Notification Messages Explained
Review the following tables for detailed explanations of the notification and event messages.
Notification Messages
| Notification Type | Notification Trigger |
|---|---|
| Agent Error | Connection issues, mostly seen with agentless devices that Netwrix Change Tracker can't discover. |
| Audit (System Config Change) | When a user changes a setting in system settings, such as password requirements, emails, etc. |
| Audit (Template Change) | When a user uploads or modifies a new template. |
| Audit (User Admin) | When a user adds or deletes an account, or modifies roles, such as email address, two-factor authentication, etc. |
| System Error | When an event's details show signs of tampering, for example, a failed hash check. |
| Audit (Device Admin) | A new device registers, a user deletes a device, or a device's group membership changes. |
| Audit (Device Details Change) | Audit of a change in agent machine name, IP address, version, etc. |
Event Messages
| Event Message | Description |
|---|---|
Your backup scheduled at <date> is complete. | Netwrix Change Tracker generates this notification message when a scheduled backup finishes successfully. Backup types vary from full backups to individual sections of the software, for example, Planned Changes or Events. |
Your backup scheduled at <date> encountered an error. (+ error here) | Netwrix Change Tracker generates this notification message when a scheduled backup finishes with errors. The events description displays the error message, which Netwrix Support may use to resolve the issue. |
Your restore scheduled at <date> is complete. | Netwrix Change Tracker generates this notification message when a scheduled restore finishes successfully. Restore types vary from full backups to individual sections of the software, for example, Planned Changes or Events. |
Your restore scheduled at <date> encountered an error. (+ error here) | Netwrix Change Tracker generates this notification message when a scheduled restore finishes with errors. The events description displays the error message, which Netwrix Support may use to resolve the issue. |
Scheduled Query document size exceeds 16mb. Consider altering the saved query schedule or filter options to produce fewer results. [<query name>] | Netwrix Change Tracker generates this notification message when a report collated from the results of a saved query is too large. Reconfigure the query schedule to include fewer days or fewer event types; being more specific produces fewer results. |
| Netwrix Change Tracker™ - Group Report Results (Scheduled compliance report run change details) | Netwrix Change Tracker generates this notification message when a scheduled report assigned to a Change Tracker group has completed. To receive this notification, configure a user's notification settings for the group (for example, Windows 2012 R2) and set the notification type to 'Group Report Ready'. |
Moved <count> events from failover event queue to primary event queue. | Netwrix Change Tracker generates this notification message when it moves events from a temporary failover queue back to the primary queue. It dynamically creates a temporary queue for redundancy if the primary queue fails. |
Moved <count> backgrounds tasks from repository to queue | Netwrix Change Tracker generates this notification message when it moves background tasks from a temporary failover queue back to the primary queue. It dynamically creates a temporary queue for redundancy if the primary queue fails. |
Event Pipeline component down [<Component Name>]. | Netwrix Change Tracker generates this notification message when a component fails. A component is a Change Tracker repository or queue. |
Event Pipeline component is back up [<Component Name>] | Netwrix Change Tracker generates this notification message when a component recovers. A component is a Change Tracker™ repository or queue. |
Error disaggregating rule result data for event <event id>, task <task id> | Netwrix Change Tracker generates this notification message when a rule from a compliance report errors during presentation to the events list. |
<Device Event Description> | Netwrix Change Tracker generates this notification message when a device changes, altering a file or setting that was part of the agent's original baseline. Events appear for all trackers enabled through the configuration template attached to the device, for example, FIM, file content, registry, or audit policy changes. |
<Alert Event Description> | Netwrix Change Tracker generates this notification message when a value included in the configuration template is missing on the monitored machine. For example, a tracked registry key is missing on a 2012 R2 Server (Tracked registry value missing: ScreenSaveActive on HKEY_USERS) |
<Audit Event Description> | Netwrix Change Tracker generates this notification message when a registered agent's details change. For example, a device joins or leaves a group, the agent's IP address changes, or the agent's version number changes. |
<Planned change name> started | Netwrix Change Tracker generates this notification message when a scheduled planned change window opens. |
<Planned change name> ended | Netwrix Change Tracker generates this notification message when a scheduled planned change window closes. |
Device Online: <device name> | Netwrix Change Tracker generates this notification message when a device starts communicating with Change Tracker. |
Device Offline: <device name> | Netwrix Change Tracker generates this notification message when a device stops communicating with Change Tracker. |
New device registered: <device name> | Netwrix Change Tracker generates this notification message when a new device registers with the Change Tracker server for the first time. You should see this message only once per device. |
| Tests syslog message from Change Tracker server | Netwrix Change Tracker generates this notification message when the Change Tracker server sends a test syslog message to your specified syslog collector. This test confirms that Change Tracker can successfully forward captured events. |