How to Configure the SIEM Integration Feature

This page provides an overview of the SIEM integration, the setup flow, and important notes.
Please check the following before proceeding with the setup.

Note: A TrustLogin Pro Plan subscription is required to use this feature. For pricing information, please see here

Table of Contents:

What is SIEM

How to Create a Token

How to Recreate a Token

How to Delete a Token

List of SIEM Reports



What is SIEM

About SIEM Integration

SIEM stands for Security Information and Event Management. It is a solution that automatically detects security incidents by collecting and analyzing logs from the devices and systems that make up your infrastructure.

How to Create a Token

  1. Open "Reports" from the Admin Page and click "SIEM Settings."

    Note: This is grayed out on the Free plan.


  2. Click "Create SIEM Client."
  3. Enter any name and click "Add" to create a token.


  4. Click the copy icon to copy it to the clipboard.
    Note: For instructions on how to use the token, please refer to the manual for the service you are using.

     How to Configure Splunk Enterprise (On-Premises)
     How to Configure Splunk Cloud Platform
     How to Configure Sumo Logic
     How to Configure ALog (On-Premises)



How to Recreate a Token

  1. From the SIEM integration settings screen, click the "Regenerate Authentication Token" icon for the token you want to recreate.
  2. Click "Yes."
    Note: If you have already set the token in your SIEM service, you will need to reconfigure it after regenerating, so please be careful.
  3. The token will be regenerated. Copy it and set it in your SIEM service.

How to Delete a Token

  1. From the SIEM integration settings screen, click the "Delete" icon for the token you want to delete.

  2. Click "Yes."
    Note: Once a token is deleted, it cannot be restored, so please check carefully before proceeding.


List of SIEM Reports

Below is the list of reports displayed in SIEM. (As of September 2024. Subject to change in the future.)

 

Object type Object(en) Object(ja) Event type Event type (en) Event type (ja) Contents example (en) Contents example (ja)
Membership User User adloginsuccess Login success Login success test@example.com logged in successfully with Active Directory Successfully logged in to TrustLogin via Active Directory. test@example.com
passwordloginsuccess Login success Login success test@example.com Login success by password Successfully logged in to TrustLogin using a password. test@example.com
Delete Deleted Delete test@example.com user deleted Deleted user test@example.com.
CSVSUpload CSV Management CSV Batch Processing Upload CSV requested by test@example.com test@example.com uploaded a CSV file.
csvsusercreated CSV Management CSV Batch Processing test@example.com CSV user created Created CSV user. test@example.com
CSVSPrepare CSV Management CSV Batch Processing Prepare CSV requested by test@example.com test@example.com started CSV preparation.
CSVSDownload CSV Management CSV Batch Processing Download CSV requested by test@example.com test@example.com downloaded a CSV file.
csvsuserupdated CSV Management CSV Batch Processing test@example.com CSV user updated Updated CSV user. test@example.com
csvsuserdeleted CSV Management CSV Batch Processing test@example.com CSV user deleted Deleted CSV user. test@example.com
suspended Updated Update test@example.com has been suspended. Set the status of test@example.com to suspended.
csvupload Uploaded CSV data CSV Upload Added multiple users. Registered members in bulk.
Create Created Create test@example.com user created Created user test@example.com.
scimusercreated SCIM User Created SCIM User Created test@example.com SCIM user created Created SCIM user. test@example.com
scimuserupdated SCIM User Updated SCIM User Updated test@example.com SCIM user updated Updated SCIM user. test@example.com
scimuserdeleted SCIM User Deleted SCIM User Deleted test@example.com SCIM user deleted Deleted SCIM user. test@example.com
loginfailure Login failure Login failure test@example.com login failure Failed to log in to TrustLogin. test@example.com
userassigntoconf assigned to config Created/Updated test@example.com assigned to config Added test@example.com to [Box]
successfullyupsertuser successfully upserted Created/Updated test@example.com successfully upserted Created/updated test@example.com in [Box]
fidoprimaryloginsuccess FIDO auth success FIDO Authentication Success test@example.com has successfully logged in with FIDO authenticator mac test@example.com successfully logged in to TrustLogin using the FIDO authenticator [OSName].
Update Updated Update test@example.com user updated Updated user information for test@example.com.
unlockaccess Account unlocked Unlock test@example.com account has been unlocked The account lock was released. test@example.com
requestresetpassword Initiate reset password Password Reset TrustLogin password was reset test@example.com Reset the TrustLogin password. test@example.com
resetpasswordsuccess Reset password complete Password Change TrustLogin Password successfully changed test@example.com Changed the TrustLogin password. test@example.com
activated Updated Update test@example.com has been made active. Set the status of test@example.com to active.
resetpassword Password reset Password Reset test@example.com TrustLogin password has been reset Reset the TrustLogin password. test@example.com
otploginfailure OTP login failure OTP Failure test@example.com OTP login failure test@example.com failed to log in using OTP.
otploginsuccess OTP login success OTP Success test@example.com OTP login success test@example.com successfully logged in using OTP.
idploginsuccess Login success Login success test@example.com logged in successfully with External IDP Successfully logged in to TrustLogin via an external IdP. test@example.com
clientcertauthloginsuccess Client authentication success Client Authentication Success test@example.com Client authentication success test@example.com successfully completed client authentication.
clientcertauthloginfailure Client authentication failure Client Authentication Failure test@example.com Client authentication failure test@example.com failed client authentication.
DeviceLogin Cookie auth success Cookie Authentication Success test@example.com has logged in with device test@example.com1 test@example.com successfully authenticated on device test@example.com1.
DeviceLoginFail Cookie auth failed Cookie Authentication Failure test@example.com has failed cookie auth and has no additional device slots to register. test@example.com failed device authentication. The maximum number of registrations has been exceeded.
kerbloginsuccess Login success Login success test@example.com logged in successfully with Desktop SSO Successfully logged in to TrustLogin via Desktop SSO. test@example.com
push_auth_qr_
code_via_pc
Push auth QR code generated Push Notification Authentication - Registration Preparation test@example.com is generated QR code. A push notification device registration code was generated for test@example.com
push_auth_registered Push auth registered Push Notification Authentication - Device Registration test@example.com registered a new device. A push notification device was registered for test@example.com.
push_auth_new_client Push auth new client Push Notification Authentication - Approval Request test@example.com accessed from new client. An approval request was made from a new browser/app for test@example.com.
push_auth_approved Push auth approved Push Notification Authentication Approved test@example.com is approved Push auth login request. Push notification authentication was approved for test@example.com.
pushauth_login_success Push auth login success Push Notification Authentication Success test@example.com Push auth login success. test@example.com successfully logged in using push notification.
push_auth_denied Push auth denied Push Notification Authentication Denied test@example.com is approved Push auth login request. Push notification authentication was denied for test@example.com.
devicecertauth
loginsuccess
Device Certificate success Device Certificate Success test@example.com was successfully authenticated with certificate [Serial Number] test@example.com successfully authenticated using certificate [Serial Number].
devicecertauth
loginfailure
Device Certificate failure Device Certificate Failure test@example.com failed authentication with certificate [Serial Number] test@example.com failed authentication using certificate [Serial Number].
scimuserlogin Login success Login success test@example.com logged in successfully with Inbound SCIM Successfully logged in to TrustLogin via SCIM IdP. test@example.com
successfullydeleteuser successfully deleted Delete test@example.com successfully deleted Deleted test@example.com in [Box]
userunassignedfromconf unassigned from config Delete test@example.com unassigned from config Removed test@example.com from [Box]
lockaccess Account locked Lock test@example.com account has been locked The account was locked. test@example.com
push_auth_qr_
code_via_mobile
Push auth QR code generated Push Notification Authentication - Registration Preparation test@example.com is generated QR code. A push notification device registration code was generated for test@example.com
faileddeleteuser failed to delete Delete test@example.com failed to delete Failed to delete test@example.com in [Box]
failedupsertuser failed to upsert Created/Updated test@example.com failed to upsert Failed to create/update test@example.com in [Box]
securityquestionupdate Update question Security Question Changed User security question updated test@example.com Updated user information for security questions. test@example.com
fidoprimaryregisterfailure FIDO authenticator registration failure FIDO Authenticator Failure test@example.com FIDO auth register failure test@example.com failed to register a FIDO authenticator.
fidoprimaryloginfailure FIDO auth failure FIDO Authentication Failure test@example.com failed authentication with FIDO authenticator [DeviceName] test@example.com failed to log in to TrustLogin using the FIDO authenticator [DeviceName].
kerbloginfailure Login failure Login failure test@example.com Desktop SSO authentication failure test@example.com failed Desktop SSO.
DeviceStepDownIp Cookie auth skipped Cookie Authentication Skipped test@example.com has successfully logged in with IP ***.***.***.*** test@example.com skipped device authentication from IP address ***.***.***.***.
Device
CertificateConfig
Device certificate Device Certificate devicecertificate
divisionadded
Group added Group Added GroupName was added to Device Certificate Added GroupName to the device certificate option.
devicecertificate
useractivated
User activated Member Enabled test@example.com can now use the device certificate option test@example.com is now able to use the device certificate option.
devicecertificate
userinactivated
User deactivated Member Disabled test@example.com is no longer able to use the device certificate option test@example.com is no longer able to use the device certificate option.
devicecertificate
useradded
User added Member Added test@example.com was added to Device Certificate Added test@example.com to the device certificate option.
devicecertificate
devicerequested
Device requested Device Request Registered device [DeviceName]for test@example.com test@example.com's device [DeviceName] was registered.
devicecertificate
deviceapproved
Device approved Device Approval Approved device [DeviceName] for test@example.com test@example.com's device [DeviceName] was approved.
devicecertificate
userremoved
User removed Member Removed test@example.com was removed from Device Certificate Removed test@example.com from the device certificate option.
devicecertificate
divisionremoved
Group removed Group Removed GroupName was removed from Device Certificate Removed GroupName from the device certificate option.
devicecertificate
deviceblocked
Device blocked Device Blocked Blocked device [DeviceName] for test@example.com Blocked device [DeviceName] for test@example.com.
devicecertificate
deviceunblocked
Device unblocked Device Unblocked Unblocked device [DeviceName] for test@example.com Unblocked device [DeviceName] for test@example.com.
devicecertificate
certificaterevoked
Certificate Revoked Certificate Revoked Revoked certificate [Serial Number]from device [DeviceName]for test@example.com Revoked certificate [Serial Number] for device [DeviceName] of test@example.com.
devicecertificate
devicedeactivated
Device deactivated Device Removed Deactivated device [DeviceName] for test@example.com Removed device [DeviceName] for test@example.com.
devicecertificate
preapprovecsvrequested
Approval CSV Preparation Bulk Registration CSV Preparation test@example.com has started CSV preparation. test@example.com started CSV preparation.
devicecertificate
preapprovecsvdownloaded
Approval CSV Downloaded Bulk Registration CSV Download test@example.com downloaded the CSV file. test@example.com downloaded a CSV file.
devicecertificate
devicescsvrequested
Export CSV Preparation Bulk Export CSV Preparation test@example.com has started CSV preparation. test@example.com started CSV preparation.
devicecertificate
devicescsvdownloaded
Export CSV Downloaded Bulk Export CSV Download test@example.com downloaded the CSV file. test@example.com downloaded a CSV file.
devicecertificate
preapprovecsvuploaded
Approval CSV Uploaded Bulk Registration CSV Upload test@example.com uploaded the CSV file. test@example.com uploaded a CSV file.
devicecertificate
devicepreapproved
Pre-approved Auto-Approval Activated device [DeviceName] for test@example.com Approved device [DeviceName] for test@example.com.
Membership
Division
User User Added Added to Group Added to Group test@example.com was added to the group GroupName test@example.com was added to the GroupName group.
Removed Removed from Group Removed from Group test@example.com was removed from the group GroupName test@example.com was removed from the GroupName group.
otpcreatemembership OTP added OTP Enabled OTP member allocation test@example.com OTP was enabled for test@example.com.
successfully
upsertusergroup
successfully upserted Created/Updated UserGroup successfully created for user test@example.com test@example.com was added to the group in [Box].
successfully
deleteusergroup
successfully deleted Delete UserGroup successfully deleted for user test@example.com Removed test@example.com from the group in [Box].
failedupsertusergroup failed to upsert Created/Updated UserGroup failed to upsert for user test@example.com Failed to add test@example.com to the group in [Box].
User User User Signup Signup Sign-up test@example.com user signed up to TrustLogin test@example.com signed up for TrustLogin.
Division Group Group Create Created Create forLogcheck group created Created the forLogcheck group.
Delete Deleted Delete forLogcheck group deleted Deleted the forLogcheck group.
Update Updated Update CSVSGroup1 group updated Updated the CSVSGroup1 group.
groupassignedtoconf assigned to config Created/Updated Any2 assigned to config Added to the Any2 service
successfullyupsertgroup successfully upserted Created/Updated Any2 successfully upserted Created/updated Any2 in [Box]
groupunassignedfromconf unassigned from config Delete Any2 unassigned from config Removed from the Any2 service
successfullydeletegroup successfully deleted Delete Any2 successfully deleted Deleted Any2 in [Box]
faileddeletegroup failed to delete Delete Failed testg failed to delete Failed to delete testg in [Box]
failedupsertgroup failed to upsert Create/Update Failed 6U failed to upsert Failed to create/update 6U in [Box]
RestrictedIp IP IP Restriction Create Created Create 0.0.0.1 IP created Created setting 0.0.0.1.
Delete Deleted Delete 0.0.0.2 IP deleted Deleted setting 0.0.0.2.
ipfailure Failure Failure Login from invalid IP ***.***.***.*** by test@example.com Login from a disallowed IP address ***.***.***.***. test@example.com
Update Updated Update ***.***.***.*** IP updated Changed setting ***.***.***.***.
ipsuccess Success Success Login from valid IP ***.***.***.*** by test@example.com Login from an allowed IP address ***.***.***.***. test@example.com
Account App App Accessed Accessed Used 7904 FORROU App accessed Used the 7904 FORROU app.
Create Created Create Kindle Store[FG1] App created for test@example.com Created the Kindle Store[FG1] app for test@example.com.
Shared Shared Shared Kindle Store App shared for test@example.com Shared the Kindle Store app with test@example.com.
mobileautofill Accessed on Mobile Used on Mobile Autofill for 1 7936 - 259 Money Forward Cloud Accounting app used from mobile. Performed autofill for the 1 7936 - 259 Money Forward Cloud Accounting app from mobile.
mobileaccountused Accessed on Mobile Used on Mobile 7936 - 259 Money Forward Cloud Accounting app used from mobile. Used the 7936 - 259 Money Forward Cloud Accounting app from mobile.
Delete Deleted Delete ActionPassport (SAML)[Manual1] App removed from test@example.com Deleted the ActionPassport (SAML)[Manual1] app from test@example.com.
Update Updated Update BASIC Authentication Template kaiin App account updated Updated the BASIC Authentication Template kaiin app.
update Updated Update FREETEL App account updated Updated the FREETEL app.
Unshared Unshared Sharing Removed Apple Developer App unshared for test@example.com Removed sharing of the Apple Developer app with test@example.com.
Restrictable     ipcreatedivision IP restriction created IP Restriction - Group Added Group forLogcheck added to IP restriction 0.0.0.1 Added forLogcheck to setting 0.0.0.1.
ipdeletemembership IP restriction deleted IP Restriction - Member Removed Member test@example.com removed to IP restriction 0.0.0.1 Removed test@example.com from setting 0.0.0.1.
ipdeletedivision IP restriction removed IP Restriction - Group Removed Group forLogcheck removed to IP restriction 0.0.0.1 Removed forLogcheck from setting 0.0.0.1.
DivisionAccount App App Create Created Create Kindle Store was added to the group FG1 Kindle Store was added to the FG1 group.
Delete Deleted Delete ActionPassport (SAML) was removed from the group Manual1 ActionPassport (SAML) was removed from the Manual1 group.
Role Role Permission Removed Removed from Group Removed from Group test@example.com is no longer an admin Set the permission of test@example.com to General.
Added Added to Group Added to Group test@example.com became an admin Set the permission of test@example.com to Administrator.
Profile Profile Profile Update Updated Update test@example.com profile updated Updated the profile of test@example.com.
Certificate
ValidationRule
Client authentication Client Authentication certvalidation
rulememberremoved
User deleted Member Removed Deleted test@example.com from setting SKUID Client Certification Removed test@example.com from the SKUID Client Certification setting.
certvalidationrulecreated rule created Rule Created Setting test_ca2 cert created Created the setting test_ca2 cert.
certvalidation
rulememberadded
User added Member Added Added test@example.com to setting SKUID Client Certification Added test@example.com to the SKUID Client Certification setting.
certvalidation
ruledivisionadded
group added Group Added Added rs_jmt2 to setting SKUID Client Certification Added rs_jmt2 to the SKUID Client Certification setting.
certvalidationruleedited rule edited Rule Updated Setting SKUID Client Certification updated Edited the SKUID Client Certification setting.
certvalidation
ruledivisionremoved
group deleted Group Removed Deleted rs_jmt2 from setting test_ca2 cert Removed rs_jmt2 from the setting test_ca2 cert.
certvalidationruledeleted rule deleted Rule Deleted Setting test_ca2 cert deleted Deleted the setting test_ca2 cert.
Admin Admin Administrator requestreset
passwordforuser
Initiate reset password for user User Password Reset Initiate reset password for test@example.com Reset the TrustLogin password of test@example.com.
setpassword
resetcodeforuser
Set password reset code for user User Password Reset Code Set Set password reset code for test@example.com Set the password reset code for test@example.com.
Setting App App Create Created Create 99designs0630 App setting created Created the 99designs0630 app.
Delete Deleted Delete Prod Bookmark Template App setting deleted Deleted the Prod Bookmark Template app.
Update Updated Update Prod freee Accounting Free_setApp005 App setting updated Updated the Prod freee Accounting Free_setApp005 app.
BasicAuthSetting App App Create Created Create BASIC1 App setting created Created the BASIC1 app.
Delete Deleted Delete BASIC3 App setting deleted Deleted the BASIC3 app.
Update Updated Update BASIC Authentication Template App setting updated Updated the BASIC Authentication Template app.
SamlIdpSetting SAML App SAML App Create Created Create ActionPassport (SAML) SAML App setting created Created the ActionPassport (SAML) SAML app.
Update Updated Update SAMLOwn1 SAML App setting updated Updated the SAMLOwn1 SAML app.
Accessed Accessed Used ActionPassport (SAML) SAML App accessed Used the ActionPassport (SAML) SAML app.
Delete Deleted Delete test SAML App setting deleted Deleted the test SAML app.
mobilesettingaccessed Accessed on Mobile Used on Mobile Salesforce (New SAML) SAML App accessed by mobile Used the Salesforce (New SAML) SAML app from mobile.
enablesso Update Update Microsoft 365 (SAML Auto Configuration) SAML SSO enabled SAML SSO was enabled for Microsoft 365 (SAML Auto Configuration).
disablesso Update Update Microsoft 365 (SAML Auto Configuration) SAML SSO disabled SAML SSO was disabled for Microsoft 365 (SAML Auto Configuration).
AccountByAdmin App App Create Created Create 99designs0630 app created for test@example.com Created the 99designs0630 app for test@example.com.
Delete Deleted Delete 99designs0630 app removed for test@example.com Deleted the 99designs0630 app for test@example.com.
Shared Shared Shared Prod freee Accounting Free_admin6 App shared for test@example.com Shared the Prod freee Accounting Free_admin6 app with test@example.com.
ReadOnlyAccount App App Create Created Create BASIC1 app created for test@example.com Created the BASIC1 app for test@example.com.
Delete Deleted Delete Basic3_adminBasic3 app removed for test@example.com Deleted the Basic3_adminBasic3 app for test@example.com.
IpSamlRestriction IP Group IP Group ipsaml
restrictionappsadded
App added App Added ActionPassport (SAML) has been added to IP Group. ActionPassport (SAML) was added to the IP group.
ipsamlrestriction
appsremoved
App deleted App Removed ActionPassport (SAML) has been deleted from IP Group. ActionPassport (SAML) was removed from the IP group.
ipsamlloginfailed     ipsaml
restrictioncheckfailed
IP restriction app failed IP Restriction - App Usage Failure The IP Address ***.***.***.*** can not be used with the app ActionPassport (SAML). ActionPassport (SAML) cannot be used from this IP address ***.***.***.***.
SubscribedUser     otpcreatemembership OTP added OTP Enabled OTP member allocation test@example.com OTP was enabled for test@example.com.
otpdeletemembership OTP removed OTP Disabled OTP member deleted test@example.com OTP was disabled for test@example.com.
SubscribedDivision     otpcreatedivision OTP added OTP Enabled OTP group added rs_jmt2 OTP was enabled for rs_jmt2.
otpdeletedivision OTP removed OTP Disabled OTP group deleted rs_jmt2 OTP was disabled for rs_jmt2.
ClientCertificate Client Certificate Client Authentication Create Created Create test@example.com has downloaded their client certificate test@example.com downloaded a certificate for their own use.
Revoke Revoke Revoke test@example.com has revoked test@example.com's client certificate from the admin portal test@example.com revoked their own certificate from the Admin Page.
Office365
Integration
Office365 Office365 office365setup Integration Integration Integration has been started Office 365 Integration Started
office365setupfinished Integration Integration Integration has been finished Office 365 Integration Completed
office365useradded User added User Added test@example.com was added to Office365 Created test@example.com in Office 365.
office365userremoved User removed User Removed test@example.com was removed from Office365 Removed test@example.com from Office 365.
office365reset Integration Released Integration has been reset. Office 365 Integration Released
GsuiteIntegration G Suite G Suite gsuitesetup Integration Integration Integration has been started G Suite Integration Started
gsuitesetupfinished Integration Integration Integration has been finished G Suite Integration Completed
gsuiteuseradded User added User Added test@example.com was added to G Suite Created test@example.com in G Suite.
gsuiteuserremoved User removed User Removed test@example.com was removed from G Suite Removed test@example.com from G Suite.
gsuitereset Integration Released Integration has been reset. G Suite Integration Released
Device Device Cookie Authentication Device DeviceCreated Created Register test@example.com has registered device test@example.com1 test@example.com registered device test@example.com1.
DeviceDeleted Deleted Delete test@example.com device test@example.com1 deleted Deleted device test@example.com1 for test@example.com.
DesktopSsoConfig Desktop SSO Desktop SSO desktopSso
memeberadded
User added Member Added test@example.com was added to Desktop SSO Added test@example.com to Desktop SSO.
desktopSso
memeberremoved
User removed Member Removed test@example.com was removed from Desktop SSO Removed test@example.com from Desktop SSO.
PushAuthConfig Push Auth Push Notification Authentication pushauthmemberadded User added Member Added test@example.com was added to Push Authentication Added test@example.com to Push Notification Authentication.
pushauth
memberremoved
User removed Member Removed test@example.com was removed from Push Authentication Removed test@example.com from Push Notification Authentication.
PushAuth
Registration
Push Auth Push Notification Authentication PushAuth
DeviceRemoved
device removed Device Removed test@example.com push auth device gs_sk's iPhone deleted Deleted the push notification authentication device gs_sk's iPhone for test@example.com.
AssignedUser     fidoprimary
createmembership
FIDO auth created FIDO Authentication - Member Added FIDO member allocation test@example.com Added test@example.com to FIDO Authentication.
fidoprimary
deletemembership
FIDO auth deleted FIDO Authentication - Member Removed FIDO member deleted test@example.com Removed test@example.com from FIDO Authentication.
AssignedDivision     fidoprimary
createdivision
FIDO auth created FIDO Authentication - Group Added FIDO group added rs_jmt2 Added rs_jmt2 to FIDO Authentication.
fidoprimary
deletedivision
FIDO auth deleted FIDO Authentication - Group Removed FIDO group deleted 1124 Removed 1124 from FIDO Authentication.
Config Config Identity Provisioning Service confcreated created Create Config created The identity provisioning service was added
confupdated updated Update Config updated The identity provisioning service was updated
ScimProvisioner SCIM Provisioner SCIM Provisioner create Created Create SCIM test created Created SCIM test.
renewkey Authentication key generation Authentication Key Updated SCIM test credential generated Updated the authentication key for SCIM test.
delete Deleted Delete SCIM test deleted Deleted SCIM test.
FidoPrimary
Authenticator
FIDO Authenticator FIDO Authenticator fidoprimary
authenticatordeleted
deleted Delete test@example.com FIDO authenticator [f] deleted test@example.com deleted the FIDO authenticator [f].
fidoprimar
yauthenticatorcreated
created Register test@example.com FIDO authenticator [y] created test@example.com registered the FIDO authenticator [y].
fidoprimary
authenticatorupdated
updated Update test@example.com FIDO authenticator [yubico] updated test@example.com updated the FIDO authenticator [yubico].
FidoPrimaryConfig   FIDO Settings fidoprimary
assignmentcsvexported
FIDO auth CSV generated Authenticator List CSV Generation Success FIDO auth test@example.com CSV generated test@example.com successfully generated the FIDO authenticator list CSV.
fidoprimary
assignmentcsvdownloaded
FIDO auth CSV downloaded Authenticator List CSV Download Success FIDO auth test@example.com CSV downloaded test@example.com successfully downloaded the FIDO authenticator list CSV.
fidoprimary
registrationcsvgenerated
FIDO registration CSV generated Authenticator Registration URL CSV Generation Success FIDO registration test@example.com CSV generated test@example.com successfully generated the FIDO authenticator registration URL CSV.
SIEMToken SIEM Client SIEM Client siemtokencreated created Create SIEM client eugene_test1 created SIEM client eugene_test1 was created
siemtokenregenerated regenerated Regenerate SIEM client eugene_test1 token regenerated The authentication token for SIEM client eugene_test1 was regenerated
siemtokenrevoked revoked Delete SIEM client eugene_test1 deleted SIEM client eugene_test1 was deleted
CustomAccount Custom App Custom App createcustomaccount Created Create HRMOS Expense Personal Custom App Created Created a personal custom app for HRMOS Expense.
CustomService Custom App Custom App createcustomservice Created Create ShopeeTestCustom1 Company Custom App Created Created the in-house custom app ShopeeTestCustom1.

How to Configure the SIEM Integration Feature

This page provides an overview of the SIEM integration, the setup flow, and important notes.
Please check the following before proceeding with the setup.

Note: A TrustLogin Pro Plan subscription is required to use this feature. For pricing information, please see here

Table of Contents:

What is SIEM

How to Create a Token

How to Recreate a Token

How to Delete a Token

List of SIEM Reports



What is SIEM

About SIEM Integration

SIEM stands for Security Information and Event Management. It is a solution that automatically detects security incidents by collecting and analyzing logs from the devices and systems that make up your infrastructure.

How to Create a Token

  1. Open "Reports" from the Admin Page and click "SIEM Settings."

    Note: This is grayed out on the Free plan.


  2. Click "Create SIEM Client."
  3. Enter any name and click "Add" to create a token.


  4. Click the copy icon to copy it to the clipboard.
    Note: For instructions on how to use the token, please refer to the manual for the service you are using.

     How to Configure Splunk Enterprise (On-Premises)
     How to Configure Splunk Cloud Platform
     How to Configure Sumo Logic
     How to Configure ALog (On-Premises)



How to Recreate a Token

  1. From the SIEM integration settings screen, click the "Regenerate Authentication Token" icon for the token you want to recreate.
  2. Click "Yes."
    Note: If you have already set the token in your SIEM service, you will need to reconfigure it after regenerating, so please be careful.
  3. The token will be regenerated. Copy it and set it in your SIEM service.

How to Delete a Token

  1. From the SIEM integration settings screen, click the "Delete" icon for the token you want to delete.

  2. Click "Yes."
    Note: Once a token is deleted, it cannot be restored, so please check carefully before proceeding.


List of SIEM Reports

Below is the list of reports displayed in SIEM. (As of September 2024. Subject to change in the future.)

 

Object type Object(en) Object(ja) Event type Event type (en) Event type (ja) Contents example (en) Contents example (ja)
Membership User User adloginsuccess Login success Login success test@example.com logged in successfully with Active Directory Successfully logged in to TrustLogin via Active Directory. test@example.com
passwordloginsuccess Login success Login success test@example.com Login success by password Successfully logged in to TrustLogin using a password. test@example.com
Delete Deleted Delete test@example.com user deleted Deleted user test@example.com.
CSVSUpload CSV Management CSV Batch Processing Upload CSV requested by test@example.com test@example.com uploaded a CSV file.
csvsusercreated CSV Management CSV Batch Processing test@example.com CSV user created Created CSV user. test@example.com
CSVSPrepare CSV Management CSV Batch Processing Prepare CSV requested by test@example.com test@example.com started CSV preparation.
CSVSDownload CSV Management CSV Batch Processing Download CSV requested by test@example.com test@example.com downloaded a CSV file.
csvsuserupdated CSV Management CSV Batch Processing test@example.com CSV user updated Updated CSV user. test@example.com
csvsuserdeleted CSV Management CSV Batch Processing test@example.com CSV user deleted Deleted CSV user. test@example.com
suspended Updated Update test@example.com has been suspended. Set the status of test@example.com to suspended.
csvupload Uploaded CSV data CSV Upload Added multiple users. Registered members in bulk.
Create Created Create test@example.com user created Created user test@example.com.
scimusercreated SCIM User Created SCIM User Created test@example.com SCIM user created Created SCIM user. test@example.com
scimuserupdated SCIM User Updated SCIM User Updated test@example.com SCIM user updated Updated SCIM user. test@example.com
scimuserdeleted SCIM User Deleted SCIM User Deleted test@example.com SCIM user deleted Deleted SCIM user. test@example.com
loginfailure Login failure Login failure test@example.com login failure Failed to log in to TrustLogin. test@example.com
userassigntoconf assigned to config Created/Updated test@example.com assigned to config Added test@example.com to [Box]
successfullyupsertuser successfully upserted Created/Updated test@example.com successfully upserted Created/updated test@example.com in [Box]
fidoprimaryloginsuccess FIDO auth success FIDO Authentication Success test@example.com has successfully logged in with FIDO authenticator mac test@example.com successfully logged in to TrustLogin using the FIDO authenticator [OSName].
Update Updated Update test@example.com user updated Updated user information for test@example.com.
unlockaccess Account unlocked Unlock test@example.com account has been unlocked The account lock was released. test@example.com
requestresetpassword Initiate reset password Password Reset TrustLogin password was reset test@example.com Reset the TrustLogin password. test@example.com
resetpasswordsuccess Reset password complete Password Change TrustLogin Password successfully changed test@example.com Changed the TrustLogin password. test@example.com
activated Updated Update test@example.com has been made active. Set the status of test@example.com to active.
resetpassword Password reset Password Reset test@example.com TrustLogin password has been reset Reset the TrustLogin password. test@example.com
otploginfailure OTP login failure OTP Failure test@example.com OTP login failure test@example.com failed to log in using OTP.
otploginsuccess OTP login success OTP Success test@example.com OTP login success test@example.com successfully logged in using OTP.
idploginsuccess Login success Login success test@example.com logged in successfully with External IDP Successfully logged in to TrustLogin via an external IdP. test@example.com
clientcertauthloginsuccess Client authentication success Client Authentication Success test@example.com Client authentication success test@example.com successfully completed client authentication.
clientcertauthloginfailure Client authentication failure Client Authentication Failure test@example.com Client authentication failure test@example.com failed client authentication.
DeviceLogin Cookie auth success Cookie Authentication Success test@example.com has logged in with device test@example.com1 test@example.com successfully authenticated on device test@example.com1.
DeviceLoginFail Cookie auth failed Cookie Authentication Failure test@example.com has failed cookie auth and has no additional device slots to register. test@example.com failed device authentication. The maximum number of registrations has been exceeded.
kerbloginsuccess Login success Login success test@example.com logged in successfully with Desktop SSO Successfully logged in to TrustLogin via Desktop SSO. test@example.com
push_auth_qr_
code_via_pc
Push auth QR code generated Push Notification Authentication - Registration Preparation test@example.com is generated QR code. A push notification device registration code was generated for test@example.com
push_auth_registered Push auth registered Push Notification Authentication - Device Registration test@example.com registered a new device. A push notification device was registered for test@example.com.
push_auth_new_client Push auth new client Push Notification Authentication - Approval Request test@example.com accessed from new client. An approval request was made from a new browser/app for test@example.com.
push_auth_approved Push auth approved Push Notification Authentication Approved test@example.com is approved Push auth login request. Push notification authentication was approved for test@example.com.
pushauth_login_success Push auth login success Push Notification Authentication Success test@example.com Push auth login success. test@example.com successfully logged in using push notification.
push_auth_denied Push auth denied Push Notification Authentication Denied test@example.com is approved Push auth login request. Push notification authentication was denied for test@example.com.
devicecertauth
loginsuccess
Device Certificate success Device Certificate Success test@example.com was successfully authenticated with certificate [Serial Number] test@example.com successfully authenticated using certificate [Serial Number].
devicecertauth
loginfailure
Device Certificate failure Device Certificate Failure test@example.com failed authentication with certificate [Serial Number] test@example.com failed authentication using certificate [Serial Number].
scimuserlogin Login success Login success test@example.com logged in successfully with Inbound SCIM Successfully logged in to TrustLogin via SCIM IdP. test@example.com
successfullydeleteuser successfully deleted Delete test@example.com successfully deleted Deleted test@example.com in [Box]
userunassignedfromconf unassigned from config Delete test@example.com unassigned from config Removed test@example.com from [Box]
lockaccess Account locked Lock test@example.com account has been locked The account was locked. test@example.com
push_auth_qr_
code_via_mobile
Push auth QR code generated Push Notification Authentication - Registration Preparation test@example.com is generated QR code. A push notification device registration code was generated for test@example.com
faileddeleteuser failed to delete Delete test@example.com failed to delete Failed to delete test@example.com in [Box]
failedupsertuser failed to upsert Created/Updated test@example.com failed to upsert Failed to create/update test@example.com in [Box]
securityquestionupdate Update question Security Question Changed User security question updated test@example.com Updated user information for security questions. test@example.com
fidoprimaryregisterfailure FIDO authenticator registration failure FIDO Authenticator Failure test@example.com FIDO auth register failure test@example.com failed to register a FIDO authenticator.
fidoprimaryloginfailure FIDO auth failure FIDO Authentication Failure test@example.com failed authentication with FIDO authenticator [DeviceName] test@example.com failed to log in to TrustLogin using the FIDO authenticator [DeviceName].
kerbloginfailure Login failure Login failure test@example.com Desktop SSO authentication failure test@example.com failed Desktop SSO.
DeviceStepDownIp Cookie auth skipped Cookie Authentication Skipped test@example.com has successfully logged in with IP ***.***.***.*** test@example.com skipped device authentication from IP address ***.***.***.***.
Device
CertificateConfig
Device certificate Device Certificate devicecertificate
divisionadded
Group added Group Added GroupName was added to Device Certificate Added GroupName to the device certificate option.
devicecertificate
useractivated
User activated Member Enabled test@example.com can now use the device certificate option test@example.com is now able to use the device certificate option.
devicecertificate
userinactivated
User deactivated Member Disabled test@example.com is no longer able to use the device certificate option test@example.com is no longer able to use the device certificate option.
devicecertificate
useradded
User added Member Added test@example.com was added to Device Certificate Added test@example.com to the device certificate option.
devicecertificate
devicerequested
Device requested Device Request Registered device [DeviceName]for test@example.com test@example.com's device [DeviceName] was registered.
devicecertificate
deviceapproved
Device approved Device Approval Approved device [DeviceName] for test@example.com test@example.com's device [DeviceName] was approved.
devicecertificate
userremoved
User removed Member Removed test@example.com was removed from Device Certificate Removed test@example.com from the device certificate option.
devicecertificate
divisionremoved
Group removed Group Removed GroupName was removed from Device Certificate Removed GroupName from the device certificate option.
devicecertificate
deviceblocked
Device blocked Device Blocked Blocked device [DeviceName] for test@example.com Blocked device [DeviceName] for test@example.com.
devicecertificate
deviceunblocked
Device unblocked Device Unblocked Unblocked device [DeviceName] for test@example.com Unblocked device [DeviceName] for test@example.com.
devicecertificate
certificaterevoked
Certificate Revoked Certificate Revoked Revoked certificate [Serial Number]from device [DeviceName]for test@example.com Revoked certificate [Serial Number] for device [DeviceName] of test@example.com.
devicecertificate
devicedeactivated
Device deactivated Device Removed Deactivated device [DeviceName] for test@example.com Removed device [DeviceName] for test@example.com.
devicecertificate
preapprovecsvrequested
Approval CSV Preparation Bulk Registration CSV Preparation test@example.com has started CSV preparation. test@example.com started CSV preparation.
devicecertificate
preapprovecsvdownloaded
Approval CSV Downloaded Bulk Registration CSV Download test@example.com downloaded the CSV file. test@example.com downloaded a CSV file.
devicecertificate
devicescsvrequested
Export CSV Preparation Bulk Export CSV Preparation test@example.com has started CSV preparation. test@example.com started CSV preparation.
devicecertificate
devicescsvdownloaded
Export CSV Downloaded Bulk Export CSV Download test@example.com downloaded the CSV file. test@example.com downloaded a CSV file.
devicecertificate
preapprovecsvuploaded
Approval CSV Uploaded Bulk Registration CSV Upload test@example.com uploaded the CSV file. test@example.com uploaded a CSV file.
devicecertificate
devicepreapproved
Pre-approved Auto-Approval Activated device [DeviceName] for test@example.com Approved device [DeviceName] for test@example.com.
Membership
Division
User User Added Added to Group Added to Group test@example.com was added to the group GroupName test@example.com was added to the GroupName group.
Removed Removed from Group Removed from Group test@example.com was removed from the group GroupName test@example.com was removed from the GroupName group.
otpcreatemembership OTP added OTP Enabled OTP member allocation test@example.com OTP was enabled for test@example.com.
successfully
upsertusergroup
successfully upserted Created/Updated UserGroup successfully created for user test@example.com test@example.com was added to the group in [Box].
successfully
deleteusergroup
successfully deleted Delete UserGroup successfully deleted for user test@example.com Removed test@example.com from the group in [Box].
failedupsertusergroup failed to upsert Created/Updated UserGroup failed to upsert for user test@example.com Failed to add test@example.com to the group in [Box].
User User User Signup Signup Sign-up test@example.com user signed up to TrustLogin test@example.com signed up for TrustLogin.
Division Group Group Create Created Create forLogcheck group created Created the forLogcheck group.
Delete Deleted Delete forLogcheck group deleted Deleted the forLogcheck group.
Update Updated Update CSVSGroup1 group updated Updated the CSVSGroup1 group.
groupassignedtoconf assigned to config Created/Updated Any2 assigned to config Added to the Any2 service
successfullyupsertgroup successfully upserted Created/Updated Any2 successfully upserted Created/updated Any2 in [Box]
groupunassignedfromconf unassigned from config Delete Any2 unassigned from config Removed from the Any2 service
successfullydeletegroup successfully deleted Delete Any2 successfully deleted Deleted Any2 in [Box]
faileddeletegroup failed to delete Delete Failed testg failed to delete Failed to delete testg in [Box]
failedupsertgroup failed to upsert Create/Update Failed 6U failed to upsert Failed to create/update 6U in [Box]
RestrictedIp IP IP Restriction Create Created Create 0.0.0.1 IP created Created setting 0.0.0.1.
Delete Deleted Delete 0.0.0.2 IP deleted Deleted setting 0.0.0.2.
ipfailure Failure Failure Login from invalid IP ***.***.***.*** by test@example.com Login from a disallowed IP address ***.***.***.***. test@example.com
Update Updated Update ***.***.***.*** IP updated Changed setting ***.***.***.***.
ipsuccess Success Success Login from valid IP ***.***.***.*** by test@example.com Login from an allowed IP address ***.***.***.***. test@example.com
Account App App Accessed Accessed Used 7904 FORROU App accessed Used the 7904 FORROU app.
Create Created Create Kindle Store[FG1] App created for test@example.com Created the Kindle Store[FG1] app for test@example.com.
Shared Shared Shared Kindle Store App shared for test@example.com Shared the Kindle Store app with test@example.com.
mobileautofill Accessed on Mobile Used on Mobile Autofill for 1 7936 - 259 Money Forward Cloud Accounting app used from mobile. Performed autofill for the 1 7936 - 259 Money Forward Cloud Accounting app from mobile.
mobileaccountused Accessed on Mobile Used on Mobile 7936 - 259 Money Forward Cloud Accounting app used from mobile. Used the 7936 - 259 Money Forward Cloud Accounting app from mobile.
Delete Deleted Delete ActionPassport (SAML)[Manual1] App removed from test@example.com Deleted the ActionPassport (SAML)[Manual1] app from test@example.com.
Update Updated Update BASIC Authentication Template kaiin App account updated Updated the BASIC Authentication Template kaiin app.
update Updated Update FREETEL App account updated Updated the FREETEL app.
Unshared Unshared Sharing Removed Apple Developer App unshared for test@example.com Removed sharing of the Apple Developer app with test@example.com.
Restrictable     ipcreatedivision IP restriction created IP Restriction - Group Added Group forLogcheck added to IP restriction 0.0.0.1 Added forLogcheck to setting 0.0.0.1.
ipdeletemembership IP restriction deleted IP Restriction - Member Removed Member test@example.com removed to IP restriction 0.0.0.1 Removed test@example.com from setting 0.0.0.1.
ipdeletedivision IP restriction removed IP Restriction - Group Removed Group forLogcheck removed to IP restriction 0.0.0.1 Removed forLogcheck from setting 0.0.0.1.
DivisionAccount App App Create Created Create Kindle Store was added to the group FG1 Kindle Store was added to the FG1 group.
Delete Deleted Delete ActionPassport (SAML) was removed from the group Manual1 ActionPassport (SAML) was removed from the Manual1 group.
Role Role Permission Removed Removed from Group Removed from Group test@example.com is no longer an admin Set the permission of test@example.com to General.
Added Added to Group Added to Group test@example.com became an admin Set the permission of test@example.com to Administrator.
Profile Profile Profile Update Updated Update test@example.com profile updated Updated the profile of test@example.com.
Certificate
ValidationRule
Client authentication Client Authentication certvalidation
rulememberremoved
User deleted Member Removed Deleted test@example.com from setting SKUID Client Certification Removed test@example.com from the SKUID Client Certification setting.
certvalidationrulecreated rule created Rule Created Setting test_ca2 cert created Created the setting test_ca2 cert.
certvalidation
rulememberadded
User added Member Added Added test@example.com to setting SKUID Client Certification Added test@example.com to the SKUID Client Certification setting.
certvalidation
ruledivisionadded
group added Group Added Added rs_jmt2 to setting SKUID Client Certification Added rs_jmt2 to the SKUID Client Certification setting.
certvalidationruleedited rule edited Rule Updated Setting SKUID Client Certification updated Edited the SKUID Client Certification setting.
certvalidation
ruledivisionremoved
group deleted Group Removed Deleted rs_jmt2 from setting test_ca2 cert Removed rs_jmt2 from the setting test_ca2 cert.
certvalidationruledeleted rule deleted Rule Deleted Setting test_ca2 cert deleted Deleted the setting test_ca2 cert.
Admin Admin Administrator requestreset
passwordforuser
Initiate reset password for user User Password Reset Initiate reset password for test@example.com Reset the TrustLogin password of test@example.com.
setpassword
resetcodeforuser
Set password reset code for user User Password Reset Code Set Set password reset code for test@example.com Set the password reset code for test@example.com.
Setting App App Create Created Create 99designs0630 App setting created Created the 99designs0630 app.
Delete Deleted Delete Prod Bookmark Template App setting deleted Deleted the Prod Bookmark Template app.
Update Updated Update Prod freee Accounting Free_setApp005 App setting updated Updated the Prod freee Accounting Free_setApp005 app.
BasicAuthSetting App App Create Created Create BASIC1 App setting created Created the BASIC1 app.
Delete Deleted Delete BASIC3 App setting deleted Deleted the BASIC3 app.
Update Updated Update BASIC Authentication Template App setting updated Updated the BASIC Authentication Template app.
SamlIdpSetting SAML App SAML App Create Created Create ActionPassport (SAML) SAML App setting created Created the ActionPassport (SAML) SAML app.
Update Updated Update SAMLOwn1 SAML App setting updated Updated the SAMLOwn1 SAML app.
Accessed Accessed Used ActionPassport (SAML) SAML App accessed Used the ActionPassport (SAML) SAML app.
Delete Deleted Delete test SAML App setting deleted Deleted the test SAML app.
mobilesettingaccessed Accessed on Mobile Used on Mobile Salesforce (New SAML) SAML App accessed by mobile Used the Salesforce (New SAML) SAML app from mobile.
enablesso Update Update Microsoft 365 (SAML Auto Configuration) SAML SSO enabled SAML SSO was enabled for Microsoft 365 (SAML Auto Configuration).
disablesso Update Update Microsoft 365 (SAML Auto Configuration) SAML SSO disabled SAML SSO was disabled for Microsoft 365 (SAML Auto Configuration).
AccountByAdmin App App Create Created Create 99designs0630 app created for test@example.com Created the 99designs0630 app for test@example.com.
Delete Deleted Delete 99designs0630 app removed for test@example.com Deleted the 99designs0630 app for test@example.com.
Shared Shared Shared Prod freee Accounting Free_admin6 App shared for test@example.com Shared the Prod freee Accounting Free_admin6 app with test@example.com.
ReadOnlyAccount App App Create Created Create BASIC1 app created for test@example.com Created the BASIC1 app for test@example.com.
Delete Deleted Delete Basic3_adminBasic3 app removed for test@example.com Deleted the Basic3_adminBasic3 app for test@example.com.
IpSamlRestriction IP Group IP Group ipsaml
restrictionappsadded
App added App Added ActionPassport (SAML) has been added to IP Group. ActionPassport (SAML) was added to the IP group.
ipsamlrestriction
appsremoved
App deleted App Removed ActionPassport (SAML) has been deleted from IP Group. ActionPassport (SAML) was removed from the IP group.
ipsamlloginfailed     ipsaml
restrictioncheckfailed
IP restriction app failed IP Restriction - App Usage Failure The IP Address ***.***.***.*** can not be used with the app ActionPassport (SAML). ActionPassport (SAML) cannot be used from this IP address ***.***.***.***.
SubscribedUser     otpcreatemembership OTP added OTP Enabled OTP member allocation test@example.com OTP was enabled for test@example.com.
otpdeletemembership OTP removed OTP Disabled OTP member deleted test@example.com OTP was disabled for test@example.com.
SubscribedDivision     otpcreatedivision OTP added OTP Enabled OTP group added rs_jmt2 OTP was enabled for rs_jmt2.
otpdeletedivision OTP removed OTP Disabled OTP group deleted rs_jmt2 OTP was disabled for rs_jmt2.
ClientCertificate Client Certificate Client Authentication Create Created Create test@example.com has downloaded their client certificate test@example.com downloaded a certificate for their own use.
Revoke Revoke Revoke test@example.com has revoked test@example.com's client certificate from the admin portal test@example.com revoked their own certificate from the Admin Page.
Office365
Integration
Office365 Office365 office365setup Integration Integration Integration has been started Office 365 Integration Started
office365setupfinished Integration Integration Integration has been finished Office 365 Integration Completed
office365useradded User added User Added test@example.com was added to Office365 Created test@example.com in Office 365.
office365userremoved User removed User Removed test@example.com was removed from Office365 Removed test@example.com from Office 365.
office365reset Integration Released Integration has been reset. Office 365 Integration Released
GsuiteIntegration G Suite G Suite gsuitesetup Integration Integration Integration has been started G Suite Integration Started
gsuitesetupfinished Integration Integration Integration has been finished G Suite Integration Completed
gsuiteuseradded User added User Added test@example.com was added to G Suite Created test@example.com in G Suite.
gsuiteuserremoved User removed User Removed test@example.com was removed from G Suite Removed test@example.com from G Suite.
gsuitereset Integration Released Integration has been reset. G Suite Integration Released
Device Device Cookie Authentication Device DeviceCreated Created Register test@example.com has registered device test@example.com1 test@example.com registered device test@example.com1.
DeviceDeleted Deleted Delete test@example.com device test@example.com1 deleted Deleted device test@example.com1 for test@example.com.
DesktopSsoConfig Desktop SSO Desktop SSO desktopSso
memeberadded
User added Member Added test@example.com was added to Desktop SSO Added test@example.com to Desktop SSO.
desktopSso
memeberremoved
User removed Member Removed test@example.com was removed from Desktop SSO Removed test@example.com from Desktop SSO.
PushAuthConfig Push Auth Push Notification Authentication pushauthmemberadded User added Member Added test@example.com was added to Push Authentication Added test@example.com to Push Notification Authentication.
pushauth
memberremoved
User removed Member Removed test@example.com was removed from Push Authentication Removed test@example.com from Push Notification Authentication.
PushAuth
Registration
Push Auth Push Notification Authentication PushAuth
DeviceRemoved
device removed Device Removed test@example.com push auth device gs_sk's iPhone deleted Deleted the push notification authentication device gs_sk's iPhone for test@example.com.
AssignedUser     fidoprimary
createmembership
FIDO auth created FIDO Authentication - Member Added FIDO member allocation test@example.com Added test@example.com to FIDO Authentication.
fidoprimary
deletemembership
FIDO auth deleted FIDO Authentication - Member Removed FIDO member deleted test@example.com Removed test@example.com from FIDO Authentication.
AssignedDivision     fidoprimary
createdivision
FIDO auth created FIDO Authentication - Group Added FIDO group added rs_jmt2 Added rs_jmt2 to FIDO Authentication.
fidoprimary
deletedivision
FIDO auth deleted FIDO Authentication - Group Removed FIDO group deleted 1124 Removed 1124 from FIDO Authentication.
Config Config Identity Provisioning Service confcreated created Create Config created The identity provisioning service was added
confupdated updated Update Config updated The identity provisioning service was updated
ScimProvisioner SCIM Provisioner SCIM Provisioner create Created Create SCIM test created Created SCIM test.
renewkey Authentication key generation Authentication Key Updated SCIM test credential generated Updated the authentication key for SCIM test.
delete Deleted Delete SCIM test deleted Deleted SCIM test.
FidoPrimary
Authenticator
FIDO Authenticator FIDO Authenticator fidoprimary
authenticatordeleted
deleted Delete test@example.com FIDO authenticator [f] deleted test@example.com deleted the FIDO authenticator [f].
fidoprimar
yauthenticatorcreated
created Register test@example.com FIDO authenticator [y] created test@example.com registered the FIDO authenticator [y].
fidoprimary
authenticatorupdated
updated Update test@example.com FIDO authenticator [yubico] updated test@example.com updated the FIDO authenticator [yubico].
FidoPrimaryConfig   FIDO Settings fidoprimary
assignmentcsvexported
FIDO auth CSV generated Authenticator List CSV Generation Success FIDO auth test@example.com CSV generated test@example.com successfully generated the FIDO authenticator list CSV.
fidoprimary
assignmentcsvdownloaded
FIDO auth CSV downloaded Authenticator List CSV Download Success FIDO auth test@example.com CSV downloaded test@example.com successfully downloaded the FIDO authenticator list CSV.
fidoprimary
registrationcsvgenerated
FIDO registration CSV generated Authenticator Registration URL CSV Generation Success FIDO registration test@example.com CSV generated test@example.com successfully generated the FIDO authenticator registration URL CSV.
SIEMToken SIEM Client SIEM Client siemtokencreated created Create SIEM client eugene_test1 created SIEM client eugene_test1 was created
siemtokenregenerated regenerated Regenerate SIEM client eugene_test1 token regenerated The authentication token for SIEM client eugene_test1 was regenerated
siemtokenrevoked revoked Delete SIEM client eugene_test1 deleted SIEM client eugene_test1 was deleted
CustomAccount Custom App Custom App createcustomaccount Created Create HRMOS Expense Personal Custom App Created Created a personal custom app for HRMOS Expense.
CustomService Custom App Custom App createcustomservice Created Create ShopeeTestCustom1 Company Custom App Created Created the in-house custom app ShopeeTestCustom1.