The classes and attributes can be used with Syslog, to pre-load possibilities on the Syslog server to trigger alerts.
Common Log Attributes
The following attributes are commonly used in Log messages.
Attribute | Type | Description |
Action | ChangeAction | The action:
|
CloudSyncDirection | String | The sync direction:
|
GenericRC | String | The return code:
|
id | Integer | The log ID number. |
protocol | SessionSource | The protocol for the event:
|
RepliType | String | The replication type:
|
source | String | The entity that sent the event log. |
sourceType | LogSourceType | The type of entity that sent the event log:
This attribute is optional. |
SyncMode | String | The sync mode:
|
time | dateTime | The date and time at which the event occurred. |
username | String | The administrator or user who triggered the event. |
Log Classes
Emergency Messages
Message | Class | Attributes |
|---|---|---|
RAID array has failed | ArrayFailed | name (String) |
Alert Messages
Message | Class | Attributes |
|---|---|---|
A storage volume is full | VolumeCriticallyFull | volume (String) usage (String) freeSpace (String) |
Active Directory connection failed: Clock skew error - Device clock and AD clock are out of sync | ADConnClockSkewError | Optional: domain (String) |
Agent did not complete a backup for a long time | AgentSyncFailed | name (String) days (Integer) |
Agent software updates will not be performed | AgentRepositoryNotReady | reason (String) |
Antivirus inoperable | AntivirusInoperable | details (String) |
Array contains a disk which is unsafe for RAID: SCT Error Recovery Control is unsupported | DiskNotCompatibleForRAID | array (String) disk (String) |
Background Download disabled due to full disk space | StorageFullBgDownloadDisabled | volume (String) usage (String) freespace (String) |
Caching Gateway is in critical condition: Too much data in non-evictable folders. Please increase cache size or reduce size of pinned folders. | TooMuchDataInNonEvictableFolders | Details (String) |
CIFS connections has almost reached the limit | CIFSLimitAlmostReached | usage (String) limit (String) |
Cloud backup has not succeeded for a long time | CloudBackupFailed | LastSuccess (dateTime) lastBackupError (String) |
Cloud Sync: Add directory watch failed | SyncLinuxAddWatchFailed | details (String) |
Cloud sync did not succeed for a long time | CloudSyncFailed | — |
Connection to cloud services has not succeeded for a long time | CloudConnectFailed | serverName (String) downSince (dateTime) |
Consistency errors were detected in volume. Run the Volume Repair Wizard | VolumeContainErrors | volume (String) |
Device clock and Portal clock are out of sync. Cloud Drive synchronization disabled | ClocksOutOfSync | localClock (dateTime) portalClock (dateTime) |
Device clock and portal clock are out of sync. Cloud Drive synchronization disabled | DeviceClockOutOfSyncError | localClock (dateTime) portalClock (dateTime) |
Disk has failed S.M.A.R.T health test | DiskFailedHealthTest | name (String) model (String) |
Disk has failed S.M.A.R.T test | DiskFailedSMARTTest | name (String) model (String) |
Download disabled due to almost critical disk space | StorageFullAllDownloadsDisabled | volume (String) usage (String) freespace (String |
Exceeding the maximum amount of synchronized directories. Some local changes may not be synchronized | SyncLinuxMaxUserWatchesExceeded | details (String) |
RAID array is running in degraded mode | ArrayDegraded | name (String) Optional: failedDisks (String) |
Replication task did not succeed for a long time | SyncFailed | name (String) days (Integer) |
Report ransomware detected | RansomwareIncident | Optional: UserName (String) IP (String) startTime (dateTime) endTime (dateTime) ConfidenceLevel (String) |
Synchronization stopped due to critical disk space | StorageEmergencyModeEntered | volume (String) usage (String) freespace (String) |
Throttling writes due to low space in cache volume. | ThrottlingWritesAlert | Details (String) |
Too much data was marked as available offline. Please increase the cache size in settings | TooMuchDataAsAvaliableOffline | Details (String) |
Unable to store logs to log volume | FailedToStoreLog | — |
UPS device reported low battery | UPSDeviceLowBattery | model (String) |
UPS device reported low battery; Safely shutting down | UPSDeviceShutDown | model (String) |
Error Messages
Message | Class | Attributes |
|---|---|---|
— | OperationErrorDetails | snapshot (String) Optional: filename (String) Optional: path (String) resultCode (GenericRC) resultMsg (String) |
Antivirus error | AntivirusError | details (String) |
Antivirus malware DB failure | AntivirusDBError | details (String) |
Antivirus malware DB update error | AntivirusUpdateFailure | details (String) |
Automatic share creation process failed | AutoShareCreationFailed | share (String) reason (String) |
Backup completed with errors | BackupFailed | syncMode (SyncMode) startTime (dateTime) executionMode (ExecutionMode) resultCode (GenericRC) resultMsg (String) totalFiles (Integer) totalSize (Integer) changedFiles (Integer) changedSize (Integer transferredFiles (Integer) transferredSize (Integer) Optional: snapshot (String) |
Cloud Sync: Full scan failed | FullScanFailed | details (String) |
CloudSync state changed to Upload Stalled | StallInUploadError | Details (String) |
Disk-level backup failed | BMTaskFailed | Name (String) startTime (dateTime) executionMode (ExecutionMode) resultCode (GenericRC) resultMsg (String) totalFiles (Integer) totalSize (Integer) transferredFiles (Integer) transferredSize (Integer) syncid (String) syncMode (SyncMode) Default value: Backup syncType (RepliType) Default value: Disk-level |
Download failed | DownloadFailed | Optional: protocol (SessionSource) Optional: clientAddr (String) file (String) |
Error | Error | details (String) |
Error Message | ErrorLog | details (String) |
Failed mounting the volume. Please try upgrading your firmware | MountFailed | Optional: volume (String) fsType (String) |
Failed running storage command | StorageCommandFailed | command (String) |
Failed sending alert. Please check your configuration | FailedSendingAlertToAll | — |
Failed sending alert to specified recipient | FailedSendingAlertToRecipient | recipient (String) |
Failed to save the configuration file | DBNotSaved | — |
File system contains errors that could not be fixed | FSCKCompletedWithPersistentErrors | volume (String) |
File system contains errors that were left unfixed | FSCKCompletedWithErrors | volume (String) |
File transfer failed | CloudSyncFileTransferFailed | backupFileStatus (BackupFileStatus) Default value: Failed direction (CloudSyncDirection) Optional: folderID (Integer) Optional: folderName (String) filename (String) Optional: path (String) startTime (dateTime) endTime (dateTime) resultCode (GenericRC) resultMsg (String) totalBlocks (Integer) transferedBlocks (Integer) totalSize (Integer) transferedSize (Integer) Optional: folderOwner (String) |
Local backup failed | ReplicationTaskFailed | Name (String) startTime (dateTime) executionMode (ExecutionMode) resultCode (GenericRC) resultMsg (String) totalFiles (Integer) totalSize (Integer) transferredFiles (Integer) transferredSize (Integer) syncid (String) syncMode (SyncMode) Default value: Backup syncType (RepliType) Default value: Sync |
No certificate is installed | CertificateFailed | — |
Populate stub folder failed | PopulateFolderFailed | Details(String) |
Post-backup operation failed | PostBackupFailed | operation (String) error (String) |
Pre-backup operation failed | PreBackupFailed | operation (String) error (String) |
Quarantine clear failed | QuarantineClearFailure | details (String) |
Quarantine file delete failed | QuarantineFileDeleteFailure | filename (String) details (String) |
Quarantine file failed | QuarantineFileFailure | filename (String) details (String) |
Quarantine restore failed | QuarantineFileRestoreFailure | filename (String) details (String) |
Retrieve Files From Path Mechanism Error | RetrieveFilesFromPathError | Details (String) |
Service Failure | ServiceFailureEvent | servicename (String) |
SMTP server cannot be contacted | SMTPServerProblem | description (String) |
Unplanned event | UnplannedEvent | details (String) |
VSS writer error | VSSWriterFailed | mainError (String) writer (String) writerError (String) |
Warning Messages
Message | Class | Attributes |
|---|---|---|
— | OperationWarningDetails | snapshot (String) Optional: filename (String) Optional: path (String) resultCode (GenericRC) resultMsg (String) |
A storage volume is full | VolumeFull | volume (String) Usage (String) freespace (String) |
A storage volume is nearly full | VolumeNearlyFull | volume (String) Usage (String) freespace (String) |
Active Directory connection failed: Domain join operation required | ADConnLocalError | domain (String) |
Active Directory connection failed: Network error | ADConnTransientError | domain (String) |
Agent failed to log in | AgentLoginFailed | hostname (String) Optional: protocol (SessionSource) Optional: clientAddr (String) |
Backing up without creating a snapshot | BackupNoSnapshot | reason (String) |
Backup completed with warnings | BackupEndedWithWarnings | syncMode (SyncMode) startTime (dateTime) executionMode (ExecutionMode) resultCode (GenericRC) resultMsg (String) totalFiles (Integer) totalSize (Integer) changedFiles (Integer) changedSize (Integer) transferredFiles (Integer) transferredSize (Integer) snapshot (String) |
Cache is full but no files could be evicted | DeviceNotificationCacheIsFull | Details (String) |
Cloud Sync: Full scan failed | FullScanFailedWarning | details (String) |
Cloud Sync: Overflow in FS listener | SyncListenerOverflow | details (String) |
CloudSync: Verify sync completed with warnings | VerifySyncCompletedWarning | Details (String) |
Connection to portal failed | ConnectionToPortalFailed | name (String) Optional: ip (iNetAddr) reason (String) retry (Integer) nextRetryDelay (Integer) |
Detected a disk with more than one partition. Using only the first one. | MoreThanOnePartition | port (String) |
Disk has a SMART attribute which exceeded its threshold | SMARTAttributeThresholdExceeded | diskName (String) model (String) attribute (String) |
Disk-level backup completed with errors | BMTaskEndedWithErrors | Name (String) startTime (dateTime) executionMode (ExecutionMode) resultCode (GenericRC) resultMsg (String) totalFiles (Integer) totalSize (Integer) transferredFiles (Integer) transferredSize (Integer) syncid (String) syncMode (SyncMode) Default value: Backup syncType (RepliType) Default value: Disk-level |
Event log was corrupted and reset | LogDBReset | details (String) |
File rejected by Cloud Drive policy | FileRejectedLog | Optional: protocol (SessionSource) Optional: clientAddr (String) path (String) Optional: action (Action) |
File synchronization failed | FileSyncFailed | snapshot (String) filename (String) path (String) resultCode (GenericRC) resultMsg (String) Optional: retry (String) |
File system contained errors, but they were fixed successfully | FSCKCompletedFixed | volume (String) |
File system global change watch is disabled. Using recursive directory watches | GlobalChangeWatchDisabled | — |
File transfer failed | FileTransferFailed | backupFileStatus (BackupFileStatus) Default value: Failed snapshot (String) Optional: filename (String) Optional: path (String) startTime (dateTime) endTime (dateTime) resultCode (GenericRC) resultMsg (String) totalBlocks (Integer) transferedBlocks (Integer) totalSize (Integer) transferedSize (Integer) |
Found a duplicate array name. Renaming the new array | DuplicateArrayName | oldName (String) newName (String) |
Found a duplicate volume name. Renaming the new volume | DuplicateVolumeName | oldName (String) newName (String) |
Found a volume with an invalid name. Renaming the volume | IllegalVolumeName | oldName (String) newName (String) |
Ignoring volume with duplicate volume name | IgnoreVolumeWithDuplicateVolName | volumeName (String) volumeType (String) |
Import failed | ImportFailed | — |
Infected file found | QuarantinedLog | Optional: logAction (String) path (String) fileName (String) Optional: macAddress (String) Optional: threat (String) Optional: threatAction (String) |
Kernel Message | KernelLog | details (String) |
Local Backup completed with errors | ReplicationTaskEndedWithErrors | Name (String) startTime (dateTime) executionMode (ExecutionMode) resultCode (GenericRC) resultMsg (String) totalFiles (Integer) totalSize (Integer) transferredFiles (Integer) transferredSize (Integer) syncid (String) syncMode (SyncMode) Default value: Backup syncType (RepliType) Default value: Sync |
Log storage location is not available. Storing logs in memory | LogVolumeNotReady | configuredVolume (String) |
Network Generic Error | NetworkGenericError | Optional: arg (String) |
Persistent change journal is disabled. File system scan is required | PersistentChangeJournalDisabled | — |
Received NFS request for an invalid path | NfsBadPath | request (String) host (String) path (String) |
Received NFS request for path that is not exported to NFS | NfsNoEntry NfsNotExported | request (String) host (String) path (String) |
Received NFS request from unauthorized client | NfsUnknownHost | request (String) host (String) path (String) |
Received NFS request on an illegal port | NfsIllegalPort | request (String) host (String) path (String) port (String) |
Redundant power supply is currently OFFLINE. Operating in single PSU mode | RedundantPSUFailed | — |
Removing an illegal array element from the configuration file | RemoveArrayElement | type (String) problem (String) |
Repair stopped | FSCKStopped | volume (String) cause (String) |
Resetting the configuration field to defaults | ResetField | field (String) problem (String) |
Resetting the configuration to defaults | ResetDB | — |
Resource Usage Limit Exceeded | ResourceUsageEvent | eventname (String) description (String) |
Send Keep-Alive alert | SendKeepAliveError | details (String) |
SMB connection dropped | CIFSConnDropped | cause (String) |
System is low on memory | LowMemory | — |
This device is unlicensed | DeviceUnlicensed | reason (String) |
Upload request denied | UploadRequestDenied | Optional: protocol (SessionSource) Optional: clientAddr (String) file (String) |
UPS device running on battery | UPSDeviceOnBattery | model (String) |
User failed to log in | UserLoggedInFailed | Optional: protocol (SessionSource) Optional: clientAddr (String) Optional: reason (String) |
User failed to log in to FTP server(too many active sessions) | FTPUserLoginFailedMaxSession | maxSessions (Integer) |
Virus detected | VirusDetected | filename (String) folder (String) virusname (String) |
Wake on LAN error | WakeOnLanError | Optional: subj (String) Optional: IP (String) MAC (String) Optional: errno (Integer) Optional: strerror (String) |
Warning | Warning | details (String) |
Notice Messages
Message | Class | Attributes |
|---|---|---|
Agent connected | AgentConnected | hostname (String) Optional: protocol (SessionSource) Optional: clientAddr (String) |
Agent disconnected | AgentDisconnected | hostname (String) Optional: protocol (SessionSource) Optional: clientAddr (String) |
Agent started up | AgentStartedUp | — |
Agent version changed | AgentVersionChanged | previous (String) current (String) |
Antivirus configuration changed | AntivirusConfigChange | details (String) |
Array status changed | ArrayStatusChanged | arrayName (String) status (RAIDState) |
Backup completed successfully | BackupEnded | syncMode (SyncMode) startTime (dateTime) executionMode (ExecutionMode) resultCode (GenericRC) resultMsg (String) totalFiles (Integer) totalSize (Integer) changedFiles (Integer) changedSize (Integer transferredFiles (Integer) transferredSize (Integer) snapshot (String) |
Configuration Changed | AuditLog | Setting (String) Action (ChangeAction) Optional: Name (String) |
Configuration Changed | DeepAuditLog | Section (String) Action (ChangeAction) ActionResult (ActionResult) Optional: FailureReason (String) Optional: Uri (String) Optional: SessionID (String) Optional: details (String) |
Connected to network | NetworkConnected | port (String) address (ip) |
Connected to portal | ConnectedToPortal | name (String) ip (ip) |
Device certificate was updated | CertificateUpdated | SHA1Fingerprint (String) |
Device main service restarted | DeviceRestarted | — |
Device restarted | RebootLog | — |
Device shut down | ShutdownLog | — |
Device started up | DeviceStartedUp | — |
Disconnected from network | NetworkDisconnected | port (String) duration (duration) |
Disconnected from portal | DisconnectedFromPortal | name (String) ip (ip) |
Disk plugged in | DiskPlugInLog | port (String) |
Disk unplugged | DiskUnPlugLog | port (String) |
Disk-level backup completed | BMTaskEnded | Name (String) startTime (dateTime) executionMode (ExecutionMode) resultCode (GenericRC) resultMsg (String) totalFiles (Integer) totalSize (Integer) transferredFiles (Integer) transferredSize (Integer) syncid (String) syncMode (SyncMode) Default value: Backup syncType (RepliType) Default value: Disk-level |
Eviction Initiated | EvictorInitiated | Details (String) Action (ChangeAction) Optional: Name (String) |
Firmware version changed | FirmwareChanged | previous (String) current (String) |
Import succeeded | ImportSucceeded | — |
Local Backup completed | ReplicationTaskEnded | Name (String) startTime (dateTime) executionMode (ExecutionMode) resultCode (GenericRC) resultMsg (String) totalFiles (Integer) totalSize (Integer) transferredFiles (Integer) transferredSize (Integer) syncid (String) syncMode (SyncMode) Default value: Backup syncType (RepliType) Default value: Sync |
Local Dedup disabled. Requires restart. | DedupDisabled | — |
Local Dedup enabled. Requires restart. | DedupEnabled | — |
Local Quota has been disabled. The change will be applied after suspending and then unsuspending syncing with the portal. | QuotaDisabled | — |
Local Quota has been enabled. The change will be applied after suspending and then unsuspending syncing with the portal. | QuotaEnabled | — |
Notice | Notice | details (String) |
Permanent Delete completed successfully | PermanentDeleteEnded | reason (strWithoutSpecial) initiator (String) startTime (dateTime) resultCode (GenericRC) deletedFiles (Integer) logTaskId (String) |
Snapshots changed | SnapshotAuditLog | Setting (String) Action (ChangeAction) Optional: Name (String) Optional: Volume (String) Optional: Comment (String) |
System time was updated by the NTP server | NTPTimeUpdate | newTime (String) oldTime (String) |
Task Finished | BGTaskFinished | Details (String) Action (ChangeAction) Optional: Name (String) |
Task Initiated | BGTaskInitiated | Details (String) Action (ChangeAction) Optional: Name (String) |
User logged in | UserLoggedIn | Optional: protocol (SessionSource) Optional: clientAddr (String) Optional: share (String) |
User logged out | UserLoggedOut | Optional: protocol (SessionSource) Optional: clientAddr (String) |
Virus definitions database updated | VirusDBUpdated | mainVer (String) dailyVer (String) |
WaterMark Memory Configuration Change | WaterMarkConfigurationChange | Details (String) Action (ChangeAction) Optional: Name (String) |
Info Messages
Message | Class | Attributes |
|---|---|---|
— | OperationInfoDetails | snapshot (String) Optional: filename (String) Optional: path (String) resultCode (GenericRC) resultMsg (String) |
Antivirus is running | AntivirusRunning | — |
Antivirus malware DB changed | AntivirusUpdateChanged | — |
Antivirus malware DB update initiated | AntivirusUpdateManualCheck | — |
Automatic Support Report Configuration change | AutoSupportConfigChange | Action (Action) Setting(String) |
Background Download resumed after exiting full disk space condition | StorageFullBgDownloadEnabled | volume (String) usage (String) freeSpace (String) |
Both power supplies are currently ONLINE. Operating in dual PSU mode | RedundantPSUOnline | — |
Cloud Sync: Full scan completed successfully | FullScanCompleted | details (String) |
Cloud Sync: Started full scan | FullScanStarted | details (String) |
CloudSync.db rename | RenameCloudSyncDB | Details (String) |
CloudSync state changed to normal | ExitedStalledStatus | Details (String) |
CloudSync: Verify sync completed successfully | VerifySyncCompleted | Details (String) |
CloudSync: Verify sync started | VerifySyncStarted | Details (String) |
CloudSync: Verify sync stopped | VerifySyncStopped | Details (String) |
Connected to Active Directory domain | ADConnOK | domain (String) |
Download completed | DownloadCompleted | Optional: protocol (SessionSource) Optional: clientAddr (String) file (String) |
Downloaded new Agent version | DownloadedAgentFirmware | type (String) version (String) |
Download resumed after exiting almost critical disk space condition | StorageFullDownloadEnabled | volume (String) usage (String) freeSpace (String) |
File system recovered after unclean shutdown | FSCKRecoveryCompleted | volume (String) |
File transferred | CloudSyncFileTransferred | backupFileStatus (BackupFileStatus) Default value: Updated direction (CloudSyncDirection) Optional: folderID (Integer) Optional: folderName (String) filename (String) Optional: path (String) startTime (dateTime) endTime (dateTime) resultCode (GenericRC) Optional: resultMsg (String) totalBlocks (Integer) transferedBlocks (Integer) totalSize (Integer) transferedSize (Integer) Optional: folderOwner (String) |
File transferred | FileTransferred | backupFileStatus (BackupFileStatus) Default value: Updated snapshot (String) filename (String) Optional: path (String) startTime (dateTime) endTime (dateTime) resultCode (GenericRC) Optional: resultMsg (String) totalBlocks (Integer) transferedBlocks (Integer) totalSize (Integer) transferedSize (Integer) |
Finished array syncing | ArraySyncFinish | Optional: Arr (String) |
Infection Caught | InfectionEvent | filename (String) infection (String) |
Info | Info | details (String) |
Instant Disaster Recovery disabled | InstantDRDisabled | — |
Instant Disaster Recovery enabled | InstantDREnabled | — |
Periodic antivirus malware DB update initiated | AntivirusUpdateAutomaticCheck | — |
Quarantine | QuarantineEvent | filename (String) infection (String) |
Quarantine clear | QuarantineClear | — |
Quarantine file delete | QuarantineFileDelete | filename (String) success (String) |
Quarantine restore | QuarantineFileRestore | filename (String) success (String) |
Ransom Protect: blocked user disconnected | RansomProtectBlockedUserDisconnect | User (String) UID (String) IP (ip) Services (String) |
Ransom Protect: excluded user disconnected | RansomProtectExcludedUserDisconnect | User (String) UID (String) IP (ip) Services (String) |
Ransom Protect: see More Information | RansomProtectDisconnectSummary | InitiatorUser (String) ClosedSessions (String) IPs (String) |
Received NFS request from authenticated client | NfsAuth | request (String) host (String) path (String) |
Repair completed successfully without errors | FSCKCompletedNoErrors | volume (String) |
replication file | ReplicationFile | backupFileStatus (BackupFileStatus) Default value: Updated snapshot (String) filename (String) Optional: path (String) resultCode (GenericRC) Optional: resultMsg (String) |
Starting array syncing | ArraySyncStart | Optional: Arr (String) |
Synchronization resumed after exiting critical disk space condition | StorageEmergencyModeExited | volume (String) usage (String) freeSpace (String) |
UPS device attached | UPSDeviceAttached | model (String) |
UPS device detached | UPSDeviceDetached | model (String) |
UPS device running on AC power | UPSDeviceOnACPower | model (String) |
Using local license - not requesting from portal | DeviceLocalLicensed | type (String) |
Volume transferred | VolumeTransferred | snapshot (String) filename (String) volTotalSize (Integer) transferred (Integer) incremental (Integer) resultCode (GenericRC) Optional: resultMsg (String) totalBlocks (Integer) transferedBlocks (Integer) totalSize (Integer) transferedSize (Integer) |
Wake on LAN succeeded | WakeOnLanSuccess | Optional: IP (String) Optional: MAC (String) Optional: more (Integer) |
Debug Messages
Message | Class | Attributes |
|---|---|---|
Antivirus malware DB: no changes | AntivirusUpdateNoChange | — |
Cloud Cache | EvictorNotification | Status (String) |
Debug Message | DebugLog | details (String) |
Error Message | ErrorLog | details (String) |
Failed connecting to a domain controller | DomainControllerConnFail | domain (String) server (String |
Informational Message | InfoLog | details (String) |
Local Backup started | ReplicationTaskStarted | Name (String) syncid (String) syncMode (SyncMode) Default value: Backup syncType (RepliType) Default value: Sync |
Log Dropped | LogDropped | Optional: Class (String) Optional: Field (String) |
Removing a deprecated configuration field from the configuration file | RemoveField | field (String) |
Warning Message | WarningLog | details (String) |