iam.sailpoint
Introduction
The tags beginning with iam.sailpoint identify events generated by Sailpoint IdentityNow.
Valid tags and data tables
The full tag must have four levels. The first two are fixed as iam.sailpoint. The third level identifies the type of events sent, and the fourth level indicated the event subtype.
Technology | Brand | Type | Subtype |
---|---|---|---|
iam | sailpoint |
|
|
These are the valid tags and corresponding data tables that will receive the parsers’ data:
Tag | Data table |
---|---|
iam.sailpoint.identitynow.event | iam.sailpoint.identitynow.event |
iam.sailpoint.identitynow.account_activity | iam.sailpoint.identitynow.account_activity |
Tag structure
[iam.sailpoint.identitynow.event] [iam.sailpoint.identitynow.account_activity]
iam.sailpoint.identitynow.event
Field | Type | Extra Label |
---|---|---|
eventdate |
| - |
hostname |
| - |
completed |
| - |
completion_status |
| - |
type |
| - |
requester_identity_summary |
| - |
target_identity_summary__id |
| - |
target_identity_summary__name |
| - |
errors |
| - |
warnings |
| - |
execution_status |
| - |
client_metadata |
| - |
id |
| - |
name |
| - |
created |
| - |
modified |
| - |
items__id |
| - |
items__name |
| - |
items__requested |
| - |
items__approval_status |
| - |
items__provisioning_status |
| - |
items__requester_comment |
| - |
items__reviewer_identity_summary |
| - |
items__reviewer_comment |
| - |
items__operation |
| - |
items__attribute |
| - |
items__value |
| - |
items__native_identity |
| - |
items__source_id |
| - |
items__account_request_info |
| - |
items__client_metadata |
| - |
items__remove_date |
| - |
items_found |
| - |
items_id |
| - |
at_devo_pulling_id |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
iam.sailpoint.identitynow.account_activity
Field | Type | Extra Label |
---|---|---|
eventdate |
| - |
hostname |
| - |
organization |
| - |
pod |
| - |
created |
| - |
id |
| - |
action |
| - |
type |
| - |
activity_type |
| - |
actor__name |
| - |
destination_ip__name |
| - |
stack |
| - |
tracking_number |
| - |
attributes__source_name |
| - |
attributes__account_uuid |
| - |
attributes__cloud_app_name |
| - |
attributes__errors |
| - |
attributes__app_id |
| - |
attributes__source_id |
| - |
attributes__interface |
| - |
objects |
| - |
operation |
| - |
status |
| - |
technical_name |
| - |
name |
| - |
synced |
| - |
version |
| - |
at_devo_pulling_id |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |