Skip to content

SIEM Event Reference

This page is the complete reference for the events forwarded by SIEM Integration: every event type, when it fires, and the message fields it carries. To configure forwarding and choose which events are enabled, see the SIEM Integration settings page.

Events are emitted in CEF (Common Event Format, the default) or Legacy key/value format. A CEF event looks like this:

CEF:0|Lockfy|Enterprise|<productVersion>|<eventClassId>|<name>|<severity>|<extensions>

The eventClassId is stable per event type, so SIEM correlation rules survive renames.

Every event carries the same base fields, regardless of category:

CEF keyMeaning
rtEvent time (milliseconds since epoch, UTC)
suserActor — the operator, account, or system/agent that triggered the event
duserTarget account, where applicable
dvchostWorkstation name, where applicable
srcSource IP, where available (the agent’s address for agent-originated events)
outcomesuccess or failure, where applicable
severityExplicit CEF severity, 0–10 (see severity)
cs1 (serverInstance)The API instance that emitted the event
cs2 (workstationId)Workstation ID, when the event concerns a workstation

Event-specific fields (the “Fields” column below) are emitted as CEF custom-string pairs (csNLabel/csN) following serverInstance and workstationId. In Legacy format the same values appear as key="value" pairs after the event name.

LevelCEF value
Info1
Low3
Medium5
High7
Critical10

Some events set severity dynamically (noted in their row) — for example, enabling a disabled account is higher severity than disabling one.

Emitted by the agent as workstation session state changes. Actor and target are the session’s user account; src is the agent’s IP.

EventeventClassIdSeverityFires whenFields
Session Startedsession.startInfoA session beginssuser/duser = user account · src · sessionId, console
Session Endedsession.endInfoA session endssuser/duser = user account · src · sessionId, console
Session Idledsession.idleLowA session goes idlesuser/duser = user account · src · sessionId, console
Session Activatedsession.activeLowA session resumes from idlesuser/duser = user account · src · sessionId, console
Session Lockedsession.lockInfoA session is lockedsuser/duser = user account · src · sessionId, console
Session Unlockedsession.unlockInfoA session is unlockedsuser/duser = user account · src · sessionId, console
Session Locked By Lockfysession.protectMediumLockfy’s session-protection enforces a locksrc · sessionId

Emitted when a local-account password is revealed or rotated, or the operation fails.

EventeventClassIdSeverityFires whenFields
Local Account Password Accessedcred.accessHighA local-account password is revealedduser = account · dvchost · src · outcome=success
Local Account Password Randomizedcred.randomizeMediumA local-account password is rotatedduser = account · dvchost · src · outcome=success
Local Account Password Operation Failedcred.failHighA reveal/rotation operation failsduser = account · dvchost · src · outcome=failure

Emitted by the applications-policy validator when a workstation’s compliance changes.

EventeventClassIdSeverityFires whenFields
Workstation Compliance Changedcompliance.changedInfo (compliant) / High (non-compliant)A workstation flips compliant ↔ non-compliantdvchost · outcome (compliant) · compliant, offendingCount, domain
Compliance Requirement Raisedcompliance.requirementMediumOne per offending app on a non-compliant workstationdvchost · action (Install / Uninstall / Update), applicationId

Operator-initiated portal changes. suser is the acting operator.

EventeventClassIdSeverityFires whenFields
Configuration Changedadmin.configMediumA portal configuration setting is changedsuser · outcome=success · setting
Policy Changedadmin.policyMediumA lock/applications policy is created, updated, or deletedsuser · outcome=success · policyType (lock / applications), operation
Manual Session Lockadmin.lockMediumAn operator locks a session from the portalsuser · dvchost · outcome=success · sessionId
User Or Role Changedadmin.userHighA portal user is created, removed, or has permissions/role changedsuser · outcome=success · userId, operation

Detected during agent local-accounts inventory. These are agent-originated (no operator), so the actor is the system; duser is the affected account.

EventeventClassIdSeverityFires whenFields
Local Account Createdaccount.createMediumA local account appears on a workstationduser = account · dvchost · sid
Local Account Deletedaccount.deleteMediumA local account is removedduser = account · dvchost · sid
Local Account Status Changedaccount.statusInfo (disabled) / High (enabled)A local account is enabled or disabledduser = account · dvchost · sid, disabled
Local Account Password Expiry Changedaccount.pwdexpiryLowThe password-expiry flag changesduser = account · dvchost · sid, passwordExpires
Local Account Added To Groupaccount.group.addHighThe account is added to a local groupduser = account · dvchost · sid, group
Local Account Removed From Groupaccount.group.removeMediumThe account is removed from a local groupduser = account · dvchost · sid, group

Emitted when an agent connects or disconnects.

EventeventClassIdSeverityFires whenFields
Workstation Connectedasset.connectInfoAn agent connects (comes online)dvchost · src · outcome=success
Workstation Disconnectedasset.disconnectLowAn agent disconnects (goes offline)dvchost

Detected during agent inventory. Agent-originated (no operator).

EventeventClassIdSeverityFires whenFields
Application Installedapp.installLowAn application appears on a workstationdvchost · app, publisher, version
Application Removedapp.uninstallLowAn application is removeddvchost · app, publisher, version
Browser Extension Installedext.installMediumA browser extension is installeddvchost · extension, extensionId
Browser Extension Removedext.uninstallLowA browser extension is removeddvchost · extension, extensionId

Emitted by the portal authentication flow.

EventeventClassIdSeverityFires whenFields
Authentication Succeededauth.successInfoA portal sign-in succeedssuser/duser = email · src · outcome=success
Authentication Failedauth.failureHighA portal sign-in failssuser/duser = username · src · outcome=failure
Token Issuedauth.token.issueLowAn access token is issuedsuser = email/client · src · outcome=success · grant (password / refresh_token / client_credentials)

A cred.access event in CEF (event-specific fields appear as csN pairs after serverInstance and workstationId):

CEF:0|Lockfy|Enterprise|2.13.3.1|cred.access|Local Account Password Accessed|7|rt=1782283722456 [email protected] duser=sampleuser dvchost=WS-01 src=203.0.113.10 outcome=success cs1Label=serverInstance cs1=api-01 cs2Label=workstationId cs2=8de1...

The same event in Legacy format:

Local Account Password Accessed serverInstance="api-01" actor="[email protected]" account="sampleuser" workstation="WS-01" src="203.0.113.10" outcome="success"