This table lists all Policy Management events and their unique subtypes specific to this release of App Control.
Subtype | ID No. | Severity | Example Descriptions/Comments | |
---|---|---|---|---|
AD rules loaded | 605 | Info | Active Directory rules script with version $param1$ was loaded successfully. | |
Approval Request closed | 646 | Info | Approval Request Id $requestID$ was closed by user '$username$' as ‘$resolvedState$’ with ‘$comment$’. |
|
Approval Request created | 644 | Info | Approval Request Id $requestID$ was created by user '$username$'. |
|
Approval Request duplicate created | 661 | Info | Duplicate of Approval Request Id $requestID$ was created by user '$username$'. |
|
Approval Request escalated | 663 | Info | Approval Request Id $requestID$ was escalated by user '$username$'. |
|
Approval Request modified | 662 | Info | Approval Request Id $requestID$ was modified by user '$username$'. |
|
Approval Request opened | 645 | Info | Approval Request Id $requestID$ was opened by user '$username$'. |
|
Certificate approval created | 651 | Info | Certificate $SubjectName$ was approved by ‘$username$’ for publisher $publisher$. | |
Certificate approval deleted | 653 | Info | Approval of certificate $SubjectName$ was deleted by '$username$' for publisher $publisher$. | |
Certificate approval modified | 652 | Info | Approval of certificate '$param1$' was modified by '$username$' for publisher '$param3$'. | |
Certificate ban created | 654 | Info | Certificate $SubjectName$ was banned by $username$ for publisher $publisher$. | |
Certificate ban deleted | 656 | Info | Ban of certificate $SubjectName$ was deleted by '$username$' for publisher $publisher$. | |
Certificate ban modified | 655 | Info | Ban of certificate '$subjectName$' was modified by '$username$' for publisher '$param3$'. | |
Custom Rule created | 638 | Info | Custom Rule '$ruleName$' was created by '$username$'. Custom Rule '$ruleName$ (Unified)' was created by '$username$'. ‘$ruleName$’ was imported by ‘$username’. |
|
Custom Rule deleted | 640 | Info | Custom Rule '$ruleName$' was deleted by '$username$'. Custom Rule '$ruleName$ (Unified)' was deleted by '$username$'. |
|
Custom Rule modified | 639 | Info | Custom Rule '$ruleName$' was modified by '$username$'. Custom Rule '$ruleName$ (Unified)' was modified by '$username$'. ‘$ruleName$’ was imported by ‘$username’. |
|
Device Rule created | 641 | Info | Device Rule for ‘$ruleName$’ with id ‘$ruleID$’ was created by '$username$'. |
|
Device Rule deleted | 642 | Info | Rule for device '$deviceName$' with id ‘$ruleID$’ was removed by '$username$'. |
|
Device Rule modified | 643 | Info | Device Rule ‘$ruleName$’ with id ‘$ruleID$’ was modified by '$username$'. |
|
File approval created | 627 | Info | Approval '$ruleName$' for hash [$hash$] was created by '$username$'. Approval ‘$ruleName (Unified)’ for hash [$hash$] was created by '$username$'. File '$filepath$ ' with hash [$hash$] was approved based on Reputation. $param1$ files were approved based on Reputation. Notes: This event occurs when the rule is created on the server, not when a file instance is approved. In the last example, ‘$param1$ files’ links to a list of files approved by reputation in this event. |
|
File approval deleted | 629 | Info | Approval '$ruleName$' for hash [$hash$] was deleted by '$username$'. Approval ‘$ruleName (Unified)’ for hash [$hash$] was deleted by '$username$'. Approval of file '$filePathAndName$' with hash [$hash$] was removed based on Reputation. Approval of $param1$ files were removed based on Reputation. Notes: This event occurs when the approval rule is deleted on the server, not when approval of a file instance is removed. For the last example, ‘$param1$ files’ is a link to the Files on Computers page where the files whose approvals were removed will be listed if they still exist in their respective locations. |
|
File approval modified | 628 | Info | Approval '$ruleName$' for hash [$hash$] was modified by '$username$'. Approval ‘$ruleName (Unified)’ for hash [$hash$] was modified by '$username$'. |
|
File approved (certificate) | 660 | Info | File '$filePathAndName$' was approved by certificate '$param1$'. | |
File ban created | 635 | Info | Ban '$name$' for [$hash$] was created by '$username$'. Ban ‘$name$ (Unified)’ for [$hash$] was created by '$username$'. Note: $name$ is either the name of the banned file or a user-created name (usually for multi-file bans). |
|
File ban deleted | 637 | Info | Ban '$name$' for [$hash$] was deleted by '$username$'. Ban ‘$name$ (Unified)’ for [$hash$] was deleted by '$username$'. Note: $name$ is the name of the banned file or a user-created name (usually for multi-file bans). |
|
File ban modified | 636 | Info | Ban '$name$' for [$hash$] was modified by '$username$'. Ban ‘$name$ (Unified)’ for [$hash$] was modified by '$username$'. Note: $name$ is the name of the banned file or a user-created name (usually for multi-file bans). |
|
File local approval | 623 | Info | File '$filePathAndName$' [$hash$] was locally approved on computer $computer$ by '$userName$'. | |
File properties modified | 611 | Info | There are multiple possible descriptions for this subtype. Examples: File [$hash$] was approved by '$username$'. File [$hash$] was marked as an installer by '$username$'. Reputation was disabled for file [$hash$] by '$username$’. |
|
File remove local approval | 625 | Info | File '$filePathAndName$' [$hash$] was changed to unapproved on computer $computer$ by '$userName$'. | |
Install package creation scheduled | 603 | Notice | An $param1$ install package $policyName$.msi was scheduled for creation by '$username$'. Note: Param1 is either empty or “automatic” for packages that allow automatic AD Policy assignment. |
|
Justification created | 650 | Info | Justification Id $param2$ was created by user '$username$'. |
|
Justification duplicate created | 664 | Info | Duplicate of Justification Id $param2$ was created by user '$username$'. | |
Memory Rule created | 129 | Info | Memory Rule '$ruleName$' created by '$username$'. Memory Rule '$ruleName$ (Unified)' created by '$username$'. ‘$ruleName$’ was imported by ‘$username’. |
|
Memory Rule deleted | 131 | Info | Memory Rule '$ruleName$' deleted by '$username$'. Memory Rule '$ruleName$ (Unified)' deleted by '$username$'. |
|
Memory Rule modified | 130 | Info | Memory Rule '$ruleName$' modified by '$username$'. Memory Rule '$ruleName$ (Unified)' modified by '$username$'. ‘$ruleName$’ was imported by ‘$username’. |
|
Notifier created | 153 | Info | Notifier ‘$notifierName$’ was created by '$username$' | |
Notifier deleted | 154 | Info | Notifier ‘$notifierName$’ was deleted by '$username$' | |
Notifier modified | 155 | Info | Notifier ‘$notifierName$’ was modified by '$username$' | |
Policy AD rules changed | 604 | Notice | '$username$' created an AD rule for mapping $param1$ to the Policy $policyName$. |
|
Policy created | 600 | Info | Policy '$policyName$' was created by '$username$'. | |
Policy deleted | 601 | Info | Policy '$policyName$' was deleted by '$username$'. | |
Policy file tracking disabled | 606 | Notice | File tracking has been disabled for Policy '$policyName$' by '$userName$'. | |
Policy file tracking enabled | 607 | Notice | File tracking has been enabled for Policy '$policyName$' by '$userName$'. | |
Policy modified | 602 | Info | Policy '$policyName$' was modified by '$username$'. | |
Process demoted | 1006 | Notice | Process $filePathAndName$ was demoted on the computer '$computer$'. New files written by this process will be unapproved. | |
Publisher approval created | 618 | Info | Publisher '$publisherName$' was approved by '$username$'. | |
Publisher approval removed | 619 | Info | Publisher '$publisherName$' approval was removed by '$username$'. | |
Publisher ban created | 657 | Info | Publisher $publisherName$ was banned by $username$. | |
Publisher ban deleted | 659 | Info | Publisher $publisherName$ ban was removed by '$username$'. | |
Publisher modified | 630 | Info | Publisher '$publisherName$' was edited by '$username$'. | |
Registry Rule created | 132 | Info | Registry Rule '$ruleName$' created by '$username$'. Registry Rule '$ruleName$ (Unified)' created by '$username$'. ‘$ruleName$’ was imported by ‘$username’. |
|
Registry Rule deleted | 134 | Info | Registry Rule '$ruleName$' deleted by '$username$'. Registry Rule '$ruleName$ (Unified)' deleted by '$username$'. |
|
Registry Rule modified | 133 | Info | Registry Rule '$ruleName$' modified by '$username$'. Registry Rule '$ruleName$ (Unified)' modified by '$username$'. ‘$ruleName$’ was imported by ‘$username’. |
|
Reputation settings modified | 144 | Info | Reputation was enabled by '$username$'. Reputation was disabled by '$username$'. Reputation settings were modified by '$username$'. |
|
Rules exported | 200 | Info | Custom Rules were exported by '$username$'. Memory Rules were exported by '$username$'. Registry Rules were exported by '$username$'. |
|
Script Rule created | 647 | Info | Script Rule '$ruleName$' was created by '$username$'. |
|
Script Rule deleted | 648 | Info | Script Rule '$ruleName$' was deleted by '$username$'. |
|
Script Rule modified | 649 | Info | Script Rule '$ruleName$' was modified by '$username$'. |
|
Trusted Directory check | 608 | Info | Trusted Directory '$pathName$' on computer '$computer$' is '$param2$'. |
|
Trusted Directory created | 613 | Info | Trusted directory '$pathname$' added by '$username$'. |
|
Trusted Directory deleted | 615 | Info | Trusted directory '$pathname$' deleted by '$username$'. |
|
Trusted Directory import | 626 | Info, Warning, Error |
Trusted package '$param1$' from '$source$' has been processed. Notes: Source may be a computer name or a manifest name. Severity is Info for status imports; Warning for improperly signed or misidentified manifests; Error for all other cases. |
|
Trusted Directory modified | 614 | Info | Trusted directory '$filePathAndName$' modified by '$username$'. |
|
Trusted Directory scan | 609 | Info | Pre-approval scan started for '$filePathAndName$'. Approval ID: $param1$. Job ID: $param2$. |
|
Trusted User added | 616 | Info | Trusted User '$name$' was added by '$username$'. | |
Trusted User deleted | 617 | Info | Trusted User '$name$' was deleted by '$username$'. | |
Unified rule overridden | 665 | Info | Unified rule '$param1$' was overridden by '$username$' |
|
Updater disabled | 621 | Info | Updater '$updaterName$' was disabled by '$username$'. | |
Updater enabled | 620 | Info | Updater '$updaterName$' was enabled by '$username$'. | |
Yara rule created | 220 | Info | Yara Rule '$param1$' created by '$username$'. | |
Yara rule deleted | 222 | Info | Yara Rule '$param1$' deleted by '$username$'. | |
Yara rule modified | 221 | Info | Yara Rule '$param1$' modified by '$username$'. |