All Rules in Microsoft.ACS.Linux.SLES.10 Management Pack

 DisplayNameDescriptionIDTargetCategoryEnabledInstance NameCounter NameFrequencyEvent_IDEvent SourceAlert GenerateAlert SeverityAlert PriorityRemotableEvent Log
Microsoft.ACS.Linux.SLES.10.Adding.GroupAdding Group (SUSE Linux Enterprise Server 10)Rule to collect events for adding a new groupMicrosoft.ACS.Linux.SLES.10.Adding.GroupMicrosoft.ACS.Linux.SLES.10.ACSEndPointEventCollectionTrue00FalseTrue
Microsoft.ACS.Linux.SLES.10.Adding.UserAdding User (SUSE Linux Enterprise Server 10)Rule to collect events for adding a new userMicrosoft.ACS.Linux.SLES.10.Adding.UserMicrosoft.ACS.Linux.SLES.10.ACSEndPointEventCollectionTrue00FalseTrue
Microsoft.ACS.Linux.SLES.10.Adding.User.To.GroupAdding User to Group (SUSE Linux Enterprise Server 10)Rule to collect events for adding a user to a groupMicrosoft.ACS.Linux.SLES.10.Adding.User.To.GroupMicrosoft.ACS.Linux.SLES.10.ACSEndPointEventCollectionTrue00FalseTrue
Microsoft.ACS.Linux.SLES.10.Console.FailedFailed Console Login (SUSE Linux Enterprise Server 10)Rule to collect events for failed console login eventsMicrosoft.ACS.Linux.SLES.10.Console.FailedMicrosoft.ACS.Linux.SLES.10.ACSEndPointEventCollectionTrue00FalseTrue
Microsoft.ACS.Linux.SLES.10.Console.InvalidInvalid Console Login (SUSE Linux Enterprise Server 10)Rule to collect events for invalid console login eventsMicrosoft.ACS.Linux.SLES.10.Console.InvalidMicrosoft.ACS.Linux.SLES.10.ACSEndPointEventCollectionTrue00FalseTrue
Microsoft.ACS.Linux.SLES.10.Deleting.GroupDeleting Group (SUSE Linux Enterprise Server 10)Rule to collect events for deleting a groupMicrosoft.ACS.Linux.SLES.10.Deleting.GroupMicrosoft.ACS.Linux.SLES.10.ACSEndPointEventCollectionTrue00FalseTrue
Microsoft.ACS.Linux.SLES.10.Deleting.UserDeleting User (SUSE Linux Enterprise Server 10)Rule to collect events for deleting a userMicrosoft.ACS.Linux.SLES.10.Deleting.UserMicrosoft.ACS.Linux.SLES.10.ACSEndPointEventCollectionTrue00FalseTrue
Microsoft.ACS.Linux.SLES.10.Deleting.User.From.GroupDeleting User from Group (SUSE Linux Enterprise Server 10)Rule to collect events for deleting a user from a groupMicrosoft.ACS.Linux.SLES.10.Deleting.User.From.GroupMicrosoft.ACS.Linux.SLES.10.ACSEndPointEventCollectionTrue00FalseTrue
Microsoft.ACS.Linux.SLES.10.Password.Change.FailedFailed Password Change (SUSE Linux Enterprise Server 10)Rule to collect events for failed password changeMicrosoft.ACS.Linux.SLES.10.Password.Change.FailedMicrosoft.ACS.Linux.SLES.10.ACSEndPointEventCollectionTrue00FalseTrue
Microsoft.ACS.Linux.SLES.10.Password.Change.From.Root.SucceededSuccessful Password Change (SUSE Linux Enterprise Server 10)Rule to collect events for successful password change from root userMicrosoft.ACS.Linux.SLES.10.Password.Change.From.Root.SucceededMicrosoft.ACS.Linux.SLES.10.ACSEndPointEventCollectionTrue00FalseTrue
Microsoft.ACS.Linux.SLES.10.Password.Change.From.User.SucceededSuccessful Password Change (SUSE Linux Enterprise Server 10)Rule to collect events for successful password change from non-root userMicrosoft.ACS.Linux.SLES.10.Password.Change.From.User.SucceededMicrosoft.ACS.Linux.SLES.10.ACSEndPointEventCollectionTrue00FalseTrue
Microsoft.ACS.Linux.SLES.10.Password.Change.Maximum.TriesMaximum Tried Password Change (SUSE Linux Enterprise Server 10)Rule to collect events for maximum number of tries to change passwordMicrosoft.ACS.Linux.SLES.10.Password.Change.Maximum.TriesMicrosoft.ACS.Linux.SLES.10.ACSEndPointEventCollectionTrue00FalseTrue
Microsoft.ACS.Linux.SLES.10.Ssh.FailedFailed ssh login (SUSE Linux Enterprise Server 10)Rule to collect events for failed ssh loginMicrosoft.ACS.Linux.SLES.10.Ssh.FailedMicrosoft.ACS.Linux.SLES.10.ACSEndPointEventCollectionTrue00FalseTrue
Microsoft.ACS.Linux.SLES.10.Ssh.InvalidInvalid ssh login (SUSE Linux Enterprise Server 10)Rule to collect events for invalid ssh loginMicrosoft.ACS.Linux.SLES.10.Ssh.InvalidMicrosoft.ACS.Linux.SLES.10.ACSEndPointEventCollectionTrue00FalseTrue
Microsoft.ACS.Linux.SLES.10.Ssh.SucceededSuccessful ssh login (SUSE Linux Enterprise Server 10)Rule to collect events for successful ssh loginMicrosoft.ACS.Linux.SLES.10.Ssh.SucceededMicrosoft.ACS.Linux.SLES.10.ACSEndPointEventCollectionTrue00FalseTrue
Microsoft.ACS.Linux.SLES.10.Su.FailedFailed su (SUSE Linux Enterprise Server 10)Rule to collect events for failed call to suMicrosoft.ACS.Linux.SLES.10.Su.FailedMicrosoft.ACS.Linux.SLES.10.ACSEndPointEventCollectionTrue00FalseTrue
Microsoft.ACS.Linux.SLES.10.Su.SucceededSuccessful su (SUSE Linux Enterprise Server 10)Rule to collect events for successful call to suMicrosoft.ACS.Linux.SLES.10.Su.SucceededMicrosoft.ACS.Linux.SLES.10.ACSEndPointEventCollectionTrue00FalseTrue
Microsoft.ACS.Linux.SLES.10.Sudo.FailedFailed sudo (SUSE Linux Enterprise Server 10)Rule to collect events for bad password call to sudoMicrosoft.ACS.Linux.SLES.10.Sudo.FailedMicrosoft.ACS.Linux.SLES.10.ACSEndPointEventCollectionTrue00FalseTrue
Microsoft.ACS.Linux.SLES.10.Sudo.InvalidInvalid sudo (SUSE Linux Enterprise Server 10)Rule to collect events for no privileges for sudo operationsMicrosoft.ACS.Linux.SLES.10.Sudo.InvalidMicrosoft.ACS.Linux.SLES.10.ACSEndPointEventCollectionTrue00FalseTrue
Microsoft.ACS.Linux.SLES.10.Sudo.SucceededSuccessful sudo (SUSE Linux Enterprise Server 10)Rule to collect events for successful call to sudoMicrosoft.ACS.Linux.SLES.10.Sudo.SucceededMicrosoft.ACS.Linux.SLES.10.ACSEndPointEventCollectionTrue00FalseTrue