Reference Guide

Navigate the Dell Server
102
Advanced Threat Prevention Syslog Event Types
Following are event types that are supported with the Syslog/SIEM Advanced Threats option
.
Application Control
This option is visible when the Application Control feature is enabled. Application Control events
represent actions occurring when the device is in Application Control mode. Selecting this option sends
a message to the Syslog server whenever an attempt is made to modify or copy an executable file, or
when an attempt is made to execute a file from an external device or network location.
Example Message for Deny PE File Change:
Example Message for Deny Execution from External Drive:
Devices
Select this option to send device events to the Syslog server.
When a new device is registered, two messages for this event are received: Registration and
SystemSecurity.
Example Message for Device Registered Event:
When a device is removed.
Example Message for Device Removed Event:
When a device’s policy or logging level has changed.
Example Message for Device Updated Event: