Skip to main content

List of Endpoint Policy Manager Event Categories and IDs

Feature Specific Events

List of Endpoint Policy Manager Event Categories and IDs

Feature Manager for Windows

Least Privilege Manager

Least Privilege Manager Mac OS

Java Rules Manager

Browser Router

Device Manager

Network Security Manager

Cloud Client

Global Event Ranges

Event IDsDescription
100-199Events related to policy processing, and specifically Group Policy processing.
200-299General events, such as errors that don't belong to any other category.
300-599Product-specific events, such as errors that don't belong to any other category.
600-9999Events related to operational activities, such as allowing, blocking or elevating a process

Policy Processing (100-199)

  1. Policies refreshed successfully

Description: Processed Group Policy successfully.

Message: Policies for %1 have been refreshed successfully. Flags: %2. Elapsed: %3. Message ID: %4

Severity: Informational

  1. Policy refresh failed

Description: Failed to process Group Policy.

Message: Couldn't refresh policies for %1. Cause: %2. Flags: %2. Elapsed: %4. Message ID: %5

Severity: Error

  1. Product is not supported on this OS.

Description: One of the products is not supported on this OS build and can’t be loaded.

Message: Product is not supported on this OS. Minimum version: %1.%2, SP: %3, Build: %4.

Severity: Informational

  1. Product is not supported on this OS.

Description: One of the products is not supported on this OS build and can’t be loaded.

Message: Product is not supported on this OS. Maximum version: %1.%2, SP: %3, Build: %4..

Severity: Informational

General (200-299)

  1. Couldn't send a message to the service

Description: Some component failed to communicate with PPExtensionService. This usually indicates a bug (e.g., the service has crashed).

Message: Couldn't send a message to the service. Cause: %1

Severity: Error

  1. The service has been disabled by Administrator

Description: Some component failed to communicate with PPExtensionService because the service is disabled.

Message: The service has been disabled by Administrator!

Severity: Warning

  1. Couldn't start the service

Description: Some component failed to communicate with PPExtensionService because it wasn't running (has probably crashed). When the component tried to start the service, it failed.

Message: Couldn't start the service. Error code: %1

Severity: Error

  1. Starting the service

Description: Some component failed to communicate with PPExtensionService because it wasn't running (has probably crashed). When the component tried to start the service, it succeeded.

Message: Starting the service...

Severity: Informational

  1. Licenses found on the machine are all valid.

Description: All of the licenses on the machine are valid.

Message: The following licenses have been found on this machine.

%1%0

Severity: Informational

  1. Licenses found on the machine are not all valid.

Description: Some of the licenses on the machine are invalid.

Message: The following licenses have been found on this machine, and there is a problem with one or more of them.

%1%0

Severity: Warning

  1. Licenses were not found on the machine.

Description: No license was found on the machine.

Message: There is no Endpoint Policy Manager license found on this machine.

%1%0

Severity: Warning

  1. Licenses were not found on the machine.

Description: No license was found on the machine.

Message: The computers license for Endpoint Policy Manager has become unavailable or this computer has become unlicensed.

%1%0

Severity: Warning

  1. Join status report.

Description: Join status report for this computer.

Message: This machine join status is shown below

%1%0

Severity: Informational

Operational Events

The following are all the operational events for Endpoint Policy Manager:

  • Remote Work Delivery Manager
  • Feature Manager for Windows
  • Least Privilege Manager
  • Least Privilege Manager Mac OS
  • Java Rules Manager
  • Browser Router
  • Device Manager
  • Network Security Manager
  • Cloud Client

Remote Work Delivery Manager

Event IDDescription
300The system will reboot to complete installation of Windows Features.
301The system reboot is pending.
500Bits became unavailable.
501The Background Intelligent Transfer Service is stopped.
505The Background Intelligent Transfer Service has been disabled by Administrator.
510Bits became available.
600SMB job is created.
601SMB job gets a temp error.
602SMB job temp error details.
603SMB job fails with error.
604SMB job error details.
605SMB job is completed.
606SMB revert job is created.
607SMB revert job gets a temp error.
608SMB revert job temp error details.
609SMB revert job fails with error.
610SMB revert job error details.
611SMB revert job fails with error.
700HTTP job is created.
701HTTP job gets a temp error.
702HTTP job temp error details.
703HTTP job fails with error.
704HTTP job error details.
705HTTP job is completed.
706HTTP revert job is created.
707HTTP revert job gets a temp error.
708HTTP revert job temp error details.
709HTTP revert job fails with error.
710HTTP revert job error details.
711HTTP revert job is completed.

Feature Manager for Windows

Event IDDescription
600Windows Feature is being installed.
601Installing Windows Feature was canceled.
602Windows Feature was installed.
603Installing Windows Feature progress.
604Installing Windows Feature failed.
650Windows Feature is being removed.
651Removing Windows Feature was canceled.
652Windows Feature was removed.
653Removing Windows Feature progress.
654Removing Windows Feature failed.
700Optional Feature is being installed.
701Installing Optional Feature was canceled.
702Installing Optional Feature was completed.
703Installing Optional Feature progress
704Installing Optional Feature failed.
750Optional Feature is being removed.
751Removing Optional Feature was canceled.
752Removing Optional Feature was completed.
753Removing Optional Feature progress
754Removing Optional Feature failed.

Least Privilege Manager

Event IDDescription
1000A process has been allowed to run by a rule.
1001A process has been allowed to run by a rule inherited from parent process.
1002An AppX package (UWP app) has been allowed to run by a rule.
1003A DLL has been allowed by a rule
1010Access to a resource has been granted
1020A process has been allowed to run by an on-demand rule.
1021A process has been allowed to run by an on-demand rule inherited from parent process.
1022A COM object has been allowed by a rule
1023An ActiveX installer has been allowed by a rule
1100A process has been forced to run with a limited token by a rule.
1101A process has been forced to run with a limited token by a rule inherited from parent process.
1120A process has been forced to run with a limited token by an on-demand rule.
1121A process has been forced to run with a limited token by an on-demand rule inherited from parent process.
1200A process has been elevated by a rule.
1201A process has been elevated by a rule inherited from parent process.
1202A COM object has been elevated by a rule
1203An ActiveX installer has been elevated by a rule
1220A process has been elevated by an on-demand rule.
1221A process has been elevated by an on-demand rule inherited from parent process.
1300A process has been allowed to run with custom security settings.
1301A process has been allowed to run with custom security settings inherited from parent process.
1320A process has been allowed to run with custom security settings by an on-demand rule.
1321A process has been allowed to run with custom security settings by an on-demand rule inherited from parent process.
2000A process has been blocked by a rule.
2002An AppX package (UWP app) has been blocked by a rule.
2003A DLL has been blocked by a rule
2010A process has been blocked by SecureRun.
2011A process has been blocked repeatedly
6200AUDIT: Process runs elevated.
6205AUDIT: Process requires elevation.
6206A COM object requires elevation
6207An ActiveX installer requires elevation
6210AUDIT: Process is untrusted and would have been blocked by SecureRun.
6211AUDIT: Active best matching SecureRun configuration
6215Executable is unsigned and would have been blocked by SecureRun
6300AA prompt is displayed because a process requires admin privileges.
6301AA prompt is displayed because a process is blocked by SecureRun.
6302AA prompt is displayed because user right-clicked on a file and selected Run with Endpoint Policy Manager.
6303A COM object requires administrator privileges
6304An ActiveX installer requires administrator privileges
6310Correct Response Code provided in AA prompt.
6311Response code verified for COM Object
6312Response code verified for an ActiveX installer
6315Alternate Admin Credentials provided in AA prompt.
6316COM object elevation approved with Admin credentials
6317An ActiveX installer elevation was approved with admin credentials
6320AA prompt has been canceled.
6321COM object AA prompt has been canceled.
6322ActiveX installer AA prompt has been canceled.
6330Incorrect Response Code provided in AA prompt.
6331Incorrect Response Code provided in COM object AA prompt.
6332Incorrect Response Code provided in ActiveX installer AA prompt.
6400Process elevated with self elevation
6401Process elevated with self elevation (with justification text)
6402Self Elevate mode ALLOWED vs NOT ALLOWED list
6403A COM object elevated with self elevation
6404A COM object elevated with self elevation (with justification text)
6500Process has been elevated as SecureCopy
6501Process has been elevated by a SecureCopy rule inherited from parent process
6500A process has been elevated as SecureCopy.
6501A process has been elevated by a SecureCopy rule inherited from parent process.
12300Process is configured to start with Netwrix Privilege Secure credentials (matching rule was found)
12310Netwrix Privilege Secure actvity session is started. Process has been restarted with user credentials provided by Netwrix Privilege Secure server
12312Netwrix Privilege Secure activity session is extended
12313Netwrix Privilege Secure activity session is stopped
12320Netwrix Privilege Secure client dialog canceled
12330User successfully signed in with Netwrix Privilege Secure

Least Privilege Manager Mac OS

Event IDDescription
1000Application launch allowed by rule.
1001Package allowed by rule.
1002Sudo allowed by rule.
1003Preferences allowed by rule.
1005Mount allowed by rule.
1006Finder allowed by rule.
1007Elevate Privileges allowed by rule
1101Package elevated by rule.
1102Sudo elevated by rule.
1103Preferences elevated by rule.
1105Mount allowed by rule.
1106Finder elevated by rule.
1107Elevate Privileges elevated by rule.
1200Application launch blocked by rule.
1201Package blocked by rule.
1202Sudo blocked by rule.
1203Preferences blocked by rule.
1205Mount blocked by rule.
1206Finder blocked by rule.
1207ElevatePrivileges blocked by rule.
2000Administrator approval is required for application launch.
2001Administrator approval is required for package.
2002Administrator approval is required for sudo.
2003Administrator approval is required for preferences.
2005Administrator approval is required for mount.
2006Administrator approval is required for Finder.
2007Administrator approval is required for Elevate Privileges.
2100Administrator approval is required to allow application to run by response code
2101Administrator approval allows package by existing code.
2102Administrator approval allows sudo by existing code.
2103Administrator approval allows preferences by existing code.
2104Administrator approval allows application launch by parent existing code.
2105Administrator approval allows mount by existing code.
2106Administrator approval allows Finder by existing code.
2107Administrator approval allows Elevate Privileges by existing code.
2200Administrator approval canceled for application launch.
2201Administrator approval canceled for package.
2202Administrator approval canceled for sudo.
2203Administrator approval canceled for preferences
2205Administrator approval canceled for mount
2206Administrator approval canceled for Finder
2207Administrator approval canceled for Elevate Privileges
2300Administrator approval response code verified for application launch
2301Administrator approval response code verified for package
2302Administrator approval response code verified for sudo
2303Administrator approval response code verified for preferences
2305Administrator approval response code verified for mount
2306Administrator approval response code verified for Finder
2307Administrator approval response code verified for Elevate Privileges
2400Administrator approval incorrect response code for application launch
2401Administrator approval incorrect response code for package
2402Administrator approval incorrect response code for sudo
2403Administrator approval incorrect response code for preferences
2405Administrator approval incorrect response code for mount
2406Administrator approval incorrect response code for Finder
2407Administrator approval incorrect response code for Elevate Privileges
2500Administrator approval allows application launch by administrator credentials
2501Administrator approval allows package by administrator credentials
2502Administrator approval allows sudo by administrator credentials
2503Administrator approval allows preferences by administrator credentials
2505Administrator approval allows mount by administrator credentials
2506Administrator approval allows Finder by administrator credentials
2507Administrator approval allows Elevate Privileges by administrator credentials
3000Approval is required for application launch
3001Approval is required for package
3002Approval is required for sudo
3003Approval is required for preferences
3005Approval is required for mount
3006Approval is required for finder
3007Approval is required for elevate privileges
3100Approval is granted for application launch
3101Approval is granted for package
3102Approval is granted for sudo
3103Approval is granted for preferences
3105Approval is granted for mount
3106Approval is granted for finder
3107Approval is granted for elevate privileges
3200Approval is canceled for application launch
3201Approval is canceled for package
3202Approval is canceled for sudo
3203Approval is canceled for preferences
3205Approval is canceled for mount
3206Approval is canceled for finder
3207Approval is canceled for elevate privileges

Java Rules Manager

Event IDDescription
8021PPJER policy has been changed
8022PPJER policy has been removed

Browser Router

Event IDDescription
9001Couldn't send message to Endpoint Policy Manager Helper Service. Cause: Endpoint Policy Manager Helper Service was not in a started state.
9002An exception occurred while processing a request from a Endpoint Policy Manager Browser Router extension.

Device Manager

Event IDDescription
10000Access to the device has been blocked due to Endpoint Policy Manager Device Manager Rule
10001Access to the device was granted by policies

Network Security Manager

Event IDDescription
10300Access to the network connection was granted by policies
10301Access to the network connection was granted by policies

Cloud Client

Event IDDescription
11001Netwrix Endpoint Policy Manager (formerly PolicyPak) Cloud Client is starting/stopping
11002Netwrix Endpoint Policy Manager (formerly PolicyPak) Cloud Client has been started/stopped or failed to start/stop
11003Netwrix Endpoint Policy Manager (formerly PolicyPak) product ( PPC Client or CSE) is being installed/updated
11004Netwrix Endpoint Policy Manager (formerly PolicyPak) product ( PPC Client or CSE) installation/update has been completed or failed
11005Customer certificate backup/restore activity
11006Netwrix Endpoint Policy Manager (formerly PolicyPak) Cloud Client registration in progress
11007Netwrix Endpoint Policy Manager (formerly PolicyPak) Cloud Client registration has been completed or failed
11008Netwrix Endpoint Policy Manager (formerly PolicyPak) Cloud Client unregistration in progress
11009Netwrix Endpoint Policy Manager (formerly PolicyPak) Cloud Client unregistration has been completed or failed
11010Netwrix Endpoint Policy Manager (formerly PolicyPak) Cloud Client sync in progress
11011Netwrix Endpoint Policy Manager (formerly PolicyPak) Cloud Client sync has been completed or failed
11012Netwrix Endpoint Policy Manager (formerly PolicyPak) Product (PPC Client or CSE) is being uninstalled
11013Netwrix Endpoint Policy Manager (formerly PolicyPak) product (PPC Client or CSE) uninstallation has been completed or failed
11014Event Collector activity
11015Collector Events submission started on schedule
11016Collector Events submission activity ended
11017Collector Events pushed manually