SIEM Event Reference
This page is the complete reference for the events forwarded by SIEM Integration: every event type, when it fires, and the message fields it carries. To configure forwarding and choose which events are enabled, see the SIEM Integration settings page.
How to read this reference
Section titled “How to read this reference”Events are emitted in CEF (Common Event Format, the default) or Legacy key/value format. A CEF event looks like this:
CEF:0|Lockfy|Enterprise|<productVersion>|<eventClassId>|<name>|<severity>|<extensions>The eventClassId is stable per event type, so SIEM correlation rules survive renames.
Common envelope
Section titled “Common envelope”Every event carries the same base fields, regardless of category:
| CEF key | Meaning |
|---|---|
rt | Event time (milliseconds since epoch, UTC) |
suser | Actor — the operator, account, or system/agent that triggered the event |
duser | Target account, where applicable |
dvchost | Workstation name, where applicable |
src | Source IP, where available (the agent’s address for agent-originated events) |
outcome | success or failure, where applicable |
| severity | Explicit CEF severity, 0–10 (see severity) |
cs1 (serverInstance) | The API instance that emitted the event |
cs2 (workstationId) | Workstation ID, when the event concerns a workstation |
Event-specific fields (the “Fields” column below) are emitted as CEF custom-string
pairs (csNLabel/csN) following serverInstance and workstationId. In Legacy
format the same values appear as key="value" pairs after the event name.
Severity
Section titled “Severity”| Level | CEF value |
|---|---|
| Info | 1 |
| Low | 3 |
| Medium | 5 |
| High | 7 |
| Critical | 10 |
Some events set severity dynamically (noted in their row) — for example, enabling a disabled account is higher severity than disabling one.
Session activity
Section titled “Session activity”Emitted by the agent as workstation session state changes. Actor and target are the
session’s user account; src is the agent’s IP.
| Event | eventClassId | Severity | Fires when | Fields |
|---|---|---|---|---|
| Session Started | session.start | Info | A session begins | suser/duser = user account · src · sessionId, console |
| Session Ended | session.end | Info | A session ends | suser/duser = user account · src · sessionId, console |
| Session Idled | session.idle | Low | A session goes idle | suser/duser = user account · src · sessionId, console |
| Session Activated | session.active | Low | A session resumes from idle | suser/duser = user account · src · sessionId, console |
| Session Locked | session.lock | Info | A session is locked | suser/duser = user account · src · sessionId, console |
| Session Unlocked | session.unlock | Info | A session is unlocked | suser/duser = user account · src · sessionId, console |
| Session Locked By Lockfy | session.protect | Medium | Lockfy’s session-protection enforces a lock | src · sessionId |
Privileged credential
Section titled “Privileged credential”Emitted when a local-account password is revealed or rotated, or the operation fails.
| Event | eventClassId | Severity | Fires when | Fields |
|---|---|---|---|---|
| Local Account Password Accessed | cred.access | High | A local-account password is revealed | duser = account · dvchost · src · outcome=success |
| Local Account Password Randomized | cred.randomize | Medium | A local-account password is rotated | duser = account · dvchost · src · outcome=success |
| Local Account Password Operation Failed | cred.fail | High | A reveal/rotation operation fails | duser = account · dvchost · src · outcome=failure |
Application compliance
Section titled “Application compliance”Emitted by the applications-policy validator when a workstation’s compliance changes.
| Event | eventClassId | Severity | Fires when | Fields |
|---|---|---|---|---|
| Workstation Compliance Changed | compliance.changed | Info (compliant) / High (non-compliant) | A workstation flips compliant ↔ non-compliant | dvchost · outcome (compliant) · compliant, offendingCount, domain |
| Compliance Requirement Raised | compliance.requirement | Medium | One per offending app on a non-compliant workstation | dvchost · action (Install / Uninstall / Update), applicationId |
Admin actions (audit)
Section titled “Admin actions (audit)”Operator-initiated portal changes. suser is the acting operator.
| Event | eventClassId | Severity | Fires when | Fields |
|---|---|---|---|---|
| Configuration Changed | admin.config | Medium | A portal configuration setting is changed | suser · outcome=success · setting |
| Policy Changed | admin.policy | Medium | A lock/applications policy is created, updated, or deleted | suser · outcome=success · policyType (lock / applications), operation |
| Manual Session Lock | admin.lock | Medium | An operator locks a session from the portal | suser · dvchost · outcome=success · sessionId |
| User Or Role Changed | admin.user | High | A portal user is created, removed, or has permissions/role changed | suser · outcome=success · userId, operation |
Local account lifecycle
Section titled “Local account lifecycle”Detected during agent local-accounts inventory. These are agent-originated (no operator),
so the actor is the system; duser is the affected account.
| Event | eventClassId | Severity | Fires when | Fields |
|---|---|---|---|---|
| Local Account Created | account.create | Medium | A local account appears on a workstation | duser = account · dvchost · sid |
| Local Account Deleted | account.delete | Medium | A local account is removed | duser = account · dvchost · sid |
| Local Account Status Changed | account.status | Info (disabled) / High (enabled) | A local account is enabled or disabled | duser = account · dvchost · sid, disabled |
| Local Account Password Expiry Changed | account.pwdexpiry | Low | The password-expiry flag changes | duser = account · dvchost · sid, passwordExpires |
| Local Account Added To Group | account.group.add | High | The account is added to a local group | duser = account · dvchost · sid, group |
| Local Account Removed From Group | account.group.remove | Medium | The account is removed from a local group | duser = account · dvchost · sid, group |
Asset connectivity
Section titled “Asset connectivity”Emitted when an agent connects or disconnects.
| Event | eventClassId | Severity | Fires when | Fields |
|---|---|---|---|---|
| Workstation Connected | asset.connect | Info | An agent connects (comes online) | dvchost · src · outcome=success |
| Workstation Disconnected | asset.disconnect | Low | An agent disconnects (goes offline) | dvchost |
Software inventory
Section titled “Software inventory”Detected during agent inventory. Agent-originated (no operator).
| Event | eventClassId | Severity | Fires when | Fields |
|---|---|---|---|---|
| Application Installed | app.install | Low | An application appears on a workstation | dvchost · app, publisher, version |
| Application Removed | app.uninstall | Low | An application is removed | dvchost · app, publisher, version |
| Browser Extension Installed | ext.install | Medium | A browser extension is installed | dvchost · extension, extensionId |
| Browser Extension Removed | ext.uninstall | Low | A browser extension is removed | dvchost · extension, extensionId |
Authentication & access
Section titled “Authentication & access”Emitted by the portal authentication flow.
| Event | eventClassId | Severity | Fires when | Fields |
|---|---|---|---|---|
| Authentication Succeeded | auth.success | Info | A portal sign-in succeeds | suser/duser = email · src · outcome=success |
| Authentication Failed | auth.failure | High | A portal sign-in fails | suser/duser = username · src · outcome=failure |
| Token Issued | auth.token.issue | Low | An access token is issued | suser = email/client · src · outcome=success · grant (password / refresh_token / client_credentials) |
Example
Section titled “Example”A cred.access event in CEF (event-specific fields appear as csN pairs after
serverInstance and workstationId):
CEF:0|Lockfy|Enterprise|2.13.3.1|cred.access|Local Account Password Accessed|7|rt=1782283722456 [email protected] duser=sampleuser dvchost=WS-01 src=203.0.113.10 outcome=success cs1Label=serverInstance cs1=api-01 cs2Label=workstationId cs2=8de1...The same event in Legacy format:
Local Account Password Accessed serverInstance="api-01" actor="[email protected]" account="sampleuser" workstation="WS-01" src="203.0.113.10" outcome="success"