Enforcement of Trellix FRP policies generates client events, which include the Event ID and appropriate information related to the event.
Removable media events
Event ID | Event | Definition |
|---|---|---|
20500 | Removable Media Device Insert Event | This event is reported whenever any type of removable media is inserted in the client. Event severity: 0 |
20501 | Removable Media User Response Event | This event is reported whenever the user clicks Yes or No in the Removable Media Format Message window. Event severity: 0 |
20502 | Removable Media Initialization Start Event | This event is reported whenever the user clicks Initialize or Cancel in the Removable Media Initialization window. Event severity: 0 |
20503 | Removable Media Initialization End Event | This event is reported when initialization is complete. Event severity: 4 |
20504 | Removable Media Device Ejection Event | This event is reported whenever any type of removable media is ejected from the client. Event severity: 0 |
20509 | Removable Media Device Upgrade Event | This event is reported whenever the removable media is being upgraded to support large file sizes (> 4GB). Event severity: 0 |
20521 | Removable Media Application Upgrade event | This event is reported when the removable media application is upgraded. |
20559 | Removable Media Authorization event is either successful or failure | This event is reported when the user's Removable Media Authorization is either successful or failure. |
20560 | Removable Media Recovery event is either successful or failure | This event is reported when the user's Removable Media Recovery is either successful or failure. |
20561 | Removable Media Authentication event is either successful or failure | This event is reported when the user's Removable Media Authentication Change is either successful or failure. |
20553 & 54 Event ID are replaced with 20559 (removable media authentication/authorization)
20555 & 56 Event ID are replaced with 20560 (RM recovery)
20557 & 58 Event ID are replaced with 20561 (RM authentication details change)
Information type | Definition |
|---|---|
Event ID | Event ID number |
System |
|
Initialization |
|
Device |
|
Event specific fields | User response — Valid for events 20501 and 20502 only |
Optical Media client events
Event ID | Event | Definition |
|---|---|---|
20505 | Optical Media Initialization Start Event | This event is reported whenever the user clicks Initialize or Cancel in the Initialization window. Event severity: 0 |
20506 | Optical Media Initialization End Event | This event is reported when initialization is complete. Event severity: 0 |
20507 | Optical Media Insertion Event | This event is reported whenever an optical media is inserted in the client. Event severity: 0 |
20508 | Optical Media Ejection Event | This event is reported whenever a optical media is ejected from the client. Event severity: 0 |
Information type | Definition |
|---|---|
Event ID | Event ID number |
Computer |
|
Media type |
|
Device |
|
Event description |
|
Event specific fields | Initialization state (Failed, Canceled, Successful). This is applicable for Optical Media Insertion and Ejection Events only. |
Note
Only relevant information is captured in each event. For example, a device insert event does not contain the initialization state.
Trellix FRP: Key Authentication events
Event ID | Event | Definition |
|---|---|---|
20510 | Token initialization success event | This event is reported when token initialization is complete. Event severity: 0 |
20511 | Token initialization failure event | This event is reported when token initialization fails. Event severity: 1 |
20512 | Authentication success event | This event is reported when authentication successfully completes. Event severity: 0 |
20513 | Authentication failure event | This event is reported when authentication fails. Event severity: 1 |
20514 | Authentication token invalidation event | This event is reported when an authentication token has been invalidated by exceeding permitted incorrect attempts. Event severity: 1 |
20515 | Authentication change success event | This event is reported when an authentication change successfully completes. Event severity: 0 |
20516 | Authentication change failure event | This event is reported when an authentication change fails. Event severity: 1 |
20517 | Authentication recovery success event | This event is reported when authentication recovery successfully completes. Event severity: 0 |
20518 | Authentication recovery failure event | This event is reported when authentication recovery fails. Event severity: 1 |
20519 | Authentication recovery expired event | This event is reported when the authentication recovery password has expired based on Trellix FRP Key Authentication settings. Event severity: 1 |
20520 | Authentication lockout event | This event is reported when authentication locks out for the user. |
20522 | Advance Debug Option event | This event is reported when the device inserted by the user is exempted by the system for better security. |
Cloud provider client events
Event ID | Event | Definition |
|---|---|---|
20551 | Cloud provider report event | This event is reported when the cloud provider sends a report to the ePO - On-prem server, even if any protection level is not selected. |
20552 | Cloud provider audit event | This event is reported when the cloud provider sends an audit-level report to the ePO - On-prem server, when the Audit protection level policy is selected. |
Self-Protection events
To monitor or troubleshoot Self-Protection deployment on ePO clients, use FRP: Self-Protection Events query from ePO Queries & Reports.
Event ID | Event | Definition |
|---|---|---|
20564 | Self-Protection Enable Event | This event is reported when the Self-Protection enabling task is performed in the client. |
20565 | Self-Protection Disable Event | This event is reported when the Self-Protection disabling task is performed in the client. |
20566 | Self-Protection Install Event | This event is reported when the Self-Protection installation task is performed in the client. |
20567 | Self-Protection Uninstall Event | This event is reported when the Self-Protection uninstallation task is performed in the client. |