HP Sure Start Automatic Firmware Intrusion Detection and Repair System - White Paper
May 2016
902696-002
HP Sure Start Technical White Paper
© Copyright 2016 HP Development Company, L.P.
3 Architectural Overview & Capabilities 9
Types of HP Sure Start Windows Event Viewer events include:
Table 3 Windows Event Viewer level categories
Event Level
Definition
Info
Events that are expected to occur during the normal course of operation (e.g., updating the BIOS).
Warning
Unexpected events that have occurred but were fully recovered from by Sure Start and there is no user/admin
action required for the platform to be fully operational.
These events are anomalous operation that the user/admin may want to investigate further, especially if there is a
trend of these events across multiple machines.
Error
Events that requires the admin/HP service to take action on the platforms to fully recover
Specific examples of HP Sure Start events include:
Table 4 Windows event ID’s, levels, and messages
EVENT
ID
Windows Event
Level
Message
30
Warning
Sure Start found the primary BIOS in shared flash memory is either corrupted or missing. Possible
causes include but not limited to interrupted BIOS update or recent BIOS attack.
31
Warning
Sure Start found the backup BIOS is either corrupted or missing. Possible causes include but not
limited to interrupted BIOS update.
32
Warning
Sure Start found shared flash memory layout is different from original factory settings.
34
Information
Sure Start has recovered the primary BIOS in shared flash memory
35
Information
Sure Start has updated the backup copy of BIOS
36
Warning
Sure Start found shared flash memory layout is different from original factory settings and has
repaired the shared flash layout.
38
Warning
Sure Start found that the primary BIOS in shared flash memory on resume from Sleep is different
than what system originally booted with
40
Error
Sure Start found that the "BIOS Update Policy" setting was set to Locked but was unable to honor
policy as backup copy of BIOS may be corrupted or missing.
43
Error
Sure Start integrity checking on backup copy of critical factory configured parameters failed and is
no longer being used
44
Error
Sure Start integrity checking on backup copy of critical network parameters data failed and is no
longer being used.
45
Error
Sure Start integrity checking on backup copy of shared memory layout descriptor failed and is no
longer being used.
46
Warning
Sure Start has found that there was an issue with logging, some logging data may have been lost.
47
Error
Sure Start policy settings have been corrupted and reverted to factory defaults.
48
Warning
System was placed in manufacturing programming mode.
49
Informational
System was taken out of manufacturing programming mode.
50
Informational
Sure Start found that backup and primary copy of BIOS do not match.