Alarm Codes Reference
Introduction
Every alarm raised by an Eyeglass appliance carries a unique alarm code made up of an application prefix and a numeric ID (for example SCA0004 REPLICATION_JOB_FAILED). This page is the master reference of alarm codes across all Eyeglass applications — use it to look up what a code means, which application raised it, and its severity where documented.
This is a code-meaning reference. For how to configure email notification, syslog forwarding, and batching behavior for these alarms, see Alarms and Alarm Batching. For DR-specific alarm forwarding configuration, see Disaster Recovery: Monitoring and Alerts.
Application Prefixes
Each Eyeglass application uses a distinct alarm code prefix, which can also be used to filter syslog forwarding by application.
| Prefix | Application |
|---|---|
SCA | DR and configuration replication |
AG | AirGap |
RSW | Ransomware Defender |
EAU | Easy Auditor |
ECA | Eyeglass Clustered Agent |
ES | Eyeglass Search |
DRSDEDGE | Eyeglass for virtual/edge clusters (PowerScaleSD) |
SETUP | Setup / initial provisioning issues |
LM | License Manager |
Severity and description are shown below only where confirmed against the source alarm reference. Where a code is listed without a documented severity or description, the appliance's own Alarms window is the authoritative source at runtime — treat any gap here as "not individually documented" rather than "no severity."
Alarm Severity Definitions
Each alarm is raised at one of the following severity levels:
| Severity | Meaning |
|---|---|
| CRITICAL | A service-impacting failure that requires immediate attention — data replication, failover readiness, or another core function has stopped working. |
| MAJOR | A significant issue that degrades functionality or will become service-impacting if left unresolved — investigate and resolve promptly. |
| WARNING | A condition that does not yet affect functionality but should be monitored or addressed to prevent escalation. |
| MINOR | A low-impact issue, typically informational in nature but worth reviewing. |
| INFORMATIONAL | No action required — the alarm reports normal operation or the successful completion of a job. |
SCA — Eyeglass (Core DR / Configuration Replication)
| Code | Meaning | Severity | Description |
|---|---|---|---|
| SCA0001 | GENERIC_ALARM | CRITICAL | Error within the SCA service — covers unknown errors with no more specific code. |
| SCA0002 | INVALID_SRC_DST_CONFIGURATION | CRITICAL | Found a replication job where either the source or destination is not a managed network element. |
| SCA0003 | INVENTORY_FAILED | CRITICAL | Failed to retrieve inventory. |
| SCA0004 | REPLICATION_JOB_FAILED | CRITICAL | Replication job failed to run. |
| SCA0005 | FAILED_TO_CONNECT | CRITICAL | Failed to connect to the designated target. |
| SCA0006 | BACKUP_JOB_FAILED | MAJOR | Failed to create a backup archive. |
| SCA0007 | JOB_AUDIT_FAILURE | MAJOR | Replication job audit failed (source and target configuration items do not match post-replication). |
| SCA0008 | QUOTA_FAILOVER_JOB_FAILED | CRITICAL | Quota failover job failed. |
| SCA0009 | BASE_LICENSE_TO_EXPIRE | WARNING | Base license is about to expire. |
| SCA0010 | BASE_LICENSE_HAS_EXPIRED | MAJOR | Base license has expired. |
| SCA0011 | DISCOVERY_LICENSE_TO_EXPIRE | WARNING | Discovery license is about to expire. |
| SCA0012 | DISCOVERY_LICENSE_HAS_EXPIRED | MAJOR | Discovery license has expired. |
| SCA0013 | FEATURE_LICENSE_TO_EXPIRE | WARNING | Feature license is about to expire. |
| SCA0014 | FEATURE_LICENSE_HAS_EXPIRED | MAJOR | Feature license has expired. |
| SCA0015 | MANAGEDOBJECT_LICENSE_TO_EXPIRE | WARNING | Managed object license is about to expire. |
| SCA0016 | MANAGEDOBJECT_LICENSE_HAS_EXPIRED | MAJOR | Managed object license has expired. |
| SCA0017 | SUPPORT_LICENSE_TO_EXPIRE | WARNING | Support license is about to expire. |
| SCA0018 | SUPPORT_LICENSE_HAS_EXPIRED | MAJOR | Support license has expired. |
| SCA0019 | TRIAL_KEY_LIMITS_REACHED | WARNING | Replication functionality limited by trial key. |
| SCA0020 | AUDITTRUSTEE_ISSUE | CRITICAL | Replication audit issue with the trustee(s). |
| SCA0021 | SINGLE_SHARE_MIGRATION_FAILURE | MAJOR | Single Share Migration job failed. |
| SCA0022 | NO_SUPPORT_LICENSE_INSTALLED | MAJOR | No support license installed — patches cannot be applied. |
| SCA0023 | REPLICATION_SOURCE_MATCHES_DESTINATION | CRITICAL | Found a replication job where the source and destination are the same. |
| SCA0024 | PREVIOUS_JOB_STILL_RUNNING | WARNING | A scheduled task could not run because another instance was already running. |
| SCA0025 | NETWORK_ELEMENT_TOO_BUSY | MAJOR | The target is too busy to respond to all requests — consider reducing parallel operations. |
| SCA0026 | DR_DASHBOARD_STATUS_CHANGE_ALARM | CRITICAL | Job status changed to error (Configuration Replication Job or SyncIQ Policy Job). |
| SCA0027 | DR_DASHBOARD_STATUS_CHANGE_WARNING | WARNING | Job status changed to pending or disabled. |
| SCA0028 | RUNBOOK_ROBOT_JOB_FAILED | MAJOR | Runbook Robot job failed for the job. |
| SCA0029 | POLICY_FAILOVER_FAILURE | MAJOR | Policy Failover job failed. |
| SCA0030 | ACCESS_ZONE_FAILOVER_FAILURE | MAJOR | Access Zone Failover job failed. |
| SCA0031 | DFS_FAILOVER_FAILURE | MAJOR | DFS Failover job failed. |
| SCA0032 | READINESS_JOB_FAILED | MAJOR | Readiness job failed to run. |
| SCA0033 | READINESS_CHECK_ERRORS | CRITICAL | Readiness job execution found errors — not ready for failover. |
| SCA0034 | SPN_PROCESSING_FAILED | MAJOR | SPN processing (checking or repairing) has failed. |
| SCA0035 | NODE_COUNT_VIOLATION | CRITICAL | The node count limitation has been exceeded for the license type. |
| SCA0036 | RUNBOOK_ROBOT_COUNT_EXCEEDED | WARNING | More than one Runbook Robot job is configured — only one will execute. |
| SCA0037 | ACCESS_ZONE_FAILOVER_SPN_FAILURE | CRITICAL | Failed to delete or repair SPNs during failover. |
| SCA0038 | POLICY_CONTAINS_EXCLUDES | WARNING | Found a policy with excluded directories — not a supported SyncIQ configuration for failback. |
| SCA0039 | DISASTER_RECOVERY_TESTING_FAILED | MAJOR | DR test mode job resulted in an error. |
| SCA0040 | FAILOVER_SUCCEEDED | INFORMATIONAL | A failover mode executed successfully without error. |
| SCA0041 | DISASTER_RECOVERY_TEMPLATE_FAILED | MAJOR | DR Template Replication failed (PowerScaleSD edge deployment). |
| SCA0042 | DISASTER_RECOVERY_EDGE_REPLICATION_FAILED | MAJOR | DR Replication to SD Edge has failed. |
| SCA0043 | DISASTER_RECOVERY_EDGE_DEPLOYMENT_FAILED | MAJOR | DR Deployment to SD Edge has failed. |
| SCA0044 | PROBE_UNDER_LICENSED | MAJOR | More clusters are managed by Eyeglass DR than CA UIM Probe license keys installed. |
| SCA0045 | INVENTORY_DEGRADED | MINOR | Inventory process encountered API failure responses from a cluster node. |
| SCA0046 | CREATE_SD_EDGE_DEPLOYMENT_JOB | MINOR | Creation of SD Edge deployment job failed (branch office / edge licensed solution). |
| SCA0047 | NE_REMOVAL_ERROR | CRITICAL | Network element removal failed / a managed cluster was deleted (user action). |
| SCA0049 | JOB_AUDIT_WARNING | WARNING | Replication job audit resulted in a warning (source/target config not 100% in sync). |
| SCA0050 | QUOTA_INVENTORY_FAILED | CRITICAL | Failed to retrieve quotas. |
| SCA0051 | DEDUPE_REPLICATION_FAILED | MAJOR | Deduplication replication job failed to run. |
| SCA0052 | DUPLICATE_INVENTORY_ITEM | MAJOR | Found duplicate inventory items. |
| SCA0053 | CONTINUOUS_OPERATION_STATUS_ERROR | MAJOR | Continuous operation status is ERROR (snapshot/dedupe sync status). |
| SCA0054 | MIGRATION_JOB_SUCCEEDED | INFORMATIONAL | Access Zone Migration job completed successfully. |
| SCA0055 | ARCHIVE_UPLOAD_FAILED | CRITICAL | Backup archive upload to support failed (typically a firewall/port 443 issue). |
| SCA0056 | DEDUPE_AUDIT_FAILED | MAJOR | Deduplication audit job failed to run. |
| SCA0057 | QUOTA_SYNCHRONIZATION_FAILED | MAJOR | Quota Synchronization job failed. |
| SCA0058 | ERROR_RETRIEVING_CLUSTER_VERSION | MAJOR | Error retrieving cluster OneFS version (heartbeat task). |
| SCA0060 | ERROR_GENERATING_DATASET | MINOR | Error generating the ServiceNow integration dataset. |
| SCA0061 | DISCOVERY_RETRIEVAL_ERROR | MAJOR | Failed to retrieve network element data (Unity REST API). |
| SCA0062 | REST_API_ERROR | MAJOR | Failed API REST request (Unity REST API). |
| SCA0063 | POLICY_FAILOVER_CANCEL | MAJOR | Policy Failover job canceled. |
| SCA0064 | ACCESS_ZONE_FAILOVER_CANCEL | MAJOR | Access Zone Failover job canceled. |
| SCA0065 | DFS_FAILOVER_CANCEL | MAJOR | DFS Failover job canceled. |
| SCA0066 | RUNBOOK_ROBOT_JOB_CANCELED | MAJOR | Runbook Robot job canceled. |
| SCA0067 | REHEARSAL_FAILOVER_CANCEL | MAJOR | DR rehearsal-mode failover canceled by user. |
| SCA0068 | REHEARSAL_FAILOVER_FAILURE | MAJOR | DR rehearsal-mode failover job failed. |
| SCA0069 | POLICY_POOL_MAPPING_ERROR | MAJOR | Error mapping a policy to an IP pool (Readiness validation). |
| SCA0070 | DISK_SPACE_FULL_WARNING | WARNING | Disk usage on Eyeglass or ECA nodes has reached 75%. |
| SCA0071 | DISK_SPACE_FULL_ERROR | CRITICAL | Disk usage on Eyeglass or ECA nodes has reached 90%. |
| SCA0073 | CSM_GROUP_QUOTAS_MANAGER_FAILURE | WARNING | Saving AD trustees to the database failed (Cluster Storage Monitor). |
| SCA0074 | REHEARSAL_FAILOVER_SUCCEEDED | INFORMATIONAL | DR rehearsal-mode failover completed successfully. |
| SCA0075 | ISK_SIZE_MONITOR_ALARM | MAJOR | Disk Size Monitor detected a folder or file exceeding a threshold. (Sic — code name as published by the source.) |
| SCA0076 | DISK_SIZE_MONITOR_INACTIVE | MAJOR | The Disk Size Monitor process is no longer active. |
| SCA0077 | DISK_SIZE_MONITOR_ERROR | MAJOR | The Disk Size Monitor process has failed. |
| SCA0078 | REST_API_CALL_FAILURE | MINOR | An internal error occurred while processing a REST API request. |
| SCA0079 | NEW_POLICY_DISCOVERED | INFORMATIONAL | A new SyncIQ policy was discovered and requires a job to be created/enabled. |
| SCA0080 | UNCONFIGURED_JOB_PRESENT | MAJOR | A job has a SyncIQ policy in an unconfigured state requiring administrator action. |
| SCA0081 | READINESS_CHECK_WARNINGS | WARNING | Readiness job execution found warnings. |
| SCA0087 | SYNCIQ_MONITOR_ERRORS | MAJOR | SyncIQ data-integrity monitor detected a file that failed to sync correctly. |
| SCA0088 | ONFIG_BACKUP_JOB_FAILURE | WARNING | Appliance backup zip creation process failed. (Sic — code name as published by the source.) |
| SCA0094 | RAM_UNDERSIZED | CRITICAL | RAM size is below the published limits for the current cluster/object/policy count. |
AG — AirGap
| Code | Meaning | Severity | Description |
|---|---|---|---|
| AG0001 | AIRGAP_JOB_FAILED | CRITICAL | An AirGap job failed and needs attention. |
| AG0002 | AIRGAP_JOB_SUCCEEDED | INFORMATIONAL | An AirGap job succeeded (vault opened, sync ran, vault closed). |
| AG0003 | AIRGAP_ROUTE_CLOSED | INFORMATIONAL | The AirGap network is now disconnected for the policy. |
| AG0004 | AIRGAP_ROUTE_OPEN | INFORMATIONAL | The AirGap network is now connected for the policy. |
| AG0005 | AIRGAP_JOB_DISABLED_FOR_ACTIVE_EVENT | WARNING | A scheduled AirGap sync was skipped because an active Ransomware Defender threat alarm exists. |
| AG0006 | VAULT_AIRGAP_JOB_FAILED | MAJOR | A Vault AirGap job failed and needs attention. |
| AG0007 | VAULT_AIRGAP_JOB_SUCCEEDED | INFORMATIONAL | A Vault AirGap job succeeded. |
| AG0008 | VAULT_OPENED | CRITICAL | The secure AirGap vault is currently open. |
| AG0009 | AIRGAP_EVENT_RETRIEVE_JOB_FAILED | CRITICAL | The job that retrieves AirGap events failed. |
| AG0010 | AIRGAP_EVENT_RETRIEVE_JOB_SUCCEEDED | INFORMATIONAL | The job that retrieves AirGap events succeeded. |
| AG0011 | AIRGAP_SCHEDULES_QUERY | INFORMATIONAL | AirGap schedule query event. |
| AG0012 | AIRGAP_JOB_NOT_STARTED | CRITICAL | An AirGap job did not start. |
| AG0013 | AIRGAP_JOB_STARTED | INFORMATIONAL | An AirGap job started. |
| AG0014 | AIRGAP_POLICY_CHANGED | CRITICAL | An AirGap policy configuration changed. |
RSW — Ransomware Defender
| Code | Meaning | Severity | Description |
|---|---|---|---|
| RSW0001 | RANSOMWARE_DEFENDER_EVENT | CRITICAL | A Ransomware Defender detection event was raised. |
| RSW0002 | RANSOMWARE_USER_LOCKED | CRITICAL | A user was locked out in response to a detection. |
| RSW0003 | RANSOMWARE_USER_LOCK_FAILED | CRITICAL | Locking out a user failed. |
| RSW0004 | RANSOMWARE_ECA_IGLS_SERVICE_FAILURE | MAJOR | An ECA IGLS service failure was detected. |
| RSW0005 | RANSOMWARE_ECA_HBASE_FAILURE | MAJOR | An ECA HBase service failure was detected. |
| RSW0006 | RANSOMWARE_ECA_COMM_FAILURE | MAJOR | Communication failure between Ransomware Defender and the ECA cluster. |
| RSW0008 | RANSOMWARE_ENTER_MONITOR_MODE | MAJOR | Ransomware Defender entered monitor-only mode. |
| RSW0009 | RANSOMWARE_LEAVE_MONITOR_MODE | MAJOR | Ransomware Defender left monitor-only mode. |
| RSW0010 | RANSOMWARE_ECA_VERSION | MAJOR | ECA version mismatch/notice relevant to Ransomware Defender. |
| RSW0011 | RSW_RESTORE_ACCESS_SUCCESS | INFORMATIONAL | Restoring a previously locked-out user's access succeeded. |
| RSW0012 | RSW_RESTORE_ACCESS_FAILED | CRITICAL | Restoring a previously locked-out user's access failed. |
| RSW0013 | RSW_SNAPSHOT_WARNING | CRITICAL | A warning occurred creating a protective snapshot. |
| RSW0014 | RSW_SNAPSHOT_FAILED | CRITICAL | Creating a protective snapshot failed. |
| RSW0015 | RSW_SNAPSHOT_DELETE_WARNING | MAJOR | A warning occurred deleting a snapshot. |
| RSW0016 | RSW_SNAPSHOT_DELETE_FAILED | MAJOR | Deleting a snapshot failed. |
| RSW0017 | HBASE_UPGRADE_FAILURE | INFORMATIONAL | An HBase upgrade step failed. |
| RSW0018 | RANSOMWARE_DEFENDER_UNDER_LICENSED | MAJOR | Ransomware Defender is under-licensed for the current environment. |
| RSW0020 | BACKUP_INGESTION_FAILURE | WARNING | A backup ingestion step failed. |
| RSW0021 | SECURITY_EVENT_FAILED | CRITICAL | A Security Guard test event failed to process. |
| RSW0022 | SECURITY_EVENT_RETURNED_ZERO | MAJOR | A Security Guard test event returned zero results. |
| RSW0024 | SECURITY_GUARD_FAILURE | MAJOR | A Security Guard test failed. |
| RSW0025 | RANSOMWARE_WARNING_ERROR | CRITICAL | A warning or error occurred — contact support. |
| RSW0026 | TURBOAUDIT_EVENTRATE_BELOW_THRESHOLD_WARNING | WARNING | Event rate for all TurboAudit nodes over the configured window is below the configured threshold — check the NFS mount for audit data ingestion. |
| RSW0027 | EVTARCHIVE_EVENTRATE_BELOW_THRESHOLD_WARNING | WARNING | Event archive ingestion rate is below the configured threshold. |
| RSW0028 | SECURITY_GUARD_SUCCESS | INFORMATIONAL | A Security Guard test completed successfully. |
| RSW0029 | CYBER_RECOVERY_MANAGER_JOB_ERROR | WARNING | A Cyber Recovery Manager job encountered an error. |
EAU — Easy Auditor
| Code | Meaning |
|---|---|
| EAU0002 | AUDITOR_REPORT_FAILURE |
| EAU0003 | EVENT_AUDIT_TIME_SKEW_ERROR |
| EAU0004 | TIME_SKEW_ERROR |
| EAU0005 | NO_SMART_QUOTA_FOR_DLP_PATH |
| EAU0006 | AUDITOR_REPORT_SUCCESS |
| EAU0007 | ACTIVE_AUDITOR_EVENT |
| EAU0008 | ROBO_AUDIT_FAILURE |
| EAU0009 | ROBO_AUDIT_SUCCESS |
ECA — Eyeglass Clustered Agent
| Code | Meaning |
|---|---|
| ECA0001 | ECA_SERVICE_INFO |
| ECA0002 | ECA_CRITICAL_ERROR |
| ECA0003 | ECA_SERVICE_WARNING |
| ECA0004 | ECA_MINOR_ERROR |
| ECA0005 | ECA_MAJOR_ERROR |
| ECA0006 | ECA_FATAL_ERROR |
| ECA0007 | ECA_NODE_FAILURE |
ES — Eyeglass Search
| Code | Meaning | Severity |
|---|---|---|
| ES0001 | ES_NODE_COUNT_VIOLATION | CRITICAL |
| ES001 | Trace notification (debug-level) | INFORMATIONAL |
| ES002 | Informational notification (task completed) | INFORMATIONAL |
| ES003 | Warning notification | WARNING |
| ES004 | Minor notification | MINOR |
| ES005 | Major notification | MAJOR |
| ES006 | Critical notification | CRITICAL |
| ES007 | Module initialized successfully | — |
| ES008 | Module failed to initialize | — |
| ES009 | Consecutive service failure | — |
| ES010 | Subsystem retrieved successfully | — |
| ES011 | Subsystem created successfully | — |
| ES012 | Subsystem deleted successfully | — |
| ES013 | Subsystem modified successfully | — |
| ES014 | Subsystem retrieval failed | — |
| ES015 | Subsystem creation failed | — |
| ES016 | Subsystem deletion failed | — |
| ES017 | Subsystem modification failed | — |
| ES018 | Configuration added successfully | — |
| ES019 | Configuration deleted successfully | — |
| ES020 | Configuration modified successfully | — |
| ES021 | Job started successfully | — |
| ES022 | Job completed successfully | — |
| ES023 | Job failed to run | — |
| ES024 | Login successful | — |
| ES025 | Login failed | — |
See Alarm Codes in the shared reference for full descriptions of each ES code.
DRSDEDGE — Eyeglass for Virtual/Edge Clusters
| Code | Meaning |
|---|---|
| DRSDEDGE0001 | DRSDEDGE_NODE_COUNT_VIOLATION |
SETUP — Setup / Initial Provisioning
| Code | Meaning |
|---|---|
| SETUP0001 | SETUP_REDISCOVER_REQUEST |
| SETUP0002 | SETUP_INVENTORY_DUPLICATES_CRITICAL |
| SETUP0003 | SETUP_INVENTORY_DUPLICATES_WARNING |
LM — License Manager
| Code | Meaning |
|---|---|
| LM0001 | LM_LICENSE_TO_EXPIRE |
| LM0002 | LM_LICENSE_HAS_EXPIRED |
See Also
- Alarms — overview of alarm delivery for this product line.
- Alarm Batching — consolidate high-volume alarm notifications into periodic batch emails, including how to bypass specific codes from this reference by alarm code.
- Disaster Recovery: Monitoring and Alerts — configure email and syslog forwarding for DR-relevant alarms, including filtering by the
SCAprefix and by individual alarm code from this reference.