1.10 ZENworks Audit Universe Objects

1.10.1 ZENworks Audit Summary

  • Count of Critical Events: Number of ZENworks audit critical events generated by ZENworks Administrators through ZCC actions or managed devices.

  • Count of Devices: Number of devices in the zone that have generated ZENworks audit summary events.

  • Count of Events: Number of ZENworks audit events generated by ZENworks Administrators through ZCC actions or managed devices irrespective of event classification.

  • Count of Informational Events: Number of ZENworks audit informational events generated by ZENworks administrators through ZCC actions or managed devices.

  • Count of Initiator: Number of individuals who performed the action. This could be a ZENworks administrator, an end user, a program, or a service.

  • Count of Major Events: Number of ZENworks audit major events generated by ZENworks administrators through ZCC actions or managed devices.

  • Primary Target Object: Name of the primary target object on which, the action was performed. Any object in ZCC it can be device, folder, bundle, policy, admin, role, user, or credential vault.

  • Secondary Target Object: Name of the primary target object on which, the action was performed. Any object in ZCC it can be device, folder, bundle, policy, admin, role, user, or credential vault.

  • Count of Users: Number of users who performed the actions in ZCC.

  • Device Name: Name of the device that generated the events in the zone.

  • Device Role: Role assigned to the device such as, Primary, Satellite or could be content, collection.

  • Email Notification: Status of the email notification.

  • Event Category: Category of the event.

  • Event Classification: Classification of the event.

  • Event Created On: Date on which the event is created.

  • Event Expiry Date: Date on which the event expires.

  • Event Initiator Name: The name of the individual who initiated the event.

  • Initiator Type: The type of initiator.

  • Event Message: The actual message in the event.

  • Event Name: Name of the event. All events of a type will be against that particular event.

  • Event Type: Type of the event.

  • Event ZUID: Unique ID for the event.

  • IP Address: IP address of the device, where ZCC is running, from which the event is generated.

  • Local File Notification: Status of the local file notification. Whether notification is sent or not.

  • Primary Target Object Name: Name of the primary target object.

  • Primary Target Object Type: Type of the primary target object.

  • Secondary Target Object Name: Name of the secondary target object.

  • Secondary Target Object Type: Type of the secondary target object.

  • Session ID: The JSession ID of the ZCC session, from which the event is generated.

  • SNMP Notification: Status of the SNMP notification. Whether notification is sent or not.

  • UDP Notification: Status of the UDP notification. Whether notification is sent or not.

  • User Name: Name of the user.

  • User Type: Type of the user.

1.10.2 ZENworks Change Summary

  • Count of Critical Events: Number of critical events.

  • Count of Devices: Number of devices.

  • Count of Events: Number of events.

  • Count of Informational Events: Number of informational events.

  • Count of Initiator: Number of event initiators.

  • Count of Major Events: Number of major events.

  • Count of Primary Target Object: Number of Primary Target Object.

  • Count of Secondary Target Object: Number of Secondary Target Object.

  • Count of Session ID: Number of session IDs.

  • Count of Users: Number of users.

  • Device Name: Name of the managed device.

  • Device Role: Role of the managed device.

  • Email Notification: Email notification status for change audit events.

  • Event Category: Category of the event.

  • Event Classification: Classification of the event.

  • Event Created On: Date on which the event was created.

  • Event Detail Field: Detailed message of the changes.

  • Event Detail New Value: New value for the event.

  • Event Detail Old Value: Old value for the event

  • Event Expiry Date: Date on which the event expires.

  • Event Initiator Name: Name of the event initiator

  • Event Initiator Type: Type of the event initiator.

  • Event Message: Message for the event

  • Event Name: Name of the event.

  • Event ZUID: Unique ID for the event.

  • IP Address: IP address using which the event was initiated.

  • Local File Notification: Local file notification for Change Audit Events

  • Primary Target Object Name: Name of the Primary Target Object

  • Primary Target Object Type: Type of the Primary Target Object

  • Secondary Target Object Name: Name of the Secondary Target Object.

  • Secondary Target Object Type: Type of the Secondary Target Object.

  • Session ID: Session ID of the event.

  • SNMP Notification: SNMP notification status for Change Audit Event.

  • UDP Notification: UDP notification status for the Change Audit Event.

  • User Name: Name of the user who initiated the event.

  • User Type: Type of the user who initiated the event.

1.10.3 ZENworks Agent Summary

  • Count of Critical Events: Number of critical event.

  • Count of Devices: Number of devices.

  • Count of Events: Number of events.

  • Count of Informational Events: Number of informational events.

  • Count of Initiators: number of initiators.

  • Count of Major Events: Number of major events.

  • Count of Primary Target Object: Number of Primary Target Object.

  • Count of Secondary Target Object: Number of Secondary Target Object.

  • Count of Users: Number of users.

  • Device Name: Name of the managed device.

  • Device Role: Role of the managed device.

  • Email Notification: Email notification status for agent audit events.

  • Event Category: Category of the agent audit event.

  • Event Classification: Classification of the agent audit event.

  • Event Created On: Date on which the agent audit event was created.

  • Event Expiry Date: Date on which the agent audit event expires.

  • Event Initiator Name: Name of the agent audit event initiator.

  • Event Initiator Type: Type of the agent audit event.

  • Event Message: Additional information of the agent audit event.

  • Event Name: Name of the agent audit event.

  • Event ZUID: Unique ID of the agent audit event.

  • Primary Target Object Name: Name of the Primary Target Object.

  • Primary Target Object Type: Type of the Primary Target Object.

  • Secondary Target Object Name: Name of the Secondary Target Object.

  • Secondary Target Object Type: Type of the Secondary Target Object.

  • SNMP Notification: SNMP notification status for agent audit events.

  • UDP Notification: UDP notification status for agent audit events.

  • User Name: Name of the agent audit event initiator.

  • User Type: Type of the agent audit event initiator.

1.10.4 User Management

  • Count of Critical Events: Number of critical events.

  • Count of Devices: Number of devices.

  • Count of Events: Number of events.

  • Count of Informational Events: Number of informational events.

  • Count of Initiators: Number of initiators.

  • Count of Major Events: Number of major events.

  • Count of Primary Target Object: Number of the Primary Target Object.

  • Count of User Login Events: Number of users login.

  • Count of Users: Number of users.

  • Device Name: Name of the device on which the event was initiated.

  • Device Role: Role of the device on which the event was initiated.

  • Email Notification: Email notification status.

  • Event Category: Category of the event.

  • Event Classification: Classification of the event.

  • Event Created On: Date on which the event was created.

  • Event Expiry Date: Date on which the event expires.

  • Event Initiator Name: Name of the event initiator.

  • Event Initiator Type: Type of the event.

  • Event Message: Additional information for the user event.

  • Event Name: Name of the event.

  • Event Status: Status of the event.

  • Event ZUID: Unique ID of the event.

  • Failure Reason: Reason of the event failure.

  • Local User Name: Name of the user who logged into the device.

  • Primary Target Object Name: Name of the Primary Target Object.

  • Primary Target Object Type: Type of the Primary Target Object.

  • Realm: Realm of the event

  • SNMP Notification: SNMP notification status.

  • UDP Notification: UDP notification status.

  • ZENworks User Name: Name of the ZENworks users.

1.10.5 Remote Management

  • Count of Critical Events: Number of critical events.

  • Count of Devices: Number of devices.

  • Count of Events: Number of events.

  • Count of Informational Events: Number of informational events.

  • Count of Initiators: Number of initiators.

  • Count of Major Events: Number of major events.

  • Count of Applications Launched: Number of applications launched.

  • Count of Commands Executed: Number of commands executed.

  • Count of Remote Management Session ID: Number of remote management session IDs.

  • Device Name: Name of the managed device

  • Device Role: Role of the managed device.

  • Event Classification: Classification of the event.

  • Event Created On: Date on which the event was created.

  • Event Expiry Date: Date on which the event expires.

  • Event Initiator Name: Name of the event initiator.

  • Event Initiator Type: Type of the event initiator.

  • Event Message: Additional information of the event.

  • Event Name: Name of the event.

  • Event ZUID: Unique ID assigned for the event.

  • Primary Target Object Name: Name of the Primary Target Object.

  • Primary Target Object Type: Type of the Primary Object Type.

  • Email Notification: Email notification status of the event.

  • SNMP Notification: SNMP notification status of the event.

  • UDP Notification: UDP notification status of the event.

  • Asked User Permission: Received permission from the user to remote control the device.

  • Authentication Mode: Password or rights mode of authentication.

  • Collaboration ID: Identification number created when multiple remote operators join a remote session.

  • Console Device: Device from which the remote operations was performed.

  • Password Mode: Authentication with password mode.

  • Remote Management Session ID: A unique identification number used to connect one or more events of the same remote session.

  • Remote Operation: Remotely performed operation.

  • Session End Time: End time of the remote session.

  • Session Start Time: Start time of the remote session.

  • Session Status: Status of the remote session.

  • Termination Reason: Reason for disconnection of a remote session.

  • Action Performed: Action performed on the managed device after abnormal termination of a remote session.

  • Remote Operator: The operator who performed the remote operation.

  • Application: The application launched during remote diagnostic session.

  • Application Launched Date: The date and time on which the application is launched.

  • Application Path: The path in which the executable file of the application is stored.

  • Agent Initiated Connection: Connection started by a managed device.

  • Authentication Failure Reason: The reason for failure of authentication of a remote session.

  • Authentication Date: Time and date on which remote operator is authenticated.

  • Command: The command executed during remote session.

  • Command Executed Date: The date and time of command execution.

  • Execution Status: The status of command execution.

  • Count of Files Transferred: Number of files transferred.

  • Count of Files Transferred Successfully: Number of files that were transferred successfully.

  • Count of Files Transferred Unsuccessfully: Number of files that were not transferred.

  • Date Modified: Date on which a file is modified.

  • Date Transferred: The date on which the file is transferred.

  • File Name: Name of the file transferred.

  • File Operation: Operation performed on the files.

  • File Path: The original path in which the remotely transferred file was stored.

  • File Size: Size of the remotely transferred file.

  • Status: Status of file operation.

  • Type: Type of the file that was remotely transferred.

  • Local User Name: Name of the user.

  • Relam: Name of the realm.

  • ZENworks User Name: Name of the ZENworks users.

1.10.6 ZENworks Endpoint Security Management

  • Count of Critical Events: Number of critical events.

  • Count of Informational Events: Number of informational events.

  • Count of Major: Number of major events.

  • Count of Initiators Events: Number of event initiators.

  • Count of Devices: Number of devices.

  • Count of Events: Number of events.

  • Count of Applications Launched: Number of applications launched.

  • Count of Commands Executed: Number of commands executed.

  • Count of Remote Management Session ID: Number of remote management session ID.

  • Device Name: Name of the managed device.

  • Device Role: Role of the managed device.

  • Event Classification: Classification of the event.

  • Event Created On: Date on which the event was created.

  • Event Expiry Date: Date on which the event expires.

  • Event Initiator Name: Name of the event initiator.

  • Event Initiator Type: Type of the event initiator.

  • Event Message: Additional information on the event.

  • Event Name: Name of the event.

  • Event ZUID: Unique ID for the event.

  • Primary Target Object Name: Name of the Primary Target Object.

  • Primary Target Object Type: Type of the Primary Target Object.

  • Email Notification: Email notification status of the event.

  • SNMP Notification: SNMP notification status of the event.

  • UDP Notification: UDP notification status of the event.

  • Boot ID: Boot ID of the device.

  • Load ID: Load ID of the device.

  • Effective Policy ID: Effective policy ID.

  • Local User Name: Name of the local user.

  • Machine Domain: Domain of the machine.

  • Security Location ID: Security location ID.

  • User Domain: Name of the user domain.

  • ZENworks User Name: Name of the ZENworks user.

  • Zone ID: ID of the zone.

  • Domain: Domain name.

  • Is Windows Administrator: Is user Windows administrator.

  • Number of Files Copied: Number of files copied.

  • Terminal ID: Terminal ID of the device.

  • ZENworks Terminal ID: ZENworks terminal ID

  • Storage Device Name: Name of the storage device.

  • Serial Number: Serial number of the device.

  • Storage Device Type: Type of storage device.

  • Bytes Read: Number of bytes read.

  • File Size: File size.

  • Bytes Written: Bytes written on the storage device.

  • File Name: Name of the file.

  • Last Accessed Date: Date on which the file was last accessed.

  • Copied Date: Date on which the file was copied.

  • File Path: Path of the file.

  • Internal Name: Internal name of the file.

  • Load Path: Load path of the file.

  • Process Name: Name of the process.

  • Session ID: Session ID that was used.

  • Session User Name: Name of the session user.

  • Windows Session Domain: Domain of the session.

  • Windows Session ID: Windows session ID.