Skip to main content

Syslog Event Types

This table displays types of events based on modules, types of tasks or actions, or status indicators. For each type of event you can view the common category name and the JSON variable used in syslog. Click the category name to view the details sent for such events.

Event category in GravityZone

Event identifier in syslog

Antiphishing

aph

Application Control

application-control

Application Inventory

application-inventory

Antimalware

av

Advanced Threat Control (ATC)

avc

Data Protection

dp

Exchange Malware Detection

exchange-malware

Exchange License Usage Limit Has Been Reached

exchange-organization-info

Exchange User Credentials

exchange-user-credentials

Firewall

fw

Hyper Detect event

hd

Product Modules Status

modules

Sandbox Analyzer Detection

network-sandboxing

Product Registration

registration

Outdated Update Server

supa-update-status

Overloaded Security Server

sva-load

Security Server Status

sva

Antiexploit Event

antiexploit

Network Attack Defense Event

network-monitor

Task Status

task-status

User Control/Content Control

uc

Storage Antimalware Event

storage-antimalware

Login event

login

Authentication audit event

authentication-audit

SMTP Connection

smtp-connection

Internet Connection

internet-connection

License expires event

license-expires

License Limit Is About To Be Reached event

license-limit-to-be-reached

License Usage Limit Has Been Reached event

license-limit-reached

Servers License Limit Is About To Be Reached event

servers-license-limit-almost-reached

Servers License Usage Limit Has Been Reached event

servers-license-limit-exceeded

Malware Outbreak

malware-outbreak

Mobile users without email event

mobile-users-without-email

Database Backup event

database-backup

Certificate expires event

certificate-expires

Upgrade Status

upgrade-status

Update Available

update-available

Troubleshooting activity

troubleshooting-activity

Device Control

device-control

Ransomware activity detection

ransomware-mitigation

New Incident

new-incident

Security Container Status Update

security-container-update-status