System event codes and messages

Symantec Data Loss Prevention
system events are monitored, reported, and logged. Each event is identified by code number listed in the tables.
System event lists and reports can be filtered by event codes.
Numbers enclosed in braces, such as {0}, indicate text strings that are dynamically inserted into the actual event name or description message.
General detection server events
Code
Summary
Description
1000
Monitor started
All monitor processes have been started.
1001
Local monitor started
All monitor processes have been started.
1002
Monitor started
Some monitor processes are disabled and haven't been started.
1003
Local monitor started
Some monitor processes are disabled and haven't been started.
1004
Monitor stopped
All monitor processes have been stopped.
1005
Local monitor stopped
All monitor processes have been stopped.
1006
{0} failed to start
Process {0} can't be started. See log files for more detail.
1007
{0} restarts excessively
Process {0} has restarted {1} times during last {2} minutes.
1008
{0} is down
{0} process went down before it had fully started.
1010
Restarted {0}
{0} process was restarted because it went down unexpectedly.
1011
Restarted {0}
{0} was restarted because it was not responding.
1012
Unable to start {0}
Cannot bind to the shutdown datagram socket. Will retry.
1013
{0} resumed starting
Successfully bound to the shutdown socket.
1014
Low disk space
Hard disk space is low. Symantec Data Loss Prevention server disk usage is over {0}%.
Endpoint server events
Code
Summary
Description
1100
Aggregator started
None
1101
Aggregator failed to start
Error starting Aggregator. {0} No incidents will be detected.
1102
Communications with non-legacy agents are disabled
SSL keystore and truststore are not configured for this endpoint server. Please go to configure server page to configure SSL keystore and truststore.
Detection configuration events
Code
Summary
Description
1200
Loaded policy
"{0}" Policy "{0}" v{1} ({2}) has been successfully loaded.
1201
Loaded policies {0}
None
1202
No policies loaded
No relevant policies are found. No incidents will be detected. 1203 Unloaded policy "{0}" Policy "{0}" has been unloaded.
1204
Updated policy "{0}"
Policy "{0}" has been successfully updated. The current policy version is {1}. Active channels: {2}.
1205
Incident limit reached for Policy "{0}"
The policy "{0}" has found incidents in more than {1} messages within the last {2} hours. The policy will not be enforced until the policy is changed, or the reset period of {2} hours is reached.
1206
Long message wait time
Message wait time was {0}:{1}:{2}:{3}.
1207
Failed to load Vector Machine Learning profile
Failed to load [{0}] Vector Machine Learning profile. See server logs for more details.
1208
Failed to unload Vector Machine Learning profile
Failed to unload [{0}] Vector Machine Learning profile. See server logs for more details.
1209
Loaded Vector Machine Learning profile
Loaded [{0}] Vector Machine Learning profile.
1210
Unloaded Vector Machine Learning profile
Unloaded [{0}] Vector Machine Learning profile.
1211
Vector Machine Learning training successful
Training succeeded for [{0}] Vector Machine Learning profile.
1212
Vector Machine Learning training failed
Training failed for [{0}] Vector Machine Learning profile.
1213
{0} messages timed out in Detection recently
{0} messages timed out in Detection in the last {1} minutes. Enable Detection execution trace logs for details.
1214
Detected regular expression rules with invalid patterns
Policy set contains regular expression rule(s) with invalid patterns. See FileReader.log for details.
1216
The Execution Matrix has reached the memory limit of 200 MBs, or the Endpoint Server did not have sufficient memory for the Execution Matrix.
The Execution Matrix has reached the memory limit of 200 MBs, or the Endpoint Server did not have sufficient memory for the Execution Matrix.
Legacy agents do not receive new policies until they are upgraded to the latest agent version or if the policy set is simplified.
File reader events
Code
Summary
Description
1301
File Reader started
None
1302
File Reader failed to start
Error starting File Reader. {0} No incidents will be detected.
1303
Unable to delete folder
File Reader was unable to delete folder "{0}" in the file system. Please investigate, as this will cause system malfunction.
1304
Channel enabled
Monitor channel "{0}" has been enabled.
1305
Channel disabled
Monitor channel "{0}" has been disabled. 1306 License received. {0}.
1306
License received.
None
1307
started
Process is started.
1308
down
Process is down.
ICAP events
Code
Summary
Description
1400
ICAP channel configured
The channel is in {0} mode
1401
Invalid license
The ICAP channel is not licensed or the license has expired. No incidents will be detected or prevented by the ICAP channel.
1402
Content Removal Incorrect
Configuration rule in line {0} is outdated or not written in proper grammar format. Either remove it from the config file or update the rule.
1403
Out of memory Error (Web Prevent) while processing message
While processing request on connection ID{0}, out of memory error occurred. Please tune your setup for traffic load.
1404
Host restriction
Any host (ICAP client) can connect to ICAP Server.
1405
Host restriction error
Unable to get the IP address of host {0}.
1406
Host restriction error
Unable to get the IP address of any host in Icap.AllowHosts.
1407
Protocol Trace Enabled
Enabled Traces available at {0}.
1408
Invalid Load Balance Factor Icap
LoadBalanceFactor configured to 0. Treating it as 1.
MTA events
Code
Summary
Description
1500
Invalid license
The SMTP Prevent channel is not licensed or the license has expired. No incidents will be detected or prevented by the SMTP Prevent channel.
1501
Bind address error
Unable to bind {0}. Please check the configured address or the RequestProcessor log for more information. 1502 MTA restriction error Unable to resolve host {0}.
1503
All MTAs restricted
Client MTAs are restricted, but no hosts were resolved. Please check the RequestProcessor log for more information and correct the RequestProcessor.AllowHosts setting for this Prevent server.
1504
Downstream TLS Handshake failed
TLS handshake with downstream MTA {0} failed. Please check SmtpPrevent and RequestProcessor logs for more information.
1505
Downstream TLS Handshake successful
TLS handshake with downstream MTA {0} was successfully completed.
File inductor events
Code
Summary
Description
1600
Override folder invalid
Monitor channel {0} has invalid source folder: {1} Using folder: {2}.
1601
Source folder invalid
Monitor channel {0} has invalid source folder: {1} The channel is disabled.
File scan events
Code
Summary
Description
1700
Scan start failed
Discover target with ID {0} does not exist. 1701 Scan terminated {0}
1702
Scan completed
Scan completed. Discover Target Name - "{0}"
1703
Scan start failed
{0}
1704
Share list had errors
{0}
1705
Scheduled scan failed
Failed to start a scheduled scan of Discover target {0}. {1}
1706
Scan suspend failed
{0}
1707
Scan resume failed
{0}
1708
Scheduled scan suspension failed
Scheduled suspension failed for scan of Discover target {0}. {1}
1709
Scheduled scan resume failed
Scheduled suspension failed for scan of Discover target {0}. {1}
1710
Maximum Scan Duration Timeout Occurred
Discover target "{0}" timed out because of Maximum Scan Duration.
1711
Maximum Scan Duration Timeout Failed
Maximum scan time duration timed out for scan: {0}. However, an error occurred while trying to abort the scan.
1712
Scan Idle Timeout Occurred
Discover target "{0}" timed out because of Scan Idle Timeout.
1713
Scan Idle Timeout Failed
Maximum idle time duration timed out for scan: {0}. However, an error occurred while trying to abort the scan.
1714
Scan terminated - Invalid Server State
Scan of discover target "{0}" has been terminated from the state of "{1}" because the associated discover server {2} entered an unexpected state of "{3}".
1715
Scan terminated - Server Removed
Scan of discover target "{0}" has been terminated because the associated discover server {1} is no longer available.
1716
Scan terminated - Server Reassigned
Scan of discover target "{0}" has been terminated because the associated discover server {1} is already scanning discover target(s) "{2}".
1717
Scan terminated - Transition Failed
Failed to handle the state change of discover server {1} while scanning discover target "{0}". See log files for details.
1718
Scan start failed
Scan of discover target "{0}" has failed to start. See log files for detailed error description.
1719
Scan start failed due to unsupported target type
Scan of discover target "{0}" has failed, as its target type is no longer supported.
1720
Scan started
Scan started. Discover Target Name - "{0}"
1721
Scan paused
Scan paused. Discover Target Name - "{0}"
1722
Scan stopped
Scan stopped. Discover Target Name - "{0}"
1723
Scan queued
Scan queued. Discover Target Name - "{0}"
1724
Scan failed
Scan failed. Discover Target Name - "{0}"
Incident attachment external storage events
Code
Summary
Description
1750
Incident attachment migration started
Migration of incident attachments from database to external storage directory has started.
1751
Incident attachment migration completed
Completed migrating incident attachments from database to external storage directory.
1752
Incident attachment migration failed
One or more incident attachments could not be migrated from database to external storage directory. Check the incident persister log for more details. Once the error is resolved, restart the
SymantecDLPIncidentPersisterService
service to resume the migration.
1753
Incident attachment migration error.
One or more incident attachments migration from database to external storage directory has encountered error. Check the incident persister log for more details. Migration will continue and will retry erred attachment later.
1754
Failed to update incident attachment deletion schedule
Failed to update the schedule to delete incident attachments in the external directory. Check the incident persister log for more details.
1755
Incident attachment deletion started
Deletion of obsolete incident attachments from the external storage directory has started.
1756
Incident attachment deletion completed
Deletion of obsolete incident attachments from the external storage directory has completed.
1757
Incident attachment deletion failed
One or more incident attachments could not be deleted from the external storage directory. Check the incident persister log for more details.
1758
Incident attachment external storage directory is not accessible
Incident attachment external storage directory is not accessible. Check the incident persister log for more details.
Incident attachment external storage directory is accessible
Incident attachment external storage directory is accessible.
Incident persister and incident writer events
Code
Summary
Description
1800
Incident Persister is unable to process incident Incident
Persister ran out of memory processing incident {0}.
1801
Incident Persister failed to process incident {0}
1802
Corrupted incident received
A corrupted incident was received, and renamed to {0}.
1803
Policy misconfigured
Policy "{0}" has no associated severity.
1804
Incident Persister is unable to start
Incident Persister cannot start because it failed to access the incident folder {0}. Check folder permissions.
1805
Incident Persister is unable to access
Incidents folder The Incident Persister is unable to access the incident folder {0}. Check folder permissions.
1806
Response rule processing failed to start
Response rule processing failed to start: {0}.
1807
Response rule processing execution failed
Response rule command runtime execution failed from error: {0}.
1808
Unable to write incident
Failed to delete old temporary file {0}.
1809
Unable to write incident
Failed to rename temporary incident file {0}.
1810
Unable to list incidents
Failed to list incident files in folder {0}. Check folder permissions.
1811
Error sending incident
Unexpected error occurred while sending an incident. {0} Look in the incident writer log for more information.
1812
Incident writer stopped
Failed to delete incident file {0} after it was sent. Delete the file manually, correct the problem and restart the incident writer.
1813
Failed to list incidents
Failed to list incident files in folder {0}. Check folder permissions.
1814
Incident queue backlogged
There are {0} incidents in this server's queue.
1815
Low disk space on incident server
Hard disk space for the incident data storage server is low. Disk usage is over {0}%.
1816
Failed to update policy statistics
Failed to update policy statistics for policy {0}.
1817
Daily incident maximum exceeded
The daily incident maximum for policy {0} has been exceeded.
No further incidents will be generated.
1818
Incident is oversized, has been persisted with a limited number of components and/or violations
Incident is oversized, has been partially persisted with messageID {0}, Incident File Name {1}.
1821
Failure to process an incident received from the cloud gateway
Unexpected error occurred while sending an incident {0}
Install or update events
Code
Summary
Description
1900
Failed to load update package
Database connection error occurred while loading the software update package {0}.
1901
Software update failed
Failed to apply software update from package {0}. Check the update service log.
Key ignition password events
Code
Summary
Description
2000
Key ignition error
Failed to ignite keys with the new ignition password. Detection against Exact Data Profiles will be disabled.
2001
Unable to update key ignition password.
The key ignition password won't be updated, because the cryptographic keys aren't ignited. Exact Data Matching will be disabled.
Admin password reset event code
Code
Summary
Description
2099
Administrator password reset
The Administrator password has been reset by the password reset tool.
Manager administrator and policy events
Code
Summary
Description
2100
Administrator saved
The administrator settings were successfully saved.
2101
Data source removed
The data source with ID {0} was removed by {1}.
2102
Data source saved
The {0} data source was saved by {1}.
2103
Document source removed
The document source with ID {0} was removed by {1}.
2104
Document source saved
The {0} document source was saved by {1}.
2105
New protocol created
The new protocol {0} was created by {1}.
2106
Protocol order changed
The protocol {0} was moved {1} by {2}.
2107
Protocol removed
The protocol {0} was removed by {1}.
2108
Protocol saved
The protocol {0} was edited by {1}.
2109
User removed
The user with ID {0} was removed by {1}.
2110
User saved
The user {0} was saved by {1}.
2111
Runaway lookup detected
One of the attribute lookup plug-ins did not complete gracefully and left a running thread in the system. Manager restart may be required for cleanup.
2112
Loaded Custom
Attribute Lookup Plug-ins The following Custom Attribute Lookup Plug-ins were loaded: {0}.
2113
No Custom Attribute Lookup Plug-in was loaded
No Custom Attribute Lookup Plug-in was found.
2114
Custom attribute lookup failed
Lookup plug-in {0} timed out. It was unloaded.
2115
Custom attribute lookup failed
Failed to instantiate lookup plug-in {0}. It was unloaded. Error message: {1}
2116
Policy changed
The {0} policy was changed by {1}.
2117
Policy removed
The {0} policy was removed by {1}.
2118
Alert or scheduled report sending failed. {0}
configured by {1} contains the following unreachable email addresses: {2}. Either the addresses are bad or your email server does not allow relay to those addresses.
2119
System settings changed
The system settings were changed by {0}.
2120
Endpoint Location settings changed
The endpoint location settings were changed by {0}.
2121
The account ''{1}'' has been locked out
The maximum consecutive failed logon number of {0} attempts has been exceeded for account ''{1}'', consequently it has been locked out.
2122
Loaded FlexResponse Actions
The following FlexResponse Actions were loaded: {0}.
2123
No FlexResponse Action was loaded.
No FlexResponse Action was found.
2124
A runaway FlexResponse action was detected.
One of the FlexResponse plug-ins did not complete gracefully and left a running thread in the system. Manager restart may be required for cleanup.
2125
Data Insight settings changed.
The Data Insight settings were changed by {0}.
2126
Agent configuration created
Agent configuration {0} was created by {1}.
2127
Agent configuration modified
Agent configuration {0} was modified by {1}.
2128
Agent configuration removed
Agent configuration {0} was removed by {1}.
2129
Agent configuration applied
Agent configuration {0} was applied to endpoint server {1} by {2}.
2130
Directory Connection source removed
The directory connection source with ID {0} was removed by {1}.
2131
Directory Connection source saved
The {0} directory connection source was saved by {1}.
2132
Agent Troubleshooting Task
Agent Troubleshooting task of type {0} created by user {1}.
2133
Certificate authority file generated.
Certificate authority file {0} generated.
2134
Certificate authority file is corrupt.
Certificate authority file {0} is corrupt.
2135
Password changed for certificate authority file.
Password changed for certificate authority file {0}. New certificate authority file is {1}.
2136
Server keystore generated.
Server keystore {0} generated for endpoint server {1}.
2137
Server keystore is missing or corrupt.
Server keystore {0} for endpoint server {1} is missing or corrupt.
2138
Server truststore generated.
Server truststore {0} generated for endpoint server {1}.
2139
Server truststore is missing or corrupt.
Server truststore {0} for endpoint server {1} is missing or corrupt.
2140
Client certificates and key generated.
Client certificates and key generated.
2141
Agent installer package generated.
Agent installer package generated for platforms {0}.
Enforce licensing and key ignition events
Code
Summary
Description
2200
End User License Agreement accepted
The Symantec Data Loss Prevention End User License Agreement was accepted by {0}, {1}, {2}.
2201
License is invalid
None
2202
License has expired
One or more of your product licenses has expired. Some system feature may be disabled. Check the status of your licenses on the system settings page.
2203
License about to expire
One or more of your product licenses will expire soon. Check the status of your licenses on the system settings page.
2204
No license
The license does not exist, is expired or invalid. No incidents will be detected.
2205
Keys ignited
The cryptographic keys were ignited by administrator logon.
2206
Key ignition failed
Failed to ignite the cryptographic keys manually. Please look in the Enforce Server logs for more information. It will be impossible to create new exact data profiles.
2207
Auto key ignition
The cryptographic keys were automatically ignited.
2208
Manual key ignition required
The automatic ignition of the cryptographic keys is not configured. Administrator logon is required to ignite the cryptographic keys. No new exact data profiles can be created until the administrator logs on.
Manager major events
Code
Summary
Description
2300
Low disk space
Hard disk space is low. Symantec Data Loss Prevention Enforce Server disk usage is over {0}%.
2301
Tablespace is almost full
Oracle tablespace {0} is over {1}% full.
2302
{0} not responding
Detection Server {0} did not update its heartbeat for at least 20 minutes.
2303
Monitor configuration changed
The {0} monitor configuration was changed by {1}.
2304
System update uploaded
A system update was uploaded that affected the following components: {0}.
2305
SMTP server is not reachable.
SMTP server is not reachable. Cannot send out alerts or schedule reports.
2306
Enforce Server started
The Enforce Server was started.
2307
Enforce Server stopped
The Enforce Server was stopped.
2308
Monitor status updater exception
The monitor status updater encountered a general exception. Please look at the Enforce Server logs for more information.
2309
System statistics update failed
Unable to update the Enforce Server disk usage and database usage statistics. Please look at the Enforce Server logs for more information.
2310
Statistics aggregation failure
The statistics summarization task encountered a general exception. Refer to the Enforce Server logs for more information.
2311
Version mismatch
Enforce version is {0}, but this monitor's version is {1}.
2312
Incident deletion failed
Incident Deletion failed.
2313
Incident deletion completed
Incident deletion ran for {0} and deleted {1} incident(s).
2314
Endpoint data deletion failed
Endpoint data deletion failed.
2315
Incident deletion started
Incident deletion process started.
2316
Over {0} incidents currently contained in the database
Persisting over {0} incidents can decrease database performance.
2318
Incident deletion flagging process started.
Incident deletion flagging process started.
2319
Incident deletion flagging process ended.
Incident deletion flagging process ended.
Monitor version support events
Code
Summary
Description
2320
Version obsolete
Detection server is not supported when two major versions older than Enforce server version. Enforce version is {0}, and this detection server's version is {1}. This detection server must be upgraded.
2321
Version older than Enforce version
Enforce will not have visibility for this detection server and will not be able to send updates to it. Detection server incidents will be received and processed normally. Enforce version is {0}, and this detection server's version is {1}.
2322
Version older than Enforce version
Functionality introduced with recent versions of Enforce relevant to this type of detection server will not be supported by this detection server. Enforce version is {0}, and this detection server's version is {1}.
2323
Minor version older than Enforce minor version
Functionality introduced with recent versions of Enforce relevant to this type of detection server will not be supported by this detection server and might be incompatible with this detection server. Enforce version is {0}, and this detection server's version is {1}. This detection server should be upgraded.
2324
Version newer than Enforce version
Detection server is not supported when its version is newer than the Enforce server version. Enforce version is {0}, and this detection server's version is {1}. Enforce must be upgraded or detection server must be downgraded.
Manager reporting events
Code
Summary
Description
2400
Export web archive finished
Archive "{0}" for user {1} was created successfully.
2401
Export web archive canceled
Archive "{0}" for user {1} was canceled.
2402
Export web archive failed
Failed to create archive "{0}" for user {1}. The report specified had over {2} incidents.
2403
Export web archive failed
Failed to create archive "{0}" for user {1}. Failure occurred at incident {2}.
2404
Unable to run scheduled report
The scheduled report job {0} was invalid and has been removed.
2405
Unable to run scheduled report
The scheduled report {0} owned by {1} encountered an error: {2}.
2406
Report scheduling is disabled
The scheduled report {0} owned by {1} cannot be run because report scheduling is disabled.
2407
Report scheduling is disabled
The scheduled report cannot be run because report scheduling is disabled.
2408
Unable to run scheduled report
Unable to connect to mail server when delivery scheduled report {0}{1}.
2409
Unable to run scheduled report
User {0} is no longer in role {1} which scheduled report {2} belongs to. The schedule has been deleted.
2410
Unable to run scheduled report
Unable to run scheduled report {0} for user {1} because the account is currently locked.
2411
Scheduled report sent
The schedule report {0} owned by {1} was successfully sent.
2412
Export XML report failed
XML Export of report by user [{0}] failed XML Export of report by user [{0}] failed.
2420
Unable to run scheduled data owner report distribution
Unable to distribute report {0} (id={1}) by data owner because sending of report data has been disabled.
2421
Report distribution by data owner failed
Report distribution by data owner for report {0} (id={1}) failed.
2422
Report distribution by data owner finished
Report distribution by data owner for report {0} (id={1}) finished with {2} incidents for {3} data owners. {4} incidents for {5} data owners failed to be exported.
2423
Report distribution to data owner truncated
The report distribution {1} (id={2}) for the data owner "{0}" exceeded the maximum allowed size. Only the first {3} incidents were sent to "{0}".
Messaging events
Code
Summary
Description
2500
Unexpected Error Processing Message
{0} encountered an unexpected error processing a message. See the log file for details.
2501
Memory Throttler disabled
{0} x {1} bytes need to be available for memory throttling. Only {2} bytes were available. Memory Throttler has been disabled.
Detection server communication events
Code
Summary
Description
2600
Communication error
Unexpected error occurred while sending {1} updates to {0}. {2} Please look at the monitor controller logs for more information.
2650
Communication error(VML)
Unexpected error occurred while sending profile updates config set {0} to {1} {2}. Please look at the monitor controller logs for more information.
Monitor controller events
Code
Summary
Description
2700
Monitor Controller started
Monitor Controller service was started.
2701
Monitor Controller stopped
Monitor Controller service was stopped.
2702
Update transferred to {0}
Successfully transferred update package {1} to detection server {0}.
2703
Update transfer complete
Successfully transferred update package {0} to all detection servers.
2704
Update of {0} failed
Failed to transfer update package to detection server {0}.
2705
Configuration file delivery complete
Successfully transferred config file {0} to detection server.
2706
Log upload request sent.
Successfully sent log upload request {0}.
2707
Unable to send log upload request
Encountered a recoverable error while attempting to deliver log upload request {0}.
2708
Unable to send log upload request
Encountered an unrecoverable error while attempting to deliver log upload request {0}.
2709
Using built-in certificate
Using built-in certificate to secure the communication between Enforce and Detection Servers.
2710
Using user generated certificate
Using user generated certificate to secure the communication between Enforce and Detection Servers.
2711
Time mismatch between Enforce and Monitor. This may affect certain functions in the system.
Time mismatch between Enforce and Monitor. It is recommended to fix the time on the monitor through automatic time synchronization.
2712
Connected to cloud detector
Connected to cloud detector.
2713
Cloud connector disconnected
Error {0} - check your network settings.
Packet capture events
Code
Summary
Description
2800
Bad spool directory configured for Packet Capture
Packet Capture has been configured with a spool directory: {0}. This directory does not have write privileges. Please check the directory permissions and monitor configuration file. Then restart the monitor.
2801
Failed to send list of NICs. {0}
{0}.
EDM index events and messages
Code
Summary
Description
2900
EDM profile search failed
{0}.
2901
Keys are not ignited
Exact Data Matching will be disabled until the cryptographic keys are ignited.
2902
Index folder inaccessible
Failed to list files in the index folder {0}. Check the configuration and the folder permissions.
2903
Created index folder
The local index folder {0} specified in the configuration had not existed. It was created.
2904
Invalid index folder
The index folder {0} specified in the configuration does not exist.
2905
Exact data profile creation failed
Data file for exact data profile "{0}" was not created. Please look in the enforce server logs for more information.
2906
Indexing canceled
Creation of database profile "{0}" was canceled.
2907
Replication canceled
Canceled replication of database profile "{0}" version {1} to server {2}.
2908
Replication failed
Connection to database was lost while replicating database profile {0} to server {1}.
2909
Replication failed
Database error occurred while replicating database profile {0} to server {1}.
2910
Failed to remove index file
Failed to delete index file {1} of database profile {0}.
2911
Failed to remove index files
Failed to delete index files {1} of database profile {0}.
2912
Failed to remove orphaned file
Failed to remove orphaned database profile index file {0}.
2913
Replication failed
Replication of database profile {0} to server {2} failed.{1} Check the monitor controller log for more details.
2914
Replication completed
Completed replication of database profile {0} to server {2}. File {1} was transferred successfully.
2915
Replication completed
Completed replication of database profile {0} to the server {2}. Files {1} were transferred successfully.
2916
Database profile removed
Database profile {0} was removed. File {1} was deleted successfully.
2917
Database profile removed
Database profile {0} was removed. Files {1} were deleted successfully.
2918
Loaded database profile
Loaded database profile {0} from {1}.
2919
Unloaded database profile
Unloaded database profile {0}.
2920
Failed to load database profile
{2} No incidents will be detected against database profile "{0}" version {1}.
2921
Failed to unload database profile
{2} It may not be possible to reload the database profile "{0}" version {1} in the future without detection server restart.
2922
Couldn't find registered content
Registered content with ID {0} wasn't found in database during indexing.
2923
Database error
Database error occurred during indexing. {0}
2924
Process shutdown during indexing
The process has been shutdown during indexing. Some registered content may have failed to create.
2925
Policy is inaccurate
Policy "{0}" has one or more rules with unsatisfactory detection accuracy against {1}.{2}
2926
Created exact data profile
Created {0} from file "{1}".
Rows processed: {2}
Invalid rows: {3}
The exact data profile will now be replicated to all Symantec Data Loss Prevention Servers.
2927
User Group "{0}" synchronization failed
The following User Group directories have been removed/renamed in the Directory Server and could not be synchronized: {1}.Please update the "{2}" User Group page to reflect such changes.
2928
One or more EDM profiles are out of date and must be reindexed
Check the "Manage > Data Profiles > Exact Data" page for more details. The following EDM profiles are out of date: {0}.
IDM index events and messages
Code
Summary
Description
3000
{0}
{1} Document profile wasn't created.
3001
Indexing canceled
Creation of document profile "{0}" was canceled.
3002
Replication canceled
Canceled replication of document profile "{0}" version {1} to server {2}.
3003
Replication failed
Connection to database was lost while replicating document profile "{0}" version {1} to server {2}.
3004
Replication failed
Database error occurred while replicating document profile "{0}" version {1} to server {2}.
3005
Failed to remove index file
Failed to delete index file {2} of document profile "{0}" version {1}.
3006
Failed to remove index files
Failed to delete index files {2} of document profile "{0}" version {1}.
3007
Failed to remove orphaned file
{0}
3008
Replication failed
Replication of document profile "{0}" version {1} to server {3} failed. {2}
Check the monitor controller log for more details.
3009
Replication completed
Completed replication of document profile "{0}" version {1} to server {3}. File {2} was transferred successfully.
3010
Replication completed
Completed replication of document profile "{0}" version {1} to server {3}.
Files {2} were transferred successfully.
3011
Document profile removed
Document profile "{0}" version {1} was removed. File {2} was deleted successfully.
3012
Document profile removed
Document profile "{0}" version {1} was removed. Files {2} were deleted successfully.
3013
Loaded document profile
Loaded document profile "{0}" version {1} from {2}.
3014
Unloaded document profile
Unloaded document profile "{0}" version {1}.
3015
Failed to load document profile
{2}No incidents will be detected against document profile "{0}" version {1}.
3016
Failed to unload document profile
{2} It may not be possible to reload the document profile "{0}" version {1} in the future without monitor restart.
3017
Created document profile
Created "{0}" from "{1}". There are {2} accessible files in the content root. {3} The profile contains index for {4} document(s). {5} The document profile will now be replicated to all Symantec Data Loss Prevention Servers.
3018
Document profile
{0} has reached maximum size. Only {1} out of {2} documents are indexed.
3019
Nothing to index
Document source "{0}" found no files to index.
3020
Created document profile
Created "{0}" from "{1}". There are {2} accessible files in the content root. {3} The profile contains index for {4} document(s). Comparing to last indexing run: {5} new document(s) were added, {6} document(s) were updated, {7} documents were unchanged, and {8} documents were removed. The document profile will now be replicated to all Symantec Data Loss Prevention servers.
3021
Nothing to index
The new remote IDM profile for source "{0}" was identical to the previous imported version.
3022
Profile conversion
IDM profile {0} has been converted to {1} on the endpoint.
3023
Endpoint IDM profiles memory usage
IDM profile {0} size plus already deployed profiles size are too large to fit on the endpoint, only exact matching will be available.
Attribute lookup events
Code
Summary
Description
3100
Invalid Attributes detected with Script Lookup Plugin
Invalid or unsafe Attributes passed from Standard In were removed during script execution. Please check the logs for more details.
3101
Invalid Attributes detected with Script Lookup Plugin
Invalid or unsafe Attributes passed to Standard Out were removed during script execution. Please check the logs for more details.
Monitor stub events
Code
Summary
Description
3200
AggregatorStub started
None
3201
{0} updated
List of updates:{1}.
3202
{0} store intialized
Initial items:{1}.
3203
Received {0}
Size: {1} bytes.
3204
FileReaderStub started
None
3205
IncidentWriterStub started
Using test incidents folder {0}.
3206
Received configuration for {0}
{1}.
3207
PacketCaptureStub started
None
3208
RequestProcessorStub started
None
3209
Received advanced settings
None
3210
Updated settings
Updated settings:{0}.
3211
Loaded advanced settings
None
3212
UpdateServiceStub started
None
3213
DetectionServerDatabaseStub started
None
Packet capture events
Code
Summary
Description
3300
Packet Capture started
Packet Capture has successfully started.
3301
Capture failed to start on device {0}
Device {0} is configured for capture, but could not be initialized. Please see PacketCapture.log for more information.
3302
PacketCapture could not elevate its privilege level
PacketCapture could not elevate its privileges. Some initialization tasks are likely to fail. Please check ownership and permissions of the PacketCapture executable.
3303
PacketCapture failed to drop its privilege level
Root privileges are still attainable after attempting to drop them. PacketCapture will not continue
3304
Packet Capture started again as more disk space is available
Packet capture started processing again because some disk space was freed on the monitor hard drives.
3305
Packet Capture stopped due to disk space limit
Packet capture stopped processing packets because there is too little space on the monitor hard drives.
3306
Endace DAG driver is not available
Packet Capture was unable to activate Endace device support. Please see PacketCapture.log for more information.
3307
PF_RING driver is not available
Packet Capture was unable to activate devices using the PF_RING interface. Please check PacketCapture.log and your system logs for more information.
3308
PACKET_MMAP driver is not available
Packet Capture was unable to activate devices using the PACKET_MMAP interface. Please check PacketCapture.log and your system logs for more information.
3309
{0} is not available
Packet Capture was unable to load {0} . No native capture interface is available. Please see PacketCapture.log for more information.
3310
No {0} Traffic Captured
{0} traffic has not been captured in the last {1} seconds. Please check Protocol filters and the traffic sent to the monitoring NIC.
3311
Could not create directory
Could not create directory {0} : {1}.
Log collection events
Code
Summary
Description
3400
Couldn't add files to zip
The files requested for collection could not be written to an archive file.
3401
Couldn't send log collection
The files requested for collection could not be sent.
3402
Couldn't read logging properties
A properties file could not be read. Logging configuration changes were not applied.
3403
Couldn't unzip log configuration package
The zip file containing logging configuration changes could not be unpacked. Configuration changes will not be applied.
3404
Couldn't find files to collect
There were no files found for the last log collection request sent to server.
3405
File creation failed
Could not create file to collect endpoint logs.
3406
Disk usage exceeded
File creation failed due to insufficient disk space.
3407
Max open file limit exceeded
File creation failed as max allowed number of files are already open.
Enforce SPC events
Code
Summary
Description
3500
SPC Server successfully registered.
SPC Server successfully registered. Product Instance Id [{0}].
3501
SPC Server successfully unregistered.
SPC Server successfully unregistered. Product Instance Id [{0}].
3502
A self-signed certificate was generated.
A self-signed certificate was generated. Certificate alias [{0}].
Enforce user data sources events
Code
Summary
Description
3600
User import completed successfully.
User import from source {0} completed successfully.
3601
User import failed.
User import from data source {0} has failed.
3602
Updated user data linked to incidents.
Updated user data linked to {0} existing incident events.
Catalog item distribution related events
Code
Summary
Description
3700
Unable to write catalog item
Failed to delete old temporary file {0}.
3701
Unable to rename catalog item
Failed to rename temporary catalog item file {0}.
3702
Unable to list catalog items
Failed to list catalog item files in folder {0}.Check folder permissions.
3703
Error sending catalog items
Unexpected error occurred while sending an catalog item.{0}Look in the file reader log for more information.
3704
File Reader failed to delete files.
Failed to delete catalog file {0} after it was sent.
Delete the file manually, correct the problem and restart the File Reader.
3705
Failed to list catalog item files
Failed to list catalog item files in folder {0}.Check folder permissions.
3706
The configuration is not valid.
The property {0} was configured with invalid value {1}. Please make sure that this has correct value provided.
3707
Scan failed: Remediation detection catalog could not be updated
Remediation detection catalog update timed out after {0} seconds for target {1}.
Detection server database events
Code
Summary
Description
3800
DetectionServerDatabase started
None
3801
DetectionServerDatabase failed to start
Error starting DetectionServerDatabase. Reason: {0}.
3802
Invalid Port for DetectionServerDatabase
Could not retrieve the port for DetectionServerDatabase process to listen to connection. Reason: {0}. Check if the property file setting has the valid port number.
Endpoint communication layer events
Code
Summary
Description
3900
Internal communications error.
Internal communications error. Please see {0} for errors. Search for the string {1}.
3901
System events have been suppressed.
System event throttle limit exceeded. {0} events have been suppressed. Internal error code = {1}.
Agent communication event code
Code
Summary
Description
4000
Agent Handshaker error
Agent Handshaker error. Please see {0} for errors. Search for the string {1}.
Monitor controller replication communication layer application error events
Code
Summary
Description
4050
Agent data batch persist error
Unexpected error occurred while agent data being persisted : {0}. Please look at the monitor controller logs for more information.
4051
Agent status attribute batch persist error
Status attribute data for {0} agent(s) could not be persisted. Please look at the monitor controller logs for more information.
4052
Agent event batch persist
Event data for {0} agent(s) could not be persisted. Please look at the monitor controller logs for more information.
Enforce Server web services event code
Code
Summary
Description
4101
Response Rule Execution Service Database failure on request fetch
Request fetch failed even after {0} retries. Database connection still down. The service will be stopped.
Cloud service enrollment events
Code
Summary
Description
4200
Cloud Service enrollment: successfully received client certificate from Symantec Managed PKI Service
Cloud Service enrollment: successfully received client certificate from Symantec Managed PKI Service.
4201
Cloud Service enrollment: error requesting client certificate from Symantec Managed PKI Service
ERROR {0}.
4205
Symantec Managed PKI certificate expires in {0} days
Symantec Managed PKI certificate expires in {0} days.
4206
Symantec Managed PKI Service certificate has expired
Symantec Managed PKI Service certificate has expired.
4210
Cloud Service enrollment bundle error
Invalid enrollment file content.
4211
Cloud Service enrollment bundle error
Enrollment file missing from ZIP bundle.
4212
Invalid Cloud Detector enrollment bundle
Detector info doesn't match the existing configuration.
Cloud detector event code
Code
Summary
Description
4300
Cloud Detector created in Enforce
Cloud detector {0} created in Enforce.
User Groups profile event code
Code
Summary
Description
4400
One or more
User Group
profiles are out of date and must be reindexed.
Check the
System > Users > User Groups
page for more details. The following
User Group
profiles are out of date: {0}.
Cloud operations event code
Code
Summary
Description
4701
Cloud operations events or notifications
Cloud operations issued an event or notification about the cloud service.
OCR event codes
Code
Summary
Description
4800
OCR service is busy
Request not processed. OCR server's request queue is full.
4801
Request failed to connect to OCR server
Please verify OCR server's address, port, and that it is reachable. Check logs for more detail.
4802
OCR server had an internal server error
Please check OCR server logs for details about what went wrong.
4803
OCR request was not successful
{0}
4804
Failed to initialize OCR Client
{0}
4805
An Unknown error encountered
{0}
4807
The client and/or OCR server are not authorized with each other
Unable to verify client and server with each other as authorized endpoints. Please verify that the client and server keystores are configured correctly. Check logs on detection server and OCR server for more details.
Network Discover Cluster event code
Code
Summary
Description
2705
Configuration file {0} delivery complete
Transferred configuration file {0} to detection server.
2726
Connected to detection server
Connected to detection server.
2727
Detection server connection disconnected
Error [FAILURE_TO_CONNECT]. Check your network settings.
2730
Initiated detection server disconnection
Initiated detection server disconnection. [REMOTE_PEER_DISCONNECTED]
3408
Unable to create temp directory
Unable to create a temporary directory for log configuration.
3409
Unable to create temp file
Unable to create a temporary zip file for log configuration.
3410
Unexpected error while applying log configuration
An error occurred while applying the log configuration. Review the Detector process logs.
3411
Unexpected error while sending log configuration
An error occurred while sending the log configuration. Review the monitor controller logs.
3412
Failed to upload the logs to the file share
Failed to upload the logs to the file share.
Error Message: {0}
File Share Path: {1}
Node ID: {2}
3413
Timed out waiting for the log file upload to complete on all cluster nodes
The cluster timed out while waiting for the log file upload to complete on all cluster nodes.
Log collection event ID: {event Id}
Timeout in milliseconds: {timeout value}
Node ID: {cluster node Id}
3414
Failed to update the log configuration from zip file
Failed to update the log configuration from zip file.
Error Message: {error message}
Node ID: {cluster node Id}
5802
Local database connectivity failed
Failed to connect to the local database.
Automatic recovery of the database will be attempted. For details, check the Symantec DLP detector logs on Discover cluster worker node: {cluster node system name}.
5806
Initiated the Discover cluster {detection server name} recycle process
Initiated the Discover cluster {detection server name} recycle process.
5807
Discover cluster {Detection Server Name} recycle completed successfully
Completed the recycle process for all nodes in the Discover cluster {Detection Server Name}.
5808
Discover cluster {0} recycle failed
{0} nodes in the Discover cluster {1} did not finish recycling.
5809
Discover cluster storage is running on node {0}
Discover cluster storage is running on node {0}.
5810
Discover cluster storage is down on node {0}
Discover cluster storage is down on node {0}.
6000
Low disk space
Hard disk space is low. Hard disk space is low. The detection server disk usage is over {usage}%.
6101
The Detector process started
The Detector process started.
6102
Discover Cluster data node {cluster node Id} started
Discover cluster data node {cluster node Id} started successfully.
6103
Discover cluster worker node {cluster node Id} started
Discover cluster worker node {cluster node Id} started successfully.
6104
{ServiceName} Detector Process failed to start
{ServiceName} Detector process failed to start. Review the Symantec DLP detector logs.
6105
Discover cluster data node {cluster node Id} startup failed
Discover cluster data node {cluster node Id} failed to start. Review the Symantec DLP detector logs.
6106
Discover cluster worker node {cluster node Id} startup failed
Discover cluster worker node {cluster node Id} failed to start. Review the Symantec DLP detector logs.
6107
Restarted {Process Name}
{Process Name} was restarted because it wasn''t responding.
6108
{Process Name} is down
{Process Name} process went down before it fully started.
6109
{Process Name} restarts excessively
The {Process Name} process has restarted {1} times during last {2} minutes.
6110
Detector process recycle requested
The Detector process will be restarted as per the recycle request.
6111
Discover cluster node {cluster node Id} recycle requested
The Discover cluster node {cluster node Id} will restart based on a recycle request.