This section describes the fields that can be in an App Control event. Those shown as “required” can be expected to be present in each App Control event. Other fields are present only for certain events or under certain conditions.
Timestamp (required) All event timestamps are stored in UTC in the App Control database.
Severity (required) Each App Control event has one of five different severity values.
Type (required) This is the top-level, general classification for an event.
Subtype (required)
Source (required) There are two possible values for Source:
Unified Server Source This release includes the ability to manage certain functions on multiple App Control servers from one server.
Description (required) The description field is a natural language description of the event. Often, the description will contain information also provided in other fields in the event. This redundancy is intentional; it allows the description to be fully descriptive of the event without the other fields.
IP Address The IP Address field denotes the IP address of the source of the event.
User The User field contains either the user that was active on the agent computer (Source) at the time of the event, or the Console User in the case of events generated by console activities.
File Events The following events relate to a specific file:
Process Events The following events relate to a specific process:
Process Name, Process Path, Process Key, Process Trust, and Process Threat Several Process fields are used within events generated by the App Control Agent.
Installer, Root Hash Installer and Root Hash are used within some events generated by the App Control Agent.
Policy The Policy field is used within events generated by the App Control Agent.
Additional Fields The following additional fields are not mandatory but may appear in events: