...
Rw ui tabs macro | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| auth.jumpcloud.directory.events |
|
Field in union table | Field in source table | Field transformation | Data type | Extra fields | ||
---|---|---|---|---|---|---|
eventdate | eventdate |
|
| |||
source | - |
|
| |||
hostname | hostname |
|
| |||
initiated_by__id | initiated_by__id |
|
| |||
initiated_by__type | initiated_by__type |
|
| |||
initiated_by__email | initiated_by__email |
|
| |||
initiated_by__username | initiated_by__username |
|
| |||
geoip__country_code | geoip__country_code |
|
| |||
geoip__timezone | geoip__timezone |
|
| |||
geoip__latitude | geoip__latitude |
|
| |||
geoip__continent_code | geoip__continent_code |
|
| |||
geoip__region_name | geoip__region_name |
|
| |||
geoip__region_code | geoip__region_code |
|
| |||
geoip__longitude | geoip__longitude |
|
| |||
resource__id | resource__id |
|
| |||
resource__type | resource__type |
|
| |||
resource__username | resource__username |
|
| |||
changes | changes |
|
| |||
auth_method | auth_method |
|
| |||
event_type | event_type |
|
| |||
provider | provider |
|
| |||
service | service |
|
| |||
organization | organization |
|
| |||
at_version | at_version |
|
| |||
client_ipv4 | client_ipv4 |
|
| |||
client_ipv6 | client_ipv6 |
|
| |||
id | id |
|
| |||
user_agent__patch | user_agent__patch |
|
| |||
user_agent__minor | user_agent__minor |
|
| |||
user_agent__os | user_agent__os |
|
| |||
user_agent__major | user_agent__major |
|
| |||
user_agent__build | user_agent__build |
|
| |||
user_agent__name | user_agent__name |
|
| |||
user_agent__os_name | user_agent__os_name |
|
| |||
user_agent__device | user_agent__device |
|
| |||
timestamp | timestamp |
|
| |||
err | - |
|
| |||
error_message | - |
|
| |||
start_tls | - |
|
| |||
tls_established | - |
|
| |||
dn | - |
|
| |||
mech | - |
|
| |||
connection_id | - |
|
| |||
port | - |
|
| |||
success | success |
|
| |||
error_code | - |
|
| |||
operation_number | - |
|
| |||
username | - |
|
| |||
mdm_type | - |
|
| |||
request_type | - |
|
| |||
mdm_device_id | - |
|
| |||
mdm_device_manager_id | - |
|
| |||
command__request_type | - |
|
| |||
command__payload | - |
|
| |||
command_uuid | - |
|
| |||
error_chain | - |
|
| |||
status | - |
|
| |||
message | - |
|
| |||
system__hostname | - |
|
| |||
system__displayName | - |
|
| |||
system__id | - |
|
| |||
process_name | - |
|
| |||
system_timestamp | - |
|
| |||
windows_meta__user_tasks | - |
|
| |||
windows_meta__user_process | - |
|
| |||
windows_meta__elevated | - |
|
| |||
windows_meta__user_services | - |
|
| |||
windows_meta__logon_type | - |
|
| |||
sso_token_success | - |
|
| |||
auth_context__policies_applied | - |
|
| |||
mfa | mfa |
|
| |||
application__name | - |
|
| |||
application__id | - |
|
| |||
application__sso_url | - |
|
| |||
idp_initiated | - |
|
| |||
at_devo_pulling_id | - |
|
| |||
hostchain | hostchain |
|
| ✓ | ||
tag | tag |
|
| ✓ | ||
rawMessage | rawMessage |
|
| ✓ |
Anchor |
---|
|
Field in union table | Field in source table | Field transformation | Data type | Extra fields | ||
---|---|---|---|---|---|---|
eventdate | eventdate |
|
| |||
source | - |
|
| |||
hostname | hostname |
|
| |||
initiated_by__id | - |
|
| |||
initiated_by__type | initiated_by__type |
|
| |||
initiated_by__email | initiated_by__email |
|
| |||
initiated_by__username | initiated_by__username |
|
| |||
geoip__country_code | - |
|
| |||
geoip__timezone | - |
|
| |||
geoip__latitude | - |
|
| |||
geoip__continent_code | - |
|
| |||
geoip__region_name | - |
|
| |||
geoip__region_code | - |
|
| |||
geoip__longitude | - |
|
| |||
resource__id | - |
|
| |||
resource__type | - |
|
| |||
resource__username | - |
|
| |||
changes | - |
|
| |||
auth_method | auth_method |
|
| |||
event_type | event_type |
|
| |||
provider | - |
|
| |||
service | service |
|
| |||
organization | organization |
|
| |||
at_version | at_version |
|
| |||
client_ipv4 | client_ipv4 |
|
| |||
client_ipv6 | client_ipv6 |
|
| |||
id | id |
|
| |||
user_agent__patch | - |
|
| |||
user_agent__minor | - |
|
| |||
user_agent__os | - |
|
| |||
user_agent__major | - |
|
| |||
user_agent__build | - |
|
| |||
user_agent__name | - |
|
| |||
user_agent__os_name | - |
|
| |||
user_agent__device | - |
|
| |||
timestamp | timestamp |
|
| |||
err | err |
|
| |||
error_message | error_message |
|
| |||
start_tls | start_tls |
|
| |||
tls_established | tls_established |
|
| |||
dn | dn |
|
| |||
mech | mech |
|
| |||
connection_id | connection_id |
|
| |||
port | port |
|
| |||
success | success |
|
| |||
error_code | error_code |
|
| |||
operation_number | operation_number |
|
| |||
username | username |
|
| |||
mdm_type | - |
|
| |||
request_type | - |
|
| |||
mdm_device_id | - |
|
| |||
mdm_device_manager_id | - |
|
| |||
command__request_type | - |
|
| |||
command__payload | - |
|
| |||
command_uuid | - |
|
| |||
error_chain | - |
|
| |||
status | - |
|
| |||
message | - |
|
| |||
system__hostname | - |
|
| |||
system__displayName | - |
|
| |||
system__id | - |
|
| |||
process_name | - |
|
| |||
system_timestamp | - |
|
| |||
windows_meta__user_tasks | - |
|
| |||
windows_meta__user_process | - |
|
| |||
windows_meta__elevated | - |
|
| |||
windows_meta__user_services | - |
|
| |||
windows_meta__logon_type | - |
|
| |||
sso_token_success | - |
|
| |||
auth_context__policies_applied | - |
|
| |||
mfa | - |
|
| |||
application__name | - |
|
| |||
application__id | - |
|
| |||
application__sso_url | - |
|
| |||
idp_initiated | - |
|
| |||
at_devo_pulling_id | - |
|
| |||
hostchain | hostchain |
|
| ✓ | ||
tag | tag |
|
| ✓ | ||
rawMessage | rawMessage |
|
| ✓ |
Anchor |
---|
|
Field in union table | Field in source table | Field transformation | Data type | Extra fields | ||
---|---|---|---|---|---|---|
eventdate | eventdate |
|
| |||
source | - |
|
| |||
hostname | hostname |
|
| |||
initiated_by__id | - |
|
| |||
initiated_by__type | - |
|
| |||
initiated_by__email | - |
|
| |||
initiated_by__username | - |
|
| |||
geoip__country_code | - |
|
| |||
geoip__timezone | - |
|
| |||
geoip__latitude | - |
|
| |||
geoip__continent_code | - |
|
| |||
geoip__region_name | - |
|
| |||
geoip__region_code | - |
|
| |||
geoip__longitude | - |
|
| |||
resource__id | - |
|
| |||
resource__type | - |
|
| |||
resource__username | - |
|
| |||
changes | - |
|
| |||
auth_method | - |
|
| |||
event_type | event_type |
|
| |||
provider | - |
|
| |||
service | service |
|
| |||
organization | organization |
|
| |||
at_version | at_version |
|
| |||
client_ipv4 | client_ipv4 |
|
| |||
client_ipv6 | client_ipv6 |
|
| |||
id | id |
|
| |||
user_agent__patch | - |
|
| |||
user_agent__minor | - |
|
| |||
user_agent__os | - |
|
| |||
user_agent__major | - |
|
| |||
user_agent__build | - |
|
| |||
user_agent__name | - |
|
| |||
user_agent__os_name | - |
|
| |||
user_agent__device | - |
|
| |||
timestamp | timestamp |
|
| |||
err | - |
|
| |||
error_message | - |
|
| |||
start_tls | - |
|
| |||
tls_established | - |
|
| |||
dn | - |
|
| |||
mech | - |
|
| |||
connection_id | - |
|
| |||
port | - |
|
| |||
success | - |
|
| |||
error_code | - |
|
| |||
operation_number | - |
|
| |||
username | - |
|
| |||
mdm_type | mdm_type |
|
| |||
request_type | request_type |
|
| |||
mdm_device_id | mdm_device_id |
|
| |||
mdm_device_manager_id | mdm_device_manager_id |
|
| |||
command__request_type | command__request_type |
|
| |||
command__payload | command__payload |
|
| |||
command_uuid | command_uuid |
|
| |||
error_chain | error_chain |
|
| |||
status | status |
|
| |||
message | - |
|
| |||
system__hostname | - |
|
| |||
system__displayName | - |
|
| |||
system__id | - |
|
| |||
process_name | - |
|
| |||
system_timestamp | - |
|
| |||
windows_meta__user_tasks | - |
|
| |||
windows_meta__user_process | - |
|
| |||
windows_meta__elevated | - |
|
| |||
windows_meta__user_services | - |
|
| |||
windows_meta__logon_type | - |
|
| |||
sso_token_success | - |
|
| |||
auth_context__policies_applied | - |
|
| |||
mfa | - |
|
| |||
application__name | - |
|
| |||
application__id | - |
|
| |||
application__sso_url | - |
|
| |||
idp_initiated | - |
|
| |||
at_devo_pulling_id | - |
|
| |||
hostchain | hostchain |
|
| ✓ | ||
tag | tag |
|
| ✓ | ||
rawMessage | rawMessage |
|
| ✓ |
Anchor |
---|
|
Field in union table | Field in source table | Field transformation | Data type | Extra fields | ||
---|---|---|---|---|---|---|
eventdate | eventdate |
|
| |||
source | - |
|
| |||
hostname | hostname |
|
| |||
initiated_by__id | initiated_by__id |
|
| |||
initiated_by__type | initiated_by__type |
|
| |||
initiated_by__email | initiated_by__email |
|
| |||
initiated_by__username | - |
|
| |||
geoip__country_code | geoip__country_code |
|
| |||
geoip__timezone | geoip__timezone |
|
| |||
geoip__latitude | geoip__latitude |
|
| |||
geoip__continent_code | geoip__continent_code |
|
| |||
geoip__region_name | geoip__region_name |
|
| |||
geoip__region_code | geoip__region_code |
|
| |||
geoip__longitude | geoip__longitude |
|
| |||
resource__id | - |
|
| |||
resource__type | - |
|
| |||
resource__username | - |
|
| |||
changes | - |
|
| |||
auth_method | - |
|
| |||
event_type | - |
|
| |||
provider | - |
|
| |||
service | service |
|
| |||
organization | organization |
|
| |||
at_version | - |
|
| |||
client_ipv4 | client_ipv4 |
|
| |||
client_ipv6 | client_ipv6 |
|
| |||
id | id |
|
| |||
user_agent__patch | - |
|
| |||
user_agent__minor | - |
|
| |||
user_agent__os | - |
|
| |||
user_agent__major | - |
|
| |||
user_agent__build | - |
|
| |||
user_agent__name | - |
|
| |||
user_agent__os_name | - |
|
| |||
user_agent__device | - |
|
| |||
timestamp | timestamp |
|
| |||
err | - |
|
| |||
error_message | error_message |
|
| |||
start_tls | - |
|
| |||
tls_established | - |
|
| |||
dn | - |
|
| |||
mech | - |
|
| |||
connection_id | - |
|
| |||
port | - |
|
| |||
success | success |
|
| |||
error_code | - |
|
| |||
operation_number | - |
|
| |||
username | username |
|
| |||
mdm_type | - |
|
| |||
request_type | - |
|
| |||
mdm_device_id | - |
|
| |||
mdm_device_manager_id | - |
|
| |||
command__request_type | - |
|
| |||
command__payload | - |
|
| |||
command_uuid | - |
|
| |||
error_chain | - |
|
| |||
status | - |
|
| |||
message | - |
|
| |||
system__hostname | - |
|
| |||
system__displayName | - |
|
| |||
system__id | - |
|
| |||
process_name | - |
|
| |||
system_timestamp | - |
|
| |||
windows_meta__user_tasks | - |
|
| |||
windows_meta__user_process | - |
|
| |||
windows_meta__elevated | - |
|
| |||
windows_meta__user_services | - |
|
| |||
windows_meta__logon_type | - |
|
| |||
sso_token_success | - |
|
| |||
auth_context__policies_applied | - |
|
| |||
mfa | mfa |
|
| |||
application__name | - |
|
| |||
application__id | - |
|
| |||
application__sso_url | - |
|
| |||
idp_initiated | - |
|
| |||
at_devo_pulling_id | - |
|
| |||
hostchain | hostchain |
|
| ✓ | ||
tag | tag |
|
| ✓ | ||
rawMessage | rawMessage |
|
| ✓ |
Rw tab | ||
---|---|---|
|
Anchor |
---|
|
Field in union table | Field in source table | Field transformation | Data type | Extra field | ||
---|---|---|---|---|---|---|
eventdate | eventdate |
|
| |||
source | - |
|
| |||
hostname | hostname |
|
| |||
initiated_by__id | initiated_by__id |
|
| |||
initiated_by__type | initiated_by__type |
|
| |||
initiated_by__email | - |
|
| |||
initiated_by__username | - |
|
| |||
geoip__country_code | - |
|
| |||
geoip__timezone | - |
|
| |||
geoip__latitude | - |
|
| |||
geoip__continent_code | - |
|
| |||
geoip__region_name | - |
|
| |||
geoip__region_code | - |
|
| |||
geoip__longitude | - |
|
| |||
resource__id | resource__id |
|
| |||
resource__type | resource__type |
|
| |||
resource__username | - |
|
| |||
changes | changes |
|
| |||
auth_method | - |
|
| |||
event_type | event_type |
|
| |||
provider | provider |
|
| |||
service | service |
|
| |||
organization | organization |
|
| |||
at_version | at_version |
|
| |||
client_ipv4 | client_ipv4 |
|
| |||
client_ipv6 | client_ipv6 |
|
| |||
id | id |
|
| |||
user_agent__patch | - |
|
| |||
user_agent__minor | - |
|
| |||
user_agent__os | - |
|
| |||
user_agent__major | - |
|
| |||
user_agent__build | - |
|
| |||
user_agent__name | - |
|
| |||
user_agent__os_name | - |
|
| |||
user_agent__device | - |
|
| |||
timestamp | timestamp |
|
| |||
err | - |
|
| |||
error_message | - |
|
| |||
start_tls | - |
|
| |||
tls_established | - |
|
| |||
dn | - |
|
| |||
mech | - |
|
| |||
connection_id | - |
|
| |||
port | - |
|
| |||
success | - |
|
| |||
error_code | - |
|
| |||
operation_number | - |
|
| |||
username | - |
|
| |||
mdm_type | - |
|
| |||
request_type | - |
|
| |||
mdm_device_id | - |
|
| |||
mdm_device_manager_id | - |
|
| |||
command__request_type | - |
|
| |||
command__payload | - |
|
| |||
command_uuid | - |
|
| |||
error_chain | - |
|
| |||
status | - |
|
| |||
message | - |
|
| |||
system__hostname | system__hostname |
|
| |||
system__displayName | - |
|
| |||
system__id | system__id |
|
| |||
process_name | - |
|
| |||
system_timestamp | - |
|
| |||
windows_meta__user_tasks | - |
|
| |||
windows_meta__user_process | - |
|
| |||
windows_meta__elevated | - |
|
| |||
windows_meta__user_services | - |
|
| |||
windows_meta__logon_type | - |
|
| |||
sso_token_success | - |
|
| |||
auth_context__policies_applied | - |
|
| |||
mfa | - |
|
| |||
application__name | application__name |
|
| |||
application__id | - |
|
| |||
application__sso_url | - |
|
| |||
idp_initiated | - |
|
| |||
at_devo_pulling_id | at_devo_pulling_id |
|
| |||
hostchain | hostchain |
|
| ✓ | ||
tag | tag |
|
| ✓ | ||
rawMessage | rawMessage |
|
| ✓ |
Anchor |
---|
|
Field in union table | Field in source table | Field transformation | Data type | Extra fields | ||
---|---|---|---|---|---|---|
eventdate | eventdate |
|
| |||
source | - |
|
| |||
hostname | hostname |
|
| |||
initiated_by__id | initiated_by__id |
|
| |||
initiated_by__type | initiated_by__type |
|
| |||
initiated_by__email | - |
|
| |||
initiated_by__username | initiated_by__username |
|
| |||
geoip__country_code | geoip__country_code |
|
| |||
geoip__timezone | geoip__timezone |
|
| |||
geoip__latitude | geoip__latitude |
|
| |||
geoip__continent_code | geoip__continent_code |
|
| |||
geoip__region_name | geoip__region_name |
|
| |||
geoip__region_code | geoip__region_code |
|
| |||
geoip__longitude | geoip__longitude |
|
| |||
resource__id | - |
|
| |||
resource__type | - |
|
| |||
resource__username | - |
|
| |||
changes | - |
|
| |||
auth_method | - |
|
| |||
event_type | event_type |
|
| |||
provider | provider |
|
| |||
service | service |
|
| |||
organization | organization |
|
| |||
at_version | at_version |
|
| |||
client_ipv4 | client_ipv4 |
|
| |||
client_ipv6 | client_ipv6 |
|
| |||
id | id |
|
| |||
user_agent__patch | user_agent__patch |
|
| |||
user_agent__minor | user_agent__minor |
|
| |||
user_agent__os | user_agent__os |
|
| |||
user_agent__major | user_agent__major |
|
| |||
user_agent__build | user_agent__build |
|
| |||
user_agent__name | user_agent__name |
|
| |||
user_agent__os_name | user_agent__os_name |
|
| |||
user_agent__device | user_agent__device |
|
| |||
timestamp | timestamp |
|
| |||
err | - |
|
| |||
error_message | error_message |
|
| |||
start_tls | - |
|
| |||
tls_established | - |
|
| |||
dn | - |
|
| |||
mech | - |
|
| |||
connection_id | - |
|
| |||
port | - |
|
| |||
success | - |
|
| |||
error_code | - |
|
| |||
operation_number | - |
|
| |||
username | - |
|
| |||
mdm_type | - |
|
| |||
request_type | - |
|
| |||
mdm_device_id | - |
|
| |||
mdm_device_manager_id | - |
|
| |||
command__request_type | - |
|
| |||
command__payload | - |
|
| |||
command_uuid | - |
|
| |||
error_chain | - |
|
| |||
status | - |
|
| |||
message | - |
|
| |||
system__hostname | - |
|
| |||
system__displayName | - |
|
| |||
system__id | - |
|
| |||
process_name | - |
|
| |||
system_timestamp | - |
|
| |||
windows_meta__user_tasks | - |
|
| |||
windows_meta__user_process | - |
|
| |||
windows_meta__elevated | - |
|
| |||
windows_meta__user_services | - |
|
| |||
windows_meta__logon_type | - |
|
| |||
sso_token_success | sso_token_success |
|
| |||
auth_context__policies_applied | auth_context__policies_applied |
|
| |||
mfa | mfa |
|
| |||
application__name | application__name |
|
| |||
application__id | application__id |
|
| |||
application__sso_url | application__sso_url |
|
| |||
idp_initiated | idp_initiated |
|
| |||
at_devo_pulling_id | - |
|
| |||
hostchain | hostchain |
|
| ✓ | ||
tag | tag |
|
| ✓ | ||
rawMessage | rawMessage |
|
| ✓ |
Anchor |
---|
|
Field in union table | Field in source table | Field transformation | Type | Extra fields | ||
---|---|---|---|---|---|---|
eventdate | eventdate |
|
| |||
source | - |
|
| |||
hostname | hostname |
|
| |||
initiated_by__id | initiated_by__id |
|
| |||
initiated_by__type | initiated_by__type |
|
| |||
initiated_by__email | - |
|
| |||
initiated_by__username | initiated_by__username |
|
| |||
geoip__country_code | geoip__country_code |
|
| |||
geoip__timezone | geoip__timezone |
|
| |||
geoip__latitude | geoip__latitude |
|
| |||
geoip__continent_code | geoip__continent_code |
|
| |||
geoip__region_name | geoip__region_name |
|
| |||
geoip__region_code | geoip__region_code |
|
| |||
geoip__longitude | geoip__longitude |
|
| |||
resource__id | resource__id |
|
| |||
resource__type | resource__type |
|
| |||
resource__username | resource__username |
|
| |||
changes | changes |
|
| |||
auth_method | - |
|
| |||
event_type | event_type |
|
| |||
provider | provider |
|
| |||
service | service |
|
| |||
organization | organization |
|
| |||
at_version | at_version |
|
| |||
client_ipv4 | client_ipv4 |
|
| |||
client_ipv6 | client_ipv6 |
|
| |||
id | id |
|
| |||
user_agent__patch | - |
|
| |||
user_agent__minor | - |
|
| |||
user_agent__os | - |
|
| |||
user_agent__major | - |
|
| |||
user_agent__build | - |
|
| |||
user_agent__name | - |
|
| |||
user_agent__os_name | - |
|
| |||
user_agent__device | - |
|
| |||
timestamp | timestamp |
|
| |||
err | - |
|
| |||
error_message | - |
|
| |||
start_tls | - |
|
| |||
tls_established | - |
|
| |||
dn | - |
|
| |||
mech | - |
|
| |||
connection_id | - |
|
| |||
port | - |
|
| |||
success | success |
|
| |||
error_code | - |
|
| |||
operation_number | - |
|
| |||
username | username |
|
| |||
mdm_type | - |
|
| |||
request_type | - |
|
| |||
mdm_device_id | - |
|
| |||
mdm_device_manager_id | - |
|
| |||
command__request_type | - |
|
| |||
command__payload | - |
|
| |||
command_uuid | - |
|
| |||
error_chain | - |
|
| |||
status | - |
|
| |||
message | message |
|
| |||
system__hostname | system__hostname |
|
| |||
system__displayName | system__displayName |
|
| |||
system__id | system__id |
|
| |||
process_name | process_name |
|
| |||
system_timestamp | system_timestamp |
|
| |||
windows_meta__user_tasks | windows_meta__user_tasks |
|
| |||
windows_meta__user_process | windows_meta__user_process |
|
| |||
windows_meta__elevated | windows_meta__elevated |
|
| |||
windows_meta__user_services | windows_meta__user_services |
|
| |||
windows_meta__logon_type | windows_meta__logon_type |
|
| |||
sso_token_success | - |
|
| |||
auth_context__policies_applied | - |
|
| |||
mfa | - |
|
| |||
application__name | - |
|
| |||
application__id | - |
|
| |||
application__sso_url | - |
|
| |||
idp_initiated | - |
|
| |||
at_devo_pulling_id | - |
|
| |||
hostchain | hostchain |
|
| ✓ | ||
tag | tag |
|
| ✓ | ||
rawMessage | rawMessage |
|
| ✓ |
...