ESM Configuration Change Event Variables
Table of Contents
4.2 (EoS)
Expand all | Collapse all
-
- Set Up the Endpoint Infrastructure
- Activate Traps Licenses
-
- Endpoint Infrastructure Installation Considerations
- TLS/SSL Encryption for Traps Components
- Configure the MS-SQL Server Database
- Install the Endpoint Security Manager Server Software
- Install the Endpoint Security Manager Console Software
- Manage Proxy Communication with the Endpoint Security Manager
- Load Balance Traffic to ESM Servers
-
- Malware Protection Policy Best Practices
- Malware Protection Flow
- Manage Trusted Signers
-
- Remove an Endpoint from the Health Page
- Install an End-of-Life Traps Agent Version
-
-
- Traps Troubleshooting Resources
- Traps and Endpoint Security Manager Processes
- ESM Tech Support File
-
- Access Cytool
- View the Status of the Agent Using Cytool
- View Processes Currently Protected by Traps Using Cytool
- Manage Logging of Traps Components Using Cytool
- Restore a Quarantined File Using Cytool
- View Statistics for a Protected Process Using Cytool
- View Details About the Traps Local Analysis Module Using Cy...
- View Hash Details About a File Using Cytool
ESM Configuration Change Event Variables
ESM configuration change events include system-wide
changes to licensing, administrative users and roles, processes,
restriction settings, and conditions. The ESM Console lists these
events under the following Logging Events categories:
- Policies - Process Management
- Policies - Restriction Settings
- Settings - Administration
- Settings Conditions
The following table displays the most commonly specified variables
in ESM configuration-related events.
Name | Meaning |
---|---|
shost | Machine name of the ESM Console server |
suser | User who is logged in to the ESM Console |
msg | Free text description |
dhost | Machine name of the endpoint |
deviceProcessName | Process name |
For example, consider the output for a Role Added/Edited event
in CEF format:
Sep 28 2016 17:42:04 ESM CEF:0|Palo Alto Networks|Traps ESM|3.4.1.16709|Role Edited|Config|3|rt=Sep 28 2016 17:42:04 shost=ESM suser=administrator msg=Role TechWriter was added\changed
Notice that this event uses several common variables, namely: shost, suser,
and msg.