Already a NinjaOne customer? Log in to view more guides and the latest updates.

NinjaOne Policies: Condition Templates

When managing conditions under your policies, NinjaOne has many templates that can be selected to quickly add a series of condition types to your policy. When selecting Use Template, a pop-up window displays categorized templates and allows users to search for templates.

Policies_Conditions_-_Templates_1.png

Below is a breakdown of each condition template. Use the following bullets to jump to the condition template you would like to learn more about: 

Antivirus

Template NameConditionProcess / Service / SourceUp / Down / Event IDsTime / Text
Webroot: Process DownProcessWebroot SecureAnywhere Core Service, Webroot SecureAnywhere Endpoint Protection, WRCoreService, WRSkyClient, WRSVCDown3 Minutes
Webroot: Daemon DownDaemonWSDaemonDown3 Minutes
Sophos: Service DownWindows ServiceSophos Agent, Sophos Anti-Virus, Sophos AutoUpdate Service, Sophos Client Firewall, Sophos Client Firewall Manager, Sophos Device Control Service, Sophos Device Encryption Service, Sophos Endpoint Defense Service, Sophos Patch Agent, Sophos Web Control Service, Sophos Web Intelligence Service, Sophos Web Intelligence Update, Sophos Web Filter Service, Sophos Network Treat Protection, Sophos System Protection Service, Sophos Clean Service, HitmanPo.Alert Service, Sophos Live Query, Sophos Safestore ServiceDown3 Minutes
ESET: Service DownWindows ServiceekmEpfw, ehttpsrv, ekrn, efdeais, efdesrv, EraAgentSvcDown3 Minutes
Windows Defender: Service DownWindows Servicewindefend, mpssvc, MsMpEng, Windows Defender ServiceDown3 Minutes
Trend Micro: Apex One Service DownWindows ServiceCETASvc, Trend Micro Endpoint Basecamp, Trend Micro Web Service Communicator, TmCCSF, tmlisten, ntrtscan, TmWSCSvcDown3 Minutes
Trend Micro: Worry-Free Business Security Service DownWindows ServicePccNTMon, PccNT, TmListen, NTRtScan, TmPfw, TMBMSRVDown3 Minutes
Trend Micro: Service DownDaemoncom.trendmicro.icore.mainDown3 Minutes
Kasperskey: Service DownWindows Servicesoyuz, angaraDown3 Minutes
Broadcom (Symantec) Endpoint Protection: Service DownWindows Servicesnc64, DoScan, Smc, SepMasterService, ccSvcHstDown3 Minutes
Broadcom (Symantec) Endpoint Protection Manager : Service DownWindows ServiceSemSvc, SemLaumchSvcDown3 Minutes
AVG: Service DownWindows ServiceAVG Antivirus, avgIDSAgent, AvgWscReporter, AVG Secure Browser Elevation Service, avg8wd, avgadmsv, avgtcpsvDown3 Minutes
MalwareBytes: Service DownWindows ServiceMBAMService, MBEndpointAgent, MBAMIService, mbMgmtSvc, MsMpSvc, MBAMSchedulerDown3 Minutes
VIPRE: Service DownWindows ServiceVipreNis, SBAMSvc, ViprePPLSvcDown3 Minutes
Panda: Service DownWindows ServiceNanoServiceMain, PandaAgent, pselamsvc, PSUAService, Panda VPN ServiceDown3 Minutes

Back to top

Application Management

Template NameConditionProcess / Service / SourceUp / Down / Event IDsTime / Text
TeamViewer service down Windows ServiceTeamViewerDown3 Minutes
Windows FTP - Services Windows ServiceMSFtpsvcDown3 Minutes

Back to top

Backup

Template NameConditionProcess / Service / SourceUp / Down / Event IDsTime / Text
Windows Server Backup ServiceWindows ServiceSDRSVCDown3 Minutes
Windows Server Backup FailureWindows EventMicrsoft-Windows-Backup5, 9, 17, 18, 19, 20, 21, 22, 49, 50, 52, 517, 518, 521, 527, 528, 544, 545, 546, 561, 564
Windows Server Backup CancelledWindows EventMicrsoft-Windows-Backup8, 100, 612 
Veeam: Agent Down Windows ServiceVeeamManagementAgentSvc, VeeamEndpointBackupSvc, VeeamBackupSvcDown3 Minutes
Acronis: Backup Services DownWindows ServiceAcronisActiveProtectionService, mmsminisrv, afcdpsrv, AcrSch2Svc, syncagentsrv, MMS, AMS, AcronisMonitoringService, AcronisAgent, RpcEptMapperDown3 Minutes
Altaro: Backup Services DownWindows ServiceAltaro.UI.Service.exe, Altaro.DedupService.exe, Altaro.SubAgent.exe, Altaro.SubAgent.N2.exe, Altaro.OffsiteServer.Service.exe, Altaro.OffsiteServer.UI.Service.exe, Altaro.DedupService.exe, Altaro.Agent.exeDown3 Minutes
MSP360: Backup Services DownWindows ServiceCloudberry Backup ServiceDown3 Minutes
StorageCraft: Backup Services DownWindows ServiceStorageCraft ImageManager, StorageCraft ImageReady, StorageCraft SPX, StorageCraft EndPoint Agent, VSNAPVSS, raw_agent_svc, SPXService, stc_endpt_svc, ShadowProtectSvc, StorageCraft Raw Agent, SPXService, StorageCraft EndPoint AgentDown3 Minutes
Datto: Backup Service StoppedWindows ServiceDattoBackupAgentService, DattoProvider, DattoCloudContinuity.exeDown3 Minutes
Carbonite: Backup Service StoppedWindows ServiceCarboniteService, ZCBService, CSBFltrSrv, CSBUIService, CSBUIService-64, ZWCServiceDown3 Minutes
N-able: Backup Service DownWindows ServiceBackup Service ControllerDown3 Minutes
Microsoft Backup: Event IDs Windows EventMicrosoft-Windows-Backup4, 5, 8 

Back to top

Hardware

Template NameConditionProcess / Service / SourceUp / Down / Event IDsTime / Text
Chassis Intrusion - Event IDs Windows EventServer Administrator1254 
Drive Errors/RAID Failures - Event IDs Windows EventDisk7, 11, 41, 51, 29

Back to top

Network Management

Template NameConditionProcess / Service / SourceUp / Down / Event IDsTime / Text
TCP Max. Connection Limit Reached - Event IDs Windows Eventtcpip4226 
TCP/IP: Duplicate IP in Network - Event ID 1 Windows Eventtcpip4199 
TCP/IP: Duplicate IP in Network - Event ID 2 Windows Eventnetbt4319, 4320 

Back to top

Security

Template NameConditionProcess / Service / SourceUp / Down / Event IDsTime / Text
Windows Security Center Service is DownWindows ServicewscvsvcDown3 Minutes
Windows Security Account Manager is DownWindows ServiceSamSsDown3 Minutes
User Account Created or EnabledWindows EventMicrosoft-Windows-Security-Auditing4720, 4722 
User Account Disabled or DeletedWindows EventMicrosoft-Windows-Security-Auditing4725, 4726 
User Account Password Change or ResetWindows EventMicrosoft-Windows-Security-Auditing4723, 4724 
User Account Failed to LoginWindows EventMicrosoft-Windows-Security-Auditing4625 
Domain Controller Failed to Validate CredentialsWindows EventMicrosoft-Windows-Security-Auditing4777 
User Account Locked OutWindows EventMicrosoft-Windows-Security-Auditing4740, 6279 
User Account UnlockedWindows EventMicrosoft-Windows-Security-Auditing4767, 6280 
Security-Enabled Group CreatedWindows EventMicrosoft-Windows-Security-Auditing4727, 4731, 4754
Security-Enabled Group ChangedWindows EventMicrosoft-Windows-Security-Auditing4735, 4737 
Security-Enabled Group DeletedWindows EventMicrosoft-Windows-Security-Auditing4730, 4734, 4758
Member Added to Security-Enabled GroupWindows EventMicrosoft-Windows-Security-Auditing4728, 4732, 4756
Member Removed From Security-Enabled GroupWindows EventMicrosoft-Windows-Security-Auditing4729, 4733, 4757
Security Group's Type ChangedWindows EventMicrosoft-Windows-Security-Auditing4764 
Windows Firewall Service StoppedWindows EventMicrosoft-Windows-Security-Auditing5025, 5034 
Windows Firewall Security Policy IssueWindows EventMicrosoft-Windows-Security-Auditing5027, 5028, 5029
Windows Firewall FailedWindows EventMicrosoft-Windows-Security-Auditing5030, 5035, 5037
Change Made to Windows Firewall ExceptionsWindows EventMicrosoft-Windows-Security-Auditing4946, 4947, 4948
Windows Firewall Settings ChangedWindows EventMicrosoft-Windows-Security-Auditing4950, 4951, 4854,  4956
DoS Attack Detected via Windows Filtering Platform Windows EventMicrosoft-Windows-Security-Auditing5148 
Windows Filtering Platform Blocked a PacketWindows EventMicrosoft-Windows-Security-Auditing5150, 5151, 5152, 5153
Windows Filtering Platform Blocked a ConnectionWindows EventMicrosoft-Windows-Security-Auditing5155, 5157, 5159
Image File Hashes IncorrectWindows EventMicrosoft-Windows-Security-Auditing5038, 6281 
Windows Security Event Log ClearedWindows EventMicrosoft-Windows-Security-Auditing1102 
Windows Security Event Log is FullWindows EventMicrosoft-Windows-Security-Auditing1104 

Back to top

Server Management

Template NameConditionProcess / Service / SourceUp / Down / Event IDsTime / Text
Active Directory Domain Controller - ServicesWindows ServiceNTDS, ADWS, Netlogon, DNS, DNScache, DHCP, DFSR, IsmServ, KDC, w32time, RPCSS, SAMSS, CertSvc, KPSSVCDown3 Minutes
DHCP Server - ServicesWindows Servicedhcpserver, dhcp, dnsDown3 Minutes
DNS Server - ServicesWindows ServiceDnscache, DNSDown3 Minutes
Hyper-V Server - ServicesWindows Servicevmms, vmicheartbeat, HvHostDown3 Minutes
Web Server IISWindows ServiceWAS, W3SVC, iisadmin, httpfilterDown3 Minutes
Windows Server Update ServicesWindows ServiceWSUSserviceDown3 Minutes
Windows Server Essentials ServicesWindows ServiceWseClientMgmtSvc, WseClientMonitorSvc, WseComputerBackupSvc, WseEmailSvc, WseHealthSvc, WseMgmtSvc, WseMediaSvc, WseNtfSvc, ServiceProviderRegistry, WseStorageSvcDown3 Minutes
Exchange Server 2016 - Mailbox ServicesWindows ServiceMSExchangeMailboxReplication, HostControllerService, MSExchangeADTopology, MSComplianceAudit, MSExchangeCompliance, MSExchangeDagMgmt, MSExchangeDiagnostics, MSExchange Mitigation, MSExchangeFrontEndTransport, MSExchangeHM,MSExchangeHMRecovery, MSExchangeIS,MSExchangeMailboxAssistants, MSExchangeDelivery, MSExchangeSubmission, MSExchangeNotificationsBroker, MSExchangeRepl, MSExchangeRPC, MSExchangeFastSearch, MSExchangeServiceHost, MSExchangeThrottling, MSExchangeTransportDown3 Minutes
Exchange Server 2019 - Mailbox ServicesWindows ServiceMSExchangeMailboxReplication, HostControllerService, MSExchangeADTopology, MSComplianceAudit, MSExchangeCompliance, MSExchangeDagMgmt, MSExchangeDiagnostics, MSExchange Mitigation, MSExchangeFrontEndTransport, MSExchangeHM,MSExchangeHMRecovery, MSExchangeIS,MSExchangeMailboxAssistants, MSExchangeDelivery, MSExchangeSubmission, MSExchangeRepl, MSExchangeRPC, MSExchangeFastSearch, MSExchangeServiceHost, MSExchangeThrottling, MSExchangeTransportDown3 Minutes
Exchange Server 2016 / 2019 - Edge Transport ServicesWindows ServiceADAM_MSExchange, MSExchangeEdgeCredential, MSExchangeDiagnostics, MSExchangeHM, MSExchangeHMRecovery, MSExchangeServiceHost, MSExchangeTransport, MSExchangeTransportLogSearchDown3 Minutes
SQL Server 2016, 2017, 2019 - ServicesWindows ServiceMSSQLSERVER, SQLServerAgent, MSSQLServerOLAPService, ReportServer, MSDTSServer100, SQLBrowser, SQLWriter, MSSQLFDLauncher, MSDTCDown3 Minutes
Ninja NMS ServerWindows ServiceNinjaNetworkManageServerDown3 Minutes
VMWare VirtualCenter ServerWindows ServicevpxdDown3 Minutes
Veeam: Backup Server Services DownWindows ServiceVeeamBackupSvc, VeeamTransportSvc, VeeamCatalogSvc, VeeamDeploySvc, VeeamMountSvc, VeeamBrokerSvc, VeeamDistributionSvc, VeeamNFSSvc, VeeamGateSvc, VeeamManagementPortalSvcDown3 Minutes
Storage Server - ServicesWindows ServiceDFS, DFSR, MSiSCSi, NtFRs, srmsvcDown3 Minutes
HP Insight - ServicesWindows ServiceCqMgHost, CpqNicMgmt, CqMgServ, CqMgStor, hpqams, CpqRcmc, CissesrvDown3 Minutes
Hyper-V Replication EventsWindows EventMicrosoft-Windows-Hyper-V-VMMS32022, 29292, 32088
Active Directory Server - Services Windows ServiceKPSSVC, Netlogon, lanmanserver, dnscache, rpcss, samss, w32time, ismserv, laNmanworkstationDown3 Minutes
Citrix Server - Services Windows ServiceCitrix_GTLicensingProv, Ctx_SMA, CitrixXTEServer, CitrixLicensingDown3 Minutes
Exchange 2003 - Services Windows ServiceMSExchangeCoCo, MSExchangeES, IMAP4Svc, MSExchangeIS, MSExchangeMGMT, POP3Svc, RESvc, MSExchangeSRS, MSExchangeSA, MSExchangeMTADown3 Minutes
Exchange 2007 - Services Windows ServiceMSExchangeADTopology, MSExchangeIS, MSExchangeMailSubmission, MSExchangeRepl, MSExchangeTransport, MSExchangeTransportLogSearch, ADAM_MSExchange, EdgeCredentialSvc, MSExchangeEdgeSync, MSExchangeFDS, MSExchangeAntispamUpdate, MSExchangeIMAP4, MSExchangeMailboxAssistants, MSExchangeMonitoring, MSExchangePOP3, MSExchangeSearch, MSExchangeServiceHost, MSSpeechService, MSExchangeSA, MSExchangeUM, MSFTESQL-ExchangeDown3 Minutes
Exchange 2010 - Services Windows ServiceMSExchangeADTopology, MSExchangeIS, MSExchangeMailSubmission, MSExchangeRepl, MSExchangeTransport, MSExchangeTransportLogSearch, MSExchangeEdgeSync, MSExchangeFDS, MSExchangeAntispamUpdate, MSExchangeIMAP4, MSExchangeMonitoring, MSExchangePOP3, MSExchangeSearch, MSExchangeServiceHost, MSExchangeSA, MSExchange AB, MSExchangeFBA, MSExchangeMailboxAssistants, MSExchangeMailboxReplication, MSExchangeProtectedServiceHost, MSExchangeRPC, wsbexchange, MSExchangeThrottlingDown3 Minutes
Exchange 2013 - Services Windows ServiceMSExchangeADTopology, MSExchangeIS, MSExchangeRepl, MSExchangeTransport, MSExchangeTransportLogSearch, MSExchangeEdgeSync, MSExchangeAntispamUpdate, MSExchangeIMAP4, MSExchangeMonitoring, MSExchangePOP3, MSExchangeServiceHost, MSExchangeUM, MSExchangeDiagnostics, MSExchangeFrontEndTransport, MSExchangeHM, MSExchangeIMAP4BE, MSEchangeMailboxAssistants, MSExchangeMailboxReplication, MSExchangeDelivery, MSExchangeSubmission, MSExchangePOP3BE, MSExchangeRPC, MSExchangeFastSearch, HostControllerService,wsbexchange, MSExchangeThrottling, MSExchangeUMCRDown3 Minutes
Exchange Server - Blacklisted Event ID 1 Windows Eventmsexchange*1002, 1003, 1012, 1013, 1113, 1309, 1333, 1400, 2050, 2102, 2103, 8206, 8207, 8213, 9690, 9665, 2060, 4018, 4057, 4114, 4126, 7004
Exchange Server Store - Blacklisted Event IDs Windows EventExchangeStoreDB121, 142 
FTP Server - Services Windows ServiceMSFtpsvcDown3 Minutes
IIS Server - Services Windows ServiceW3SVC, iisadminDown3 Minutes
ISA 2004 - Services Windows Servicefwsrv, isactrl, isasched, isastg, mssql$msfwDown3 Minutes
MySQL Server - Services Windows ServiceMYSQLDown3 Minutes
OS - Windows Server 2012 R2 Services Windows Servicewinmgmt, WmiApSrv, BFE", MSIServer, LmHosts, ProfSvc, iphlpsvc, gpsvc, BrokerInfrastructure, Dhcp, Power, VSS, Dnscache, PlugPlay, TermService, SessionEnv, Spooler, CertPropSvc, EventLog, MpsSvc, Schedule, serverDown3 Minutes
OS: Windows 2008/2008 R2 - Services Windows ServiceBrowser, CryptSvc, DFSR, MMCSS, PlugPlay, Spooler, ProtectedStorage, seclogon, SensorDataService, dnscache, rpcss, samss, w32time, msdtc, remoteregistry, dcomlaunch, trkwks, ersvc, policyagent, wzcsvc, dhcpserver, wuaUserv, eVentlog, lAnmanserver, lAnmanworkstation, hElpsvc, dMserverDown3 Minutes
OS: Windows Time Server - Services Windows Servicew32timeDown3 Minutes
SQL Server 2005 - Services Windows Servicemssqlserver, SQLSERVERAGEBT, MsDtsServer, sqlwriter, dtcmsdtc, MSSQLServerADHelper, MSSQLServerOLAPService, sqlbrowser, msfttesql, reportserverDown3 Minutes
SQL Server 2008/2008 R2 - Services Windows ServiceMSFTESQL-Exchange, mssqlserver, SQLSERVERAGEBT, MsDtsServer, sqlwriter, msdtc, MSSQLServerADHelper, MSSQLServerOLAPService, sqlbrowser, ReportServerDown3 Minutes
SQL Server 2012 - Services Windows Servicemssqlserver, sqlserveragent, MSSQLServerOLAPService, sqlbrowser, SQLServerDistributedReplayClient, SQLServerDistributedReplayController, MsDtsServer110, ReportServer, sqlwriterDown3 Minutes
SharePoint Server - Services Windows Servicemssearch, spadmin, sptimerv3, sptraceDown3 Minutes
Symantec Backup Exec - Services Windows ServiceBackupExecAgentBrowser, BackupExecDeviceMediaService, BackupExecJobEngine, BackupExecAgentAccelerator, BackupExecRPCService, ENL, RxASA, RxNoService, RxRMS, RxRSA, RxWebApp, RxWRG, rxWriterSvc, SUIR, bedbg, DLOAdminSvcu, DLOMaintenanceSvc, BackupExecNamingServiceDown3 Minutes
Print Server - Services Windows ServiceSpoolerDown3 Minutes
Terminal Server - Services Windows ServiceTermServiceDown3 Minutes

Back to top

User Behavior

Template NameConditionProcess / Service / SourceUp / Down / Event IDsTime / Text
Failed Login Attempts: Event ID 1 Windows Eventlogon/logoff4625 
Failed Login Attempts: Event ID 2 Windows EventAccount Logon4777 
User Profile Load Failure - Event IDs Windows EventMicrosoft-Windows1515, 1511, 1500, 6004

Back to top

Workstation Management

Template NameConditionProcess / Service / SourceUp / Down / Event IDsTime / Text
OS - Windows 10 Services Windows ServiceAppinfo, UserManager, EventSystem, LanmanWorkstation, WlanSvc, hidserv,n DPS, BFE, wscsvc, AudioSrv, CoreMessagingRegistrar, LmHosts, ProfSvc, NcbService, iphlpsvc, NlaSvc, WdiServiceHost, SharedAccess, CryptSvc, BrokerInfrastructure, Dhcp, WinDefend, DeviceInstall, Power, Dnscache, Nla, NcdAutoSetup, eventlog, WdiSystemHost, PlugPlay, netprofm, Spooler, LanmanServer, RpcSs, KeyIso, DcomLaunch, DeviceAssociationService, LSM, FDResPub, fdPHost, VaultSvcDown3 Minutes
OS: Windows 7 - Services Windows ServiceEventSystem, Eventlog, Netlogon, Power, Spooler, SensorDataService, ShellHWDetection, Schedule, Themes, ProfSvc, audioendpointbuilder, rpcss, samss, w32time, wuaserv, cryptsvc, dcomlaunch, trkwks, dhcpserver, bfe, uxsms, dps, fdrespub, nlasvc, plugplay, rpceptmapper, sysmain, audiosvc, fontcache, wsearch, gPsvc, iPhlpsvc, nSi, wScsvc, lAnmanserver, lAnmanworkstation, lMhosts, wInmgmtDown3 Minutes
OS: Windows 8 - Services Windows ServiceNetlogon, schedule, sens, spooler, themes, cRyptsvc, lAnmanworkstation, lAnmanserver, lMhosts, pLugplay, rPcss, sAmss, sHellhwdetection, tRkwks, wInmgmt, wUauserv, w32TIme, audioendpointbuilder, audiosrv, brokerinfrastructure, cscservice, eventsystem, lsm, mmcss, power, profsvc, bFe, dComlaunch, dPs, eVentlog, fDrespub, fOntcache, gPsvc, iPhlpsvc, nLasvc, nSi, rPceptmapper, sYsmain, wScsvc, wSearchDown3 Minutes
OS: Windows Vista - Services Windows ServiceEventSystem, Eventlog, Netlogon, Spooler, lAnmanworkstation, pLugplay, sAmss, w32TIme, wUAuservDown3 Minutes

FAQ

Next Steps