SentinelOne
104 events across 2 channels
Event ID 1 — Windows Agent is starting in mode. Agent version, running on Windows.
Message
Fields
| Name | Description |
|---|---|
ProductVersion | — |
WindowsVersion | — |
AgentMode | — |
Event ID 2 — Policy was changed in the Console: %1.
Message
Event ID 3 — Policy was changed with override commands: %1.
Message
Event ID 4 — Failed to register with management because it no longer exists.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Event ID 5 — Failed to register with management: %1 (%2).
Message
Fields
| Name | Description |
|---|---|
Reason | — |
ErrorCode | — |
RetrySeconds | — |
Event ID 6 — Threat remediation: Failed to delete file %1 because it was already deleted.
Message
Fields
| Name | Description |
|---|---|
FilePath | — |
Event ID 7 — Threat remediation: Failed to delete file %1.
Message
Fields
| Name | Description |
|---|---|
FilePath | — |
Error | — |
Event ID 8 — Threat remediation: Failed to rename file %1 to %2 because the file was deleted.
Message
Fields
| Name | Description |
|---|---|
SourceFilePath | — |
DestinationFilePath | — |
Event ID 9 — Threat remediation: Failed to rename file %1 to %2 because the file's parent directory does not exist.
Message
Fields
| Name | Description |
|---|---|
SourceFilePath | — |
DestinationFilePath | — |
Event ID 10 — Threat remediation: Failed to rename file %1 to %2 because the destination path already exists.
Message
Fields
| Name | Description |
|---|---|
SourceFilePath | — |
DestinationFilePath | — |
Event ID 11 — Threat remediation: Failed to rename file %1 to %2.
Message
Fields
| Name | Description |
|---|---|
SourceFilePath | — |
DestinationFilePath | — |
Error | — |
Event ID 12 — Threat remediation: Failed to restore file %1 to timestamp %2 because no snapshots were found up to the desired period.
Message
Fields
| Name | Description |
|---|---|
FilePath | — |
DesiredTimestamp | — |
Event ID 13 — Threat remediation: Failed to restore file %1 to timestamp %2 because it is being used by another process.
Message
Fields
| Name | Description |
|---|---|
FilePath | — |
DesiredTimestamp | — |
Event ID 14 — Threat remediation: Failed to restore file %1 to timestamp %2 because access was denied.
Message
Fields
| Name | Description |
|---|---|
FilePath | — |
DesiredTimestamp | — |
Event ID 15 — Threat remediation: Failed to restore registry value (key: %1, value: %2) because it does not exist.
Message
Fields
| Name | Description |
|---|---|
RegistryKeyPath | — |
Value | — |
Event ID 16 — Threat mitigation: Failed to kill malicious processes because the true context does not exist.
Message
Event ID 17 — Threat mitigation completion after reboot requested another reboot.
Message
Fields
| Name | Description |
|---|---|
TrueContextID | — |
MitigationAction | — |
Event ID 18 — Threat mitigation: Not killing process %1 (Path: %2, Process ID: %3) due to relation %4.
Message
Fields
| Name | Description |
|---|---|
ProcessName | — |
ProcessPath | — |
ProcessID | — |
Relation | — |
Event ID 19 — Threat mitigation: Cannot kill process %1 (Path: %2, Process ID: %3) because it is a core OS process.
Message
Fields
| Name | Description |
|---|---|
ProcessName | — |
ProcessPath | — |
ProcessID | — |
Event ID 20 — Threat mitigation: Cannot kill process %1 (Path: %2, Process ID: %3) because it is signed by SentinelOne.
Message
Fields
| Name | Description |
|---|---|
ProcessName | — |
ProcessPath | — |
ProcessID | — |
Event ID 21 — Threat mitigation: Cannot kill process %1 (Path: %2, Process ID: %3) due to an unknown error.
Message
Fields
| Name | Description |
|---|---|
ProcessName | — |
ProcessPath | — |
ProcessID | — |
Event ID 22 — Threat mitigation: Cannot kill threads of process %1 (Path: %2, Process ID: %3) due to an unknown error.
Message
Fields
| Name | Description |
|---|---|
ProcessName | — |
ProcessPath | — |
ProcessID | — |
Event ID 23 — Threat mitigation: Failed to quarantine file %1 because the file is remote.
Message
Fields
| Name | Description |
|---|---|
FilePath | — |
Event ID 24 — Threat mitigation: Failed to quarantine file %1 because the file belongs to a core OS process.
Message
Fields
| Name | Description |
|---|---|
FilePath | — |
Event ID 25 — Threat mitigation: Failed to scramble file %1.
Message
Fields
| Name | Description |
|---|---|
FilePath | — |
Error | — |
Event ID 26 — Threat mitigation: skipping quarantine of file %1 because the file was already quarantined by another threat mitigation.
Message
Fields
| Name | Description |
|---|---|
FilePath | — |
Event ID 27 — Threat mitigation: Failed to quarantine file %1 because the file does not exist.
Message
Fields
| Name | Description |
|---|---|
FilePath | — |
Event ID 28 — Threat mitigation: A reboot is required to complete the quarantine of file %1.
Message
Fields
| Name | Description |
|---|---|
FilePath | — |
Event ID 29 — Threat mitigation: Failed to quarantine a file.
Message
Fields
| Name | Description |
|---|---|
Error | — |
Event ID 30 — Network quarantine failed.
Message
Fields
| Name | Description |
|---|---|
Error | — |
Event ID 31 — Malware detected!
Message
Fields
| Name | Description |
|---|---|
TrueContextID | — |
Name | — |
Path | — |
DetectionEngine | — |
Event ID 32 — Mitigation report True Context ID: %1 Action: %2 Result: %3.
Message
Fields
| Name | Description |
|---|---|
TrueContextID | — |
Action | — |
Result | — |
Event ID 33 — Failed to unquarantine file because the file cannot be found
Message
Fields
| Name | Description |
|---|---|
FilePath | — |
Event ID 34 — Unquarantine: Failed to restore file times for %1.
Message
Fields
| Name | Description |
|---|---|
FilePath | — |
Error | — |
Event ID 35 — Failed to unquarantine files affected by threat of True Context ID %1.
Message
Fields
| Name | Description |
|---|---|
TrueContextID | — |
Error | — |
Event ID 36 — Network unquarantine failed.
Message
Fields
| Name | Description |
|---|---|
Error | — |
Event ID 37 — Policy not changed. Verification key not provided.
Message
Event ID 38 — Policy not changed. The provided verification key is incorrect.
Message
Event ID 39 — Policy not changed. A parameter cannot be both set and undefined.
Message
Event ID 40 — Policy not changed. Parameter was not provided.
Message
Event ID 41 — Policy not changed. The value is not valid for: invalid URL.
Message
Fields
| Name | Description |
|---|---|
Parameter | — |
Value | — |
Event ID 42 — Policy not changed. The value is not valid.
Message
Fields
| Name | Description |
|---|---|
Parameter | — |
Value | — |
Event ID 43 — Policy not changed. The provided proxy credentials are invalid.
Message
Fields
| Name | Description |
|---|---|
Parameter | — |
Event ID 44 — Policy not changed. Failed to write value for UI Language due to error
Message
Fields
| Name | Description |
|---|---|
Parameter | — |
Value | — |
Error | — |
Event ID 45 — Policy not changed. Invalid UI configuration property.
Message
Fields
| Name | Description |
|---|---|
Parameter | — |
Event ID 46 — Policy not changed. Invalid engine status.
Message
Fields
| Name | Description |
|---|---|
Parameter | — |
Value | — |
Event ID 47 — Policy not changed. Invalid parameter.
Message
Fields
| Name | Description |
|---|---|
Parameter | — |
Error | — |
Event ID 48 — Policy not changed.
Message
Fields
| Name | Description |
|---|---|
Parameter | — |
Value | — |
Error | — |
Event ID 49 — Policy not changed. Cannot undefine parameter.
Message
Fields
| Name | Description |
|---|---|
Parameter | — |
Event ID 50 — Cannot scan because the path does not exist.
Message
Fields
| Name | Description |
|---|---|
Path | — |
Event ID 51 — Cannot scan because it is not a folder.
Message
Fields
| Name | Description |
|---|---|
Path | — |
Event ID 52 — Scan not started because a previous scan is still in progress.
Message
Event ID 53 — Cannot scan because Sentinel Agent is not running.
Message
Event ID 54 — Scan aborted.
Message
Event ID 55 — Full Disk Scan started.
Message
Event ID 56 — Scan of started.
Message
Fields
| Name | Description |
|---|---|
Path | — |
Event ID 57 — Scan completed successfully.
Message
Event ID 58 — Failed to execute command %1.
Message
Fields
| Name | Description |
|---|---|
Command | — |
Error | — |
Event ID 59 — Remote Shell: %1.
Message
Fields
| Name | Description |
|---|---|
Error | — |
Event ID 60 — Agent Upgrade: BITS job created for downloading the new Agent.
Message
Fields
| Name | Description |
|---|---|
BITSJobTitle | — |
BITSJobGUID | — |
DownloadDestination | — |
Event ID 61 — Agent Upgrade: BITS download job complete.
Message
Fields
| Name | Description |
|---|---|
BITSJobTitle | — |
BITSJobGUID | — |
DownloadDestinationPath | — |
Event ID 62 — Agent Upgrade: BITS download job failed.
Message
Fields
| Name | Description |
|---|---|
ErrorMessage | — |
ErrorCode | — |
BITSJobTitle | — |
BITSJobGUID | — |
Event ID 63 — Agent Upgrade: BITS download job failed.
Message
Fields
| Name | Description |
|---|---|
ErrorMessage | — |
ErrorCode | — |
BITSJobTitle | — |
BITSJobGUID | — |
Event ID 64 — Agent Upgrade: BITS is unavailable.
Message
Event ID 65 — Agent handled the creation of process %1 (PID: %2).
Message
Fields
| Name | Description |
|---|---|
Name | — |
PID | — |
UID | — |
GroupUID | — |
Event ID 66 — DB pruning %1.
Message
Fields
| Name | Description |
|---|---|
Result | — |
SizeBefore | — |
SizeAfter | — |
NewGUID | — |
OldPath | — |
NewPath | — |
Event ID 67 — Customer ID: %1.
Message
Fields
| Name | Description |
|---|---|
customerID | — |
Event ID 68 — Mark as on True Context ID received from Deep Visibility
Message
Fields
| Name | Description |
|---|---|
TrueContextID | — |
Status | — |
Event ID 69 — Failed to Mark True Context ID %1 as %2.
Message
Fields
| Name | Description |
|---|---|
TrueContextID | — |
Status | — |
Event ID 70 — Failed to Mark as: True Context ID.
Message
Fields
| Name | Description |
|---|---|
TrueContextID | — |
Status | — |
Event ID 71 — True Context ID was changed from suspicious to threat
Message
Fields
| Name | Description |
|---|---|
TrueContextID | — |
Event ID 72 — Failed to Mark as: True Context ID.
Message
Fields
| Name | Description |
|---|---|
TrueContextID | — |
Status | — |
Event ID 73 — Failed to Mark as Suspicious True Context ID %1.
Message
Fields
| Name | Description |
|---|---|
TrueContextID | — |
Event ID 74 — Failed to Mark as True Context ID.
Message
Fields
| Name | Description |
|---|---|
TrueContextID | — |
Status | — |
Event ID 75 — Agent handled the termination of process %1 (PID: %2).
Message
Fields
| Name | Description |
|---|---|
Name | — |
PID | — |
UID | — |
GroupUID | — |
Event ID 76 — Agent encountered invalid pattern: %1.
Message
Fields
| Name | Description |
|---|---|
Pattern | — |
Event ID 77 — USB device was based on SentinelOne Device Control policy
Message
Fields
| Name | Description |
|---|---|
DeviceName | — |
Action | — |
UsbDeviceClass | — |
VendorId | — |
ProductId | — |
SerialId | — |
Event ID 78 — Bluetooth device was based on SentinelOne Device Control policy
Message
Fields
| Name | Description |
|---|---|
DeviceName | — |
Action | — |
DeviceClass | — |
DeviceMinorClass | — |
VendorId | — |
ProductId | — |
ManufacturerName | — |
BluetoothAddress | — |
BluetoothVersion | — |
GATTService | — |
DeviceInformation | — |
Event ID 79 — %1 device %2 was %3 based on SentinelOne Device Control policy %4.
Message
Fields
| Name | Description |
|---|---|
Interface | — |
DeviceName | — |
Action | — |
Info | — |
Event ID 80 — The agent encountered an error that is usually ignored, but shouldn't be ignored in automation: %1.
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 81 — Scan ended.
Message
Fields
| Name | Description |
|---|---|
ScanStartTime | — |
ScanEndTime | — |
ScannedPath | — |
TriggerType | — |
ScannedCount | — |
MaliciousCount | — |
ExcludedMaliciousCount | — |
Status | — |
Event ID 82 — BlueKeep exploitation attempt detected from: %1.
Message
Fields
| Name | Description |
|---|---|
IP | — |
Event ID 83 — Resizing the VSS diff area on %2 was blocked.
Message
Fields
| Name | Description |
|---|---|
VolumeNameLength | — |
VolumeName | — |
OldDiffAreaUsed | — |
OldDiffAreaAllocated | — |
NewDiffAreaMaximum | — |
Event ID 84 — Blocked %5 connection.
Message
Fields
| Name | Description |
|---|---|
RemoteAddress | — |
Port | — |
ProcessId | — |
AppId | — |
PacketDirection | — |
FilterId | — |
LayerId | — |
Fqdn | — |
RuleId | — |
RuleName | — |
Event ID 85 — Unable to handle configuration change, dropping the configuration
Message
Event ID 86 — UI storage reached maximum allowed file size
Message
Event ID 87 — UI storage read error %2 "%1".
Message
Fields
| Name | Description |
|---|---|
ErrorMessage | — |
ErrorCode | — |
Event ID 88 — UI storage write error %2 "%1".
Message
Fields
| Name | Description |
|---|---|
ErrorMessage | — |
ErrorCode | — |
Event ID 89 — UI storage is corrupted and will be deleted.
Message
Event ID 90 — Error deleting corrupted UI storage.
Message
Event ID 91 — Remote script orchestrator: script %1 execution completed.
Message
Fields
| Name | Description |
|---|---|
ScriptName | — |
StartTime | — |
Duration | — |
ExitCode | — |
Event ID 92 — File was detected as a malicious driver when attempting to load it (Malicious Driver Type:)
Message
Fields
| Name | Description |
|---|---|
FilePath | — |
MaliciousDriverType | — |
Event ID 93 — SentinelCTL command of type "%1" was executed - result was: %2.
Message
Fields
| Name | Description |
|---|---|
CommandType | — |
Result | — |
Event ID 94 — Anti-tampering was activated.
Message
Event ID 95 — Anti-tampering was deactivated.
Message
Event ID 96 — Agent upgrade was initiated.
Message
Fields
| Name | Description |
|---|---|
OldVersion | — |
NewVersion | — |
Event ID 97 — Windows Agent is shutting down.
Message
Event ID 98 — Sentinel process has crashed.
Message
Fields
| Name | Description |
|---|---|
DumpPath | — |
Event ID 99 — Dump file was deleted, as dump limit of %1 was reached.
Message
Fields
| Name | Description |
|---|---|
DumpFileLimit | — |
DumpPath | — |
Event ID 100 — The agent has successfully connected to the SentinelOne console (%1).
Message
Fields
| Name | Description |
|---|---|
ConsoleURL | — |
Event ID 101 — The agent received a command from console
Message
Fields
| Name | Description |
|---|---|
CommandType | — |
Event ID 102 — Entering disable mode by command.
Message
Event ID 103 — Exiting disable mode.
Message
Event ID 104 —
Message
Fields
| Name | Description |
|---|---|
CommSdkMessage | — |