Enforcement of Trellix FRP policies generates client events, which include the Event ID and appropriate information related to the event.
Removable media events
| Event ID | Event | Definition |
|---|---|---|
| 20500 | Removable Media Device Insert Event | This event is reported whenever any type of removable media is inserted in the client.
Event severity: 0 |
| 20501 | Removable Media User Response Event | This event is reported whenever the user clicks
Yes or
No in the
Removable Media Format Message
window.
Event severity: 0 |
| 20502 | Removable Media Initialization Start Event | This event is reported whenever the user clicks
Initialize or
Cancel in the
Removable Media Initialization
window.
Event severity: 0 |
| 20503 | Removable Media Initialization End Event | This event is reported when initialization is complete.
Event severity: 4 |
| 20504 | Removable Media Device Ejection Event | This event is reported whenever any type of removable media is ejected from the client.
Event severity: 0 |
| 20509 | Removable Media Device Upgrade Event | This event is reported whenever the removable media is being upgraded to support large file sizes (> 4GB).
Event severity: 0 |
| 20521 | Removable Media Application Upgrade event | This event is reported when the removable media application is upgraded. |
| 20559 | Removable Media Authorization event is either successful or failure | This event is reported when the user's Removable Media Authorization is either successful or failure. |
| 20560 | Removable Media Recovery event is either successful or failure | This event is reported when the user's Removable Media Recovery is either successful or failure. |
| 20561 | Removable Media Authentication event is either successful or failure | This event is reported when the user's Removable Media Authentication Change is either successful or failure. |
- 20553 & 54 Event ID are replaced with 20559 (removable media authentication/authorization)
- 20555 & 56 Event ID are replaced with 20560 (RM recovery)
- 20557 & 58 Event ID are replaced with 20561 (RM authentication details change)
| Information type | Definition |
|---|---|
| Event ID | Event ID number |
| System |
|
| Initialization |
|
| Device |
|
| Event specific fields | User response — Valid for events 20501 and 20502 only |
Optical Media client events
| Event ID | Event | Definition |
|---|---|---|
| 20505 | Optical Media Initialization Start Event | This event is reported whenever the user clicks
Initialize or
Cancel in the
Initialization
window.
Event severity: 0 |
| 20506 | Optical Media Initialization End Event | This event is reported when initialization is complete.
Event severity: 0 |
| 20507 | Optical Media Insertion Event | This event is reported whenever an optical media is inserted in the client.
Event severity: 0 |
| 20508 | Optical Media Ejection Event | This event is reported whenever a optical media is ejected from the client.
Event severity: 0 |
| Information type | Definition |
|---|---|
| Event ID | Event ID number |
| Computer |
|
| Media type |
|
| Device |
|
| Event description |
|
| Event specific fields | Initialization state (Failed, Canceled, Successful). This is applicable for Optical Media Insertion and Ejection Events only. |
Note
Only relevant information is captured in each event. For example, a device insert event does not contain the initialization state.
Trellix FRP: Key Authentication events
| Event ID | Event | Definition |
|---|---|---|
| 20510 | Token initialization success event | This event is reported when token initialization is complete.
Event severity: 0 |
| 20511 | Token initialization failure event | This event is reported when token initialization fails.
Event severity: 1 |
| 20512 | Authentication success event | This event is reported when authentication successfully completes.
Event severity: 0 |
| 20513 | Authentication failure event | This event is reported when authentication fails.
Event severity: 1 |
| 20514 | Authentication token invalidation event | This event is reported when an authentication token has been invalidated by exceeding permitted incorrect attempts.
Event severity: 1 |
| 20515 | Authentication change success event | This event is reported when an authentication change successfully completes.
Event severity: 0 |
| 20516 | Authentication change failure event | This event is reported when an authentication change fails.
Event severity: 1 |
| 20517 | Authentication recovery success event | This event is reported when authentication recovery successfully completes.
Event severity: 0 |
| 20518 | Authentication recovery failure event | This event is reported when authentication recovery fails.
Event severity: 1 |
| 20519 | Authentication recovery expired event | This event is reported when the authentication recovery password has expired based on
Trellix FRP Key Authentication settings.
Event severity: 1 |
| 20520 | Authentication lockout event | This event is reported when authentication locks out for the user. |
| 20522 | Advance Debug Option event | This event is reported when the device inserted by the user is exempted by the system for better security. |
Cloud provider client events
| Event ID | Event | Definition |
|---|---|---|
| 20551 | Cloud provider report event | This event is reported when the cloud provider sends a report to the Trellix ePO - On-prem server, even if any protection level is not selected. |
| 20552 | Cloud provider audit event | This event is reported when the cloud provider sends an audit-level report to the Trellix ePO - On-prem server, when the Audit protection level policy is selected. |