TIBCO LogLogic Reports and Filter Bloks for PCI
The following table lists the reports and filter bloks included in LogLogic Compliance Suite - PCI Edition.
| # | Real-Time Report Name | Advanced Filter Blok Name | Description | Compliance Mapping |
|---|---|---|---|---|
| 1 | PCI: Account Activities on UNIX Servers | PCI_Account_Activities_on_ UNIX_Servers |
Displays all accounts activities on UNIX servers to ensure authorized and appropriate access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.8, 9.10, 10.8, 11.6 |
| 2 | PCI: Account Activities on Windows Servers | PCI_Account_Activities_on_ Windows_Servers |
Displays all accounts activities on Windows servers to ensure authorized and appropriate access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.8, 9.10, 10.8, 11.6 |
| 3 | PCI: Accounts Changed on NetApp Filer | PCI_Accounts_Changed_ on_NetApp_Filer |
Displays all accounts changed on NetApp Filer to ensure authorized and appropriate access. |
1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.8, 11.6 |
| 4 | PCI: Accounts Changed on TIBCO ActiveMatrix Administrator | PCI_Accounts_Changed_ on_TIBCO_ActiveMatrix_Administrator |
Displays all accounts changed on TIBCO ActiveMatrix Administrator to ensure authorized and appropriate access. |
1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.8, 11.6 |
| 5 | PCI: Accounts Changed on TIBCO Administrator | PCI_Accounts_Changed_on_TIBCO_Administrator | Displays all accounts changed on TIBCO Administrator to ensure authorized and appropriate access. |
1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.8, 11.6 |
| 6 | PCI: Accounts Changed on UNIX Servers | PCI_Accounts_Changed_on_UNIX_Servers | Displays all accounts changed on UNIX servers to ensure authorized and appropriate access. |
1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.8, 11.6 |
| 7 | PCI: Accounts Changed on Windows Servers | PCI_Accounts_Changed_ on_Windows_Servers |
Displays all accounts changed on Windows servers to ensure authorized and appropriate access. |
1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.8, 11.6 |
| 8 | PCI: Accounts Created on NetApp Filer | PCI_Accounts_Created_on_NetApp_Filer | Displays all accounts created on NetApp Filer to ensure authorized and appropriate access. |
1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.8, 11.6 |
| 9 | PCI: Accounts Created on NetApp Filer Audit | PCI_Accounts_Created_on_NetApp_Filer_Audit | Displays all accounts created on NetApp Filer Audit to ensure authorized and appropriate access. |
1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.8, 11.6 |
| 10 | PCI: Accounts Created on Symantec Endpoint Protection | PCI_Accounts_Created_ on_Symantec_Endpoint_Protection |
Displays all accounts created on Symantec Endpoint Protection to ensure authorized and appropriate access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.8, 11.6 |
| 11 | PCI: Accounts Created on TIBCO ActiveMatrix Administrator | PCI_Accounts_Created_on _TIBCO_ActiveMatrix_Administrator |
Displays all accounts created on TIBCO ActiveMatrix Administrator to ensure authorized and appropriate access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.8, 11.6 |
| 12 | PCI: Accounts Created on TIBCO Administrator | PCI_Accounts_ Created_on_TIBCO_Administrator |
Displays all accounts created on TIBCO Administrator to ensure authorized and appropriate access. |
1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.8, 11.6 |
| 13 | PCI: Accounts Created on UNIX Servers | PCI_Accounts_Created_on_UNIX_Servers | Displays all accounts created on UNIX servers to ensure authorized and appropriate access. |
1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.8, 11.6 |
| 14 | PCI: Accounts Created on Windows Servers | PCI_Accounts_Created_on_Windows_Servers | Displays all accounts created on Windows servers to ensure authorized and appropriate access. |
1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.8, 11.6 |
| 15 | PCI: Accounts Deleted on NetApp Filer | PCI_Accounts_ Deleted_on_NetApp_Filer |
Displays all accounts deleted on NetApp Filer to ensure authorized and appropriate access. |
1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.5.4, 8.8, 9.10, 10.8, 11.6 |
| 16 | PCI: Accounts Deleted on NetApp Filer Audit | PCI_Accounts_Deleted_ on_NetApp_Filer_Audit |
Displays all accounts deleted on NetApp Filer Audit to ensure authorized and appropriate access. |
1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.5.4, 8.8, 9.10, 10.8, 11.6 |
| 17 | PCI: Accounts Deleted on Symantec Endpoint Protection | PCI_Accounts_Deleted_ on_Symantec_Endpoint_Protection |
Displays all accounts deleted on Symantec Endpoint Protection to ensure authorized and appropriate access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.5.4, 8.8, 9.10, 10.8, 11.6 |
| 18 | PCI: Accounts Deleted on TIBCO ActiveMatrix Administrator | PCI_Accounts_ Deleted_on_TIBCO_ActiveMatrix_Administrator |
Displays all accounts deleted on TIBCO ActiveMatrix Administrator to ensure authorized and appropriate access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.5.4, 8.8, 9.10, 10.8, 11.6 |
| 19 | PCI: Accounts Deleted on TIBCO Administrator | PCI_Accounts_Deleted_ on_TIBCO_Administrator |
Displays all accounts deleted on TIBCO Administrator to ensure authorized and appropriate access. |
1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.5.4, 8.8, 9.10, 10.8, 11.6 |
| 20 | PCI: Accounts Deleted on UNIX Servers | PCI_Accounts_Deleted_on_UNIX_Servers | Displays all accounts deleted on UNIX servers to ensure authorized and appropriate access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.5.4, 8.8, 9.10, 10.8, 11.6 |
| 21 | PCI: Accounts Deleted on Windows Servers | PCI_Accounts_Deleted_on_Windows_Servers | Displays all accounts deleted on Windows servers to ensure authorized and appropriate access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.5.4, 8.8, 9.10, 10.8, 11.6 |
| 22 | PCI: Active Directory System Changes | PCI_Active_Directory_System_Changes | Displays changes made within Active Directory. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.1, 7.2, 7.3, 8.1, 8.5.1, 8.5.4, 8.5.8, 8.5.9, 8.5.13, 8.8, 9.10, 10.1, 10.2.1, 10.2.2, 10.2.4, 10.8, 11.6 |
| 23 | PCI: Administrator Logins on Windows Servers | PCI_Administrator_ Logins_on_Windows_Servers |
Displays all logins with the administrator account on Windows servers. |
1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.1, 8.5.8, 8.6, 8.8, 10.1, 9.10, 10.8, 11.6 |
| 24 | PCI: Administrators Activities on Servers | Not Applicable | Displays the latest activities performed by administrators and root users to ensure appropriate access. |
1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.1, 10.2.1, 10.2.2, 10.2.4, 10.2.5, 10.8, 11.6 |
| 25 | Not Applicable | PCI_Amazon_Cloudtrail_Change_Events | Displays all Amazon Cloudtrail audit events related to policy objects changed. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 7.1, 7.2, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 26 | Not Applicable | PCI_Amazon_Cloudtrail_Create_Events | Displays all Amazon Cloudtrail audit events related to policy objects created. |
1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.8, 11.6 |
| 27 | Not Applicable | PCI_Amazon_Cloudtrail_Delete_Events | Displays all Amazon Cloudtrail audit events related to policy objects deleted. |
1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.5.4, 8.8, 9.10, 10.8, 11.6 |
| 28 | Not Applicable | PCI_Amazon_Cloudtrail_Failed_Logins | Displays all failed login attempts to review any access violations or unusual activity. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.2.1, 10.2.2, 10.2.4, 10.2.5, 10.8, 11.6 |
| 29 | Not Applicable | PCI_Amazon_Cloudtrail_Successful_Logins | Displays successful Amazon Cloudtrail logins. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.1.5, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.5.16, 8.8, 9.10, 10.2.5, 10.8, 11.6 |
| 30 | PCI: Applications Through Firewalls | Not Applicable | Displays the most active applications used through the firewalls. | 1.1.6, 1.1.7, 1.2, 1.3.2, 1.3.5, 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 31 | PCI: Applications Under Attack | Not Applicable | Displays all applications under attack as well as the attack signatures. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.4, 11.6, 12.10.5 |
| 32 | PCI: Applications Under Attack - Cisco IOS | PCI_Applications_Under_Attack_Cisco_IOS | Displays all applications under attack as well as the attack signatures by Cisco IOS. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.4, 11.6, 12.10.5 |
| 33 | PCI: Applications Under Attack - FireEye MPS | PCI_Applications_Under_ Attack_FireEye_MPS |
Displays all applications under attack as well as the attack signatures by FireEye MPS. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.4, 11.6, 12.10.5 |
| 34 | PCI: Applications Under Attack - ISS SiteProtector | PCI_Applications_Under_ Attack_ISS_SiteProtector |
Displays all applications under attack as well as the attack signatures by ISS SiteProtector. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.4, 11.6, 12.10.5 |
| 35 | PCI: Applications Under Attack - SiteProtector | PCI_Applications_Under_ Attack_SiteProtector |
Displays all applications under attack as well as the attack signatures by SiteProtector. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.4, 11.6, 12.10.5 |
| 36 | PCI: Applications Under Attack - Sourcefire Defense Center | PCI_Applications_Under_Attack_Cisco_FirePower | Displays all applications under attack as well as the attack signatures by Cisco FirePower and Sourcefire Defense Center. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.4, 11.6, 12.10.5 |
| 37 | PCI: Attack Origins | Not Applicable | Displays the sources that have initiated the most attacks. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.4, 11.6, 12.10.5 |
| 38 | PCI: Attack Origins - Cisco IOS | PCI_Attack_Origins_Cisco_IOS | Displays the sources that have initiated the most attacks by Cisco IOS. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.4, 11.6, 12.10.5 |
| 39 | PCI: Attack Origins - ISS SiteProtector | PCI_Attack_Origins_ISS_SiteProtector | Displays the sources that have initiated the most attacks by ISS SiteProtector. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.4, 11.6, 12.10.5 |
| 40 | PCI: Attack Origins - McAfee HIPS | PCI_Attack_Origins_ McAfee_HIPS |
Displays the sources that have initiated the most attacks by McAfee HIPS. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.4, 11.6, 12.10.5 |
| 41 | PCI: Attack Origins - SiteProtector | PCI_Attack_Origins_SiteProtector | Displays the sources that have initiated the most attacks by SiteProtector. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.4, 11.6, 12.10.5 |
| 42 | PCI: Attack Origins - Sourcefire Defense Center | PCI_Attack_Origins_ Cisco_FirePower |
Displays the sources that have initiated the most attacks by Cisco FirePower and Sourcefire Defense Center. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.4, 11.6, 12.10.5 |
| 43 | PCI: Attacks Detected | Not Applicable | Displays all IDS attacks detected to servers and applications. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.4, 11.6, 12.10.5 |
| 44 | PCI: Attacks Detected - Cisco IOS | PCI_Attacks_Detected_ Cisco_IOS |
Displays all IDS attacks detected to servers and applications by Cisco IOS. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.4, 11.6, 12.10.5 |
| 45 | PCI: Attacks Detected - ISS SiteProtector | PCI_Attacks_Detected_ ISS_SiteProtector |
Displays all IDS attacks detected to servers and applications by ISS SiteProtector. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.4, 11.6, 12.10.5 |
| 46 | PCI: Attacks Detected - McAfee HIPS | PCI_Attacks_Detected_McAfee_HIPS | Displays all IPS attacks detected to servers and applications by McAfee HIPS. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.4, 11.6, 12.10.5 |
| 47 | PCI: Attacks Detected - SiteProtector | PCI_Attacks_Detected_SiteProtector | Displays all IDS attacks detected to servers and applications by SiteProtector. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.4, 11.6, 12.10.5 |
| 48 | PCI: Attacks Detected - Sourcefire Defense Center | PCI_Attacks_Detected_ Cisco_FirePower |
Displays all IDS attacks detected to servers and applications by Cisco FirePower and Sourcefire Defense Center. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.4, 11.6, 12.10.5 |
| 49 | PCI: Check Point Configuration Changes | PCI_Check_Point_Configuration_Changes | Displays all Check Point audit events related to configuration changes. | 1.1.1, 1.1.6, 1.1.7, 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 50 | PCI: Check Point Management Station Login | PCI_Check_Point_Management_Station_Login | Displays all login events to the Check Point management station. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.1.5, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.5.16, 8.8, 9.10, 10.2.5, 10.8, 11.6 |
| 51 | PCI: Check Point Objects Created | PCI_Check_Point_ Objects_Created |
Displays all Check Point audit events related to object creation in policies. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 52 | PCI: Check Point Objects Deleted | PCI_Check_Point_Objects_Deleted | Displays all Check Point audit events related to policy objects deleted. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 53 | PCI: Check Point Objects Modified | PCI_Check_Point_Objects_Modified | Displays all Check Point audit events related to policy objects modified. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 54 | PCI: Check Point SIC Revoked | PCI_Check_Point_SIC_Revoked | Displays all Check Point audit events related to the security certificate being revoked. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 55 | PCI: Cisco ASA, FWSM Failover Disabled | PCI_Cisco_ASA_FWSM_Failover_Disabled | Displays all logs related to disabling Cisco ASA and FWSM failover capability. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 56 | PCI: Cisco ASA, FWSM Failover Performed | PCI_Cisco_ASA_FWSM_Failover_Performed | Displays all logs related to performing a Cisco ASA and FWSM failover. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 57 | PCI: Cisco ASA, FWSM Policy Changed | PCI_Cisco_ASA_FWSM_Policy_Changed | Displays all configuration changes made to the Cisco ASA and FWSM devices. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 7.1, 7.2, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 58 | PCI: Cisco ASA, FWSM Restarted | PCI_Cisco_ASA_FWSM_Restarted | Displays all Cisco ASA or FWSM restart activities to detect unusual activities. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 59 | PCI: Cisco ASA, FWSM Routing Failure | PCI_CIsco_ASA_FWSM_Routing_Failure | Displays all Cisco ASA and FWSM routing error messages. | 1.1.1, 1.1.6, 1.1.7, 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 60 | PCI: Cisco ESA: Attacks by Event ID | PCI_Cisco_ESA_Attacks_by_Event_ID | Displays Cisco ESA attacks by Event ID. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.5, 11.6, 12.10.5 |
| 61 | PCI: Cisco ESA: Attacks by Threat Name | PCI_Cisco_ESA_Attacks_by_Threat_Name | Displays Cisco ESA attacks by threat name. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.5, 11.6, 12.10.5 |
| 62 | PCI: Cisco ESA: Attacks Detected | PCI_Cisco_ESA_Attacks_Detected | Displays attacks detected by Cisco ESA. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.5, 11.6, 12.10.5 |
| 63 | PCI: Cisco ESA: Scans | PCI_Cisco_ESA_Scans | Displays scans using Cisco ESA. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.5, 11.6 |
| 64 | PCI: Cisco ESA: Updated | PCI_Cisco_ESA_Updated | Displays updates to Cisco ESA. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.2, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 65 | PCI: Cisco FWSM HA State Changed | PCI_Cisco_FWSM_HA_State_Changed | Displays all Cisco FWSM firewall fail-over state change events. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.1, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 66 | PCI: Cisco ISE, ACS Accounts Created | PCI_Cisco_ISE_ACS_Accounts_Created | Displays all accounts created on Cisco ISE and Cisco SecureACS to ensure authorized and appropriate access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.8, 11.6 |
| 67 | PCI: Cisco ISE, ACS Accounts Removed | PCI_Cisco_ISE_ACS_Accounts_Removed | Displays all accounts removed on Cisco ISE and Cisco SecureACS to ensure authorized and appropriate access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.5.4, 8.8, 9.10, 10.8, 11.6 |
| 68 | PCI: Cisco ISE, ACS Configuration Changes | PCI_Cisco_ISE_ACS_Configuration_Changes | Displays Cisco ISE and Cisco SecureACS configuration changes. | 1.1.1, 1.1.6, 1.1.7, 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 69 | PCI: Cisco ISE, ACS Password Changes | PCI_Cisco_ISE_ACS_Password_Changes | Displays all password change activities on Cisco ISE and Cisco SecureACS to ensure authorized and appropriate access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.5.9, 8.8, 9.10, 10.8, 11.6 |
| 70 | PCI: Cisco Peer Reset/Reload | PCI_Cisco_Peer_Reset_Reload | Displays all Cisco Peer reset and reload events. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 71 | PCI: Cisco Peer Supervisor Status Changes | PCI_Cisco_Peer_Supervisor_Status_Changes | Displays all Cisco Peer Supervisor status changes. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.1, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 72 | PCI: Cisco Redundancy Version Check Failed | PCI_Cisco_Redundancy_Version_Check_Failed | Displays all Cisco redundancy version check failures. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 73 | PCI: Cisco Routers and Switches Restart | PCI_Cisco_Routers_and_Switches_Restart | Displays all Cisco routers and switches restart activities to detect unusual activities. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 74 | PCI: Cisco Switch Policy Changes | PCI_Cisco_Switch_Policy_Changes | Displays all configuration changes to the Cisco router and switch policies. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 7.1, 7.2, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 75 | PCI: Creation and Deletion of System Level Objects: AIX Audit | PCI_Creation_and_Deletion _of_System_Level_Objects_AIX_Audit |
Displays AIX audit events related to creation and deletion of system-level objects. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.2.7, 10.8, 11.6 |
| 76 | PCI: Creation and Deletion of System Level Objects: DB2 Database | PCI_Creation_and_Deletion _of_System_Level_Objects_ DB2_Database |
Displays DB2 database events related to creation and deletion of system-level objects. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.2.7, 10.8, 11.6 |
| 77 | PCI: Creation and Deletion of System Level Objects: HP-UX Audit | PCI_Creation_and_Deletion _of_System_Level_Objects _HP-UX_Audit |
Displays HP-UX audit events related to creation and deletion of system-level objects. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7,
7.3, 8.8, 9.10, 10.2.7, 10.8, 11.6 |
| 78 | PCI: Creation and Deletion of System Level Objects: Oracle | PCI_Creation_and _Deletion_of_System_ Level_Objects_Oracle |
Displays Oracle database events related to creation and deletion of system-level objects. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.2.7, 10.8, 11.6 |
| 79 | PCI: Creation and Deletion of System Level Objects: Solaris BSM | PCI_Creation_ and_Deletion_of_ System_Level_Objects_Solaris_BSM |
Displays Solaris BSM events related to creation and deletion of system-level objects. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.2.7, 10.8, 11.6 |
| 80 | PCI: Creation and Deletion of System Level Objects: SQL Server | PCI_Creation_and_Deletion_of_ System_Level_Objects_SQL_Server |
Displays Microsoft SQL Server events related to creation and deletion of system-level objects. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.2.7, 10.8, 11.6 |
| 81 | PCI: Creation and Deletion of System Level Objects: Windows | PCI_Creation_and_Deletion _of_System_Level_Objects _Windows |
Displays all Windows events related to creation and deletion of system-level objects. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.2.7, 10.8, 11.6 |
| 82 | PCI: DB2 Database Configuration Changes | PCI_DB2_Database_Configuration _Changes |
Displays DB2 database configuration changes. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 83 | PCI: DB2 Database Failed Logins | PCI_DB2_Database_Failed_Logins | Displays all failed login attempts to review any access violations or unusual activity. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.2.1, 10.2.2, 10.2.4, 10.2.5, 10.8, 11.6 |
| 84 | PCI: DB2 Database Successful Logins | PCI_DB2_Database_Successful_Logins | Displays successful DB2 database logins. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.1.5, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.5.16, 8.8, 9.10, 10.2.5, 10.8, 11.6 |
| 85 | PCI: DB2 Database User Additions and Deletions | PCI_DB2_Database _User_Additions_and_Deletions |
Displays IBM DB2 Database events related to creation and deletion of database users. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.1, 8.5.4, 8.5.8, 8.8, 9.10, 10.8, 11.6 |
| 86 | PCI: DHCP Activities on Microsoft DHCP | PCI_DHCP_Activities_on_Microsoft_DHCP | Displays all DHCP activities on Microsoft DHCP Server. | 1.5, 2.2.2, 2.2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 87 | PCI: DNS Server Error | PCI_DNS_Server_Error | Displays all events when DNS Server has errors. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.7, 10.8, 11.6 |
| 88 | PCI: Escalated Privilege Activities on Servers | Not Applicable | Displays all privilege escalation activities performed on servers to ensure appropriate access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.1, 10.2.1, 10.2.2, 10.2.4, 10.2.5, 10.8, 11.6 |
| 89 | PCI: ESX Accounts Activities | PCI_ESX_Accounts_Activities | Displays all accounts activities on VMware ESX servers to ensure authorized and appropriate access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.8, 9.10, 10.8, 11.6 |
| 90 | PCI: ESX Accounts Created | PCI_ESX_Accounts_Created | Displays all accounts created on VMware ESX servers to ensure authorized and appropriate access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.8, 11.6 |
| 91 | PCI: ESX Accounts Deleted | PCI_ESX_Accounts_Deleted | Displays all accounts deleted on VMware ESX servers to ensure authorized and appropriate access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.5.4, 8.8, 9.10, 10.8, 11.6 |
| 92 | PCI: ESX Failed Logins | PCI_ESX_Failed_Logins | Failed VMware ESX logins for known user. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.2.1, 10.2.2, 10.2.4, 10.2.5, 10.8, 11.6 |
| 93 | PCI: ESX Group Activities | PCI_ESX_Group_Activities | Displays all group activities on VMware ESX servers to ensure authorized and appropriate access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.5.1, 8.5.4, 8.6, 8.8, 9.10, 10.8, 11.6 |
| 94 | PCI: ESX Kernel log daemon terminating | PCI_ESX_Kernel_log_daemon_terminating | Displays all VMware ESX Kernel log daemon terminating. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.2, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 95 | PCI: ESX Kernel logging Stop | PCI_ESX_Kernel_logging_Stop | Displays all VMware ESX Kernel logging stops. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.2, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 96 | PCI: ESX Logins Failed Unknown User | PCI_ESX_Logins_Failed_Unknown_User | Failed VMware ESX logins for unknown user. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.2.1, 10.2.2, 10.2.4, 10.2.5, 10.8, 11.6 |
| 97 | PCI: ESX Logins Succeeded | PCI_ESX_Logins_Succeeded | Displays successful logins to VMware ESX to ensure only authorized personnel have access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.1.5, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.5.16, 8.8, 9.10, 10.2.5, 10.8, 11.6 |
| 98 | PCI: ESX Syslogd Restart | PCI_ESX_Syslogd_Restart | Displays all VMware ESX syslogd restarts. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.2, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 99 | PCI: F5 BIG-IP TMOS Login Failed | PCI_F5_BIG-IP_TMOS_Login_Failed | Displays all F5 BIG-IP TMOS login events which have failed. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.2.1, 10.2.2, 10.2.4, 10.2.5, 10.8, 11.6 |
| 100 | PCI: F5 BIG-IP TMOS Login Successful | PCI_F5_BIG-IP_TMOS_Login_Successful | Displays all F5 BIG-IP TMOS login events which have succeeded. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.1.5, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.5.16, 8.8, 9.10, 10.2.5, 10.8, 11.6 |
| 101 | PCI: F5 BIG-IP TMOS Password Changes | PCI_F5_BIG-IP_TMOS_Password_Changes | Displays all password change activities on F5 BIG-IP TMOS to ensure authorized and appropriate access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.5.9, 8.8, 9.10, 10.8, 11.6 |
| 102 | PCI: F5 BIG-IP TMOS Restarted | PCI_F5_BIG-IP_TMOS_Restarted | Displays all events when the F5 BIG-IP TMOS has been restarted. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 103 | PCI: Failed Logins | Not Applicable | Displays all failed login attempts to review any access violations or unusual activity. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.2.1, 10.2.2, 10.2.4, 10.2.5, 10.8, 11.6 |
| 104 | PCI: Files Accessed on NetApp Filer Audit | PCI_Files_Accessed_on_NetApp_Filer_Audit | Displays all files accessed on NetApp Filer Audit to ensure appropriate access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.2, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 105 | PCI: Files Accessed on Servers | Not Applicable | Displays all files accessed on servers to ensure appropriate access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.2, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 106 | PCI: Files Accessed through Juniper SSL VPN (Secure Access) | PCI_Files_Accessed_through_Juniper_SSL _VPN_Secure_Access |
Displays all files accessed through Juniper SSL VPN (Secure Access). | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.2, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 107 | PCI: Files Accessed through PANOS | PCI_Files_Accessed_through_PANOS | Displays all files accessed through Palo Alto Networks. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.2, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 108 | PCI: Files Accessed through Pulse Connect Secure | PCI_Files_Accessed_through_ Pulse_Connect_Secure |
Displays all files accessed through Pulse Connect Secure. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.2, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 109 | PCI: FireEye MPS: Attacks by Event ID | PCI_FireEye_MPS_ Attacks_by_Event_ID |
Displays FireEye MPS attacks by Event ID. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.5, 11.6, 12.10.5 |
| 110 | PCI: FireEye MPS: Attacks by Threat Name | PCI_FireEye_MPS_Attacks_by_Threat_Name | Displays FireEye MPS attacks by threat name. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.5, 11.6, 12.10.5 |
| 111 | PCI: FireEye MPS: Attacks Detected | PCI_FireEye_MPS_Attacks_Detected | Displays attacks detected by FireEye MPS. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.5, 11.6, 12.10.5 |
| 112 | PCI: Firewall Connections Accepted - Check Point | PCI_Firewall_ Connections_Accepted_Check_Point |
Displays all traffic passing through the Check Point firewall. | 1.1.6, 1.1.7, 1.2, 1.3.1, 1.3.2, 1.3.5, 1.5, 2.2.2, 2.2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 113 | PCI: Firewall Connections Accepted - Cisco IOS | PCI_Firewall_Connections_Accepted_Cisco_IOS | Displays all traffic passing through the Cisco IOS firewall. | 1.1.6, 1.1.7, 1.2, 1.3.1, 1.3.2, 1.3.5, 1.5, 2.2.2, 2.2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 114 | PCI: Firewall Connections Accepted - Cisco Netflow | PCI_Firewall_ Connections_Accepted_Cisco_Netflow |
Displays all traffic passing through the Cisco Netflow. | 1.1.6, 1.1.7, 1.2, 1.3.1, 1.3.2, 1.3.5, 1.5, 2.2.2, 2.2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 115 | PCI: Firewall Connections Accepted - Cisco NXOS | PCI_Firewall_ Connections _Accepted_Cisco_NXOS |
Displays all traffic passing through the Cisco NXOS device. | 1.1.6, 1.1.7, 1.2, 1.3.1, 1.3.2, 1.3.5, 1.5, 2.2.2, 2.2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 116 | PCI: Firewall Connections Accepted - F5 BIG-IP TMOS | PCI_Firewall_Connections_Accepted_F5_BIG-IP_TMOS | Displays all traffic passing through the F5 BIG-IP TMOS device. | 1.1.6, 1.1.7, 1.2, 1.3.1, 1.3.2, 1.3.5, 1.5, 2.2.2, 2.2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 117 | PCI: Firewall Connections Accepted - Juniper JunOS | PCI_Firewall_ Connections_Accepted_Juniper_JunOS |
Displays all traffic passing through the Juniper JunOS firewall. | 1.1.6, 1.1.7, 1.2, 1.3.1, 1.3.2, 1.3.5, 1.5, 2.2.2, 2.2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 118 | PCI: Firewall Connections Accepted - PANOS | PCI_Firewall_Connections_Accepted_PANOS | Displays all traffic passing through the Palo Alto Networks firewall. | 1.1.6, 1.1.7, 1.2, 1.3.1, 1.3.2, 1.3.5, 1.5, 2.2.2, 2.2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 119 | PCI: Firewall Connections Denied - Check Point | PCI_Firewall_Connections_Denied_Check_Point | Displays the applications that have been denied access the most by the Check Point devices. | 1.3.1, 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 120 | PCI: Firewall Connections Denied - Cisco ASA | PCI_Firewall_ Connections_Denied_Cisco_ASA |
Displays the applications that have been denied access the most by the Cisco ASA devices. | 1.3.1, 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 121 | PCI: Firewall Connections Denied - Cisco FWSM | PCI_Firewall_ Connections_Denied_Cisco_FWSM |
Displays the applications that have been denied access the most by the Cisco FWSM devices. | 1.3.1, 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 122 | PCI: Firewall Connections Denied - Cisco IOS | PCI_Firewall_Connections_Denied_Cisco_IOS | Displays the applications that have been denied access the most by the Cisco IOS. | 1.3.1, 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 123 | PCI: Firewall Connections Denied - Cisco NXOS | PCI_Firewall_Connections_Denied_Cisco_NXOS | Displays the applications that have been denied access the most by the Cisco NXOS devices. | 1.3.1, 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 124 | PCI: Firewall Connections Denied - Cisco Router | Not Applicable | Displays the applications that have been denied access the most by the Cisco Router. | 1.3.1, 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 125 | PCI: Firewall Connections Denied - F5 BIG-IP TMOS | PCI_Firewall_ Connections_Denied_F5_BIG-IP_TMOS |
Displays the applications that have been denied access the most by the F5 BIG-IP TMOS. | 1.3.1, 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 126 | PCI: Firewall Connections Denied - Fortinet | PCI_Firewall_Connections_Denied_Fortinet | Displays the applications that have been denied access the most by the Fortinet devices. | 1.3.1, 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 127 | PCI: Firewall Connections Denied - Juniper JunOS | PCI_Firewall_ Connections_Denied_Juniper_JunOS |
Displays the applications that have been denied access the most by the Juniper JunOS. | 1.3.1, 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 128 | PCI: Firewall Connections Denied - Nortel | Not Applicable | Displays the applications that have been denied access the most by the Nortel devices. | 1.3.1, 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 129 | PCI: Firewall Connections Denied - PANOS | PCI_Firewall_Connections_Denied_PANOS | Displays the applications that have been denied access the most by the Palo Alto Networks devices. | 1.3.1, 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 130 | PCI: Firewall Traffic Besides HTTP, SSL and SSH - Check Point | Not Applicable | Displays all traffic passing through the Check Point that is not HTTP, SSL, and SSH. | 1.1.6, 1.1.7, 1.2, 1.3.2, 1.3.5, 2.3, 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 131 | PCI: Firewall Traffic Besides HTTP, SSL and SSH - Cisco ASA | PCI_Firewall_Traffic_ Besides_HTTP_SSL_and_SSH_Cisco_ASA |
Displays all traffic passing through the Cisco ASA that is not HTTP, SSL, and SSH. | 1.1.6, 1.1.7, 1.2, 1.3.2, 1.3.5, 2.3, 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 132 | PCI: Firewall Traffic Besides HTTP, SSL and SSH - Cisco FWSM | PCI_Firewall_Traffic_ Besides_HTTP_SSL_and_SSH_Cisco_FWSM |
Displays all traffic passing through the Cisco FWSM that is not HTTP, SSL, and SSH. | 1.1.6, 1.1.7, 1.2, 1.3.2, 1.3.5, 2.3, 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 133 | PCI: Firewall Traffic Besides HTTP, SSL and SSH - Cisco IOS | PCI_Firewall_Traffic_ Besides_HTTP_SSL_and_SSH_Cisco_IOS |
Displays all traffic passing through the Cisco IOS that is not HTTP, SSL, and SSH. | 1.1.6, 1.1.7, 1.2, 1.3.2, 1.3.5, 2.3, 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 134 | PCI: Firewall Traffic Besides HTTP, SSL and SSH - Cisco Netflow | PCI_Firewall_Traffic_Besides_HTTP_SSL_ and_SSH_Cisco_Netflow |
Displays all traffic passing through the Cisco Netflow that is not HTTP, SSL, and SSH. | 1.1.6, 1.1.7, 1.2, 1.3.2, 1.3.5, 2.3, 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 135 | PCI: Firewall Traffic Besides HTTP, SSL and SSH - F5 BIG-IP TMOS | PCI_Firewall_Traffic_Besides_HTTP_SSL_ and_SSH_F5_BIG-IP_TMOS |
Displays all traffic passing through the F5 BIG-IP TMOS that is not HTTP, SSL, and SSH. | 1.1.6, 1.1.7, 1.2, 1.3.2, 1.3.5, 2.3, 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 136 | PCI: Firewall Traffic Besides HTTP, SSL and SSH - Fortinet | PCI_Firewall_Traffic_Besides_HTTP_SSL_ and_SSH_Fortinet |
Displays all traffic passing through the Fortinet that is not HTTP, SSL, and SSH. | 1.1.6, 1.1.7, 1.2, 1.3.2, 1.3.5, 2.3, 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 137 | PCI: Firewall Traffic Besides HTTP, SSL and SSH - Juniper JunOS | PCI_Firewall_Traffic_Besides_HTTP_SSL_ and_SSH_Juniper_JunOS |
Displays all traffic passing through the Juniper JunOS that is not HTTP, SSL, and SSH. | 1.1.6, 1.1.7, 1.2, 1.3.2, 1.3.5, 2.3, 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 138 | PCI: Firewall Traffic Besides HTTP, SSL and SSH - Nortel | Not Applicable | Displays all traffic passing through the Nortel that is not HTTP, SSL, and SSH. | 1.1.6, 1.1.7, 1.2, 1.3.2, 1.3.5, 2.3, 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 139 | PCI: Firewall Traffic Besides HTTP, SSL and SSH - PANOS | PCI_Firewall_Traffic_ Besides_HTTP_SSL_and_SSH_PANOS |
Displays all traffic passing through the Palo Alto Networks that is not HTTP, SSL, and SSH. | 1.1.6, 1.1.7, 1.2, 1.3.2, 1.3.5, 2.3, 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 140 | PCI: Firewall Traffic Besides SSL and SSH - Check Point | Not Applicable | Displays all traffic passing through the Check Point that is not SSL and SSH. | 1.5, 2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 141 | PCI: Firewall Traffic Besides SSL and SSH - Cisco ASA | PCI_Firewall_Traffic_ Besides_SSL_and_SSH_Cisco_ASA |
Displays all traffic passing through the Cisco ASA that is not SSL and SSH. | 1.5, 2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 142 | PCI: Firewall Traffic Besides SSL and SSH - Cisco FWSM | PCI_Firewall_Traffic_ Besides_SSL_and_SSH_Cisco_FWSM |
Displays all traffic passing through the Cisco FWSM that is not SSL and SSH. | 1.5, 2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 143 | PCI: Firewall Traffic Besides SSL and SSH - Cisco IOS | PCI_Firewall_Traffic_ Besides_SSL_and_SSH_Cisco_IOS |
Displays all traffic passing through the Cisco IOS that is not SSL and SSH. | 1.5, 2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 144 | PCI: Firewall Traffic Besides SSL and SSH - Cisco Netflow | PCI_Firewall_Traffic_ Besides_SSL_and_SSH_Cisco_Netflow |
Displays all traffic passing through the Cisco Netflow that is not SSL and SSH. | 1.5, 2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 145 | PCI: Firewall Traffic Besides SSL and SSH - F5 BIG-IP TMOS | PCI_Firewall_Traffic_ Besides_SSL_and_SSH_F5_BIG-IP_TMOS |
Displays all traffic passing through the F5 BIG-IP TMOS that is not SSL and SSH. | 1.5, 2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 146 | PCI: Firewall Traffic Besides SSL and SSH - Fortinet | PCI_Firewall_Traffic_ Besides_SSL_and_SSH_Fortinet |
Displays all traffic passing through the Fortinet that is not SSL and SSH. | 1.5, 2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 147 | PCI: Firewall Traffic Besides SSL and SSH - Juniper JunOS | PCI_Firewall_Traffic_ Besides_SSL_and_SSH_Juniper_JunOS |
Displays all traffic passing through the Juniper JunOS that is not SSL and SSH. | 1.5, 2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 148 | PCI: Firewall Traffic Besides SSL and SSH - Nortel | Not Applicable | Displays all traffic passing through the Nortel that is not SSL and SSH. | 1.5, 2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 149 | PCI: Firewall Traffic Besides SSL and SSH - PANOS | PCI_Firewall_Traffic_ Besides_SSL_and_SSH_PANOS |
Displays all traffic passing through the Palo Alto Networks that is not SSL and SSH. | 1.5, 2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 150 | PCI: Firewall Traffic Considered Risky - Check Point | Not Applicable | Displays Check Point allowed firewall traffic that is considered risky. | 1.1.7, 1.5, 2.2.2, 2.2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 151 | PCI: Firewall Traffic Considered Risky - Cisco ASA | PCI_Firewall_Traffic_ Considered_Risky_Cisco_ASA |
Displays Cisco ASA allowed firewall traffic that is considered risky. | 1.1.7, 1.5, 2.2.2, 2.2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 152 | PCI: Firewall Traffic Considered Risky - Cisco FWSM | PCI_Firewall_Traffic_ Considered_Risky_Cisco_FWSM |
Displays Cisco FWSM allowed firewall traffic that is considered risky. | 1.1.7, 1.5, 2.2.2, 2.2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 153 | PCI: Firewall Traffic Considered Risky - Cisco IOS | PCI_Firewall_Traffic_ Considered_Risky_Cisco_IOS |
Displays Cisco IOS allowed firewall traffic that is considered risky. | 1.1.7, 1.5, 2.2.2, 2.2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 154 | PCI: Firewall Traffic Considered Risky - Cisco Netflow | PCI_Firewall_Traffic_ Considered_Risky_Cisco_Netflow |
Displays Cisco Netflow allowed firewall traffic that is considered risky. | 1.1.7, 1.5, 2.2.2, 2.2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 155 | PCI: Firewall Traffic Considered Risky - F5 BIG-IP TMOS | PCI_Firewall_Traffic_ Considered_Risky_F5_BIG-IP_TMOS |
Displays F5 BIG-IP TMOS allowed firewall traffic that is considered risky. | 1.1.7, 1.5, 2.2.2, 2.2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 156 | PCI: Firewall Traffic Considered Risky - Fortinet | PCI_Firewall_Traffic_Considered_Risky_Fortinet | Displays Fortinet allowed firewall traffic that is considered risky. | 1.1.7, 1.5, 2.2.2, 2.2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 157 | PCI: Firewall Traffic Considered Risky - Juniper JunOS | PCI_Firewall_Traffic_ Considered_Risky_Juniper_JunOS |
Displays Juniper JunOS allowed firewall traffic that is considered risky. | 1.1.7, 1.5, 2.2.2, 2.2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 158 | PCI: Firewall Traffic Considered Risky - Nortel | Not Applicable | Displays Nortel allowed firewall traffic that is considered risky. | 1.1.7, 1.5, 2.2.2, 2.2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 159 | PCI: Firewall Traffic Considered Risky - PANOS | PCI_Firewall_Traffic_Considered_Risky_PANOS | Displays Palo Alto Networks allowed firewall traffic that is considered risky. | 1.1.7, 1.5, 2.2.2, 2.2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 160 | PCI: FortiOS DLP Attacks Detected | PCI_FortiOS_DLP_Attacks_Detected | Displays all DLP attacks detected by FortiOS. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.5, 11.6, 12.10.5 |
| 161 | PCI: FortiOS: Attacks by Event ID | PCI_FortiOS_Attacks_by_Event_ID | Displays FortiOS attacks by Event ID. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.5, 11.6, 12.10.5 |
| 162 | PCI: FortiOS: Attacks by Threat Name | PCI_FortiOS_Attacks_by_Threat_Name | Displays FortiOS attacks by threat name. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.5, 11.6, 12.10.5 |
| 163 | PCI: FortiOS: Attacks Detected | PCI_FortiOS_Attacks_Detected | Displays attacks detected by FortiOS. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.5, 11.6, 12.10.5 |
| 164 | PCI: Group Activities on NetApp Filer Audit | PCI_Group_Activities_on_NetApp_Filer_Audit | Displays all group activities on NetApp Filer Audit to ensure authorized and appropriate access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.8, 8.5.1, 8.5.4, 8.6, 9.10, 10.8, 11.6 |
| 165 | PCI: Group Activities on Symantec Endpoint Protection | PCI_Group_Activities_on_ Symantec_Endpoint_Protection |
Displays all group activities on Symantec Endpoint Protection to ensure authorized and appropriate access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.8, 8.5.1, 8.5.4, 8.6, 9.10, 10.8, 11.6 |
| 166 | PCI: Group Activities on TIBCO ActiveMatrix Administrator | PCI_Group_Activities_ on_TIBCO_ActiveMatrix_Administrator |
Displays all group activities on TIBCO ActiveMatrix Administrator to ensure authorized and appropriate access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.8, 8.5.1, 8.5.4, 8.6, 9.10, 10.8, 11.6 |
| 167 | Not Applicable | PCI_Group_Activities_ on_TIBCO_Spotfire |
Displays all accounts added to groups to ensure appropriate access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3,
6.7, 7.1, 7.2, 7.3, 8.8, 8.5.1, 8.5.4, 8.6, 9.10, 10.8, 11.6 |
| 168 | PCI: Group Activities on UNIX Servers | PCI_Group_Activities_on_UNIX_Servers | Displays all group activities on UNIX servers to ensure authorized and appropriate access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.8, 8.5.1, 8.5.4, 8.6, 9.10, 10.8, 11.6 |
| 169 | PCI: Group Activities on Windows Servers | PCI_Group_Activities_on_Windows_Servers | Displays all group activities on Windows servers to ensure authorized and appropriate access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.8, 8.5.1, 8.5.4, 8.6, 9.10, 10.8, 11.6 |
| 170 | PCI: Guardium SQL Guard Audit Configuration Changes | PCI_Guardium_SQL _Guard_Audit_Configuration_Changes |
Displays all configuration changes on the Guardium SQL Guard Audit database. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 171 | PCI: Guardium SQL Guard Audit Data Access | PCI_Guardium_SQL_Guard_Audit_Data_Access | Displays all select statements made on Guardium SQL Audit Server. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.1, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 172 | PCI: Guardium SQL Guard Audit Logins | PCI_Guardium_SQL_Guard_Audit_Logins | Displays all login attempts to the Guardium SQL Server Audit database. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.1.5, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.5.16, 8.8, 9.10, 10.2.5, 10.8, 11.6 |
| 173 | PCI: Guardium SQL Guard Configuration Changes | PCI_Guardium_SQL_Guard_Configuration_Changes | Displays all configuration changes on the Guardium SQL Guard database. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 174 | PCI: Guardium SQL Guard Data Access | PCI_Guardium_ SQL_Guard_Data_Access |
Displays all select statements made on Guardium SQL Server. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.1, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 175 | PCI: Guardium SQL Guard Logins | PCI_Guardium_SQL_Guard_Logins | Displays all login attempts to the Guardium SQL Server database. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.1.5, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.5.16, 8.8, 9.10, 10.2.5, 10.8, 11.6 |
| 176 | PCI: HP NonStop Audit Configuration Changes | PCI_HP_NonStop_Audit_Configuration_Changes | Displays all audit configuration changes on HP NonStop. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 177 | PCI: HP NonStop Audit Login Failed | PCI_HP_NonStop_Audit_Login_Failed | Displays all HP NonStop Audit login events which have failed. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.2.1, 10.2.2, 10.2.4, 10.2.5, 10.8, 11.6 |
| 178 | PCI: HP NonStop Audit Login Successful | PCI_HP_NonStop_Audit_Login_Successful | Displays all HP NonStop Audit login events which have succeeded. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.1.5, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.5.16, 8.8, 9.10, 10.2.5, 10.8, 11.6 |
| 179 | PCI: HP NonStop Audit Object Changes | PCI_HP_NonStop_Audit_Object_Changes | Displays HP NonStop Audit events related to object changes. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.3, 8.5.1, 8.5.4, 8.8, 9.10, 10.8, 11.6 |
| 180 | PCI: HP NonStop Audit Permissions Changed | PCI_HP_NonStop_ Audit_Permissions_Changed |
Displays all permission modification activities on HP NonStop Audit to ensure authorized access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.2, 7.3, 8.5.1, 8.5.4, 8.8, 9.10, 10.8, 11.6 |
| 181 | PCI: i5/OS DST Password Reset | PCI_i5_OS_DST_Password_Reset | Displays i5/OS events related to the reset of the DST (Dedicated Service Tools) password. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.5.9, 8.8, 9.10, 10.8, 11.6 |
| 182 | PCI: i5/OS Files Accessed | PCI_i5_OS_Files_Accessed | Lists all events when a user gains access an i5/OS file. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.2, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 183 | PCI: i5/OS Network User Login Failed | PCI_i5_OS_Network_User_Login_Failed | Lists all events when a network user was denied access into the i5/OS. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.2.1, 10.2.2, 10.2.4, 10.2.5, 10.8, 11.6 |
| 184 | PCI: i5/OS Network User Login Successful | PCI_i5_OS_Network_User_Login_Successful | Lists all events when a network user successfully logs into the i5/OS. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.1.5, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.5.16, 8.8, 9.10, 10.2.5, 10.8, 11.6 |
| 185 | PCI: i5/OS Network User Profile Creation | PCI_i5_OS_Network_User_Profile_Creation | Displays i5/OS events when a network user profile has been created. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.8, 11.6 |
| 186 | PCI: i5/OS Network User Profile Deletion | PCI_i5_OS_Network_User_Profile_Deletion | Displays i5/OS events when a network user profile has been deleted. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.5.4, 8.8, 9.10, 10.8, 11.6 |
| 187 | PCI: i5/OS Network User Profile Modified | PCI_i5_OS_Network_User_Profile_Modified | Displays i5/OS events when a network user profile has been modified. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.3, 8.5.1, 8.5.4, 8.8, 9.10, 10.8, 11.6 |
| 188 | PCI: i5/OS Object Permissions Modified | PCI_i5_OS_Object_Permissions_Modified | Displays all permission modification activities on i5/OS to ensure authorized access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.2, 7.3, 8.5.1, 8.5.4, 8.8, 9.10, 10.8, 11.6 |
| 189 | PCI: i5/OS Restarted | PCI_i5_OS_Restarted | Lists all events when the i5/OS has been restarted. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 190 | PCI: i5/OS Service Started | PCI_i5_OS_Service_Started | Lists all events when a user starts a service on the i5/OS. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.2, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 191 | PCI: i5/OS User Login Failed | PCI_i5_OS_User_Login_Failed | Lists all events when a user was denied access into the i5/OS. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.2.1, 10.2.2, 10.2.4, 10.2.5, 10.8, 11.6 |
| 192 | PCI: i5/OS User Login Successful | PCI_i5_OS_User_Login_Successful | Lists all events when a user successfully logs into the i5/OS. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.1.5, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.5.16, 8.8, 9.10, 10.2.5, 10.8, 11.6 |
| 193 | PCI: i5/OS User Profile Creation | PCI_i5_OS_User_ Profile_Creation |
Displays i5/OS events when a user profile has been created. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.8, 11.6 |
| 194 | PCI: i5/OS User Profile Modifications | PCI_i5_OS_User_Profile_Modifications | Displays i5/OS events when a user profile has been modified. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.3, 8.5.1, 8.5.4, 8.8, 9.10, 10.8, 11.6 |
| 195 | PCI: Juniper SSL VPN (Secure Access) Failed Logins by User | PCI_Juniper_SSL_ VPN_Secure_Access_Failed_Logins_by_User |
Displays all failed Juniper SSL VPN (Secure Access) logins based on user. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.2.1, 10.2.2, 10.2.4, 10.2.5, 10.8, 11.6 |
| 196 | PCI: Juniper SSL VPN (Secure Access) Successful Logins by User | PCI_Juniper_SSL_ VPN_Secure_Access_Successful_Logins_by_User |
Displays all successful Juniper SSL VPN (Secure Access) logins based on user. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.1.5, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.5.16, 8.8, 9.10, 10.2.5, 10.8, 11.6 |
| 197 | PCI: Juniper SSL VPN Failed Logins by User | Not Applicable | Displays all failed logins per user at the Juniper SSL VPN. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.2.1, 10.2.2, 10.2.4, 10.2.5, 10.8, 11.6 |
| 198 | PCI: Juniper SSL VPN Successful Logins by User | Not Applicable | Displays all successful Juniper SSL VPN logins based on user. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.1.5, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.5.16, 8.8, 9.10, 10.2.5, 10.8, 11.6 |
| 199 | PCI: Logins by Authentication Type | Not Applicable | Displays all logins categorized by the authentication type. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.1.5, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.8, 9.10, 10.2.5, 10.8, 11.6 |
| 200 | PCI: LogLogic Disk Full | PCI_Loglogic_Disk_Full | Displays events that indicate the LogLogic appliance's disk is near full. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.7, 10.8, 11.6 |
| 201 | PCI: LogLogic File Retrieval Errors | PCI_LogLogic_File_Retrieval_Errors | Displays all errors while retrieving log files from devices, servers and applications. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.2.3, 10.2.6, 10.5.1, 10.5.2, 10.5.3, 10.5.5, 10.6, 10.7, 10.8, 11.6 |
| 202 | PCI: LogLogic HA State Changed | PCI_LogLogic_HA_State_Changed | Displays all LogLogic appliance failover state change events. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.1, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 203 | PCI: LogLogic Management Center Account Activities | PCI_LogLogic_Management _Center_Account_Activities |
Displays all accounts activities on LogLogic Management Center to ensure authorized and appropriate access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.8, 9.10, 10.8, 11.6 |
| 204 | PCI: LogLogic Management Center Login | PCI_LogLogic_Management_Center_Login | Displays all login events to the LogLogic Management Center. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.1.5, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.5.16, 8.8, 9.10, 10.2.5, 10.8, 11.6 |
| 205 | PCI: LogLogic Management Center Password Changes | PCI_LogLogic_ Management_Center_Password_Changes |
Displays all password change activities on LogLogic Management Center to ensure authorized and appropriate access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.5.9, 8.8, 9.10, 10.8, 11.6 |
| 206 | PCI: LogLogic Management Center Upgrade Success | PCI_LogLogic_ Management_Center_Upgrade_Success |
Displays all successful events related to the system's upgrade. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.2, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 207 | PCI: LogLogic Message Routing Errors | PCI_LogLogic_Message_Routing_Errors | Displays all log forwarding errors on the LogLogic appliance to ensure all logs are archived properly. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.7, 10.8, 11.6 |
| 208 | PCI: LogLogic Universal Collector Configuration Changes | PCI_LogLogic_ Universal_Collector_Configuration_Changes |
Displays LogLogic universal collector configuration changes. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 209 | PCI: McAfee AntiVirus: Attacks by Event ID | PCI_McAfee_AntiVirus_Attacks_by_Event_ID | Displays McAfee AntiVirus attacks by Event ID. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.5, 11.6, 12.10.5 |
| 210 | PCI: McAfee AntiVirus: Attacks by Threat Name | PCI_McAfee_AntiVirus_Attacks_by_Threat_Name | Displays McAfee AntiVirus attacks by threat name. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.5, 11.6, 12.10.5 |
| 211 | PCI: McAfee AntiVirus: Attacks Detected | PCI_McAfee_AntiVirus_Attacks_Detected | Displays attacks detected by McAfee AntiVirus. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.5, 11.6, 12.10.5 |
| 212 | PCI: Microsoft Operations Manager - Windows Accounts Activities | PCI_Microsoft_ Operations_Manager_Windows_Accounts_Activities |
Displays all accounts activities on Windows servers to ensure authorized and appropriate access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.8, 9.10, 10.8, 11.6 |
| 213 | PCI: Microsoft Operations Manager - Windows Accounts Created | PCI_Microsoft_ Operations_Manager _Windows_Accounts_Created |
Displays all accounts created on Windows servers to ensure authorized and appropriate access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.8, 11.6 |
| 214 | PCI: Microsoft Operations Manager - Windows Accounts Enabled | PCI_Microsoft_ Operations_Manager _Windows_Accounts_Enabled |
Displays all accounts enabled on Windows servers to ensure authorized and appropriate access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.8, 11.6 |
| 215 | PCI: Microsoft Operations Manager - Windows Password Changes | PCI_Microsoft_Operations_ Manager_Windows_Password_Changes |
Displays all password change activities on Windows servers to ensure authorized and appropriate access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.5.9, 8.8, 9.10, 10.8, 11.6 |
| 216 | PCI: Microsoft Operations Manager - Windows Permissions Modified | PCI_Microsoft_Operations_ Manager_Windows_Permissions_Modified |
Displays all permission modification activities on Windows servers to ensure authorized access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.2, 7.3, 8.5.1, 8.5.4, 8.8, 9.10, 10.8, 11.6 |
| 217 | PCI: Microsoft Operations Manager - Windows Policies Modified | PCI_Microsoft_Operations_ Manager_Windows_Policies_Modified |
Displays all policy modification activities on Windows servers to ensure authorized and appropriate access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 7.1, 7.2, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 218 | PCI: Microsoft Operations Manager - Windows Servers Restarted | PCI_Microsoft_Operations_ Manager_Windows_Servers_Restarted |
Displays all Windows server restart activities to detect unusual activities. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 219 | PCI: Microsoft Sharepoint Content Deleted | PCI_Microsoft_Sharepoint_Content_Deleted | Displays all events when content has been deleted from Microsoft Sharepoint. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.5.16, 10.2.1, 10.2.2, 10.2.3, 10.2.7, 10.3.1, 10.3.2, 10.3.3, 10.3.5, 10.3.6, 8.8, 9.10, 10.8, 11.6 |
| 220 | PCI: Microsoft Sharepoint Content Updates | PCI_Microsoft_Sharepoint_Content_Updates | Displays all events when content is updated within Microsoft Sharepoint. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.5.16, 8.8, 9.10, 10.2.1, 10.2.2, 10.2.3, 10.2.7, 10.3.1, 10.3.2, 10.3.3, 10.3.5, 10.3.6, 10.8, 11.6 |
| 221 | PCI: Microsoft Sharepoint Permissions Changed | PCI_Microsoft_Sharepoint_Permissions_Changed | Displays all user/group permission events to Microsoft Sharepoint. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.2, 7.3, 8.5.1, 8.5.4, 8.8, 9.10, 10.8, 11.6 |
| 222 | PCI: Microsoft Sharepoint Policy Add, Remove, or Modify | PCI_Microsoft_Sharepoint_ Policy_Add_Remove_or_Modify |
Displays all events when a Microsoft Sharepoint policy is added, removed, or modified. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 7.1, 7.2, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 223 | PCI: Microsoft SQL Server Configuration Changes | PCI_Microsoft_ SQL_Server_Configuration_Changes |
Displays Microsoft SQL database configuration changes. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 224 | PCI: Microsoft SQL Server Data Access | PCI_Microsoft_ SQL_Server_Data_Access |
Displays data access events on Microsoft SQL Server databases. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.1, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 225 | PCI: Microsoft SQL Server Database Failed Logins | PCI_Microsoft_ SQL_Server_Database_Failed_Logins |
Displays failed Microsoft SQL Server database logins. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.2.1, 10.2.2, 10.2.4, 10.2.5, 10.8, 11.6 |
| 226 | PCI: Microsoft SQL Server Database Permission Events | PCI_Microsoft_ SQL_Server_Database_Permission_Events |
Displays events related to Microsoft SQL Server database permission modifications. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.2, 7.3, 8.5.1, 8.5.4, 8.8, 9.10, 10.8, 11.6 |
| 227 | PCI: Microsoft SQL Server Database Successful Logins | PCI_Microsoft_ SQL_Server_Database_Successful_Logins |
Displays successful Microsoft SQL Server database logins. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.1.5, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.5.16, 8.8, 9.10, 10.2.5, 10.8, 11.6 |
| 228 | PCI: Microsoft SQL Server Database User Additions and Deletions | PCI_Microsoft_SQL_ Server_Database_User_Additions_and_Deletions |
Displays Microsoft SQL Server events related to creation and deletion of database users. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.1, 8.5.4, 8.5.8, 8.8, 9.10, 10.8, 11.6 |
| 229 | PCI: Microsoft SQL Server Password Changes | PCI_Microsoft_SQL_ Server_Password_Changes |
Displays password changes for Microsoft SQL Server database accounts. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.5.9, 8.8, 9.10, 10.8, 11.6 |
| 230 | PCI: NetApp Filer Accounts Locked | PCI_NetApp_Filer _Accounts_Locked |
Displays all accounts locked out of NetApp Filer to detect access violations or unusual activities. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.5.1, 8.5.13, 8.8, 9.10, 10.8, 11.6 |
| 231 | PCI: NetApp Filer Audit Accounts Enabled | PCI_NetApp_Filer_Audit_Accounts_Enabled | Displays all accounts enabled on NetApp Filer Audit to ensure authorized and appropriate access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.8, 11.6 |
| 232 | PCI: NetApp Filer Audit Login Failed | PCI_NetApp_Filer_Audit_Login_Failed | Displays all NetApp Filer Audit login events which have failed. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.2.1, 10.2.2, 10.2.4, 10.2.5, 10.8, 11.6 |
| 233 | PCI: NetApp Filer Audit Login Successful | PCI_NetApp_Filer_Audit_Login_Successful | Displays all NetApp Filer Audit login events which have succeeded. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.1.5, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.5.16, 8.8, 9.10, 10.2.5, 10.8, 11.6 |
| 234 | PCI: NetApp Filer Audit Logs Cleared | PCI_NetApp_Filer_Audit_Logs_Cleared | Displays all audit logs clearing activities on NetApp Filer Audit to detect access violations or unusual activity. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.2.3, 10.2.6, 10.5.1, 10.5.2, 10.5.3, 10.5.5, 10.6, 10.8, 11.6 |
| 235 | PCI: NetApp Filer Audit Policies Modified | PCI_NetApp_Filer_Audit_Policies_Modified | Displays all policy modification activities on NetApp Filer Audit to ensure authorized and appropriate access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 7.1, 7.2, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 236 | PCI: NetApp Filer Disk Failure | PCI_NetApp_Filer_Disk_Failure | Displays all disk failure events on the NetApp Filer servers. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 237 | PCI: NetApp Filer Disk Missing | PCI_NetApp_Filer_Disk_Missing | Displays events that indicate disk missing on the NetApp Filer servers. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 238 | PCI: NetApp Filer File Activity | PCI_NetApp_Filer_File_Activity | Displays all file activities on NetApp Filer. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.2.1, 10.2.2, 10.2.4, 10.2.5, 10.8, 11.6 |
| 239 | PCI: NetApp Filer File System Full | PCI_NetApp_Filer_File_System_Full | Displays events that indicate the NetApp Filer's disk is near full. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.7, 10.8, 11.6 |
| 240 | PCI: NetApp Filer Login Failed | PCI_NetApp_Filer_Login_Failed | Displays all NetApp Filer login events which have failed. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.2.1, 10.2.2, 10.2.4, 10.2.5, 10.8, 11.6 |
| 241 | PCI: NetApp Filer Login Successful | PCI_NetApp_Filer_Login_Successful | Displays all NetApp Filer login events which have succeeded. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.1.5, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.5.16, 8.8, 9.10, 10.2.5, 10.8, 11.6 |
| 242 | PCI: NetApp Filer Password Changes | PCI_NetApp_Filer_Password_Changes | Displays all password change activities on NetApp Filer to ensure authorized and appropriate access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.5.9, 8.8, 9.10, 10.8, 11.6 |
| 243 | PCI: NetApp Filer Snapshot Error | PCI_NetApp_Filer_Snapshot_Error | Displays events that indicate backup on the NetApp Filer has failed. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.7, 10.8, 11.6 |
| 244 | PCI: Oracle Database Configuration Changes | PCI_Oracle_Database_Configuration_Changes | Displays Oracle database configuration changes. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 245 | PCI: Oracle Database Data Access | PCI_Oracle_Database_Data_Access | Displays data access events on Oracle databases. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.1, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 246 | PCI: Oracle Database Failed Logins | PCI_Oracle_Database_Failed_Logins | Displays all failed login attempts to the Oracle database. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.2.1, 10.2.2, 10.2.4, 10.2.5, 10.8, 11.6 |
| 247 | PCI: Oracle Database Permission Events | PCI_Oracle_Database_Permission_Events | Displays events related to Oracle Server database role and privilege management. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.2, 7.3, 8.5.1, 8.5.4, 8.8, 9.10, 10.8, 11.6 |
| 248 | PCI: Oracle Database Successful Logins | PCI_Oracle_Database_Successful_Logins | Displays successful Oracle database logins. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.1.5, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.5.16, 8.8, 9.10, 10.2.5, 10.8, 11.6 |
| 249 | PCI: Oracle Database User Additions and Deletions | PCI_Oracle_Database_User_Additions_and_Deletions | Displays Oracle database events related to creation and deletion of database users. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.1, 8.5.4, 8.5.8, 8.8, 9.10, 10.8, 11.6 |
| 250 | PCI: PANOS: Attacks by Event ID | PCI_PANOS_Attacks_by_Event_ID | Displays Palo Alto Networks attacks by Event ID. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.5, 11.6, 12.10.5 |
| 251 | PCI: PANOS: Attacks by Threat Name | PCI_PANOS_Attacks_by_Threat_Name | Displays Palo Alto Networks attacks by threat name. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.5, 11.6, 12.10.5 |
| 252 | PCI: PANOS: Attacks Detected | PCI_PANOS_Attacks_Detected | Displays attacks detected by Palo Alto Networks. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.5, 11.6, 12.10.5 |
| 253 | PCI: Password Changes on Windows Servers | PCI_Password_Changes_on_Windows_Servers | Displays all password change activities on Windows servers to ensure authorized and appropriate access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.5.9, 8.8, 9.10, 10.8, 11.6 |
| 254 | PCI: Periodic Review of Log Reports | PCI_Periodic_Review_of_Log_Reports | Displays all review activities performed by administrators to ensure review for any access violations. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.2.3, 10.2.6, 10.5.1, 10.5.2, 10.5.3, 10.5.5, 10.6, 10.8, 11.6 |
| 255 | PCI: Periodic Review of User Access Logs | PCI_Periodic_Review_of_User_Access_Logs | Displays all review activities performed by administrators to ensure review for any access violations. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.2.3, 10.2.6, 10.5.1, 10.5.2, 10.5.3, 10.5.5, 10.6, 10.8, 11.6 |
| 256 | PCI: Permissions Modified on Windows Servers | PCI_Permissions_Modified_on_Windows_Servers | Displays all permission modification activities on Windows Servers to ensure authorized access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.2, 7.3, 8.5.1, 8.5.4, 8.8, 9.10, 10.8, 11.6 |
| 257 | PCI: Policies Modified on Windows Servers | PCI_Policies_Modified_on_Windows_Servers | Displays all policy modification activities on Windows servers to ensure authorized and appropriate access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 7.1, 7.2, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 258 | PCI: Pulse Connect Secure Failed Logins by User | PCI_Pulse_Connect_Secure_Failed_Logins_by_User | Displays all failed Pulse Connect Secure logins based on user. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.2.1, 10.2.2, 10.2.4, 10.2.5, 10.8, 11.6 |
| 259 | PCI: Pulse Connect Secure Successful Logins by User | PCI_Pulse_Connect_Secure_Successful_Logins_by_User | Displays all successful Pulse Connect Secure logins based on user. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.1.5, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.5.16, 8.8, 9.10, 10.2.5, 10.8, 11.6 |
| 260 | PCI: RACF Accounts Created | PCI_RACF_Accounts_Created | Displays all accounts created on RACF servers to ensure authorized and appropriate access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.8, 11.6 |
| 261 | PCI: RACF Accounts Deleted | PCI_RACF_Accounts_Deleted | Displays all accounts deleted on RACF servers to ensure authorized and appropriate access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.5.4, 8.8, 9.10, 10.8, 11.6 |
| 262 | PCI: RACF Accounts Modified | PCI_RACF_Accounts_Modified | Displays all events when a network user profile has been modified. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.3, 8.5.1, 8.5.4, 8.8, 9.10, 10.8, 11.6 |
| 263 | PCI: RACF Failed Logins | PCI_RACF_Failed_Logins | Displays all failed login attempts to review any access violations or unusual activity. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.2.1, 10.2.2, 10.2.4, 10.2.5, 10.8, 11.6 |
| 264 | PCI: RACF Files Accessed | PCI_RACF_Files_Accessed | Displays all files accessed on RACF servers to ensure appropriate access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.2, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 265 | PCI: RACF Password Changed | PCI_RACF_Passwords_Changed | Displays all password change activities on RACF servers to ensure authorized and appropriate access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.5.9, 8.8, 9.10, 10.8, 11.6 |
| 266 | PCI: RACF Permissions Changed | PCI_RACF_Permissions_Changed | Displays all permission modification activities on RACF to ensure authorized access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.2, 7.3, 8.5.1, 8.5.4, 8.8, 9.10, 10.8, 11.6 |
| 267 | PCI: RACF Process Started | PCI_RACF_Process_Started | Displays all processes started on the RACF servers. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.2, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 268 | PCI: RACF Successful Logins | PCI_RACF_Successful_Logins | Displays successful logins to ensure only authorized personnel have access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.1.5, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.5.16, 8.8, 9.10, 10.2.5, 10.8, 11.6 |
| 269 | PCI: Root Logins | Not Applicable | Displays root logins. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.1, 8.5.8, 8.6, 8.8, 9.10, 10.1, 10.8, 11.6 |
| 270 | PCI: Software Update Successes on i5/OS | PCI_Software_Update_Successes_on_i5_OS | Displays all i5/OS successful events related to the system's software or patch update. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.2, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 271 | PCI: Successful Logins | Not Applicable | Displays successful logins to ensure only authorized personnel have access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.1.5, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.5.16, 8.8, 9.10, 10.2.5, 10.8, 11.6 |
| 272 | PCI: Sybase ASE Database Configuration Changes | PCI_Sybase_ASE_Database_Configuration_Changes | Displays configuration changes to the Sybase database. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 273 | PCI: Sybase ASE Database Data Access | PCI_Sybase_ASE_Database_Data_Access | Displays Sybase ASE events involving the SELECT statement. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.1, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 274 | PCI: Sybase ASE Database User Additions and Deletions | PCI_Sybase_ASE_Database_User_Additions_and_Deletions | Displays Sybase database events related to creation and deletion of database users. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.1, 8.5.4, 8.5.8, 8.8, 9.10, 10.8, 11.6 |
| 275 | PCI: Sybase ASE Failed Logins | PCI_Sybase_ASE_Failed_Logins | Displays failed Sybase ASE database logins. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.2.1, 10.2.2, 10.2.4, 10.2.5, 10.8, 11.6 |
| 276 | PCI: Sybase ASE Successful Logins | PCI_Sybase_ASE_Successful_Logins | Displays successful Sybase ASE database logins. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.1.5, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.5.16, 8.8, 9.10, 10.2.5, 10.8, 11.6 |
| 277 | PCI: Symantec Endpoint Protection Configuration Changes | PCI_Symantec_Endpoint _Protection_Configuration_Changes |
Displays Symantec Endpoint Protection configuration changes. | 1.1.1, 1.1.6, 1.1.7, 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 278 | PCI: Symantec Endpoint Protection Password Changes | PCI_Symantec_Endpoint _Protection_Password_Changes |
Displays all password change activities on Symantec Endpoint Protection to ensure authorized and appropriate access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.5.9, 8.8, 9.10, 10.8, 11.6 |
| 279 | PCI: Symantec Endpoint Protection Policy Add, Remove, or Modify | PCI_Symantec_ Endpoint_Protection _Policy_Add_Remove_or_Modify |
Displays all events when a Symantec Endpoint Protection policy is added, removed, or modified. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 7.1, 7.2, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 280 | PCI: Symantec Endpoint Protection: Attacks by Threat Name | PCI_Symantec_ Endpoint_Protection _Attacks_by_Threat_Name |
Displays Symantec Endpoint Protection attacks by threat name. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.5, 11.6, 12.10.5 |
| 281 | PCI: Symantec Endpoint Protection: Attacks Detected | PCI_Symantec_ Endpoint_Protection_Attacks_Detected |
Displays attacks detected by Symantec Endpoint Protection. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.5, 11.6, 12.10.5 |
| 282 | PCI: Symantec Endpoint Protection: Scans | PCI_Symantec_Endpoint_Protection_Scans | Displays scans using Symantec Endpoint Protection. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.5, 11.6 |
| 283 | PCI: Symantec Endpoint Protection: Updated | PCI_Symantec_Endpoint_Protection_Updated | Displays updates to Symantec Endpoint Protection. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.2, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 284 | PCI: System Restarted | Not Applicable | Displays all logs related to system restarts. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 285 | PCI: TIBCO ActiveMatrix Administrator Failed Logins | PCI_TIBCO_ActiveMatrix_Administrator_Failed_Logins | Displays all TIBCO ActiveMatrix Administrator login events which have failed. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.2.1, 10.2.2, 10.2.4, 10.2.5, 10.8, 11.6 |
| 286 | PCI: TIBCO ActiveMatrix Administrator Permission Changes | PCI_TIBCO_ActiveMatrix _Administrator_Permission_Changes |
Displays events related to TIBCO ActiveMatrix Administrator permission modifications. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.2, 7.3, 8.5.1, 8.5.4, 8.8, 9.10, 10.8, 11.6 |
| 287 | PCI: TIBCO ActiveMatrix Administrator Successful Logins | PCI_TIBCO_ActiveMatrix_ Administrator_Successful_Logins |
Displays successful logins to TIBCO ActiveMatrix Administrator to ensure only authorized personnel have access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.1.5, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.5.16, 8.8, 9.10, 10.2.5, 10.8, 11.6 |
| 288 | PCI: TIBCO Administrator Password Changes | PCI_TIBCO_Administrator_Password_Changes | Displays all password change activities on TIBCO Administrator to ensure authorized and appropriate access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.5.9, 8.8, 9.10, 10.8, 11.6 |
| 289 | PCI: TIBCO Administrator Permission Changes | PCI_TIBCO_Administrator_Permission_Changes | Displays events related to TIBCO Administrator permission modifications. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.2, 7.3, 8.5.1, 8.5.4, 8.8, 9.10, 10.8, 11.6 |
| 290 | Not Applicable | PCI_TIBCO_Spotfire_Failed_Logins | Failed logins to the TIBCO Spotfire. | No Compliance Mapping |
| 291 | Not Applicable | PCI_TIBCO_Spotfire_Group_Members_Deleted | Displays all accounts deleted to groups to ensure appropriate access. | No Compliance Mapping |
| 292 | Not Applicable | PCI_TIBCO_Spotfire_Password_Changes | Displays all password change activities on TIBCO Spotfire to ensure authorized and appropriate access. | No Compliance Mapping |
| 293 | Not Applicable | PCI_TIBCO_Spotfire_Successful_Logins | Successful logins to the TIBCO Spotfire. | No Compliance Mapping |
| 294 | Not Applicable | PCI_TIBCO_Spotfire_User_Permission_Change | A permission role has been added, changed, removed, or applied to a user on TIBCO Spotfire server. | No Compliance Mapping |
| 295 | PCI: TrendMicro Control Manager: Attacks Detected | PCI_TrendMicro_Control_Manager_Attacks_Detected | Displays attacks detected by TrendMicro Control Manager. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.5, 11.6, 12.10.5 |
| 296 | PCI: TrendMicro Control Manager: Attacks Detected by Threat Name | PCI_TrendMicro_Control_ Manager_Attacks_Detected _by_Threat_Name |
Displays attacks detected by TrendMicro Control Manager by threat name. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.5, 11.6, 12.10.5 |
| 297 | PCI: TrendMicro OfficeScan: Attacks Detected | PCI_TrendMicro_OfficeScan_Attacks_Detected | Displays attacks detected by TrendMicro OfficeScan. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.5, 11.6, 12.10.5 |
| 298 | PCI: TrendMicro OfficeScan: Attacks Detected by Threat Name | PCI_TrendMicro_ OfficeScan_Attacks _Detected_by_Threat_Name |
Displays attacks detected by TrendMicro OfficeScan bythreat name. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.5, 11.6, 12.10.5 |
| 299 | PCI: Tripwire Modifications, Additions, and Deletions | PCI_Tripwire_ Modifications_Additions_and_Deletions |
Displays system modifications, additions, and deletions detected by Tripwire. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.5, 11.6, 12.10.5 |
| 300 | PCI: Unauthorized Logins | Not Applicable | Displays all logins from unauthorized users to ensure appropriate access to data. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.3, 8.8, 9.10, 10.2.1, 10.2.2, 10.2.4, 10.2.5, 10.8, 11.6 |
| 301 | PCI: Unencrypted Network Services - Check Point | PCI_Unencrypted_Network_Services_Check_Point | Displays Check Point firewall traffic containing unencrypted network services. | 1.1.7, 1.5, 2.2.2, 2.2.3, 2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 302 | PCI: Unencrypted Network Services - Cisco ASA | PCI_Unencrypted _Network_Services_Cisco_ASA |
Displays Cisco ASA firewall traffic containing unencrypted network services. | 1.1.7, 1.5, 2.2.2, 2.2.3, 2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 303 | PCI: Unencrypted Network Services - Cisco FWSM | PCI_Unencrypted_Network _Services_Cisco_FWSM |
Displays Cisco FWSM firewall traffic containing unencrypted network services. | 1.1.7, 1.5, 2.2.2, 2.2.3, 2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 304 | PCI: Unencrypted Network Services - Cisco IOS | PCI_Unencrypted_Network_Services_Cisco_IOS | Displays Cisco IOS firewall traffic containing unencrypted network services. | 1.1.7, 1.5, 2.2.2, 2.2.3, 2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 305 | PCI: Unencrypted Network Services - Cisco Netflow | PCI_Unencrypted_Network _Services_Cisco_Netflow |
Displays Cisco Netflow traffic containing unencrypted network services. | 1.1.7, 1.5, 2.2.2, 2.2.3, 2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 306 | PCI: Unencrypted Network Services - Fortinet | PCI_Unencrypted_Network _Services_Fortinet |
Displays Fortinet firewall traffic containing unencrypted network services. | 1.1.7, 1.5, 2.2.2, 2.2.3, 2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 307 | PCI: Unencrypted Network Services - Juniper JunOS | PCI_Unencrypted_Network _Services_Juniper_JunOS |
Displays Juniper JunOS firewall traffic containing unencrypted network services. | 1.1.7, 1.5, 2.2.2, 2.2.3, 2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 308 | PCI: Unencrypted Network Services - Nortel | Not Applicable | Displays Nortel firewall traffic containing unencrypted network services. | 1.1.7, 1.5, 2.2.2, 2.2.3, 2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 309 | PCI: Unencrypted Network Services - PANOS | PCI_Unencrypted_Network _Services_PANOS |
Displays Palo Alto Networks firewall traffic containing unencrypted network services. | 1.1.7, 1.5, 2.2.2, 2.2.3, 2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 310 | PCI: UNIX Failed Logins | PCI_UNIX_Failed_Logins | Displays failed UNIX logins for known and unknown users. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.2.1, 10.2.2, 10.2.4, 10.2.5, 10.8, 11.6 |
| 311 | PCI: vCenter Change Attributes | PCI_vCenter_Change_Attributes | Modification of VMware vCenter and VMware ESX properties. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.1, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 312 | PCI: vCenter Data Move | PCI_vCenter_Data_Move | Entity has been moved within the VMware vCenter infrastructure. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.2, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 313 | PCI: vCenter Datastore Events | PCI_vCenter_Datastore_Events | Displays create, modify, and delete datastore events on VMware vCenter. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.2, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 314 | PCI: vCenter Failed Logins | PCI_vCenter_Failed_Logins | Failed logins to the VMware vCenter console. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.2.1, 10.2.2, 10.2.4, 10.2.5, 10.8, 11.6 |
| 315 | PCI: vCenter Modify Firewall Policy | PCI_vCenter_Modify_Firewall_Policy | Displays changes to the VMware ESX allowed servicesfirewall policy. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 7.1, 7.2, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 316 | PCI: vCenter Resource Usage Change | PCI_vCenter_Resource_Usage_Change | Resources have changed on VMware vCenter. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.1, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 317 | PCI: vCenter Restart ESX Services | PCI_vCenter_Restart_ESX_Services | VMware vCenter restarted services running on VMware ESX Server. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.2, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 318 | PCI: vCenter Shutdown or Restart of ESX Server | PCI_vCenter_Shutdown _or_Restart_of_ESX_Server |
VMware ESX Server is shutdown or restarted from VMware vCenter console. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 319 | PCI: vCenter Successful Logins | PCI_vCenter_Successful_Logins | Successful logins to the VMware vCenter console. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.1.5, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.5.16, 8.8, 9.10, 10.2.5, 10.8, 11.6 |
| 320 | PCI: vCenter User Permission Change | PCI_vCenter_User_Permission_Change | A permission role has been added, changed, removed, or applied to a user on VMware vCenter server. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.2, 7.3, 8.5.1, 8.5.4, 8.8, 9.10, 10.8, 11.6 |
| 321 | PCI: vCenter Virtual Machine Created | PCI_vCenter_Virtual_Machine_Created | Virtual machine has been created from VMware vCenter console. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 322 | PCI: vCenter Virtual Machine Deleted | PCI_vCenter_Virtual_Machine_Deleted | Virtual machine has been deleted or removed from VMware vCenter console. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 323 | PCI: vCenter Virtual Machine Shutdown | PCI_vCenter_Virtual_Machine_Shutdown | Virtual machine has been shutdown or paused from VMware vCenter console. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 324 | PCI: vCenter Virtual Machine Started | PCI_vCenter_Virtual_Machine_Started | Virtual machine has been started or resumed from VMware vCenter console. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 325 | PCI: vCenter vSwitch Added, Changed or Removed | PCI_vCenter_ vSwitch_Added_Changed_or_Removed |
vSwitch on VMware ESX server has been added, modified or removed from the VMware vCenter console. | 1.1.1, 1.1.6, 1.1.7, 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 326 | PCI: VPN Users Accessing Corporate Network | Not Applicable | Displays all users logging into the corporate network via Virtual Private Network to ensure appropriate access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7,7.1, 7.2, 7.3, 8.1, 8.1.5, 8.5.4, 8.5.8, 8.8, 9.10, 10.2.1, 10.2.2, 10.2.4, 10.2.5, 10.8, 11.6 |
| 327 | PCI: Web Access to Applications | Not Applicable | Displays all web-based access to applications to ensure appropriate and authorized access. | 1.1.6, 1.1.7, 1.2, 1.3.2, 1.3.5, 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 328 | PCI: Web Access to Applications - F5 BIG-IP TMOS | PCI_Web_Access_ to_Applications_F5_BIG-IP_TMOS |
Displays all web-based access to applications to ensure appropriate and authorized access on F5 BIG-IP TMOS. | 1.1.6, 1.1.7, 1.2, 1.3.2, 1.3.5, 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 329 | PCI: Web Access to Applications - Fortinet | PCI_Web_Access_to_Applications_Fortinet | Displays all web-based access to applications to ensure appropriate and authorized access on Fortinet. | 1.1.6, 1.1.7, 1.2, 1.3.2, 1.3.5, 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 330 | PCI: Web Access to Applications - Microsoft IIS | Not Applicable | Displays all web-based access to applications to ensure appropriate and authorized access on Microsoft IIS. | 1.1.6, 1.1.7, 1.2, 1.3.2, 1.3.5, 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 331 | PCI: Web Access to Applications - PANOS | PCI_Web_Access_to_Applications_PANOS | Displays all web-based access to applications to ensure appropriate and authorized access on Palo Alto Networks. | 1.1.6, 1.1.7, 1.2, 1.3.2, 1.3.5, 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 332 | PCI: Windows Accounts Enabled | PCI_Windows_Accounts_Enabled | Displays all accounts enabled on Windows servers to ensure authorized and appropriate access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.8, 11.6 |
| 333 | PCI: Windows Accounts Locked | PCI_Windows_Accounts_Locked | Displays all accounts locked out of Windows servers to detect access violations or unusual activities. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.5.1, 8.5.13, 8.8, 9.10, 10.8, 11.6 |
| 334 | PCI: Windows Audit Logs Cleared | PCI_Windows_Audit_Logs_Cleared | Displays all audit logs clearing activities on Windows servers to detect access violations or unusual activity. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.2.3, 10.2.6, 10.5.1, 10.5.2, 10.5.3, 10.5.5, 10.6, 10.8, 11.6 |
| 335 | PCI: Windows New Services Installed | PCI_Windows_New_Services_Installed | Displays a list of new services installed on Windows servers to ensure authorized access. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.2, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 336 | PCI: Windows Servers Restarted | PCI_Windows_Servers_Restarted | Displays all Windows server restart activities to detect unusual activities. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 337 | PCI: Windows Software Update Activities | PCI_Windows_Software_Update_Activities | Displays all events related to the system's software or patch update. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.2, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 338 | PCI: Windows Software Update Failures | PCI_Windows_Software_Update_Failures | Displays all failed events related to the system's software or patch update. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.2, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |
| 339 | PCI: Windows Software Update Successes | PCI_Windows_Software_Update_Successes | Displays all successful events related to the system's software or patch update. | 1.5, 2.5, 3.7, 4.3, 5.4, 6.2, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6 |