SentinelOne

EventTitleChannelSampleRule
1Windows Agent is starting in AgentMode mode.OperationalNN
2Policy was changed in the Console: %1.OperationalNN
3Policy was changed with override commands: %1.OperationalNN
4Failed to register with management because it no longer exists.OperationalNN
5Failed to register with management: Reason (ErrorCode).OperationalNN
6Threat remediation: Failed to delete file FilePath because it was already …OperationalNN
7Threat remediation: Failed to delete file FilePath.OperationalNN
8Threat remediation: Failed to rename file SourceFilePath to DestinationFilePath …OperationalNN
9Threat remediation: Failed to rename file SourceFilePath to DestinationFilePath …OperationalNN
10Threat remediation: Failed to rename file SourceFilePath to DestinationFilePath …OperationalNN
11Threat remediation: Failed to rename file SourceFilePath to DestinationFilePath.OperationalNN
12Threat remediation: Failed to restore file FilePath to timestamp …OperationalNN
13Threat remediation: Failed to restore file FilePath to timestamp …OperationalNN
14Threat remediation: Failed to restore file FilePath to timestamp …OperationalNN
15Threat remediation: Failed to restore registry value (key: RegistryKeyPath, …OperationalNN
16Threat mitigation: Failed to kill malicious processes because the true context …OperationalNN
17Threat mitigation completion after reboot requested another reboot.OperationalNN
18Threat mitigation: Not killing process ProcessName (Path: ProcessPath, Process …OperationalNN
19Threat mitigation: Cannot kill process ProcessName (Path: ProcessPath, Process …OperationalNN
20Threat mitigation: Cannot kill process ProcessName (Path: ProcessPath, Process …OperationalNN
21Threat mitigation: Cannot kill process ProcessName (Path: ProcessPath, Process …OperationalNN
22Threat mitigation: Cannot kill threads of process ProcessName (Path: …OperationalNN
23Threat mitigation: Failed to quarantine file FilePath because the file is …OperationalNN
24Threat mitigation: Failed to quarantine file FilePath because the file belongs …OperationalNN
25Threat mitigation: Failed to scramble file FilePath.OperationalNN
26Threat mitigation: skipping quarantine of file FilePath because the file was …OperationalNN
27Threat mitigation: Failed to quarantine file FilePath because the file does not …OperationalNN
28Threat mitigation: A reboot is required to complete the quarantine of file …OperationalNN
29Threat mitigation: Failed to quarantine a file.OperationalNN
30Network quarantine failed.OperationalNN
31Malware detected!OperationalNN
32Mitigation report.OperationalNN
33Failed to unquarantine file FilePath because the file cannot be found.OperationalNN
34Unquarantine: Failed to restore file times for FilePath.OperationalNN
35Failed to unquarantine files affected by threat of True Context ID …OperationalNN
36Network unquarantine failed.OperationalNN
37Policy not changed. Verification key not provided.OperationalNN
38Policy not changed. The provided verification key is incorrect.OperationalNN
39Policy not changed. A parameter cannot be both set and undefined.OperationalNN
40Policy not changed. Parameter was not provided.OperationalNN
41Policy not changed.OperationalNN
42Policy not changed.OperationalNN
43Policy not changed. The provided proxy credentials are invalid.OperationalNN
44Policy not changed.OperationalNN
45Policy not changed.OperationalNN
46Policy not changed.OperationalNN
47Policy not changed.OperationalNN
48Policy not changed.OperationalNN
49Policy not changed.OperationalNN
50Cannot scan Path because the path does not exist.OperationalNN
51Cannot scan Path because it is not a folder.OperationalNN
52Scan not started because a previous scan is still in progress.OperationalNN
53Cannot scan because Sentinel Agent is not running.OperationalNN
54Scan aborted.OperationalNN
55Full Disk Scan started.OperationalNN
56Scan of Path started.OperationalNN
57Scan completed successfully.OperationalNN
58Failed to execute command Command.OperationalNN
59Remote Shell: Error.OperationalNN
60Agent Upgrade: BITS job created for downloading the new Agent.OperationalNN
61Agent Upgrade: BITS download job complete.OperationalNN
62Agent Upgrade: BITS download job failed.OperationalNN
63Agent Upgrade: BITS download job failed.OperationalNN
64Agent Upgrade: BITS is unavailable.OperationalNN
65Agent handled the creation of process Name (PID: PID).OperationalNN
66DB pruning Result.OperationalNN
67Customer ID: customerID.OperationalNN
68Mark as Status on True Context ID TrueContextID received from Deep Visibility.OperationalNN
69Failed to Mark True Context ID TrueContextID as Status.OperationalNN
70Failed to Mark as Status: True Context ID TrueContextID.OperationalNN
71True Context ID TrueContextID was changed from suspicious to threat.OperationalNN
72Failed to Mark as Status: True Context ID TrueContextID.OperationalNN
73Failed to Mark as Suspicious True Context ID TrueContextID.OperationalNN
74Failed to Mark as Status True Context ID TrueContextID.OperationalNN
75Agent handled the termination of process Name (PID: PID).OperationalNN
76Agent encountered invalid pattern: Pattern.OperationalNN
77USB device DeviceName was Action based on SentinelOne Device Control policy.OperationalNN
78Bluetooth device DeviceName was Action based on SentinelOne Device Control …OperationalNN
79Interface device DeviceName was Action based on SentinelOne Device Control …OperationalNN
80The agent encountered an error that is usually ignored, but shouldn't be ignored …OperationalNN
81Scan ended.OperationalNN
82BlueKeep exploitation attempt detected from: IP.OperationalNN
83Resizing the VSS diff area on VolumeName was blocked.OperationalNN
84Blocked PacketDirection connection.FirewallNN
85Unable to handle configuration change, dropping the configurationOperationalNN
86UI storage reached maximum allowed file sizeOperationalNN
87UI storage read error ErrorCode "ErrorMessage".OperationalNN
88UI storage write error ErrorCode "ErrorMessage".OperationalNN
89UI storage is corrupted and will be deleted.OperationalNN
90Error deleting corrupted UI storage.OperationalNN
91Remote script orchestrator: script ScriptName execution completed.OperationalNN
92File FilePath was detected as a malicious driver when attempting to load it …OperationalNN
93SentinelCTL command of type "CommandType" was executed - result was: Result.OperationalNN
94Anti-tampering was activated.OperationalNN
95Anti-tampering was deactivated.OperationalNN
96Agent upgrade was initiated.OperationalNN
97Windows Agent is shutting down.OperationalNN
98Sentinel process has crashed.OperationalNN
99Dump file was deleted, as dump limit of DumpFileLimit was reached.OperationalNN
100The agent has successfully connected to the SentinelOne console (ConsoleURL).OperationalNN
101The agent received a "CommandType" command from console.OperationalNN
102Entering disable mode by command.OperationalNN
103Exiting disable mode.OperationalNN
104Event ID 104OperationalNN

Event ID 1: Windows Agent is starting in AgentMode mode.

#
Channel
Operational

Description

Windows Agent is starting in AgentMode mode. Agent version ProductVersion, running on Windows WindowsVersion.

Message #

Windows Agent is starting in %3 mode. Agent version %1, running on Windows %2.

Fields #

NameDescription
ProductVersion UnicodeString
WindowsVersion UnicodeString
AgentMode UnicodeString

Event ID 2: Policy was changed in the Console: %1.

#
Channel
Operational

Description

Policy was changed in the Console.

Message #

Policy was changed in the Console:



%1

Event ID 3: Policy was changed with override commands: %1.

#
Channel
Operational

Description

Policy was changed with override commands.

Message #

Policy was changed with override commands:



%1

Event ID 4: Failed to register with management because it no longer exists.

#
Channel
Operational

Description

Failed to register with management because it no longer exists. Not retrying.

Message #

Failed to register with management because it no longer exists. Not retrying.

Fields #

NameDescription
ErrorCode Int32

Event ID 5: Failed to register with management: Reason (ErrorCode).

#
Channel
Operational

Description

Failed to register with management: Reason (ErrorCode). Retrying in RetrySeconds seconds.

Message #

Failed to register with management: %1 (%2). Retrying in %3 seconds.

Fields #

NameDescription
Reason AnsiString
ErrorCode Int32
RetrySeconds Int32

Event ID 6: Threat remediation: Failed to delete file FilePath because it was already deleted.

#
Channel
Operational

Message #

Threat remediation: Failed to delete file %1 because it was already deleted.

Fields #

NameDescription
FilePath UnicodeString

Event ID 7: Threat remediation: Failed to delete file FilePath.

#
Channel
Operational

Message #

Threat remediation: Failed to delete file %1.

Error: %2

Fields #

NameDescription
FilePath UnicodeString
Error UInt32

Event ID 8: Threat remediation: Failed to rename file SourceFilePath to DestinationFilePath because the file was deleted.

#
Channel
Operational

Message #

Threat remediation: Failed to rename file %1 to %2 because the file was deleted.

Fields #

NameDescription
SourceFilePath UnicodeString
DestinationFilePath UnicodeString

Event ID 9: Threat remediation: Failed to rename file SourceFilePath to DestinationFilePath because the file's parent directory does not exist.

#
Channel
Operational

Message #

Threat remediation: Failed to rename file %1 to %2 because the file's parent directory does not exist.

Fields #

NameDescription
SourceFilePath UnicodeString
DestinationFilePath UnicodeString

Event ID 10: Threat remediation: Failed to rename file SourceFilePath to DestinationFilePath because the destination path already exists.

#
Channel
Operational

Message #

Threat remediation: Failed to rename file %1 to %2 because the destination path already exists.

Fields #

NameDescription
SourceFilePath UnicodeString
DestinationFilePath UnicodeString

Event ID 11: Threat remediation: Failed to rename file SourceFilePath to DestinationFilePath.

#
Channel
Operational

Message #

Threat remediation: Failed to rename file %1 to %2.

Error: %3

Fields #

NameDescription
SourceFilePath UnicodeString
DestinationFilePath UnicodeString
Error UInt32

Event ID 12: Threat remediation: Failed to restore file FilePath to timestamp DesiredTimestamp because no snapshots were found up to the desired period.

#
Channel
Operational

Message #

Threat remediation: Failed to restore file %1 to timestamp %2 because no snapshots were found up to the desired period.

Fields #

NameDescription
FilePath UnicodeString
DesiredTimestamp FILETIME

Event ID 13: Threat remediation: Failed to restore file FilePath to timestamp DesiredTimestamp because it is being used by another process.

#
Channel
Operational

Message #

Threat remediation: Failed to restore file %1 to timestamp %2 because it is being used by another process.

Fields #

NameDescription
FilePath UnicodeString
DesiredTimestamp FILETIME

Event ID 14: Threat remediation: Failed to restore file FilePath to timestamp DesiredTimestamp because access was denied.

#
Channel
Operational

Message #

Threat remediation: Failed to restore file %1 to timestamp %2 because access was denied.

Fields #

NameDescription
FilePath UnicodeString
DesiredTimestamp FILETIME

Event ID 15: Threat remediation: Failed to restore registry value (key: RegistryKeyPath, value: Value) because it does not exist.

#
Channel
Operational

Message #

Threat remediation: Failed to restore registry value (key: %1, value: %2) because it does not exist.

Fields #

NameDescription
RegistryKeyPath UnicodeString
Value UnicodeString

Event ID 16: Threat mitigation: Failed to kill malicious processes because the true context does not exist.

#
Channel
Operational

Event ID 17: Threat mitigation completion after reboot requested another reboot.

#
Channel
Operational

Message #

Threat mitigation completion after reboot requested another reboot.

True Context ID: %1, Mitigation action: %2

Fields #

NameDescription
TrueContextID UnicodeString
MitigationAction UnicodeString

Event ID 18: Threat mitigation: Not killing process ProcessName (Path: ProcessPath, Process ID: ProcessID) due to relation Relation.

#
Channel
Operational

Message #

Threat mitigation: Not killing process %1 (Path: %2, Process ID: %3) due to relation %4.

Fields #

NameDescription
ProcessName UnicodeString
ProcessPath UnicodeString
ProcessID UInt32
Relation UnicodeString

Event ID 19: Threat mitigation: Cannot kill process ProcessName (Path: ProcessPath, Process ID: ProcessID) because it is a core OS process.

#
Channel
Operational

Message #

Threat mitigation: Cannot kill process %1 (Path: %2, Process ID: %3) because it is a core OS process.

Fields #

NameDescription
ProcessName UnicodeString
ProcessPath UnicodeString
ProcessID UInt32

Event ID 20: Threat mitigation: Cannot kill process ProcessName (Path: ProcessPath, Process ID: ProcessID) because it is signed by SentinelOne.

#
Channel
Operational

Message #

Threat mitigation: Cannot kill process %1 (Path: %2, Process ID: %3) because it is signed by SentinelOne.

Fields #

NameDescription
ProcessName UnicodeString
ProcessPath UnicodeString
ProcessID UInt32

Event ID 21: Threat mitigation: Cannot kill process ProcessName (Path: ProcessPath, Process ID: ProcessID) due to an unknown error.

#
Channel
Operational

Message #

Threat mitigation: Cannot kill process %1 (Path: %2, Process ID: %3) due to an unknown error.

Fields #

NameDescription
ProcessName UnicodeString
ProcessPath UnicodeString
ProcessID UInt32

Event ID 22: Threat mitigation: Cannot kill threads of process ProcessName (Path: ProcessPath, Process ID: ProcessID) due to an unknown error.

#
Channel
Operational

Message #

Threat mitigation: Cannot kill threads of process %1 (Path: %2, Process ID: %3) due to an unknown error.

Fields #

NameDescription
ProcessName UnicodeString
ProcessPath UnicodeString
ProcessID UInt32

Event ID 23: Threat mitigation: Failed to quarantine file FilePath because the file is remote.

#
Channel
Operational

Message #

Threat mitigation: Failed to quarantine file %1 because the file is remote.

Fields #

NameDescription
FilePath UnicodeString

Event ID 24: Threat mitigation: Failed to quarantine file FilePath because the file belongs to a core OS process.

#
Channel
Operational

Message #

Threat mitigation: Failed to quarantine file %1 because the file belongs to a core OS process.

Fields #

NameDescription
FilePath UnicodeString

Event ID 25: Threat mitigation: Failed to scramble file FilePath.

#
Channel
Operational

Message #

Threat mitigation: Failed to scramble file %1.

Error: %2

Fields #

NameDescription
FilePath UnicodeString
Error AnsiString

Event ID 26: Threat mitigation: skipping quarantine of file FilePath because the file was already quarantined by another threat mitigation.

#
Channel
Operational

Message #

Threat mitigation: skipping quarantine of file %1 because the file was already quarantined by another threat mitigation.

Fields #

NameDescription
FilePath UnicodeString

Event ID 27: Threat mitigation: Failed to quarantine file FilePath because the file does not exist.

#
Channel
Operational

Message #

Threat mitigation: Failed to quarantine file %1 because the file does not exist.

Fields #

NameDescription
FilePath UnicodeString

Event ID 28: Threat mitigation: A reboot is required to complete the quarantine of file FilePath.

#
Channel
Operational

Message #

Threat mitigation: A reboot is required to complete the quarantine of file %1.

Fields #

NameDescription
FilePath UnicodeString

Event ID 29: Threat mitigation: Failed to quarantine a file.

#
Channel
Operational

Message #

Threat mitigation: Failed to quarantine a file.

Error: %1

Fields #

NameDescription
Error AnsiString

Event ID 30: Network quarantine failed.

#
Channel
Operational

Message #

Network quarantine failed.

Error: %1

Fields #

NameDescription
Error AnsiString

Event ID 31: Malware detected!

#
Channel
Operational

Message #

Malware detected!



True Context ID: %1

Name: %2

Path: %3

Detection engine: %4

Fields #

NameDescription
TrueContextID UnicodeString
Name UnicodeString
Path UnicodeString
DetectionEngine UnicodeString

Event ID 32: Mitigation report.

#
Channel
Operational

Message #

Mitigation report



True Context ID: %1

Action: %2

Result: %3

Fields #

NameDescription
TrueContextID UnicodeString
Action UnicodeString
Result UnicodeString

Event ID 33: Failed to unquarantine file FilePath because the file cannot be found.

#
Channel
Operational

Message #

Failed to unquarantine file %1 because the file cannot be found

Fields #

NameDescription
FilePath UnicodeString

Event ID 34: Unquarantine: Failed to restore file times for FilePath.

#
Channel
Operational

Message #

Unquarantine: Failed to restore file times for %1.

Error: %2

Fields #

NameDescription
FilePath UnicodeString
Error AnsiString

Event ID 35: Failed to unquarantine files affected by threat of True Context ID TrueContextID.

#
Channel
Operational

Message #

Failed to unquarantine files affected by threat of True Context ID %1.

Error: %2

Fields #

NameDescription
TrueContextID UnicodeString
Error AnsiString

Event ID 36: Network unquarantine failed.

#
Channel
Operational

Message #

Network unquarantine failed.

Error: %1

Fields #

NameDescription
Error AnsiString

Event ID 37: Policy not changed. Verification key not provided.

#
Channel
Operational

Description

Policy not changed. Verification key not provided. Get the Agent passphrase and enter it with the -k flag.

Message #

Policy not changed. Verification key not provided. Get the Agent passphrase and enter it with the -k flag.

Event ID 38: Policy not changed. The provided verification key is incorrect.

#
Channel
Operational

Event ID 39: Policy not changed. A parameter cannot be both set and undefined.

#
Channel
Operational

Event ID 40: Policy not changed. Parameter was not provided.

#
Channel
Operational

Event ID 41: Policy not changed.

#
Channel
Operational

Description

Policy not changed. The value Value is not valid for Parameter: invalid URL.

Message #

Policy not changed. The value %2 is not valid for %1: invalid URL.

Fields #

NameDescription
Parameter UnicodeString
Value UnicodeString

Event ID 42: Policy not changed.

#
Channel
Operational

Description

Policy not changed. The value Value is not valid. Remove the slash from the end of the URL.

Message #

Policy not changed. The value %2 is not valid. Remove the slash from the end of the URL.

Fields #

NameDescription
Parameter UnicodeString
Value UnicodeString

Event ID 43: Policy not changed. The provided proxy credentials are invalid.

#
Channel
Operational

Fields #

NameDescription
Parameter UnicodeString

Event ID 44: Policy not changed.

#
Channel
Operational

Description

Policy not changed. Failed to write value Parameter for UI Language due to error: Value.

Message #

Policy not changed. Failed to write value %1 for UI Language due to error: %2

Fields #

NameDescription
Parameter UnicodeString
Value UnicodeString
Error AnsiString

Event ID 45: Policy not changed.

#
Channel
Operational

Description

Policy not changed. Invalid UI configuration property Parameter.

Message #

Policy not changed. Invalid UI configuration property %1.

Fields #

NameDescription
Parameter UnicodeString

Event ID 46: Policy not changed.

#
Channel
Operational

Description

Policy not changed. Invalid engine status Value.

Message #

Policy not changed. Invalid engine status %2.

Engine status must be one of: "off", "suppressed", "disable", "local".

Fields #

NameDescription
Parameter UnicodeString
Value UnicodeString

Event ID 47: Policy not changed.

#
Channel
Operational

Description

Policy not changed. Invalid parameter Parameter: Error.

Message #

Policy not changed. Invalid parameter %1: %2.

Fields #

NameDescription
Parameter UnicodeString
Error AnsiString

Event ID 48: Policy not changed.

#
Channel
Operational

Message #

Policy not changed.

Error: %3.

Parameter: %1

Invalid given value: %2

Fields #

NameDescription
Parameter UnicodeString
Value UnicodeString
Error AnsiString

Event ID 49: Policy not changed.

#
Channel
Operational

Description

Policy not changed. Cannot undefine parameter Parameter.

Message #

Policy not changed. Cannot undefine parameter %1.

Fields #

NameDescription
Parameter UnicodeString

Event ID 50: Cannot scan Path because the path does not exist.

#
Channel
Operational

Message #

Cannot scan %1 because the path does not exist.

Fields #

NameDescription
Path UnicodeString

Event ID 51: Cannot scan Path because it is not a folder.

#
Channel
Operational

Message #

Cannot scan %1 because it is not a folder.

Fields #

NameDescription
Path UnicodeString

Event ID 52: Scan not started because a previous scan is still in progress.

#
Channel
Operational

Event ID 53: Cannot scan because Sentinel Agent is not running.

#
Channel
Operational

Description

Cannot scan because Sentinel Agent is not running. Load the Agent and try again.

Message #

Cannot scan because Sentinel Agent is not running. Load the Agent and try again.

Event ID 54: Scan aborted.

#
Channel
Operational

Event ID 55: Full Disk Scan started.

#
Channel
Operational

Event ID 56: Scan of Path started.

#
Channel
Operational

Message #

Scan of %1 started.

Fields #

NameDescription
Path UnicodeString

Event ID 57: Scan completed successfully.

#
Channel
Operational

Event ID 58: Failed to execute command Command.

#
Channel
Operational

Message #

Failed to execute command %1.

Error: %2

Fields #

NameDescription
Command UnicodeString
Error UnicodeString

Event ID 59: Remote Shell: Error.

#
Channel
Operational

Message #

Remote Shell: %1

Fields #

NameDescription
Error UnicodeString

Event ID 60: Agent Upgrade: BITS job created for downloading the new Agent.

#
Channel
Operational

Message #

Agent Upgrade: BITS job created for downloading the new Agent.

Job title: %1

GUID: %2

Destination: %3

Fields #

NameDescription
BITSJobTitle UnicodeString
BITSJobGUID UnicodeString
DownloadDestination UnicodeString

Event ID 61: Agent Upgrade: BITS download job complete.

#
Channel
Operational

Description

Agent Upgrade: BITS download job complete. Executing installation.

Message #

Agent Upgrade: BITS download job complete. Executing installation.

Job title: %1

GUID: %2

Destination: %3

Fields #

NameDescription
BITSJobTitle UnicodeString
BITSJobGUID UnicodeString
DownloadDestinationPath UnicodeString

Event ID 62: Agent Upgrade: BITS download job failed.

#
Channel
Operational

Message #

Agent Upgrade: BITS download job failed.

Error: %1 (%2)

Job title: %3

GUID: %4

Fields #

NameDescription
ErrorMessage UnicodeString
ErrorCode UInt32
BITSJobTitle UnicodeString
BITSJobGUID UnicodeString

Event ID 63: Agent Upgrade: BITS download job failed.

#
Channel
Operational

Description

Agent Upgrade: BITS download job failed. Falling back to the classic downloader.

Message #

Agent Upgrade: BITS download job failed. Falling back to the classic downloader.

Error: %1 (%2)

Job title: %3

GUID: %4

Fields #

NameDescription
ErrorMessage UnicodeString
ErrorCode UInt32
BITSJobTitle UnicodeString
BITSJobGUID UnicodeString

Event ID 64: Agent Upgrade: BITS is unavailable.

#
Channel
Operational

Description

Agent Upgrade: BITS is unavailable. Falling back to the classic downloader.

Message #

Agent Upgrade: BITS is unavailable. Falling back to the classic downloader.

Event ID 65: Agent handled the creation of process Name (PID: PID).

#
Channel
Operational

Message #

Agent handled the creation of process %1 (PID: %2).

Fields #

NameDescription
Name UnicodeString
PID UInt32
UID UnicodeString
GroupUID UnicodeString

Event ID 66: DB pruning Result.

#
Channel
Operational

Message #

DB pruning %1.

Size before: %2

Size after: %3

New DB GUID: %4

Old DB path: %5

New DB path: %6

Fields #

NameDescription
Result UnicodeString
SizeBefore UInt64
SizeAfter UInt64
NewGUID UnicodeString
OldPath UnicodeString
NewPath UnicodeString

Event ID 67: Customer ID: customerID.

#
Channel
Operational

Message #

Customer ID: %1

Fields #

NameDescription
customerID UnicodeString

Event ID 68: Mark as Status on True Context ID TrueContextID received from Deep Visibility.

#
Channel
Operational

Message #

Mark as %2 on True Context ID %1 received from Deep Visibility

Fields #

NameDescription
TrueContextID UnicodeString
Status UnicodeStringNTSTATUS reference

Event ID 69: Failed to Mark True Context ID TrueContextID as Status.

#
Channel
Operational

Message #

Failed to Mark True Context ID %1 as %2.

Error: True Context ID was not found on the Agent

Fields #

NameDescription
TrueContextID UnicodeString
Status UnicodeStringNTSTATUS reference

Event ID 70: Failed to Mark as Status: True Context ID TrueContextID.

#
Channel
Operational

Message #

Failed to Mark as %2: True Context ID %1.

Error: Already marked

Fields #

NameDescription
TrueContextID UnicodeString
Status UnicodeStringNTSTATUS reference

Event ID 71: True Context ID TrueContextID was changed from suspicious to threat.

#
Channel
Operational

Message #

True Context ID %1 was changed from suspicious to threat

Fields #

NameDescription
TrueContextID UnicodeString

Event ID 72: Failed to Mark as Status: True Context ID TrueContextID.

#
Channel
Operational

Message #

Failed to Mark as %2: True Context ID %1.

Error: Marked as Exclusion

Fields #

NameDescription
TrueContextID UnicodeString
Status UnicodeStringNTSTATUS reference

Event ID 73: Failed to Mark as Suspicious True Context ID TrueContextID.

#
Channel
Operational

Message #

Failed to Mark as Suspicious True Context ID %1.

Error: Already marked as Threat

Fields #

NameDescription
TrueContextID UnicodeString

Event ID 74: Failed to Mark as Status True Context ID TrueContextID.

#
Channel
Operational

Message #

Failed to Mark as %2 True Context ID %1.

Error: Status is invalid

Fields #

NameDescription
TrueContextID UnicodeString
Status UnicodeStringNTSTATUS reference

Event ID 75: Agent handled the termination of process Name (PID: PID).

#
Channel
Operational

Message #

Agent handled the termination of process %1 (PID: %2).

Fields #

NameDescription
Name UnicodeString
PID UInt32
UID UnicodeString
GroupUID UnicodeString

Event ID 76: Agent encountered invalid pattern: Pattern.

#
Channel
Operational

Message #

Agent encountered invalid pattern: %1.

Fields #

NameDescription
Pattern UnicodeString

Event ID 77: USB device DeviceName was Action based on SentinelOne Device Control policy.

#
Channel
Operational

Message #

USB device %1 was %2 based on SentinelOne Device Control policy



Class: %3

Interface: USB

Vendor ID: %4

Product ID: %5

Serial ID: %6

Device Name: %1

Fields #

NameDescription
DeviceName UnicodeString
Action UnicodeString
UsbDeviceClass UnicodeString
VendorId UnicodeString
ProductId UnicodeString
SerialId UnicodeString

Event ID 78: Bluetooth device DeviceName was Action based on SentinelOne Device Control policy.

#
Channel
Operational

Message #

Bluetooth device %1 was %2 based on SentinelOne Device Control policy



Class: %3

Minor Class: %4

Interface: Bluetooth

Vendor ID: %5

Product ID: %6

Manufacturer Name: %7

Bluetooth Address: %8

Device Name: %1

Bluetooth Version: %9

GATT Service: %10

Device Information: %11

Fields #

NameDescription
DeviceName UnicodeString
Action UnicodeString
DeviceClass UnicodeString
DeviceMinorClass UnicodeString
VendorId UnicodeString
ProductId UnicodeString
ManufacturerName UnicodeString
BluetoothAddress UnicodeString
BluetoothVersion UnicodeString
GATTService UnicodeString
DeviceInformation UnicodeString

Event ID 79: Interface device DeviceName was Action based on SentinelOne Device Control policy Info.

#
Channel
Operational

Description

Interface device DeviceName was Action based on SentinelOne Device Control policy.

Message #

%1 device %2 was %3 based on SentinelOne Device Control policy



%4

Fields #

NameDescription
Interface UnicodeString
DeviceName UnicodeString
Action UnicodeString
Info UnicodeString

Event ID 80: The agent encountered an error that is usually ignored, but shouldn't be ignored in automation: Message.

#
Channel
Operational

Message #

The agent encountered an error that is usually ignored, but shouldn't be ignored in automation: %1

Fields #

NameDescription
Message UnicodeString

Event ID 81: Scan ended.

#
Channel
Operational

Message #

Scan ended.

Scan start time: %1

Scan end time: %2

Scanned %3

Scan triggered by: %4

Total files scanned: %5

Malicious files count: %6

Excluded malicious files count: %7

Scan status: %8

Fields #

NameDescription
ScanStartTime FILETIME
ScanEndTime FILETIME
ScannedPath UnicodeString
TriggerType UnicodeString
ScannedCount UInt64
MaliciousCount UInt64
ExcludedMaliciousCount UInt64
Status UnicodeStringNTSTATUS reference

Event ID 82: BlueKeep exploitation attempt detected from: IP.

#
Channel
Operational

Message #

BlueKeep exploitation attempt detected from: %1

Fields #

NameDescription
IP UnicodeString

Event ID 83: Resizing the VSS diff area on VolumeName was blocked.

#
Channel
Operational

Message #

Resizing the VSS diff area on %2 was blocked.

The existing diff area has %3 used bytes and %4 allocated bytes.

The requested new diff area maximum was %5 bytes.

Fields #

NameDescription
VolumeNameLength UInt16
VolumeName UnicodeString
OldDiffAreaUsed Int64
OldDiffAreaAllocated Int64
NewDiffAreaMaximum Int64

Event ID 84: Blocked PacketDirection connection.

#
Channel
Firewall

Description

Blocked PacketDirection connection. Rule Id: RuleId Rule Name: RuleName PID: ProcessId Remote Address: RemoteAddress:Port, FQDN: Fqdn.

Message #

Blocked %5 connection. Rule Id: %9 Rule Name: %10 PID: %3 Remote Address: %1:%2, FQDN: %8.

Application Name :%4.

Fields #

NameDescription
RemoteAddress UnicodeString
Port UInt16
ProcessId UInt32
AppId UnicodeString
PacketDirection UnicodeString
FilterId UInt64
LayerId UInt16
Fqdn UnicodeString
RuleId UnicodeString
RuleName UnicodeString

Event ID 85: Unable to handle configuration change, dropping the configuration

#
Channel
Operational

Event ID 86: UI storage reached maximum allowed file size

#
Channel
Operational

Event ID 87: UI storage read error ErrorCode "ErrorMessage".

#
Channel
Operational

Message #

UI storage read error %2 "%1"

Fields #

NameDescription
ErrorMessage UnicodeString
ErrorCode Int32

Event ID 88: UI storage write error ErrorCode "ErrorMessage".

#
Channel
Operational

Message #

UI storage write error %2 "%1"

Fields #

NameDescription
ErrorMessage UnicodeString
ErrorCode Int32

Event ID 89: UI storage is corrupted and will be deleted.

#
Channel
Operational

Event ID 90: Error deleting corrupted UI storage.

#
Channel
Operational

Event ID 91: Remote script orchestrator: script ScriptName execution completed.

#
Channel
Operational

Description

Remote script orchestrator: script ScriptName execution completed. Start time: StartTime, duration: Duration milliseconds, exit status: ExitCode.

Message #

Remote script orchestrator: script %1 execution completed. Start time: %2, duration: %3 milliseconds, exit status: %4.

Fields #

NameDescription
ScriptName UnicodeString
StartTime FILETIME
Duration UInt64
ExitCode UInt64

Event ID 92: File FilePath was detected as a malicious driver when attempting to load it (Malicious Driver Type: MaliciousDriverType).

#
Channel
Operational

Message #

File %1 was detected as a malicious driver when attempting to load it (Malicious Driver Type: %2)

Fields #

NameDescription
FilePath UnicodeString
MaliciousDriverType UInt32

Event ID 93: SentinelCTL command of type "CommandType" was executed - result was: Result.

#
Channel
Operational

Message #

SentinelCTL command of type "%1" was executed - result was: %2.

Fields #

NameDescription
CommandType UnicodeString
Result UInt32

Event ID 94: Anti-tampering was activated.

#
Channel
Operational

Event ID 95: Anti-tampering was deactivated.

#
Channel
Operational

Event ID 96: Agent upgrade was initiated.

#
Channel
Operational

Description

Agent upgrade was initiated. (OldVersion -> NewVersion).

Message #

Agent upgrade was initiated. (%1 -> %2)

Fields #

NameDescription
OldVersion UnicodeString
NewVersion UnicodeString

Event ID 97: Windows Agent is shutting down.

#
Channel
Operational

Event ID 98: Sentinel process has crashed.

#
Channel
Operational

Description

Sentinel process has crashed. Dump file path: "DumpPath".

Message #

Sentinel process has crashed. Dump file path: "%1".

Fields #

NameDescription
DumpPath UnicodeString

Event ID 99: Dump file was deleted, as dump limit of DumpFileLimit was reached.

#
Channel
Operational

Description

Dump file was deleted, as dump limit of DumpFileLimit was reached. Dump file path: "DumpPath".

Message #

Dump file was deleted, as dump limit of %1 was reached. Dump file path: "%2".

Fields #

NameDescription
DumpFileLimit UInt32
DumpPath UnicodeString

Event ID 100: The agent has successfully connected to the SentinelOne console (ConsoleURL).

#
Channel
Operational

Message #

The agent has successfully connected to the SentinelOne console (%1).

Fields #

NameDescription
ConsoleURL UnicodeString

Event ID 101: The agent received a "CommandType" command from console.

#
Channel
Operational

Message #

The agent received a "%1" command from console

Fields #

NameDescription
CommandType UnicodeString

Event ID 102: Entering disable mode by command.

#
Channel
Operational

Event ID 103: Exiting disable mode.

#
Channel
Operational

Event ID 104

#
Channel
Operational

Message #

%1

Fields #

NameDescription
CommSdkMessage AnsiString