removed from VMware vCenter Orchestrator console. |
| 332 | NERC: vCenter Resource Usage Change | Resources have changed on VMware vCenter. |
| 333 | NERC: vCenter Restart ESX Services | VMware vCenter restarted services running on VMware ESX Server. |
| 334 | NERC: vCenter Shutdown or Restart of ESX Server | VMware ESX Server is shutdown or restarted from VMware vCenter console. |
| 335 | NERC: vCenter Successful Logins | Successful logins to the VMware vCenter console. |
| 336 | NERC: vCenter User Permission Change | A permission role is added, changed, removed, or applied to a user on VMware vCenter server. |
| 337 | NERC: vCenter Virtual Machine Created | Virtual machine is created from VMware vCenter console. |
| 338 | NERC: vCenter Virtual Machine Deleted | Virtual machine is deleted or removed from VMware vCenter console. |
| 339 | NERC: vCenter Virtual Machine Shutdown | Virtual machine is shutdown or paused from VMware vCenter console. |
| 340 | NERC: vCenter Virtual Machine Started | Virtual machine is started or resumed from VMware vCenter console. |
| 341 | NERC: vCenter vSwitch Added, Changed or Removed | vSwitch on VMware ESX server is added, modified or removed from the VMware vCenter console. |
| 342 | NERC: vCloud Failed Logins | Failed logins to the VMware vCloud Director console. |
| 343 | NERC: vCloud Organization Created | VMware vCloud Director organization created events. |
| 344 | NERC: vCloud Organization Deleted | VMware vCloud Director organization deleted events. |
| 345 | NERC: vCloud Organization Modified | VMware vCloud Director organization modified events. |
| 346 | NERC: vCloud Successful Logins | Successful logins to the VMware vCloud Director console. |
| 347 | NERC: vCloud User Created | VMware vCloud Director user-created events. |
| 348 | NERC: vCloud User Deleted or Removed | VMware vCloud Director users have been deleted or removed from the system. |
| 349 | NERC: vCloud vApp Created, Modified, or Deleted | VMware vCloud Director vApp created, deleted, and modified events. |
| 350 | NERC: vCloud vDC Created, Modified, or Deleted | VMware vCloud Director virtual datacenter created, modified, or deleted events. |
| 351 | NERC: VPN Connections by Users | Displays users who are made the most connections. |
| 352 | NERC: VPN Denied Connections by Users | Displays users with the most number of denied connections. |
| 353 | NERC: VPN Sessions by Destination IPs | Displays all VPN sessions categorized by destination IP addresses. |
| 354 | NERC: VPN Sessions by Source IPs | Displays all VPN sessions categorized by source IP addresses. |
| 355 | NERC: VPN Sessions by Users | Displays all VPN sessions categorized by authenticated users. |
| 356 | NERC: VPN Users Accessing Corporate Network | Displays all users logging in to the corporate network via Virtual Private Network to ensure appropriate access. |
| 357 | NERC: vShield Edge Configuration Changes | Displays changes to the VMware vShield Edge policies. |
| 358 | NERC: vShield Risky Firewall Traffic | Displays all allowed VMware vShield Edge firewall traffic that are considered risky. |
| 359 | NERC: Web Access from All Users | Displays all web-based access by all users for regular reviews and updates. |
| 360 | NERC: Web Access from All Users - Fortinet | Displays all web-based access by all users for regular reviews and updates on Fortinet. |
| 361 | NERC: Web Access from All Users - F5 BIG-IP TMOS | Displays all web-based access by all users for regular reviews and updates on F5 BIG-IP TMOS. |
| 362 | NERC: Web Access from All Users - Microsoft IIS | Displays all web-based access by all users for regular reviews and updates on Microsoft IIS. |
| 363 | NERC: Web Access from All Users - PANOS | Displays all web-based access by all users for regular reviews and updates on Palo Alto Networks. |
| 364 | NERC: Web Access to Applications - F5 BIG-IP TMOS | Displays all web-based access to applications to ensure appropriate and authorized access on F5 BIG-IP TMOS. |
| 365 | NERC: Web Access to Applications - Fortinet | Displays all web-based access to applications to ensure appropriate and authorized access on Fortinet. |
| 366 | NERC: Web Access to Applications - Microsoft IIS | Displays all web-based access to applications to ensure appropriate and authorized access on Microsoft IIS. |
| 367 | NERC: Web Access to Applications - PANOS | Displays all web-based access to applications to ensure appropriate and authorized access on Palo Alto Networks. |
| 368 | NERC: Web Access to Applications | Displays all web-based access to applications to ensure appropriate and authorized access. |
| 369 | NERC: Windows Accounts Enabled | Displays all accounts enabled on Windows servers to ensure authorized and appropriate access. |
| 370 | NERC: Windows Accounts Locked | Displays all accounts locked out of Windows servers to detect access violations or unusual activities. |
| 371 | NERC: Windows Events by Users | Displays a summary of access-related Windows events by source and target users. |
| 372 | NERC: Windows Group Members Added | Displays all accounts added to groups on the Windows servers to ensure appropriate access. |
| 373 | NERC: Windows Group Members Deleted | Displays all accounts removed from groups on the Windows servers to ensure appropriate access. |
Copyright © Cloud Software Group, Inc. All rights reserved.
