Tags beginning with auth.jumpcloud
identify events generated by JumpCloud.
The full tag must have 4 levels. The first two are fixed as auth.jumpcloud
. The third level identifies the type of events sent, and the fourth level indicates the event subtype.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables | |
---|---|---|---|
JumpCloud |
|
| |
|
| ||
|
| ||
|
| ||
|
| ||
|
| ||
|
| ||
|
|
For more information, read more About Devo tags.
Use the JumpCloud collector. Documentation will be published in due course.
These are the fields displayed in these tables:
|
Field | Type | Extra fields |
---|---|---|
eventdate |
|
|
hostname |
|
|
initiated_by__id |
|
|
initiated_by__type |
|
|
initiated_by__email |
|
|
initiated_by__username |
|
|
initiated_by__source |
|
|
initiated_by__source_metadata__name |
|
|
geoip__country_code |
|
|
geoip__timezone |
|
|
geoip__latitude |
|
|
geoip__continent_code |
|
|
geoip__region_name |
|
|
geoip__region_code |
|
|
geoip__longitude |
|
|
resource__id |
|
|
resource__type |
|
|
resource__username |
|
|
changes |
|
|
auth_method |
|
|
auth_context__system__hostname |
|
|
auth_context__system__os |
|
|
auth_context__system__display_name |
|
|
auth_context__system__id |
|
|
auth_context__system__version |
|
|
success |
|
|
mfa |
|
|
event_type |
|
|
provider |
|
|
service |
|
|
organization |
|
|
at_version |
|
|
client_ip |
|
|
client_ipv6 |
|
|
id |
|
|
user_agent__patch |
|
|
user_agent__minor |
|
|
user_agent__os |
|
|
user_agent__major |
|
|
user_agent__build |
|
|
user_agent__name |
|
|
user_agent__os_name |
|
|
user_agent__device |
|
|
association__type |
|
|
association__id |
|
|
association__email |
|
|
timestamp |
|
|
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
Field | Type | Extra fields |
---|---|---|
eventdate |
|
|
hostname |
|
|
err |
|
|
error_message |
|
|
initiated_by__type |
|
|
initiated_by__username |
|
|
initiated_by__email |
|
|
start_tls |
|
|
tls_established |
|
|
dn |
|
|
mech |
|
|
auth_method |
|
|
event_type |
|
|
connection_id |
|
|
port |
|
|
success |
|
|
service |
|
|
organization |
|
|
at_version |
|
|
error_code |
|
|
id |
|
|
oid |
|
|
base |
|
|
scope |
|
|
filter |
|
|
operation_number |
|
|
username |
|
|
timestamp |
|
|
deref |
|
|
operation_type |
|
|
number_of_results |
|
|
attr |
|
|
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
Field | Type | Extra fields |
---|---|---|
eventdate |
| |
hostname |
| |
mdm_type |
| |
request_type |
| |
mdm_device_id |
| |
mdm_device_manager_id |
| |
command__request_type |
| |
command__payload |
| |
event_type |
| |
command_uuid |
| |
service |
| |
organization |
| |
at_version |
| |
error_chain |
| |
id |
| |
timestamp_str |
| |
timestamp |
| |
status |
| |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
Field | Type | Extra fields |
---|---|---|
eventdate |
|
|
hostname |
|
|
initiated_by__id |
|
|
initiated_by__type |
|
|
initiated_by__email |
|
|
id |
|
|
nas_mfa_state |
|
|
auth_type |
|
|
eap_type |
|
|
client_ip |
|
|
client_ipv6 |
|
|
geoip__country_code |
|
|
geoip__timezone |
|
|
geoip__latitude |
|
|
geoip__continent_code |
|
|
geoip__region_name |
|
|
geoip__region_code |
|
|
geoip__longitude |
|
|
service |
|
|
success |
|
|
username |
|
|
organization |
|
|
error_message |
|
|
mfa |
|
|
outer__eap_type |
|
|
outer__error_message |
|
|
outer__username |
|
|
timestamp |
|
|
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
Field | Type | Extra fields |
---|---|---|
eventdate |
| |
hostname |
| |
initiated_by__id |
| |
initiated_by__type |
| |
system__hostname |
| |
system__id |
| |
event_type |
| |
application__path |
| |
application__uninstall_string |
| |
application__name |
| |
application__publisher |
| |
application__version |
| |
resource__id |
| |
resource__type |
| |
provider |
| |
service |
| |
organization |
| |
changes |
| |
id |
| |
timestamp |
| |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
Field | Type | Extra fields |
---|---|---|
eventdate |
|
|
hostname |
|
|
initiated_by__id |
|
|
initiated_by__type |
|
|
initiated_by__username |
|
|
error_message |
|
|
geoip__country_code |
|
|
geoip__timezone |
|
|
geoip__latitude |
|
|
geoip__continent_code |
|
|
geoip__region_name |
|
|
geoip__longitude |
|
|
geoip__region_code |
|
|
sso_token_success |
|
|
auth_context__policies_applied |
|
|
auth_context__system__hostname |
|
|
auth_context__system__os |
|
|
auth_context__system__display_name |
|
|
auth_context__system__id |
|
|
auth_context__system__version |
|
|
mfa |
|
|
event_type |
|
|
application__name |
|
|
application__id |
|
|
application__sso_url |
|
|
application__display_label |
|
|
provider |
|
|
service |
|
|
organization |
|
|
at_version |
|
|
client_ip |
|
|
client_ipv6 |
|
|
idp_initiated |
|
|
id |
|
|
user_agent__patch |
|
|
user_agent__os |
|
|
user_agent__minor |
|
|
user_agent__major |
|
|
user_agent__build |
|
|
user_agent__name |
|
|
user_agent__os_name |
|
|
user_agent__device |
|
|
timestamp_str |
|
|
timestamp |
|
|
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
Field | Type | Extra fields |
---|---|---|
eventdate |
| |
hostname |
| |
initiated_by__id |
| |
initiated_by__type |
| |
initiated_by__username |
| |
error_message |
| |
geoip__country_code |
| |
geoip__timezone |
| |
geoip__latitude |
| |
geoip__continent_code |
| |
geoip__region_name |
| |
geoip__longitude |
| |
geoip__region_code |
| |
sso_token_success |
| |
auth_context__policies_applied |
| |
mfa |
| |
event_type |
| |
application__name |
| |
application__id |
| |
application__sso_url |
| |
provider |
| |
service |
| |
organization |
| |
at_version |
| |
client_ip |
| |
idp_initiated |
| |
id |
| |
user_agent__patch |
| |
user_agent__os |
| |
user_agent__minor |
| |
user_agent__major |
| |
user_agent__build |
| |
user_agent__name |
| |
user_agent__os_name |
| |
user_agent__device |
| |
timestamp_str |
| |
timestamp |
| |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |