Log event IDs
The records that matter to a log collector or a SIEM carry a numeric eventId field. This page lists every ID. Log records explains the record format, the fields, and the rules these IDs follow.
An ID names what happened, not where: the same event has the same ID on every protocol, and the protocol is a field. IDs are grouped in blocks of a thousand, so a rule can match a whole block or a range inside one (for example, 3100 to 3199 is every failed end user sign in).
NOTE
The meaning of an ID never changes, and an ID that is withdrawn is never used again. New IDs and new fields can be added in any release.
Every record also has the fields described in Log records. The Fields column lists the ones an event adds.
1000: Service lifecycle
| ID | Name | Level | What happened | Fields | Sources | Notes |
|---|---|---|---|---|---|---|
| 1001 | ServiceStarted | Info | The service started and its listeners are accepting connections. | webrest, worker | ||
| 1002 | ServiceStopping | Info | The service is shutting down. | webrest, worker | ||
| 1003 | ServiceStopped | Info | The service finished shutting down. | webrest, worker | ||
| 1010 | ListenerStarted | Info | A listener started accepting connections. | protocol, listener | webrest, worker | |
| 1011 | ListenerFailed | Error | A listener could not start, usually because its address is in use or not available. | protocol, listener | webrest, worker | |
| 1012 | ListenerStopped | Error | A listener stopped unexpectedly while the service kept running. | protocol, listener | webrest, worker | |
| 1013 | WorkerNoListener | Error | A virtual site cannot run because none of its protocol listeners started. | worker | ||
| 1014 | HandlerNotLicensed | Error | A protocol handler was not started because the license does not include it. | protocol | worker | |
| 1020 | NodeDrainEnabled | Info | The node stopped accepting new sessions for this virtual site (draining). | worker | ||
| 1021 | NodeDrainDisabled | Info | The node accepts new sessions again for this virtual site. | worker | ||
| 1030 | ConfigReloadFailed | Error | A configuration reload failed; the service keeps the configuration it had. | webrest, worker | ||
| 1031 | VFSReloadFailed | Error | Reloading the virtual file system definitions failed. | worker | ||
| 1040 | LicenseRefused | Error | The license does not allow the service to run as configured, and the service stops. | worker | ||
| 1050 | DatabaseDefaultCredential | Warning | The database was opened with the shared default credential instead of the installation's own. | webrest, worker |
2000: Client connections and sessions
| ID | Name | Level | What happened | Fields | Sources | Notes |
|---|---|---|---|---|---|---|
| 2001 | ClientConnected | Info | A client opened a connection; nobody has signed in yet. | sessionId, clientIp, protocol | ssh, ftp, ftps, ftpes | Same moment as OnNewConnection. |
| 2010 | ConnRefusedDraining | Warning | A connection or sign in was refused because the node is draining. | sessionId, clientIp, protocol | ssh, ftp, ftps, ftpes, https, share | Older releases tagged it /DRAIN in the comment. |
| 2011 | ConnRefusedTotalLimit | Warning | A connection or sign in was refused because the configured total number of connections is reached. | sessionId, clientIp, protocol | ssh, ftp, ftps, ftpes, https, share | Older releases tagged it /MTC in the comment. |
| 2012 | ConnRefusedLicenseLimit | Warning | A connection or sign in was refused because the number of connections the license allows is reached. | sessionId, clientIp, protocol | ssh, ftp, ftps, ftpes, https, share | Older releases tagged it /MTC in the comment. |
| 2013 | ConnRefusedAddressLimit | Warning | A connection or sign in was refused because its source address reached its connection limit. | sessionId, clientIp, protocol | ssh, ftp, ftps, ftpes, https, share | Older releases tagged it /MCP, /MPC in the comment. |
| 2014 | ConnRefusedAccountLimit | Warning | A sign in was refused because the account reached its connection limit. | sessionId, clientIp, protocol, username | ssh, ftp, ftps, ftpes, https, share | Older releases tagged it /UMC, /MPU in the comment. |
| 2015 | ConnRefusedByScript | Warning | An event handler script refused a new connection before sign in. | sessionId, clientIp, protocol | ssh, ftp, ftps, ftpes, https, share | Same moment as OnNewConnection, BeforeSendSoftwareID. Older releases tagged it /SCR in the comment. |
| 2016 | ConnRefusedAllowList | Warning | A connection was refused at accept because its source is not on the allow list. | clientIp, listener | webrest, ssh, ftp, ftps, ftpes, https, share | Sampled: the first refusal per source per minute. |
| 2017 | ConnRefusedListenerLimit | Warning | A connection was refused at accept because the listener's connection limits are reached. | clientIp, listener | webrest, ssh, ftp, ftps, ftpes, https, share | Sampled: the first refusal per source per minute. |
| 2020 | SSHNoCommonAlgorithms | Warning | An SSH connection failed because client and server share no algorithm. | sessionId, clientIp, protocol | ssh | Older releases tagged it /NCA in the comment. |
| 2021 | SSHHandshakeFailed | Warning | An SSH connection ended before a successful sign in: a failed handshake, a client that gave up, or failed sign in attempts. | sessionId, clientIp, protocol | ssh | Older releases tagged it /NSC in the comment. |
| 2022 | TLSHandshakeFailed | Warning | A TLS handshake failed. | clientIp | https, webrest | |
| 2023 | PlainTextOnTLSPort | Warning | A client spoke plain text to a port that requires TLS. | clientIp | https, webrest | |
| 2030 | ProtocolViolation | Warning | A client broke the protocol in a way the Shield counts against it (for example a forwarding request, a non session channel, too many usernames, a malformed sign in request, or a connection held open without signing in). | sessionId, clientIp, protocol | ssh, ftp, ftps, ftpes, https, share | |
| 2050 | SessionOpened | Info | A session opened after a successful sign in (for SSH, one per channel). | username, channelId, sessionId, clientIp, protocol | ssh, https, share | FTP opens its session at connect, which is ClientConnected. |
| 2051 | SessionClosed | Info | A session closed. | username, endReason, channelId, sessionId, clientIp, protocol | ssh, ftp, ftps, ftpes, https, share | Same moment as OnConnectionClose. endReason is one of: client closed, logout, idle timeout, admin terminated, terminated by script, session expired, server shutdown, share login refused. |
3000: End user sign in and credentials
| ID | Name | Level | What happened | Fields | Sources | Notes |
|---|---|---|---|---|---|---|
| 3001 | SignInSucceeded | Info | A user signed in. | authMethod, sessionId, clientIp, protocol, username | ssh, ftp, ftps, ftpes, https, share | Same moment as OnAuthSuccess. authMethod lists every method used, in order, for a multi factor sign in. |
| 3002 | SignInWithRecoveryCode | Warning | A user signed in with a recovery code instead of the authenticator; the account should enroll again. | sessionId, clientIp, protocol, username | https | |
| 3101 | SignInUnknownUser | Warning | A sign in named a user that does not exist. | sessionId, clientIp, protocol, username | ssh, ftp, ftps, ftpes, https, share | username is what the client typed. |
| 3102 | SignInWrongPassword | Warning | A sign in failed because the password is wrong. | sessionId, clientIp, protocol, username | ssh, ftp, ftps, ftpes, https, share | Same moment as OnAuthFail. Older releases tagged it /PV in the comment. |
| 3103 | SignInPublicKeyRejected | Warning | An SSH connection ended unauthenticated after the client offered public keys the account does not accept. | sessionId, clientIp, protocol, username | ssh | Written once per connection, not once per key offered. |
| 3104 | SignInSecondFactorRejected | Warning | A sign in failed because the one time code was wrong. | sessionId, clientIp, protocol, username | ssh, ftp, ftps, ftpes, https, share | Same moment as OnAuthFail. |
| 3105 | SignInRecoveryCodeRejected | Warning | A sign in failed because the recovery code was wrong or already used. | sessionId, clientIp, protocol, username | https | |
| 3106 | SignInAnswerRejected | Warning | A keyboard interactive sign in failed on a question set by a script. | sessionId, clientIp, protocol, username | ssh | Same moment as OnAuthFail. |
| 3107 | SignInPasskeyRejected | Warning | A passkey sign in was rejected. | sessionId, clientIp, protocol, username | https | |
| 3108 | SignInSSONoAccount | Warning | A verified single sign on identity matches no user. | sessionId, clientIp, protocol, username | https | |
| 3109 | SignInSSOAmbiguous | Warning | A verified single sign on identity matches more than one user, so the sign in was refused. | sessionId, clientIp, protocol, username | https | |
| 3110 | SignInSSOStateInvalid | Warning | A single sign on attempt came back with a missing, expired or foreign sign in state. | sessionId, clientIp, protocol, username | https | |
| 3120 | SignInMethodNotAllowed | Warning | A sign in used an authentication method the account does not allow. | authMethod, sessionId, clientIp, protocol, username | ssh | |
| 3121 | SignInProtocolNotAllowed | Warning | A sign in used a protocol the account is not allowed to use. | sessionId, clientIp, protocol, username | ssh, ftp, ftps, ftpes, https, share | Older releases tagged it /UPC in the comment. |
| 3122 | SignInAccountNotAllowed | Warning | A sign in was refused because the account is disabled, outside its validity period, or not allowed from the client's address. | sessionId, clientIp, protocol, username | ssh, ftp, ftps, ftpes, https, share | Older releases tagged it /UAL in the comment. |
| 3123 | SignInPasswordExpired | Warning | A correct password was refused because it expired under strict enforcement. | sessionId, clientIp, protocol, username | ssh, ftp, ftps, ftpes | |
| 3124 | SignInDeniedByScript | Warning | An event handler script refused a sign in. | sessionId, clientIp, protocol, username | ssh, ftp, ftps, ftpes, https, share | Same moment as OnAuthRequest, OnAuthPassword, OnAuthPKI, OnAuthInteractive, OnAuthSuccess. Older releases tagged it /USCRAR, /USCRAP in the comment. |
| 3125 | ShareNotAvailable | Warning | A shared link was refused because it expired, reached its access limit, or its owner can no longer sign in. | sessionId, clientIp, protocol, username | share | |
| 3140 | RevokedTokenPresented | Warning | A WebClient request carried a session token that was revoked. | sessionId, clientIp, protocol, username | https, share | Throttled: at most once per token per minute. |
| 3141 | TokenFromOtherAddress | Warning | A WebClient session token was presented from an address other than the one it was issued to. | sessionId, clientIp, protocol, username | https, share | Throttled: at most once per token per minute. |
| 3201 | PasswordChanged | Info | A user changed their own password. | sessionId, clientIp, protocol, username | https | |
| 3202 | PasswordChangeRefused | Warning | A user's own password change was refused because the current password was wrong. | sessionId, clientIp, protocol, username | https | |
| 3203 | SecondFactorEnrolled | Info | A user enrolled an authenticator. | sessionId, clientIp, protocol, username | https | |
| 3204 | SecondFactorRemoved | Info | A user removed their authenticator. | sessionId, clientIp, protocol, username | https | |
| 3205 | RecoveryCodesRegenerated | Info | A user generated a new set of recovery codes. | sessionId, clientIp, protocol, username | https | |
| 3206 | PasskeyEnrolled | Info | A user enrolled a passkey. | sessionId, clientIp, protocol, username | https | |
| 3207 | PasskeyDeleted | Info | A user deleted a passkey. | sessionId, clientIp, protocol, username | https | |
| 3208 | AppPasswordCreated | Info | A user created an app password. | sessionId, clientIp, protocol, username | https | |
| 3209 | AppPasswordRevoked | Info | A user revoked an app password. | sessionId, clientIp, protocol, username | https | |
| 3210 | TrustedDevicesRevoked | Info | A user revoked trusted devices. | sessionId, clientIp, protocol, username | https |
4000: End user file activity
| ID | Name | Level | What happened | Fields | Sources | Notes |
|---|---|---|---|---|---|---|
| 4001 | FileUploaded | Info | A file upload completed (including appends and combined uploads). | sessionId, clientIp, protocol, username, relPath | ssh, ftp, ftps, ftpes, https, share | Same moment as AfterFileUpload. |
| 4002 | FileDownloaded | Info | A file download completed. | sessionId, clientIp, protocol, username, relPath | ssh, ftp, ftps, ftpes, https, share | Same moment as AfterFileDownload. |
| 4003 | FileTransferFailed | Warning | A file upload or download ended with an error. | sessionId, clientIp, protocol, username, relPath | ssh, ftp, ftps, ftpes, https, share | Same moment as OnUploadFail, OnDownloadFail. |
| 4010 | FileDeleted | Info | A file was deleted. | sessionId, clientIp, protocol, username, relPath | ssh, ftp, ftps, ftpes, https, share | Same moment as AfterDeleteFile. |
| 4011 | DirectoryDeleted | Info | A directory was deleted. | sessionId, clientIp, protocol, username, relPath | ssh, ftp, ftps, ftpes, https, share | Same moment as AfterDeleteDir. |
| 4012 | Renamed | Info | A file or directory was renamed or moved. | relTargetPath, sessionId, clientIp, protocol, username, relPath | ssh, ftp, ftps, ftpes, https, share | Same moment as AfterRenameFile, AfterRenameDir. |
| 4013 | DirectoryCreated | Info | A directory was created. | sessionId, clientIp, protocol, username, relPath | ssh, ftp, ftps, ftpes, https, share | Same moment as AfterMakeDir. |
| 4015 | AttributesChanged | Info | The owner or the permissions of a file changed. | sessionId, clientIp, protocol, username, relPath | ssh, ftp, ftps, ftpes, https, share | Same moment as AfterAttrChange. |
| 4016 | TimestampsChanged | Info | The timestamps of a file changed. | sessionId, clientIp, protocol, username, relPath | ssh, ftp, ftps, ftpes, https, share | Same moment as AfterTimeChange. |
| 4017 | FileTruncated | Info | A file was truncated. | sessionId, clientIp, protocol, username, relPath | ssh, ftp, ftps, ftpes, https, share | Same moment as AfterAttrChange. |
| 4101 | PermissionDenied | Warning | A file operation was refused because the user has no permission for it. | sessionId, clientIp, protocol, username, relPath | ssh, ftp, ftps, ftpes, https, share | |
| 4102 | DeniedByScript | Warning | An event handler script refused a file operation. | sessionId, clientIp, protocol, username, relPath | ssh, ftp, ftps, ftpes, https, share | |
| 4103 | QuotaExceeded | Warning | An upload was refused or stopped because the quota is exceeded. | sessionId, clientIp, protocol, username, relPath | ssh, ftp, ftps, ftpes, https, share | Same moment as OnQuotaExceeded. Written once per upload. |
| 4104 | SubsystemNotAllowed | Warning | An SSH client asked for a subsystem the account is not allowed to use (SFTP, SCP, commands or shell). | sessionId, clientIp, protocol, username | ssh | Older releases tagged it /SCP, /EXEC, /SHELL in the comment. |
| 4201 | ShareCreated | Info | A user created a shared link. | objectId, sessionId, clientIp, protocol, username, relPath | https | Same moment as AfterShrCreate. |
| 4202 | ShareDeleted | Info | A user deleted a shared link. | objectId, sessionId, clientIp, protocol, username | https |
5000: Shield
| ID | Name | Level | What happened | Fields | Sources | Notes |
|---|---|---|---|---|---|---|
| 5001 | SourceBanned | Warning | The Shield banned an address or a network. | target, rule, protocol, detail, expiresOn | webrest, worker | Same moment as OnShieldBan. |
| 5002 | BanLifted | Info | A Shield ban was lifted. | target, rule, cause, hits | webrest, worker | In a cluster every node writes it when a replicated ban expires. |
| 5003 | BanMadePermanent | Info | A Shield ban was made permanent. | target, rule | webrest, worker | |
| 5004 | BannedSourceRefused | Warning | A connection from a banned source was refused at accept. | clientIp, listener | webrest, ssh, ftp, ftps, ftpes, https, share | Same moment as OnShieldBanHit. Sampled: the first refusal per source per minute. |
| 5010 | ShieldScriptEventsDropped | Warning | Shield events were dropped because their event handler scripts could not keep up. | webrest, worker |
6000: Operator sign in and credentials
| ID | Name | Level | What happened | Fields | Sources | Notes |
|---|---|---|---|---|---|---|
| 6001 | OperatorSignedIn | Info | A SuperAdmin or an Admin signed in. | actorRole, authMethod, clientIp, username, vsite | webrest | |
| 6002 | OperatorSignedInWithRecoveryCode | Warning | An operator signed in with a recovery code instead of the authenticator; the account should enroll again. | actorRole, clientIp, username, vsite | webrest | |
| 6003 | OperatorSignedOut | Info | An operator signed out. | actorRole, clientIp, username, vsite | webrest | |
| 6101 | OperatorUnknownAccount | Warning | An operator sign in named an account (or a virtual site) that does not exist. | actorRole, clientIp, username, vsite | webrest | username is what the client typed. |
| 6102 | OperatorWrongPassword | Warning | An operator sign in failed because the password is wrong. | actorRole, clientIp, username, vsite | webrest | |
| 6103 | OperatorLocalPasswordRefused | Warning | A password sign in was refused because the account signs in through single sign on only. | actorRole, clientIp, username, vsite | webrest | |
| 6104 | OperatorNotAllowed | Warning | An operator sign in was refused because the account is disabled or not allowed from the client's address. | actorRole, clientIp, username, vsite | webrest | |
| 6105 | AdminNoPermissions | Warning | An Admin sign in was refused because the account has no permissions. | clientIp, username, vsite | webrest | |
| 6106 | OperatorSecondFactorRejected | Warning | An operator's one time code was wrong or reused. | actorRole, clientIp, username, vsite | webrest | Also written when the code is asked to confirm a password change. |
| 6107 | OperatorRecoveryCodeRejected | Warning | An operator's recovery code was wrong or already used. | actorRole, clientIp, username, vsite | webrest | |
| 6108 | OperatorPasskeyRejected | Warning | An operator passkey sign in was rejected. | actorRole, clientIp, username, vsite | webrest | |
| 6109 | OperatorSSONoAccount | Warning | A verified single sign on identity matches no operator account. | actorRole, clientIp, username, vsite | webrest | |
| 6110 | OperatorSSOAmbiguous | Warning | A verified single sign on identity matches more than one operator account, so the sign in was refused. | actorRole, clientIp, username, vsite | webrest | |
| 6111 | OperatorSSOStateInvalid | Warning | An operator single sign on attempt came back with a missing, expired or foreign sign in state. | clientIp | webrest | |
| 6112 | OperatorAccountLocked | Warning | An operator account crossed the failed sign in threshold and is temporarily locked. | username, failures, minutes | webrest | username is the lockout key: sa:<account> or adm:<vsite>:<account>. |
| 6113 | OperatorSignInRefusedLocked | Warning | An operator sign in was refused because the account is temporarily locked. | actorRole, clientIp, username, vsite | webrest | |
| 6120 | OperatorRevokedTokenPresented | Warning | A request carried an operator token that was revoked. | actorRole, clientIp, username, vsite | webrest | Throttled: at most once per token per minute. |
| 6201 | OperatorPasswordChanged | Info | An operator changed their own password. | actor, actorRole, vsite, objectType, objectId, clientIp, method, route | webrest | |
| 6202 | OperatorPasswordSetOnAccount | Info | An operator set the password of another account. | actor, actorRole, vsite, objectType, objectId, clientIp, method, route | webrest | Always accompanied by ObjectUpdated for the same request. |
| 6203 | OperatorPasswordChangeRefused | Warning | An operator's own password change was refused because the current password was wrong. | actorRole, clientIp, username, vsite | webrest | |
| 6204 | OperatorSecondFactorEnrolled | Info | An authenticator was enrolled on an operator account (their own or, by a SuperAdmin, another one). | actor, actorRole, vsite, objectType, objectId, clientIp, method, route | webrest | Always accompanied by ObjectUpdated for the same request. |
| 6205 | OperatorSecondFactorRemoved | Info | The authenticator of an operator account was removed (by its owner or by a SuperAdmin). | actor, actorRole, vsite, objectType, objectId, clientIp, method, route | webrest | Always accompanied by ObjectUpdated for the same request. |
| 6206 | OperatorRecoveryCodesRegenerated | Info | An operator generated a new set of recovery codes. | actor, actorRole, vsite, objectType, objectId, clientIp, method, route | webrest | |
| 6207 | OperatorTrustedDevicesRevoked | Info | An operator revoked trusted devices. | actor, actorRole, vsite, objectType, objectId, clientIp, method, route | webrest | |
| 6208 | OperatorPasskeyEnrolled | Info | An operator enrolled a passkey. | actor, actorRole, vsite, objectType, objectId, clientIp, method, route | webrest | |
| 6209 | OperatorPasskeyDeleted | Info | A passkey was deleted (by its operator, or by an operator managing another account). | actor, actorRole, vsite, objectType, objectId, clientIp, method, route | webrest |
7000: Operator changes and actions
| ID | Name | Level | What happened | Fields | Sources | Notes |
|---|---|---|---|---|---|---|
| 7001 | ObjectCreated | Info | An operator created a configuration object. | actor, actorRole, vsite, objectType, objectId, clientIp, method, route | webrest | objectType names the kind of object (user, vfs, admin, vsite, ...); objectId is the new object's ID. |
| 7002 | ObjectUpdated | Info | An operator changed a configuration object. | actor, actorRole, vsite, objectType, objectId, clientIp, method, route | webrest | |
| 7003 | ObjectDeleted | Info | An operator deleted a configuration object. | actor, actorRole, vsite, objectType, objectId, clientIp, method, route | webrest | |
| 7010 | BackupExported | Info | An operator exported a configuration backup. | actor, actorRole, vsite, objectType, objectId, clientIp, method, route | webrest | |
| 7011 | ConfigurationRestored | Info | An operator restored the configuration from a backup. | actor, actorRole, vsite, objectType, objectId, clientIp, method, route | webrest | |
| 7012 | VSiteStarted | Info | An operator started a virtual site (on every node or on one node). | node, actor, actorRole, vsite, objectType, objectId, clientIp, method, route | webrest | |
| 7013 | VSiteStopped | Info | An operator stopped a virtual site (on every node or on one node). | node, actor, actorRole, vsite, objectType, objectId, clientIp, method, route | webrest | |
| 7014 | VSiteRestarted | Info | An operator restarted a virtual site through the Telegram bot. | node, actor, actorRole, vsite, objectType, objectId, clientIp, method, route | webrest | |
| 7015 | NodeDrainChanged | Info | An operator put a node in drain mode, or took it out. | node, actor, actorRole, vsite, objectType, objectId, clientIp, method, route | webrest | |
| 7020 | SessionsTerminated | Info | An operator terminated client sessions. | actor, actorRole, vsite, objectType, objectId, clientIp, method, route | webrest | |
| 7030 | UpdateRequested | Info | An operator asked for a software update to be applied. | actor, actorRole, vsite, objectType, objectId, clientIp, method, route | webrest | |
| 7031 | UpdateCancelled | Info | An operator cancelled a pending software update. | actor, actorRole, vsite, objectType, objectId, clientIp, method, route | webrest | |
| 7040 | LicenseActivated | Info | An operator activated a license. | actor, actorRole, vsite, objectType, objectId, clientIp, method, route | webrest | |
| 7041 | LicenseDeactivated | Info | An operator deactivated the license. | actor, actorRole, vsite, objectType, objectId, clientIp, method, route | webrest | |
| 7050 | HANodeAdded | Info | An operator added a node to the cluster. | actor, actorRole, vsite, objectType, objectId, clientIp, method, route | webrest | The cluster itself also writes ClusterPeerAdded. |
| 7051 | HANodeRemoved | Info | An operator removed a node from the cluster. | actor, actorRole, vsite, objectType, objectId, clientIp, method, route | webrest | The cluster itself also writes ClusterMemberRemoved. |
| 7052 | HANodeLeft | Info | An operator made this node leave the cluster. | actor, actorRole, vsite, objectType, objectId, clientIp, method, route | webrest | |
| 7053 | HAMaintenance | Info | An operator ran a cluster maintenance action (repair, heal or legacy cleanup). | actor, actorRole, vsite, objectType, objectId, clientIp, method, route | webrest | |
| 7060 | SetupNodeConfigured | Info | The node was configured during initial setup. | actor, actorRole, vsite, objectType, objectId, clientIp, method, route | webrest | |
| 7061 | SetupFirstSuperAdmin | Info | The first SuperAdmin was created during initial setup. | actor, actorRole, vsite, objectType, objectId, clientIp, method, route | webrest | |
| 7062 | SetupJoinedCluster | Info | The node was joined to a cluster during initial setup. | actor, actorRole, vsite, objectType, objectId, clientIp, method, route | webrest | The cluster itself also writes ClusterJoined. |
| 7090 | OperatorActionRefused | Warning | A signed in operator was refused an action (403). | actor, actorRole, vsite, objectType, objectId, clientIp, method, route | webrest | Not written when a more specific event already describes the refusal. |
| 7201 | CLISuperAdminPasswordReset | Warning | A SuperAdmin password was reset from the command line. | actor, objectId | cli | |
| 7202 | CLISecondFactorDisabled | Warning | A SuperAdmin's second factor was disabled from the command line. | actor, objectId | cli | |
| 7203 | CLINodeReset | Warning | The node was reset from the command line, deleting its configuration. | actor | cli | |
| 7204 | CLIDatabaseCredentialRotated | Info | The database credential was rotated from the command line. | actor | cli | |
| 7205 | CLISecretsReencrypted | Info | Every stored secret was encrypted again from the command line. | actor | cli | |
| 7206 | CLIInitializedFromBackup | Warning | The node was initialized from a backup from the command line, replacing its configuration. | actor | cli | |
| 7207 | CLIBackupExported | Info | A backup was exported from the command line. | actor | cli |
8000: High availability cluster
| ID | Name | Level | What happened | Fields | Sources | Notes |
|---|---|---|---|---|---|---|
| 8003 | ClusterJoined | Info | This node joined a cluster. | peer | webrest | |
| 8004 | ClusterPeerAdded | Info | A node was added to the cluster. | peer | webrest | |
| 8005 | ClusterMemberRemoved | Info | A node was removed from the cluster. | peer | webrest | |
| 8006 | ClusterSelfEvicted | Warning | The cluster removed this node. | webrest | ||
| 8010 | ClusterJoinRefused | Warning | A request to join the cluster was refused. | clientIp | webrest | |
| 8011 | ClusterPeerRequestRefused | Warning | A request from a cluster peer was refused (signature, membership or key check). | peer, clientIp | webrest | |
| 8012 | ClusterPeerKeyRefused | Warning | A cluster peer presented a key different from the one on record, and it was refused. | peer | webrest | |
| 8020 | ClusterPeerOffline | Warning | A cluster peer stopped answering. | peer | webrest | |
| 8021 | ClockDrift | Warning | A clock drifted too far from a cluster peer or from network time. | peer | webrest | Written when the condition starts, not on every check. |
9000: Platform health
| ID | Name | Level | What happened | Fields | Sources | Notes |
|---|---|---|---|---|---|---|
| 9001 | CertificateExpiring | Warning | A TLS certificate expires soon. | certificate, daysLeft | webrest, worker | |
| 9002 | CertificateExpired | Error | A TLS certificate in use has expired. | certificate | worker | |
| 9003 | NoUsableCertificate | Error | A TLS listener cannot start because no usable certificate is available. | protocol, listener | worker | |
| 9010 | StorageUnreachable | Warning | The storage behind a virtual file system cannot be reached. | vfs | worker | Throttled: at most once per virtual file system per minute. |
| 9011 | R2FSStorageUnhealthy | Warning | An R2FS! node reports the storage behind a virtual file system unhealthy. | vfs, node | worker | |
| 9012 | R2FSStorageRecovered | Info | An R2FS! node reports the storage behind a virtual file system reachable again. | vfs, node | worker | |
| 9013 | R2FSAgentUnencrypted | Warning | An R2FS! agent attached without encryption. | vfs, node | worker | |
| 9020 | ScriptFailed | Error | An event handler script failed or timed out. | event, script, sessionId, protocol | worker | |
| 9021 | ScriptLoadFailed | Error | An event handler script could not be loaded. | event, script | worker | |
| 9022 | ScriptSkippedBusy | Warning | Asynchronous event handler scripts were skipped because every script slot was busy. | event, script | worker | Throttled: at most once per minute. |
| 9030 | EmailFailed | Warning | A notification email could not be sent. | recipient | webrest, worker | |
| 9031 | EmailQueueFull | Warning | A notification email was dropped because the send queue is full. | webrest, worker | ||
| 9040 | VFSHardQuotaExceeded | Warning | A virtual file system exceeded its hard quota. | vfs | worker | Written once, when the condition is first detected. |
| 9041 | VFSSoftQuotaExceeded | Warning | A virtual file system exceeded its soft quota. | vfs | worker | Written once, when the condition is first detected. |
