All Rules in Microsoft.ACS.Linux.Universal Management Pack

 DisplayNameDescriptionIDTargetCategoryEnabledInstance NameCounter NameFrequencyEvent_IDEvent SourceAlert GenerateAlert SeverityAlert PriorityRemotableEvent Log
Microsoft.ACS.Linux.Universal.Adding.GroupAdding Group (Universal Linux)Rule to collect events for adding a new groupMicrosoft.ACS.Linux.Universal.Adding.GroupMicrosoft.ACS.Linux.Universal.ACSEndPointEventCollectionFalse00FalseTrue
Microsoft.ACS.Linux.Universal.Adding.UserAdding User (Universal Linux)Rule to collect events for adding a new userMicrosoft.ACS.Linux.Universal.Adding.UserMicrosoft.ACS.Linux.Universal.ACSEndPointEventCollectionFalse00FalseTrue
Microsoft.ACS.Linux.Universal.Adding.User.To.GroupAdding User to Group (Universal Linux)Rule to collect events for adding a user to a groupMicrosoft.ACS.Linux.Universal.Adding.User.To.GroupMicrosoft.ACS.Linux.Universal.ACSEndPointEventCollectionFalse00FalseTrue
Microsoft.ACS.Linux.Universal.Console.Login.FailedFailed Console Login (Universal Linux)Rule to collect events for failed console loginMicrosoft.ACS.Linux.Universal.Console.Login.FailedMicrosoft.ACS.Linux.Universal.ACSEndPointEventCollectionFalse00FalseTrue
Microsoft.ACS.Linux.Universal.Console.Login.SucceededSuccessful Console Login (Universal Linux)Rule to collect events for successful console loginMicrosoft.ACS.Linux.Universal.Console.Login.SucceededMicrosoft.ACS.Linux.Universal.ACSEndPointEventCollectionFalse00FalseTrue
Microsoft.ACS.Linux.Universal.Deleting.GroupDeleting Group (Universal Linux)Rule to collect events for deleting a groupMicrosoft.ACS.Linux.Universal.Deleting.GroupMicrosoft.ACS.Linux.Universal.ACSEndPointEventCollectionFalse00FalseTrue
Microsoft.ACS.Linux.Universal.Deleting.UserDeleting User (Universal Linux)Rule to collect events for deleting a userMicrosoft.ACS.Linux.Universal.Deleting.UserMicrosoft.ACS.Linux.Universal.ACSEndPointEventCollectionFalse00FalseTrue
Microsoft.ACS.Linux.Universal.Deleting.User.From.GroupDeleting User from Group (Universal Linux)Rule to collect events for deleting a user from a groupMicrosoft.ACS.Linux.Universal.Deleting.User.From.GroupMicrosoft.ACS.Linux.Universal.ACSEndPointEventCollectionFalse00FalseTrue
Microsoft.ACS.Linux.Universal.Password.Change.FailedFailed Password Change (Universal Linux)Rule to collect events for failed password changeMicrosoft.ACS.Linux.Universal.Password.Change.FailedMicrosoft.ACS.Linux.Universal.ACSEndPointEventCollectionFalse00FalseTrue
Microsoft.ACS.Linux.Universal.Password.Change.SucceededSuccessful Password Change (Universal Linux)Rule to collect events for successful password changeMicrosoft.ACS.Linux.Universal.Password.Change.SucceededMicrosoft.ACS.Linux.Universal.ACSEndPointEventCollectionFalse00FalseTrue
Microsoft.ACS.Linux.Universal.Ssh.FailedFailed ssh login (Universal Linux)Rule to collect events for failed ssh loginMicrosoft.ACS.Linux.Universal.Ssh.FailedMicrosoft.ACS.Linux.Universal.ACSEndPointEventCollectionFalse00FalseTrue
Microsoft.ACS.Linux.Universal.Ssh.SucceededSuccessful ssh login (Universal Linux)Rule to collect events for successful ssh loginMicrosoft.ACS.Linux.Universal.Ssh.SucceededMicrosoft.ACS.Linux.Universal.ACSEndPointEventCollectionFalse00FalseTrue
Microsoft.ACS.Linux.Universal.Su.FailedFailed su (Universal Linux)Rule to collect events for failed call to suMicrosoft.ACS.Linux.Universal.Su.FailedMicrosoft.ACS.Linux.Universal.ACSEndPointEventCollectionFalse00FalseTrue
Microsoft.ACS.Linux.Universal.Su.SucceededSuccessful su (Universal Linux)Rule to collect events for successful call to suMicrosoft.ACS.Linux.Universal.Su.SucceededMicrosoft.ACS.Linux.Universal.ACSEndPointEventCollectionFalse00FalseTrue
Microsoft.ACS.Linux.Universal.Sudo.FailedFailed sudo (Universal Linux)Rule to collect events for failed call to sudoMicrosoft.ACS.Linux.Universal.Sudo.FailedMicrosoft.ACS.Linux.Universal.ACSEndPointEventCollectionFalse00FalseTrue
Microsoft.ACS.Linux.Universal.Sudo.InvalidInvalid sudo (Universal Linux)Rule to collect events for invalid call to sudoMicrosoft.ACS.Linux.Universal.Sudo.InvalidMicrosoft.ACS.Linux.Universal.ACSEndPointEventCollectionFalse00FalseTrue
Microsoft.ACS.Linux.Universal.Sudo.SucceededSuccessful sudo (Universal Linux)Rule to collect events for successful call to sudoMicrosoft.ACS.Linux.Universal.Sudo.SucceededMicrosoft.ACS.Linux.Universal.ACSEndPointEventCollectionFalse00FalseTrue