RSA Authentication Manager Log Messages (16291-16355)
The following table lists AM log messages based on the event category and action ID. It also lists the corresponding action key, description, and log message. The log message has placeholders in the “{number}” format, which represents actual data in the logs and Activity Monitor.
Use this table to understand simple network management protocol (SNMP) trap information captured by a network management system. For more information on the information displayed by the object identifier structure (OID) in the SNMP trap, see RSA Authentication Manager SNMP.
Event Category | Action ID | Action Key | Description | Message |
eventSystem | 16291 | START_SERVICE | Start Service | Attempting to start service “{3}”. |
eventSystem | 16294 | IDENTITY_SOURCE_GET | Failed to connect to identity source | Cannot process requests that need access to identity source “{3}”. The identity source is currently unreachable. |
eventSystem | 16295 | TRACK_USER_MOVE_IN | System cannot process this authentication request | The user''s distinguished name has changed. Cannot contact primary instance to update the user.Authentication requests from “{3}” to this instance will not be successful until primary updates the user. |
eventSystem | 16296 | TRACK_USER_MOVE_IN | System cannot process this authentication request | The user''s distinguished name has changed. Either the primary could not update the user or the primary cannot be contacted. Authentication requests from “{3}” to this instance will not be successful until primary updates the user. |
eventSystem | 16297 | BUILD_RELATED_IDENTITY | System cannot initialize related identity source cache | System cannot initialize related identity sources for identity source “{3}” |
eventSystem | 16298 | UNABLE_LOOKUP_NAMING | System cannot lookup directory server''s root DSE attributes | System cannot lookup directory server''s root DSE attributes for identity source “{3}” |
eventSystem | 16299 | UPDATE_PRINCIPAL_FOR | Update principal | System attempted to update principal “{3}” based on changes made in identity source “{4}” |
eventSystem | 16300 | CREATE_BACKUP_ORIG | Create Backup | Created backup in the original primary instance at “{3}” |
eventSystem | 16301 | PRINCIPAL_WITH | Duplicate user ID user found | User ID “{3}” already exists. User IDs must be unique within an identity source |
eventSystem | 16302 | INVALID_PRINCIPAL | Invalid user state | User ID “{3}” already exists. User IDs must be unique within an identity source |
eventSystem | 16303 | IMPORT_BACKUP | Import Backup | Importing backup on the promoted Replica instance from the following location “{3}” |
eventSystem | 16304 | TRANSFER_BACKUP | Transfer Backup | Transferred backup “{3}” to the promoted Replica instance |
eventSystem | 16317 | CREATE_RBA_POLICY | Create RBA policy | Administrator “{0}” attempted to create an RBA policy |
eventSystem | 16318 | DELETE_RBA_POLICY | Delete RBA policy | Administrator “{0}” attempted to delete RBA policy “{4}” |
eventSystem | 16319 | UPDATE_RBA_POLICY | Update RBA policy | Administrator “{0}” attempted to update RBA policy “{4}” |
eventSystem | 16320 | READ_RBA_POLICY | Read RBA policy | Administrator “{0}” attempted to read RBA policy “{4}” |
eventSystem | 16321 | UNLINK_SECURITY_DOMAIN | Unlink policies from security domain | Administrator “{0}” attempted to unlink the RBA policy from security domain “{3}” |
eventSystem | 16322 | AA_MAINTENANCE_TASK | AA maintenance task | System attempted to run AA maintenance task procedure “{0}” |
eventSystem | 16323 | RBA_AUTHN_ATTEMPT | Risk Based Authentication attempt | User attempted to authenticate via RBA |
eventSystem | 16324 | UPDATE_SECURITY | update security questions list | Administrator “{0}” attempted to read security questions list “{4}” |
eventSystem | 16325 | CREATE_SECURITY_DOMAIN | Create Security Domain mapping | Administrator “{0}” attempted to create security domain mapping for identity source “{3}” |
eventSystem | 16326 | READ_SECURITY_DOMAIN | Read Security Domain mapping | Administrator “{0}” attempted to read security domain mapping for identity source “{3}” |
eventSystem | 16327 | UPDATE_SECURITY_DOMAIN | Update Security Domain mapping | Administrator “{0}” attempted to update security domain mapping for identity source “{3}” |
eventSystem | 16328 | DELETE_SECURITY_DOMAIN | Delete Security Domain mapping | Administrator “{0}” attempted to delete security domain mapping for identity source “{3}” |
eventSystem | 16329 | READ_ACTIVE_USERS | Unable to read active users from the system configuration | System failed to read the licensed number of active users from the system configuration |
eventSystem | 16330 | REGISTRY_INSTANCE_MOST | Getting last instance update time | System attempted to get last instance update time |
eventSystem | 16331 | FILE_SERVICE_CREATE_FILE | Creating new file for upload service | Administrator attempted to create new file for upload service |
eventSystem | 16332 | FILE_SERVICE_DELETE_FILE | Deleting uploaded file | Administrator attempted to delete uploaded file |
eventSystem | 16333 | FILE_SERVICE_APPEND_FILE | Appending data to file for upload | Administrator attempted to append data to upload file |
eventSystem | 16334 | FILE_SERVICE_OPEN_FILE | Opening uploaded file | Administrator attempted to open uploaded file |
eventSystem | 16335 | WEBTIER_BIZTIER_TIME | Web-tier time not in sync | Web-tier time is not in sync with biz-tier server |
eventSystem | 16336 | CONN_POOL_OFFLINE | All connection pools failed | All connection pools for “{3}” failed |
eventSystem | 16337 | CREATE_DATABASE_BACKUP | Create Backup | Create backup of internal database at “{3}” |
eventSystem | 16338 | RESTORE_DATABASE | Restore database | Restore backup of internal database from “{3}” |
eventSystem | 16339 | LICENSE_INVALID_SIGNING | Invalid license signing material | System does not recognize license signing material |
eventSystem | 16340 | IMPORT_SECRETS | Import secrets | Import contents of the password-protected file into the system fingerprint. |
eventSystem | 16341 | EXPORT_SECRETS | Export secrets | Export contents of the system fingerprint to the password-protected file. |
eventSystem | 16342 | RECOVER_SECRETS | Recover secrets | Recover the system fingerprint. |
eventSystem | 16343 | CHANGE_SECRETS_MASTER | Change master password | Change the master password for the system fingerprint. |
eventSystem | 16344 | MANAGE_SSL_CERT_IMPORT | Import certificate | Import the certificate “{3}” into the keystore “{4}”. |
eventSystem | 16345 | MANAGE_SSL_CERT_CONFIG | Configure server | Configure the server “{3}” to use the new private key alias and password. |
eventSystem | 16346 | OC_CREATE_IDENTITY | Create identity source | Operations Console administrator “{0}” attempted to create an identity source “{3}” using Super Admin credentials of “{4}”. |
eventSystem | 16347 | OC_DELETE_IDENTITY | Delete identity source | Operations Console administrator “{0}” attempted to delete an identity source “{3}” using Super Admin credentials of “{4}”. |
eventSystem | 16348 | OC_UPDATE_IDENTITY | Update identity source | Operations Console administrator “{0}” attempted to update an identity source “{3}” using Super Admin credentials of “{4}”. |
eventSystem | 16349 | COPY_DATABASE_LOGS | Copy database logs | System attempted to copy database audit logs from external database to internal database. |
eventSystem | 16350 | CRITICAL_NOTIFICATION | Critical System Event Notification | System ecountered a critical event. |
eventSystem | 16351 | DELETE_JOB_RESTRICTED | Delete batch job restircted to non-existing instance | Administrator “{0}” attempted to delete job restricted to non-existing instance “{3}” |
eventSystem | 16352 | REGISTRY_INSTANCE | Look up instance version | Administrator “{0}” attempted to read an instance's version |
eventSystem | 16353 | REGISTRY_INSTANCE | Update instance version | System attempted to update the version for the instance “{3}” |
eventSystem | 16354 | UPDATE_WEBTIER | Update Webtier Customization | Administrator “{0}” attempted to update Webtier Customization Configuration |
eventSystem | 16355 | READ_WEBTIER | Read Webtier Customization | Administrator “{0}” attempted to read Webtier Customization Configuration |
Related Articles
Configure Connection to Authentication Manager 5Number of Views Publishing Changes to Cloud Access Service Without an Identity Router 10Number of Views Publishing Changes to the Identity Router and Cloud Access Service 95Number of Views Configure Agent Settings 28Number of Views Select Software Tokens for Provisioning 25Number of Views
Trending Articles
RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Authentication Manager 8.9 Release Notes (January 2026) How to install the jTDS JDBC driver on WildFly for use with Data Collections in RSA Identity Governance & Lifecycle RSA Authentication Manager 8.8 Setup and Configuration Guide Artifacts to gather in RSA Identity Governance & Lifecycle