Skip to content

Device Events

The framework event taxonomy. Severity is inherited from the parent when an event does not set its own. The Message column is the operator-facing wording; values in braces are filled in when the event happens.

pq.event.access

Physical access control events. Every event carries thingId.

Event id Severity Message Description Required Optional
pq.event.access.antipassback Info — Anti-passback state events — —
pq.event.access.antipassback.cleared Info Antipassback state cleared at — — spaceId, personId
pq.event.access.area.occupancy Info — Access area occupancy status events for mustering and capacity tracking — —
pq.event.access.area.occupancy.changed Info Area {thingName} occupancy changed to {occupancyCount} of {occupancyLimit} — occupancyCount occupancyLimit
pq.event.access.area.occupancy.empty Info Area {thingName} is now empty — — —
pq.event.access.area.occupancy.full Warn Area {thingName} has reached maximum occupancy ({occupancyCount} persons) limit {occupancyLimit} — — occupancyCount, occupancyLimit
pq.event.access.area.state Info — Access area operational state events — —
pq.event.access.area.state.disabled Warn Area {thingName} disabled — — —
pq.event.access.area.state.enabled Info Area {thingName} enabled — — —
pq.event.access.credential Info — Credential lifecycle events (enrollment, deletion, limits) — —
pq.event.access.credential.deleted Info — Credential deletion events — —
pq.event.access.credential.deleted.all Critical All credentials deleted from {thingName} by {personName} ({deletedCount} credentials) — — personId, deletedCount
pq.event.access.credential.deleted.single Info Credential deleted from {thingName} for {personName} ({credentialType}) — — personId, credentialType
pq.event.access.credential.enrollment Info — Credential enrollment lifecycle events — —
pq.event.access.credential.enrollment.duplicate Warn Duplicate credential detected at {thingName} for {personName} ({credentialType}) — — personId, credentialType, existingPersonId
pq.event.access.credential.enrollment.failed Warn Credential enrollment failed at {thingName} for {personName} — — personId, technology
pq.event.access.credential.enrollment.succeeded Info Credential enrolled for {personName} at {thingName} ({technology}) — personId credentialId, technology, card_code, card_bits
pq.event.access.credential.limit Info — Credential limit events — —
pq.event.access.credential.limit.usage Info — Usage limit events for temporary passes and visitor cards — —
pq.event.access.credential.limit.usage.changed Info Credential use limit changed for {personName} at {thingName}: {remainingUses} uses remaining — personId, remainingUses —
pq.event.access.credential.limit.usage.exhausted Warn Credential use limit exhausted for {personName} at {thingName} — personId —
pq.event.access.denied Warn Access denied to {personName} at {thingName} (credential: {credentialType}) — — personId, credentialId, credentialType
pq.event.access.denied.antipassback Warn Access denied to {personName} at {thingName}: antipassback violation — — personId, credentialId, credentialType, personId, credentialId, credentialType, refExternalPerson
pq.event.access.denied.blocked Warn Access denied at {thingName}: credential blocked {plate} ({personName}) - {blockReason} (Direction: {direction}) — — personId, credentialId, credentialType, personId, credentialId, blockReason
pq.event.access.denied.dual Warn Access denied at {thingName}: second person required — — personId, credentialId, credentialType
pq.event.access.denied.expired Warn Access denied at {thingName}: credential expired ({personName}) - expired {expiryDate} — — personId, credentialId, credentialType, personId, credentialId, expiryDate
pq.event.access.denied.fraud Critical Access denied at {thingName}: biometric fraud detected ({credentialType}) — — personId, credentialId, credentialType, credentialType
pq.event.access.denied.incomplete Warn Access denied at {thingName}: incomplete multifactor sequence ({personName}) — — personId, credentialId, credentialType, personId, credentialId, credentialType
pq.event.access.denied.interlock Warn Access denied at {thingName}: interlock active — — personId, credentialId, credentialType
pq.event.access.denied.invalid Warn Access denied at {thingName}: invalid credential ({credentialType}) — — personId, credentialId, credentialType, credentialId, credentialType
pq.event.access.denied.locked Warn Access denied at {thingName}: access point locked — — personId, credentialId, credentialType
pq.event.access.denied.occupancy Warn Access denied at {thingName}: occupancy limit reached — — personId, credentialId, credentialType
pq.event.access.denied.pin Warn Access denied at {thingName}: invalid PIN — — personId, credentialId, credentialType
pq.event.access.denied.schedule Warn Access denied outside scheduled hours at {thingName} to {personName} (schedule: {scheduleName}) — — personId, credentialId, credentialType, personId, scheduleName
pq.event.access.denied.unknown Warn Access denied at {thingName}: unknown {credentialType} ({card_display}) — — personId, credentialId, credentialType, credentialType, card_code, card_bits
pq.event.access.door Info — — — —
pq.event.access.door.closed Info Door {thingName} closed — — —
pq.event.access.door.forced Critical Door {thingName} forced open — — —
pq.event.access.door.forced.cleared Info Door {thingName} forced open alarm cleared — — —
pq.event.access.door.held Warn Door {thingName} held open — — —
pq.event.access.door.held.cleared Info Door {thingName} held open alarm cleared — — —
pq.event.access.door.held.extended Info Door {thingName} held extended by {personName} — — personId
pq.event.access.door.locked Info Door {thingName} locked (deadbolt) by {personName} — — personId
pq.event.access.door.locked.remote Info Door {thingName} locked remotely by {personName} — — personId
pq.event.access.door.opened Info Door {thingName} opened by {personName} — — personId
pq.event.access.door.secured Info Door {thingName} secured by {personName} — — personId
pq.event.access.door.secured.remote Info Door {thingName} secured remotely by {personName} — — personId
pq.event.access.door.secured.schedule Info Door {thingName} secured by schedule ({scheduleName}) — — scheduleName
pq.event.access.door.unlocked Info Door {thingName} unlocked (deadbolt) by {personName} — — personId
pq.event.access.door.unlocked.remote Info Door {thingName} unlocked remotely by {personName} — — personId
pq.event.access.door.unsecured Info Door {thingName} unsecured for {personName} — — personId
pq.event.access.door.unsecured.remote Info Door {thingName} unsecured remotely by {personName} — — personId
pq.event.access.door.unsecured.rex Info Door {thingName} unsecured via REX — — —
pq.event.access.door.unsecured.schedule Info Door {thingName} unsecured by schedule ({scheduleName}) — — scheduleName
pq.event.access.granted Info Access granted to {personName} at {thingName} using {credentialType} {plate} (Direction: {direction}) — — personId, credentialId, credentialType, direction
pq.event.access.granted.antipassback Warn Access granted despite antipassback violation to {personName} at {thingName} — — personId, credentialId, credentialType, direction, personId, credentialId, credentialType, refExternalPerson
pq.event.access.position Info — — — —
pq.event.access.position.changed Info Position changed at {thingName} to {position} — — position
pq.event.access.position.cleared Info Position returned to normal at — — —
pq.event.access.reader Info — — — —
pq.event.access.reader.lockout Info — Reader lockout lifecycle — —
pq.event.access.reader.lockout.cleared Info Reader {thingName} lockout cleared — — —
pq.event.access.reader.lockout.triggered Warn Reader {thingName} locked out after {failedAttempts} failed attempts for {lockoutDuration} — failedAttempts lockoutDuration
pq.event.access.synchronization Info — Access synchronization lifecycle events — —
pq.event.access.synchronization.completed Info Access synchronization completed at — — —
pq.event.access.synchronization.completed.warnings Warn Access synchronization completed at {thingName} with {problemCount} problems — problemCount —
pq.event.access.synchronization.failed Error Access synchronization failed at — — —
pq.event.access.synchronization.restore_needed Warn Access synchronization restore needed at — — —
pq.event.access.synchronization.started Info Access synchronization started at — — —
pq.event.access.zone Info — — — —
pq.event.access.zone.entered Info {personName} entered zone — zoneName personId, refExternalPerson
pq.event.access.zone.exited Info {personName} exited zone — zoneName personId, refExternalPerson

pq.event.alarm

Alarm signaling and annunciation events. Every event carries thingId.

Event id Severity Message Description Required Optional
pq.event.alarm.sounder Info — Audible alarm signaling events — —
pq.event.alarm.sounder.activated Warn Sounder activated at — — —
pq.event.alarm.sounder.deactivated Info Sounder deactivated at — — —
pq.event.alarm.sounder.fault Warn Sounder circuit fault at {thingName} ({faultType}) — — faultType
pq.event.alarm.sounder.fault.cleared Info Sounder circuit fault cleared at {thingName} ({faultType}) — — faultType
pq.event.alarm.sounder.silenced Warn Sounder silenced at — — —

pq.event.connection

Connection state change events emitted by ConnectionStateTracker. Every event carries thingId.

Event id Severity Message Description Required Optional
pq.event.connection.lost Warn Connection lost to {thingName} (stable for {duration}) (failure #{count}) — — duration, count
pq.event.connection.restored Info Connection restored to {thingName} (downtime: {duration}) after {count} attempts — — duration, count

pq.event.control

Generic output and actuator control events. Every event carries thingId.

Event id Severity Message Description Required Optional
pq.event.control.activated Info Output activated at — — —
pq.event.control.activated.remote Info Output {thingName} activated remotely by {personName} — — personId, refExternalPerson
pq.event.control.deactivated Info Output deactivated at — — —
pq.event.control.deactivated.remote Info Output {thingName} deactivated remotely by {personName} — — personId, refExternalPerson
pq.event.control.denied Warn Control action denied by device at {thingName} - {reason} — — reason, eventType, personId, rawData

pq.event.detection

Generic detection and monitoring events. Every event carries thingId.

Event id Severity Message Description Required Optional
pq.event.detection.activated Warn Input activated at — — —
pq.event.detection.deactivated Info Input deactivated at — — —
pq.event.detection.fault Warn Input fault at — — —

pq.event.device

Generic device events for unhandled or unknown event types. Every event carries thingId.

Event id Severity Message Description Required Optional
pq.event.device.discovery.completed Info Device discovery completed on {thingName}: {devicesAdded} added, {devicesChanged} changed, {devicesRemoved} removed — devicesAdded, devicesChanged, devicesRemoved —
pq.event.device.import.completed Info Configuration file import completed on {thingName}: {devicesAdded} added, {devicesChanged} changed, {devicesRemoved} removed — devicesAdded, devicesChanged, devicesRemoved —
pq.event.device.unknown Warn Unknown event '{eventType}' at {thingName} by {personName} (credential: {credentialInfo}) — eventType personId, credentialId, credentialInfo, rawData
pq.event.device.unresolved Warn Event '{eventType}' for unconfigured {unresolvedThingType} at address {unresolvedAddress} on {thingName} — eventType, unresolvedThingType unresolvedAddress, personId, credentialId, credentialInfo, rawData

pq.event.energy

Energy and power management events. Every event carries thingId.

Event id Severity Message Description Required Optional
pq.event.energy.consumption Info — — — —
pq.event.energy.consumption.high Warn High power consumption at {thingName}: {consumption}kW (threshold: {threshold}kW) — consumption threshold
pq.event.energy.consumption.threshold Warn Power consumption threshold exceeded at {thingName}: {consumption}kW (threshold: {threshold}kW) — consumption, threshold —
pq.event.energy.power Info — — — —
pq.event.energy.power.failure Critical Power failure at — — —
pq.event.energy.power.fuse Info — Power fuse state events — —
pq.event.energy.power.fuse.failed Warn Fuse failure detected at — — —
pq.event.energy.power.fuse.restored Info Fuse restored at — — —
pq.event.energy.power.on Info Device {thingName} powered on — — —
pq.event.energy.power.overload Warn Power output overload at — — —
pq.event.energy.power.overload.restored Info Power output overload cleared at — — —
pq.event.energy.power.restored Info Power restored at — — —
pq.event.energy.ups Info — — — —
pq.event.energy.ups.active Warn UPS activated at {thingName} (battery: {batteryPercentage}%) (runtime: {estimatedRuntime}) — — batteryPercentage, estimatedRuntime

pq.event.fire

Fire detection and suppression events. Every event carries thingId.

Event id Severity Message Description Required Optional
pq.event.fire.address Critical — Fire address lifecycle and addressing fault events — —
pq.event.fire.address.auto_addressing Info Fire detector auto-addressing at — — rawEventNumber
pq.event.fire.address.disabled Warn Fire address disabled at {thingName} by {personName} — — personId, rawEventNumber
pq.event.fire.address.duplicate Error Duplicate fire address at {thingName} ({address}) — — address, rawEventNumber
pq.event.fire.address.enabled Info Fire address enabled at {thingName} by {personName} — — personId, rawEventNumber
pq.event.fire.address.lost Error Fire address lost at {thingName} ({address}) — — address, rawEventNumber
pq.event.fire.address.out_of_configuration Warn Fire address outside configuration at {thingName} ({address}) — — address, rawEventNumber
pq.event.fire.alarm Critical Fire alarm at {thingName} zone {zoneId} ({detectorType}) — — zoneId, detectorType
pq.event.fire.alarm.acknowledged Info Fire alarm acknowledged at {thingName} by {personName} — — personId, rawEventNumber
pq.event.fire.alarm.blocked Warn Fire alarm blocking started at — — rawEventNumber
pq.event.fire.alarm.conditional Critical Conditional fire alarm at {thingName} zone {zoneId} — — zoneId, rawEventNumber
pq.event.fire.alarm.general Critical General fire alarm at {thingName} zone {zoneId} — — zoneId, rawEventNumber
pq.event.fire.alarm.general.cleared Info General fire alarm cleared at {thingName} zone {zoneId} — — zoneId, rawEventNumber
pq.event.fire.alarm.section Critical Section fire alarm at {thingName} zone {zoneId} — — zoneId, rawEventNumber
pq.event.fire.alarm.section.cleared Info Section fire alarm cleared at {thingName} zone {zoneId} — — zoneId, rawEventNumber
pq.event.fire.alarm.unblocked Info Fire alarm blocking ended at — — rawEventNumber
pq.event.fire.cleared Info Fire condition cleared at — — —
pq.event.fire.control Critical — Fire protection control output events — —
pq.event.fire.control.activated Critical Fire control output activated at {thingName} ({controlType}) — — controlType, rawEventNumber
pq.event.fire.control.deactivated Info Fire control output deactivated at {thingName} ({controlType}) — — controlType, rawEventNumber
pq.event.fire.control.disabled Warn Fire control output disabled at {thingName} ({controlType}) — — controlType, rawEventNumber
pq.event.fire.control.enabled Info Fire control output enabled at {thingName} ({controlType}) — — controlType, rawEventNumber
pq.event.fire.detector Critical — Fire detector diagnostic events — —
pq.event.fire.detector.blinded Warn Fire detector blinded or shadowed at — — rawEventNumber
pq.event.fire.detector.dirty Warn Fire detector dirty at — — rawEventNumber
pq.event.fire.detector.glared Warn Fire detector glare detected at — — rawEventNumber
pq.event.fire.detector.unconfigured Warn Fire detector not configured at — — rawEventNumber
pq.event.fire.detector.unstable Warn Fire detector cannot stabilize at — — rawEventNumber
pq.event.fire.heat Critical — — — —
pq.event.fire.heat.detected Critical High temperature detected at {thingName}: {temperature}°C — temperature —
pq.event.fire.heat.rising Warn Rapid temperature rise at {thingName} ({ratePerMinute}°C/min) — — ratePerMinute
pq.event.fire.input Critical — Fire input address activation events — —
pq.event.fire.input.activated Warn Fire input activated at — — rawEventNumber
pq.event.fire.input.deactivated Info Fire input deactivated at — — rawEventNumber
pq.event.fire.intervention Critical — Fire alarm intervention window - the confirmation and investigation timers that hold back transmission to the fire brigade, and how the window ended — —
pq.event.fire.intervention.cancelled Info Intervention at {thingName} ended by cancellation criterion, the fire brigade was not called — — rawEventNumber
pq.event.fire.intervention.cleared Info Intervention at {thingName} ended — — rawEventNumber
pq.event.fire.intervention.dispatched Critical Intervention time expired at {thingName}, the fire brigade has been called — — rawEventNumber
pq.event.fire.intervention.extended Critical Investigation time (T2) running at {thingName} ({durationSeconds}s) after the alarm was acknowledged — — rawEventNumber, durationSeconds, expiresAt
pq.event.fire.intervention.started Critical Alarm confirmation time (T1) running at {thingName} ({durationSeconds}s), transmission to the fire brigade held back — — rawEventNumber, durationSeconds, expiresAt
pq.event.fire.line Critical — Fire loop or line wiring fault events — —
pq.event.fire.line.ground_fault Error Fire line ground fault at — — lineId, rawEventNumber
pq.event.fire.line.interrupted Error Fire line interrupted at — — lineId, rawEventNumber
pq.event.fire.line.leakage Warn Fire line leakage at — — lineId, rawEventNumber
pq.event.fire.line.short Error Fire line short circuit at — — lineId, rawEventNumber
pq.event.fire.manual Critical Manual fire alarm activated at {thingName} by {personName} — — personId
pq.event.fire.output Critical — Fire output address activation events — —
pq.event.fire.output.activated Info Fire output activated at — — rawEventNumber
pq.event.fire.output.deactivated Info Fire output deactivated at — — rawEventNumber
pq.event.fire.panel Critical — Fire panel operational events — —
pq.event.fire.panel.alarm_counter Info Fire alarm counter on {thingName} is {alarmCount} (revision {revisionCount}) — — alarmCount, revisionCount, previousAlarmCount
pq.event.fire.panel.day_mode Info Fire panel day mode set at — — rawEventNumber
pq.event.fire.panel.external_configuration Critical — External configuration session lifecycle — —
pq.event.fire.panel.external_configuration.completed Info External fire panel configuration completed at — — rawEventNumber
pq.event.fire.panel.external_configuration.started Warn External fire panel configuration started at — — rawEventNumber
pq.event.fire.panel.night_mode Info Fire panel night mode set at — — rawEventNumber
pq.event.fire.panel.reset Warn Fire panel reset at {thingName} by {personName} — — personId, rawEventNumber
pq.event.fire.panel.service_access Warn Fire panel service access at — — rawEventNumber
pq.event.fire.prealarm Warn Fire pre-alarm at — — —
pq.event.fire.routing Critical — Fire alarm routing/transmission events to remote display or dispatch equipment — —
pq.event.fire.routing.disabled Warn Fire alarm routing disabled at {thingName} to {target} — — target, rawEventNumber
pq.event.fire.routing.enabled Info Fire alarm routing enabled at {thingName} to {target} — — target, rawEventNumber
pq.event.fire.routing.started Critical Fire alarm routing started at {thingName} to {target} — — target, rawEventNumber
pq.event.fire.routing.stopped Info Fire alarm routing stopped at {thingName} to {target} — — target, rawEventNumber
pq.event.fire.smoke Critical — — — —
pq.event.fire.smoke.cleared Info Smoke cleared at — — —
pq.event.fire.smoke.detected Critical Smoke detected at {thingName} (level: {smokeLevel}) — — smokeLevel
pq.event.fire.sounder Critical — Fire sounder and audible alarm signaling events — —
pq.event.fire.sounder.activated Critical Fire sounder activated at — — rawEventNumber
pq.event.fire.sounder.deactivated Info Fire sounder deactivated at — — rawEventNumber
pq.event.fire.sounder.disabled Warn Fire sounder disabled at — — rawEventNumber
pq.event.fire.sounder.enabled Info Fire sounder enabled at — — rawEventNumber
pq.event.fire.sounder.silenced Warn Fire sounder silenced at {thingName} by {personName} — — personId, rawEventNumber
pq.event.fire.supervisory Warn Fire system supervisory condition at {thingName}: {condition} — condition —
pq.event.fire.suppression Critical — — — —
pq.event.fire.suppression.activated Critical Fire suppression system activated at {thingName} ({systemType}) — — systemType
pq.event.fire.suppression.flow Critical Water flow detected in suppression system at — — —
pq.event.fire.test Critical — Fire system test lifecycle and point test results — —
pq.event.fire.test.activation Info Fire test activation at — — rawEventNumber
pq.event.fire.test.completed Info Fire test completed at {thingName} ({testType}) by {personName} — — personId, testType, rawEventNumber
pq.event.fire.test.fault Warn Fire test fault at {thingName} ({faultType}) — — faultType, faultCode, rawEventNumber
pq.event.fire.test.partial Info Fire group test partially completed at — — rawEventNumber
pq.event.fire.test.passed Info Fire test passed at {thingName}, waiting for finish — — rawEventNumber
pq.event.fire.test.started Info Fire test started at {thingName} ({testType}) by {personName} — — personId, testType, rawEventNumber
pq.event.fire.trouble Warn Fire system trouble at {thingName} ({faultType}) code {faultCode} — — faultType, faultCode, rawEventNumber
pq.event.fire.trouble.cleared Info Fire system trouble cleared at {thingName} ({faultType}) — — faultType, faultCode, rawEventNumber

pq.event.hvac

HVAC system events. Every event carries thingId.

Event id Severity Message Description Required Optional
pq.event.hvac.filter Info — — — —
pq.event.hvac.filter.due Warn Filter replacement due at {thingName} ({remainingTime} remaining) — — remainingTime
pq.event.hvac.mode Info — — — —
pq.event.hvac.mode.cooling Info Cooling mode activated at — — —
pq.event.hvac.mode.heating Info Heating mode activated at — — —
pq.event.hvac.mode.off Info HVAC system turned off at — — —
pq.event.hvac.mode.ventilating Info Ventilation mode activated at — — —
pq.event.hvac.setpoint Info — — — —
pq.event.hvac.setpoint.changed Info Temperature setpoint changed to {setpoint}°C at {thingName} by {personName} (was: {previousSetpoint}°C) — setpoint personId, previousSetpoint
pq.event.hvac.temperature Info — — — —
pq.event.hvac.temperature.high Warn High temperature at {thingName}: {temperature}°C (threshold: {threshold}°C) — temperature threshold
pq.event.hvac.temperature.low Warn Low temperature at {thingName}: {temperature}°C (threshold: {threshold}°C) — temperature threshold
pq.event.hvac.threshold Info — — — —
pq.event.hvac.threshold.exceeded Warn Environmental threshold exceeded at {thingName} for {parameter} (value: {value}) — — parameter, value
pq.event.hvac.threshold.normal Info Environmental conditions returned to normal at — — —

pq.event.intrusion

Intrusion detection system events. Every event carries thingId.

Event id Severity Message Description Required Optional
pq.event.intrusion.alarm Critical Intrusion alarm at — — —
pq.event.intrusion.alarm.acknowledged Info Alarm acknowledged at {thingName} by {personName} — — personId
pq.event.intrusion.alarm.acknowledged.remote Info Alarm acknowledged remotely at {thingName} by {personName} — — personId, personId
pq.event.intrusion.alarm.verified Critical Verified intrusion alarm at — — —
pq.event.intrusion.armed Info System armed by — — personId, refExternalPerson
pq.event.intrusion.armed.exit_delay Info System arming exit delay started by — — personId, refExternalPerson
pq.event.intrusion.armed.exit_delay.remote Info System arming exit delay started remotely by — — personId, refExternalPerson
pq.event.intrusion.armed.forced Warn System forced armed by — — personId, refExternalPerson, bypassedZoneCount
pq.event.intrusion.armed.forced.bypass Warn System armed with bypassed zones by — — personId, refExternalPerson, bypassedZoneCount
pq.event.intrusion.armed.forced.remote Warn System forced armed remotely by — — personId, refExternalPerson, bypassedZoneCount
pq.event.intrusion.armed.instant Info System armed instantly by — — personId, refExternalPerson
pq.event.intrusion.armed.partial Info System partially armed by — — personId, refExternalPerson
pq.event.intrusion.armed.partial.remote Info System partially armed remotely by — — personId, refExternalPerson
pq.event.intrusion.armed.partial.sleep Info System armed in sleep mode by — — personId, refExternalPerson
pq.event.intrusion.armed.partial.sleep.remote Info System armed remotely in sleep mode by — — personId, refExternalPerson
pq.event.intrusion.armed.partial.stay Info System armed in stay mode by — — personId, refExternalPerson
pq.event.intrusion.armed.partial.stay.remote Info System armed remotely in stay mode by — — personId, refExternalPerson
pq.event.intrusion.armed.rearm Info System re-armed at — — personId, refExternalPerson
pq.event.intrusion.armed.remote Info System armed remotely by — — personId, refExternalPerson
pq.event.intrusion.armed.schedule Info System armed by schedule ({scheduleName}) — — personId, refExternalPerson, scheduleName
pq.event.intrusion.armed.schedule.early Warn System armed earlier than schedule at {thingName} by {personName} — — personId, refExternalPerson, scheduleName, personId, scheduleName
pq.event.intrusion.armed.schedule.late Warn System armed later than schedule at {thingName} by {personName} — — personId, refExternalPerson, scheduleName, personId, scheduleName
pq.event.intrusion.arming Warn — Arming attempt events (system not armed) — —
pq.event.intrusion.arming.denied Warn System arming denied to {personName} at {thingName} — — personId
pq.event.intrusion.arming.failed Warn System arming failed at {thingName} by {personName} — — personId
pq.event.intrusion.arming.failed.close Warn Close-arming failed at — — personId
pq.event.intrusion.arming.failed.schedule Warn Scheduled auto-arming failed at — — personId
pq.event.intrusion.arming.failed.timeout Warn Arming failed at {thingName}: arming window expired — — personId
pq.event.intrusion.arming.postponed Warn Auto-arming postponed at {thingName} by {personName} — — personId
pq.event.intrusion.arming.warning Warn — Pre-arming warning events — —
pq.event.intrusion.arming.warning.schedule Warn Scheduled auto-arming warning at — — —
pq.event.intrusion.bypassed Info Zone {thingName} bypassed by {personName} — — personId
pq.event.intrusion.bypassed.cleared Info Zone {thingName} bypass cleared by {personName} — — personId, personId
pq.event.intrusion.bypassed.cleared.remote Info Zone {thingName} bypass cleared remotely by {personName} — — personId, personId, personId
pq.event.intrusion.bypassed.remote Info Zone {thingName} bypassed remotely by {personName} — — personId, personId
pq.event.intrusion.cleared Info Intrusion condition cleared at {thingName} by {personName} — — personId
pq.event.intrusion.contact Warn — — — —
pq.event.intrusion.contact.closed Info Contact closed at — — —
pq.event.intrusion.contact.open Warn Contact open at — — —
pq.event.intrusion.disarmed Info System disarmed by — — personId, refExternalPerson
pq.event.intrusion.disarmed.alarm Warn System disarmed during active alarm by — — personId, refExternalPerson, personId, refExternalPerson
pq.event.intrusion.disarmed.alarm.remote Warn System disarmed remotely during active alarm by — — personId, refExternalPerson, personId, refExternalPerson
pq.event.intrusion.disarmed.partial Info System partially disarmed at {thingName} by {personName} — — personId, refExternalPerson, personId
pq.event.intrusion.disarmed.remote Info System disarmed remotely by — — personId, refExternalPerson, personId, refExternalPerson
pq.event.intrusion.disarmed.schedule Info System disarmed by schedule ({scheduleName}) — — personId, refExternalPerson, scheduleName
pq.event.intrusion.disarmed.schedule.early Warn System disarmed earlier than schedule at {thingName} by {personName} — — personId, refExternalPerson, scheduleName, personId, scheduleName
pq.event.intrusion.disarmed.schedule.late Warn System disarmed later than schedule at {thingName} by {personName} — — personId, refExternalPerson, scheduleName, personId, scheduleName
pq.event.intrusion.disarming Warn — Disarming attempt events (system not disarmed) — —
pq.event.intrusion.disarming.denied Warn System disarming denied to {personName} at {thingName} — — personId
pq.event.intrusion.disarming.failed Warn System disarming failed at {thingName} by {personName} — — personId
pq.event.intrusion.disarming.failed.open Warn Open-disarming failed at — — personId
pq.event.intrusion.duress Critical Duress alarm from {personName} at {thingName} — — personId
pq.event.intrusion.duress.cleared Info Duress alarm cleared at — — personId
pq.event.intrusion.entry Warn — Intrusion entry events — —
pq.event.intrusion.entry.forced Critical Forced entry detected at — — —
pq.event.intrusion.entry.timeout Warn Entry/exit delay timeout at — — —
pq.event.intrusion.motion Warn — — — —
pq.event.intrusion.motion.cleared Info Motion cleared at — — —
pq.event.intrusion.motion.detected Info Motion detected at — — —
pq.event.intrusion.prealarm Warn Pre-alarm condition at — — —
pq.event.intrusion.schedule Warn — Schedule compliance events — —
pq.event.intrusion.schedule.closed_early Warn Premises closed earlier than schedule at — — —
pq.event.intrusion.schedule.closed_late Warn Premises closed later than schedule at — — —
pq.event.intrusion.schedule.opened_early Warn Premises opened earlier than schedule at — — —
pq.event.intrusion.schedule.opened_late Warn Premises opened later than schedule at — — —
pq.event.intrusion.tamper Critical Tamper alarm at {thingName} ({tamperType}) — — tamperType
pq.event.intrusion.tamper.cleared Info Tamper alarm cleared at — — tamperType
pq.event.intrusion.testing Warn — Walk test mode lifecycle — —
pq.event.intrusion.testing.completed Info Test mode completed at {thingName} by {personName} — — personId
pq.event.intrusion.testing.point Warn — Per-point walk test results — —
pq.event.intrusion.testing.point.failed Warn Test failed for point — — —
pq.event.intrusion.testing.point.not_tested Warn Point {thingName} was not tested — — —
pq.event.intrusion.testing.point.passed Info Test passed for point — — —
pq.event.intrusion.testing.started Info Test mode started at {thingName} by {personName} — — personId
pq.event.intrusion.zone Warn — Zone-level intrusion state events — —
pq.event.intrusion.zone.shutdown Warn Zone shutdown at — — —

pq.event.notification

Notification and announcement events. Every event carries thingId.

Event id Severity Message Description Required Optional
pq.event.notification.sent Info Notification sent from {thingName} to {recipientCount} recipients - {message} — — recipientCount, message
pq.event.notification.test Info Test notification from {thingName} by {personName} — — personId

pq.event.safety

Life safety and emergency events. Every event carries thingId.

Event id Severity Message Description Required Optional
pq.event.safety.emergency Critical — — — —
pq.event.safety.emergency.evacuation Critical Emergency evacuation triggered at {thingName} by {personName} — — personId
pq.event.safety.emergency.evacuation.cleared Info Emergency evacuation cleared at {thingName} by {personName} — — personId, personId
pq.event.safety.emergency.evacuation.cleared.remote Info Emergency evacuation cleared remotely at {thingName} by {personName} — — personId, personId, personId
pq.event.safety.emergency.evacuation.remote Critical Emergency evacuation triggered remotely at {thingName} by {personName} — — personId, personId
pq.event.safety.emergency.lockdown Critical Emergency lockdown activated at {thingName} by {personName} — — personId
pq.event.safety.emergency.lockdown.cleared Info Emergency lockdown cleared at {thingName} by {personName} — — personId, personId
pq.event.safety.emergency.lockdown.cleared.remote Info Emergency lockdown cleared remotely at {thingName} by {personName} — — personId, personId, personId
pq.event.safety.emergency.lockdown.remote Critical Emergency lockdown activated remotely at {thingName} by {personName} — — personId, personId
pq.event.safety.medical Critical Medical emergency at {thingName} involving {personName} — — personId
pq.event.safety.panic Critical Panic button activated at {thingName} by {personName} Panic button activation events — personId
pq.event.safety.panic.cleared Info Panic alarm cleared at — — personId
pq.event.safety.panic.fire Critical Fire panic button activated at {thingName} by {personName} — — personId, personId
pq.event.safety.panic.medical Critical Medical panic button activated at {thingName} by {personName} — — personId, personId
pq.event.safety.panic.police Critical Police/holdup panic button activated at {thingName} by {personName} — — personId, personId

pq.event.security

Security and compliance events. Every event carries thingId.

Event id Severity Message Description Required Optional
pq.event.security.admin Warn — Administrative access events — —
pq.event.security.admin.entered Warn Admin mode entered at {thingName} by {personName} — — personId
pq.event.security.admin.exited Info Admin mode exited at {thingName} by {personName} — — personId
pq.event.security.audit Warn — Audit log lifecycle events — —
pq.event.security.audit.capacity Warn — Audit log capacity thresholds — —
pq.event.security.audit.capacity.half Warn Audit log at 50% capacity on — — —
pq.event.security.audit.capacity.near_full Warn Audit log almost full on — — —
pq.event.security.audit.cleared Critical Audit log cleared at {thingName} by {personName} ({clearedCount} entries) — — personId, clearedCount
pq.event.security.audit.overwritten Critical Audit log entries overwritten on {thingName} due to full capacity — — —
pq.event.security.audit.reset Critical Audit log reset on {thingName} by {personName} — — personId
pq.event.security.audit.test_report Info Periodic test report generated by — — —
pq.event.security.code Warn — User code (PIN) management events for security audit trail — —
pq.event.security.code.created Info User code created at {thingName} for {personName} (slot {codeSlot}) by {operatorName} — — personId, codeSlot, operatorId
pq.event.security.code.deleted Warn User code deleted at {thingName} for {personName} (slot {codeSlot}) by {operatorName} — — personId, codeSlot, operatorId
pq.event.security.code.invalid Warn — Invalid code entry events — —
pq.event.security.code.invalid.repeated Warn Repeated invalid code entries detected at — — —
pq.event.security.code.locked Warn User code locked at {thingName} for {personName} after {failedAttempts} failed attempts for {lockoutDuration} — failedAttempts personId, lockoutDuration
pq.event.security.code.modified Warn User code modified at {thingName} for {personName} (slot {codeSlot}) by {operatorName} — — personId, codeSlot, operatorId
pq.event.security.code.unlocked Info User code unlocked at {thingName} for {personName} by {operatorName} — — personId, operatorId
pq.event.security.keypad Warn — Keypad user command events — —
pq.event.security.keypad.command Info User command '{commandCode}' entered at {thingName} by {personName} — commandCode personId
pq.event.security.monitoring Warn — Security monitoring session lifecycle — —
pq.event.security.monitoring.ended Info Monitoring ended on — — —
pq.event.security.monitoring.started Info Monitoring started on — — —
pq.event.security.remote_access Warn — Remote access authorization and session events — —
pq.event.security.remote_access.allowed Warn Remote access allowed on — — —
pq.event.security.remote_access.denied Warn Remote access denied on — — —
pq.event.security.remote_access.ended Info Remote access session ended on — — —
pq.event.security.verification Warn — Post-alarm verification workflow events — —
pq.event.security.verification.listen_in Warn Listen-in verification active on — — —

pq.event.supervision

Sensor and device supervision faults / troubles (raised by detector Fault actions). Every event carries thingId.

Event id Severity Message Description Required Optional
pq.event.supervision.fault Warn Supervision fault at — — —

pq.event.system

System-level operational events. Every event carries thingId.

Event id Severity Message Description Required Optional
pq.event.system.adapter Info — Adapter lifecycle events — —
pq.event.system.adapter.start_failed Error Adapter {thingName} failed to start — — —
pq.event.system.adapter.started Info Adapter {thingName} started — — —
pq.event.system.adapter.stopped Info Adapter {thingName} stopped — — —
pq.event.system.configuration Info — — — —
pq.event.system.configuration.changed Info Configuration changed at {thingName} by {personName} - {changeDescription} — — personId, changeDescription
pq.event.system.configuration.invalid Error Invalid property '{propertyName}' on {thingName}: {errorMessage} — errorMessage propertyName
pq.event.system.configuration.restored Warn Configuration restored from backup at {thingName} by {personName} — — personId
pq.event.system.device Info — Device operational state events — —
pq.event.system.device.disabled Warn Device {thingName} disabled by {personName} — — personId
pq.event.system.device.enabled Info Device {thingName} enabled by {personName} — — personId
pq.event.system.device.module Info — Device module health and presence — —
pq.event.system.device.module.missing Info — — — —
pq.event.system.device.module.missing.pcs Error PCS module missing on — — —
pq.event.system.device.module.missing.voice Error Voice module missing on — — —
pq.event.system.firmware Info — — — —
pq.event.system.firmware.update Info — Firmware update lifecycle — —
pq.event.system.firmware.update.completed Info Firmware update completed at {thingName} version {version} — — version
pq.event.system.firmware.update.failed Error Firmware update failed at — — —
pq.event.system.firmware.update.started Warn Firmware update started at {thingName} version {version} — — version
pq.event.system.reset Info — System reset events (data destruction) — —
pq.event.system.reset.database Critical Database reset at {thingName} by {personName} — — personId
pq.event.system.reset.factory Critical Factory reset performed at {thingName} by {personName} — — personId
pq.event.system.reset.settings Critical Settings reset at {thingName} by {personName} — — personId
pq.event.system.restart Info — — — —
pq.event.system.restart.completed Info System restart completed at {thingName} (uptime: {uptimeDuration}) — — uptimeDuration
pq.event.system.restart.initiated Warn System restart initiated at {thingName} by {personName} — — personId
pq.event.system.restart.watchdog Critical System restarted by watchdog on — — —
pq.event.system.time Info — System time and clock events — —
pq.event.system.time.changed Info System time changed on {thingName} by {personName} — — personId

pq.event.technical

Technical faults and maintenance events. Every event carries thingId.

Event id Severity Message Description Required Optional
pq.event.technical.battery Warn — — — —
pq.event.technical.battery.critical Critical Critical battery level at {thingName} ({batteryPercentage}%) (est. {estimatedRemaining} remaining) — — batteryPercentage, estimatedRemaining
pq.event.technical.battery.fault Warn Battery fault at {thingName} (voltage: {batteryVoltage}V) ({batteryPercentage}%) — — batteryVoltage, batteryPercentage
pq.event.technical.battery.low Warn Low battery at {thingName} ({batteryPercentage}%) — — batteryPercentage
pq.event.technical.battery.normal Info Battery condition normal at — — —
pq.event.technical.battery.replaced Info Battery replaced at {thingName} by {personName} — — personId
pq.event.technical.calibration Warn — — — —
pq.event.technical.calibration.completed Info Calibration completed at — — —
pq.event.technical.calibration.failed Error Calibration failed at — — —
pq.event.technical.calibration.started Info Calibration started at — — —
pq.event.technical.command Warn — — — —
pq.event.technical.command.failed Warn Command {commandName} failed on {thingName}: {reason} — commandName, reason correlationId
pq.event.technical.command.succeeded Info Command {commandName} succeeded on {thingName} — commandName correlationId
pq.event.technical.communication Warn — — — —
pq.event.technical.communication.callback_requested Warn Callback requested by — — —
pq.event.technical.communication.callup Warn — Call setup control events — —
pq.event.technical.communication.callup.force_answer Warn Force answer triggered on — — —
pq.event.technical.communication.callup.force_hangup Warn Force hangup triggered on — — —
pq.event.technical.communication.callup.user_initiated Info User initiated callup on — — —
pq.event.technical.communication.degraded Warn Communication degraded with {thingName} (signal: {signalStrength}%) (loss: {packetLoss}%) — — signalStrength, packetLoss
pq.event.technical.communication.jamming Critical RF jamming detected on — — —
pq.event.technical.communication.jamming.cleared Info RF jamming cleared on — — —
pq.event.technical.communication.jamming.gsm Critical GSM RF jamming detected on — — —
pq.event.technical.communication.lost Error Communication lost with {thingName} (last seen: {lastSeenTimestamp}) — — lastSeenTimestamp
pq.event.technical.communication.overload Error Communication overload on — — —
pq.event.technical.communication.overload.cleared Info Communication overload cleared on — — —
pq.event.technical.communication.restored Info Communication restored with {thingName} (outage: {outageDuration}) — — outageDuration
pq.event.technical.communication.telephone.failed Error Telephone reporting communication failed on — — —
pq.event.technical.communication.voice_reporting Warn — — — —
pq.event.technical.communication.voice_reporting.failed Error Voice reporting failed on — — —
pq.event.technical.fault Warn — — — —
pq.event.technical.fault.cleared Info Fault cleared at {thingName} ({faultType}) — — faultType
pq.event.technical.fault.hardware Error Hardware fault at {thingName}: {faultDescription} (code: {faultCode}) — faultDescription faultCode
pq.event.technical.fault.sensor Warn Sensor fault at {thingName} ({sensorType}) — — sensorType
pq.event.technical.fault.software Error Software fault at {thingName}: {faultDescription} (error: {errorCode}) — faultDescription errorCode
pq.event.technical.maintenance Warn — — — —
pq.event.technical.maintenance.performed Info Maintenance performed at {thingName} by {personName} ({maintenanceType}) — — personId, maintenanceType
pq.event.technical.maintenance.required Warn Maintenance required at {thingName} ({maintenanceType}) due {dueDate} — — maintenanceType, dueDate
pq.event.technical.peripheral Warn — — — —
pq.event.technical.peripheral.printer Warn — — — —
pq.event.technical.peripheral.printer.failed Warn Printer output failed on — — —
pq.event.technical.peripheral.printer.restored Info Printer output restored on — — —

pq.event.utility

Building utility events. Every event carries thingId.

Event id Severity Message Description Required Optional
pq.event.utility.elevator Info — — — —
pq.event.utility.elevator.emergency Critical Elevator emergency at — — —
pq.event.utility.elevator.stuck Critical Elevator stuck at {thingName} floor {floorNumber} ({occupantCount} occupants) — — floorNumber, occupantCount
pq.event.utility.gas Info — — — —
pq.event.utility.gas.leak Critical Gas leak detected at {thingName} ({gasConcentration} ppm) ({gasType}) — — gasConcentration, gasType
pq.event.utility.water Info — — — —
pq.event.utility.water.flow Info Water flow detected at {thingName} ({flowRate} L/min) — — flowRate
pq.event.utility.water.leak Critical Water leak detected at {thingName} (flow: {flowRate} L/min) — — flowRate

pq.event.video

Video surveillance and analytics events. Every event carries thingId.

Event id Severity Message Description Required Optional
pq.event.video.analysis Info — — — —
pq.event.video.analysis.started Info Video analysis started at — — —
pq.event.video.analysis.stopped Info Video analysis stopped at — — —
pq.event.video.analytics Info — — — —
pq.event.video.analytics.intrusion Warn Intrusion detected by {thingName} in zone {zoneName} — zoneName —
pq.event.video.analytics.loitering Warn Loitering detected by {thingName} for {duration}s — — duration
pq.event.video.analytics.object_detected Info Object detected by {thingName}: {objectType} {plate} ({country}) (confidence: {confidence}%) — objectType confidence, boundingBox, plate, country, vehicleMake, vehicleColor, image
pq.event.video.blind Warn Camera {thingName} vision blocked — — —
pq.event.video.blind.cleared Info Camera {thingName} vision restored — — —
pq.event.video.motion Info — — — —
pq.event.video.motion.cleared Info Motion cleared at camera — — —
pq.event.video.motion.detected Info Motion detected by camera {thingName} in zone {zoneId} (confidence: {confidence}%) — — zoneId, confidence
pq.event.video.preset Info — — — —
pq.event.video.preset.activated Info Preset {presetNumber} activated on camera {thingName} by {personName} — presetNumber personId
pq.event.video.preset.stored Info Preset {presetNumber} stored on camera {thingName} by {personName} — presetNumber personId
pq.event.video.quality Info — — — —
pq.event.video.quality.degraded Warn Video quality degraded at — — —
pq.event.video.quality.restored Info Video quality restored at — — —
pq.event.video.recording Info — — — —
pq.event.video.recording.failed Error Recording failed at — — —
pq.event.video.recording.started Info Recording started at {thingName} (ID: {recordingId}) triggered by {trigger} — — recordingId, trigger
pq.event.video.recording.stopped Info Recording stopped at {thingName} (ID: {recordingId}) duration {duration}s — — recordingId, duration
pq.event.video.stream.ready Info Stream ready at {thingName} for {personName} (playback) — — personId, stream_alias, transaction_id, is_playback, playback_from, playback_scales
pq.event.video.streaming Info — — — —
pq.event.video.streaming.started Info Streaming started at — — —
pq.event.video.streaming.stopped Info Streaming stopped at — — —