If you are running cf-monitord, you may also see entropy and anomaly
detection classes:

entropy_cfengine_in_low
entropy_cfengine_out_low
entropy_dns_in_low
entropy_dns_out_low
entropy_ftp_in_low
entropy_ftp_out_low
entropy_icmp_in_low
entropy_icmp_out_low
entropy_irc_in_low
entropy_irc_out_low
entropy_misc_in_low
entropy_misc_out_low
entropy_netbiosdgm_in_low
entropy_netbiosdgm_out_low
entropy_netbiosns_in_low
entropy_netbiosns_out_low
entropy_netbiosssn_in_low
entropy_netbiosssn_out_low
entropy_nfsd_in_low
entropy_nfsd_out_low
entropy_smtp_in_low
entropy_smtp_out_low
entropy_tcpack_in_low
entropy_tcpack_out_low
entropy_tcpfin_in_low
entropy_tcpfin_out_low
entropy_tcpsyn_in_low
entropy_tcpsyn_out_low
entropy_udp_in_low
entropy_udp_out_low
entropy_www_in_low
entropy_www_out_low
entropy_wwws_in_low
entropy_wwws_out_low

A low entropy value means that most of the events came from
only a few (or one) IP addresses. A high entropy value
implies that the events were spread over many IP sources.

Anomaly detection  - example classes:

loadavg_high_ldt - load average higher than usual (based on
                   Leap-Detection Test)

messages_high_dev1 -the current value of the metric is more
                    than 1 standard deviation above the average.

etc.

Reference: http://www.iu.hio.no/cfengine/docs/cfengine-Anomalies.pdf
