Enforcement of Trellix FRP policies generates client events, which include the Event ID and appropriate information related to the event.
Removable media events
Event ID | Event | Definition |
|---|---|---|
20500 | Removable Media Device Insert Event | This event is reported whenever any type of removable media is inserted in the client. Event severity: 0 |
20501 | Removable Media User Response Event | This event is reported whenever the user clicks Yes or No in the Removable Media Format Message window. Event severity: 0 |
20502 | Removable Media Initialization Start Event | This event is reported whenever the user clicks Initialize or Cancel in the Removable Media Initialization window. Event severity: 0 |
20503 | Removable Media Initialization End Event | This event is reported when initialization is complete. Event severity: 4 |
20504 | Removable Media Device Ejection Event | This event is reported whenever any type of removable media is ejected from the client. Event severity: 0 |
20509 | Removable Media Device Upgrade Event | This event is reported whenever the removable media is being upgraded to support large file sizes (> 4GB). Event severity: 0 |
20521 | Removable Media Application Upgrade event | This event is reported when the removable media application is upgraded. |
20559 | Removable Media Authorization event is either successful or failure | This event is reported when the user's Removable Media Authorization is either successful or failure. |
20560 | Removable Media Recovery event is either successful or failure | This event is reported when the user's Removable Media Recovery is either successful or failure. |
20561 | Removable Media Authentication event is either successful or failure | This event is reported when the user's Removable Media Authentication Change is either successful or failure. |
20553 & 54 Event ID are replaced with 20559 (removable media authentication/authorization)
20555 & 56 Event ID are replaced with 20560 (RM recovery)
20557 & 58 Event ID are replaced with 20561 (RM authentication details change)
Information type | Definition |
|---|---|
Event ID | Event ID number |
System |
|
Initialization |
|
Device |
|
Event specific fields | User response — Valid for events 20501 and 20502 only |