| DisplayName | ID | Target | Category | Enabled | Alert Generate |
| Root 密碼 SSH 驗證警示規則 | Microsoft.Linux.Universal.LogFile.Syslog.Root.SSHAuth.Password.Alert | Microsoft.Linux.Universal.Computer | EventCollection | False | True |
| SSH 驗證失敗警示規則 | Microsoft.Linux.Universal.LogFile.Syslog.SSHAuth.PAM.Root.Failure.Alert | Microsoft.Linux.Universal.Computer | EventCollection | False | True |
| SU 命令失敗警示規則 | Microsoft.Linux.Universal.LogFile.Syslog.SU.Command.Root.Failure.Alert | Microsoft.Linux.Universal.Computer | EventCollection | False | True |
| SU 命令成功警示規則 | Microsoft.Linux.Universal.LogFile.Syslog.SU.Command.Root.Success.Alert | Microsoft.Linux.Universal.Computer | EventCollection | False | True |
| Logical Disk Bytes/sec (Universal Linux) | Microsoft.Linux.Universal.LogicalDisk.DiskBytesPerSecond.Collection | Microsoft.Linux.Universal.LogicalDisk | PerformanceCollection | True | False |
| Disk Read Bytes/sec (Universal Linux) | Microsoft.Linux.Universal.LogicalDisk.DiskReadBytesPerSecond.Collection | Microsoft.Linux.Universal.LogicalDisk | PerformanceCollection | True | False |
| Disk Reads/sec (Universal Linux) | Microsoft.Linux.Universal.LogicalDisk.DiskReadsPerSecond.Collection | Microsoft.Linux.Universal.LogicalDisk | PerformanceCollection | True | False |
| Disk Transfers/sec (Universal Linux) | Microsoft.Linux.Universal.LogicalDisk.DiskTransfersPerSecond.Collection | Microsoft.Linux.Universal.LogicalDisk | PerformanceCollection | True | False |
| Disk Write Bytes/sec (Universal Linux) | Microsoft.Linux.Universal.LogicalDisk.DiskWriteBytesPerSecond.Collection | Microsoft.Linux.Universal.LogicalDisk | PerformanceCollection | True | False |
| Disk Writes/sec (Universal Linux) | Microsoft.Linux.Universal.LogicalDisk.DiskWritesPerSecond.Collection | Microsoft.Linux.Universal.LogicalDisk | PerformanceCollection | True | False |
| Free Megabytes (Universal Linux) | Microsoft.Linux.Universal.LogicalDisk.FreeMegabytes.Collection | Microsoft.Linux.Universal.LogicalDisk | PerformanceCollection | True | False |
| \% Free Inodes (Universal Linux) | Microsoft.Linux.Universal.LogicalDisk.PercentFreeInodes.Collection | Microsoft.Linux.Universal.LogicalDisk | PerformanceCollection | False | False |
| \% Free Space (Universal Linux) | Microsoft.Linux.Universal.LogicalDisk.PercentFreeSpace.Collection | Microsoft.Linux.Universal.LogicalDisk | PerformanceCollection | False | False |
| \% Used Inodes (Universal Linux) | Microsoft.Linux.Universal.LogicalDisk.PercentUsedInodes.Collection | Microsoft.Linux.Universal.LogicalDisk | PerformanceCollection | True | False |
| \% Used Space (Universal Linux) | Microsoft.Linux.Universal.LogicalDisk.PercentUsedSpace.Collection | Microsoft.Linux.Universal.LogicalDisk | PerformanceCollection | True | False |
| Used Megabytes (Universal Linux) | Microsoft.Linux.Universal.LogicalDisk.UsedMegabyte.Collection | Microsoft.Linux.Universal.LogicalDisk | PerformanceCollection | True | False |
| Byte Received/Sec (Universal Linux) | Microsoft.Linux.Universal.NetworkAdapter.BytesReceivedPerSec.Collection | Microsoft.Linux.Universal.NetworkAdapter | PerformanceCollection | True | False |
| Byte Sent/Sec (Universal Linux) | Microsoft.Linux.Universal.NetworkAdapter.BytesSentPerSec.Collection | Microsoft.Linux.Universal.NetworkAdapter | PerformanceCollection | True | False |
| Bytes Total/Sec (Universal Linux) | Microsoft.Linux.Universal.NetworkAdapter.BytesTotalSec.Collection | Microsoft.Linux.Universal.NetworkAdapter | PerformanceCollection | True | False |
| Available MBytes Memory (Universal Linux) | Microsoft.Linux.Universal.OperatingSystem.AvailableMBytes.Collection | Microsoft.Linux.Universal.OperatingSystem | PerformanceCollection | True | False |
| Available MBytes Swap (Universal Linux) | Microsoft.Linux.Universal.OperatingSystem.AvailableMBytesSwap.Collection | Microsoft.Linux.Universal.OperatingSystem | PerformanceCollection | True | False |
| Page Reads/sec (Universal Linux) | Microsoft.Linux.Universal.OperatingSystem.PageReadsPerSecond.Collection | Microsoft.Linux.Universal.OperatingSystem | PerformanceCollection | True | False |
| Pages/sec (Universal Linux) | Microsoft.Linux.Universal.OperatingSystem.PagesPerSecond.Collection | Microsoft.Linux.Universal.OperatingSystem | PerformanceCollection | True | False |
| Page Writes/sec (Universal Linux) | Microsoft.Linux.Universal.OperatingSystem.PageWritesPerSecond.Collection | Microsoft.Linux.Universal.OperatingSystem | PerformanceCollection | True | False |
| \% Available Memory (Universal Linux) | Microsoft.Linux.Universal.OperatingSystem.PercentAvailableMemory.Collection | Microsoft.Linux.Universal.OperatingSystem | PerformanceCollection | True | False |
| \% Available Swap Space (Universal Linux) | Microsoft.Linux.Universal.OperatingSystem.PercentAvailableSwap.Collection | Microsoft.Linux.Universal.OperatingSystem | PerformanceCollection | True | False |
| \% Used Memory (Universal Linux) | Microsoft.Linux.Universal.OperatingSystem.PercentUsedMemory.Collection | Microsoft.Linux.Universal.OperatingSystem | PerformanceCollection | True | False |
| \% Used Swap Space (Universal Linux) | Microsoft.Linux.Universal.OperatingSystem.PercentUsedSwapSpace.Collection | Microsoft.Linux.Universal.OperatingSystem | PerformanceCollection | True | False |
| Total Processor \% DPC Time (Universal Linux) | Microsoft.Linux.Universal.OperatingSystem.TotalPercentDPCTime.Collection | Microsoft.Linux.Universal.OperatingSystem | PerformanceCollection | True | False |
| Total Processor \% Idle Time (Universal Linux) | Microsoft.Linux.Universal.OperatingSystem.TotalPercentIdleTime.Collection | Microsoft.Linux.Universal.OperatingSystem | PerformanceCollection | True | False |
| Total Processor \% Interrupt Time (Universal Linux) | Microsoft.Linux.Universal.OperatingSystem.TotalPercentInterruptTime.Collection | Microsoft.Linux.Universal.OperatingSystem | PerformanceCollection | True | False |
| Total Processor \% IO Wait Time (Universal Linux) | Microsoft.Linux.Universal.OperatingSystem.TotalPercentIOWaitTime.Collection | Microsoft.Linux.Universal.OperatingSystem | PerformanceCollection | True | False |
| Total Processor \% Nice Time (Universal Linux) | Microsoft.Linux.Universal.OperatingSystem.TotalPercentNiceTime.Collection | Microsoft.Linux.Universal.OperatingSystem | PerformanceCollection | True | False |
| Total Processor \% Privileged Time (Universal Linux) | Microsoft.Linux.Universal.OperatingSystem.TotalPercentPrivilegedTime.Collection | Microsoft.Linux.Universal.OperatingSystem | PerformanceCollection | True | False |
| Total Processor \% Processor Time (Universal Linux) | Microsoft.Linux.Universal.OperatingSystem.TotalPercentProcessorTime.Collection | Microsoft.Linux.Universal.OperatingSystem | PerformanceCollection | True | False |
| Total Processor \% User Time (Universal Linux) | Microsoft.Linux.Universal.OperatingSystem.TotalPercentUserTime.Collection | Microsoft.Linux.Universal.OperatingSystem | PerformanceCollection | True | False |
| Used Swap MBytes (Universal Linux) | Microsoft.Linux.Universal.OperatingSystem.UsedMBytesSwap.Collection | Microsoft.Linux.Universal.OperatingSystem | PerformanceCollection | True | False |
| Used Memory MBytes (Universal Linux) | Microsoft.Linux.Universal.OperatingSystem.UsedMemoryMBytes.Collection | Microsoft.Linux.Universal.OperatingSystem | PerformanceCollection | True | False |
| Avg.Disk sec/Read (Universal Linux) | Microsoft.Linux.Universal.PhysicalDisk.AverageDiskReadTime.Collection | Microsoft.Linux.Universal.PhysicalDisk | PerformanceCollection | True | False |
| Avg.Disk sec/Transfer (Universal Linux) | Microsoft.Linux.Universal.PhysicalDisk.AverageDiskTransferTime.Collection | Microsoft.Linux.Universal.PhysicalDisk | PerformanceCollection | True | False |
| Avg.Disk sec/Write (Universal Linux) | Microsoft.Linux.Universal.PhysicalDisk.AverageDiskWriteTime.Collection | Microsoft.Linux.Universal.PhysicalDisk | PerformanceCollection | True | False |
| Physical Disk Bytes/sec (Universal Linux) | Microsoft.Linux.Universal.PhysicalDisk.DiskBytesPerSecond.Collection | Microsoft.Linux.Universal.PhysicalDisk | PerformanceCollection | True | False |
| Processor \% Idle Time (Universal Linux) | Microsoft.Linux.Universal.Processor.PercentIdleTime.Collection | Microsoft.Linux.Universal.Processor | PerformanceCollection | True | False |
| Processor \% Nice Time (Universal Linux) | Microsoft.Linux.Universal.Processor.PercentNiceTime.Collection | Microsoft.Linux.Universal.Processor | PerformanceCollection | True | False |
| Processor \% Privileged Time (Universal Linux) | Microsoft.Linux.Universal.Processor.PercentPrivilegedTime.Collection | Microsoft.Linux.Universal.Processor | PerformanceCollection | True | False |
| Processor \% Time (Universal Linux) | Microsoft.Linux.Universal.Processor.PercentProcessorTime.Collection | Microsoft.Linux.Universal.Processor | PerformanceCollection | True | False |
| Processor \% User Time (Universal Linux) | Microsoft.Linux.Universal.Processor.PercentUserTime.Collection | Microsoft.Linux.Universal.Processor | PerformanceCollection | True | False |
| Processor \% DPC Time (Universal Linux) | Microsoft.Linux.Universal.Processor.TotalPercentDPCTime.Collection | Microsoft.Linux.Universal.Processor | PerformanceCollection | True | False |
| Processor \% Interrupt Time (Universal Linux) | Microsoft.Linux.Universal.Processor.TotalPercentInterruptTime.Collection | Microsoft.Linux.Universal.Processor | PerformanceCollection | True | False |
| Processor \% IO Time (Universal Linux) | Microsoft.Linux.Universal.Processor.TotalPercentIOWaitTime.Collection | Microsoft.Linux.Universal.Processor | PerformanceCollection | True | False |