Previous Topic: How to Filter Events Automatically

Next Topic: Filter Rule Setup

Generic Event Data

Information about events is communicated using a generic event data structure. The generic event data structure consists of the following data elements:

Source Type

Identifies the format for the rest of the event.

Node ID

Identifies the device name or ID.

User ID

Identifies the user name or ID (when applicable).

Major Source

Identifies the source application ID.

Minor Source

Identifies the agent of event or further delineation.

Date/Time

Identifies the event date and time.

Event ID

Identifies the source event string that triggered the event.

Event Data

Identifies the associated event data.

Severity

Identifies the measure of the event’s importance.

Handle

Identifies the daemon-supplied string resulting from rules.

Handle Source

Identifies the daemon identifier that assigned the handle.

Handle Status

Identifies the status as create, update, or terminate.

Status Count

Identifies the number of updates.