System log messages
The log messages in this section are issues related to the overall operation of the FortiSwitch unit.
Alarm occurred
ID |
30100 |
Type |
Event log |
Subtype |
System |
Severity |
Alert |
Message |
msg=\"<alarm_ID>\" |
Meaning |
An alarm occurred. |
Alarm acknowledged
ID |
30101 |
Type |
Event log |
Subtype |
System |
Severity |
Alert |
Message |
msg=\"<alarm_ID>\" |
Meaning |
The alarm was acknowledged. |
Domain name in alert email cannot be resolved
ID |
30150 |
Type |
Event log |
Subtype |
System |
Severity |
Notice |
Message |
msg=\"Can't resolve the IP address of <alert_email_address_sender>\" |
Meaning |
The domain name of the sender of the alert email cannot be resolved. |
Alert email failed
ID |
30151 |
Type |
Event log |
Subtype |
System |
Severity |
Notice |
Message |
msg=\"Failed to send alert email from <user_name> to (<user_name>)\" |
Meaning |
Sending the alert email failed. |
Alert email resent
ID |
30152 |
Type |
Event log |
Subtype |
System |
Severity |
Information |
Message |
msg=\"Resending alert e-mail with <number of alerts> pending alert(s) from <user_name> to (<user_name>)\" |
Meaning |
The alert email was successfully resent. |
FortiSwitch unit started
ID |
30200 |
Type |
Event log |
Subtype |
System |
Severity |
Information |
Message |
msg=\"FortiSwitch started <time>\" |
Meaning |
The FortiSwitch unit was started. |
FortiSwitch unit rebooted
ID |
30201 |
Type |
Event log |
Subtype |
System |
Severity |
Critical |
Message |
|
Meaning |
The specified user rebooted the FortiSwitch unit. |
Daily FortiSwitch unit restart
ID |
30202 |
Type |
Event log |
Subtype |
System |
Severity |
Critical |
Message |
msg=\"System will reboot due to scheduled daily restart.\" |
Meaning |
The FortiSwitch unit is being rebooted because it was scheduled to restart daily. |
FortiSwitch unit shut down
ID |
30203 |
Type |
Event log |
Subtype |
System |
Severity |
Critical |
Message |
msg=\"User <user_name> shutdown the device from <IP_address>\" |
Meaning |
The specified user shut down the FortiSwitch unit. |
CA certificate will be automatically updated
ID |
30300 |
Type |
Event log |
Subtype |
System |
Severity |
Warning |
Message |
msg=\"CA certificate <certificate_name> will auto-update in <number_of_days> days.\" |
Meaning |
The certificate authority (CA) certificate will automatically update in the specified number of days. |
Local certificate will be automatically regenerated
ID |
30301 |
Type |
Event log |
Subtype |
System |
Severity |
Warning |
Message |
msg=\"Local certificate <certificate_name> will auto-regenerate in <number_of_days> days.\" |
Meaning |
The local certificate will automatically regenerate in the specified number of days. |
Certificate failed to automatically update
ID |
30302 |
Type |
Event log |
Subtype |
System |
Severity |
Error |
Message |
msg=\"<certificate_name>\" |
Meaning |
The certificate failed to automatically update. |
Certificate failed to automatically regenerate
ID |
30303 |
Type |
Event log |
Subtype |
System |
Severity |
Error |
Message |
msg=\"<certificate_name>\" |
Meaning |
The certificate failed to automatically regenerate. |
PKCS #12 certificate imported
ID |
30304 |
Type |
Event log |
Subtype |
System |
Severity |
Critical |
Message |
msg=\"User <user_name> imported the certificate from <path>\" |
Meaning |
The specified user imported a PKCS #12 certificate. |
CRL update requested
ID |
30306 |
Type |
Event log |
Subtype |
System |
Severity |
Notice |
Message |
msg=\"User <user_name> requested a CRL update from <URL>\" |
Meaning |
The specified user requested an update for a certificate revocation list (CRL). |
Power supply restored
ID |
30400 |
Type |
Event log |
Subtype |
System |
Severity |
Critical |
Message |
msg=\"Power supply <unit_ID> restore\" |
Meaning |
The specified power supply unit was restored. |
Power supply failed
ID |
30401 |
Type |
Event log |
Subtype |
System |
Severity |
Critical |
Message |
msg=\"Power supply <unit_ID> failure\" |
Meaning |
The specified power supply unit failed. |
System configuration changed
ID |
30500 |
Type |
Event log |
Subtype |
System |
Severity |
Alert |
Message |
|
Meaning |
The specified user changed the system configuration. |
System configuration changed using the GUI
ID |
30501 |
Type |
Event log |
Subtype |
System |
Severity |
Alert |
Message |
msg=\"User <user_name> made a change via <GUI>: <submodule>\" |
Meaning |
The specified user changed the system configuration from the GUI. |
System configuration restored
ID |
30502 |
Type |
Event log |
Subtype |
System |
Severity |
Critical |
Message |
msg=\"User <user_name> restored the configuration from <IP_address>\" |
Meaning |
The specified user restored the system configuration. |
Restoring the configuration failed
ID |
30503 |
Type |
Event log |
Subtype |
System |
Severity |
Warning |
Message |
msg=\"User <user_name> failed to restore the configuration from <IP_address>\" |
Meaning |
The specified user failed to restore the system configuration. |
System reset to factory settings
ID |
30507 |
Type |
Event log |
Subtype |
System |
Severity |
Critical |
Message |
msg=\"User <user_name> reset to the factory settings from <IP_address>\" |
Meaning |
The specified user reset the system to factory default settings. |
Global setting changed
ID |
30514 |
Type |
Event log |
Subtype |
System |
Severity |
Notice |
Message |
|
Meaning |
|
System configuration backed up
ID |
30515 |
Type |
Event log |
Subtype |
System |
Severity |
Notice |
Message |
|
Meaning |
|
Configuration revision uploaded
ID |
30516 |
Type |
Event log |
Subtype |
System |
Severity |
Notice |
Message |
msg=\"User <user_name> upload the <file_name> from <IP_address> to flash disk\" |
Meaning |
The specified user uploaded the configuration revision to the flash disk. |
Database revision deleted
ID |
30518 |
Type |
Event log |
Subtype |
System |
Severity |
Notice |
Message |
msg=\"<item>:<revision_number> has been deleted from revision data base\" |
Meaning |
The item has been deleted from the revision database. |
Revision item deleted from flash disk
ID |
30520 |
Type |
Event log |
Subtype |
System |
Severity |
Notice |
Message |
msg=\"User <user_name> delete the <item> from <path> from flash disk\" |
Meaning |
The specified user deleted the revision item from the flash disk. |
Command failed
ID |
30522 |
Type |
Event log |
Subtype |
System |
Severity |
Notice |
Message |
msg=\"Command failed: <user_name>. Return code <code_number>\" |
Meaning |
The command failed. |
Failed to back up system configuration
ID |
30524 |
Type |
Event log |
Subtype |
System |
Severity |
Error |
Message |
|
Meaning |
|
Layer-2 table is more than 75-percent full
ID |
30532 |
Type |
Event log |
Subtype |
System |
Severity |
Warning |
Message |
msg=\"L2 table utilization is over 75 percent(current_size <current_size>, max size <maximum_size>).\" |
Meaning |
The layer-2 table is more than 75-percent full. |
Layer-2 table is less than 70-percent full
ID |
30533 |
Type |
Event log |
Subtype |
System |
Severity |
Warning |
Message |
msg=\"L2 table utilization is below 70 percent(current_size <current_size>, max size <maximum_size>).\" |
Meaning |
The layer-2 table is less than 70-percent full. |
Daemon started
ID |
30700 |
Type |
Event log |
Subtype |
System |
Severity |
Information |
Message |
msg=\"Daemon <daemon_name> started\" |
Meaning |
The specified daemon was started. |
Daemon shut down
ID |
30701 |
Type |
Event log |
Subtype |
System |
Severity |
Information |
Message |
msg=\"Daemon <daemon_name> shut down\" |
Meaning |
The specified daemon was shut down. |
IP address too small
ID |
30901 |
Type |
Event log |
Subtype |
System |
Severity |
Varies |
Message |
msg=\"Address for requested options is too small. Dump all config: \n timeout: <time>\n init_interval: <initial_interval>\n retry_interval: <retry_interval>\n select_interval: <select_interval>\n reboot_timeout: <reboot_timeout>\n backoff_cutoff: <backoff_cutoff>\n arpcheck_timeout: <ARP_check_timeout>\n requested_lease: <requested_lease>\n requested_options address: <IP_address>\n\" |
Meaning |
The DHCP client module daemon reported crash information for the log because the IP address for the requested options is too small. |
Log information from the DHCP client module daemon
ID |
30902-30909 |
Type |
Event log |
Subtype |
System |
Severity |
Varies |
Message |
msg=\"<log_entry>\" |
Meaning |
The DHCP client module daemon reported information for the log. |
DHCP statistics
ID |
31004 |
Type |
Event log |
Subtype |
System |
Severity |
Information |
Message |
msg=\"<how_much_of_total_is_used>\" |
Meaning |
The system reports how much of DHCP-snooping binding database for the interface is used. |
DHCP server used all of its leases
ID |
31005 |
Type |
Event log |
Subtype |
System |
Severity |
Warning |
Message |
msg=\"DHCP server <IP_address> has used up all of its leases\" |
Meaning |
The specified DHCP server has used all of its leases. |
DHCP server used most of its leases
ID |
31006 |
Type |
Event log |
Subtype |
System |
Severity |
Warning |
Message |
msg=\"DHCP server <IP_address> has used up over 80%% of its leases\" |
Meaning |
The specified DHCP server has used over 80 percent of its leases. |
DHCP server sends a DDNS add query
ID |
31007 |
Type |
Event log |
Subtype |
System |
Severity |
Information |
Message |
msg=\"DHCP server sends a DDNS add query\" |
Meaning |
The DHCP server is sending a DDNS add query. |
DHCP server sends a DDNS delete query
ID |
31008 |
Type |
Event log |
Subtype |
System |
Severity |
Information |
Message |
msg=\"DHCP server sends a DDNS delete query\" |
Meaning |
The DHCP server is sending a DDNS delete query. |
DHCP server blocked the DHCP client
ID |
31009 |
Type |
Event log |
Subtype |
System |
Severity |
Notice |
Message |
msg=\"DHCP client is blocked by the DHCP server\" |
Meaning |
The DHCP server blocked the DHCP client. |
DHCP server sends a DHCP acknowledgment
ID |
31010 |
Type |
Event log |
Subtype |
System |
Severity |
Information |
Message |
msg=\"DHCP server sends a DHCPACK\" |
Meaning |
The DHCP server sends a DHCP acknowledgment message |
DHCP server receives a DHCP release
ID |
31011 |
Type |
Event log |
Subtype |
System |
Severity |
Information |
Message |
msg=\"DHCP server receives a DHCPRELEASE\" |
Meaning |
The DHCP server receives a DHCP release message. |
Administrator logged in successfully
ID |
32001 |
Type |
Event log |
Subtype |
System |
Severity |
Notice |
Message |
|
Meaning |
An administrator logged in successfully. |
Administrator failed to log in
ID |
32002 |
Type |
Event log |
Subtype |
System |
Severity |
Alert |
Message |
msg=\"Administrator <user_name> login failed from <IP_address>\" |
Meaning |
An administrator failed to log in. |
Administrator logged out
ID |
32003 |
Type |
Event log |
Subtype |
System |
Severity |
Notice |
Message |
msg=\"Administrator <user_name> <action> <status>\" |
Meaning |
An administrator logged out. |
Admin login disabled because of login failures
ID |
32008 |
Type |
Event log |
Subtype |
System |
Severity |
Alert |
Message |
|
Meaning |
The admin login was disabled because of too many failed attempts to log in. |
Alarm test
ID |
32010 |
Type |
Event log |
Subtype |
System |
Severity |
Alert |
Message |
msg=\"Alarm testing\" |
Meaning |
The alarm is being tested. |
Partitioning or formatting error
ID |
33000 |
Type |
Event log |
Subtype |
System |
Severity |
Warning |
Message |
msg=\"Partitioning or formatting error (<error_number>, <error_message>) partition=<partition_name> format=<type> label=<label_name>\" |
Meaning |
A partitioning error or formatting error occurred. |
Log disk failure imminent
ID |
33001 |
Type |
Event log |
Subtype |
System |
Severity |
Critical |
Message |
msg=\"Log disk failure is imminent, logs should be backed up\" |
Meaning |
This S.M.A.R.T. (Self-Monitoring, Analysis and Reporting Technology) error is erroneous. |
Lack of flash space
ID |
33002 |
Type |
Event log |
Subtype |
System |
Severity |
Critical |
Message |
Cannot store config due to short of flash space: require <number_of_blocks> blocks, only <number_of_blocks> free blocks left on flash disk |
Meaning |
The system configuration cannot be saved because of lack of flash space. |
Disk formatting requested
ID |
33003 |
Type |
Event log |
Subtype |
System |
Severity |
Critical |
Message |
msg=\"User <user_name> requested to format <disk_name> disk from <IP_address>\" |
Meaning |
The specified user requested that the disk to be formatted. |
Disk storage set up
ID |
33004 |
Type |
Event log |
Subtype |
System |
Severity |
Notice |
Message |
user=\"<user_name\" ui=<disk storage> action=<action> name=\"<disk name>\" |
Meaning |
The user set up the disk storage. |
Disk storage entry deleted
ID |
33005 |
Type |
Event log |
Subtype |
System |
Severity |
Notice |
Message |
msg=\"user <user_name> delete disk storage entry\" |
Meaning |
The user deleted an entry in disk storage. |
Fan failure detected
ID |
33100 |
Type |
Event log |
Subtype |
System |
Severity |
Warning |
Message |
msg=\"FAN failure detected\" |
Meaning |
A fan failure was detected. |
Fan tray not detected
ID |
33101 |
Type |
Event log |
Subtype |
System |
Severity |
Warning |
Message |
msg=\"FAN TRAY undetected\" |
Meaning |
The fan tray was not detected. |
Fan tray detected
ID |
33102 |
Type |
Event log |
Subtype |
System |
Severity |
Warning |
Message |
msg=\"FAN TRAY detected\" |
Meaning |
The fan tray was detected. |
Fan tray detection failed
ID |
33103 |
Type |
Event log |
Subtype |
System |
Severity |
Warning |
Message |
msg=\"FAN failure detected\" |
Meaning |
The fan tray detection failed. |
Fan resumed working
ID |
33104 |
Type |
Event log |
Subtype |
System |
Severity |
Warning |
Message |
msg=\"FAN resumes\" |
Meaning |
The fan has resumed working. |
Encryption failed
ID |
33302 |
Type |
Event log |
Subtype |
System |
Severity |
Alert |
Message |
msg=\"EVP encryption failed\" |
Meaning |
Encryption has failed. |
Decryption failed
ID |
33303 |
Type |
Event log |
Subtype |
System |
Severity |
Alert |
Message |
msg=\"EVP decryption failed\" |
Meaning |
Decryption has failed. |
New entropy seed generated
ID |
33304 |
Type |
Event log |
Subtype |
System |
Severity |
Notice |
Message |
msg=\" re-seeding entropy {status =<status>, trng=<type_of_random_number_generator>} |
Meaning |
A new entropy seed has been generated. |
HTTPS message
ID |
33601 |
Type |
Event log |
Subtype |
System |
Severity |
Notice |
Message |
msg=\"<HTTPS code> -- <HTTPS_message>\" |
Meaning |
An HTTPS message was received. |
FortiLAN Cloud started
ID |
34000 |
Type |
Event log |
Subtype |
System |
Severity |
Warning |
Message |
msg=\"flan_cloud service is started by user.\" |
Meaning |
The user started FortiLAN Cloud. |
FortiLAN Cloud stopped
ID |
34001 |
Type |
Event log |
Subtype |
System |
Severity |
Warning |
Message |
msg=\"flan_cloud service is stopped by user.\" |
Meaning |
The user stopped FortiLAN Cloud. |
SSL connection to FortiLAN Cloud established
ID |
34002 |
Type |
Event log |
Subtype |
System |
Severity |
Warning |
Message |
msg=\"SSL connection to cloud-manager ip=<IP_address>, port=<port_name> is established.\" |
Meaning |
The SSL connection to the FortiLAN Cloud has been established. |
SSL connection to FortiLAN Cloud down
ID |
34003 |
Type |
Event log |
Subtype |
System |
Severity |
Warning |
Message |
msg=\"SSL connection to cloud-manager ip=<IP_address>, port=<port_name> is down (reason= <reason>).\" |
Meaning |
The SSL connection to FortiLAN Cloud is down. |
SSL connection to FortiLAN Cloud not established
ID |
34004 |
Type |
Event log |
Subtype |
System |
Severity |
Warning |
Message |
msg=\"SSL connection to cloud-manager ip=<IP_address>, port=<port_number> not be established.\" |
Meaning |
The SSL connection to FortiLAN Cloud cannot be established. |
Packet capture stopped because of lack of storage
ID |
34006 |
Type |
Event log |
Subtype |
System |
Severity |
Warning |
Message |
msg=\"sniffer profile <profile_name> stopped due to storage error. (err=<error>).\" |
Meaning |
The packet capture stopped because there is not enough storage. |
SSL connection being restarted
ID |
34007 |
Type |
Event log |
Subtype |
System |
Severity |
Warning |
Message |
msg=\"Restarting SSL connection, error= <error>. \" |
Meaning |
The SSL connection was restarted because of an error. |
Firmware image loaded
ID |
34300 |
Type |
Event log |
Subtype |
System |
Severity |
Critical |
Message |
|
Meaning |
The specified user loaded or updated the firmware image. |
Firmware image restored
ID |
34301 |
Type |
Event log |
Subtype |
System |
Severity |
Critical |
Message |
msg=\"User <user_name> restored the image from <IP_address> (<old_version_number>,build <old_build_number>-> <new_version_number>,build <new_build_number>)\" |
Meaning |
The specified user restored the firmware image. |
Firmware image failures
ID |
34306 |
Type |
Event log |
Subtype |
System |
Severity |
Critical |
Message |
|
Meaning |
|
Firmware image backed up to flash disk
ID |
34314 |
Type |
Event log |
Subtype |
System |
Severity |
Notice |
Message |
msg=\"Firmware image backed up to flash disk for system <IP_address>\" |
Meaning |
The firmware image was backed up to a flash disk. |
Backing up firmware image failed
ID |
34315 |
Type |
Event log |
Subtype |
System |
Severity |
Notice |
Message |
msg=\"Failed to backup firmware image for system <IP_address>. The reason is: <reason>\" |
Meaning |
Backing up the firmware image failed. |
IP address conflict
ID |
35000 |
Type |
Event log |
Subtype |
System |
Severity |
Notice |
Message |
msg=\"IP Conflict: conflict detected on system interface <interface_name> for IP address <IP_address>\" |
Meaning |
An IP address conflict was detected on the specified system interface. |
Changes to link monitor
ID |
35100 |
Type |
Event log |
Subtype |
System |
Severity |
Critical |
Message |
msg=\"<changes>\" |
Meaning |
Changes were made to the link monitor. |
Changes to a static route
ID |
35101 |
Type |
Event log |
Subtype |
System |
Severity |
Critical |
Message |
msg=\"<changes>\" |
Meaning |
Changes were made to a static route. |
Changes to the link monitor state
ID |
35102 |
Type |
Event log |
Subtype |
System |
Severity |
Notice |
Message |
msg=\"<changes>\" |
Meaning |
Changes were made to the link monitor state. |
RADIUS IPC error
ID |
35200 |
Type |
Event log |
Subtype |
System |
Severity |
Error |
Message |
msg=\"Unable to initialize RADIUS IPC (<IP_address>)\" |
Meaning |
The RADIUS IPC could not be initialized. |
User viewed memory logs
ID |
35213 |
Type |
Event log |
Subtype |
System |
Severity |
Notice |
Message |
msg=\"User <user_name> has viewed the memory logs from <log>\" |
Meaning |
The specified user has viewed memory logs. |
Log full
ID |
35214 |
Type |
Event log |
Subtype |
System |
Severity |
Alert |
Message |
msg=\"Memory <type> log is <percent> full\" |
Meaning |
The memory log is full. |
Disk has rolled log maximum number of times
ID |
35215 |
Type |
Event log |
Subtype |
System |
Severity |
Emergency |
Message |
msg=\"Disk has rolled the max number of times.It will not roll logs again until deleting some of the old rolled logs. |
Meaning |
The disk has rolled the logs the maximum number of times. Some of the old rolled logs must be deleted before the disk will start rolling logs again. |
System deleted uploaded logs
ID |
35216 |
Type |
Event log |
Subtype |
System |
Severity |
Information |
Message |
msg=\"System deleted logs that are uploaded\" |
Meaning |
The system deleted uploaded logs. |
Log disk full
ID |
35217 |
Type |
Event log |
Subtype |
System |
Severity |
Emergency |
Message |
|
Meaning |
|
Log rotation
ID |
35218 |
Type |
Event log |
Subtype |
System |
Severity |
Notice |
Message |
msg=\"Disk log has rolled.\" |
Meaning |
The disk logs have been rolled. |
System entered CC error mode
ID |
35219 |
Type |
Event log |
Subtype |
System |
Severity |
Emergency |
Message |
|
Meaning |
The system is in CC error mode because the memory or disk logs are full. |
System reboot required after log disk error
ID |
35220 |
Type |
Event log |
Subtype |
System |
Severity |
Emergency |
Message |
msg=\"System reboot is required after disk error\" |
Meaning |
The system must be rebooted because of a log disk error. |
System exited CC error mode
ID |
35221 |
Type |
Event log |
Subtype |
System |
Severity |
Information |
Message |
msg=\"System exiting out of error mode.\" |
Meaning |
The system is exiting CC error mode. |
Logs cleared
ID |
35222 |
Type |
Event log |
Subtype |
System |
Severity |
Notice |
Message |
msg=\"User <user_name> has cleared logs () from <time_range>\" |
Meaning |
The specified user has cleared logs. |
Rolled log files deleted
ID |
35223 |
Type |
Event log |
Subtype |
System |
Severity |
Notice |
Message |
msg=\"User <user_name> has deleted <number_of_logs> rolled <log_type> log file <file_name>(<IP_address>) from <IP_address>\" |
Meaning |
The specified user has deleted rolled log files. |
User failed to view logs
ID |
35227 |
Type |
Event log |
Subtype |
System |
Severity |
Warning |
Message |
|
Meaning |
|
Daily logging quota full
ID |
35229 |
Type |
Event log |
Subtype |
System |
Severity |
Alert |
Message |
msg=\" daily quota is reached.System stops logging until <number_of_seconds> sec later.\" |
Meaning |
The daily logging quota has been reached, and the system has stopped logging. |
Logging file downloaded
ID |
35230 |
Type |
Event log |
Subtype |
System |
Severity |
Warning |
Message |
msg=\"<action> by user <user_name> via <interface>\" |
Meaning |
The specified user has used the GUI to download a logging file from the firewall. |
Log backed up
ID |
35231 |
Type |
Event log |
Subtype |
System |
Severity |
Notice |
Message |
|
Meaning |
The specified user has backed up the log. |
Backing up all logs failed
ID |
35232 |
Type |
Event log |
Subtype |
System |
Severity |
Notice |
Message |
|
Meaning |
The specified user failed to back up all logs. |
All logs backed up
ID |
35233 |
Type |
Event log |
Subtype |
System |
Severity |
Notice |
Message |
|
Meaning |
The specified user backed up all logs. |
Log backup failed
ID |
35236 |
Type |
Event log |
Subtype |
System |
Severity |
Notice |
Message |
msg=\"User <user_name> failed to backup <log_type> log from <IP_address>\" |
Meaning |
The specified user failed to back up all logs. |
Warning from monitor-and-alert daemon
ID |
35242 |
Type |
Event log |
Subtype |
System |
Severity |
Warning |
Message |
msg=\"<message_text>.\" |
Meaning |
The monitor-and-alert daemon sent a warning. |
USB device inserted or removed
ID |
35243 |
Type |
Event log |
Subtype |
System |
Severity |
Notice |
Message |
|
Meaning |
A USB device was inserted or removed. |
Log nearly full
ID |
35245 |
Type |
Event log |
Subtype |
System |
Severity |
Alert |
Message |
|
Meaning |
The log is nearly full. |
Oldest logs uploaded
ID |
35246 |
Type |
Event log |
Subtype |
System |
Severity |
Notice |
Message |
msg=\"<log> is <percentage> full.System will upload oldest 20%% logs.\" |
Meaning |
The log is full. The system will upload the oldest 20 percent logs. |
Log full
ID |
35248 |
Type |
Event log |
Subtype |
System |
Severity |
Notice |
Message |
msg=\"Memory <log> log is <percentage> full\" |
Meaning |
The memory log is full. |
Log nearly full
ID |
35249 |
Type |
Event log |
Subtype |
System |
Severity |
Warning |
Message |
msg=\"Memory <log> log is <percentage> full\" |
Meaning |
The memory log is nearly full. |
Logs deleted and logs uploaded
ID |
35250 |
Type |
Event log |
Subtype |
System |
Severity |
Information |
Message |
msg=\"<log> is <percentage> full.System will delete oldest 20%% uploaded logs, and upload another oldest 20%% un-upload logs.\" |
Meaning |
The log is full. The sysem will delete 20 percent of logs that were uploaded and then upload 20 percent of the logs that were not previously uploaded. |
Log test
ID |
36000 |
Type |
Event log |
Subtype |
System |
Severity |
Varies |
Message |
msg=\"user admin logged into the fw - <action>\" |
Meaning |
Log test |
PSU 1 is down
ID |
36106 |
Type |
Event log |
Subtype |
System |
Severity |
Warning |
Message |
msg=\"PSU 1 is down\" |
Meaning |
Power supply unit (PSU) 1 is down. |
PSU 1 is up
ID |
36107 |
Type |
Event log |
Subtype |
System |
Severity |
Warning |
Message |
msg=\"PSU 1 is up\" |
Meaning |
PSU 1 is up. |
PSU 2 is down
ID |
36108 |
Type |
Event log |
Subtype |
System |
Severity |
Warning |
Message |
msg=\"PSU 2 is down\" |
Meaning |
PSU 2 is down. |
PSU 2 is up
ID |
36109 |
Type |
Event log |
Subtype |
System |
Severity |
Warning |
Message |
msg=\"PSU 2 is up\" |
Meaning |
PSU 2 is up. |
Corrupt MAC packet detected
ID |
36250 |
Type |
Event log |
Subtype |
System |
Severity |
Warning |
Message |
msg=\"Corrupted MAC packet detected\" |
Meaning |
A corrupt MAC packet was detected. |
Unable to negotiate
ID |
36251 |
Type |
Event log |
Subtype |
System |
Severity |
Error |
Message |
msg=\"Negotiation failed: <IP_address>. Their offer: <IP_address>.\" |
Meaning |
Unable to negotiate. |
SSH server needs rekeying
ID |
36252 |
Type |
Event log |
Subtype |
System |
Severity |
Warning |
Message |
msg=\"SSH server rekey\" |
Meaning |
The SSH server needs rekeying. |
Bad packet length
ID |
36254 |
Type |
Event log |
Subtype |
System |
Severity |
Warning |
Message |
msg=\"Bad packet length:<number_of_bytes>\" |
Meaning |
The maximum packet length was exceeded. |
Fan tray status
ID |
36300 |
Type |
Event log |
Subtype |
System |
Severity |
Warning |
Message |
Varies |
Meaning |
The fan tray status is reported. |
Alarm testing
ID |
36350 |
Type |
Event log |
Subtype |
System |
Severity |
Emergency |
Message |
msg=\"Alarm testing\" |
Meaning |
The alarm is being tested. |
Learning-limit violations reset
ID |
42000 |
Type |
Event log |
Subtype |
System |
Severity |
Notice |
Message |
|
Meaning |
|
Learning-limit violations deleted
ID |
42001 |
Type |
Event log |
Subtype |
System |
Severity |
Notice |
Message |
|
Meaning |
|
Learning-limit violation log enabled
ID |
42002 |
Type |
Event log |
Subtype |
System |
Severity |
Notice |
Message |
msg=\"Enabled learning limit violation records.\" |
Meaning |
The learning-limit violation log has been enabled. |
Learning-limit violation log disabled
ID |
42003 |
Type |
Event log |
Subtype |
System |
Severity |
Notice |
Message |
msg=\"Disabled learning limit violation records.\" |
Meaning |
The learning-limit violation log has been disabled. |
Learning limit exceeded
ID |
42004 |
Type |
Event log |
Subtype |
System |
Severity |
Notice |
Message |
|
Meaning |
The learning limit was exceeded on the specified VLAN or interface. |
VM license file added
ID |
42100 |
Type |
Event log |
Subtype |
System |
Severity |
Critical |
Message |
msg=\"User <user_name> added VM license file.\" |
Meaning |
The specified user added a VM license file. |
Failed to add VM license file
ID |
42101 |
Type |
Event log |
Subtype |
System |
Severity |
Critical |
Message |
msg=\"User <user_name> failed to add VM license file.\" |
Meaning |
The specified user failed to add a VM license file. |
No more IP source guard entries can be added
ID |
42200 |
Type |
Event log |
Subtype |
System |
Severity |
Warning |
Message |
msg=\"Not install entry <IP_address> on <switch_interface> due to \"FULL\" error code.\" |
Meaning |
No more IP source guard entries can be added because the maximum number of entries has been added. |
IP source-guard violations
ID |
42201 |
Type |
Event log |
Subtype |
System |
Severity |
Notice |
Message |
msg=\"Source guard violation, interface=<interface_name>, mac=<MAC_address>, ip=<IP_address>" |
Meaning |
Events that violate the IP source-guard settings have occured. |
Cable-diagnostics messages
ID |
42300 |
Type |
Event log |
Subtype |
System |
Severity |
Notice |
Message |
|
Meaning |
|
Global time setting changed
ID |
42451 |
Type |
Event log |
Subtype |
System |
Severity |
Notice |
Message |
|
Meaning |
|
Local user added
ID |
42471 |
Type |
Event log |
Subtype |
System |
Severity |
Notice |
Message |
msg=\"User <user_name> added local user <user_name> from <IP_address>\" |
Meaning |
The specified user added a local user. |
Local userʼs setting changed
ID |
42472 |
Type |
Event log |
Subtype |
System |
Severity |
Notice |
Message |
msg=\"User <user_name> changed local user <user_name> setting from <IP_address>\" |
Meaning |
The specified user changed the setting for a local user. |
Log information from the DHCPv6 client module daemon
ID |
42492-42499 |
Type |
Event log |
Subtype |
System |
Severity |
Varies |
Message |
msg=\"<log_entry>\" |
Meaning |
The DHCPv6 client module daemon reported information for the log. |
Start running a script
ID |
42520 |
Type |
Event log |
Subtype |
System |
Severity |
Information |
Message |
msg=\"User <user_name> start script <script_name> from <IP_address>\" |
Meaning |
The specified user started to run a script. |
Stopped running a script
ID |
42521 |
Type |
Event log |
Subtype |
System |
Severity |
Information |
Message |
|
Meaning |
|
User deleted script results
ID |
42523 |
Type |
Event log |
Subtype |
System |
Severity |
Information |
Message |
msg=\"User <user_name> delete the result of script <script_name> from <IP_address>\" |
Meaning |
The specified user deleted the script output. |
Backed up script results
ID |
42524 |
Type |
Event log |
Subtype |
System |
Severity |
Information |
Message |
msg=\"backup autoscript <script_name> result via <IP_address> -- <action>\" |
Meaning |
The script output was backed up. |
Checked script status
ID |
42525 |
Type |
Event log |
Subtype |
System |
Severity |
Information |
Message |
msg=\"User <user_name> checked the status of autoscript(s) from <IP_address>\" |
Meaning |
The specified user checked the status of the script. |
Script stopped because of output limit
ID |
42526 |
Type |
Event log |
Subtype |
System |
Severity |
Information |
Message |
msg=\"script <script_name> stopped due to the output has reached the size limit\" |
Meaning |
The script stopped running when the output reached the maximum size. |
Automation stitch triggered
ID |
42580 |
Type |
Event log |
Subtype |
System |
Severity |
Notice |
Message |
msg=\"stitch:<stitch_name> is triggered.\" |
Meaning |
The trigger for the specified automation stitch has occurred, so the stitchʼs action will be performed. |