The following is the list of system log messages. Each log message includes the following types of information:
- Log Category - The Severity Level of the log.
- Log ID - The Event ID of the log.
- Log Message - Description about the log.
Log Category | Log ID | Log Message | Notes |
---|---|---|---|
SYSTEM | |||
LOG_NOTICE | 1003 | Mem Start: SCB <Start Address>, Low <Start Address>, High <Start Address> | |
LOG_INFO | 1012 | EVENTID_SYS_SHUTDOWN - Secure Traffic Manager is exiting | |
LOG_CRIT | 1013 | System startup failed at initializing: <stage>. Switching to maintenance mode | |
LOG_NOTICE | 1024 | Activate: Default boot image set to <Image Name> | |
LOG_ALERT | 1119 | (System is getting real hot) or (Possible overheating at device <device-name> temp reading=<temp in 'C>) | |
LOG_INFO | 1122 | This Hardware =<component-name> is not on the Board | |
LOG_ALERT | 1125 | SBC PII temp overshoot. | |
LOG_ALERT | 1126 | System highest temp has reached = <External temp 'C> <Internal Temp in 'C> | |
LOG_ALERT | 1128 | In Fan Group <Group ID> Fan <Fan ID> is Running at <Current Value> rps which is less than expected <default value> | |
LOG_NOTICE | 1130 | HW: Changing FAN speed <Old Value> -> <New Value> TempReadings (<Max internal 'C> <Max External temp in 'C>]) | |
LOG_NOTICE | 1203 | SBC FAN <fan-name> detected rpm = <rpm value> | |
LOG_WARN | 41001 | Cookie Encryption Key is going to expire within <Number> days", REMAINING_DAYS_FOR_EXPIRY( pSharedKey->keyExpiryTimeout,curTimeInSecs) | |
MONITOR | |||
LOG_CRIT | 1014 | [MON]: Shutting down all services | |
LOG_NOTICE | 1014 | [MON]: Shutting down services completed | |
LOG_NOTICE | 1015 | [MON]: Restarting services | |
LOG_NOTICE | 1015 | [MON]: Restarting services completed | |
LOG_ERROR | 27001 | SetMonitorAttributes: NULL monitor id\n | |
LOG_INFO | 27001 | SetMonitorAttributes: monitor (id 0x<internal-handle>) already exists. Deleting it | |
LOG_INFO | 27002 | Monitor (0x<internal-handle> - <IP:Port>) status is FEHC_INACTIVE | |
LOG_INFO | 27002 | Monitor (0x<internal-handle>) to <IP:Port> freed | |
ARP | |||
LOG_WARN | 4011 | arprequest for <IP Address> failed with no memory | |
LOG_INFO | 4012 | ether address is broadcast for IP address <IP Address> | |
LOG_ERROR | 4013 | <Host IP Address> is using my IP address <IP Address> | |
LOG_ERROR | 4014 | Failed to find route for arp response to client <IP Address> | |
LOG_WARN | 4015 | arp: <MAC Address> attempts to modify permanent entry for <IP Address> on <Interface Name> | |
LOG_WARN | 4016 | arp_rtrequest: bad gateway value | |
LOG_ERROR | 4017 | arpresolve: can't allocate info for <IP Address>, rt=<route> | |
LOG_ERROR | 4017 | arp_rtrequest: malloc failed | |
CACHING (CACHE) | |||
LOG_NOTICE | 6001 | System Low on Memory: Adjusting Cache Parameters - Current Max:<Max Size>, High:<High Water Mark>, Safe<Safe Water Mark> | |
LOG_NOTICE | 6001 | System Low on Memory: Adjusting Cache Parameters - New Max:<Max Size>, High:<High Water Mark>, Safe<Safe Water Mark> | |
LOG_NOTICE | 6002 | Cache Purged | |
LOG_NOTICE | 6003 | Cache purge failed: instance <Count>, thid <Thread ID>, table <Table ID>, target <Size>, collected <Freed Size> | |
LOAD BALANCER (LB) | |||
LOG_ALERT | 7005 | Server <IP Address>:<Port> is enabled | |
LOG_ALERT | 7006 | Server <IP Address>:<Port> is disabled. New mode <Operational Mode> | |
LOG_NOTICE | 7007 | Server <IP Address>:<Port> is created | |
LOG_ALERT | 7008 | Server <IP Address>:<Port> is deleted | |
WEBLOG | |||
LOG_WARN | 9001 | Configurations for start or stop time *MAY* not be proper. | |
LOG_ERROR | 9003 | Error: Unable to establish control connection. | |
LOG_ERROR | 9004 | Error: Unable to establish data connection | |
LOG_ERROR | 9005 | Error: Unable to establish ssl control connection | |
LOG_ERROR | 9006 | Error: Unable to authenticate the user | |
LOG_ERROR | 9007 | Error: Unable to transfer data to ftp server: <IP Address> | |
LOG_ERROR | 9009 | Connection to <IP Address> failed, error code = <Error Code> | |
LOG_ERROR | 9009 | SSL Connection to <IP Address> failed | |
LOG_ERROR | 9010 | Out of memory for formatting logs | |
LOG_INFO | 9011 | ---- START OF LOG STATS FOR LOGS EXPORTED TO <IP Address>:<Port> ---- | |
LOG_INFO | 9011 | Connection to <IP Address>failed, error code =<Error Code> | |
LOG_INFO | 9011 | Total number of logs: <Number> | |
LOG_INFO | 9011 | Total number of formatted: <Number> | |
LOG_INFO | 9011 | Total number of dropped: <Number> | |
LOG_INFO | 9011 | Total number of long url logs: <Number> | |
LOG_INFO | 9011 | Total number of control connection attempts to the ftp server: <Number> | |
LOG_INFO | 9011 | Total number of control connections successes: <Number> | |
LOG_INFO | 9011 | Total number of data connections: <Number> | |
LOG_INFO | 9011 | Total number of 4xx errors: < number > | |
LOG_INFO | 9011 | Total number of 5xx errors: <Number> | |
LOG_INFO | 9011 | Total number of ftp failures: <Number> | |
LOG_INFO | 9011 | Total number of requests: <Number>, Total duration: <Duration> secs | |
LOG_INFO | 9011 | ---- END OF LOG STATS FOR LOGS EXPORTED TO <IP Address>:<Port> ---- | |
LOG_INFO | 9012 | Web Logging enabled | |
LOG_NOTICE | 9013 | Dropping logs, running low on memory | |
LOG_ERROR | 9013 | Error in hash generation or encryption | |
LOG_NOTICE | 9014 | Logging parameters are set for vip <IP Address>:<Port> | |
LOG_INFO | 9017 | FTP Session to <IP Address>, status code = <FTP Status> | |
LOG_ERROR | 9018 | Unable to log the request since FTP server is slow or unreachable | |
LOG_ERROR | 9018 | Dropping logs since queue is full | |
LOG_ERROR | 9019 | Signature generation of logs failed | |
EVENT MANAGER (EVM) | |||
LOG_ERROR | 11001 | Event Manager startup failure: could not handle signals | |
LOG_INFO | 11005 | Forwarding log messages to syslog host[<index>]=<ip_address>, facility=<facility> (socket=<socket_id>) | |
LOG_ERROR | 11007 | EnableSyslogService: create socket failed | |
LOG_ERROR | 11008 | fopen <log_filename>: <error_description> | |
LOG_ERROR | 11009 | <log_filename> write failed <error_description> | |
CONFIG AGENT (CONFIG) | |||
LOG_ERROR | 12001 | Digest failed | |
LOG_ERROR | 12001 | Configuring Secure Traffic Manager Succeeded | |
LOG_ERROR | 12002 | Service | |
LOG_ERROR | 12002 | Duplicate parameter | |
LOG_ERROR | 12002 | VSite | |
LOG_ERROR | 12002 | Target doesn't exist | |
LOG_ERROR | 12002 | Backup | |
LOG_ERROR | 12002 | Deleting Server | |
LOG_ERROR | 12002 | Server delete succeeded | |
LOG_ERROR | 12002 | Unable to delete Server | |
LOG_ERROR | 12002 | Deleting Service | |
LOG_ERROR | 12002 | Service delete succeeded | |
LOG_ERROR | 12002 | Unable to delete Service | |
LOG_CRIT | 12003 | Failed to retrieve initial groups | |
LOG_INFO | 12003 | Failed to retrieve User’s Realms | |
LOG_ERROR | 12004 | Can't store rule ID | |
LOG_INFO | 12004 | Adding RuleGroup | |
LOG_ERROR | 12005 | Can't get " NEXTSAPID ": missing " SAPID " or error retrieving " SAPID | |
LOG_ERROR | 12007 | Target doesn't exist | |
LOG_ERROR | 12007 | Failed to create server | |
LOG_ERROR | 12007 | SetServerConnAttr failed | |
LOG_ERROR | 12007 | SetServerRedirectAttr failed | |
LOG_ERROR | 12007 | SetServerOutOfBandMonitorAttr failed | |
LOG_ERROR | 12007 | SetServerMonitorAttr failed | |
LOG_ERROR | 12007 | SetServerLBAttr failed | |
LOG_ERROR | 12007 | StartServer failed | |
LOG_ERROR | 12007 | SetServerSSLServicePolicy failed | |
LOG_ERROR | 12007 | SetServerSSLServiceOn failed | |
LOG_ERROR | 12007 | SetServerSSLServiceOff failed | |
LOG_ERROR | 12007 | ActiveServerOutOfBandMonitorAttr failed | |
LOG_ERROR | 12007 | Failed to delete server | |
LOG_ERROR | 12007 | Failed to reset server ip, port or vlan | |
LOG_ERROR | 12007 | Failed to look up server | |
LOG_ERROR | 12007 | SetServerTcpMonitorAttr failed | |
LOG_ERROR | 12007 | EnableServer failed | |
LOG_ERROR | 12007 | DisableServer failed | |
LOG_ERROR | 12007 | ActiveServerOutOfBandMonitorAttr failed | |
LOG_ERROR | 12007 | Failed to delete server | |
LOG_ERROR | 12007 | Failed to reset server ip, port or vlan | |
LOG_ERROR | 12007 | Failed to look up server | |
LOG_ERROR | 12007 | SetServerTcpMonitorAttr failed | |
LOG_ERROR | 12007 | EnableServer failed | |
LOG_ERROR | 12007 | DisableServer failed | |
LOG_ERROR | 12007 | ActiveServerOutOfBandMonitorAttr failed | |
LOG_ERROR | 12007 | Server | |
LOG_ERROR | 12008 | Duplicate server | |
LOG_ERROR | 12008 | Attaching server | |
LOG_ERROR | 12008 | Attaching server succeeded | |
LOG_ERROR | 12008 | Failed to look up back-end server | |
LOG_ERROR | 12008 | Detaching server | |
LOG_ERROR | 12008 | Detaching server succeeded | |
LOG_ERROR | 12009 | OUT OF MEMORY !!! Asserting… | |
LOG_ERROR | 12009 | Error in reading ReadXmlFileIntoString | |
LOG_ERROR | 12009 | sapIndex.AddFromXMLStr (..., SAP::nsap) failed | |
LOG_ERROR | 12009 | Error. AddFromXMLStr failed ! | |
LOG_ERROR | 12009 | Cannot modify a read-only node | |
LOG_ERROR | 12009 | No path provided | |
LOG_ERROR | 12009 | Failed due to insufficient user permission | |
LOG_ERROR | 12009 | Internal error while adding a child node! | |
LOG_ERROR | 12009 | Internal error: while parsing query! | |
LOG_ERROR | 12009 | No Parameter found for querying | |
LOG_ERROR | 12009 | No path provided | |
LOG_ERROR | 12009 | Failed due to insufficient user permission | |
LOG_ERROR | 12009 | Internal error while adding a child node! | |
LOG_ERROR | 12009 | Invalid or non existent home dir found ! | |
LOG_ERROR | 12009 | GetPathForUser failed | |
LOG_ERROR | 12009 | Context doesn't exist ! | |
LOG_ERROR | 12009 | CheckPerm failed for path | |
LOG_ERROR | 12009 | Failed due to insufficient user permission | |
LOG_ERROR | 12009 | Unable to allocate memory | |
LOG_ERROR | 12009 | OUT OF MEMORY !!! Asserting... | |
LOG_ERROR | 12009 | in PutSAPTree. GetHomeDirForUser failed ! | |
LOG_ERROR | 12009 | In PutSAPTree. Invalid path specified ! | |
LOG_ERROR | 12009 | in PutSAPTree. No acl perm | |
LOG_ERROR | 12009 | in PutSAPTree.ModifySAP failed | |
LOG_ERROR | 12009 | in PutSAPTree. Trying to modify a read-only node | |
LOG_ERROR | 12009 | in PutSAPTree.AddChildSAP failed | |
LOG_ERROR | 12009 | in PutSAPTree.DeleteSAPTree failed | |
LOG_ERROR | 12009 | PutRootSAPTree failed in GetAggSAP | |
LOG_ERROR | 12010 | Rule Group | |
LOG_ERROR | 12010 | Duplicate application | |
LOG_ERROR | 12010 | Failed to find back-end server in server list | |
LOG_ERROR | 12010 | Failed to look up Secure Traffic Manager object | |
LOG_ERROR | 12011 | Couldn't add paramSAP, name: | |
LOG_ERROR | 12018 | Invalid Path Specified | |
LOG_ERROR | 12018 | Internal Error | |
LOG_ERROR | 12018 | Invalid Path Specified | |
LOG_ERROR | 12019 | Unable to allocate memory | |
LOG_ERROR | 12021 | in ParamCmp. Cant modify node attributes | |
LOG_ERROR | 12021 | Incorrect permissions given to root role | |
LOG_ERROR | 12021 | Cannot modify ACL for root node | |
LOG_ERROR | 12021 | Cannot give write permissions for a read-only node. | |
LOG_ERROR | 12021 | in ParamCmp. Cant modify node attributes | |
LOG_ERROR | 12021 | in AggCmp. Cant modify node attributes | |
LOG_ERROR | 12021 | Incorrect permissions given to root role | |
LOG_ERROR | 12021 | Cannot modify ACL for root node | |
LOG_ERROR | 12021 | Cannot give write permissions for a read-only node | |
LOG_ERROR | 12024 | Backup rule group cannot be the same as the primary rule group | |
LOG_NOTICE | 12040 | Processing messages in the list | |
LOG_INFO | 12049 | Received SIGTERM | |
LOG_INFO | 12049 | Received SIGALRM | |
LOG_NOTICE | 12049 | Processing messages in the list failed. Ignoring the error | |
LOG_NOTICE | 12049 | Starting main message processing loop | |
LOG_INFO | 12049 | Termination requested by the signal handler | |
LOG_ERROR | 12053 | Failed to initialize signal handlers | |
LOG_ERROR | 12053 | Failed to digest initial configuration | |
LOG_ERROR | 12053 | Termination requested by the signal handler | |
LOG_ERROR | 12054 | GetCmdGrpXML failed | |
LOG_ERROR | 12054 | sapIndex.AddFromXMLStr(..., \"nc:ncRoot\") failed | |
LOG_ERROR | 12054 | Usage: sap_initdb xmlFile | |
LOG_ERROR | 12054 | Failed to initialize the sessions DB | |
LOG_ERROR | 12054 | Failed to initialize SAP DB | |
LOG_ERROR | 12057 | Can't store vhid | |
LOG_ERROR | 12057 | Updating virtual host id is not supported | |
LOG_ERROR | 12057 | VirtualHostId | |
LOG_ERROR | 12057 | VirtualHost | |
LOG_ERROR | 12066 | Socket::WritePktToSocket - sockfd == -1 | |
LOG_ERROR | 12067 | Failed to look up associated application | |
LOG_ERROR | 12067 | Adding Application | |
LOG_ERROR | 12067 | Rule Group | |
LOG_ERROR | 12067 | No such object | |
LOG_ERROR | 12068 | Rule | |
LOG_ERROR | 12068 | No rules | |
LOG_ERROR | 12068 | Failed find back-end server in server list | |
LOG_ERROR | 12081 | Finalize succeeded! | |
LOG_ERROR | 12083 | Failed to look up Secure Traffic Manager object | |
LOG_ERROR | 12083 | No such object | |
HTTP | |||
LOG_DEBUG | 13102 | Server <IP Address:Port> prematurely closes the connection | |
LOG_WARN | 13103 | OnHttpServerSockRecv: Session timed out from <Client IP:Port> | |
HTTPSVC | |||
LOG_ERROR | 0 | Bind failed due to 98 (Unable to connect to the back-end server using the TCP port that the client used while sending the request.). | |
SMTP | |||
LOG_INFO | 13201 | QUIT command received before EHLO command | |
LOG_INFO | 13202 | Backend server supports AUTH | |
LOG_INFO | 13203 | Client has not sent EHLO command as the first command | |
LOG_INFO | 13204 | AUTH mechanism other than PLAIN/LOGIN has been requested when WSG does user-authentication | |
LOG_INFO | 13205 | Using PLAIN authentication mechanism | |
LOG_INFO | 13206 | Using LOGIN authentication mechanism | |
LOG_INFO | 13207 | User authentication failed | |
HEARTBEAT (HB) | |||
LOG_ERROR | 15001 | Heartbeat events dropped, queue is full | |
LOG_ERROR | 15002 | Unable to bind to address | |
LOG_ERROR | 15003 | Error sending packet | |
LOG_INFO | 15003 | Opening the Heartbeat Connection pci port | |
LOG_INFO | 15003 | Closing the Heartbeat Connection pci port | |
LOG_INFO | 15003 | Unable to close Heartbeat connection pci port | |
LOG_INFO | 15003 | Ignoring Heartbeat Connection close command pci port | |
LOG_INFO | 15003 | Received data before initialization | |
LOG_ERROR | 15003 | Error receiving data From remote gateway | |
LOG_ERROR | 15004 | Attempting to reinitialize the Heartbeat Server before closing | |
LOG_ERROR | 15004 | Attempting to send data without Initialization | |
CERTIFICATE (CERT) | |||
LOG_NOTICE | 17500 | Cert Initialization | |
SSL | |||
LOG_NOTICE | 13200 | Can not connect to server (<Error Code>) for connection from: <Client IP Address> | |
LOG_NOTICE | 13200 | SSL connection to server for connection from: <Client IP Address> failed | |
LOG_NOTICE | 13200 | Error connecting to server (<Error Code>) for connection from: <Client IP Address> | |
LOG_NOTICE | 13200 | Error opening SSL connection to server for connection from: <Client IP Address> | |
LOG_NOTICE | 13200 | SSL accept failed for connection from: <Client IP Address> | |
LOG_NOTICE | 13200 | Error switching connection from: <Client IP Address > to SSL | |
LOG_NOTICE | 13200 | Error accepting SSL connection from: <Client IP Address > | |
LOG_INFO | 13200 | QUIT command received before switching to SSL | |
LOG_NOTICE | 16001 | <ssl-function-name>: Base 0x<ssl-handle> - Access denied: received bad certificate signature | |
LOG_NOTICE | 16001 | <ssl-function-name>: Base 0x<ssl-handle> - Access denied: failed to verify certificate signature | |
LOG_NOTICE | 16001 | <ssl-function-name>: Base 0x<ssl-handle> - Access denied: certificate chain too long | |
LOG_NOTICE | 16001 | <ssl-function-name>: Base 0x<ssl-handle> - Access denied: failed to decode certificate | |
LOG_NOTICE | 16001 | <ssl-function-name>: Base 0x<ssl-handle> - Access denied: no certificate | |
LOG_NOTICE | 16001 | <ssl-function-name>: Base 0x<ssl-handle> - Access denied: failed to validate certificate chain | |
LOG_NOTICE | 16001 | <ssl-function-name>: Base 0x<ssl-handle> - Access denied: <Error Code> | |
LOG_NOTICE | 16004 | <ssl-function-name>: Base 0x<ssl-handle> - Sending alert: <Alert-desc> (<Alert Code>) from [<IP Address>:<Port>] | |
LOG_NOTICE | 16005 | <ssl-function-name>: Base 0x<ssl-handle> - Received alert: <Alert-desc> (<Alert Code>) from [<IP Address>:<Port>] | |
LOG_DEBUG | 16010 | <ssl-function-name>: Base 0x<ssl-handle> - New SSL socket 0x<ssl-socket-handle> for <Client IP:Port> | |
LOG_NOTICE | 16012 | <ssl-function-name>: Base 0x<ssl-handle> - No RSA private key available | |
LOG_NOTICE | 16012 | <ssl-function-name>: Base 0x<ssl-handle> - Mismatched key size <Size> (expected <Size>) | |
LOG_NOTICE | 16012 | <ssl-function-name>: Base 0x<ssl-handle> - Failed to get authority private key | |
LOG_NOTICE | 16012 | <ssl-function-name>: Base 0x<ssl-handle> - Called on a client socket | |
LOG_NOTICE | 16012 | <ssl-function-name>: Base 0x<ssl-handle> - Called on a server | |
LOG_ERROR | 16013 | <ssl-function-name>: Out of memory | |
LOG_ERROR | 16013 | <ssl-function-name>: Base 0x<ssl-handle> - Out of memory | |
LOG_ERROR | 16013 | <ssl-function-name>: Socket 0x<sslsock-handle> - Out of memory | |
LOG_NOTICE | 16014 | <ssl-function-name>: Incorrect server name: length should be between 0 and < length > | |
LOG_ERROR | 16016 | <ssl-function-name>: Base 0x<ssl-handle> - Failed to schedule crypto command | |
LOG_NOTICE | 16019 | < ssl-function-name >: Cannot configure more than <Number> certificate policies | |
LOG_NOTICE | 16020 | <ssl-function-name>: Cannot configure more than <Number> trusted certificates per service | |
LOG_NOTICE | 16021 | <ssl-function-name>: No available SSL version for client socket | |
LOG_NOTICE | 16023 | <ssl-function-name>: Ephemeral Key changed | |
LOG_NOTICE | 16024 | <ssl-function-name>: Base 0x<ssl-handle> - No ephemeral key available | |
LOG_NOTICE | 16500 | SSL Initialization | |
LOG_NOTICE | 17001 | <ssl-function-name>: Trusted certificate expired: CN=<Common Name>, OU=<Org Name > | |
LOG_NOTICE | 17001 | <ssl-function-name>: Trusted certificate expired: O=<Org Name> L=<Location> S=<State> C=<City> | |
STM | |||
LOG_ERROR | 13100 | HttpServerParseRequest: Parse failed; Malformed version <request-buffer> | |
LOG_ERROR | 13100 | HttpServerParseRequest: Parse failed; Unknown major number <request-buffer> | |
LOG_ERROR | 13100 | HttpServerParseRequest: Parse failed; Unknown minor number <request-buffer> | |
LOG_ERROR | 13100 | HttpServerParseRequest: Parse failed; Unknown method: <request-buffer> | |
LOG_ERROR | 13100 | HttpServerParseRequest: Parse failed; Malformed URL <request-buffer> | |
LOG_ERROR | 13100 | HttpServerParseRequest: Parse failed; Malformed line end <request-buffer> | |
LOG_ERROR | 13101 | HttpClientParseResponse: Parse failed; Malformed version <request-buffer> | |
LOG_ERROR | 13101 | HttpClientParseResponse: Parse failed; Unknown major number <request-buffer> | |
LOG_ERROR | 13101 | HttpClientParseResponse: Parse failed; Unknown minor number <request-buffer> | |
LOG_ERROR | 13101 | HttpClientParseResponse: Parse failed; Malformed status code <request-buffer> | |
LOG_ERROR | 13101 | HttpClientParseResponse: Parse failed; Header: <request-buffer> | |
LOG_ERROR | 13101 | HttpClientParseResponse: Parse failed; Malformed line end <request-buffer> | |
LOG_NOTICE | 14001 | New Service (ID 0x<vip-context>) Created at <IP Address>:<Port> | |
LOG_ERROR | 14001 | Failed to Create Service at <IP Address>:<Port> | |
LOG_NOTICE | 14002 | Service Started <IP Address>:<Port> | |
LOG_ERROR | 14003 | Failed to Delete Service (ID 0x%08x) at <IP Address>:<Port> | |
LOG_ERROR | 14004 | Failed to Create Rule at <IP Address>:<Port> | |
LOG_NOTICE | 14004 | New Rule (ID 0x<rule-context>) Created at <IP Address>:<Port> for ID 0x<vip-context> | |
LOG_NOTICE | 14005 | <Not Commited | Commited> Rule: URL [<URL Key>] Header [<Extended match key>] | |
LOG_ERROR | 14007 | Failed to Create Service at <IP Address>:<Port> | |
LOG_NOTICE | 14007 | New Vapp (ID 0x<vapp-context>) Created at <IP Address>:<Port> for ID 0x<vip-context> | |
LOG_NOTICE | 14008 | Failed to commit Application: Domain [<Application Rule Domain>] URL [<Application Rule URL>] | |
LOG_ERROR | 14009 | Failed to Delete Vapp (ID 0x<vapp-context>) at <IP Address>:<Port> Domain [<Application Rule Domain>] URL [<Application Rule URL>] | |
LOG_INFO | 25200 | getServerBySrcIPPort: ClntIp 0x<IP Address> ClntPort 0x<port> Svr NULL | |
LOG_INFO | 25200 | bindServerBySrcIPPort: SvrIP 0x<IP Address> SvrCookId <internal-id> SvrId <internal-return-value> | |
AAA | |||
LOG_INFO | 18201 | User <User ID> logged in | |
LOG_INFO | 18202 | Password changed successfully for User <User ID> | |
LOG_ERROR | 18203 | Unable to contact the authentication server, (RPC Queue full) | |
LOG_ERROR | 18204 | Remote procedure call to authentication server timed out | |
LOG_ERROR | 18205 | Login attempt failed for user <User ID> | |
LOG_ERROR | 18206 | Changing password failed for user <User ID> | |
LOG_NOTICE | 18207 | Added a realm:<Realm ID> | |
LOG_ERROR | 18208 | Unable to add realm:<Realm ID> | |
LOG_NOTICE | 18209 | Deleted a realm:<Realm ID> | |
LOG_DEBUG | 18210 | Session created for user <User ID> | |
LOG_DEBUG | 18211 | Number of current users sessions = <Number of User Sessions> | |
LOG_DEBUG | 18212 | Session destroyed for user <User ID> in realm <Realm ID> | |
LOG_DEBUG | 18213 | Session exists for user <User ID> | |
LOG_DEBUG | 18214 | Session does not exist for user session id <Session ID> | |
LOG_ERROR | 18215 | Error received from webauthd , <Error String> | |
LOG_NOTICE | 18216 | Insert into ptrie - allocation failed (flags: 0x<internal-flags-value>, mem: <internal-mem-handle>) "Creating AuthzCache - inserting into ptrie failed(nodes: <internal-node-handle>, <internal-node-handle> | |
LOG_NOTICE | 18217 | Client attempted to Logout without login session cookie\n | |
LOG_WARN | 18218 | Invalid external policy store configured, realm name = <realm-name> | |
IPS | |||
LOG_NOTICE | 19031 | XML Firewall error: <error-string> ( offset: <offset number>, code: <error code> )",pErr->desc,( int )pErr->offset, pErr->code | |
LOG_NOTICE | 19031 | XML Firewall error: Input validation | |
LOG_NOTICE | 19031 | XML Firewall error: Attack pattern | |
LOG_NOTICE | 19031 | XML Firewall error: Operation denied | |
LOG_ERROR | 19032 | Failed to allocate NCFORMINFO buffer | |
LOG_ERROR | 19032 | Unable to add session param to NCFORMINFO (no-name param) | |
LOG_ERROR | 19032 | Failed to allocate NCFORMINFO buffer(resp) | |
LOG_ERROR | 19032 | Unable to add session param to NCFORMINFO (multi-value) | |
LOG_ERROR | 19032 | Failed to allocate buffer for response URL rewrite | |
LOG_ERROR | 19032 | Failed to allocate buffer for form encryption | |
LOG_WARN | 19500 | Could not cloak match for %s. Value of Initial or Trailing Characters to Keep is too large | |
LOG_WARN | 19500 | POST request with both Content-Length and Transfer-Encoding headers [ url: <URL|Malformed URL> ], dropped | |
LOG_WARN | 19500 | No intrusion information for %d", intrusion | |
COOKIE | |||
LOG_ALERT | 20002 | Session cookie decryption failed | |
LOG_ALERT | 20003 | Cookie expires: Client <IP Address> | |
LOG_ALERT | 20004 | Cookie auth failed: cookiename auth failed | |
LOG_ALERT | 20005 | Cookie Length Overflow: Client <IP Address> | |
LOG_ERROR | 20006 | Failed to allocate Shared Key context for cookie encryption | |
FTP PROXY (FTPPXY) | |||
LOG_INFO | 21002 | <FTP Module Name>:created ftp proxy session client-ip:<Client IP Address> VhId = <Internal ID> | |
LOG_INFO | 21003 | Closing server session | |
LOG_INFO | 21004 | Control connection established with the FTP server, <Interface IP Address> <Server IP Address> <Server Port> | |
LOG_INFO | 21005 | Back-end FTP server connection has timed out | |
LOG_INFO | 21005 | Closing connection to the FTP server | |
LOG_INFO | 21005 | FTP server closed the control connection | |
LOG_INFO | 21006 | Established data connection to FTP client <Client IP Address> | |
LOG_INFO | 21008 | Established data connection to FTP server <Server IP Address> | |
LOG_INFO | 21010 | Data transfer completed successfully | |
LOG_ERROR | 21011 | Error while transferring data | |
LOG_INFO | 21012 | Received the FTP command | |
LOG_WARN | 21014 | <Internal Session ID>:Invalid client ip-address (<IP Address>) specified with the port command, actual client ip-address is (<IP Address>) | |
LOG_WARN | 21014 | <Internal Session ID>:Invalid port (<Port>) specified with the port command, port value must be greater than 1024 | |
LOG_WARN | 21014 | <Internal Session ID>:Invalid ip-addr (<IP Address>) used to connect to listening ftp data socket, expected from (<IP Address>) | |
LOG_INFO | 21015 | <Internal Session ID>:Sent the FTP response (<Response String>) | |
LOG_INFO | 21016 | Established SSL data connection with the FTP client, <Client IP Address> | |
LOG_INFO | 21016 | Established SSL control connection with the FTP client | |
LOG_INFO | 21018 | Established SSL control connection with the FTP server | |
LOG_DEBUG | 21020 | Command sent to FTP server | |
LOG_DEBUG | 21021 | Client received <number> bytes on control connection | |
LOG_ERROR | 21022 | Unable to allocate state control block for a session | |
LOG_ERROR | 21022 | Unable to allocate memory for ftp session | |
LOG_ERROR | 21022 | Out of memory | |
LOG_ERROR | 21022 | <Service IP Address:Port>:Unable to allocate memory for PORT cmd to FTP server | |
LOG_ERROR | 21022 | <Service IP Address:Port>:Unable to allocate memory for SSL verbs | |
LOG_ERROR | 21022 | <Service IP Address:Port>:Unable to allocate memory for PORT cmd to FTP server | |
LOG_ERROR | 21023 | Unable to get an active back-end server | |
LOG_ERROR | 21024 | Failed to create new socket | |
LOG_ERROR | 21024 | Failed to create SSL socket | |
LOG_ERROR | 21024 | Failed to create ssl client socket for data connection | |
LOG_ERROR | 21025 | Unable to bind a server for data connection | |
LOG_ERROR | 21025 | Unable to setup data connection | |
LOG_ERROR | 21026 | Failed to connect to FTP server | |
LOG_ERROR | 21026 | Unable to establish SSL control connection with the FTP server | |
LOG_ERROR | 21026 | Unable to connect to FTP server <Server IP Address> | |
LOG_ERROR | 21027 | Unable to accept SSL connection from FTP client | |
LOG_ERROR | 21028 | Failed to send response to the client | |
LOG_ERROR | 21028 | Failed to send control data to the server, because of small TCP windows | |
LOG_ERROR | 21028 | Failed to send data to the FTP client on the data connection | |
LOG_ERROR | 21029 | Failed to receive data from the FTP client on the data connection | |
LOG_ERROR | 21029 | Failed to receive data from FTP server on the data connection | |
LOG_ERROR | 21030 | Received bad response codes from the FTP server | |
COMPRESSION (COMPRESS) | |||
LOG_ERROR | 24001 | Compression request errored, <Error Code>, <Error String> | |
LOG_INFO | 24004 | Part of the response data not submitted for compression | |
LOG_ERROR | 24006 | Failed to initialize compression, switching back to no-compression mode | |
REWRITE | |||
LOG_INFO | 26001 | Rewrite Module: Low on Memory. | |
LOG_INFO | 26001 | <rewrite-module-name>: ReqCtx 0x<internal-reqctx-handle>, Error in ncvbuf handling | |
LOG_ERROR | 26051 | Rewrite Module: URL rewrite by both Url-Translation and Request Rewrite | |
LOG_ERROR | 26052 | Rewrite Module: HTTP header rewrite by both URL-translation and Request Rewrite. Please go over your configuration to see if this can be avoided | |
LOG_INFO | 26053 | Response Body Rewrite: Replaced \"<find buffer>\" with \"<replace buffer> | |
ROUTE | |||
LOG_ERROR | 3011 | rn_addmask: mask impossibly already in tree | |
LOG_ERROR | 3011 | Mask for route not entered | |
LOG_ERROR | 3012 | rn_delete <Node Info>: Orphaned Mask <node-info> at <Node Info> | |
LOG_ERROR | 3013 | rn_init: radix functions require max_keylen be set | |
INTERFACE (IF) | |||
LOG_ERROR | 3002 | failed to attach interface <Interface Name> | |
LOG_NOTICE | 3003 | <Interface Name>: promiscuous mode enabled | |
ICMP | |||
LOG_INFO | 4001 | redirect from <-address>: <Destination Address> => <Gateway Address> | |
IP | |||
LOG_ERROR | 4033 | can't find virtual host for route, dst = <IP Address> | |
LOG_NOTICE | 4034 | ipflow to <IP Address> reached max refs | |
LOG_NOTICE | 4034 | Copyright (c) 2001, 2002 Barracuda Inc. | |
LOG_NOTICE | 4034 | Copyright (c) 1982, 1986, 1993 The Regents of the University of California | |
TCP | |||
LOG_ALERT | 4054 | Detected a SYN attack, using SYN cookies | |
CRYPTO | |||
LOG_DEBUG | 5003 | Setting Encrypt Context Failed | |
LOG_DEBUG | 5003 | Encrypt Update Failed | |
LOG_DEBUG | 5003 | Encrypt Failed | |
LOG_DEBUG | 5004 | Decrypt Failed | |
PROCMON | |||
LOG_WARN | 44001 | 'PROCMON' "STM crash detected current state is: <STM State> state <Number> crashes in last <Time in Seconds>" | |
LOG_WARN | 44002 | 'PROCMON' "Total retries: <Number> waiting for <Time in seconds> before next restart" | |
LOG_WARN | 44003 | 'PROCMON' "Too many <Number> tries to restart unstable STM, switching to Failed state" | |
LOG_WARN | 44004 | 'PROCMON' "Too many STM crashes switching to Unstable state, will attempt restart in <Time in seconds>" | |
LOG_NOTICE | 44005 | 'PROCMON' "Attempting to restart STM and Eventmgr" | |
LOG_NOTICE | 44006 | 'PROCMON' "Attempting to recreate the log DB" | |
LOG_ERROR | 44007 | 'PROCMON' "Error : <Error code> encountered with stm start" | |
LOG_ERROR | 44008 | 'PROCMON' "STM restart failed: switching to Failed state" | |
LOG_ERROR | 44009 | 'PROCMON' "STM restart failed: switching to Failed state" | |
LOG_NOTICE | 44010 | 'PROCMON' "STM restart succeeded: current state: Stable" | |
LOG_WARN | 44011 | 'PROCMON' "shmget failed | |
LOG_WARN | 44012 | 'PROCMON' "number of stm worker threads is <Number of STM Threads>" | |
LOG_WARN | 44013 | 'PROCMON' "shmread error <Failure Error>" | |
LOG_WARN | 44014 | 'PROCMON' "STM worker thread <Number> seems to be hung. Event count <Number>" | |
LOG_WARN | 44015 | 'PROCMON' "STM seems to be hung. Killing STM" | |
LOG_NOTICE | 44016 | 'PROCMON' "STM alive: switching from <STM State> to stable state" | |
LOG_WARN | 44017 | 'PROCMON' "<Process Name> state is <Process State>" | |
LOG_ERROR | 44018 | 'PROCMON' "bypass_hbeat.pl is dead restarting gpio and bypass_hbeat" | |
LOG_ERROR | 44019 | 'PROCMON' "clamd is dead, restarting <Process Name>" | |
LOG_ERROR | 44019 | 'PROCMON' "snmpd is dead, restarting <Process Name>" | |
LOG_ERROR | 44020 | 'PROCMON' "profile agent is dead, restarting <Process Name>" | |
LOG_ERROR | 44021 | 'PROCMON' "collectd is dead, restarting <Process Name>" | |
LOG_ERROR | 44022 | 'PROCMON' "namemon is dead, restarting namemon" | |
LOG_ERROR | 44023 | 'PROCMON' "config agent is dead, restarting config_agent and stm" | |
LOG_CRIT | 50003 | 'PROCMON' "System highest temp has reached = <Temperature>" | |
LOG_CRIT | 50004 | 'PROCMON' "System is getting real hot = <Temperature>" | |
LOG_CRIT | 50003 | 'PROCMON' "System highest temp has reached = <Temperature>" | |
LOG_CRIT | 50004 | 'PROCMON' "System is getting real hot = <Temperature>" | |
LOG_ALERT | 50005 | 'PROCMON' "One of the CPU fans is dead" | |
LOG_ALERT | 50005 | 'PROCMON' "One of the System fans is dead" | |
LOG_ALERT | 50007 | 'PROCMON' "Firmware storage exceeds 85%" | |
LOG_ALERT | 50008 | 'PROCMON' "Mail storage exceeds 85%" | |
LOG_ALERT | 50009 | 'PROCMON' "Log storage exceeds 85%" | |
LOG_ALERT | 50010 | 'PROCMON' "One of the RAID arrays is degrading" | |
LOG_WARN | 44034 | 'PROCMON' "<Interface Name>: link seems down" | |
LOG_ALERT | 44035 | 'PROCMON' "<Interface Name>: link is down" | |
LOG_NOTICE | 44036 | 'PROCMON' "<Interface Name>: link is up" | |
LOG_NOTICE | 44001 | 'PROCMON' "Checking if configuration needs to be synchronized with peer system" | |
LOG_NOTICE | 44001 | 'PROCMON' "Notifying peer system to check if configuration needs to be synchronized" | |
LOG_ALERT | 44038 | 'PROCMON' "<Interface Name>: link is down" | |
LOG_ERROR | 44039 | 'PROCMON' "heartbeat.pl is dead <Number>, restarting" | |
LOG_ERROR | 44040 | 'PROCMON' "heartbeat.pl is in state D for <Number> tick(s). Ignoring the state" | |
LOG_ERROR | 44041 | 'PROCMON' "cluster_manager is dead <Number>, restarting" | |
LOG_ERROR | 44042 | 'PROCMON' "cluster_manager is in state D for <Number> tick(s). Ignoring the state" | |
LOG_ERROR | 44043 | 'PROCMON' "Restarting spinal cord process since there may be an issue in connecting to Control Center" | |
LOG_ERROR | 44043 | 'PROCMON' "Restarting ssh" | |
LOG_NOTICE | 44001 | 'PROCMON' "Checking if configuration needs to be synchronized with peer system" | |
LOG_ERROR | 44044 | 'PROCMON' "Configuration dispatcher is dead <Number>, restarting" | |
LOG_ERROR | 44045 | 'PROCMON' "Configuration dispatcher is in state D for <Number> tick(s). Ignoring the state" | |
LOG_ALERT | 44046 | 'PROCMON' "STM seems to be running high on Memory. Please contact to Barracuda Networks Support Center for analysis" | |
LOG_ALERT | 44047 | 'PROCMON' "Memory Usage exceeds 70%" | |
LOG_NOTICE | 44048 | 'PROCMON' "Monitoring links: <Link Name>" | |
LOG_NOTICE | 44049 | 'PROCMON' "Started monitoring" | |
LOG_EMERG | 1105 | <Process> is not present | |
LOG_NOTICE | 1111 | Process mon /proc error ret =<retcode> comm=<commandid> pid=<process-id> | |
CLUSTER | |||
LOG_NOTICE | 43001 | 'CLUSTER' "We are not yet in cluster mode. Could not calculate destination IP and destination Identity. Exiting.." | |
LOG_NOTICE | 43001 | 'CLUSTER' "Invalid Role : <PRIMARY/BACKUP:self_role> specified in cluster.conf. Could not determine self role. Exiting.." | |
LOG_ERROR | 43001 | 'CLUSTER' "cluster.conf file is not existing...Exiting" | |
UPDATE | |||
LOG_ALERT | 44401 | 'UPDATE' "Energize update subscription is about to expire in <Number> days" | |
LOG_ALERT | 44402 | 'UPDATE' "New attack definition version <Number> is available" | |
LOG_ALERT | 44403 | 'UPDATE' "New firmware update is available Current Version = <Version Number> Beta Version = <Version Number>" | |
LOG_ALERT | 44404 | 'UPDATE' "New firmware update is available Current Version = <Version Number> New Version = <Version Number>" | |
LOG_ALERT | 44402 | 'UPDATE' "New Attack Def version <Number> current_attack_def_version is installed reboot appliance to apply attack def" | |
BYPASS | |||
LOG_ALERT | 44221 | 'BYPASS' "Unit is switching to bypass mode" | |
LOG_NOTICE | 44222 | 'BYPASS' "State set to bypass: stopping heartbeat" | |
LOG_NOTICE | 44223 | 'BYPASS' "State set to normal: starting heartbeat." | |
LOG_NOTICE | 44201 | 'BYPASS' "Mode change: Hard bypass = <Hard Bypass Enabled> Bypass on Failure = <Soft Bypass Enabled>" | |
LOG_NOTICE | 44202 | 'BYPASS' "Mode set to bypass Hard bypass = <Hard Bypass Enabled> Bypass on Failure = <Soft Bypass Enabled>" | |
LOG_NOTICE | 44203 | 'BYPASS' "Changing Heartbeat bit state from <Old Hearbeat Version> to <New Hearbeat Version>" | |
LOG_NOTICE | 44204 | 'BYPASS' "Mode set to never bypass" | |
REPORTS | |||
LOG_ERROR | 44701 | 'REPORTS' "Could not open pdf <Report Name> because: <Reason>" | |
LOG_ERROR | 44702 | 'REPORTS' "Could not open html '<Report Name>' because: <Reason>" | |
LOG_ERROR | 44703 | 'REPORTS' "Report not sent to <IP Address>: ".<Email Address> | |
LOG_INFO | 44720 | 'REPORTS' "<Report Type>" | |
STM_WRAPPER | |||
LOG_WARN | 45001 | 'STM_WRAPPER' "Cannot execute <Command Name> Command. Exiting.." | |
LOG_WARN | 45002 | 'STM_WRAPPER' "Configuration agent is not running. Cannot monitor <Command Name> command" | |
LOG_WARN | 45003 | 'STM_WRAPPER' "command<Command Name> execution status = <Status>" | |
LOG_WARN | 45004 | 'STM_WRAPPER' "Configuration agent crashed. Failed to execute <Command Name> command" | |
LOG_WARN | 45005 | 'STM_WRAPPER' "Configuration agent is not running....Cannot execute <Command Name> command" | |
LOG_WARN | 45006 | 'STM_WRAPPER' "Socket between stm wrapper and Configuration agent failed...Cannot execute <Command Name> command" | |
LOG_ERROR | 45007 | 'STM_WRAPPER' "Failed to initialize STM" | |
LOG_NOTICE | 45008 | 'STM_WRAPPER' "Successfully initialized STM" | |
LOG_NOTICE | 45008 | 'STM_WRAPPER' "creatin db snapshot after initwac" | |
LOG_NOTICE | 45009 | 'STM_WRAPPER' "Successfully stopped STM" | |
LOG_NOTICE | 45010 | 'STM_WRAPPER' "<Failure Reason>" | |
LOG_INFO | 45011 | 'STM_WRAPPER' "Procmon rollback :Loading at <Date> from DB snapshotlast successful digest" | |
LOG_NOTICE | 45012 | 'STM_WRAPPER' "Rollback finished: success" | |
LOG_ERROR | 45013 | 'STM_WRAPPER' "Rollback failed: Failed to restart STM" | |
LOG_NOTICE | 45014 | 'STM_WRAPPER' "Configuration digest failed" | The updated configuration failed at the data path process and has been rolled back to the old configuration. This problem could be caused by an issue with the certificate, a duplicated server, or may have some other cause. |
LOG_INFO | 45015 | 'STM_WRAPPER' "Loading at <date> from DB snapshotlast successful digest" | |
LOG_WARN | 45016 | 'STM_WRAPPER' "[ALERT:<Event ID>] Configuration size is <Current Config Size> Bytes which exceeds the <Max Config Size> Bytes safe limit. Please check your configuration." | |
LOG_INFO | 45017 | 'STM_WRAPPER' "creating db snapshot for stm at <Date> because current config.xml = previous config.xml" | |
LOG_WARN | 45018 | 'STM_WRAPPER' "System in failed state: attempting recovery for config" | |
LOG_ERROR | 45019 | 'STM_WRAPPER' "STM startup failed. Retrying with blank config" | |
LOG_ERROR | 45020 | 'STM_WRAPPER' "STM startup failed even with blank config. Exiting." | |
LOG_INFO | 45021 | 'STM_WRAPPER' "STM startup succeeded with blank config" | |
LOG_NOTICE | 45022 | 'STM_WRAPPER' "Committing UI configuration" | |
LOG_INFO | 45023 | 'STM_WRAPPER' "creating db snapshot last successful digest at <Date>" | |
LOG_NOTICE | 45024 | 'STM_WRAPPER' "Killing STM for dumping core" | |
NTP | |||
LOG_INFO | 48301 | 'NTP' "Time synced with the NTP server at <Server Name/IP Address> time after sync = <Timestamp>" | |
LOG_ERROR | 48302 | "NTP" "Couldn't connect to NTP server: <Server Name/IP Address>" | |
LOG_INFO | 48303 | 'NTP' "Time synced with the NTP server at ntp.barracudacentral.com time after sync = <Timestamp>" | |
PROCESS SCHEDULE | |||
LOG_WARN | 49001 | 'PROCESS SCHEDULE' "Scheduled Backup failed : System has locked key configuration" |