Previous Topic: Kernel Notification ActionNext Topic: Kernel Status Action


Kernel Operation Action

The Kernel Operation action expresses general information on system kernel operations. When you want to record kernel normal functions or if you cannot map the event to a more specific CEG action, consider mapping the event to this action.

Information

Level

Source - User Information

Secondary

Source - Host Information

Tertiary

Source - Object Information

Tertiary

Source - Process Information

Tertiary

Source - Group Information

Tertiary

Dest - User Information

Tertiary

Dest - Host Information

Primary

Dest - Object Information

Primary

Dest - Group Information

Tertiary

Agent - Information

Primary

Agent - Host Information

Primary

Event Source - Host Information

Primary

Event Source - Information

Tertiary

Event - Information

Primary

Result - Information

Primary

Result

event_result

event_severity

Success

S

2

Failure

F

3