windows_event_log_codes

Windows Event Log Codes

Event Identifications for notifications written into windows event logs have changed a lot from previous versions of ScanMail. This change might impact your monitoring efforts. Consult the following table to understand the Windows event logs.

ScanMail Windows Event Log Codes

Event ID

Facility

Type/

Severity

Category

Description

3

Application

Error

None

Alert. ScanMail service did not start successfully.

4

Application

Error

None

Alert. ScanMail service is unavailable.

5

Application

Warning

None

Security risk scan notifica­tion.

6

Application

Warning

None

Attachment blocking noti­fication.

7

Application

Warning

None

Content filtering notifica­tion.

16

Application

Warning

None

Alert. Manual update unsuccessful.

17

Application

Informa­tion

None

Alert. Manual update suc­cessful.

18

Application

Warning

None

Alert. Last update time is older than specified time.

19

Application

Informa­tion

None

Alert. Manual scan suc­cessful.

20

Application

Error

None

Alert. Manual scan unsuc­cessful.

21

Application

Warning

None

Alert. Scan time exceeds specified time.

22

Application

Warning

None

Alert. The disk space on the local drive (volume) of the backup or quarantine directory is less than specified size.

23

Application

Warning

None

Alert. The size of data­base to keep quarantine and logs exceeds speci­fied size.

24

Application

Informa­tion

None

Alert. Scheduled scan successful.

25

Application

Error

None

Alert. Scheduled scan unsuccessful.

32

Application

Error

None

Alert. Scheduled update unsuccessful.

33

Application

Informa­tion

None

Alert. Scheduled update successful.

34

Application

Warning

None

Web reputation notifica­tion.

35

Application

Warning

None

Data Protection notifica­tion

80

Application

Informa­tion

None

Alert. Outbreak Preven­tion Mode started.

82

Application

Informa­tion

None

Alert. Outbreak Preven­tion Mode stopped and configuration restored.

257

Application

Warning

None

Virus/Malware Outbreak Alert.

258

Application

Warning

None

Uncleanable Virus/Mal­ware Outbreak Alert.

259

Application

Warning

None

Blocked attachment Out­break Alert.

260

Application

Warning

None

Spyware/Grayware Out­break Alert.

513

Application

Error

None

Filter loading exception.

514

Application

Error

None

Adapter loading excep­tion.

4097

Application

Warning

None

Alert. The disk space on the local drive of the MS Exchange transaction log is less than specified size.

4098

Application

Warning

None

Alert. The Microsoft Exchange mail store size exceeds specified size.

4099

Application

Warning

None

Alert. The Microsoft Exchange SMTP mes­sages queued continu­ously exceeds the specified number.

4112

Application

Error

None

ScanMail Master Service stopped due to insufficient disk space. Please free up some disk space and restart ScanMail Master Service.

8193

Application

Informa­tion

None

EUQ. Processing manual End User Quarantine maintenance task started.

8194

Application

Informa­tion

None

EUQ. Processing of man­ual End User Quarantine maintenance task ended.

8195

Application

Informa­tion

None

EUQ. Processing of schedule End User Quar­antine maintenance task started.

8196

Application

Informa­tion

None

EUQ. End of processing schedule End User Quar­antine maintenance task.

8197

Application

Informa­tion

None

EUQ. Start to process enable End User Quaran­tine task.

8198

Application

Informa­tion

None

EUQ. End of processing enable End User Quaran­tine task.

8199

Application

Informa­tion

None

EUQ. Start to process dis­able End User Quarantine task.

8200

Application

Informa­tion

None

EUQ. End of processing disable End User Quaran­tine task.

12289

Application

Error

None

The transport scan mod­ule was unable to load the ScanMail transport hook. This could be caused by improper COM registra­tion, missing DLL files, or privilege issues with the hookSMTP.dll. Check if the required files are com­plete, manually register hookSMTP.dll, and restart ScanMail Master Service.

12290

Application

Error

None

The ScanMail transport scan module is unable to send IPC requests to the ScanMail Master service. Check Windows event log for system errors.

12291

Application

Error

None

The transport scan mod­ule is unable to detect ScanMail or it does not have proper permission to access ScanMail related files or registries. Scan­Mail Master Service has not started. Please restart ScanMail Master Service.

12292

Application

Error

None

Another transport scan module may be active. Please check if a trans­port scan module has already been loaded by the Exchange transport service. Another trans­port scan module is run­ning.

12293

Application

Error

None

The ScanMail transport scan module is unable to create a transport agent object. Make sure the ScanMail DLL files are complete.

12294

Application

Warning

None

Transport scan has been disabled and messages have been passed through without being scanned by ScanMail. To enable transport scanning, log on to the ScanMail Manage­ment Console and enable any of the following trans­port level real-time secu­rity risk scan, transport level attachment block­ing, transport level con­tent filtering, or spam prevention.

12545

Application

Error

None

The MCP agent between ScanMail and Control manager stopped unex­pectedly.

20480

Application

Informa­tion

None

Log on/off ScanMail prod­uct console.

20481

Application

Informa­tion

None

ScanMail configuration change.

20482

Application

Informa­tion

None

ScanMail management operation.

28672

Application

Informa­tion

None

Switch security risk scan methods

28673

Application

Warning

None

Smart Scan - Each time File Reputation service was Unavailable.

28675

Application

Informa­tion

None

Smart Scan - Each time File Reputation service was Recovered.

28676

Application

Warning

None

Smart Scan - Each time Web Reputation service was Unavailable.

28677

Application

Informa­tion

None

Smart Scan - Each time Web Reputation service was Recovered.