RSA Authentication Manager Log Messages (10061-10250)
The following table lists AM log messages based on the event category and action ID. It also lists the corresponding action key, description, and log message. The log message has placeholders in the “{number}” format, which represents actual data in the logs and Activity Monitor.
Use this table to understand simple network management protocol (SNMP) trap information captured by a network management system. For more information on the information displayed by the object identifier structure (OID) in the SNMP trap, see RSA Authentication Manager SNMP.
Event Category | Action ID | Action Key | Description | Message |
eventAdmin | 10061 | UPDATE_PRINCIPAL | Update console preferences for principal | Administrator “{0}” attempted to update preferences for principal ; “{4}” stored in identity source “{6}” and managed in security domain “{5}” |
eventAdmin | 10062 | READ_PRINCIPAL | Read console preferences for principal | Administrator “{0}” attempted to read preferences for principal “{4}” ; stored in identity source “{6}” and managed in security domain “{5}” |
eventAdmin | 10063 | CREATE_REALM | Assign console preferences to realm | Administrator “{0}” attempted to assign preferences for realm “{5}” |
eventAdmin | 10064 | DELETE_REALM | Remove console preferences for realm | Administrator “{0}” attempted to remove preferences for realm “{5}” |
eventAdmin | 10065 | UPDATE_REALM | Update console preferences for realm | Administrator “{0}” attempted to change preferences for realm “{5}” |
eventAdmin | 10066 | READ_REALM_PREFERENCES | Read console preferences for realm | Administrator “{0}” attempted to read preferences for realm “{5}” |
eventAdmin | 10067 | DEREFERENCE_REALM | Dereference realm | Administrator “{0}” attempted to dereference realm “{4}” |
eventAdmin | 10068 | CREATE_REPORT_QUERY | Create report query | Administrator “{0}” attempted to create report query “{4}” ; to be managed in security domain “{5}” |
eventAdmin | 10069 | DELETE_REPORT_QUERY | Delete report query | Administrator “{0}” attempted to delete report query “{4}” ; managed in security domain “{5}” |
eventAdmin | 10070 | UPDATE_REPORT_QUERY | Update report query | Administrator “{0}” attempted to update report query “{4}” ; managed in security domain “{5}” |
eventAdmin | 10071 | READ_REPORT_QUERY | Read report query | Administrator “{0}” attempted to read report query “{4}” ; managed in security domain “{5}” |
eventAdmin | 10072 | SESSION_FORCED_LOGOFF | Force session logoff for principal | Administrator “{0}” attempted a forced session logoff for principal “{4}” ; stored in identity source “{6}” and managed in security domain “{5}” |
eventAdmin | 10073 | SESSION_FETCH | Fetch session for principal | Administrator “{0}” attempted to fetch the session of principal “{4}” ; stored in identity source “{6}” and managed in security domain “{5}” |
eventAdmin | 10074 | SESSION_MODIFICATION | Session attribute modification | Administrator “{0}” modified a session attribute of principal “{4}” ; stored in identity source “{6}” and managed in security domain “{5}” |
eventAdmin | 10075 | ASSOCIATE_PWD_POLICY_TO | Associate password policy with security domain | Administrator “{0}” attempted to associate a password policy with a security domain |
eventAdmin | 10076 | ASSOCIATE_LOCKOUT | Associate lockout policy with security domain | Administrator “{0}” attempted to associate a lockout policy with a security domain |
eventAdmin | 10077 | ASSOCIATE_AUTHN_POLICY | Associate authentication policy with security domain | Administrator “{0}” attempted to associate an authentication policy with a security domain |
eventAdmin | 10078 | DIS_ASSOCIATE_PWD | Disassociate password policy from security domain | Administrator “{0}” attempted to disassociate a password policy from a security domain |
eventAdmin | 10079 | DIS_ASSOCIATE_LOCKOUT | Disassociate lockout policy from security domain | Administrator “{0}” attempted to disassociate a lockout policy from a security domain |
eventAdmin | 10080 | DIS_ASSOCIATE_AUTHN | Disassociate authentication policy from security domain | Administrator “{0}” attempted to disassociate an authentication policy from a security domain |
eventAdmin | 10081 | CREATE_SELFSERVICE | Create self-service troubleshooting policy | Administrator “{0}” attempted to create self-service troubleshooting policy “{4}” ; to be managed in security domain “{5}” |
eventAdmin | 10082 | DELETE_SELFSERVICE | Delete self-service troubleshooting policy | Administrator “{0}” attempted to delete self-service troubleshooting policy “{4}” ; managed in security domain “{5}” |
eventAdmin | 10083 | UPDATE_SELFSERVICE | Update self-service troubleshooting policy | Administrator “{0}” attempted to update self-service troubleshooting policy “{4}” ; managed in security domain “{5}” |
eventAdmin | 10084 | READ_SELFSERVICE_POLICY | Read self-service troubleshooting policy | Administrator “{0}” attempted to view self-service troubleshooting policy “{4}” ; managed in security domain “{5}” |
eventAdmin | 10085 | ASSOCIATE_SELFSERVICE | Associate self-service troubleshooting policy with security domain | Administrator “{0}” attempted to associate a self-service troubleshooting policy with a security domain |
eventAdmin | 10086 | DIS_ASSOCIATE | Disassociate self-service troubleshooting policy from security domain | Administrator “{0}” attempted to disassociate a self-service troubleshooting policy from a security domain |
eventAdmin | 10087 | UPDATE_SECURITY | Update security question policy | Administrator “{0}” attempted to update security question policy “{4}” ; managed in security domain “{5}” |
eventAdmin | 10088 | READ_SECURITY | Read security question policy | Administrator “{0}” attempted to view security question policy “{4}” ; managed in security domain “{5}” |
eventAdmin | 10089 | READ_SECURITY | Read security questions list | Administrator “{0}” attempted to view security questions list ?c{4}” |
eventAdmin | 10200 | CREATE_TRUST | Create trust realm | Administrator “{0}” attempted to create trust realm “{4}” ; to be managed in security domain “{5}” |
eventAdmin | 10201 | DELETE_TRUST | Delete trust realm | Administrator “{0}” attempted to delete trust realm “{4}” ; managed in security domain “{5}” |
eventAdmin | 10202 | UPDATE_TRUST | Update trust realm | Administrator “{0}” attempted to update trust realm “{4}” ; managed in security domain “{5}” |
eventAdmin | 10203 | READ_TRUST | Read trust realm | Administrator “{0}” attempted to read trust realm “{4}” ; managed in security domain “{5}” |
eventAdmin | 10204 | MANAGE_ATTR_CATEGORY | Manage attribute category | Administrator “{0}” attempted to manage attribute category“{4}” ; managed in security domain “{5}” |
eventAdmin | 10205 | IMPORT_PWD_DICTIONARY | Import Password Dictionary | Administrator “{0}” attempted to import password dictionary “{4}” |
eventAdmin | 10206 | EXPORT_PWD_DICTIONARY | Export Password Dictionary | Administrator “{0}” attempted to export password dictionary “{4}” |
eventAdmin | 10207 | DELETE_PWD_DICTIONARY | Delete Password Dictionary | Administrator “{0}” attempted to delete password dictionary “{4}” |
eventAdmin | 10208 | READ_PWD_DICTIONARY | Read Password Dictionary | Administrator “{0}” attempted to read password dictionary “{4}” |
eventAdmin | 10209 | DELETE_BATCH_JOB | Delete batch job | Administrator “{0}” attempted to delete “{11}” batch job “{4}” |
eventAdmin | 10210 | READ_BATCH_JOB | Read batch job | Administrator “{0}” attempted to read “{11}” batch job “{4}” |
eventAdmin | 10211 | READ_SCHEDULE_JOB | Read scheduled job | Administrator “{0}” attempted to read scheduled “{11}” batch job “{4}” |
eventAdmin | 10212 | ADD_BATCH_JOB | Add batch job | Administrator “{0}” attempted to add “{11}” batch job “{4}” |
eventAdmin | 10213 | SCHEDULE_BATCH_JOB | Schedule batch job | Administrator “{0}” attempted to schedule “{11}” batch job “{4}” |
eventAdmin | 10214 | DELETE_SCHEDULE_JOB | Delete scheduled job | Administrator “{0}” attempted to delete scheduled “{11}” job “{4}” |
eventAdmin | 10215 | CANCEL_BATCH_JOB | Cancel batch job | Administrator “{0}” attempted to cancel “{11}” batch job “{4}” |
eventAdmin | 10216 | CANCEL_SCHEDULE_JOB | Cancel scheduled job | Administrator “{0}” attempted to cancel scheduled “{11}” batch job “{4}” |
eventAdmin | 10217 | READ_REPORT_DATA | Read report data | Administrator “{0}” attempted to read result of report “{4}” ; managed in security domain “{5}” |
eventAdmin | 10218 | READ_REPORT_META_DATA | Read report meta data | Administrator “{0}” attempted to read meta data of report “{4}” ; managed in security domain “{5}” |
eventAdmin | 10219 | CREATE_REPORT_CLASS | Create report generation class | Administrator “{0}” attempted to create a report generation instance of “{4}” |
eventAdmin | 10220 | LOOKUP_PRINCIPALS | Lookup principals | Administrator “{0}” attempted to lookup principals stored in identity source “{6}” and managed in security domain “{5}” |
eventAdmin | 10243 | ASSIGN_SYSTEMFIELDS | Assign system user an administrator role | Super Administrator “{0}” attempted to assign administrative role “{8}” to system user “{4}”. |
eventAdmin | 10244 | RESET_SYSTEMFIELDS_USER | Reset system user password | Super Administrator “{0}” attempted to reset system user “{4}” password. |
eventAdmin | 10245 | UNASSIGN_SYSTEMFIELDS | Unassign system user an administrator role | Super Administrator “{0}” attempted to unassign administrative role “{8}” from system user “{4}”. |
eventAdmin | 10246 | LIST_SYSTEMFIELDS_USERS | List system users | Super Administrator “{0}” attempted to list system users with administrative roles such as Operations Console admin. |
eventAdmin | 10247 | CREATE_SYSTEMFIELDS | Create system administrator role | Super Administrator “{0}” attempted to create new system administrator role “{4}”. System administrator roles have no attributes other than a name. |
eventAdmin | 10248 | DELETE_SYSTEMFIELDS | Delete system administrator role | Super Administrator “{0}” attempted to delete system administrator role “{4}”. |
eventAdmin | 10249 | FIND_ORPHANED | Find unresolvable users | Administrator “{0}” attempted to find unresolvable users |
eventAdmin | 10250 | CLEANUP_UNRESOLVED | Cleaning unresolvable users | Administrator “{0}” attempted to clean unresolvable users |
Related Articles
Authentication Manager Log Messages (20061-20120) 32Number of Views Authentication Manager Log Messages (20001-20060) 47Number of Views Log Messages 57Number of Views Authentication Manager Log Messages (13001-13008) 195Number of Views Authentication Manager Log Messages (10001-10060) 77Number of Views
Trending Articles
Passwordless Authentication in Windows MFA Agent for Active Directory – Quick Setup Guide RSA Authentication Manager 8.9 Release Notes (January 2026) RSA Authentication Manager Upgrade Process RSA Authentication Manager 8.7 SP2 Setup and Configuration Guide An example of SSO using SAML and ADFS with RSA Identity Management and Governance 6.9.x