Document toolboxDocument toolbox

app.slack

Introduction

The tags beginning with app.slack identify events generated by Slack.

Valid tags and data tables 

The full tag must have 3 levels. The first two are fixed as app.slack. The third level identifies the type of events sent.

These are the valid tags and corresponding data tables that will receive the parsers' data:

Product / Service

Tags

Data tables

Product / Service

Tags

Data tables

Slack

app.slack.audit

app.slack.audit

For more information, read more About Devo tags.

Table structure

These are the fields displayed in this table:

app.slack.audit

Field

Type

Field transformation

Source field name

Extra fields

Field

Type

Field transformation

Source field name

Extra fields

eventdate

timestamp

 

 

 

id

str

 

 

 

date_create

timestamp

 

 

 

action

str

 

 

 

actor_type

str

 

 

 

actor_id

str

 

 

 

actor_name

str

 

 

 

actor_email

str

 

 

 

actor_team

str

 

 

 

entity_type

str

 

 

 

entity_file_id

str

 

 

 

entity_file_name

str

 

 

 

entity_file_filetype

str

 

 

 

entity_file_title

str

 

 

 

entity_user_id

str

 

 

 

entity_user_name

str

 

 

 

entity_user_email

str

 

 

 

entity_user_team

str

 

 

 

entity_channel_is_shared

bool

 

 

 

entity_channel_privacy

str

 

 

 

entity_channel_is_org_shared

bool

 

 

 

entity_channel_teams_shared_with_str

str

join(entity_channel_teams_shared_with, ",")

entity_channel_teams_shared_with

 

entity_channel_id

str

 

 

 

entity_channel_name

str

 

 

 

entity_workspace_domain

str

 

 

 

entity_workspace_id

str

 

 

 

entity_workspace_name

str

 

 

 

entity_app_is_directory_approved

bool

 

 

 

entity_app_is_distributed

bool

 

 

 

entity_app_id

str

 

 

 

entity_app_name

str

 

 

 

entity_app_scopes_str

str

join(entity_app_scopes, ",")

entity_app_scopes

 

context_location_type

str

 

 

 

context_location_id

str

 

 

 

context_location_name

str

 

 

 

context_location_domain

str

 

 

 

context_ua

str

 

 

 

context_ip_address

ip4

 

 

 

message

str

 

 

 

hostchain

str

 

 

✓

tag

str

 

 

✓

rawMessage

str

 

message

✓