• No results found

The settings of Kaspersky Anti-Virus SNMP traps are summarized in the table below.

Table 63. Kaspersky Anti-Virus SNMP traps

TRAP DESCRIPTION SETTINGS

eventThreatDetected An object has been

detected.

eventBackupStorageSizeExceeds Maximum backup size

exceeded. The total size of data in Backup has

eventThresholdBackupStorageSizeExceeds Backup free space threshold reached. The amount of free size in Backup assigned by the

eventQuarantineStorageSizeExceeds Maximum Quarantine size exceeded. The total size of data in Quarantine has

eventThresholdQuarantineStorageSizeExceeds Quarantine free space threshold reached. The amount of free size in Quarantine assigned by the Quarantine threshold of free space is less than the specified value.

eventObjectNotQuarantined Quarantining error eventSeverity

eventDateAndTime

KA S P E R S K Y AN T I- VI R U S C O U N T E R S

145

TRAP DESCRIPTION SETTINGS

eventObjectNotBackuped Error of saving an object

copy in the backup storage

eventSeverity

eventBackupInternalError Backup has experienced

an error.

eventSeverity eventDateAndTime eventSource eventReason

eventAVBasesOutdated Anti-Virus database is out

of date. Number of days since the last execution of database update task (local task, or group task, or task for sets of computers) is being calculated.

eventSeverity eventDateAndTime eventSource days

eventAVBasesTotallyOutdated Anti-Virus database is obsolete. Number of days since the last execution of database update task (local task, or group task, or task for sets of computers) is being calculated. eventCriticalAreasScanWasntPerformForALongTime Critical areas have not

been scanned for a long time. Calculated as the number of days since the last completion of the

eventLicenseHasExpired License has expired. eventSeverity

eventDateAndTime eventSource

eventLicenseExpiresSoon License expires soon.

Calculated as the number of days until the expiration date for the license.

eventSeverity eventDateAndTime eventSource days

AD M I N I S T R A T O R'S GU I D E

146

TRAP DESCRIPTION SETTINGS

eventTaskInternalError Task completion error eventSeverity

eventDateAndTime eventSource errorCode knowledgeBaseId taskName

eventUpdateError Error performance an

update task

eventSeverity eventDateAndTime taskName

updaterErrorEventReason The following table describes the settings of traps and possible parameter values.

Table 64. SNMP traps: values of the settings

SETTING DESCRIPTION AND POSSIBLE VALUES

eventDateAndTime Event time.

eventSeverity Severity level. The setting can take the following values:

 critical (1) – critical,

 warning (2) – warning,

 info (3) – informational.

userName Username (for example, name of the user that attempted to gain access to an infected file).

computerName Computer name (for example, name of the computer from which a user attempted to gain access to an infected file).

eventSource Event source: functional component where the event was generated. The setting can take the following values:

 unknown (0) – functional component not known;

 quarantine (1) – Quarantine;

 backup (2) – Backup;

 reporting (3) – task logs;

 updates (4)– Update;

 realTimeProtection (5) - Real-time file protection;

 onDemandScanning (6) – On-demand scan;

 product (7) – event related to operation of Kaspersky Anti-Virus as a whole rather than operation of individual components;

 systemAudit (8) – system audit log;

 nasProtection (10) – Network storage protection.

eventReason What triggered the event. The setting can take the following values:

 reasonUnknown (0) – reason not known,

 reasonInvalidSettings (1) – only for a Backup and Quarantine events, displayed if Quarantine or Backup is unavailable (insufficient access permissions or the folder is specified incorrectly in the Quarantine settings -- for example, a network path is specified). In this case, Kaspersky Anti-Virus will use the default Backup or Quarantine folder.

objectName Object name (for example, name of the file where the virus was detected).

KA S P E R S K Y AN T I- VI R U S C O U N T E R S

147

SETTING DESCRIPTION AND POSSIBLE VALUES

threatName The name of object according to the Virus Encyclopedia classification (http://www.securelist.com/en/). This name is included in the full name of the detected object that Kaspersky Anti-Virus returns on detecting an object. You can view the full name of the detected object in the task log (see the section "Viewing statistics and information of a Kaspersky Anti-Virus task using tasks logs" on page 88).

detectType Type of object detected.

The setting can take the following values:

 undefined (0) – undefined;

 virware – classic viruses and network worms;

 trojware – Trojans;

 malware – other malicious programs;

 adware – advertising software;

 pornware – pornographic software;

 Riskware: legitimate applications that may be used by intruders to harm the user's computer or data.

detectCertainty Certainty level for threat detection. The setting can take the following values:

 Suspicion (probably infected) – Kaspersky Anti-Virus has detected a partial match between a section of the object code and the known malicious code section.

 Sure (infected) – Kaspersky Anti-Virus has detected a complete match between a section of the object code and the known malicious code section.

days Number of days (for example, the number of days until the license expiration date)

errorCode Error code.

knowledgeBaseId Address of a knowledge base article (for example, address of an article that explains a particular error).

taskName Task name.

updaterErrorEventReason Reason of the update error. The setting can take the following values:

 reasonUnknown(0) – reason is unknown;

 reasonAccessDenied – access denied;

 reasonUrlsExhausted – the list of update sources is exhausted;

 reasonInvalidConfig – invalid configuration file;

 reasonInvalidSignature – invalid signature;

 reasonCantCreateFolder – folder cannot be created;

 reasonFileOperError – file error;

 reasonDataCorrupted – object is corrupted;

 reasonConnectionReset – connection reset;

 reasonTimeOut – connection timeout exceeded;

 reasonProxyAuthError – proxy authentication error;

 reasonServerAuthError – server authentication error;

 reasonHostNotFound – computer not found;

 reasonServerBusy – server unavailable;

 reasonConnectionError – connection error;

 reasonModuleNotFound – object not found;

 reasonBlstCheckFailed(16) – error checking the black list of keys. It is possible that databases updates were being published at the moment of update; please repeat the update in a few minutes.

See the list of these reasons and possible administrator actions on the Technical Support website in the section "If a program generated an error"

(http://support.kaspersky.com/error).

AD M I N I S T R A T O R'S GU I D E

148

SETTING DESCRIPTION AND POSSIBLE VALUES

storageObjectNotAddedEventReason The reason why the object was not backed up or quarantined. The setting can take the following values:

 reasonUnknown(0) – reason is unknown;

 reasonStorageInternalError – database error; please restore Kaspersky Anti-Virus;

 reasonStorageReadOnly – database is read-only; please restore Kaspersky Anti-Virus;

 reasonStorageIOError – input-output error: a) Kaspersky Anti-Virus is corrupted, please restore Kaspersky Virus; b) disk with Kaspersky Anti-Virus files is corrupted;

 reasonStorageCorrupted – storage is corrupted; please restore Kaspersky Anti-Virus;

 reasonStorageFull – database is full; free up disk space;

 reasonStorageOpenError – database file could not be opened; please restore Kaspersky Anti-Virus;

 reasonStorageOSFeatureError – some operating system features do not correspond to Kaspersky Anti-Virus requirements.

 reasonObjectNotFound – object being placed to Quarantine does not exist on the disk.

 reasonObjectAccessError – insufficient privileges for using Backup API: the account under which the operation is attempted does not have Backup Operator privileges.

 reasonDiskOutOfSpace – not enough space on the disk.

149

Related documents