Information about the operation of each Kaspersky Endpoint Security component, data encryption events, the completion of each malware scan task, update task and integrity check task, and the overall operation of the application is recorded in the Kaspersky Security Center event log and Windows event log.
Kaspersky Endpoint Security generates events of the following types: general events and specific events. Specific events are created only by Kaspersky Endpoint Security for Windows. Specific events have a simple ID, such as 000000cb. Specific events contain the following required parameters:
GNRL_EA_DESCRIPTION is the content of the event.GNRL_EA_ID is the service ID of the event.GNRL_EA_SEVERITY is the status of the event. 1 – Informational message 2 – Warning 3 – Functional failure 4 – Critical EVENT_TYPE_DISPLAY_NAME is the title of the event.TASK_DISPLAY_NAME is the name of the application component that initiated the event.General events can be created by Kaspersky Endpoint Security for Windows as well as other Kaspersky applications (for example, Kaspersky Security for Windows Server). General events have a more complex ID, such as GNRL_EV_VIRUS_FOUND. In addition to required settings, general events contain advanced settings.
Critical events
End User License Agreement violated
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Databases are missing or corrupted
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
– |
Databases are extremely out of date
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Application autorun is disabled
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
– |
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Active threat detected. Advanced Disinfection should be started
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Not enough space in Quarantine storage
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Object not restored from Quarantine
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Object not deleted from Quarantine
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
The application established a connection to a website with an untrusted certificate
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Failed to verify an encrypted connection. The domain is added to the list of exclusions
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Malicious object detected (local bases)
Status |
|
Component |
File Threat Protection Web Threat Protection Mail Threat Protection AMSI Protection Host Intrusion Prevention Behavior Detection Exploit Prevention Malware Scan |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Event parameters |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Malicious object detected (KSN)
Status |
|
Component |
File Threat Protection Web Threat Protection Mail Threat Protection AMSI Protection Host Intrusion Prevention Behavior Detection Exploit Prevention Malware Scan |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Event parameters |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
File Threat Protection Mail Threat Protection Host Intrusion Prevention Malware Scan |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Event parameters |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
File Threat Protection Host Intrusion Prevention Behavior Detection Malware Scan |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
File Threat Protection Web Threat Protection Mail Threat Protection Host Intrusion Prevention AMSI Protection Malware Scan |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
File Threat Protection Host Intrusion Prevention Behavior Detection Malware Scan |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
File Threat Protection Host Intrusion Prevention Behavior Detection Malware Scan |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
– |
Status |
|
Component |
Web Threat Protection |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Event parameters |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
Web Threat Protection |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Event parameters |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Previously opened dangerous link detected
Status |
|
Component |
Web Threat Protection |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Event parameters |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
Adaptive Anomaly Control |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Event parameters |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
BadUSB Attack Prevention |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
AMSI Protection |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
Firewall |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
Network Threat Protection |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Event parameters |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Application startup prohibited
Status |
|
Component |
Application Control |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Event parameters |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Prohibited process was started before Kaspersky Endpoint Security startup
Status |
|
Component |
Application Control |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
Web Control |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Event parameters |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
Web Control |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Event parameters |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Operation with the device prohibited
Status |
|
Component |
Device Control |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Event parameters |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
Device Control |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
Database update |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Error distributing component updates
Status |
|
Component |
Database update |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
Database update |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
Database update |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Cannot start two tasks at the same time
Status |
|
Component |
Database update |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Error verifying application databases and modules
Status |
|
Component |
Database update |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Error in interaction with Kaspersky Security Center
Status |
|
Component |
Database update |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Not all components were updated
Status |
|
Component |
Database update |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Update completed successfully, update distribution failed
Status |
|
Component |
Database update |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
Database update |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
Database update |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Error applying file encryption / decryption rules
Status |
|
Component |
Data Encryption |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
File encryption / decryption error
Status |
|
Component |
Data Encryption |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Event parameters |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
Data Encryption |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Event parameters |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
Data Encryption |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
Data Encryption |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Error creating encrypted package
Status |
|
Component |
Data Encryption |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Error encrypting / decrypting device
Status |
|
Component |
Data Encryption |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Could not load encryption module
Status |
|
Component |
Data Encryption |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
The task for managing Authentication Agent accounts ended with an error
Status |
|
Component |
Data Encryption |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
Data Encryption |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
Data Encryption |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Kaspersky Anti Targeted Attack Platform server unavailable
Status |
|
Component |
Endpoint Sensor |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
Kaspersky Sandbox |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Object not quarantined (Kaspersky Sandbox)
Status |
|
Component |
Kaspersky Sandbox |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
Kaspersky Sandbox |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Invalid Kaspersky Sandbox server certificate
Status |
|
Component |
Kaspersky Sandbox |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
The Kaspersky Sandbox node is unavailable
Status |
|
Component |
Kaspersky Sandbox |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
An error occurred while processing the object in Kaspersky Sandbox
Status |
|
Component |
Kaspersky Sandbox |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Maximum load to Kaspersky Sandbox is exceeded
Status |
|
Component |
Kaspersky Sandbox |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
Endpoint Detection and Response |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Kaspersky Sandbox license verification failed
Status |
|
Component |
Kaspersky Sandbox |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
Endpoint Detection and Response |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
Endpoint Detection and Response |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
Endpoint Detection and Response |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Object not quarantined (Endpoint Detection and Response)
Status |
|
Component |
Endpoint Detection and Response |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Process startup is not blocked
Status |
|
Component |
Endpoint Detection and Response |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
Endpoint Detection and Response |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Script execution is not blocked
Status |
|
Component |
Endpoint Detection and Response |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Error changing application components
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
There are patterns of a possible brute-force attack in the system
Status |
|
Component |
Log Inspection |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
There are patterns of a possible Windows Event Log abuse
Status |
|
Component |
Log Inspection |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Atypical actions detected on behalf of a new service installed
Status |
|
Component |
Log Inspection |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Atypical logon that uses explicit credentials detected
Status |
|
Component |
Log Inspection |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
There are patterns of a possible Kerberos forged PAC (MS14-068) attack in the system
Status |
|
Component |
Log Inspection |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Suspicious changes detected in the privileged built-in Administrators group
Status |
|
Component |
Log Inspection |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
There is an atypical activity detected during a network logon session
Status |
|
Component |
Log Inspection |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
Log Inspection |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Atypical event occurs too often. Event aggregation started
Status |
|
Component |
Log Inspection |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Report on an atypical event for the aggregation period
Status |
|
Component |
Log Inspection |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Functional failure
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Invalid task settings. Settings not applied
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Warning
Application crashed during previous session
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
– |
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
– |
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Automatic updates are disabled
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Protection components are disabled
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Computer is running in safe mode
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
– |
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Quit and reopen the application to complete updating
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
The license allows the use of components that have not been installed
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Advanced Disinfection completed
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
Behavior Detection Exploit Prevention Web Threat Protection |
Windows event ID |
|
Kaspersky Security Center event ID |
– |
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
– |
Cannot restore object from Backup
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
– |
Suspicious network activity detected
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Encrypted connection terminated
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Processing of some OS functions is disabled
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Quarantine storage is almost out of space
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
File Threat Protection Behavior Detection Host Intrusion Prevention Malware Scan |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
File Threat Protection Mail Threat Protection Host Intrusion Prevention AMSI Protection Malware Scan |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Event parameters |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
Host Intrusion Prevention |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
– |
Status |
|
Component |
File Threat Protection Web Threat Protection Mail Threat Protection AMSI Protection Host Intrusion Prevention Malware Scan |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
– |
Status |
|
Component |
File Threat Protection Web Threat Protection Mail Threat Protection Host Intrusion Prevention AMSI Protection Behavior Detection Malware Scan |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Event parameters |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
File Threat Protection Web Threat Protection Mail Threat Protection Host Intrusion Prevention AMSI Protection Behavior Detection Malware Scan |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Event parameters |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
File Threat Protection Mail Threat Protection Host Intrusion Prevention Exploit Prevention Behavior Detection Malware Scan |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Event parameters |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
File Threat Protection Mail Threat Protection Host Intrusion Prevention Malware Scan |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Event parameters |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Object will be disinfected on restart
Status |
|
Component |
Host Intrusion Prevention File Threat Protection Malware Scan |
Windows event ID |
|
Kaspersky Security Center event ID |
– |
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
– |
Object will be deleted on restart
Status |
|
Component |
Behavior Detection Exploit Prevention Host Intrusion Prevention File Threat Protection Malware Scan |
Windows event ID |
|
Kaspersky Security Center event ID |
– |
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
– |
Object deleted according to settings
Status |
|
Component |
Mail Threat Protection |
Windows event ID |
|
Kaspersky Security Center event ID |
– |
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
– |
Status |
|
Component |
File Threat Protection Behavior Detection Exploit Prevention Malware Scan |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
Web Threat Protection |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Event parameters |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
BadUSB Attack Prevention |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
The object scan result has been sent to a third-party application
Status |
|
Component |
AMSI Protection |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Event parameters |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Task settings applied successfully
Status |
|
Component |
Application Control |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Warning about undesirable content (local bases)
Status |
|
Component |
Web Control |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Event parameters |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Warning about undesirable content (KSN)
Status |
|
Component |
Web Control |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Event parameters |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Undesirable content was accessed after a warning
Status |
|
Component |
Web Control |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
– |
Temporary access to the device activated
Status |
|
Component |
Device Control |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
– |
Operation cancelled by the user
Status |
|
Component |
Database update |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
User has opted out of the encryption policy
Status |
|
Component |
Data Encryption |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Interrupted applying file encryption / decryption rules
Status |
|
Component |
Data Encryption |
Windows event ID |
|
Kaspersky Security Center event ID |
– |
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
– |
File encryption / decryption interrupted
Status |
|
Component |
Data Encryption |
Windows event ID |
|
Kaspersky Security Center event ID |
– |
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
– |
Device encryption / decryption interrupted
Status |
|
Component |
Data Encryption |
Windows event ID |
|
Kaspersky Security Center event ID |
– |
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
– |
Failed to install or upgrade Kaspersky Disk Encryption drivers in the WinRE image
Status |
|
Component |
Data Encryption |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
Integrity check |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Application startup was blocked
Status |
|
Component |
Endpoint Sensor |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
Endpoint Sensor |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Process was terminated by the Kaspersky Anti Targeted Attack Platform server administrator
Status |
|
Component |
Endpoint Sensor |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
The application was terminated by the Kaspersky Anti Targeted Attack Platform server administrator
Status |
|
Component |
Endpoint Sensor |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
File or stream was deleted by the Kaspersky Anti Targeted Attack Platform server administrator
Status |
|
Component |
Endpoint Sensor |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
Endpoint Sensor |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
File was quarantined on the Kaspersky Anti Targeted Attack Platform server by administrator
Status |
|
Component |
Endpoint Sensor |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Network activity of all third-party applications is blocked
Status |
|
Component |
Endpoint Sensor |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Network activity of all third-party applications is unblocked
Status |
|
Component |
Endpoint Sensor |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Object will be deleted after restart (Kaspersky Sandbox)
Status |
|
Component |
Kaspersky Sandbox |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Total size of scan tasks exceeded the limit
Status |
|
Component |
Kaspersky Sandbox |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Object startup allowed, event logged
Status |
|
Component |
Endpoint Detection and Response |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Process startup allowed, event logged
Status |
|
Component |
Endpoint Detection and Response |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Object will be deleted after restart (Endpoint Detection and Response)
Status |
|
Component |
Endpoint Detection and Response |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
Endpoint Detection and Response |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Termination of network isolation
Status |
|
Component |
Endpoint Detection and Response |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Restart required to complete the task
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Application startup blockage message to administrator
Status |
|
Component |
Application Control |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Event parameters |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Device access blockage message to administrator
Status |
|
Component |
Device Control |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Event parameters |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Web page access blockage message to administrator
Status |
|
Component |
Web Control |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Event parameters |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
Device Control |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Event parameters |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Application activity blockage message to administrator
Status |
|
Component |
Adaptive Anomaly Control |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Event parameters |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
File Integrity Monitor |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Object changes too often. Event aggregation started
Status |
|
Component |
File Integrity Monitor |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Report on object modification for the aggregation period
Status |
|
Component |
File Integrity Monitor |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Monitoring scope includes incorrect objects
Status |
|
Component |
File Integrity Monitor |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Informational message
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
– |
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
– |
Self-Defense restricted access to the protected resource
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
– |
Subscription settings have changed
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
The application works and processes data under relevant laws and uses the appropriate infrastructure
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Object restored from Quarantine
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Object deleted from Quarantine
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
A backup copy of the object was created
Status |
|
Component |
File Threat Protection Mail Threat Protection Behavior Detection Host Intrusion Prevention Kaspersky Sandbox Malware Scan |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Overwritten by a copy that was disinfected earlier
Status |
|
Component |
File Threat Protection Host Intrusion Prevention Malware Scan |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
– |
Password-protected archive detected
Status |
|
Component |
File Threat Protection Web Threat Protection Mail Threat Protection AMSI Protection Host Intrusion Prevention Malware Scan |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Event parameters |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Information about detected object
Status |
|
Component |
File Threat Protection Web Threat Protection Mail Threat Protection AMSI Protection Host Intrusion Prevention Malware Scan |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
The object is in the Private KSN allowlist
Status |
|
Component |
File Threat Protection Web Threat Protection Mail Threat Protection AMSI Protection Host Intrusion Prevention Malware Scan |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
Mail Threat Protection Exploit Prevention Behavior Detection Malware Scan |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
Host Intrusion Prevention File Threat Protection Web Threat Protection Mail Threat Protection Malware Scan |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
– |
Status |
|
Component |
Host Intrusion Prevention File Threat Protection AMSI Protection Malware Scan |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
– |
Status |
|
Component |
Host Intrusion Prevention File Threat Protection Web Threat Protection Mail Threat Protection AMSI Protection Malware Scan |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
– |
Status |
|
Component |
Host Intrusion Prevention File Threat Protection Web Threat Protection Mail Threat Protection AMSI Protection Malware Scan |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
– |
Status |
|
Component |
Web Threat Protection |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
– |
Status |
|
Component |
Application Control |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
– |
Status |
|
Component |
Database update |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
– |
Status |
|
Component |
Database update |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
– |
The link is in the Private KSN allowlist
Status |
|
Component |
Web Threat Protection |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Application placed in the trusted group
Status |
|
Component |
Host Intrusion Prevention |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Application placed in restricted group
Status |
|
Component |
Host Intrusion Prevention |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Host Intrusion Prevention was triggered
Status |
|
Component |
Host Intrusion Prevention |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
Behavior Detection Exploit Prevention Host Intrusion Prevention |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
Behavior Detection Exploit Prevention |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
– |
Status |
|
Component |
Behavior Detection Exploit Prevention |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
– |
Status |
|
Component |
Adaptive Anomaly Control |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Event parameters |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
BadUSB Attack Prevention |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
Firewall |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
– |
Application startup prohibited in test mode
Status |
|
Component |
Application Control |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Event parameters |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Application startup allowed in test mode
Status |
|
Component |
Application Control |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Event parameters |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
– |
A page that is allowed was opened
Status |
|
Component |
Web Control |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
– |
Operation with the device allowed
Status |
|
Component |
Device Control |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
– |
Status |
|
Component |
Device Control |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Event parameters |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
– |
Status |
|
Component |
Database update |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
– |
Update distribution completed successfully
Status |
|
Component |
Database update |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
– |
Status |
|
Component |
Database update |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
– |
Status |
|
Component |
Database update |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
– |
Status |
|
Component |
Database update |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
– |
Status |
|
Component |
Database update |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
– |
File rolled back due to update error
Status |
|
Component |
Database update |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
– |
Status |
|
Component |
Database update |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
– |
Status |
|
Component |
Database update |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
– |
Status |
|
Component |
Database update |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
– |
Creating the list of files to download
Status |
|
Component |
Database update |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
– |
Status |
|
Component |
Database update |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
– |
Status |
|
Component |
Database update |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
– |
Status |
|
Component |
Database update |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
– |
Status |
|
Component |
Database update |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
– |
Status |
|
Component |
Database update |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
– |
Started applying file encryption / decryption rules
Status |
|
Component |
Data Encryption |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Finished applying file encryption / decryption rules
Status |
|
Component |
Data Encryption |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Resumed applying file encryption / decryption rules
Status |
|
Component |
Data Encryption |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
– |
File encryption / decryption started
Status |
|
Component |
Data Encryption |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
– |
File encryption / decryption completed
Status |
|
Component |
Data Encryption |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
– |
File has not been encrypted because it is an exclusion
Status |
|
Component |
Data Encryption |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
– |
Status |
|
Component |
Data Encryption |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
– |
Status |
|
Component |
Data Encryption |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
– |
Device encryption / decryption started
Status |
|
Component |
Data Encryption |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
– |
Device encryption / decryption completed
Status |
|
Component |
Data Encryption |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
– |
Device encryption / decryption resumed
Status |
|
Component |
Data Encryption |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
– |
Status |
|
Component |
Data Encryption |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
– |
Device encryption / decryption process has been switched to active mode
Status |
|
Component |
Data Encryption |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
– |
Device encryption / decryption process has been switched to passive mode
Status |
|
Component |
Data Encryption |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
– |
Status |
|
Component |
Data Encryption |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
– |
New Authentication Agent account created
Status |
|
Component |
Data Encryption |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
– |
Authentication Agent account deleted
Status |
|
Component |
Data Encryption |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
– |
Authentication Agent account password changed
Status |
|
Component |
Data Encryption |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
– |
Successful Authentication Agent login
Status |
|
Component |
Data Encryption |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
– |
Failed Authentication Agent login attempt
Status |
|
Component |
Data Encryption |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
– |
Hard drive accessed using the procedure of requesting access to encrypted devices
Status |
|
Component |
Data Encryption |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
– |
Status |
|
Component |
Data Encryption |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
– |
Account was not added. This account already exists
Status |
|
Component |
Data Encryption |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
– |
Account was not modified. This account does not exist
Status |
|
Component |
Data Encryption |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
– |
Account was not deleted. This account does not exist
Status |
|
Component |
Data Encryption |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
– |
Status |
|
Component |
Data Encryption |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
FDE upgrade rollback successful
Status |
|
Component |
Data Encryption |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Failed to uninstall Kaspersky Disk Encryption drivers from the WinRE image
Status |
|
Component |
Data Encryption |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
BitLocker recovery key was changed
Status |
|
Component |
Data Encryption |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
BitLocker password / PIN was changed
Status |
|
Component |
Data Encryption |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
BitLocker recovery key was saved to a removable drive
Status |
|
Component |
Data Encryption |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Processing of tasks from the Kaspersky Anti Targeted Attack Platform server is inactive
Status |
|
Component |
Endpoint Sensor |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Endpoint Sensor connected to server
Status |
|
Component |
Endpoint Sensor |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Connection to the Kaspersky Anti Targeted Attack Platform server restored
Status |
|
Component |
Endpoint Sensor |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Tasks from the Kaspersky Anti Targeted Attack Platform server are being processed
Status |
|
Component |
Endpoint Sensor |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
Wipe Data |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
– |
Status |
|
Component |
Wipe Data |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Object quarantined (Kaspersky Sandbox)
Status |
|
Component |
Kaspersky Sandbox |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Object deleted (Kaspersky Sandbox)
Status |
|
Component |
Kaspersky Sandbox |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
– |
Status |
|
Component |
Endpoint Detection and Response |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
Endpoint Detection and Response |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Object quarantined (Endpoint Detection and Response)
Status |
|
Component |
Endpoint Detection and Response |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Object deleted (Endpoint Detection and Response)
Status |
|
Component |
Endpoint Detection and Response |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|
Application components successfully changed
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
Kaspersky Sandbox |
Windows event ID |
|
Kaspersky Security Center event ID |
– |
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
– |
Status |
|
Component |
Kaspersky Sandbox |
Windows event ID |
|
Kaspersky Security Center event ID |
– |
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
– |
Status |
|
Component |
Kaspersky Sandbox |
Windows event ID |
|
Kaspersky Security Center event ID |
– |
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
– |
Status |
|
Component |
Kaspersky Sandbox |
Windows event ID |
|
Kaspersky Security Center event ID |
– |
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
– |
Asynchronous Kaspersky Sandbox detection
Status |
|
Component |
Kaspersky Sandbox |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Event parameters |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
Device Control |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Event parameters |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Status |
|
Component |
Device Control |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Event parameters |
|
Windows event log (default) |
– |
Kaspersky Security Center event log (default) |
|
Error removing the previous version of the application
Status |
|
Component |
System Audit |
Windows event ID |
|
Kaspersky Security Center event ID |
|
Windows event log (default) |
|
Kaspersky Security Center event log (default) |
|