TIBCO LogLogic Reports and Filter Bloks for PCI

The following table lists the reports and filter bloks included in LogLogic Compliance Suite - PCI Edition.

# Real-Time Report Name Advanced Filter Blok Name Description Compliance Mapping
1 PCI: Account Activities on UNIX Servers PCI_Account_Activities_on_
UNIX_Servers
Displays all accounts activities on UNIX servers to ensure authorized and appropriate access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.8, 9.10, 10.8, 11.6
2 PCI: Account Activities on Windows Servers PCI_Account_Activities_on_
Windows_Servers
Displays all accounts activities on Windows servers to ensure authorized and appropriate access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.8, 9.10, 10.8, 11.6
3 PCI: Accounts Changed on NetApp Filer PCI_Accounts_Changed_
on_NetApp_Filer
Displays all accounts
changed on NetApp Filer to ensure authorized and appropriate access.
1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.8, 11.6
4 PCI: Accounts Changed on TIBCO ActiveMatrix Administrator PCI_Accounts_Changed_
on_TIBCO_ActiveMatrix_Administrator
Displays all
accounts changed on TIBCO ActiveMatrix Administrator to ensure authorized and appropriate access.
1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.8, 11.6
5 PCI: Accounts Changed on TIBCO Administrator PCI_Accounts_Changed_on_TIBCO_Administrator Displays all accounts changed
on TIBCO Administrator to ensure authorized and appropriate access.
1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.8, 11.6
6 PCI: Accounts Changed on UNIX Servers PCI_Accounts_Changed_on_UNIX_Servers Displays all accounts changed on UNIX servers
to ensure authorized and appropriate access.
1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.8, 11.6
7 PCI: Accounts Changed on Windows Servers PCI_Accounts_Changed_
on_Windows_Servers
Displays all accounts changed
on Windows servers to ensure authorized and appropriate access.
1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.8, 11.6
8 PCI: Accounts Created on NetApp Filer PCI_Accounts_Created_on_NetApp_Filer Displays all accounts created on NetApp Filer
to ensure authorized and appropriate access.
1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.8, 11.6
9 PCI: Accounts Created on NetApp Filer Audit PCI_Accounts_Created_on_NetApp_Filer_Audit Displays all accounts created on NetApp
Filer Audit to ensure authorized and appropriate access.
1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.8, 11.6
10 PCI: Accounts Created on Symantec Endpoint Protection PCI_Accounts_Created_
on_Symantec_Endpoint_Protection
Displays all accounts created on Symantec Endpoint Protection to ensure authorized and appropriate access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.8, 11.6
11 PCI: Accounts Created on TIBCO ActiveMatrix Administrator PCI_Accounts_Created_on
_TIBCO_ActiveMatrix_Administrator
Displays all accounts created on TIBCO ActiveMatrix Administrator to ensure authorized and appropriate access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.8, 11.6
12 PCI: Accounts Created on TIBCO Administrator PCI_Accounts_
Created_on_TIBCO_Administrator
Displays all accounts created on TIBCO Administrator
to ensure authorized and appropriate access.
1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.8, 11.6
13 PCI: Accounts Created on UNIX Servers PCI_Accounts_Created_on_UNIX_Servers Displays all accounts created on UNIX servers
to ensure authorized and appropriate access.
1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.8, 11.6
14 PCI: Accounts Created on Windows Servers PCI_Accounts_Created_on_Windows_Servers Displays all accounts created on Windows
servers to ensure authorized and appropriate access.
1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.8, 11.6
15 PCI: Accounts Deleted on NetApp Filer PCI_Accounts_
Deleted_on_NetApp_Filer
Displays all accounts deleted on NetApp
Filer to ensure authorized and appropriate access.
1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.5.4, 8.8, 9.10, 10.8, 11.6
16 PCI: Accounts Deleted on NetApp Filer Audit PCI_Accounts_Deleted_
on_NetApp_Filer_Audit
Displays all accounts deleted on NetApp
Filer Audit to ensure authorized and appropriate access.
1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.5.4, 8.8, 9.10, 10.8, 11.6
17 PCI: Accounts Deleted on Symantec Endpoint Protection PCI_Accounts_Deleted_
on_Symantec_Endpoint_Protection
Displays all accounts deleted on Symantec Endpoint Protection to ensure authorized and appropriate access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.5.4, 8.8, 9.10, 10.8, 11.6
18 PCI: Accounts Deleted on TIBCO ActiveMatrix Administrator PCI_Accounts_
Deleted_on_TIBCO_ActiveMatrix_Administrator
Displays all accounts deleted on TIBCO ActiveMatrix Administrator to ensure authorized and appropriate access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.5.4, 8.8, 9.10, 10.8, 11.6
19 PCI: Accounts Deleted on TIBCO Administrator PCI_Accounts_Deleted_
on_TIBCO_Administrator
Displays all accounts deleted on TIBCO Administrator
to ensure authorized and appropriate access.
1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.5.4, 8.8, 9.10, 10.8, 11.6
20 PCI: Accounts Deleted on UNIX Servers PCI_Accounts_Deleted_on_UNIX_Servers Displays all accounts deleted on UNIX servers to ensure authorized and appropriate access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.5.4, 8.8, 9.10, 10.8, 11.6
21 PCI: Accounts Deleted on Windows Servers PCI_Accounts_Deleted_on_Windows_Servers Displays all accounts deleted on Windows servers to ensure authorized and appropriate access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.5.4, 8.8, 9.10, 10.8, 11.6
22 PCI: Active Directory System Changes PCI_Active_Directory_System_Changes Displays changes made within Active Directory. 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.1, 7.2, 7.3, 8.1, 8.5.1, 8.5.4, 8.5.8, 8.5.9, 8.5.13, 8.8, 9.10, 10.1, 10.2.1, 10.2.2, 10.2.4, 10.8, 11.6
23 PCI: Administrator Logins on Windows Servers PCI_Administrator_
Logins_on_Windows_Servers
Displays all logins with
the administrator account on Windows servers.
1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.1, 8.5.8, 8.6, 8.8, 10.1, 9.10, 10.8, 11.6
24 PCI: Administrators Activities on Servers Not Applicable Displays the latest activities performed
by administrators and root users to ensure appropriate access.
1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.1, 10.2.1, 10.2.2, 10.2.4, 10.2.5, 10.8, 11.6
25 Not Applicable PCI_Amazon_Cloudtrail_Change_Events Displays all Amazon Cloudtrail audit events related to policy objects changed. 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 7.1, 7.2, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
26 Not Applicable PCI_Amazon_Cloudtrail_Create_Events Displays all Amazon Cloudtrail
audit events related to policy objects created.
1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.8, 11.6
27 Not Applicable PCI_Amazon_Cloudtrail_Delete_Events Displays all Amazon Cloudtrail
audit events related to policy objects deleted.
1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.5.4, 8.8, 9.10, 10.8, 11.6
28 Not Applicable PCI_Amazon_Cloudtrail_Failed_Logins Displays all failed login attempts to review any access violations or unusual activity. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.2.1, 10.2.2, 10.2.4, 10.2.5, 10.8, 11.6
29 Not Applicable PCI_Amazon_Cloudtrail_Successful_Logins Displays successful Amazon Cloudtrail logins. 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.1.5, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.5.16, 8.8, 9.10, 10.2.5, 10.8, 11.6
30 PCI: Applications Through Firewalls Not Applicable Displays the most active applications used through the firewalls. 1.1.6, 1.1.7, 1.2, 1.3.2, 1.3.5, 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
31 PCI: Applications Under Attack Not Applicable Displays all applications under attack as well as the attack signatures. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.4, 11.6, 12.10.5
32 PCI: Applications Under Attack - Cisco IOS PCI_Applications_Under_Attack_Cisco_IOS Displays all applications under attack as well as the attack signatures by Cisco IOS. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.4, 11.6, 12.10.5
33 PCI: Applications Under Attack - FireEye MPS PCI_Applications_Under_
Attack_FireEye_MPS
Displays all applications under attack as well as the attack signatures by FireEye MPS. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.4, 11.6, 12.10.5
34 PCI: Applications Under Attack - ISS SiteProtector PCI_Applications_Under_
Attack_ISS_SiteProtector
Displays all applications under attack as well as the attack signatures by ISS SiteProtector. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.4, 11.6, 12.10.5
35 PCI: Applications Under Attack - SiteProtector PCI_Applications_Under_
Attack_SiteProtector
Displays all applications under attack as well as the attack signatures by SiteProtector. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.4, 11.6, 12.10.5
36 PCI: Applications Under Attack - Sourcefire Defense Center PCI_Applications_Under_Attack_Cisco_FirePower Displays all applications under attack as well as the attack signatures by Cisco FirePower and Sourcefire Defense Center. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.4, 11.6, 12.10.5
37 PCI: Attack Origins Not Applicable Displays the sources that have initiated the most attacks. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.4, 11.6, 12.10.5
38 PCI: Attack Origins - Cisco IOS PCI_Attack_Origins_Cisco_IOS Displays the sources that have initiated the most attacks by Cisco IOS. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.4, 11.6, 12.10.5
39 PCI: Attack Origins - ISS SiteProtector PCI_Attack_Origins_ISS_SiteProtector Displays the sources that have initiated the most attacks by ISS SiteProtector. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.4, 11.6, 12.10.5
40 PCI: Attack Origins - McAfee HIPS PCI_Attack_Origins_
McAfee_HIPS
Displays the sources that have initiated the most attacks by McAfee HIPS. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.4, 11.6, 12.10.5
41 PCI: Attack Origins - SiteProtector PCI_Attack_Origins_SiteProtector Displays the sources that have initiated the most attacks by SiteProtector. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.4, 11.6, 12.10.5
42 PCI: Attack Origins - Sourcefire Defense Center PCI_Attack_Origins_
Cisco_FirePower
Displays the sources that have initiated the most attacks by Cisco FirePower and Sourcefire Defense Center. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.4, 11.6, 12.10.5
43 PCI: Attacks Detected Not Applicable Displays all IDS attacks detected to servers and applications. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.4, 11.6, 12.10.5
44 PCI: Attacks Detected - Cisco IOS PCI_Attacks_Detected_
Cisco_IOS
Displays all IDS attacks detected to servers and applications by Cisco IOS. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.4, 11.6, 12.10.5
45 PCI: Attacks Detected - ISS SiteProtector PCI_Attacks_Detected_
ISS_SiteProtector
Displays all IDS attacks detected to servers and applications by ISS SiteProtector. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.4, 11.6, 12.10.5
46 PCI: Attacks Detected - McAfee HIPS PCI_Attacks_Detected_McAfee_HIPS Displays all IPS attacks detected to servers and applications by McAfee HIPS. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.4, 11.6, 12.10.5
47 PCI: Attacks Detected - SiteProtector PCI_Attacks_Detected_SiteProtector Displays all IDS attacks detected to servers and applications by SiteProtector. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.4, 11.6, 12.10.5
48 PCI: Attacks Detected - Sourcefire Defense Center PCI_Attacks_Detected_
Cisco_FirePower
Displays all IDS attacks detected to servers and applications by Cisco FirePower and Sourcefire Defense Center. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.4, 11.6, 12.10.5
49 PCI: Check Point Configuration Changes PCI_Check_Point_Configuration_Changes Displays all Check Point audit events related to configuration changes. 1.1.1, 1.1.6, 1.1.7, 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
50 PCI: Check Point Management Station Login PCI_Check_Point_Management_Station_Login Displays all login events to the Check Point management station. 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.1.5, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.5.16, 8.8, 9.10, 10.2.5, 10.8, 11.6
51 PCI: Check Point Objects Created PCI_Check_Point_
Objects_Created
Displays all Check Point audit events related to object creation in policies. 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
52 PCI: Check Point Objects Deleted PCI_Check_Point_Objects_Deleted Displays all Check Point audit events related to policy objects deleted. 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
53 PCI: Check Point Objects Modified PCI_Check_Point_Objects_Modified Displays all Check Point audit events related to policy objects modified. 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
54 PCI: Check Point SIC Revoked PCI_Check_Point_SIC_Revoked Displays all Check Point audit events related to the security certificate being revoked. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
55 PCI: Cisco ASA, FWSM Failover Disabled PCI_Cisco_ASA_FWSM_Failover_Disabled Displays all logs related to disabling Cisco ASA and FWSM failover capability. 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
56 PCI: Cisco ASA, FWSM Failover Performed PCI_Cisco_ASA_FWSM_Failover_Performed Displays all logs related to performing a Cisco ASA and FWSM failover. 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
57 PCI: Cisco ASA, FWSM Policy Changed PCI_Cisco_ASA_FWSM_Policy_Changed Displays all configuration changes made to the Cisco ASA and FWSM devices. 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 7.1, 7.2, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
58 PCI: Cisco ASA, FWSM Restarted PCI_Cisco_ASA_FWSM_Restarted Displays all Cisco ASA or FWSM restart activities to detect unusual activities. 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
59 PCI: Cisco ASA, FWSM Routing Failure PCI_CIsco_ASA_FWSM_Routing_Failure Displays all Cisco ASA and FWSM routing error messages. 1.1.1, 1.1.6, 1.1.7, 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
60 PCI: Cisco ESA: Attacks by Event ID PCI_Cisco_ESA_Attacks_by_Event_ID Displays Cisco ESA attacks by Event ID. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.5, 11.6, 12.10.5
61 PCI: Cisco ESA: Attacks by Threat Name PCI_Cisco_ESA_Attacks_by_Threat_Name Displays Cisco ESA attacks by threat name. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.5, 11.6, 12.10.5
62 PCI: Cisco ESA: Attacks Detected PCI_Cisco_ESA_Attacks_Detected Displays attacks detected by Cisco ESA. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.5, 11.6, 12.10.5
63 PCI: Cisco ESA: Scans PCI_Cisco_ESA_Scans Displays scans using Cisco ESA. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.5, 11.6
64 PCI: Cisco ESA: Updated PCI_Cisco_ESA_Updated Displays updates to Cisco ESA. 1.5, 2.5, 3.7, 4.3, 5.4, 6.2, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
65 PCI: Cisco FWSM HA State Changed PCI_Cisco_FWSM_HA_State_Changed Displays all Cisco FWSM firewall fail-over state change events. 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.1, 7.3, 8.8, 9.10, 10.8, 11.6
66 PCI: Cisco ISE, ACS Accounts Created PCI_Cisco_ISE_ACS_Accounts_Created Displays all accounts created on Cisco ISE and Cisco SecureACS to ensure authorized and appropriate access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.8, 11.6
67 PCI: Cisco ISE, ACS Accounts Removed PCI_Cisco_ISE_ACS_Accounts_Removed Displays all accounts removed on Cisco ISE and Cisco SecureACS to ensure authorized and appropriate access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.5.4, 8.8, 9.10, 10.8, 11.6
68 PCI: Cisco ISE, ACS Configuration Changes PCI_Cisco_ISE_ACS_Configuration_Changes Displays Cisco ISE and Cisco SecureACS configuration changes. 1.1.1, 1.1.6, 1.1.7, 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
69 PCI: Cisco ISE, ACS Password Changes PCI_Cisco_ISE_ACS_Password_Changes Displays all password change activities on Cisco ISE and Cisco SecureACS to ensure authorized and appropriate access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.5.9, 8.8, 9.10, 10.8, 11.6
70 PCI: Cisco Peer Reset/Reload PCI_Cisco_Peer_Reset_Reload Displays all Cisco Peer reset and reload events. 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
71 PCI: Cisco Peer Supervisor Status Changes PCI_Cisco_Peer_Supervisor_Status_Changes Displays all Cisco Peer Supervisor status changes. 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.1, 7.3, 8.8, 9.10, 10.8, 11.6
72 PCI: Cisco Redundancy Version Check Failed PCI_Cisco_Redundancy_Version_Check_Failed Displays all Cisco redundancy version check failures. 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
73 PCI: Cisco Routers and Switches Restart PCI_Cisco_Routers_and_Switches_Restart Displays all Cisco routers and switches restart activities to detect unusual activities. 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
74 PCI: Cisco Switch Policy Changes PCI_Cisco_Switch_Policy_Changes Displays all configuration changes to the Cisco router and switch policies. 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 7.1, 7.2, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
75 PCI: Creation and Deletion of System Level Objects: AIX Audit PCI_Creation_and_Deletion
_of_System_Level_Objects_AIX_Audit
Displays AIX audit events related to creation and deletion of system-level objects. 1.5, 2.5, 3.7, 4.3,
5.4, 6.7, 7.3, 8.8, 9.10, 10.2.7, 10.8, 11.6
76 PCI: Creation and Deletion of System Level Objects: DB2 Database PCI_Creation_and_Deletion
_of_System_Level_Objects_
DB2_Database
Displays DB2 database events related to creation and deletion of system-level objects. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.2.7, 10.8, 11.6
77 PCI: Creation and Deletion of System Level Objects: HP-UX Audit PCI_Creation_and_Deletion
_of_System_Level_Objects
_HP-UX_Audit
Displays HP-UX audit events related to creation and deletion of system-level objects. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10,
10.2.7, 10.8, 11.6
78 PCI: Creation and Deletion of System Level Objects: Oracle PCI_Creation_and
_Deletion_of_System_
Level_Objects_Oracle
Displays Oracle database events related to creation and deletion of system-level objects. 1.5, 2.5, 3.7, 4.3,
5.4, 6.7, 7.3, 8.8, 9.10,
10.2.7, 10.8, 11.6
79 PCI: Creation and Deletion of System Level Objects: Solaris BSM PCI_Creation_
and_Deletion_of_
System_Level_Objects_Solaris_BSM
Displays Solaris BSM events related to creation and deletion of system-level objects. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.2.7, 10.8, 11.6
80 PCI: Creation and Deletion of System Level Objects: SQL Server PCI_Creation_and_Deletion_of_
System_Level_Objects_SQL_Server
Displays Microsoft SQL Server events related to creation and deletion of system-level objects. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.2.7, 10.8, 11.6
81 PCI: Creation and Deletion of System Level Objects: Windows PCI_Creation_and_Deletion
_of_System_Level_Objects
_Windows
Displays all Windows events related to creation and deletion of system-level objects. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.2.7, 10.8, 11.6
82 PCI: DB2 Database Configuration Changes PCI_DB2_Database_Configuration
_Changes
Displays DB2 database configuration changes. 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
83 PCI: DB2 Database Failed Logins PCI_DB2_Database_Failed_Logins Displays all failed login attempts to review any access violations or unusual activity. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.2.1, 10.2.2, 10.2.4, 10.2.5, 10.8, 11.6
84 PCI: DB2 Database Successful Logins PCI_DB2_Database_Successful_Logins Displays successful DB2 database logins. 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.1.5, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.5.16, 8.8, 9.10, 10.2.5, 10.8, 11.6
85 PCI: DB2 Database User Additions and Deletions PCI_DB2_Database
_User_Additions_and_Deletions
Displays IBM DB2 Database events related to creation and deletion of database users. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.1, 8.5.4, 8.5.8, 8.8, 9.10, 10.8, 11.6
86 PCI: DHCP Activities on Microsoft DHCP PCI_DHCP_Activities_on_Microsoft_DHCP Displays all DHCP activities on Microsoft DHCP Server. 1.5, 2.2.2, 2.2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
87 PCI: DNS Server Error PCI_DNS_Server_Error Displays all events when DNS Server has errors. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.7, 10.8, 11.6
88 PCI: Escalated Privilege Activities on Servers Not Applicable Displays all privilege escalation activities performed on servers to ensure appropriate access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.1, 10.2.1, 10.2.2, 10.2.4, 10.2.5, 10.8, 11.6
89 PCI: ESX Accounts Activities PCI_ESX_Accounts_Activities Displays all accounts activities on VMware ESX servers to ensure authorized and appropriate access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.8, 9.10, 10.8, 11.6
90 PCI: ESX Accounts Created PCI_ESX_Accounts_Created Displays all accounts created on VMware ESX servers to ensure authorized and appropriate access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.8, 11.6
91 PCI: ESX Accounts Deleted PCI_ESX_Accounts_Deleted Displays all accounts deleted on VMware ESX servers to ensure authorized and appropriate access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.5.4, 8.8, 9.10, 10.8, 11.6
92 PCI: ESX Failed Logins PCI_ESX_Failed_Logins Failed VMware ESX logins for known user. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.2.1, 10.2.2, 10.2.4, 10.2.5, 10.8, 11.6
93 PCI: ESX Group Activities PCI_ESX_Group_Activities Displays all group activities on VMware ESX servers to ensure authorized and appropriate access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.5.1, 8.5.4, 8.6, 8.8, 9.10, 10.8, 11.6
94 PCI: ESX Kernel log daemon terminating PCI_ESX_Kernel_log_daemon_terminating Displays all VMware ESX Kernel log daemon terminating. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.2, 7.3, 8.8, 9.10, 10.8, 11.6
95 PCI: ESX Kernel logging Stop PCI_ESX_Kernel_logging_Stop Displays all VMware ESX Kernel logging stops. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.2, 7.3, 8.8, 9.10, 10.8, 11.6
96 PCI: ESX Logins Failed Unknown User PCI_ESX_Logins_Failed_Unknown_User Failed VMware ESX logins for unknown user. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.2.1, 10.2.2, 10.2.4, 10.2.5, 10.8, 11.6
97 PCI: ESX Logins Succeeded PCI_ESX_Logins_Succeeded Displays successful logins to VMware ESX to ensure only authorized personnel have access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.1.5, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.5.16, 8.8, 9.10, 10.2.5, 10.8, 11.6
98 PCI: ESX Syslogd Restart PCI_ESX_Syslogd_Restart Displays all VMware ESX syslogd restarts. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.2, 7.3, 8.8, 9.10, 10.8, 11.6
99 PCI: F5 BIG-IP TMOS Login Failed PCI_F5_BIG-IP_TMOS_Login_Failed Displays all F5 BIG-IP TMOS login events which have failed. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.2.1, 10.2.2, 10.2.4, 10.2.5, 10.8, 11.6
100 PCI: F5 BIG-IP TMOS Login Successful PCI_F5_BIG-IP_TMOS_Login_Successful Displays all F5 BIG-IP TMOS login events which have succeeded. 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.1.5, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.5.16, 8.8, 9.10, 10.2.5, 10.8, 11.6
101 PCI: F5 BIG-IP TMOS Password Changes PCI_F5_BIG-IP_TMOS_Password_Changes Displays all password change activities on F5 BIG-IP TMOS to ensure authorized and appropriate access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.5.9, 8.8, 9.10, 10.8, 11.6
102 PCI: F5 BIG-IP TMOS Restarted PCI_F5_BIG-IP_TMOS_Restarted Displays all events when the F5 BIG-IP TMOS has been restarted. 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
103 PCI: Failed Logins Not Applicable Displays all failed login attempts to review any access violations or unusual activity. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.2.1, 10.2.2, 10.2.4, 10.2.5, 10.8, 11.6
104 PCI: Files Accessed on NetApp Filer Audit PCI_Files_Accessed_on_NetApp_Filer_Audit Displays all files accessed on NetApp Filer Audit to ensure appropriate access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.2, 7.3, 8.8, 9.10, 10.8, 11.6
105 PCI: Files Accessed on Servers Not Applicable Displays all files accessed on servers to ensure appropriate access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.2, 7.3, 8.8, 9.10, 10.8, 11.6
106 PCI: Files Accessed through Juniper SSL VPN (Secure Access) PCI_Files_Accessed_through_Juniper_SSL
_VPN_Secure_Access
Displays all files accessed through Juniper SSL VPN (Secure Access). 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.2, 7.3, 8.8, 9.10, 10.8, 11.6
107 PCI: Files Accessed through PANOS PCI_Files_Accessed_through_PANOS Displays all files accessed through Palo Alto Networks. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.2, 7.3, 8.8, 9.10, 10.8, 11.6
108 PCI: Files Accessed through Pulse Connect Secure PCI_Files_Accessed_through_
Pulse_Connect_Secure
Displays all files accessed through Pulse Connect Secure. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.2, 7.3, 8.8, 9.10, 10.8, 11.6
109 PCI: FireEye MPS: Attacks by Event ID PCI_FireEye_MPS_
Attacks_by_Event_ID
Displays FireEye MPS attacks by Event ID. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.5, 11.6, 12.10.5
110 PCI: FireEye MPS: Attacks by Threat Name PCI_FireEye_MPS_Attacks_by_Threat_Name Displays FireEye MPS attacks by threat name. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.5, 11.6, 12.10.5
111 PCI: FireEye MPS: Attacks Detected PCI_FireEye_MPS_Attacks_Detected Displays attacks detected by FireEye MPS. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.5, 11.6, 12.10.5
112 PCI: Firewall Connections Accepted - Check Point PCI_Firewall_
Connections_Accepted_Check_Point
Displays all traffic passing through the Check Point firewall. 1.1.6, 1.1.7, 1.2, 1.3.1, 1.3.2, 1.3.5, 1.5, 2.2.2, 2.2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
113 PCI: Firewall Connections Accepted - Cisco IOS PCI_Firewall_Connections_Accepted_Cisco_IOS Displays all traffic passing through the Cisco IOS firewall. 1.1.6, 1.1.7, 1.2, 1.3.1, 1.3.2, 1.3.5, 1.5, 2.2.2, 2.2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
114 PCI: Firewall Connections Accepted - Cisco Netflow PCI_Firewall_
Connections_Accepted_Cisco_Netflow
Displays all traffic passing through the Cisco Netflow. 1.1.6, 1.1.7, 1.2, 1.3.1, 1.3.2, 1.3.5, 1.5, 2.2.2, 2.2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
115 PCI: Firewall Connections Accepted - Cisco NXOS PCI_Firewall_
Connections
_Accepted_Cisco_NXOS
Displays all traffic passing through the Cisco NXOS device. 1.1.6, 1.1.7, 1.2, 1.3.1, 1.3.2, 1.3.5, 1.5, 2.2.2, 2.2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
116 PCI: Firewall Connections Accepted - F5 BIG-IP TMOS PCI_Firewall_Connections_Accepted_F5_BIG-IP_TMOS Displays all traffic passing through the F5 BIG-IP TMOS device. 1.1.6, 1.1.7, 1.2, 1.3.1, 1.3.2, 1.3.5, 1.5, 2.2.2, 2.2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
117 PCI: Firewall Connections Accepted - Juniper JunOS PCI_Firewall_
Connections_Accepted_Juniper_JunOS
Displays all traffic passing through the Juniper JunOS firewall. 1.1.6, 1.1.7, 1.2, 1.3.1, 1.3.2, 1.3.5, 1.5, 2.2.2, 2.2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
118 PCI: Firewall Connections Accepted - PANOS PCI_Firewall_Connections_Accepted_PANOS Displays all traffic passing through the Palo Alto Networks firewall. 1.1.6, 1.1.7, 1.2, 1.3.1, 1.3.2, 1.3.5, 1.5, 2.2.2, 2.2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
119 PCI: Firewall Connections Denied - Check Point PCI_Firewall_Connections_Denied_Check_Point Displays the applications that have been denied access the most by the Check Point devices. 1.3.1, 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
120 PCI: Firewall Connections Denied - Cisco ASA PCI_Firewall_
Connections_Denied_Cisco_ASA
Displays the applications that have been denied access the most by the Cisco ASA devices. 1.3.1, 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
121 PCI: Firewall Connections Denied - Cisco FWSM PCI_Firewall_
Connections_Denied_Cisco_FWSM
Displays the applications that have been denied access the most by the Cisco FWSM devices. 1.3.1, 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
122 PCI: Firewall Connections Denied - Cisco IOS PCI_Firewall_Connections_Denied_Cisco_IOS Displays the applications that have been denied access the most by the Cisco IOS. 1.3.1, 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
123 PCI: Firewall Connections Denied - Cisco NXOS PCI_Firewall_Connections_Denied_Cisco_NXOS Displays the applications that have been denied access the most by the Cisco NXOS devices. 1.3.1, 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
124 PCI: Firewall Connections Denied - Cisco Router Not Applicable Displays the applications that have been denied access the most by the Cisco Router. 1.3.1, 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
125 PCI: Firewall Connections Denied - F5 BIG-IP TMOS PCI_Firewall_
Connections_Denied_F5_BIG-IP_TMOS
Displays the applications that have been denied access the most by the F5 BIG-IP TMOS. 1.3.1, 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
126 PCI: Firewall Connections Denied - Fortinet PCI_Firewall_Connections_Denied_Fortinet Displays the applications that have been denied access the most by the Fortinet devices. 1.3.1, 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
127 PCI: Firewall Connections Denied - Juniper JunOS PCI_Firewall_
Connections_Denied_Juniper_JunOS
Displays the applications that have been denied access the most by the Juniper JunOS. 1.3.1, 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
128 PCI: Firewall Connections Denied - Nortel Not Applicable Displays the applications that have been denied access the most by the Nortel devices. 1.3.1, 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
129 PCI: Firewall Connections Denied - PANOS PCI_Firewall_Connections_Denied_PANOS Displays the applications that have been denied access the most by the Palo Alto Networks devices. 1.3.1, 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
130 PCI: Firewall Traffic Besides HTTP, SSL and SSH - Check Point Not Applicable Displays all traffic passing through the Check Point that is not HTTP, SSL, and SSH. 1.1.6, 1.1.7, 1.2, 1.3.2, 1.3.5, 2.3, 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
131 PCI: Firewall Traffic Besides HTTP, SSL and SSH - Cisco ASA PCI_Firewall_Traffic_
Besides_HTTP_SSL_and_SSH_Cisco_ASA
Displays all traffic passing through the Cisco ASA that is not HTTP, SSL, and SSH. 1.1.6, 1.1.7, 1.2, 1.3.2, 1.3.5, 2.3, 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
132 PCI: Firewall Traffic Besides HTTP, SSL and SSH - Cisco FWSM PCI_Firewall_Traffic_
Besides_HTTP_SSL_and_SSH_Cisco_FWSM
Displays all traffic passing through the Cisco FWSM that is not HTTP, SSL, and SSH. 1.1.6, 1.1.7, 1.2, 1.3.2, 1.3.5, 2.3, 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
133 PCI: Firewall Traffic Besides HTTP, SSL and SSH - Cisco IOS PCI_Firewall_Traffic_
Besides_HTTP_SSL_and_SSH_Cisco_IOS
Displays all traffic passing through the Cisco IOS that is not HTTP, SSL, and SSH. 1.1.6, 1.1.7, 1.2, 1.3.2, 1.3.5, 2.3, 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
134 PCI: Firewall Traffic Besides HTTP, SSL and SSH - Cisco Netflow PCI_Firewall_Traffic_Besides_HTTP_SSL_
and_SSH_Cisco_Netflow
Displays all traffic passing through the Cisco Netflow that is not HTTP, SSL, and SSH. 1.1.6, 1.1.7, 1.2, 1.3.2, 1.3.5, 2.3, 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
135 PCI: Firewall Traffic Besides HTTP, SSL and SSH - F5 BIG-IP TMOS PCI_Firewall_Traffic_Besides_HTTP_SSL_
and_SSH_F5_BIG-IP_TMOS
Displays all traffic passing through the F5 BIG-IP TMOS that is not HTTP, SSL, and SSH. 1.1.6, 1.1.7, 1.2, 1.3.2, 1.3.5, 2.3, 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
136 PCI: Firewall Traffic Besides HTTP, SSL and SSH - Fortinet PCI_Firewall_Traffic_Besides_HTTP_SSL_
and_SSH_Fortinet
Displays all traffic passing through the Fortinet that is not HTTP, SSL, and SSH. 1.1.6, 1.1.7, 1.2, 1.3.2, 1.3.5, 2.3, 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
137 PCI: Firewall Traffic Besides HTTP, SSL and SSH - Juniper JunOS PCI_Firewall_Traffic_Besides_HTTP_SSL_
and_SSH_Juniper_JunOS
Displays all traffic passing through the Juniper JunOS that is not HTTP, SSL, and SSH. 1.1.6, 1.1.7, 1.2, 1.3.2, 1.3.5, 2.3, 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
138 PCI: Firewall Traffic Besides HTTP, SSL and SSH - Nortel Not Applicable Displays all traffic passing through the Nortel that is not HTTP, SSL, and SSH. 1.1.6, 1.1.7, 1.2, 1.3.2, 1.3.5, 2.3, 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
139 PCI: Firewall Traffic Besides HTTP, SSL and SSH - PANOS PCI_Firewall_Traffic_
Besides_HTTP_SSL_and_SSH_PANOS
Displays all traffic passing through the Palo Alto Networks that is not HTTP, SSL, and SSH. 1.1.6, 1.1.7, 1.2, 1.3.2, 1.3.5, 2.3, 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
140 PCI: Firewall Traffic Besides SSL and SSH - Check Point Not Applicable Displays all traffic passing through the Check Point that is not SSL and SSH. 1.5, 2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
141 PCI: Firewall Traffic Besides SSL and SSH - Cisco ASA PCI_Firewall_Traffic_
Besides_SSL_and_SSH_Cisco_ASA
Displays all traffic passing through the Cisco ASA that is not SSL and SSH. 1.5, 2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
142 PCI: Firewall Traffic Besides SSL and SSH - Cisco FWSM PCI_Firewall_Traffic_
Besides_SSL_and_SSH_Cisco_FWSM
Displays all traffic passing through the Cisco FWSM that is not SSL and SSH. 1.5, 2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
143 PCI: Firewall Traffic Besides SSL and SSH - Cisco IOS PCI_Firewall_Traffic_
Besides_SSL_and_SSH_Cisco_IOS
Displays all traffic passing through the Cisco IOS that is not SSL and SSH. 1.5, 2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
144 PCI: Firewall Traffic Besides SSL and SSH - Cisco Netflow PCI_Firewall_Traffic_
Besides_SSL_and_SSH_Cisco_Netflow
Displays all traffic passing through the Cisco Netflow that is not SSL and SSH. 1.5, 2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
145 PCI: Firewall Traffic Besides SSL and SSH - F5 BIG-IP TMOS PCI_Firewall_Traffic_
Besides_SSL_and_SSH_F5_BIG-IP_TMOS
Displays all traffic passing through the F5 BIG-IP TMOS that is not SSL and SSH. 1.5, 2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
146 PCI: Firewall Traffic Besides SSL and SSH - Fortinet PCI_Firewall_Traffic_
Besides_SSL_and_SSH_Fortinet
Displays all traffic passing through the Fortinet that is not SSL and SSH. 1.5, 2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
147 PCI: Firewall Traffic Besides SSL and SSH - Juniper JunOS PCI_Firewall_Traffic_
Besides_SSL_and_SSH_Juniper_JunOS
Displays all traffic passing through the Juniper JunOS that is not SSL and SSH. 1.5, 2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
148 PCI: Firewall Traffic Besides SSL and SSH - Nortel Not Applicable Displays all traffic passing through the Nortel that is not SSL and SSH. 1.5, 2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
149 PCI: Firewall Traffic Besides SSL and SSH - PANOS PCI_Firewall_Traffic_
Besides_SSL_and_SSH_PANOS
Displays all traffic passing through the Palo Alto Networks that is not SSL and SSH. 1.5, 2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
150 PCI: Firewall Traffic Considered Risky - Check Point Not Applicable Displays Check Point allowed firewall traffic that is considered risky. 1.1.7, 1.5, 2.2.2, 2.2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
151 PCI: Firewall Traffic Considered Risky - Cisco ASA PCI_Firewall_Traffic_
Considered_Risky_Cisco_ASA
Displays Cisco ASA allowed firewall traffic that is considered risky. 1.1.7, 1.5, 2.2.2, 2.2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
152 PCI: Firewall Traffic Considered Risky - Cisco FWSM PCI_Firewall_Traffic_
Considered_Risky_Cisco_FWSM
Displays Cisco FWSM allowed firewall traffic that is considered risky. 1.1.7, 1.5, 2.2.2, 2.2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
153 PCI: Firewall Traffic Considered Risky - Cisco IOS PCI_Firewall_Traffic_
Considered_Risky_Cisco_IOS
Displays Cisco IOS allowed firewall traffic that is considered risky. 1.1.7, 1.5, 2.2.2, 2.2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
154 PCI: Firewall Traffic Considered Risky - Cisco Netflow PCI_Firewall_Traffic_
Considered_Risky_Cisco_Netflow
Displays Cisco Netflow allowed firewall traffic that is considered risky. 1.1.7, 1.5, 2.2.2, 2.2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
155 PCI: Firewall Traffic Considered Risky - F5 BIG-IP TMOS PCI_Firewall_Traffic_
Considered_Risky_F5_BIG-IP_TMOS
Displays F5 BIG-IP TMOS allowed firewall traffic that is considered risky. 1.1.7, 1.5, 2.2.2, 2.2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
156 PCI: Firewall Traffic Considered Risky - Fortinet PCI_Firewall_Traffic_Considered_Risky_Fortinet Displays Fortinet allowed firewall traffic that is considered risky. 1.1.7, 1.5, 2.2.2, 2.2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
157 PCI: Firewall Traffic Considered Risky - Juniper JunOS PCI_Firewall_Traffic_
Considered_Risky_Juniper_JunOS
Displays Juniper JunOS allowed firewall traffic that is considered risky. 1.1.7, 1.5, 2.2.2, 2.2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
158 PCI: Firewall Traffic Considered Risky - Nortel Not Applicable Displays Nortel allowed firewall traffic that is considered risky. 1.1.7, 1.5, 2.2.2, 2.2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
159 PCI: Firewall Traffic Considered Risky - PANOS PCI_Firewall_Traffic_Considered_Risky_PANOS Displays Palo Alto Networks allowed firewall traffic that is considered risky. 1.1.7, 1.5, 2.2.2, 2.2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
160 PCI: FortiOS DLP Attacks Detected PCI_FortiOS_DLP_Attacks_Detected Displays all DLP attacks detected by FortiOS. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.5, 11.6, 12.10.5
161 PCI: FortiOS: Attacks by Event ID PCI_FortiOS_Attacks_by_Event_ID Displays FortiOS attacks by Event ID. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.5, 11.6, 12.10.5
162 PCI: FortiOS: Attacks by Threat Name PCI_FortiOS_Attacks_by_Threat_Name Displays FortiOS attacks by threat name. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.5, 11.6, 12.10.5
163 PCI: FortiOS: Attacks Detected PCI_FortiOS_Attacks_Detected Displays attacks detected by FortiOS. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.5, 11.6, 12.10.5
164 PCI: Group Activities on NetApp Filer Audit PCI_Group_Activities_on_NetApp_Filer_Audit Displays all group activities on NetApp Filer Audit to ensure authorized and appropriate access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.8, 8.5.1, 8.5.4, 8.6, 9.10, 10.8, 11.6
165 PCI: Group Activities on Symantec Endpoint Protection PCI_Group_Activities_on_
Symantec_Endpoint_Protection
Displays all group activities on Symantec Endpoint Protection to ensure authorized and appropriate access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.8, 8.5.1, 8.5.4, 8.6, 9.10, 10.8, 11.6
166 PCI: Group Activities on TIBCO ActiveMatrix Administrator PCI_Group_Activities_
on_TIBCO_ActiveMatrix_Administrator
Displays all group activities on TIBCO ActiveMatrix Administrator to ensure authorized and appropriate access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.8, 8.5.1, 8.5.4, 8.6, 9.10, 10.8, 11.6
167 Not Applicable PCI_Group_Activities_
on_TIBCO_Spotfire
Displays all accounts added to groups to ensure appropriate access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.8, 8.5.1, 8.5.4, 8.6, 9.10, 10.8, 11.6
168 PCI: Group Activities on UNIX Servers PCI_Group_Activities_on_UNIX_Servers Displays all group activities on UNIX servers to ensure authorized and appropriate access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.8, 8.5.1, 8.5.4, 8.6, 9.10, 10.8, 11.6
169 PCI: Group Activities on Windows Servers PCI_Group_Activities_on_Windows_Servers Displays all group activities on Windows servers to ensure authorized and appropriate access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.8, 8.5.1, 8.5.4, 8.6, 9.10, 10.8, 11.6
170 PCI: Guardium SQL Guard Audit Configuration Changes PCI_Guardium_SQL
_Guard_Audit_Configuration_Changes
Displays all configuration changes on the Guardium SQL Guard Audit database. 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
171 PCI: Guardium SQL Guard Audit Data Access PCI_Guardium_SQL_Guard_Audit_Data_Access Displays all select statements made on Guardium SQL Audit Server. 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.1, 7.3, 8.8, 9.10, 10.8, 11.6
172 PCI: Guardium SQL Guard Audit Logins PCI_Guardium_SQL_Guard_Audit_Logins Displays all login attempts to the Guardium SQL Server Audit database. 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.1.5, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.5.16, 8.8, 9.10, 10.2.5, 10.8, 11.6
173 PCI: Guardium SQL Guard Configuration Changes PCI_Guardium_SQL_Guard_Configuration_Changes Displays all configuration changes on the Guardium SQL Guard database. 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
174 PCI: Guardium SQL Guard Data Access PCI_Guardium_
SQL_Guard_Data_Access
Displays all select statements made on Guardium SQL Server. 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.1, 7.3, 8.8, 9.10, 10.8, 11.6
175 PCI: Guardium SQL Guard Logins PCI_Guardium_SQL_Guard_Logins Displays all login attempts to the Guardium SQL Server database. 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.1.5, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.5.16, 8.8, 9.10, 10.2.5, 10.8, 11.6
176 PCI: HP NonStop Audit Configuration Changes PCI_HP_NonStop_Audit_Configuration_Changes Displays all audit configuration changes on HP NonStop. 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
177 PCI: HP NonStop Audit Login Failed PCI_HP_NonStop_Audit_Login_Failed Displays all HP NonStop Audit login events which have failed. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.2.1, 10.2.2, 10.2.4, 10.2.5, 10.8, 11.6
178 PCI: HP NonStop Audit Login Successful PCI_HP_NonStop_Audit_Login_Successful Displays all HP NonStop Audit login events which have succeeded. 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.1.5, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.5.16, 8.8, 9.10, 10.2.5, 10.8, 11.6
179 PCI: HP NonStop Audit Object Changes PCI_HP_NonStop_Audit_Object_Changes Displays HP NonStop Audit events related to object changes. 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.3, 8.5.1, 8.5.4, 8.8, 9.10, 10.8, 11.6
180 PCI: HP NonStop Audit Permissions Changed PCI_HP_NonStop_
Audit_Permissions_Changed
Displays all permission modification activities on HP NonStop Audit to ensure authorized access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.2, 7.3, 8.5.1, 8.5.4, 8.8, 9.10, 10.8, 11.6
181 PCI: i5/OS DST Password Reset PCI_i5_OS_DST_Password_Reset Displays i5/OS events related to the reset of the DST (Dedicated Service Tools) password. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.5.9, 8.8, 9.10, 10.8, 11.6
182 PCI: i5/OS Files Accessed PCI_i5_OS_Files_Accessed Lists all events when a user gains access an i5/OS file. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.2, 7.3, 8.8, 9.10, 10.8, 11.6
183 PCI: i5/OS Network User Login Failed PCI_i5_OS_Network_User_Login_Failed Lists all events when a network user was denied access into the i5/OS. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.2.1, 10.2.2, 10.2.4, 10.2.5, 10.8, 11.6
184 PCI: i5/OS Network User Login Successful PCI_i5_OS_Network_User_Login_Successful Lists all events when a network user successfully logs into the i5/OS. 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.1.5, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.5.16, 8.8, 9.10, 10.2.5, 10.8, 11.6
185 PCI: i5/OS Network User Profile Creation PCI_i5_OS_Network_User_Profile_Creation Displays i5/OS events when a network user profile has been created. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.8, 11.6
186 PCI: i5/OS Network User Profile Deletion PCI_i5_OS_Network_User_Profile_Deletion Displays i5/OS events when a network user profile has been deleted. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.5.4, 8.8, 9.10, 10.8, 11.6
187 PCI: i5/OS Network User Profile Modified PCI_i5_OS_Network_User_Profile_Modified Displays i5/OS events when a network user profile has been modified. 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.3, 8.5.1, 8.5.4, 8.8, 9.10, 10.8, 11.6
188 PCI: i5/OS Object Permissions Modified PCI_i5_OS_Object_Permissions_Modified Displays all permission modification activities on i5/OS to ensure authorized access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.2, 7.3, 8.5.1, 8.5.4, 8.8, 9.10, 10.8, 11.6
189 PCI: i5/OS Restarted PCI_i5_OS_Restarted Lists all events when the i5/OS has been restarted. 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
190 PCI: i5/OS Service Started PCI_i5_OS_Service_Started Lists all events when a user starts a service on the i5/OS. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.2, 7.3, 8.8, 9.10, 10.8, 11.6
191 PCI: i5/OS User Login Failed PCI_i5_OS_User_Login_Failed Lists all events when a user was denied access into the i5/OS. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.2.1, 10.2.2, 10.2.4, 10.2.5, 10.8, 11.6
192 PCI: i5/OS User Login Successful PCI_i5_OS_User_Login_Successful Lists all events when a user successfully logs into the i5/OS. 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.1.5, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.5.16, 8.8, 9.10, 10.2.5, 10.8, 11.6
193 PCI: i5/OS User Profile Creation PCI_i5_OS_User_
Profile_Creation
Displays i5/OS events when a user profile has been created. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.8, 11.6
194 PCI: i5/OS User Profile Modifications PCI_i5_OS_User_Profile_Modifications Displays i5/OS events when a user profile has been modified. 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.3, 8.5.1, 8.5.4, 8.8, 9.10, 10.8, 11.6
195 PCI: Juniper SSL VPN (Secure Access) Failed Logins by User PCI_Juniper_SSL_
VPN_Secure_Access_Failed_Logins_by_User
Displays all failed Juniper SSL VPN (Secure Access) logins based on user. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.2.1, 10.2.2, 10.2.4, 10.2.5, 10.8, 11.6
196 PCI: Juniper SSL VPN (Secure Access) Successful Logins by User PCI_Juniper_SSL_
VPN_Secure_Access_Successful_Logins_by_User
Displays all successful Juniper SSL VPN (Secure Access) logins based on user. 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.1.5, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.5.16, 8.8, 9.10, 10.2.5, 10.8, 11.6
197 PCI: Juniper SSL VPN Failed Logins by User Not Applicable Displays all failed logins per user at the Juniper SSL VPN. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.2.1, 10.2.2, 10.2.4, 10.2.5, 10.8, 11.6
198 PCI: Juniper SSL VPN Successful Logins by User Not Applicable Displays all successful Juniper SSL VPN logins based on user. 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.1.5, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.5.16, 8.8, 9.10, 10.2.5, 10.8, 11.6
199 PCI: Logins by Authentication Type Not Applicable Displays all logins categorized by the authentication type. 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.1.5, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.8, 9.10, 10.2.5, 10.8, 11.6
200 PCI: LogLogic Disk Full PCI_Loglogic_Disk_Full Displays events that indicate the LogLogic appliance's disk is near full. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.7, 10.8, 11.6
201 PCI: LogLogic File Retrieval Errors PCI_LogLogic_File_Retrieval_Errors Displays all errors while retrieving log files from devices, servers and applications. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.2.3, 10.2.6, 10.5.1, 10.5.2, 10.5.3, 10.5.5, 10.6, 10.7, 10.8, 11.6
202 PCI: LogLogic HA State Changed PCI_LogLogic_HA_State_Changed Displays all LogLogic appliance failover state change events. 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.1, 7.3, 8.8, 9.10, 10.8, 11.6
203 PCI: LogLogic Management Center Account Activities PCI_LogLogic_Management
_Center_Account_Activities
Displays all accounts activities on LogLogic Management Center to ensure authorized and appropriate access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.8, 9.10, 10.8, 11.6
204 PCI: LogLogic Management Center Login PCI_LogLogic_Management_Center_Login Displays all login events to the LogLogic Management Center. 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.1.5, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.5.16, 8.8, 9.10, 10.2.5, 10.8, 11.6
205 PCI: LogLogic Management Center Password Changes PCI_LogLogic_
Management_Center_Password_Changes
Displays all password change activities on LogLogic Management Center to ensure authorized and appropriate access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.5.9, 8.8, 9.10, 10.8, 11.6
206 PCI: LogLogic Management Center Upgrade Success PCI_LogLogic_
Management_Center_Upgrade_Success
Displays all successful events related to the system's upgrade. 1.5, 2.5, 3.7, 4.3, 5.4, 6.2, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
207 PCI: LogLogic Message Routing Errors PCI_LogLogic_Message_Routing_Errors Displays all log forwarding errors on the LogLogic appliance to ensure all logs are archived properly. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.7, 10.8, 11.6
208 PCI: LogLogic Universal Collector Configuration Changes PCI_LogLogic_
Universal_Collector_Configuration_Changes
Displays LogLogic universal collector configuration changes. 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
209 PCI: McAfee AntiVirus: Attacks by Event ID PCI_McAfee_AntiVirus_Attacks_by_Event_ID Displays McAfee AntiVirus attacks by Event ID. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.5, 11.6, 12.10.5
210 PCI: McAfee AntiVirus: Attacks by Threat Name PCI_McAfee_AntiVirus_Attacks_by_Threat_Name Displays McAfee AntiVirus attacks by threat name. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.5, 11.6, 12.10.5
211 PCI: McAfee AntiVirus: Attacks Detected PCI_McAfee_AntiVirus_Attacks_Detected Displays attacks detected by McAfee AntiVirus. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.5, 11.6, 12.10.5
212 PCI: Microsoft Operations Manager - Windows Accounts Activities PCI_Microsoft_
Operations_Manager_Windows_Accounts_Activities
Displays all accounts activities on Windows servers to ensure authorized and appropriate access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.8, 9.10, 10.8, 11.6
213 PCI: Microsoft Operations Manager - Windows Accounts Created PCI_Microsoft_
Operations_Manager
_Windows_Accounts_Created
Displays all accounts created on Windows servers to ensure authorized and appropriate access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.8, 11.6
214 PCI: Microsoft Operations Manager - Windows Accounts Enabled PCI_Microsoft_
Operations_Manager
_Windows_Accounts_Enabled
Displays all accounts enabled on Windows servers to ensure authorized and appropriate access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.8, 11.6
215 PCI: Microsoft Operations Manager - Windows Password Changes PCI_Microsoft_Operations_
Manager_Windows_Password_Changes
Displays all password change activities on Windows servers to ensure authorized and appropriate access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.5.9, 8.8, 9.10, 10.8, 11.6
216 PCI: Microsoft Operations Manager - Windows Permissions Modified PCI_Microsoft_Operations_
Manager_Windows_Permissions_Modified
Displays all permission modification activities on Windows servers to ensure authorized access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.2, 7.3, 8.5.1, 8.5.4, 8.8, 9.10, 10.8, 11.6
217 PCI: Microsoft Operations Manager - Windows Policies Modified PCI_Microsoft_Operations_
Manager_Windows_Policies_Modified
Displays all policy modification activities on Windows servers to ensure authorized and appropriate access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 7.1, 7.2, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
218 PCI: Microsoft Operations Manager - Windows Servers Restarted PCI_Microsoft_Operations_
Manager_Windows_Servers_Restarted
Displays all Windows server restart activities to detect unusual activities. 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
219 PCI: Microsoft Sharepoint Content Deleted PCI_Microsoft_Sharepoint_Content_Deleted Displays all events when content has been deleted from Microsoft Sharepoint. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.5.16, 10.2.1, 10.2.2, 10.2.3, 10.2.7, 10.3.1, 10.3.2, 10.3.3, 10.3.5, 10.3.6, 8.8, 9.10, 10.8, 11.6
220 PCI: Microsoft Sharepoint Content Updates PCI_Microsoft_Sharepoint_Content_Updates Displays all events when content is updated within Microsoft Sharepoint. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.5.16, 8.8, 9.10, 10.2.1, 10.2.2, 10.2.3, 10.2.7, 10.3.1, 10.3.2, 10.3.3, 10.3.5, 10.3.6, 10.8, 11.6
221 PCI: Microsoft Sharepoint Permissions Changed PCI_Microsoft_Sharepoint_Permissions_Changed Displays all user/group permission events to Microsoft Sharepoint. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.2, 7.3, 8.5.1, 8.5.4, 8.8, 9.10, 10.8, 11.6
222 PCI: Microsoft Sharepoint Policy Add, Remove, or Modify PCI_Microsoft_Sharepoint_
Policy_Add_Remove_or_Modify
Displays all events when a Microsoft Sharepoint policy is added, removed, or modified. 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 7.1, 7.2, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
223 PCI: Microsoft SQL Server Configuration Changes PCI_Microsoft_
SQL_Server_Configuration_Changes
Displays Microsoft SQL database configuration changes. 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
224 PCI: Microsoft SQL Server Data Access PCI_Microsoft_
SQL_Server_Data_Access
Displays data access events on Microsoft SQL Server databases. 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.1, 7.3, 8.8, 9.10, 10.8, 11.6
225 PCI: Microsoft SQL Server Database Failed Logins PCI_Microsoft_
SQL_Server_Database_Failed_Logins
Displays failed Microsoft SQL Server database logins. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.2.1, 10.2.2, 10.2.4, 10.2.5, 10.8, 11.6
226 PCI: Microsoft SQL Server Database Permission Events PCI_Microsoft_
SQL_Server_Database_Permission_Events
Displays events related to Microsoft SQL Server database permission modifications. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.2, 7.3, 8.5.1, 8.5.4, 8.8, 9.10, 10.8, 11.6
227 PCI: Microsoft SQL Server Database Successful Logins PCI_Microsoft_
SQL_Server_Database_Successful_Logins
Displays successful Microsoft SQL Server database logins. 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.1.5, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.5.16, 8.8, 9.10, 10.2.5, 10.8, 11.6
228 PCI: Microsoft SQL Server Database User Additions and Deletions PCI_Microsoft_SQL_
Server_Database_User_Additions_and_Deletions
Displays Microsoft SQL Server events related to creation and deletion of database users. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.1, 8.5.4, 8.5.8, 8.8, 9.10, 10.8, 11.6
229 PCI: Microsoft SQL Server Password Changes PCI_Microsoft_SQL_
Server_Password_Changes
Displays password changes for Microsoft SQL Server database accounts. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.5.9, 8.8, 9.10, 10.8, 11.6
230 PCI: NetApp Filer Accounts Locked PCI_NetApp_Filer
_Accounts_Locked
Displays all accounts locked out of NetApp Filer to detect access violations or unusual activities. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.5.1, 8.5.13, 8.8, 9.10, 10.8, 11.6
231 PCI: NetApp Filer Audit Accounts Enabled PCI_NetApp_Filer_Audit_Accounts_Enabled Displays all accounts enabled on NetApp Filer Audit to ensure authorized and appropriate access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.8, 11.6
232 PCI: NetApp Filer Audit Login Failed PCI_NetApp_Filer_Audit_Login_Failed Displays all NetApp Filer Audit login events which have failed. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.2.1, 10.2.2, 10.2.4, 10.2.5, 10.8, 11.6
233 PCI: NetApp Filer Audit Login Successful PCI_NetApp_Filer_Audit_Login_Successful Displays all NetApp Filer Audit login events which have succeeded. 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.1.5, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.5.16, 8.8, 9.10, 10.2.5, 10.8, 11.6
234 PCI: NetApp Filer Audit Logs Cleared PCI_NetApp_Filer_Audit_Logs_Cleared Displays all audit logs clearing activities on NetApp Filer Audit to detect access violations or unusual activity. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.2.3, 10.2.6, 10.5.1, 10.5.2, 10.5.3, 10.5.5, 10.6, 10.8, 11.6
235 PCI: NetApp Filer Audit Policies Modified PCI_NetApp_Filer_Audit_Policies_Modified Displays all policy modification activities on NetApp Filer Audit to ensure authorized and appropriate access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 7.1, 7.2, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
236 PCI: NetApp Filer Disk Failure PCI_NetApp_Filer_Disk_Failure Displays all disk failure events on the NetApp Filer servers. 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
237 PCI: NetApp Filer Disk Missing PCI_NetApp_Filer_Disk_Missing Displays events that indicate disk missing on the NetApp Filer servers. 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
238 PCI: NetApp Filer File Activity PCI_NetApp_Filer_File_Activity Displays all file activities on NetApp Filer. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.2.1, 10.2.2, 10.2.4, 10.2.5, 10.8, 11.6
239 PCI: NetApp Filer File System Full PCI_NetApp_Filer_File_System_Full Displays events that indicate the NetApp Filer's disk is near full. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.7, 10.8, 11.6
240 PCI: NetApp Filer Login Failed PCI_NetApp_Filer_Login_Failed Displays all NetApp Filer login events which have failed. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.2.1, 10.2.2, 10.2.4, 10.2.5, 10.8, 11.6
241 PCI: NetApp Filer Login Successful PCI_NetApp_Filer_Login_Successful Displays all NetApp Filer login events which have succeeded. 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.1.5, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.5.16, 8.8, 9.10, 10.2.5, 10.8, 11.6
242 PCI: NetApp Filer Password Changes PCI_NetApp_Filer_Password_Changes Displays all password change activities on NetApp Filer to ensure authorized and appropriate access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.5.9, 8.8, 9.10, 10.8, 11.6
243 PCI: NetApp Filer Snapshot Error PCI_NetApp_Filer_Snapshot_Error Displays events that indicate backup on the NetApp Filer has failed. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.7, 10.8, 11.6
244 PCI: Oracle Database Configuration Changes PCI_Oracle_Database_Configuration_Changes Displays Oracle database configuration changes. 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
245 PCI: Oracle Database Data Access PCI_Oracle_Database_Data_Access Displays data access events on Oracle databases. 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.1, 7.3, 8.8, 9.10, 10.8, 11.6
246 PCI: Oracle Database Failed Logins PCI_Oracle_Database_Failed_Logins Displays all failed login attempts to the Oracle database. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.2.1, 10.2.2, 10.2.4, 10.2.5, 10.8, 11.6
247 PCI: Oracle Database Permission Events PCI_Oracle_Database_Permission_Events Displays events related to Oracle Server database role and privilege management. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.2, 7.3, 8.5.1, 8.5.4, 8.8, 9.10, 10.8, 11.6
248 PCI: Oracle Database Successful Logins PCI_Oracle_Database_Successful_Logins Displays successful Oracle database logins. 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.1.5, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.5.16, 8.8, 9.10, 10.2.5, 10.8, 11.6
249 PCI: Oracle Database User Additions and Deletions PCI_Oracle_Database_User_Additions_and_Deletions Displays Oracle database events related to creation and deletion of database users. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.1, 8.5.4, 8.5.8, 8.8, 9.10, 10.8, 11.6
250 PCI: PANOS: Attacks by Event ID PCI_PANOS_Attacks_by_Event_ID Displays Palo Alto Networks attacks by Event ID. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.5, 11.6, 12.10.5
251 PCI: PANOS: Attacks by Threat Name PCI_PANOS_Attacks_by_Threat_Name Displays Palo Alto Networks attacks by threat name. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.5, 11.6, 12.10.5
252 PCI: PANOS: Attacks Detected PCI_PANOS_Attacks_Detected Displays attacks detected by Palo Alto Networks. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.5, 11.6, 12.10.5
253 PCI: Password Changes on Windows Servers PCI_Password_Changes_on_Windows_Servers Displays all password change activities on Windows servers to ensure authorized and appropriate access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.5.9, 8.8, 9.10, 10.8, 11.6
254 PCI: Periodic Review of Log Reports PCI_Periodic_Review_of_Log_Reports Displays all review activities performed by administrators to ensure review for any access violations. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.2.3, 10.2.6, 10.5.1, 10.5.2, 10.5.3, 10.5.5, 10.6, 10.8, 11.6
255 PCI: Periodic Review of User Access Logs PCI_Periodic_Review_of_User_Access_Logs Displays all review activities performed by administrators to ensure review for any access violations. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.2.3, 10.2.6, 10.5.1, 10.5.2, 10.5.3, 10.5.5, 10.6, 10.8, 11.6
256 PCI: Permissions Modified on Windows Servers PCI_Permissions_Modified_on_Windows_Servers Displays all permission modification activities on Windows Servers to ensure authorized access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.2, 7.3, 8.5.1, 8.5.4, 8.8, 9.10, 10.8, 11.6
257 PCI: Policies Modified on Windows Servers PCI_Policies_Modified_on_Windows_Servers Displays all policy modification activities on Windows servers to ensure authorized and appropriate access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 7.1, 7.2, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
258 PCI: Pulse Connect Secure Failed Logins by User PCI_Pulse_Connect_Secure_Failed_Logins_by_User Displays all failed Pulse Connect Secure logins based on user. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.2.1, 10.2.2, 10.2.4, 10.2.5, 10.8, 11.6
259 PCI: Pulse Connect Secure Successful Logins by User PCI_Pulse_Connect_Secure_Successful_Logins_by_User Displays all successful Pulse Connect Secure logins based on user. 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.1.5, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.5.16, 8.8, 9.10, 10.2.5, 10.8, 11.6
260 PCI: RACF Accounts Created PCI_RACF_Accounts_Created Displays all accounts created on RACF servers to ensure authorized and appropriate access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.8, 11.6
261 PCI: RACF Accounts Deleted PCI_RACF_Accounts_Deleted Displays all accounts deleted on RACF servers to ensure authorized and appropriate access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.5.4, 8.8, 9.10, 10.8, 11.6
262 PCI: RACF Accounts Modified PCI_RACF_Accounts_Modified Displays all events when a network user profile has been modified. 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.3, 8.5.1, 8.5.4, 8.8, 9.10, 10.8, 11.6
263 PCI: RACF Failed Logins PCI_RACF_Failed_Logins Displays all failed login attempts to review any access violations or unusual activity. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.2.1, 10.2.2, 10.2.4, 10.2.5, 10.8, 11.6
264 PCI: RACF Files Accessed PCI_RACF_Files_Accessed Displays all files accessed on RACF servers to ensure appropriate access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.2, 7.3, 8.8, 9.10, 10.8, 11.6
265 PCI: RACF Password Changed PCI_RACF_Passwords_Changed Displays all password change activities on RACF servers to ensure authorized and appropriate access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.5.9, 8.8, 9.10, 10.8, 11.6
266 PCI: RACF Permissions Changed PCI_RACF_Permissions_Changed Displays all permission modification activities on RACF to ensure authorized access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.2, 7.3, 8.5.1, 8.5.4, 8.8, 9.10, 10.8, 11.6
267 PCI: RACF Process Started PCI_RACF_Process_Started Displays all processes started on the RACF servers. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.2, 7.3, 8.8, 9.10, 10.8, 11.6
268 PCI: RACF Successful Logins PCI_RACF_Successful_Logins Displays successful logins to ensure only authorized personnel have access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.1.5, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.5.16, 8.8, 9.10, 10.2.5, 10.8, 11.6
269 PCI: Root Logins Not Applicable Displays root logins. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.1, 8.5.8, 8.6, 8.8, 9.10, 10.1, 10.8, 11.6
270 PCI: Software Update Successes on i5/OS PCI_Software_Update_Successes_on_i5_OS Displays all i5/OS successful events related to the system's software or patch update. 1.5, 2.5, 3.7, 4.3, 5.4, 6.2, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
271 PCI: Successful Logins Not Applicable Displays successful logins to ensure only authorized personnel have access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.1.5, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.5.16, 8.8, 9.10, 10.2.5, 10.8, 11.6
272 PCI: Sybase ASE Database Configuration Changes PCI_Sybase_ASE_Database_Configuration_Changes Displays configuration changes to the Sybase database. 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
273 PCI: Sybase ASE Database Data Access PCI_Sybase_ASE_Database_Data_Access Displays Sybase ASE events involving the SELECT statement. 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.1, 7.3, 8.8, 9.10, 10.8, 11.6
274 PCI: Sybase ASE Database User Additions and Deletions PCI_Sybase_ASE_Database_User_Additions_and_Deletions Displays Sybase database events related to creation and deletion of database users. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.1, 8.5.4, 8.5.8, 8.8, 9.10, 10.8, 11.6
275 PCI: Sybase ASE Failed Logins PCI_Sybase_ASE_Failed_Logins Displays failed Sybase ASE database logins. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.2.1, 10.2.2, 10.2.4, 10.2.5, 10.8, 11.6
276 PCI: Sybase ASE Successful Logins PCI_Sybase_ASE_Successful_Logins Displays successful Sybase ASE database logins. 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.1.5, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.5.16, 8.8, 9.10, 10.2.5, 10.8, 11.6
277 PCI: Symantec Endpoint Protection Configuration Changes PCI_Symantec_Endpoint
_Protection_Configuration_Changes
Displays Symantec Endpoint Protection configuration changes. 1.1.1, 1.1.6, 1.1.7, 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
278 PCI: Symantec Endpoint Protection Password Changes PCI_Symantec_Endpoint
_Protection_Password_Changes
Displays all password change activities on Symantec Endpoint Protection to ensure authorized and appropriate access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.5.9, 8.8, 9.10, 10.8, 11.6
279 PCI: Symantec Endpoint Protection Policy Add, Remove, or Modify PCI_Symantec_
Endpoint_Protection
_Policy_Add_Remove_or_Modify
Displays all events when a Symantec Endpoint Protection policy is added, removed, or modified. 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 7.1, 7.2, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
280 PCI: Symantec Endpoint Protection: Attacks by Threat Name PCI_Symantec_
Endpoint_Protection
_Attacks_by_Threat_Name
Displays Symantec Endpoint Protection attacks by threat name. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.5, 11.6, 12.10.5
281 PCI: Symantec Endpoint Protection: Attacks Detected PCI_Symantec_
Endpoint_Protection_Attacks_Detected
Displays attacks detected by Symantec Endpoint Protection. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.5, 11.6, 12.10.5
282 PCI: Symantec Endpoint Protection: Scans PCI_Symantec_Endpoint_Protection_Scans Displays scans using Symantec Endpoint Protection. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.5, 11.6
283 PCI: Symantec Endpoint Protection: Updated PCI_Symantec_Endpoint_Protection_Updated Displays updates to Symantec Endpoint Protection. 1.5, 2.5, 3.7, 4.3, 5.4, 6.2, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
284 PCI: System Restarted Not Applicable Displays all logs related to system restarts. 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
285 PCI: TIBCO ActiveMatrix Administrator Failed Logins PCI_TIBCO_ActiveMatrix_Administrator_Failed_Logins Displays all TIBCO ActiveMatrix Administrator login events which have failed. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.2.1, 10.2.2, 10.2.4, 10.2.5, 10.8, 11.6
286 PCI: TIBCO ActiveMatrix Administrator Permission Changes PCI_TIBCO_ActiveMatrix
_Administrator_Permission_Changes
Displays events related to TIBCO ActiveMatrix Administrator permission modifications. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.2, 7.3, 8.5.1, 8.5.4, 8.8, 9.10, 10.8, 11.6
287 PCI: TIBCO ActiveMatrix Administrator Successful Logins PCI_TIBCO_ActiveMatrix_
Administrator_Successful_Logins
Displays successful logins to TIBCO ActiveMatrix Administrator to ensure only authorized personnel have access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.1.5, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.5.16, 8.8, 9.10, 10.2.5, 10.8, 11.6
288 PCI: TIBCO Administrator Password Changes PCI_TIBCO_Administrator_Password_Changes Displays all password change activities on TIBCO Administrator to ensure authorized and appropriate access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.5.9, 8.8, 9.10, 10.8, 11.6
289 PCI: TIBCO Administrator Permission Changes PCI_TIBCO_Administrator_Permission_Changes Displays events related to TIBCO Administrator permission modifications. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.2, 7.3, 8.5.1, 8.5.4, 8.8, 9.10, 10.8, 11.6
290 Not Applicable PCI_TIBCO_Spotfire_Failed_Logins Failed logins to the TIBCO Spotfire. No Compliance Mapping
291 Not Applicable PCI_TIBCO_Spotfire_Group_Members_Deleted Displays all accounts deleted to groups to ensure appropriate access. No Compliance Mapping
292 Not Applicable PCI_TIBCO_Spotfire_Password_Changes Displays all password change activities on TIBCO Spotfire to ensure authorized and appropriate access. No Compliance Mapping
293 Not Applicable PCI_TIBCO_Spotfire_Successful_Logins Successful logins to the TIBCO Spotfire. No Compliance Mapping
294 Not Applicable PCI_TIBCO_Spotfire_User_Permission_Change A permission role has been added, changed, removed, or applied to a user on TIBCO Spotfire server. No Compliance Mapping
295 PCI: TrendMicro Control Manager: Attacks Detected PCI_TrendMicro_Control_Manager_Attacks_Detected Displays attacks detected by TrendMicro Control Manager. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.5, 11.6, 12.10.5
296 PCI: TrendMicro Control Manager: Attacks Detected by Threat Name PCI_TrendMicro_Control_
Manager_Attacks_Detected
_by_Threat_Name
Displays attacks detected by TrendMicro Control Manager by threat name. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.5, 11.6, 12.10.5
297 PCI: TrendMicro OfficeScan: Attacks Detected PCI_TrendMicro_OfficeScan_Attacks_Detected Displays attacks detected by TrendMicro OfficeScan. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.5, 11.6, 12.10.5
298 PCI: TrendMicro OfficeScan: Attacks Detected by Threat Name PCI_TrendMicro_
OfficeScan_Attacks
_Detected_by_Threat_Name
Displays attacks detected by TrendMicro OfficeScan bythreat name. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.5, 11.6, 12.10.5
299 PCI: Tripwire Modifications, Additions, and Deletions PCI_Tripwire_
Modifications_Additions_and_Deletions
Displays system modifications, additions, and deletions detected by Tripwire. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.5, 11.6, 12.10.5
300 PCI: Unauthorized Logins Not Applicable Displays all logins from unauthorized users to ensure appropriate access to data. 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.3, 8.8, 9.10, 10.2.1, 10.2.2, 10.2.4, 10.2.5, 10.8, 11.6
301 PCI: Unencrypted Network Services - Check Point PCI_Unencrypted_Network_Services_Check_Point Displays Check Point firewall traffic containing unencrypted network services. 1.1.7, 1.5, 2.2.2, 2.2.3, 2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
302 PCI: Unencrypted Network Services - Cisco ASA PCI_Unencrypted
_Network_Services_Cisco_ASA
Displays Cisco ASA firewall traffic containing unencrypted network services. 1.1.7, 1.5, 2.2.2, 2.2.3, 2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
303 PCI: Unencrypted Network Services - Cisco FWSM PCI_Unencrypted_Network
_Services_Cisco_FWSM
Displays Cisco FWSM firewall traffic containing unencrypted network services. 1.1.7, 1.5, 2.2.2, 2.2.3, 2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
304 PCI: Unencrypted Network Services - Cisco IOS PCI_Unencrypted_Network_Services_Cisco_IOS Displays Cisco IOS firewall traffic containing unencrypted network services. 1.1.7, 1.5, 2.2.2, 2.2.3, 2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
305 PCI: Unencrypted Network Services - Cisco Netflow PCI_Unencrypted_Network
_Services_Cisco_Netflow
Displays Cisco Netflow traffic containing unencrypted network services. 1.1.7, 1.5, 2.2.2, 2.2.3, 2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
306 PCI: Unencrypted Network Services - Fortinet PCI_Unencrypted_Network
_Services_Fortinet
Displays Fortinet firewall traffic containing unencrypted network services. 1.1.7, 1.5, 2.2.2, 2.2.3, 2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
307 PCI: Unencrypted Network Services - Juniper JunOS PCI_Unencrypted_Network
_Services_Juniper_JunOS
Displays Juniper JunOS firewall traffic containing unencrypted network services. 1.1.7, 1.5, 2.2.2, 2.2.3, 2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
308 PCI: Unencrypted Network Services - Nortel Not Applicable Displays Nortel firewall traffic containing unencrypted network services. 1.1.7, 1.5, 2.2.2, 2.2.3, 2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
309 PCI: Unencrypted Network Services - PANOS PCI_Unencrypted_Network
_Services_PANOS
Displays Palo Alto Networks firewall traffic containing unencrypted network services. 1.1.7, 1.5, 2.2.2, 2.2.3, 2.3, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
310 PCI: UNIX Failed Logins PCI_UNIX_Failed_Logins Displays failed UNIX logins for known and unknown users. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.2.1, 10.2.2, 10.2.4, 10.2.5, 10.8, 11.6
311 PCI: vCenter Change Attributes PCI_vCenter_Change_Attributes Modification of VMware vCenter and VMware ESX properties. 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.1, 7.3, 8.8, 9.10, 10.8, 11.6
312 PCI: vCenter Data Move PCI_vCenter_Data_Move Entity has been moved within the VMware vCenter infrastructure. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.2, 7.3, 8.8, 9.10, 10.8, 11.6
313 PCI: vCenter Datastore Events PCI_vCenter_Datastore_Events Displays create, modify, and delete datastore events on VMware vCenter. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.2, 7.3, 8.8, 9.10, 10.8, 11.6
314 PCI: vCenter Failed Logins PCI_vCenter_Failed_Logins Failed logins to the VMware vCenter console. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.2.1, 10.2.2, 10.2.4, 10.2.5, 10.8, 11.6
315 PCI: vCenter Modify Firewall Policy PCI_vCenter_Modify_Firewall_Policy Displays changes to the VMware ESX allowed servicesfirewall policy. 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 7.1, 7.2, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
316 PCI: vCenter Resource Usage Change PCI_vCenter_Resource_Usage_Change Resources have changed on VMware vCenter. 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.1, 7.3, 8.8, 9.10, 10.8, 11.6
317 PCI: vCenter Restart ESX Services PCI_vCenter_Restart_ESX_Services VMware vCenter restarted services running on VMware ESX Server. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.2, 7.3, 8.8, 9.10, 10.8, 11.6
318 PCI: vCenter Shutdown or Restart of ESX Server PCI_vCenter_Shutdown
_or_Restart_of_ESX_Server
VMware ESX Server is shutdown or restarted from VMware vCenter console. 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
319 PCI: vCenter Successful Logins PCI_vCenter_Successful_Logins Successful logins to the VMware vCenter console. 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.7, 7.1, 7.2, 7.3, 8.1, 8.1.5, 8.5.1, 8.5.4, 8.5.8, 8.6, 8.5.16, 8.8, 9.10, 10.2.5, 10.8, 11.6
320 PCI: vCenter User Permission Change PCI_vCenter_User_Permission_Change A permission role has been added, changed, removed, or applied to a user on VMware vCenter server. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.2, 7.3, 8.5.1, 8.5.4, 8.8, 9.10, 10.8, 11.6
321 PCI: vCenter Virtual Machine Created PCI_vCenter_Virtual_Machine_Created Virtual machine has been created from VMware vCenter console. 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
322 PCI: vCenter Virtual Machine Deleted PCI_vCenter_Virtual_Machine_Deleted Virtual machine has been deleted or removed from VMware vCenter console. 1.5, 2.5, 3.7, 4.3, 5.4, 6.3.3, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
323 PCI: vCenter Virtual Machine Shutdown PCI_vCenter_Virtual_Machine_Shutdown Virtual machine has been shutdown or paused from VMware vCenter console. 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
324 PCI: vCenter Virtual Machine Started PCI_vCenter_Virtual_Machine_Started Virtual machine has been started or resumed from VMware vCenter console. 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
325 PCI: vCenter vSwitch Added, Changed or Removed PCI_vCenter_
vSwitch_Added_Changed_or_Removed
vSwitch on VMware ESX server has been added, modified or removed from the VMware vCenter console. 1.1.1, 1.1.6, 1.1.7, 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
326 PCI: VPN Users Accessing Corporate Network Not Applicable Displays all users logging into the corporate network via Virtual Private Network to ensure appropriate access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7,7.1, 7.2, 7.3, 8.1, 8.1.5, 8.5.4, 8.5.8, 8.8, 9.10, 10.2.1, 10.2.2, 10.2.4, 10.2.5, 10.8, 11.6
327 PCI: Web Access to Applications Not Applicable Displays all web-based access to applications to ensure appropriate and authorized access. 1.1.6, 1.1.7, 1.2,
1.3.2, 1.3.5, 1.5,
2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.3, 8.8, 9.10, 10.8, 11.6
328 PCI: Web Access to Applications - F5 BIG-IP TMOS PCI_Web_Access_
to_Applications_F5_BIG-IP_TMOS
Displays all web-based access to applications to ensure appropriate and authorized access on F5 BIG-IP TMOS. 1.1.6, 1.1.7, 1.2,
1.3.2, 1.3.5, 1.5, 2.5, 3.7, 4.3,
5.4, 6.7, 7.1, 7.3, 8.8, 9.10, 10.8, 11.6
329 PCI: Web Access to Applications - Fortinet PCI_Web_Access_to_Applications_Fortinet Displays all web-based access to applications to ensure appropriate and authorized access on Fortinet. 1.1.6, 1.1.7, 1.2, 1.3.2,
1.3.5, 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.3,
8.8, 9.10, 10.8, 11.6
330 PCI: Web Access to Applications - Microsoft IIS Not Applicable Displays all web-based access to applications to ensure appropriate and authorized access on Microsoft IIS. 1.1.6, 1.1.7, 1.2, 1.3.2, 1.3.5, 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.3, 8.8, 9.10, 10.8, 11.6
331 PCI: Web Access to Applications - PANOS PCI_Web_Access_to_Applications_PANOS Displays all web-based access to applications to ensure appropriate and authorized access on Palo Alto Networks. 1.1.6, 1.1.7, 1.2, 1.3.2, 1.3.5, 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.3, 8.8, 9.10, 10.8, 11.6
332 PCI: Windows Accounts Enabled PCI_Windows_Accounts_Enabled Displays all accounts enabled on Windows servers to ensure authorized and appropriate access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.1, 8.5.8, 8.8, 9.10, 10.8, 11.6
333 PCI: Windows Accounts Locked PCI_Windows_Accounts_Locked Displays all accounts locked out of Windows servers to detect access violations or unusual activities. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.5.1, 8.5.13, 8.8, 9.10, 10.8, 11.6
334 PCI: Windows Audit Logs Cleared PCI_Windows_Audit_Logs_Cleared Displays all audit logs clearing activities on Windows servers to detect access violations or unusual activity. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.2.3, 10.2.6, 10.5.1, 10.5.2, 10.5.3, 10.5.5, 10.6, 10.8, 11.6
335 PCI: Windows New Services Installed PCI_Windows_New_Services_Installed Displays a list of new services installed on Windows servers to ensure authorized access. 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.1, 7.2, 7.3, 8.8, 9.10, 10.8, 11.6
336 PCI: Windows Servers Restarted PCI_Windows_Servers_Restarted Displays all Windows server restart activities to detect unusual activities. 1.5, 2.5, 3.7, 4.3, 5.4, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
337 PCI: Windows Software Update Activities PCI_Windows_Software_Update_Activities Displays all events related to the system's software or patch update. 1.5, 2.5, 3.7, 4.3, 5.4, 6.2, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
338 PCI: Windows Software Update Failures PCI_Windows_Software_Update_Failures Displays all failed events related to the system's software or patch update. 1.5, 2.5, 3.7, 4.3, 5.4, 6.2, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6
339 PCI: Windows Software Update Successes PCI_Windows_Software_Update_Successes Displays all successful events related to the system's software or patch update. 1.5, 2.5, 3.7, 4.3, 5.4, 6.2, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6