In this blog, we will discuss Workspace One UEM (AirWatch) Event logs. This was asked by many of my customers hence, i decided to create a post with the event details here.
Workspace One UEM (AirWatch) Event are records of administrative and device actions that the AirWatch Console stores in logs. The event logs show both device events and AirWatch Console events. Device events show the commands sent from the AirWatch Console to devices, device responses, and device user actions. The AirWatch Console events show actions taken from the AirWatch Console including login sessions, failed login attempts, admin actions, system settings changes, and user preferences.
Events Name | Description |
SecurityInformation | When the query command is requested and sent from device to console in bytes |
SecurityInformationConfirmed | When the query command is requested and is confirmed by the device |
InstallProvisioningProfileRequested | When installation of Provisioning Profile is requested |
InstallApplicationRequested | When installation of App is requested |
InstallProfileRequested | When installation of Profile is requested |
InstallProfileConfirmed | When installation of Profile is confirmed |
InstallApplicationConfirmed | When installation of App is confirmed |
SecureChannelCheckIn | Is for the AirWatch app registration |
DeviceOperatingSystemChanged | When the OS is changed or upgraded on the device |
ContentAdded | When a Content is added on the console |
AppCatalogLaunch | When the App Catalog is launched at the device |
HmacAuthenticationFailure | When the HMAC authentication is failed from the device end |
InstallApplicationFailed | When the app install Is failed from Server |
RemoveProfileRequested | When removal of profile is requested from console |
InstallProvisioningProfileConfirmed | When installation of Provisioning Profile is confirmed |
AuthenticationError | When an invalid token is passed at the time of enrollment we see the Authentication Error |
ApplicationDownload | This is Application Download event is from App Catalog |
RemoveProfileConfirmed | When removal of Profile is confirmed |
ComplianceStatusChanged | When there is Compliance status change at the device end |
LocationGroupChanged | When the Location Group information is changed |
CertificateIssued | When the certificate issue command is processed on the device |
AppleTokenUpdateComplete | At the time of enrollment when the APNs Token Update Complete is confirmed for the device |
AppleOsXmdmDeviceTokenUpdate | When the APNs token update message is received from the device |
CompromisedStatusChanged | When there is Compromised status change at the device end |
MDMConfiguration | The MDMConfiguration event is triggered when an MDM profile is generated for Apple devices. |
MDMEnrollmentStarted | After the device sends the first sample at the time of enrollment the server acknowledges it |
MDMEnrollmentAuthentication | After the device authenticates at the time of enrollment the server acknowledges it |
SampleListsRequested | Contains all the sample information requested like Deviceinformation, App list, Cert list sample, profile list etc |
MDMEnrollmentComplete | After the device is enrollment the server acknowledges it |
RemoveProfileFailed | When the remove profile command from console to device is failed |
AvailableOsUpdatesConfirmed | When the OS update sent from console is confirmed by device |
AvailableOSUpdatesList | The device will notify the console about the OS update available |
ContentVersionAdded | When there is a new content version added on the console |
DeleteDeviceRequested | When Delete Device is requested from Console |
BreakMDMConfirmed | When the device confirms the Break MDM to be received |
EULAAccepted | When the Terms of use is accepted at the time of enrollment by the device |
BreakMDMRequested | When Break MDM is requested to the device |
ComplianceNotificationSent | When the Complaince status Notification is sent from console |
ComplianceStatusChanged | When there is a change in the Compliane status on the console |
WipeRequest | When the Wipe Request is sent from console to device |
AdminSessionEndedDueToInactivity | When the console session times out for an admin |
InstallProfileFailed | When the install profile command is failed from console to the device |
ContentEdit | When the content is edited on the console |
Revoked | When the certificates are revoked |
DeviceEnterpriseWipeRequested | When Enterprise Wipe is requested from console to the device |
SyncGroupFailureEvent | When the directory sync is failed for a User Group |
UserEnrollmentTokenCreated | When enrollment token is created for a user account on console |
ApplicationInstallOnDeviceRequested | When the user is trying to install an app this event is captured |
RemoveApplicationRequested | When the application removal command is requested from server to device |
AppListSampleFailed | When the query apps is performed from console is initiated and failed |
SmartGroupsModified | When Smart Groups are modfied on console |
SecurityInformationRequested | When the query command is requested |
AvailableOsUpdatesRequested | When the OS update information is queried |
AddMissingUserFailureEvent | When an existing AD User Group fails to update members |
MemDeviceWhiteList | Whitelisting a device on email list view |
ApplicationPublished | When a new application is published on the console |
MemDeviceApplyDefaultRules | When the default emails rules are applied |
AddMissingAdminFailure | When an existing AD Admin Group fails to update admin accounts |
AvailableOsUpdatesFailed | When the OS update information is queried and failed to update |
ApplicationRemoveFromDeviceRequested | When the Application Removal command from the Device is Requested |
ApplicationModified | When the application is modified on the console |
RemoveApplicationConfirmed | When App removal is confirmed by the device |
ProfileInstallOnDeviceRequested | When the user is trying to install a profile this event is captured |
SearchMissingUserFailureEvent | When we perform the Add missing users for a User Group this command is captured |
InstallProvisioningProfileFailed | When the install provisional profile command from console is failed to the device |
RemoveProvisioningProfileRequested | When removal of provisioning profile is requested from console to the device |
DeviceLockRequested | When Device Lock command is requested from console |
DeviceDataModfied | When Device Details are modified on the console |
AdminUserRoleAssignmentAdded | When a the role assignment is added for the admin user on the console |
AdminUserAdded | When a new admin user us added to console |
ActivationLockBypassCodeSampleSave | The activation bypass code initially provided to the MDM by the device |
UserGroupPermissionsModified | When the User Group permissions are modified on the console |
UserGroupDirectorySyncCompleted | When the Directory sync for User Group is completed on the console |
UserGroupAdded | When the User Group is added to the console |
UserDeleted | When the user account is deleted from console |
UnAuthorizedSecurityPin | When an incorrect security pin is keyed in on the console for an action which requires pin |
SmartGroupsCreated | When SmartGroups are created on the console |
SendMessageConfirmed | When the message is sent from console to device and when the device confirm receiving it |
MemSyncMailboxesFailed | When the Sync Mailbox command is failed from console to exchange |
EditDevice | When Edit device is performed |
DeviceLockConfirmed | When the Device Lock command is confirmed from Device |
DeviceAttributeAssetNumberModified | When the Asset Number is modified from the console |
ApplicationAdded | When a new app is added on console |
SecureChannelCheckIn | AirWatch app registration. |
AuthenticationError | When an invalid token is passed at the time of enrollment we see the Authentication Error. |
AppleOsXmdmDeviceTokenUpdate | When the APNs token update message is received from the device. |
I hope this is informative for you. Thanks for Reading! Be Social and share it in social media, if you feel worth sharing it.