Previous Topic: System Call Execution ActionNext Topic: System Call Operation Action


System Call Notification Action

The System Call Notification action expresses information on notifications and messages generated by a system call. A system call is a request made by any program to the operating system for performing tasks. System calls provide the interface between a process and the operating system. You can map any type of system call notification to this action if the event cannot be mapped to a more specific action. Use the System Call Status action if the event describes the status of a system call.

Information

Level

Source - User Information

Secondary

Source - Host Information

Tertiary

Source - Object Information

Tertiary

Source - Process Information

Tertiary

Source - Group Information

Tertiary

Dest - User Information

Tertiary

Dest - Host Information

Primary

Dest - Object Information

Primary

Dest - Group Information

Tertiary

Agent - Information

Primary

Agent - Host Information

Primary

Event Source - Host Information

Primary

Event Source - Information

Tertiary

Event - Information

Primary

Result - Information

Primary

Result

event_result

event_severity

Success

S

2

Failure

F

3