Authentication Manager Log Messages (10061-10250)
a month ago

RSA Authentication Manager Log Messages (10061-10250)

The following table lists AM log messages based on the event category and action ID. It also lists the corresponding action key, description, and log message. The log message has placeholders in the “{number}” format, which represents actual data in the logs and Activity Monitor.

Use this table to understand simple network management protocol (SNMP) trap information captured by a network management system. For more information on the information displayed by the object identifier structure (OID) in the SNMP trap, see RSA Authentication Manager SNMP.

Event Category

Action ID

Action Key

Description

Message

eventAdmin

10061

UPDATE_PRINCIPAL
_PREFERENCES

Update console preferences for principal

Administrator “{0}” attempted to update preferences for principal ; “{4}” stored in identity source “{6}” and managed in security domain “{5}”

eventAdmin

10062

READ_PRINCIPAL
_PREFERENCES

Read console preferences for principal

Administrator “{0}” attempted to read preferences for principal “{4}” ; stored in identity source “{6}” and managed in security domain “{5}”

eventAdmin

10063

CREATE_REALM
_PREFERENCES

Assign console preferences to realm

Administrator “{0}” attempted to assign preferences for realm “{5}”

eventAdmin

10064

DELETE_REALM
_PREFERENCES

Remove console preferences for realm

Administrator “{0}” attempted to remove preferences for realm “{5}”

eventAdmin

10065

UPDATE_REALM
_PREFERENCES

Update console preferences for realm

Administrator “{0}” attempted to change preferences for realm “{5}”

eventAdmin

10066

READ_REALM_PREFERENCES

Read console preferences for realm

Administrator “{0}” attempted to read preferences for realm “{5}”

eventAdmin

10067

DEREFERENCE_REALM

Dereference realm

Administrator “{0}” attempted to dereference realm “{4}”

eventAdmin

10068

CREATE_REPORT_QUERY

Create report query

Administrator “{0}” attempted to create report query “{4}” ; to be managed in security domain “{5}”

eventAdmin

10069

DELETE_REPORT_QUERY

Delete report query

Administrator “{0}” attempted to delete report query “{4}” ; managed in security domain “{5}”

eventAdmin

10070

UPDATE_REPORT_QUERY

Update report query

Administrator “{0}” attempted to update report query “{4}” ; managed in security domain “{5}”

eventAdmin

10071

READ_REPORT_QUERY

Read report query

Administrator “{0}” attempted to read report query “{4}” ; managed in security domain “{5}”

eventAdmin

10072

SESSION_FORCED_LOGOFF

Force session logoff for principal

Administrator “{0}” attempted a forced session logoff for principal “{4}” ; stored in identity source “{6}” and managed in security domain “{5}”

eventAdmin

10073

SESSION_FETCH

Fetch session for principal

Administrator “{0}” attempted to fetch the session of principal “{4}” ; stored in identity source “{6}” and managed in security domain “{5}”

eventAdmin

10074

SESSION_MODIFICATION

Session attribute modification

Administrator “{0}” modified a session attribute of principal “{4}” ; stored in identity source “{6}” and managed in security domain “{5}”

eventAdmin

10075

ASSOCIATE_PWD_POLICY_TO
_SECURITY_DOMAIN

Associate password policy with security domain

Administrator “{0}” attempted to associate a password policy with a security domain

eventAdmin

10076

ASSOCIATE_LOCKOUT
_POLICY_TO_SECURITY
_DOMAIN

Associate lockout policy with security domain

Administrator “{0}” attempted to associate a lockout policy with a security domain

eventAdmin

10077

ASSOCIATE_AUTHN_POLICY
_TO_SECURITY_DOMAIN

Associate authentication policy with security domain

Administrator “{0}” attempted to associate an authentication policy with a security domain

eventAdmin

10078

DIS_ASSOCIATE_PWD
_POLICY_FROM_SECURITY
_DOMAIN

Disassociate password policy from security domain

Administrator “{0}” attempted to disassociate a password policy from a security domain

eventAdmin

10079

DIS_ASSOCIATE_LOCKOUT
_POLICY_FROM_SECURITY
_DOMAIN

Disassociate lockout policy from security domain

Administrator “{0}” attempted to disassociate a lockout policy from a security domain

eventAdmin

10080

DIS_ASSOCIATE_AUTHN
_POLICY_FROM_SECURITY
_DOMAIN

Disassociate authentication policy from security domain

Administrator “{0}” attempted to disassociate an authentication policy from a security domain

eventAdmin

10081

CREATE_SELFSERVICE
_POLICY

Create self-service troubleshooting policy

Administrator “{0}” attempted to create self-service troubleshooting policy “{4}” ; to be managed in security domain “{5}”

eventAdmin

10082

DELETE_SELFSERVICE
_POLICY

Delete self-service troubleshooting policy

Administrator “{0}” attempted to delete self-service troubleshooting policy “{4}” ; managed in security domain “{5}”

eventAdmin

10083

UPDATE_SELFSERVICE
_POLICY

Update self-service troubleshooting policy

Administrator “{0}” attempted to update self-service troubleshooting policy “{4}” ; managed in security domain “{5}”

eventAdmin

10084

READ_SELFSERVICE_POLICY

Read self-service troubleshooting policy

Administrator “{0}” attempted to view self-service troubleshooting policy “{4}” ; managed in security domain “{5}”

eventAdmin

10085

ASSOCIATE_SELFSERVICE
_POLICY_TO_SECURITY
_DOMAIN

Associate self-service troubleshooting policy with security domain

Administrator “{0}” attempted to associate a self-service troubleshooting policy with a security domain

eventAdmin

10086

DIS_ASSOCIATE
_SELFSERVICE_POLICY
_FROM_SEC_DOM

Disassociate self-service troubleshooting policy from security domain

Administrator “{0}” attempted to disassociate a self-service troubleshooting policy from a security domain

eventAdmin

10087

UPDATE_SECURITY
_QUESTIONS_POLICY

Update security question policy

Administrator “{0}” attempted to update security question policy “{4}” ; managed in security domain “{5}”

eventAdmin

10088

READ_SECURITY
_QUESTIONS_POLICY

Read security question policy

Administrator “{0}” attempted to view security question policy “{4}” ; managed in security domain “{5}”

eventAdmin

10089

READ_SECURITY
_QUESTIONS_LIST

Read security questions list

Administrator “{0}” attempted to view security questions list ?c{4}”

eventAdmin

10200

CREATE_TRUST

Create trust realm

Administrator “{0}” attempted to create trust realm “{4}” ; to be managed in security domain “{5}”

eventAdmin

10201

DELETE_TRUST

Delete trust realm

Administrator “{0}” attempted to delete trust realm “{4}” ; managed in security domain “{5}”

eventAdmin

10202

UPDATE_TRUST

Update trust realm

Administrator “{0}” attempted to update trust realm “{4}” ; managed in security domain “{5}”

eventAdmin

10203

READ_TRUST

Read trust realm

Administrator “{0}” attempted to read trust realm “{4}” ; managed in security domain “{5}”

eventAdmin

10204

MANAGE_ATTR_CATEGORY

Manage attribute category

Administrator “{0}” attempted to manage attribute category“{4}” ; managed in security domain “{5}”

eventAdmin

10205

IMPORT_PWD_DICTIONARY

Import Password Dictionary

Administrator “{0}” attempted to import password dictionary “{4}”

eventAdmin

10206

EXPORT_PWD_DICTIONARY

Export Password Dictionary

Administrator “{0}” attempted to export password dictionary “{4}”

eventAdmin

10207

DELETE_PWD_DICTIONARY

Delete Password Dictionary

Administrator “{0}” attempted to delete password dictionary “{4}”

eventAdmin

10208

READ_PWD_DICTIONARY

Read Password Dictionary

Administrator “{0}” attempted to read password dictionary “{4}”

eventAdmin

10209

DELETE_BATCH_JOB

Delete batch job

Administrator “{0}” attempted to delete “{11}” batch job “{4}”

eventAdmin

10210

READ_BATCH_JOB

Read batch job

Administrator “{0}” attempted to read “{11}” batch job “{4}”

eventAdmin

10211

READ_SCHEDULE_JOB

Read scheduled job

Administrator “{0}” attempted to read scheduled “{11}” batch job “{4}”

eventAdmin

10212

ADD_BATCH_JOB

Add batch job

Administrator “{0}” attempted to add “{11}” batch job “{4}”

eventAdmin

10213

SCHEDULE_BATCH_JOB

Schedule batch job

Administrator “{0}” attempted to schedule “{11}” batch job “{4}”

eventAdmin

10214

DELETE_SCHEDULE_JOB

Delete scheduled job

Administrator “{0}” attempted to delete scheduled “{11}” job “{4}”

eventAdmin

10215

CANCEL_BATCH_JOB

Cancel batch job

Administrator “{0}” attempted to cancel “{11}” batch job “{4}”

eventAdmin

10216

CANCEL_SCHEDULE_JOB

Cancel scheduled job

Administrator “{0}” attempted to cancel scheduled “{11}” batch job “{4}”

eventAdmin

10217

READ_REPORT_DATA

Read report data

Administrator “{0}” attempted to read result of report “{4}” ; managed in security domain “{5}”

eventAdmin

10218

READ_REPORT_META_DATA

Read report meta data

Administrator “{0}” attempted to read meta data of report “{4}” ; managed in security domain “{5}”

eventAdmin

10219

CREATE_REPORT_CLASS

Create report generation class

Administrator “{0}” attempted to create a report generation instance of “{4}”

eventAdmin

10220

LOOKUP_PRINCIPALS

Lookup principals

Administrator “{0}” attempted to lookup principals stored in identity source “{6}” and managed in security domain “{5}”

eventAdmin

10243

ASSIGN_SYSTEMFIELDS
_USER_ROLE

Assign system user an administrator role

Super Administrator “{0}” attempted to assign administrative role “{8}” to system user “{4}”.

eventAdmin

10244

RESET_SYSTEMFIELDS_USER
_PASSWORD

Reset system user password

Super Administrator “{0}” attempted to reset system user “{4}” password.

eventAdmin

10245

UNASSIGN_SYSTEMFIELDS
_USER_ROLE

Unassign system user an administrator role

Super Administrator “{0}” attempted to unassign administrative role “{8}” from system user “{4}”.

eventAdmin

10246

LIST_SYSTEMFIELDS_USERS

List system users

Super Administrator “{0}” attempted to list system users with administrative roles such as Operations Console admin.

eventAdmin

10247

CREATE_SYSTEMFIELDS
_ROLE

Create system administrator role

Super Administrator “{0}” attempted to create new system administrator role “{4}”. System administrator roles have no attributes other than a name.

eventAdmin

10248

DELETE_SYSTEMFIELDS
_ROLE

Delete system administrator role

Super Administrator “{0}” attempted to delete system administrator role “{4}”.

eventAdmin

10249

FIND_ORPHANED
_PRINCIPALS_IS
_UNSPECIFIED

Find unresolvable users

Administrator “{0}” attempted to find unresolvable users

eventAdmin

10250

CLEANUP_UNRESOLVED
_USERS_IS_UNSPECIFIED

Cleaning unresolvable users

Administrator “{0}” attempted to clean unresolvable users