SNMP trap events and object definitions
Use this article to identify BeyondInsight SNMP trap objects, OIDs, varbinds, and event values for on-premises monitoring integrations. BeyondInsight sends SNMP traps to external monitoring systems, and each trap includes a set of fields, called varbinds, that describe what occurred, where it occurred, and which product or service generated the event.
Important informationConfigure SNMP traps only for on-premises deployments.
SNMP trap enumeration
OID Tree
| Object | OID |
|---|---|
eEye | 1.3.6.1.4.1.20730 |
eEyeNotificationMIB | 1.3.6.1.4.1.20730.1 |
eEyeEventObjects | 1.3.6.1.4.1.20730.1.1 |
eEyeEvent | 1.3.6.1.4.1.20730.1.1.1 |
Object definitions
eEyeEventUniqueID
Definition: Use this object to identify the unique event ID (GUID).
| Field | Value |
|---|---|
| OID | 1.3.6.1.4.1.20730.1.1.1.0 |
| Syntax | OCTET STRING |
| Status | optional |
This object uses sub-identifier
0undereEyeEvent, which is non-standard in SMIv1 (sub-identifiers typically start at1). The SNMP formatter does not include a varbind for this field, and theeEyeEventAlertVARIABLES list excludes it.
eEyeEventID
| Field | Value |
|---|---|
| OID | 1.3.6.1.4.1.20730.1.1.1.1 |
| Syntax | OCTET STRING |
| Status | mandatory |
BeyondTrust Discovery scan events
| Value | Description |
|---|---|
RET-SCAN-001 | General |
RET-SCAN-002 | |
RET-SCAN-003 | Machine |
RET-SCAN-004 | Ports |
RET-SCAN-005 | Services |
RET-SCAN-006 | |
RET-SCAN-007 | Users and Groups |
RET-SCAN-008 | Asset |
RET-SCAN-009 | Processes |
RET-SCAN-010 | START_JOB |
RET-SCAN-011 | STOP_JOB |
RET-SCAN-012 | START_IP |
RET-SCAN-013 | STOP_IP |
RET-SCAN-014 | |
RET-SCAN-015 | |
RET-SCAN-016 | Target Alerts |
RET-SCAN-017 | |
RET-SCAN-018 | UNUSED |
RET-SCAN-019 | JobDetail |
RET-SCAN-020 | Software |
RET-SCAN-021 | |
RET-SCAN-022 | |
RET-SCAN-023 | |
RET-SCAN-024 | |
RET-SCAN-025 | |
RET-SCAN-026 | |
RET-SCAN-027 | |
RET-SCAN-028 | Job Alerts |
RET-SCAN-029 | |
RET-SCAN-030 | Database Enumeration |
RET-SCAN-031 | |
RET-SCAN-032 | Scheduled Tasks |
RET-SCAN-033 | |
RET-SCAN-034 | DCOM Services, COM ClassIDs, and COM+ events |
Application audit events
| Value | Description |
|---|---|
AppAudit | Application Audit event |
Endpoint Privilege Management for Windows / Endpoint Privilege Management for Mac events
| Value | Description |
|---|---|
PBW-EVENT-28691 | Application Requested Elevation |
PBW-EVENT-28692 | Application Launched |
PBW-EVENT-28693 | Custom Rule Applied |
PBW-EVENT-28694 | Shell Rule Applied |
PBW-EVENT-28695 | ActiveX Control Rule Applied |
PBW-EVENT-28696 | ActiveX - Application Requested Elevation |
PBW-EVENT-28697 | UAC Prompt |
PBW-EVENT-28698 | Denied Rule Applied |
PBW-EVENT-28699 | Passive Rule Applied |
PBW-EVENT-28701 | Heartbeat |
PBW-EVENT-28702 | Validate Policy |
PBW-EVENT-28703 | Policy Applied |
Password Safe events
| Value | Description |
|---|---|
PBPS | Password Safe event |
Privilege Management Reporting events
| Value | Description |
|---|---|
01 | Service Starts |
02 | User Logons |
03 | Privileged Account Protection |
04 | Processes |
Appliance Health events
| Value | Name | Description |
|---|---|---|
UVM-SERVICE-001 | ServiceErrorAlert | Service not running when expected |
UVM-PERF-001 | PerformanceAlert | SQL Memory Percentage |
UVM-PERF-002 | PerformanceAlert | Total CPU |
UVM-PERF-003 | PerformanceAlert | SQL CPU |
UVM-PERF-004 | PerformanceAlert | C Drive Space Free |
UVM-PERF-005 | PerformanceAlert | M Drive Space Free |
UVM-PERF-006 | PerformanceAlert | N Drive Space Free |
UVM-PERF-007 | PerformanceAlert | O Drive Space Free |
UVM-PERF-008 | PerformanceAlert | RAM Usage |
UVM-PERF-105 | PerformanceAlert | Physical Disk Avg Disk sec/Write |
UVM-PERF-106 | PerformanceAlert | Physical Disk Current Queue Length |
UVM-PERF-108 | PerformanceAlert | Memory Pages/sec |
UVM-PERF-109 | PerformanceAlert | Memory Cache Bytes |
UVM-PERF-112 | PerformanceAlert | Paging File % Usage |
UVM-PERF-115 | PerformanceAlert | SQL Server Batch Requests/sec |
UVM-PERF-116 | PerformanceAlert | SQL Server SQL Compilations/sec |
UVM-PERF-117 | PerformanceAlert | SQL Server SQL Re-Compilations/sec |
UVM-PERF-118 | PerformanceAlert | SQL Server User Connections |
UVM-PERF-119 | PerformanceAlert | SQL Server Lock Waits/sec |
UVM-PERF-120 | PerformanceAlert | SQL Server Page Splits/sec |
UVM-PERF-121 | PerformanceAlert | SQL Server Processes Blocked |
UVM-PERF-122 | PerformanceAlert | SQL Server Checkpoint Pages/sec |
UVM-PERF-123 | PerformanceAlert | Working Set Total |
UVM-HARDWARE-001 | HardwareFaultAlert | Battery Probe Warning |
UVM-HARDWARE-002 | HardwareFaultAlert | Battery Failure |
UVM-HARDWARE-003 | HardwareFaultAlert | Fan Probe Warning |
UVM-HARDWARE-004 | HardwareFaultAlert | Fan Probe Failure |
UVM-HARDWARE-005 | HardwareFaultAlert | Hardware Log Near Capacity |
UVM-HARDWARE-006 | HardwareFaultAlert | Hardware Log Full |
UVM-HARDWARE-007 | HardwareFaultAlert | Chassis Intrusion Detected |
UVM-HARDWARE-008 | HardwareFaultAlert | Memory Pre-failure |
UVM-HARDWARE-009 | HardwareFaultAlert | Memory Failure |
UVM-HARDWARE-010 | HardwareFaultAlert | System Power Warning |
UVM-HARDWARE-011 | HardwareFaultAlert | System Power Failure |
UVM-HARDWARE-012 | HardwareFaultAlert | Power Supply Failure |
UVM-HARDWARE-013 | HardwareFaultAlert | Power Supply Warning |
UVM-HARDWARE-014 | HardwareFaultAlert | Processor Warning (throttled) |
UVM-HARDWARE-015 | HardwareFaultAlert | Processor Failure |
UVM-HARDWARE-016 | HardwareFaultAlert | Redundancy Degraded |
UVM-HARDWARE-017 | HardwareFaultAlert | Redundancy Lost |
UVM-HARDWARE-018 | HardwareFaultAlert | Temperature Probe Warning |
UVM-HARDWARE-019 | HardwareFaultAlert | Temperature Probe Failure |
UVM-HARDWARE-020 | HardwareFaultAlert | Voltage Probe Warning |
UVM-HARDWARE-021 | HardwareFaultAlert | Voltage Probe Failure |
UVM-HARDWARE-022 | HardwareFaultAlert | Watchdog Auto System Recovery |
UVM-HARDWARE-023 | HardwareFaultAlert | Storage System Warning |
UVM-HARDWARE-024 | HardwareFaultAlert | Storage System Failure |
UVM-HARDWARE-025 | HardwareFaultAlert | Storage Controller Warning |
UVM-HARDWARE-026 | HardwareFaultAlert | Storage Controller Failure |
UVM-HARDWARE-027 | HardwareFaultAlert | Physical Disk Warning |
UVM-HARDWARE-028 | HardwareFaultAlert | Physical Disk Failure |
UVM-HARDWARE-029 | HardwareFaultAlert | Virtual Disk Warning |
UVM-HARDWARE-030 | HardwareFaultAlert | Virtual Disk Failure |
UVM-HARDWARE-031 | HardwareFaultAlert | Enclosure Warning |
UVM-HARDWARE-032 | HardwareFaultAlert | Enclosure Failure |
UVM-HARDWARE-033 | HardwareFaultAlert | Storage Controller Battery Warning |
UVM-HARDWARE-034 | HardwareFaultAlert | Storage Controller Battery Failure |
UVM-HARDWARE-035 | HardwareFaultAlert | System Peak Power |
UVM-ANTIMALWARE-001 | AntiMalwareAlert | Windows Defender malware detection |
UVM-PERFDAILY-001 | DailyPerformanceSummary | Daily performance digest summary |
UVM-GENERAL-001 | GeneralAlert | Catch-all; see eEyeEventDescription for the specific condition (authentication, boot/shutdown, anti-malware) |
eEyeEventAgentDescription
Definition: Use this object to identify the agent that sent the event.
| Field | Value |
|---|---|
| OID | 1.3.6.1.4.1.20730.1.1.1.2 |
| Syntax | OCTET STRING |
| Status | mandatory |
Valid values
| Value | Notes |
|---|---|
BTDiscovery | BeyondTrust Discovery scanner |
Retina | Legacy Retina agent |
Blink | (deprecated - Blink agent retired) |
eEye Auto-Update | (deprecated - eEye auto-update agent retired) |
Application Bus 3.0 | Fallback default when the event does not include an agent description |
normalized | EPM for Windows / EPM for Mac events |
Privileged Management Reporting | Privilege Management Reporting events |
| (database value) | Appliance Health events - value read from database; no fixed enumeration |
| (empty) | Password Safe and Application Audit events do not populate this field |
eEyeEventAgentVersion
Definition: Use this object to identify the version of the agent that sent the event.
| Field | Value |
|---|---|
| OID | 1.3.6.1.4.1.20730.1.1.1.3 |
| Syntax | OCTET STRING |
| Status | optional |
You can find this object and its OID in the MIB, and the Event populates the value. The SNMP formatter does not currently emit a varbind for this field, and the
eEyeEventAlertVARIABLES list excludes it.
eEyeEventType
| Field | Value |
|---|---|
| OID | 1.3.6.1.4.1.20730.1.1.1.4 |
| Syntax | INTEGER |
| Status | mandatory |
Valid values
| Value | Description |
|---|---|
0 | Info |
1 | Warning |
2 | Error |
eEyeEventCategory
| Field | Value |
|---|---|
| OID | 1.3.6.1.4.1.20730.1.1.1.5 |
| Syntax | OCTET STRING |
| Status | mandatory |
Definition: Use this field to identify the event category. The value varies by event source:
- EPM for Windows / EPM for Mac events: always
"pbw" - Password Safe events:
"System","Change", or"Propagation" - Privilege Management Reporting events:
"Service Starts","User Logons","Privileged Account Protection","Processes" - Appliance Health events: always
"UVMHealth"regardless of sub-type - BeyondTrust Discovery scan events: the scan engine sets this value; no fixed enumeration exists. For vulnerability findings (deprecated) it contains the vulnerability category (e.g.,
"Web","OS","Database"). For infrastructure/OS detection events, known values include:"OSDETECT","OSDETECT\Method","OSDETECT\CpeString","Traceroute","Authentication","AssetType","OriginalDNSName" - Application audit events: the system or section that generates the event
Application audit category values
| Group | Values |
|---|---|
| Authentication / Session | Login, Logout, Login Failure, Application Session, Account Lockout, Change Password, BeyondInsight Password Policy, Direct Connect, Direct Connect Failure, TOTP Authentication Failure, TOTP Device Enrolled, Client Certificate, RetinaInsight Login, RetinaInsight Login Failure |
| Password Safe | PMM Login, PMM Login Failure, PMM API SignAppIn, PMM API SignOut, PMM API SignIn Failure, PMM API SignAppIn Failure, PMM API Authentication Rule Failure, PMM API Authentication Failure, PMM API Registration, PMM Connector, PMM Change Email Template, PMM Password Rule, PMM Managed System, PMM Managed Account, PMM Functional Account, PMM Global Settings, PMM Application, PMM SSH Key Policies, PMM Access Policy, PMM Access Policy Schedule, PMM Accounts, PMM Mask, PMM Connection Profile, PMM Connection Profile Filter, PMM Cache, PMM Oracle Internet Directory, Managed Account Alias, Propagation Action |
| Secrets Safe | Secrets Safe, Secrets Safe Folder, Secrets Safe Secret |
| User / Group Management | User, User Group, User Group - Smart Rule Role, Attribute, Attribute Type, Domain, Domain Management, Authenticator |
| Asset / Scanning | Assets, Jobs, Scan, Audits and VulnerabilitiesEPM Exclusion, EPM Rule, EPM Policy, EPM Policy User |
| Configuration / Administration | Dashboard, Configure, System Options, BeyondInsight Configuration Tool, Plugin Setting, Purging Options, Worker Node, U-Series Appliance |
| Organization / Structure | Organization, Workgroup, Smart Rule, Audit Group, Port Group, Address Group, Active Directory Query, Directory Query, Network Security Rule, Shared Safe, Shared Safe Permission |
| Connectors / Integrations | Cloud Connector, Credential, Third Party Import, Third Party Connector, Third Party Credential Provider, Sailpoint STI, SCIM, Remedy Connector, Remedy Connector Mapping, ServiceNow Connector, ServiceNow Export, ServiceNow Export Mapping, ServiceNow Ticket System, ServiceNow Ticket System Mapping, ServiceNow Import, JIRA Ticket System, CPB Cloud ConnectorCPB RecommendationEventCollectorOAuth, Ticket |
| Session / Infrastructure | Session Monitoring, Session Utility, Event Forwarder, Reports, Databases, Retina Agent Scan OptionsVAAddress, VAAddresses, VAAddressGroup, ProxyConfig |
eEyeEventDescription
Definition: For Appliance Health UVM-GENERAL-001 (GeneralAlert) events, use this field to identify the specific condition, since all general events share the same ID. Known conditions include authentication access successes and failures, boot/shutdown events (clean vs. unexpected), and anti-malware notifications.
| Field | Value |
|---|---|
| OID | 1.3.6.1.4.1.20730.1.1.1.6 |
| Syntax | OCTET STRING |
| Status | mandatory |
eEyeEventSeverity
Definition: Use this object to identify the event severity, 0–9 from lowest to highest.
| Field | Value |
|---|---|
| OID | 1.3.6.1.4.1.20730.1.1.1.7 |
| Syntax | INTEGER |
| Status | mandatory |
eEyeEventSubject
Definition: Use this object to identify the event subject. Valid values are the following:
- Target IP
- Job Name
- Job ID
| Field | Value |
|---|---|
| OID | 1.3.6.1.4.1.20730.1.1.1.8 |
| Syntax | OCTET STRING |
| Status | mandatory |
eEyeEventName
| Field | Value |
|---|---|
| OID | 1.3.6.1.4.1.20730.1.1.1.9 |
| Syntax | OCTET STRING |
| Status | mandatory |
Definition: Use this object to identify the event name. The value varies by event source:
- EPM for Windows / EPM for Mac events: the numeric EventTypeId -
"28691","28692","28693","28694","28695","28696","28697","28698","28699","28701","28702","28703" - Password Safe - System events: the role used for the access request. Known values:
"Requestor","Approver","Requestor/Approver","ISA","Administrators","Built-in Admin","Session Auditor","Credentials Manager","Recorded Session Reviewer","Active Session Reviewer","Reports Auditor","SystemManagement","AccountManagement","ConfigurationManagement","PolicyManagement","AgentManagement","DomainManagement","RoleManagement","BulkPasswordChange","AdminSession","AdminSessionReviewer","AssetManagement","APIGlobalQuarantine","PBW RunAsEvent","Administrator","Non-Requestor","N/A" - Password Safe - Change events:
"Managed"(managed account),"Functional"(functional account), or"Change"(fallback) - Password Safe - Propagation events:
"Propagation" - Privilege Management Reporting events:
"400"(Service Starts),"300"(User Logons),"198"(Privileged Account Protection); Processes events use a dynamic event number read from the database - Appliance health events:
"ServiceErrorAlert"(UVM-SERVICE-*)"PerformanceAlert"(UVM-PERF-*)"HardwareFaultAlert"(UVM-HARDWARE-*)"AntiMalwareAlert"(UVM-ANTIMALWARE-*)"DailyPerformanceSummary"(UVM-PERFDAILY-*)"GeneralAlert"(UVM-GENERAL-*)
- BeyondTrust Discovery scan events: set by the scan engine; not a fixed enumeration. For vulnerability findings (deprecated) it contains the specific audit or check name (e.g., a CVE or MS bulletin ID). For scan summary and metadata events, known values include:
"Total hosts scanned","Total hosts found","Audit Group","Address Group","Credential","IP Entry","OS Detected","Traceroute","Netbios Name","Method","REM NAV","Virtual Machine Name","Virtual Machine UUID" - Application audit events: the action performed. Known values:
"Login","Logout","Add","Edit","Delete","Read","Enable","Disable","Increase Priority","Decrease Priority","Assign","Rename","Save As","Schedule","Pause Job","Resume Job","Stop Job","Delete Job","Reset","Import","Copy","Generate","Validate","Test","Update","Unlock","Download","Completed","Session End",(deprecated),"Add Vulnerability Exclusion"(deprecated),"Remove Vulnerability Exclusion""Ignore","Remove from Ignored","Download Policy JSON","Bulk Password Change","Bulk Domain Account Unlink","Bulk Move Credential","Bulk Add Credential","Bulk Read","Read Password","ReadSecret","Move Folder","Share Secret","Delete Secret Share","Delete Secret Shares","Edit Secret Share","Lock Session","Terminate Session","Default"
eEyeEventNVNumber
Definition: Use this object to identify the number of extra name-value pairs.
| Field | Value |
|---|---|
| OID | 1.3.6.1.4.1.20730.1.1.1.10 |
| Syntax | INTEGER |
| Status | mandatory |
eEyeEventNVTable
Definition: Use this object to identify the table that contains extra information. Every extra item is a name-value pair.
| Field | Value |
|---|---|
| OID | 1.3.6.1.4.1.20730.1.1.1.11 |
| Syntax | SEQUENCE OF EEyeEventNVEntry |
| Status | optional |
eEyeEventNVEntry
Definition: Use this object to identify one name-value pair, indexed by eEyeEventNVName.
| Field | Value |
|---|---|
| OID | 1.3.6.1.4.1.20730.1.1.1.11.1 |
| Status | mandatory |
eEyeEventNVName
Definition: Use this object to identify the name part of the event name-value pair.
| Field | Value |
|---|---|
| OID | 1.3.6.1.4.1.20730.1.1.1.11.1.1 |
| Syntax | OCTET STRING (SIZE 0..50) |
| Status | mandatory |
NVP keys by event source
Password Safe-System events
| Key | Description |
|---|---|
UserName | Username performing the action |
RoleUsed | Role used (see eEyeEventName for System events for valid values) |
ObjectTypeID | Numeric ID of the object type |
ObjectType | Type of object affected: "Password Rule", "Email Template", "Functional Account", "Account", "System", "Release Request", "Request Response", "Ticket System", "Password", "Isa Release", "Agent", "AccessPolicy", "Password History", "DSS Key Rule", "RemoteApp Program", "Connection Profile", "Connection Profile Filter", "Session", "Network Security Rule" |
ObjectID | Numeric ID of the affected object |
Operation | Action performed: "Unknown", "Add", "Update", "Delete", "Start", "Stop", "Shutdown", "Retrieve", "Deny", "Expire", "Approve", "Cancel", "Unlock", "SyncAccount", "DeleteSoft", "Enable", "Disable" |
Failed | 0 (success) or 1 (failure) |
Target | Target of the operation |
UserID | Numeric ID of the user |
IPAddress | IP address of the requester |
Reason | Reason provided with a ticket-based request |
TicketSystem | Ticket system name |
TicketNumber | Ticket identifier |
Approver | Approver name |
Password Safe-Change events
| Key | Description |
|---|---|
ManagedAccountID | Numeric ID of the managed account |
FunctionalAccountID | Numeric ID of the functional account |
ManagedSystemID | Numeric ID of the managed system |
ChangeDt | Date/time of the change |
ChangeReasonCd | Reason code: S (Scheduled), R (Post-release reset), T (Ticket-approved reset), V (Approval reset), F (Forced reset), M (Mismatch reset), U (Manual entry), N (Manual entry for new account), A (API change), P (EPM agent change), X (Synced with primary), Y (Un-synced from primary), Z (Forced sync with primary), O (Initial on-boarding via Smart Rule) |
Result | Change result: S (Success), F (Failed), C (Cancelled), Q (Queued), U (Schedule Update) |
ReleaseID | Associated release ID |
RequestID | Associated request ID |
AccountName | Name of the account |
NextChangeDate | Next scheduled change date |
ElevationCommand | Elevation command (if applicable) |
Password Safe-Propagation events
Same keys as Change events, plus per-action result entries for each propagation target (action type, result, target name, username).
eEyeEventNVValue
Definition: Use this object to identify the value part of the event name-value pair.
| Field | Value |
|---|---|
| OID | 1.3.6.1.4.1.20730.1.1.1.11.1.2 |
| Syntax | OCTET STRING |
| Status | mandatory |
eEyeEventSourceIP
Definition: Use this object to identify the event source IP.
| Field | Value |
|---|---|
| OID | 1.3.6.1.4.1.20730.1.1.1.12 |
| Syntax | OCTET STRING |
| Status | mandatory |
eEyeEventOS
Definition: Use this object to identify the operating system.
| Field | Value |
|---|---|
| OID | 1.3.6.1.4.1.20730.1.1.1.13 |
| Syntax | OCTET STRING |
| Status | mandatory |
eEyeEventWKLoc
Description: Use this object to identify the workgroup location.
| Field | Value |
|---|---|
| OID | 1.3.6.1.4.1.20730.1.1.1.14 |
| Syntax | OCTET STRING |
| Status | mandatory |
eEyeEventWKID
Definition: Use this object to identify the workgroup ID.
| Field | Value |
|---|---|
| OID | 1.3.6.1.4.1.20730.1.1.1.15 |
| Syntax | OCTET STRING |
| Status | mandatory |
eEyeEventWKDesc
Definition: Use this object to identify the workgroup description.
| Field | Value |
|---|---|
| OID | 1.3.6.1.4.1.20730.1.1.1.16 |
| Syntax | OCTET STRING |
| Status | mandatory |
eEyeEventClientHost
Definition: Use this object to identify the client hostname.
| Field | Value |
|---|---|
| OID | 1.3.6.1.4.1.20730.1.1.1.17 |
| Syntax | OCTET STRING |
| Status | mandatory |
eEyeEventUserName
**Definition:**Use this object to identify the user name. Valid value: System.
| Field | Value |
|---|---|
| OID | 1.3.6.1.4.1.20730.1.1.1.18 |
| Syntax | OCTET STRING |
| Status | mandatory |
eEyeEventDate
Definition: Use this object to identify the event date.
| Field | Value |
|---|---|
| OID | 1.3.6.1.4.1.20730.1.1.1.19 |
| Syntax | OCTET STRING |
| Status | mandatory |
eEyeEventTransactionGroup
Definition: Use this object to identify the transaction group.
| Field | Value |
|---|---|
| OID | 1.3.6.1.4.1.20730.1.1.1.20 |
| Syntax | OCTET STRING |
| Status | mandatory |
eEyeEventSubjectDesc
Definition: Use this object to identify the subject description. The meaning of this field varies by event source (for example: target computer name for scan events, account name for Password Safe events, user identifier for Application Audit events).
| Field | Value |
|---|---|
| OID | 1.3.6.1.4.1.20730.1.1.1.21 |
| Syntax | OCTET STRING |
| Status | optional |
The MIB defines this object and its OID, but the SNMP formatter does not currently emit a varbind for this field. The
eEyeEventAlertVARIABLES list excludes it.
eEyeEventAgentID
Definition: Use this object to identify the agent ID.
| Field | Value |
|---|---|
| OID | 1.3.6.1.4.1.20730.1.1.1.22 |
| Syntax | OCTET STRING |
| Status | mandatory |
Valid values
| Value | Notes |
|---|---|
retina | BeyondTrust Discovery / legacy Retina scan events. Value is the lowercase enum name from LegacyForwardingEventsType. The human-readable scanner label ("BTDiscovery" or "Retina") appears in eEyeEventAgentDescription, not here. |
Blink | (deprecated - Blink agent retired) |
eEye Auto-Update | (deprecated - eEye auto-update agent retired) |
AppAudit | Application Audit events |
pbw | Endpoint Privilege Management for Windows events |
pbmac | Endpoint Privilege Management for Mac events |
PBPS | Password Safe events |
pmr | Privilege Management Reporting events |
generic_appliance_health | Appliance Health events |
eEyeEventDLLVersion
Definition: Use this object to identify the DLL version.
| Field | Value |
|---|---|
| OID | 1.3.6.1.4.1.20730.1.1.1.23 |
| Syntax | OCTET STRING |
| Status | mandatory |
Trap definition
eEyeEventAlert
| Field | Value |
|---|---|
| Enterprise | eEyeNotificationMIB (1.3.6.1.4.1.20730.1) |
| Specific Trap | ::= 2 |
Use this single trap type to monitor BeyondInsight security event notifications, regardless of event source.
Trap OID behavior
- SNMPv1: The formatter does not explicitly set the enterprise OID and specific-trap field. Do not rely on the specific-trap value matching
::= 2. - SNMPv2c/v3: The formatter sets
TrapObjectID(snmpTrapOID.0) to the configuredtrapOid, which defaults to1.3.6.1.4.1.20730.1. This does not follow the RFC 2576 translation rule that would derive1.3.6.1.4.1.20730.1.0.2from the::= 2assignment. Match on1.3.6.1.4.1.20730.1rather than on the TRAP-TYPE-derived OID.
To identify the event source, examine the eEyeEventAgentID varbind (e.g., 'retina', 'PBPS', 'pbw', 'pbmac', 'AppAudit', 'pmr', 'generic_appliance_health'). To identify the event type within a source, examine the eEyeEventID varbind.
Variables (varbinds included in every trap)
| # | Object | OID |
|---|---|---|
| 1 | eEyeEventID | 1.3.6.1.4.1.20730.1.1.1.1 |
| 2 | eEyeEventAgentDescription | 1.3.6.1.4.1.20730.1.1.1.2 |
| 3 | eEyeEventType | 1.3.6.1.4.1.20730.1.1.1.4 |
| 4 | eEyeEventCategory | 1.3.6.1.4.1.20730.1.1.1.5 |
| 5 | eEyeEventDescription | 1.3.6.1.4.1.20730.1.1.1.6 |
| 6 | eEyeEventSeverity | 1.3.6.1.4.1.20730.1.1.1.7 |
| 7 | eEyeEventSubject | 1.3.6.1.4.1.20730.1.1.1.8 |
| 8 | eEyeEventName | 1.3.6.1.4.1.20730.1.1.1.9 |
| 9 | eEyeEventNVNumber | 1.3.6.1.4.1.20730.1.1.1.10 |
| 10 | eEyeEventNVName | 1.3.6.1.4.1.20730.1.1.1.11.1.1 |
| 11 | eEyeEventNVValue | 1.3.6.1.4.1.20730.1.1.1.11.1.2 |
| 12 | eEyeEventSourceIP | 1.3.6.1.4.1.20730.1.1.1.12 |
| 13 | eEyeEventOS | 1.3.6.1.4.1.20730.1.1.1.13 |
| 14 | eEyeEventWKLoc | 1.3.6.1.4.1.20730.1.1.1.14 |
| 15 | eEyeEventWKID | 1.3.6.1.4.1.20730.1.1.1.15 |
| 16 | eEyeEventWKDesc | 1.3.6.1.4.1.20730.1.1.1.16 |
| 17 | eEyeEventClientHost | 1.3.6.1.4.1.20730.1.1.1.17 |
| 18 | eEyeEventUserName | 1.3.6.1.4.1.20730.1.1.1.18 |
| 19 | eEyeEventDate | 1.3.6.1.4.1.20730.1.1.1.19 |
| 20 | eEyeEventTransactionGroup | 1.3.6.1.4.1.20730.1.1.1.20 |
| 21 | eEyeEventAgentID | 1.3.6.1.4.1.20730.1.1.1.22 |
| 22 | eEyeEventDLLVersion | 1.3.6.1.4.1.20730.1.1.1.23 |
The MIB defineseEyeEventUniqueID(OID.0),eEyeEventAgentVersion(OID.3), andeEyeEventSubjectDesc(OID.21`), but the VARIABLES list above excludes them. The SNMP formatter does not currently emit varbinds for these fields.
Updated about 2 hours ago
