All Data Insight return Codes (as of DI 3.0.1)

Article:TECH204399  |  Created: 2013-03-27  |  Updated: 2013-09-30  |  Article URL http://www.symantec.com/docs/TECH204399
Article Type
Technical Solution

Product(s)

Environment

Issue



I see a return code or error code in Data Insight I've never seen before...what does it mean?


Solution



All events published by the product as of 3.0.1:

## Scanner events: 100 - 199
100=Full scan started for {1.EN_US} {0.EN_US}
101=Full scan for {1.EN_US} {0.EN_US} finished
102=Full scan for {1.EN_US} {0.EN_US} failed
103=Incremental scan started for {1.EN_US} {0.EN_US}
104=Incremental scan for {1.EN_US} {0.EN_US} finished
105=Incremental scan for {1.EN_US} {0.EN_US} failed
106=Full scan for {1.EN_US} {0.EN_US} cancelled
107=All scans aborted by user
108=All incremental scans aborted by user
109={1.EN_US} {0.EN_US} added to full scan queue
110={1.EN_US} {0.EN_US} added to incremental scan queue
111={1.EN_US} {0.EN_US} removed from full scan queue
112={1.EN_US} {0.EN_US} removed from incremental scan queue
113=Incremental scan for {1.EN_US} {0.EN_US} cancelled
114=Full scan for {1.EN_US} {0.EN_US} paused
115=Incremental scan for {1.EN_US} {0.EN_US} paused
116=Full scan for {1.EN_US} {0.EN_US} resumed
117=Incremental scan for {1.EN_US} {0.EN_US} resumed
118=No scanner error files for filer
119=Scanner error files present for filer
120=Incremental scanner dropped path records after repeated failures. A Full scan is required to fetch the path details.
130=Scan successful for {0.EN_US} domain {1.EN_US}
131=Scan failed for {0.EN_US} domain {1.EN_US}

## Indexer events: 200 - 299
200=Index for {1.EN_US} {0.EN_US} updated with audit information
201=Index for {1.EN_US} {0.EN_US} updated with scan information
202=Error updating audit information for {2.EN_US} {0.EN_US}. Input file {1.EN_US} moved to data/indexer/err folder
203=Error updating scan information for {2.EN_US} {0.EN_US}. Input file {1.EN_US} moved to data/indexer/err folder
204=Index for {2.EN_US} {0.EN_US} located at \"{1.EN_US}\" could not be merged
205=Index for {1.EN_US} {0.EN_US} updated with tags information
206=Error updating tags information for {2.EN_US} {0.EN_US}. Input file {1.EN_US} moved to data/indexer/err folder
207=Purging stale folder {0.EN_US}
208=Segment(s) {0.EN_US} for month(s) of {1.EN_US} for {3.EN_US} {2.EN_US} could not be archived
209=Segment(s) {0.EN_US} for month(s) of {1.EN_US} for {3.EN_US} {2.EN_US} could not be purged
210=Segment(s) {0.EN_US} for month(s) of {1.EN_US} for {3.EN_US} {2.EN_US} archived successfully. NOTE: It could be some time before the segments get moved to the archive folder
211=Segment(s) {0.EN_US} for month(s) of {1.EN_US} for {3.EN_US} {2.EN_US} purged successfully
212=Error restoring segments for {1.EN_US} {0.EN_US}
213=Segment(s) {0.EN_US} for month(s) of {1.EN_US} for {3.EN_US} {2.EN_US} restored successfully
214=Segment(s) {0.EN_US} for month(s) of {1.EN_US} for {3.EN_US} {2.EN_US} could not be restored
215=Corrupt index detected for {2.EN_US} {0.EN_US}. Index will be recreated. Backup of corrupt index at {1.EN_US}
216=Error creating index for {1.EN_US} {0.EN_US}
217=New index created for {2.EN_US} {0.EN_US} at {1.EN_US}
218=Corrupt index detected for {2.EN_US} {0.EN_US}. Index will be recreated. Backup of corrupt index will not be taken because previous backup already exists at {1.EN_US}
219=No index error files for filer
220=Index error files present for filer
221=Index for {2.EN_US} {0.EN_US} at {1.EN_US} rehashed successfully
222=Error rehashing index for {2.EN_US} {0.EN_US} at {1.EN_US}
223=Error updating activity index for {0.EN_US} {1.EN_US} at {2.EN_US}

## Collector events: 300 - 399
300={0.EN_US} input files processed by collector for {1.EN_US} shares
301=Error generating audit log data for extracts {0.EN_US} of filer {2.EN_US}. Input files {1.EN_US} moved to data/collector/err folder
302={0.EN_US} registration failed for filer {1.EN_US}
303=Volume capacity information could not be obtained for filer {0.EN_US}
304=Error splitting pathdb files for shares {0.EN_US}
305=Error collecting audit logs from sharepoint
306=Auditing enabled for site collection
307=Auditing disabled for site collection
308=Error enabling auditing for site collection
309=Error disabling auditing for site collection
310=Error fetching audit events from Veritas Storage Foundation filer
311=Error mapping users for filer
312=Filer is associated with unknown domain {0.EN_US}. User mapping will be incorrect
313=Filer is associated with unknown domain type {0.EN_US}. User mapping will be incorrect
314=Error compacting changelog {0.EN_US}. Offending file will be moved to collector/err folder
315=Fetched audit events successfully from Veritas Storage Foundation filer
316=High filer latency observed on filer
317=No collector error files for filer
318=Collector error files present for filer

## AD scanner events: 400 - 499
400=Starting Active Directory scan
401=Active Directory scan finished
402=Active Directory scan failed. Please check log file \"{1.EN_US}\" for details
403=Active Directory scan failed due to corrupt users database. Please remove users.db.N file from $data/users folder and re-scan Active Directory
404=Active directory scan aborted by user {0.EN_US}
405=Local user scan finished
406=Local user scan failed. Please check log file \"{1.EN_US}\" for details
407=Active Directory scan finished successfully. However, BU Mapping file ({0.EN_US}) could not be imported. Please check log file \"{1.EN_US}\" for details

## Commd events: 500 - 599
500=File {0.EN_US} uploaded to {1.EN_US} ({2.EN_US} kb)
501=File {0.EN_US} moved to inbox ({1.EN_US} kb)
502=File {0.EN_US} moved to folder {1.EN_US}
503=Configuration updated from version {0.EN_US} to {1.EN_US} ({2.EN_US})
504=Communication service started ({0.EN_US})
505=Communication service stopped
506=Policy execution failed for instance {0.EN_US}
507=All node report execution failed for instance {0.EN_US}

## Console events: 600 - 699
# Add/Delete/Edit of {0.EN_US}=obj_type {1.EN_US}=obj_id
600={0.EN_US} {1.EN_US} added
601={0.EN_US} {1.EN_US} deleted
602={0.EN_US} {1.EN_US} modified
603=User {0.EN_US} logged in
604=User {0.EN_US} logged out
605=Login failed for {0.EN_US}
606=Management console started ({0.EN_US})
607=Management console stopped
608=Server {0.EN_US} has connected
609=Server {1.EN_US} has disconnected
610={0.EN_US} {1.EN_US} enabled
611={0.EN_US} {1.EN_US} disabled
612=Event notification settings updated
613=DFS Mappings uploaded
614=Scanning disabled at a global level
615=Scanning enabled at a global level
616=Event monitoring disabled at a global level
617=Event monitoring enabled at a global level
618=Folder ACL scanning enabled at a global level
619=Folder ACL scanning disabled at a global level
620=Throttling enabled for {0.EN_US} file system scanner at a global level
621=Throttling disabled for {0.EN_US} file system scanner at a global level
622=Exclude rules updated


## Data retention 623-643

623=Data will not be archived automatically
624=Data older than {0.EN_US} months will be archived automatically
625=Data will not be purged automatically
626=Data older than {0.EN_US} months will be purged automatically
627=Data for deleted shares will be purged automatically
628=Data for deleted shares will not be purged automatically
629=Events data will not be purged automatically
630=Events data older than {0.EN_US} months will be purged automatically
631=Alerts data will not be purged automatically
632=Alerts data older than {0.EN_US} months will be purged automatically
633=Extracting file/folder ownership information enabled
634=Extracting file/folder ownership information disabled
635=Backup operator mode for scanner changed from {0.EN_US} to {1.EN_US}
636=SMTP settings updated
637=DLP settings updated
638=Watchdog service started ({0.EN_US})
639=Email could not be sent due an error (Subject: {0.EN_US})
640=The node is now running in NORMAL mode
641=The node is now running in SAFEGUARD mode
642=Communication Service is now running in NORMAL mode
643=Communication Service is now running in SAFEGUARD mode

## Server events: 700 - 799
700=Memory Usage: {0.EN_US}mb total {1.EN_US}mb used {2.EN_US}mb free
701=Disk Usage: {0.EN_US}mb total {1.EN_US}mb used {2.EN_US}mb free
702=New core file {0.EN_US} detected
703={0.EN_US} service configured successfully
704=Error configuring {0.EN_US} service
705={0.EN_US} service unconfigured successfully
706=Error unconfiguring {0.EN_US} service
707=Server Information: OS: {0.EN_US} CPU:{1.EN_US} Memory: {2.EN_US}
708=Service {0.EN_US} has changed from {1.EN_US} To  {2.EN_US} state
709=Service {0.EN_US} has changed from {1.EN_US} To  {2.EN_US} state
710={0.EN_US}, CPU usage is consistently over {1.EN_US}% for past {2.EN_US} monitor cycles
711={0.EN_US}, Memory usage is consistently over {1.EN_US}% for past {2.EN_US} monitor cycles
712={0.EN_US}, Disk usage for {1.EN_US} consistently over {2.EN_US}% for past {3.EN_US} monitor cycles
713=Host {0.EN_US} missed heartbeat with management server
714=Directory threshold for {0.EN_US} exceeds; current count is {1.EN_US}
715=Index check job falied
716=Symantec Data Insight {0.EN_US} installed
717=Job {0.EN_US} aborted by user
718=Host {0.EN_US} is back online
719=Worker node {0.EN_US} registered with the management server
720=Worker node {0.EN_US} re-registered with the management server
721=User requested agent {0.EN_US} on Windows File Server {1.EN_US}
722=Agent {0.EN_US} on Windows File Server {1.EN_US} successful
723=Agent {0.EN_US} on Windows File Server {1.EN_US} failed
724=User requested {0.EN_US} cancellation for Windows File Server {1.EN_US}
725=Scanner setting: ''{0.EN_US}'' changed from {1.EN_US} to {2.EN_US}
726=Scanner setting: ''{0.EN_US}'' reset to default
727=Indexer setting: ''{0.EN_US}'' changed from {1.EN_US} to {2.EN_US}
728=Indexer setting: ''{0.EN_US}'' reset to default
729=Audit log preprocessor (collector.exe) setting: 'schedule' changed from {0.EN_US} to {1.EN_US}
730=Audit log preprocessor (collector.exe) setting: 'schedule' reset to default
731=High availability setting: ''{0.EN_US}'' changed from {1.EN_US} to {2.EN_US}
732=High availability setting: ''{0.EN_US}'' reset to default
733=Report setting: ''{0.EN_US}'' changed from {1.EN_US} to {2.EN_US}
734=Report setting: ''{0.EN_US}'' reset to default
735=Window file server filter driver setting: ''{0.EN_US}'' changed from {1.EN_US} to {2.EN_US}
736=Window file server filter driver setting: ''{0.EN_US}'' reset to default
737=Miscellaneous setting: ''{0.EN_US}'' changed from {1.EN_US} to {2.EN_US}
738=Miscellaneous setting: ''{0.EN_US}'' reset to default
739=Received new agent bundle
740=Windows File Server Agent Bundle download failed
741=User requested Windows File Server bundle to be uploaded
742=Windows File Server agent bundle upload canceled by user
743=Windows File Server agent bundle upload failed
744=Advanced server setting ''{0.EN_US}'' changed from ''{1.EN_US}'' to ''{2.EN_US}''
745=Advanced server setting ''{0.EN_US}'' reset to the default value
746=Advanced server setting ''{0.EN_US}'' set to ''{1.EN_US}''
747=Advanced server setting ''{0.EN_US}'' deleted
748=Symantec Data Insight data upgraded from version {0.EN_US} to version {1.EN_US}
750={0.EN_US}, CPU usage is normal
751={0.EN_US}, Memory usage is normal
752={0.EN_US}, Disk usage for {1.EN_US} is normal
754=Files in directory {0.EN_US} are below threshold value
755=Service {0.EN_US} has is now {1.EN_US}
756=Service {0.EN_US} is now running
# Alerts and policies events
801=Policy created
802=Policy updated
803={0.EN_US} policies deleted
804={0.EN_US} alerts updated
805={0.EN_US} alerts deleted
806={0.EN_US} sensitive file paths imported from Data Loss Prevention Server
807=Error importing Sensitive file paths from Data Loss Prevention Server
808=Could not notify custodian {0.EN_US} on email address {1.EN_US}
# Workflow events
900=Unable to get categories from EV server

# Fpolicy events
2180=DataInsight Fpolicy Server is unable to register "
                "with filer %s. This may happen if fpolicy server "
                "does not have enough privileges to connect to the "
                "filer. This may also happen if a corresponding "
                "policy has not been created on the filer or the "
                "policy name length is too long. If a fpolicy server "
                "is already registered with the filer from this IP "
                "address the registration may fail. Please refer to "
                "the log file fpolicyd.log for more details
1062=Disconnected from filer %s
2176=Disconnected fpolicy %s serverid %d from filer %s
1124=DataInsightFpolicy service could not get filer version "
                "of %s. Possible reasons: Invalid DataInsightFpolicy "
                "service logon credentials, filer ONTAP version is "
                "not  >= 7.0 and <= 8.0 or there is problem in "
                "network connectivity with the filer
1117=Filer %s connected.
1111=Filer %s is dropping connection to this host. "
                                "Possible reasons: filer cannot ping "
                                "this host using IP, hostname or "
                                "FQHN. It may also be a DNS issue. "
                                "In most cases adding an entry for "
                                "this host in the hosts file on the "
                                "filer works. The Windows firewall "
                                "should be turned off on this host "
                                "or port 139 and 445 should not be "
                                "blocked by firewall. Please ensure "
                                "that the time on the filer and this "
                                "host do not differ by more than 5 "
                                "minutes.
2212=All vfilers from the filer %s "
                                "will be disconnected. %s %.3lf millisecs which is more than "
                                "high watermark %u millisecs
2159=Filer %s will be disconnected. %s %.3lf millisecs which "
                                "is more than high watermark %u millisecs
2159=Filer %s will be disconnected. %s %.3lf millisecs which "
                                "is more than high watermark %u millisecs
2163=Filer %s to be connected. "
                                "Avg cifs latency %.3lf millisecs, Avg cifs write "
                                "latency %.3lf millisecs, Avg cifs read latency %.3lf "
                                "millisecs, Avg nfsv3 latency %.3lf millisecs, Avg "
                                "nfsv3 write latency %.3lf millisecs, Avg nfsv3 read "
                                "latency %.3lf millisecs are all less than low "
                                "watermarks of %u, %u, %u, %u, %u and %u millisecs "
                                "respectively."

# Windows File Server Agent events
1149=The kernel driver's ring buffer is full. "
1150=The kernel driver's ring buffer is out of "
                                                                "memory. Some events may have been dropped

# SharePoint events
1113=The sharepoint client and the webservice versions "
                                                  "do not match. Client ver: %s Webservice version %s "
                                                  "Sharepoint URL: %s"
1114=The sharepoint client and the webservice versions "
                                                  "match. Client ver: %s Webservice version %s "
                                                  "Sharepoint URL: %s"
1115=Sharepoint audit success for %s

# Custodian events
185=User %s successfully made %u custodian assignment(s)
1001=Custodian %s added to %s by %s
1002=Error adding custodian %s to %s
1003=Custodians %sremoved from %s by %s
1004=Error removing custodians %sfrom %s
1003=Custodians %sremoved from %s by %s
1004=Error removing custodians %sfrom %s
1005=All custodian assignments deleted for %s by %s
1006=Error deleting custodian assignments for %s
 




Article URL http://www.symantec.com/docs/TECH204399


Terms of use for this information are found in Legal Notices