All Rules in Microsoft.ACS.Linux.RHEL.4 Management Pack

 DisplayNameDescriptionIDTargetCategoryEnabledInstance NameCounter NameFrequencyEvent_IDEvent SourceAlert GenerateAlert SeverityAlert PriorityRemotableEvent Log
Microsoft.ACS.Linux.RHEL.4.Adding.GroupAdding Group (Red Hat Enterprise Linux Server 4)Rule to collect events for adding a new groupMicrosoft.ACS.Linux.RHEL.4.Adding.GroupMicrosoft.ACS.Linux.RHEL.4.ACSEndPointEventCollectionTrue00FalseTrue
Microsoft.ACS.Linux.RHEL.4.Adding.UserAdding User (Red Hat Enterprise Linux Server 4)Rule to collect events for adding a new userMicrosoft.ACS.Linux.RHEL.4.Adding.UserMicrosoft.ACS.Linux.RHEL.4.ACSEndPointEventCollectionTrue00FalseTrue
Microsoft.ACS.Linux.RHEL.4.Adding.User.To.GroupAdding User to Group (Red Hat Enterprise Linux Server 4)Rule to collect events for adding a user to a groupMicrosoft.ACS.Linux.RHEL.4.Adding.User.To.GroupMicrosoft.ACS.Linux.RHEL.4.ACSEndPointEventCollectionTrue00FalseTrue
Microsoft.ACS.Linux.RHEL.4.Console.Login.FailedFailed Console Login (Red Hat Enterprise Linux Server 4)Rule to collect events for failed console loginMicrosoft.ACS.Linux.RHEL.4.Console.Login.FailedMicrosoft.ACS.Linux.RHEL.4.ACSEndPointEventCollectionTrue00FalseTrue
Microsoft.ACS.Linux.RHEL.4.Console.Login.SucceededSuccessful Console Login (Red Hat Enterprise Linux Server 4)Rule to collect events for successful console loginMicrosoft.ACS.Linux.RHEL.4.Console.Login.SucceededMicrosoft.ACS.Linux.RHEL.4.ACSEndPointEventCollectionTrue00FalseTrue
Microsoft.ACS.Linux.RHEL.4.Deleting.GroupDeleting Group (Red Hat Enterprise Linux Server 4)Rule to collect events for deleting a groupMicrosoft.ACS.Linux.RHEL.4.Deleting.GroupMicrosoft.ACS.Linux.RHEL.4.ACSEndPointEventCollectionTrue00FalseTrue
Microsoft.ACS.Linux.RHEL.4.Deleting.UserDeleting User (Red Hat Enterprise Linux Server 4)Rule to collect events for deleting a userMicrosoft.ACS.Linux.RHEL.4.Deleting.UserMicrosoft.ACS.Linux.RHEL.4.ACSEndPointEventCollectionTrue00FalseTrue
Microsoft.ACS.Linux.RHEL.4.Deleting.User.From.GroupDeleting User from Group (Red Hat Enterprise Linux Server 4)Rule to collect events for deleting a user from a groupMicrosoft.ACS.Linux.RHEL.4.Deleting.User.From.GroupMicrosoft.ACS.Linux.RHEL.4.ACSEndPointEventCollectionTrue00FalseTrue
Microsoft.ACS.Linux.RHEL.4.Password.Change.FailedFailed Password Change (Red Hat Enterprise Linux Server 4)Rule to collect events for failed password changeMicrosoft.ACS.Linux.RHEL.4.Password.Change.FailedMicrosoft.ACS.Linux.RHEL.4.ACSEndPointEventCollectionTrue00FalseTrue
Microsoft.ACS.Linux.RHEL.4.Password.Change.SucceededSuccessful Password Change (Red Hat Enterprise Linux Server 4)Rule to collect events for successful password changeMicrosoft.ACS.Linux.RHEL.4.Password.Change.SucceededMicrosoft.ACS.Linux.RHEL.4.ACSEndPointEventCollectionTrue00FalseTrue
Microsoft.ACS.Linux.RHEL.4.Ssh.FailedFailed ssh login (Red Hat Enterprise Linux Server 4)Rule to collect events for failed ssh loginMicrosoft.ACS.Linux.RHEL.4.Ssh.FailedMicrosoft.ACS.Linux.RHEL.4.ACSEndPointEventCollectionTrue00FalseTrue
Microsoft.ACS.Linux.RHEL.4.Ssh.SucceededSuccessful ssh login (Red Hat Enterprise Linux Server 4)Rule to collect events for successful ssh loginMicrosoft.ACS.Linux.RHEL.4.Ssh.SucceededMicrosoft.ACS.Linux.RHEL.4.ACSEndPointEventCollectionTrue00FalseTrue
Microsoft.ACS.Linux.RHEL.4.Su.FailedFailed su (Red Hat Enterprise Linux Server 4)Rule to collect events for failed call to suMicrosoft.ACS.Linux.RHEL.4.Su.FailedMicrosoft.ACS.Linux.RHEL.4.ACSEndPointEventCollectionTrue00FalseTrue
Microsoft.ACS.Linux.RHEL.4.Su.SucceededSuccessful su (Red Hat Enterprise Linux Server 4)Rule to collect events for successful call to suMicrosoft.ACS.Linux.RHEL.4.Su.SucceededMicrosoft.ACS.Linux.RHEL.4.ACSEndPointEventCollectionTrue00FalseTrue
Microsoft.ACS.Linux.RHEL.4.Sudo.FailedFailed sudo (Red Hat Enterprise Linux Server 4)Rule to collect events for failed call to sudoMicrosoft.ACS.Linux.RHEL.4.Sudo.FailedMicrosoft.ACS.Linux.RHEL.4.ACSEndPointEventCollectionTrue00FalseTrue
Microsoft.ACS.Linux.RHEL.4.Sudo.InvalidInvalid sudo (Red Hat Enterprise Linux Server 4)Rule to collect events for invalid call to sudoMicrosoft.ACS.Linux.RHEL.4.Sudo.InvalidMicrosoft.ACS.Linux.RHEL.4.ACSEndPointEventCollectionTrue00FalseTrue
Microsoft.ACS.Linux.RHEL.4.Sudo.SucceededSuccessful sudo (Red Hat Enterprise Linux Server 4)Rule to collect events for successful call to sudoMicrosoft.ACS.Linux.RHEL.4.Sudo.SucceededMicrosoft.ACS.Linux.RHEL.4.ACSEndPointEventCollectionTrue00FalseTrue