The Tags data column contains "tags" for events related to applications, endpoints, policies, and servers. To learn about tags and their meanings, see the following table:
Tag |
Description |
Log Types |
---|---|---|
application-start |
Application start explicitly allowed or blocked by policy |
|
fallback-action |
Application start passively allowed because of missing rule information or an error collecting rule or application information |
|
file-access |
Application access explicitly allowed or blocked by policy |
|
inventory |
Application included in endpoint inventory |
|
log-only |
Application start or access tracked but no actions applied because log-only mode is enabled |
|
lockdown-action |
Application start or access blocked because the application was added to the endpoint after a Lockdown rule was applied |
|
multiuser-rule-conflict-action |
Application or child-process start or access blocked by the policy of another logged on user. |
|
no-connection-to-server-action |
Application start or access blocked because the application was not explicitly allowed by the policy and the agent is unable to connect to the server to determine if the application should be allowed as matching a Certified Safe Software List package |
|
rule-action |
Application start explicitly allowed or blocked by Allow or Block rule |
|
safe-match |
Application exactly matches its Certified Safe Software List package |
|
safe-match-loose |
Application in Certified Safe Software List, but not as part of its typical application package |
|
safe-unchecked |
Application pending look-up in Certified Safe Software List |
|
safe-unknown |
Application does not match any Certified Safe Software List package |
|
safe-version-<version> For example, "safe-version-01.192" |
Application evaluated against this Certified Safe Software version |
|
trust-level-medium |
Application explicitly allowed that has a Trusted Source level of Medium |
|
trust-level-high |
Application explicitly allowed that has a Trusted Source level of High |
|
trust-level-very-high |
Application explicitly allowed that has a Trusted Source level of Very High |
|
trusted-source-permanent-action |
Application's child-process temporarily allowed by a Trusted Source level of Medium |
|
trusted-source-temporary-action |
Application's child-process permanently allowed by a Trusted Source level of High or Very High |
|