The settings of Kaspersky Anti-Virus SNMP traps are summarized in the table below.
Table 63. Kaspersky Anti-Virus SNMP traps
TRAP DESCRIPTION SETTINGS
eventThreatDetected An object has been
detected.
eventBackupStorageSizeExceeds Maximum backup size
exceeded. The total size of data in Backup has
eventThresholdBackupStorageSizeExceeds Backup free space threshold reached. The amount of free size in Backup assigned by the
eventQuarantineStorageSizeExceeds Maximum Quarantine size exceeded. The total size of data in Quarantine has
eventThresholdQuarantineStorageSizeExceeds Quarantine free space threshold reached. The amount of free size in Quarantine assigned by the Quarantine threshold of free space is less than the specified value.
eventObjectNotQuarantined Quarantining error eventSeverity
eventDateAndTime
KA S P E R S K Y AN T I- VI R U S C O U N T E R S
145
TRAP DESCRIPTION SETTINGS
eventObjectNotBackuped Error of saving an object
copy in the backup storage
eventSeverity
eventBackupInternalError Backup has experienced
an error.
eventSeverity eventDateAndTime eventSource eventReason
eventAVBasesOutdated Anti-Virus database is out
of date. Number of days since the last execution of database update task (local task, or group task, or task for sets of computers) is being calculated.
eventSeverity eventDateAndTime eventSource days
eventAVBasesTotallyOutdated Anti-Virus database is obsolete. Number of days since the last execution of database update task (local task, or group task, or task for sets of computers) is being calculated. eventCriticalAreasScanWasntPerformForALongTime Critical areas have not
been scanned for a long time. Calculated as the number of days since the last completion of the
eventLicenseHasExpired License has expired. eventSeverity
eventDateAndTime eventSource
eventLicenseExpiresSoon License expires soon.
Calculated as the number of days until the expiration date for the license.
eventSeverity eventDateAndTime eventSource days
AD M I N I S T R A T O R'S GU I D E
146
TRAP DESCRIPTION SETTINGS
eventTaskInternalError Task completion error eventSeverity
eventDateAndTime eventSource errorCode knowledgeBaseId taskName
eventUpdateError Error performance an
update task
eventSeverity eventDateAndTime taskName
updaterErrorEventReason The following table describes the settings of traps and possible parameter values.
Table 64. SNMP traps: values of the settings
SETTING DESCRIPTION AND POSSIBLE VALUES
eventDateAndTime Event time.
eventSeverity Severity level. The setting can take the following values:
critical (1) – critical,
warning (2) – warning,
info (3) – informational.
userName Username (for example, name of the user that attempted to gain access to an infected file).
computerName Computer name (for example, name of the computer from which a user attempted to gain access to an infected file).
eventSource Event source: functional component where the event was generated. The setting can take the following values:
unknown (0) – functional component not known;
quarantine (1) – Quarantine;
backup (2) – Backup;
reporting (3) – task logs;
updates (4)– Update;
realTimeProtection (5) - Real-time file protection;
onDemandScanning (6) – On-demand scan;
product (7) – event related to operation of Kaspersky Anti-Virus as a whole rather than operation of individual components;
systemAudit (8) – system audit log;
nasProtection (10) – Network storage protection.
eventReason What triggered the event. The setting can take the following values:
reasonUnknown (0) – reason not known,
reasonInvalidSettings (1) – only for a Backup and Quarantine events, displayed if Quarantine or Backup is unavailable (insufficient access permissions or the folder is specified incorrectly in the Quarantine settings -- for example, a network path is specified). In this case, Kaspersky Anti-Virus will use the default Backup or Quarantine folder.
objectName Object name (for example, name of the file where the virus was detected).
KA S P E R S K Y AN T I- VI R U S C O U N T E R S
147
SETTING DESCRIPTION AND POSSIBLE VALUES
threatName The name of object according to the Virus Encyclopedia classification (http://www.securelist.com/en/). This name is included in the full name of the detected object that Kaspersky Anti-Virus returns on detecting an object. You can view the full name of the detected object in the task log (see the section "Viewing statistics and information of a Kaspersky Anti-Virus task using tasks logs" on page 88).
detectType Type of object detected.
The setting can take the following values:
undefined (0) – undefined;
virware – classic viruses and network worms;
trojware – Trojans;
malware – other malicious programs;
adware – advertising software;
pornware – pornographic software;
Riskware: legitimate applications that may be used by intruders to harm the user's computer or data.
detectCertainty Certainty level for threat detection. The setting can take the following values:
Suspicion (probably infected) – Kaspersky Anti-Virus has detected a partial match between a section of the object code and the known malicious code section.
Sure (infected) – Kaspersky Anti-Virus has detected a complete match between a section of the object code and the known malicious code section.
days Number of days (for example, the number of days until the license expiration date)
errorCode Error code.
knowledgeBaseId Address of a knowledge base article (for example, address of an article that explains a particular error).
taskName Task name.
updaterErrorEventReason Reason of the update error. The setting can take the following values:
reasonUnknown(0) – reason is unknown;
reasonAccessDenied – access denied;
reasonUrlsExhausted – the list of update sources is exhausted;
reasonInvalidConfig – invalid configuration file;
reasonInvalidSignature – invalid signature;
reasonCantCreateFolder – folder cannot be created;
reasonFileOperError – file error;
reasonDataCorrupted – object is corrupted;
reasonConnectionReset – connection reset;
reasonTimeOut – connection timeout exceeded;
reasonProxyAuthError – proxy authentication error;
reasonServerAuthError – server authentication error;
reasonHostNotFound – computer not found;
reasonServerBusy – server unavailable;
reasonConnectionError – connection error;
reasonModuleNotFound – object not found;
reasonBlstCheckFailed(16) – error checking the black list of keys. It is possible that databases updates were being published at the moment of update; please repeat the update in a few minutes.
See the list of these reasons and possible administrator actions on the Technical Support website in the section "If a program generated an error"
(http://support.kaspersky.com/error).
AD M I N I S T R A T O R'S GU I D E
148
SETTING DESCRIPTION AND POSSIBLE VALUES
storageObjectNotAddedEventReason The reason why the object was not backed up or quarantined. The setting can take the following values:
reasonUnknown(0) – reason is unknown;
reasonStorageInternalError – database error; please restore Kaspersky Anti-Virus;
reasonStorageReadOnly – database is read-only; please restore Kaspersky Anti-Virus;
reasonStorageIOError – input-output error: a) Kaspersky Anti-Virus is corrupted, please restore Kaspersky Virus; b) disk with Kaspersky Anti-Virus files is corrupted;
reasonStorageCorrupted – storage is corrupted; please restore Kaspersky Anti-Virus;
reasonStorageFull – database is full; free up disk space;
reasonStorageOpenError – database file could not be opened; please restore Kaspersky Anti-Virus;
reasonStorageOSFeatureError – some operating system features do not correspond to Kaspersky Anti-Virus requirements.
reasonObjectNotFound – object being placed to Quarantine does not exist on the disk.
reasonObjectAccessError – insufficient privileges for using Backup API: the account under which the operation is attempted does not have Backup Operator privileges.
reasonDiskOutOfSpace – not enough space on the disk.
149