Document toolboxDocument toolbox

auth.keycloak

Introduction

The tags beginning with auth.keycloak identify events generated by Keycloak.

Tag structure

The full tag must have 4 levels. The first two are fixed as auth.keycloak. The third level identifies the type of event sent and the fourth level identifies the subtype.

There are the valid tags and corresponding data tables that will receive the parser’s data:

Product / Service

Tags

Data tables

Product / Service

Tags

Data tables

Keycloak

auth.keycloak.user.event

auth.keycloak.user.event

For more information, read more About Devo tags.

Table structure

These are the fields displayed in this table:

auth.keycloak.user.event

Field

Type

Extra fields

Field

Type

Extra fields

auth_method

str

 

auth_session_parent_id

str

 

auth_session_tab_id

str

 

auth_type

str

 

client_id

str

 

code_id

str

 

error

str

 

event_time

timestamp

 

eventdate

timestamp

 

executor_thread

int4

 

hostchain

str

✓

hostname

str

 

ip

ip4

 

log_level

str

 

rawMessage

str

✓

realm_id

str

 

redirect_uri

str

 

tag

str

✓

user_id

str

 

username

str

 

Â