20
E
C
VENT
ATEGORY
Table 2-10 Authentication Categories (continued)
Low Level Event
Category
Description
System Security
Indicates that system security
Access Granted
access was successfully granted.
System Security
Indicates that system security
Access Removed
access was successfully removed.
Policy Added
Indicates that a policy was
successfully added.
Policy Change
Indicates that a policy was
successfully changed.
User Account
Indicates that a user account was
Added
successfully added.
User Account
Indicates a change to an existing
Changed
user account.
Password Change
Indicates that an attempt to
Failed
change an existing password
failed.
Password Change
Indicates that a password change
Succeeded
was successful.
User Account
Indicates that a user account was
Removed
successfully removed.
Group Member
Indicates that a group member
Added
was successfully added.
Group Member
Indicates that a group member
Removed
was removed.
Group Added
Indicates that a group was
successfully added.
Group Changed
Indicates a change to an existing
group.
Group Removed
Indicates a group was removed.
Computer Account
Indicates a computer account has
Added
been successfully added.
Computer Account
Indicates a change to an existing
Changed
computer account.
Computer Account
Indicates a computer account has
Removed
been successfully removed.
Remote Access
Indicates that access to the
Login Succeeded
network using a remote login was
successful.
Remote Access
Indicates that an attempt to
Login Failed
access the network using a
remote login failed.
C
ORRELATION
STRM Event Category Correlation Reference
Severity Level
Event Correlation/
(0 to 10)
Processing
1
Correlation Group 3 Scenario 2
1
Correlation Group 3 Scenario 2
1
Correlation Group 3 Scenario 2
1
Correlation Group 3 Scenario 2
1
Correlation Group 3 Scenario 2
1
Correlation Group 3 Scenario 2
3
Correlation Group 3 Scenario 2
1
Correlation Group 3 Scenario 2
1
Correlation Group 3 Scenario 2
1
Correlation Group 3 Scenario 2
1
Correlation Group 3 Scenario 2
1
Correlation Group 3 Scenario 2
1
Correlation Group 3 Scenario 2
1
Correlation Group 3 Scenario 2
1
Correlation Group 3 Scenario 2
1
Correlation Group 3 Scenario 2
1
Correlation Group 3 Scenario 2
1
Correlation Group 3 Scenario 2
3
Correlation Group 3 Scenario 2
Additional Event
Processing
Need help?
Do you have a question about the SECURITY THREAT RESPONSE MANAGER 2008.2 - EVENT CATEGORY CORRELATION REFERENCE GUIDE REV 1 and is the answer not in the manual?
Questions and answers