All Rules in Microsoft.ACS.Linux.SLES.9 Management Pack

 DisplayNameDescriptionIDTargetCategoryEnabledInstance NameCounter NameFrequencyEvent_IDEvent SourceAlert GenerateAlert SeverityAlert PriorityRemotableEvent Log
Microsoft.ACS.Linux.SLES.9.Adding.GroupAdding Group (SUSE Linux Enterprise Server 9)Rule to collect events for adding a new groupMicrosoft.ACS.Linux.SLES.9.Adding.GroupMicrosoft.ACS.Linux.SLES.9.ACSEndPointEventCollectionTrue00FalseTrue
Microsoft.ACS.Linux.SLES.9.Adding.UserAdding User (SUSE Linux Enterprise Server 9)Rule to collect events for adding a new userMicrosoft.ACS.Linux.SLES.9.Adding.UserMicrosoft.ACS.Linux.SLES.9.ACSEndPointEventCollectionTrue00FalseTrue
Microsoft.ACS.Linux.SLES.9.Console.FailedFailed Console Login (SUSE Linux Enterprise Server 9)Rule to collect events for failed console login eventsMicrosoft.ACS.Linux.SLES.9.Console.FailedMicrosoft.ACS.Linux.SLES.9.ACSEndPointEventCollectionTrue00FalseTrue
Microsoft.ACS.Linux.SLES.9.Console.InvalidInvalid Console Login (SUSE Linux Enterprise Server 9)Rule to collect events for invalid console login eventsMicrosoft.ACS.Linux.SLES.9.Console.InvalidMicrosoft.ACS.Linux.SLES.9.ACSEndPointEventCollectionTrue00FalseTrue
Microsoft.ACS.Linux.SLES.9.Deleting.UserDeleting User (SUSE Linux Enterprise Server 9)Rule to collect events for deleting a userMicrosoft.ACS.Linux.SLES.9.Deleting.UserMicrosoft.ACS.Linux.SLES.9.ACSEndPointEventCollectionTrue00FalseTrue
Microsoft.ACS.Linux.SLES.9.Password.Change.FailedFailed Password Change (SUSE Linux Enterprise Server 9)Rule to collect events for failed password changeMicrosoft.ACS.Linux.SLES.9.Password.Change.FailedMicrosoft.ACS.Linux.SLES.9.ACSEndPointEventCollectionTrue00FalseTrue
Microsoft.ACS.Linux.SLES.9.Password.Change.Maximum.TriesMaximum Tried Password Change (SUSE Linux Enterprise Server 9)Rule to collect events for maximum number of tries to change passwordMicrosoft.ACS.Linux.SLES.9.Password.Change.Maximum.TriesMicrosoft.ACS.Linux.SLES.9.ACSEndPointEventCollectionTrue00FalseTrue
Microsoft.ACS.Linux.SLES.9.Ssh.FailedFailed ssh login (SUSE Linux Enterprise Server 9)Rule to collect events for failed ssh loginMicrosoft.ACS.Linux.SLES.9.Ssh.FailedMicrosoft.ACS.Linux.SLES.9.ACSEndPointEventCollectionTrue00FalseTrue
Microsoft.ACS.Linux.SLES.9.Ssh.InvalidInvalid ssh login (SUSE Linux Enterprise Server 9)Rule to collect events for invalid ssh loginMicrosoft.ACS.Linux.SLES.9.Ssh.InvalidMicrosoft.ACS.Linux.SLES.9.ACSEndPointEventCollectionTrue00FalseTrue
Microsoft.ACS.Linux.SLES.9.Ssh.SucceededSuccessful ssh login (SUSE Linux Enterprise Server 9)Rule to collect events for successful ssh loginMicrosoft.ACS.Linux.SLES.9.Ssh.SucceededMicrosoft.ACS.Linux.SLES.9.ACSEndPointEventCollectionTrue00FalseTrue
Microsoft.ACS.Linux.SLES.9.Su.FailedFailed su (SUSE Linux Enterprise Server 9)Rule to collect events for failed call to suMicrosoft.ACS.Linux.SLES.9.Su.FailedMicrosoft.ACS.Linux.SLES.9.ACSEndPointEventCollectionTrue00FalseTrue
Microsoft.ACS.Linux.SLES.9.Su.SucceededSuccessful su (SUSE Linux Enterprise Server 9)Rule to collect events for successful call to suMicrosoft.ACS.Linux.SLES.9.Su.SucceededMicrosoft.ACS.Linux.SLES.9.ACSEndPointEventCollectionTrue00FalseTrue
Microsoft.ACS.Linux.SLES.9.Sudo.FailedFailed sudo (SUSE Linux Enterprise Server 9)Rule to collect events for bad password failed call to sudoMicrosoft.ACS.Linux.SLES.9.Sudo.FailedMicrosoft.ACS.Linux.SLES.9.ACSEndPointEventCollectionTrue00FalseTrue
Microsoft.ACS.Linux.SLES.9.Sudo.InvalidInvalid sudo (SUSE Linux Enterprise Server 9)Rule to collect events for no privileges for sudo operationsMicrosoft.ACS.Linux.SLES.9.Sudo.InvalidMicrosoft.ACS.Linux.SLES.9.ACSEndPointEventCollectionTrue00FalseTrue
Microsoft.ACS.Linux.SLES.9.Sudo.SucceededSuccessful sudo (SUSE Linux Enterprise Server 9)Rule to collect events for successful call to sudoMicrosoft.ACS.Linux.SLES.9.Sudo.SucceededMicrosoft.ACS.Linux.SLES.9.ACSEndPointEventCollectionTrue00FalseTrue