This page provides an overview of the SIEM integration, the setup flow, and important notes.
Please check the following before proceeding with the setup.
Note: A TrustLogin Pro Plan subscription is required to use this feature. For pricing information, please see here
|
Table of Contents: |
What is SIEM
About SIEM Integration
SIEM stands for Security Information and Event Management. It is a solution that automatically detects security incidents by collecting and analyzing logs from the devices and systems that make up your infrastructure.
How to Create a Token
- Open "Reports" from the Admin Page and click "SIEM Settings."
Note: This is grayed out on the Free plan.
- Click "Create SIEM Client."
- Enter any name and click "Add" to create a token.
- Click the copy icon to copy it to the clipboard.
Note: For instructions on how to use the token, please refer to the manual for the service you are using.
How to Configure Splunk Enterprise (On-Premises)
How to Configure Splunk Cloud Platform
How to Configure Sumo Logic
How to Configure ALog (On-Premises)
How to Recreate a Token
- From the SIEM integration settings screen, click the "Regenerate Authentication Token" icon for the token you want to recreate.
- Click "Yes."
Note: If you have already set the token in your SIEM service, you will need to reconfigure it after regenerating, so please be careful. - The token will be regenerated. Copy it and set it in your SIEM service.
How to Delete a Token
- From the SIEM integration settings screen, click the "Delete" icon for the token you want to delete.
- Click "Yes."
Note: Once a token is deleted, it cannot be restored, so please check carefully before proceeding.
List of SIEM Reports
Below is the list of reports displayed in SIEM. (As of September 2024. Subject to change in the future.)
| Object type | Object(en) | Object(ja) | Event type | Event type (en) | Event type (ja) | Contents example (en) | Contents example (ja) |
| Membership | User | User | adloginsuccess | Login success | Login success | test@example.com logged in successfully with Active Directory | Successfully logged in to TrustLogin via Active Directory. test@example.com |
| passwordloginsuccess | Login success | Login success | test@example.com Login success by password | Successfully logged in to TrustLogin using a password. test@example.com | |||
| Delete | Deleted | Delete | test@example.com user deleted | Deleted user test@example.com. | |||
| CSVSUpload | CSV Management | CSV Batch Processing | Upload CSV requested by test@example.com | test@example.com uploaded a CSV file. | |||
| csvsusercreated | CSV Management | CSV Batch Processing | test@example.com CSV user created | Created CSV user. test@example.com | |||
| CSVSPrepare | CSV Management | CSV Batch Processing | Prepare CSV requested by test@example.com | test@example.com started CSV preparation. | |||
| CSVSDownload | CSV Management | CSV Batch Processing | Download CSV requested by test@example.com | test@example.com downloaded a CSV file. | |||
| csvsuserupdated | CSV Management | CSV Batch Processing | test@example.com CSV user updated | Updated CSV user. test@example.com | |||
| csvsuserdeleted | CSV Management | CSV Batch Processing | test@example.com CSV user deleted | Deleted CSV user. test@example.com | |||
| suspended | Updated | Update | test@example.com has been suspended. | Set the status of test@example.com to suspended. | |||
| csvupload | Uploaded CSV data | CSV Upload | Added multiple users. | Registered members in bulk. | |||
| Create | Created | Create | test@example.com user created | Created user test@example.com. | |||
| scimusercreated | SCIM User Created | SCIM User Created | test@example.com SCIM user created | Created SCIM user. test@example.com | |||
| scimuserupdated | SCIM User Updated | SCIM User Updated | test@example.com SCIM user updated | Updated SCIM user. test@example.com | |||
| scimuserdeleted | SCIM User Deleted | SCIM User Deleted | test@example.com SCIM user deleted | Deleted SCIM user. test@example.com | |||
| loginfailure | Login failure | Login failure | test@example.com login failure | Failed to log in to TrustLogin. test@example.com | |||
| userassigntoconf | assigned to config | Created/Updated | test@example.com assigned to config | Added test@example.com to [Box] | |||
| successfullyupsertuser | successfully upserted | Created/Updated | test@example.com successfully upserted | Created/updated test@example.com in [Box] | |||
| fidoprimaryloginsuccess | FIDO auth success | FIDO Authentication Success | test@example.com has successfully logged in with FIDO authenticator mac | test@example.com successfully logged in to TrustLogin using the FIDO authenticator [OSName]. | |||
| Update | Updated | Update | test@example.com user updated | Updated user information for test@example.com. | |||
| unlockaccess | Account unlocked | Unlock | test@example.com account has been unlocked | The account lock was released. test@example.com | |||
| requestresetpassword | Initiate reset password | Password Reset | TrustLogin password was reset test@example.com | Reset the TrustLogin password. test@example.com | |||
| resetpasswordsuccess | Reset password complete | Password Change | TrustLogin Password successfully changed test@example.com | Changed the TrustLogin password. test@example.com | |||
| activated | Updated | Update | test@example.com has been made active. | Set the status of test@example.com to active. | |||
| resetpassword | Password reset | Password Reset | test@example.com TrustLogin password has been reset | Reset the TrustLogin password. test@example.com | |||
| otploginfailure | OTP login failure | OTP Failure | test@example.com OTP login failure | test@example.com failed to log in using OTP. | |||
| otploginsuccess | OTP login success | OTP Success | test@example.com OTP login success | test@example.com successfully logged in using OTP. | |||
| idploginsuccess | Login success | Login success | test@example.com logged in successfully with External IDP | Successfully logged in to TrustLogin via an external IdP. test@example.com | |||
| clientcertauthloginsuccess | Client authentication success | Client Authentication Success | test@example.com Client authentication success | test@example.com successfully completed client authentication. | |||
| clientcertauthloginfailure | Client authentication failure | Client Authentication Failure | test@example.com Client authentication failure | test@example.com failed client authentication. | |||
| DeviceLogin | Cookie auth success | Cookie Authentication Success | test@example.com has logged in with device test@example.com1 | test@example.com successfully authenticated on device test@example.com1. | |||
| DeviceLoginFail | Cookie auth failed | Cookie Authentication Failure | test@example.com has failed cookie auth and has no additional device slots to register. | test@example.com failed device authentication. The maximum number of registrations has been exceeded. | |||
| kerbloginsuccess | Login success | Login success | test@example.com logged in successfully with Desktop SSO | Successfully logged in to TrustLogin via Desktop SSO. test@example.com | |||
| push_auth_qr_ code_via_pc |
Push auth QR code generated | Push Notification Authentication - Registration Preparation | test@example.com is generated QR code. | A push notification device registration code was generated for test@example.com | |||
| push_auth_registered | Push auth registered | Push Notification Authentication - Device Registration | test@example.com registered a new device. | A push notification device was registered for test@example.com. | |||
| push_auth_new_client | Push auth new client | Push Notification Authentication - Approval Request | test@example.com accessed from new client. | An approval request was made from a new browser/app for test@example.com. | |||
| push_auth_approved | Push auth approved | Push Notification Authentication Approved | test@example.com is approved Push auth login request. | Push notification authentication was approved for test@example.com. | |||
| pushauth_login_success | Push auth login success | Push Notification Authentication Success | test@example.com Push auth login success. | test@example.com successfully logged in using push notification. | |||
| push_auth_denied | Push auth denied | Push Notification Authentication Denied | test@example.com is approved Push auth login request. | Push notification authentication was denied for test@example.com. | |||
| devicecertauth loginsuccess |
Device Certificate success | Device Certificate Success | test@example.com was successfully authenticated with certificate [Serial Number] | test@example.com successfully authenticated using certificate [Serial Number]. | |||
| devicecertauth loginfailure |
Device Certificate failure | Device Certificate Failure | test@example.com failed authentication with certificate [Serial Number] | test@example.com failed authentication using certificate [Serial Number]. | |||
| scimuserlogin | Login success | Login success | test@example.com logged in successfully with Inbound SCIM | Successfully logged in to TrustLogin via SCIM IdP. test@example.com | |||
| successfullydeleteuser | successfully deleted | Delete | test@example.com successfully deleted | Deleted test@example.com in [Box] | |||
| userunassignedfromconf | unassigned from config | Delete | test@example.com unassigned from config | Removed test@example.com from [Box] | |||
| lockaccess | Account locked | Lock | test@example.com account has been locked | The account was locked. test@example.com | |||
| push_auth_qr_ code_via_mobile |
Push auth QR code generated | Push Notification Authentication - Registration Preparation | test@example.com is generated QR code. | A push notification device registration code was generated for test@example.com | |||
| faileddeleteuser | failed to delete | Delete | test@example.com failed to delete | Failed to delete test@example.com in [Box] | |||
| failedupsertuser | failed to upsert | Created/Updated | test@example.com failed to upsert | Failed to create/update test@example.com in [Box] | |||
| securityquestionupdate | Update question | Security Question Changed | User security question updated test@example.com | Updated user information for security questions. test@example.com | |||
| fidoprimaryregisterfailure | FIDO authenticator registration failure | FIDO Authenticator Failure | test@example.com FIDO auth register failure | test@example.com failed to register a FIDO authenticator. | |||
| fidoprimaryloginfailure | FIDO auth failure | FIDO Authentication Failure | test@example.com failed authentication with FIDO authenticator [DeviceName] | test@example.com failed to log in to TrustLogin using the FIDO authenticator [DeviceName]. | |||
| kerbloginfailure | Login failure | Login failure | test@example.com Desktop SSO authentication failure | test@example.com failed Desktop SSO. | |||
| DeviceStepDownIp | Cookie auth skipped | Cookie Authentication Skipped | test@example.com has successfully logged in with IP ***.***.***.*** | test@example.com skipped device authentication from IP address ***.***.***.***. | |||
| Device CertificateConfig |
Device certificate | Device Certificate | devicecertificate divisionadded |
Group added | Group Added | GroupName was added to Device Certificate | Added GroupName to the device certificate option. |
| devicecertificate useractivated |
User activated | Member Enabled | test@example.com can now use the device certificate option | test@example.com is now able to use the device certificate option. | |||
| devicecertificate userinactivated |
User deactivated | Member Disabled | test@example.com is no longer able to use the device certificate option | test@example.com is no longer able to use the device certificate option. | |||
| devicecertificate useradded |
User added | Member Added | test@example.com was added to Device Certificate | Added test@example.com to the device certificate option. | |||
| devicecertificate devicerequested |
Device requested | Device Request | Registered device [DeviceName]for test@example.com | test@example.com's device [DeviceName] was registered. | |||
| devicecertificate deviceapproved |
Device approved | Device Approval | Approved device [DeviceName] for test@example.com | test@example.com's device [DeviceName] was approved. | |||
| devicecertificate userremoved |
User removed | Member Removed | test@example.com was removed from Device Certificate | Removed test@example.com from the device certificate option. | |||
| devicecertificate divisionremoved |
Group removed | Group Removed | GroupName was removed from Device Certificate | Removed GroupName from the device certificate option. | |||
| devicecertificate deviceblocked |
Device blocked | Device Blocked | Blocked device [DeviceName] for test@example.com | Blocked device [DeviceName] for test@example.com. | |||
| devicecertificate deviceunblocked |
Device unblocked | Device Unblocked | Unblocked device [DeviceName] for test@example.com | Unblocked device [DeviceName] for test@example.com. | |||
| devicecertificate certificaterevoked |
Certificate Revoked | Certificate Revoked | Revoked certificate [Serial Number]from device [DeviceName]for test@example.com | Revoked certificate [Serial Number] for device [DeviceName] of test@example.com. | |||
| devicecertificate devicedeactivated |
Device deactivated | Device Removed | Deactivated device [DeviceName] for test@example.com | Removed device [DeviceName] for test@example.com. | |||
| devicecertificate preapprovecsvrequested |
Approval CSV Preparation | Bulk Registration CSV Preparation | test@example.com has started CSV preparation. | test@example.com started CSV preparation. | |||
| devicecertificate preapprovecsvdownloaded |
Approval CSV Downloaded | Bulk Registration CSV Download | test@example.com downloaded the CSV file. | test@example.com downloaded a CSV file. | |||
| devicecertificate devicescsvrequested |
Export CSV Preparation | Bulk Export CSV Preparation | test@example.com has started CSV preparation. | test@example.com started CSV preparation. | |||
| devicecertificate devicescsvdownloaded |
Export CSV Downloaded | Bulk Export CSV Download | test@example.com downloaded the CSV file. | test@example.com downloaded a CSV file. | |||
| devicecertificate preapprovecsvuploaded |
Approval CSV Uploaded | Bulk Registration CSV Upload | test@example.com uploaded the CSV file. | test@example.com uploaded a CSV file. | |||
| devicecertificate devicepreapproved |
Pre-approved | Auto-Approval | Activated device [DeviceName] for test@example.com | Approved device [DeviceName] for test@example.com. | |||
| Membership Division |
User | User | Added | Added to Group | Added to Group | test@example.com was added to the group GroupName | test@example.com was added to the GroupName group. |
| Removed | Removed from Group | Removed from Group | test@example.com was removed from the group GroupName | test@example.com was removed from the GroupName group. | |||
| otpcreatemembership | OTP added | OTP Enabled | OTP member allocation test@example.com | OTP was enabled for test@example.com. | |||
| successfully upsertusergroup |
successfully upserted | Created/Updated | UserGroup successfully created for user test@example.com | test@example.com was added to the group in [Box]. | |||
| successfully deleteusergroup |
successfully deleted | Delete | UserGroup successfully deleted for user test@example.com | Removed test@example.com from the group in [Box]. | |||
| failedupsertusergroup | failed to upsert | Created/Updated | UserGroup failed to upsert for user test@example.com | Failed to add test@example.com to the group in [Box]. | |||
| User | User | User | Signup | Signup | Sign-up | test@example.com user signed up to TrustLogin | test@example.com signed up for TrustLogin. |
| Division | Group | Group | Create | Created | Create | forLogcheck group created | Created the forLogcheck group. |
| Delete | Deleted | Delete | forLogcheck group deleted | Deleted the forLogcheck group. | |||
| Update | Updated | Update | CSVSGroup1 group updated | Updated the CSVSGroup1 group. | |||
| groupassignedtoconf | assigned to config | Created/Updated | Any2 assigned to config | Added to the Any2 service | |||
| successfullyupsertgroup | successfully upserted | Created/Updated | Any2 successfully upserted | Created/updated Any2 in [Box] | |||
| groupunassignedfromconf | unassigned from config | Delete | Any2 unassigned from config | Removed from the Any2 service | |||
| successfullydeletegroup | successfully deleted | Delete | Any2 successfully deleted | Deleted Any2 in [Box] | |||
| faileddeletegroup | failed to delete | Delete Failed | testg failed to delete | Failed to delete testg in [Box] | |||
| failedupsertgroup | failed to upsert | Create/Update Failed | 6U failed to upsert | Failed to create/update 6U in [Box] | |||
| RestrictedIp | IP | IP Restriction | Create | Created | Create | 0.0.0.1 IP created | Created setting 0.0.0.1. |
| Delete | Deleted | Delete | 0.0.0.2 IP deleted | Deleted setting 0.0.0.2. | |||
| ipfailure | Failure | Failure | Login from invalid IP ***.***.***.*** by test@example.com | Login from a disallowed IP address ***.***.***.***. test@example.com | |||
| Update | Updated | Update | ***.***.***.*** IP updated | Changed setting ***.***.***.***. | |||
| ipsuccess | Success | Success | Login from valid IP ***.***.***.*** by test@example.com | Login from an allowed IP address ***.***.***.***. test@example.com | |||
| Account | App | App | Accessed | Accessed | Used | 7904 FORROU App accessed | Used the 7904 FORROU app. |
| Create | Created | Create | Kindle Store[FG1] App created for test@example.com | Created the Kindle Store[FG1] app for test@example.com. | |||
| Shared | Shared | Shared | Kindle Store App shared for test@example.com | Shared the Kindle Store app with test@example.com. | |||
| mobileautofill | Accessed on Mobile | Used on Mobile | Autofill for 1 7936 - 259 Money Forward Cloud Accounting app used from mobile. | Performed autofill for the 1 7936 - 259 Money Forward Cloud Accounting app from mobile. | |||
| mobileaccountused | Accessed on Mobile | Used on Mobile | 7936 - 259 Money Forward Cloud Accounting app used from mobile. | Used the 7936 - 259 Money Forward Cloud Accounting app from mobile. | |||
| Delete | Deleted | Delete | ActionPassport (SAML)[Manual1] App removed from test@example.com | Deleted the ActionPassport (SAML)[Manual1] app from test@example.com. | |||
| Update | Updated | Update | BASIC Authentication Template kaiin App account updated | Updated the BASIC Authentication Template kaiin app. | |||
| update | Updated | Update | FREETEL App account updated | Updated the FREETEL app. | |||
| Unshared | Unshared | Sharing Removed | Apple Developer App unshared for test@example.com | Removed sharing of the Apple Developer app with test@example.com. | |||
| Restrictable | ipcreatedivision | IP restriction created | IP Restriction - Group Added | Group forLogcheck added to IP restriction 0.0.0.1 | Added forLogcheck to setting 0.0.0.1. | ||
| ipdeletemembership | IP restriction deleted | IP Restriction - Member Removed | Member test@example.com removed to IP restriction 0.0.0.1 | Removed test@example.com from setting 0.0.0.1. | |||
| ipdeletedivision | IP restriction removed | IP Restriction - Group Removed | Group forLogcheck removed to IP restriction 0.0.0.1 | Removed forLogcheck from setting 0.0.0.1. | |||
| DivisionAccount | App | App | Create | Created | Create | Kindle Store was added to the group FG1 | Kindle Store was added to the FG1 group. |
| Delete | Deleted | Delete | ActionPassport (SAML) was removed from the group Manual1 | ActionPassport (SAML) was removed from the Manual1 group. | |||
| Role | Role | Permission | Removed | Removed from Group | Removed from Group | test@example.com is no longer an admin | Set the permission of test@example.com to General. |
| Added | Added to Group | Added to Group | test@example.com became an admin | Set the permission of test@example.com to Administrator. | |||
| Profile | Profile | Profile | Update | Updated | Update | test@example.com profile updated | Updated the profile of test@example.com. |
| Certificate ValidationRule |
Client authentication | Client Authentication | certvalidation rulememberremoved |
User deleted | Member Removed | Deleted test@example.com from setting SKUID Client Certification | Removed test@example.com from the SKUID Client Certification setting. |
| certvalidationrulecreated | rule created | Rule Created | Setting test_ca2 cert created | Created the setting test_ca2 cert. | |||
| certvalidation rulememberadded |
User added | Member Added | Added test@example.com to setting SKUID Client Certification | Added test@example.com to the SKUID Client Certification setting. | |||
| certvalidation ruledivisionadded |
group added | Group Added | Added rs_jmt2 to setting SKUID Client Certification | Added rs_jmt2 to the SKUID Client Certification setting. | |||
| certvalidationruleedited | rule edited | Rule Updated | Setting SKUID Client Certification updated | Edited the SKUID Client Certification setting. | |||
| certvalidation ruledivisionremoved |
group deleted | Group Removed | Deleted rs_jmt2 from setting test_ca2 cert | Removed rs_jmt2 from the setting test_ca2 cert. | |||
| certvalidationruledeleted | rule deleted | Rule Deleted | Setting test_ca2 cert deleted | Deleted the setting test_ca2 cert. | |||
| Admin | Admin | Administrator | requestreset passwordforuser |
Initiate reset password for user | User Password Reset | Initiate reset password for test@example.com | Reset the TrustLogin password of test@example.com. |
| setpassword resetcodeforuser |
Set password reset code for user | User Password Reset Code Set | Set password reset code for test@example.com | Set the password reset code for test@example.com. | |||
| Setting | App | App | Create | Created | Create | 99designs0630 App setting created | Created the 99designs0630 app. |
| Delete | Deleted | Delete | Prod Bookmark Template App setting deleted | Deleted the Prod Bookmark Template app. | |||
| Update | Updated | Update | Prod freee Accounting Free_setApp005 App setting updated | Updated the Prod freee Accounting Free_setApp005 app. | |||
| BasicAuthSetting | App | App | Create | Created | Create | BASIC1 App setting created | Created the BASIC1 app. |
| Delete | Deleted | Delete | BASIC3 App setting deleted | Deleted the BASIC3 app. | |||
| Update | Updated | Update | BASIC Authentication Template App setting updated | Updated the BASIC Authentication Template app. | |||
| SamlIdpSetting | SAML App | SAML App | Create | Created | Create | ActionPassport (SAML) SAML App setting created | Created the ActionPassport (SAML) SAML app. |
| Update | Updated | Update | SAMLOwn1 SAML App setting updated | Updated the SAMLOwn1 SAML app. | |||
| Accessed | Accessed | Used | ActionPassport (SAML) SAML App accessed | Used the ActionPassport (SAML) SAML app. | |||
| Delete | Deleted | Delete | test SAML App setting deleted | Deleted the test SAML app. | |||
| mobilesettingaccessed | Accessed on Mobile | Used on Mobile | Salesforce (New SAML) SAML App accessed by mobile | Used the Salesforce (New SAML) SAML app from mobile. | |||
| enablesso | Update | Update | Microsoft 365 (SAML Auto Configuration) SAML SSO enabled | SAML SSO was enabled for Microsoft 365 (SAML Auto Configuration). | |||
| disablesso | Update | Update | Microsoft 365 (SAML Auto Configuration) SAML SSO disabled | SAML SSO was disabled for Microsoft 365 (SAML Auto Configuration). | |||
| AccountByAdmin | App | App | Create | Created | Create | 99designs0630 app created for test@example.com | Created the 99designs0630 app for test@example.com. |
| Delete | Deleted | Delete | 99designs0630 app removed for test@example.com | Deleted the 99designs0630 app for test@example.com. | |||
| Shared | Shared | Shared | Prod freee Accounting Free_admin6 App shared for test@example.com | Shared the Prod freee Accounting Free_admin6 app with test@example.com. | |||
| ReadOnlyAccount | App | App | Create | Created | Create | BASIC1 app created for test@example.com | Created the BASIC1 app for test@example.com. |
| Delete | Deleted | Delete | Basic3_adminBasic3 app removed for test@example.com | Deleted the Basic3_adminBasic3 app for test@example.com. | |||
| IpSamlRestriction | IP Group | IP Group | ipsaml restrictionappsadded |
App added | App Added | ActionPassport (SAML) has been added to IP Group. | ActionPassport (SAML) was added to the IP group. |
| ipsamlrestriction appsremoved |
App deleted | App Removed | ActionPassport (SAML) has been deleted from IP Group. | ActionPassport (SAML) was removed from the IP group. | |||
| ipsamlloginfailed | ipsaml restrictioncheckfailed |
IP restriction app failed | IP Restriction - App Usage Failure | The IP Address ***.***.***.*** can not be used with the app ActionPassport (SAML). | ActionPassport (SAML) cannot be used from this IP address ***.***.***.***. | ||
| SubscribedUser | otpcreatemembership | OTP added | OTP Enabled | OTP member allocation test@example.com | OTP was enabled for test@example.com. | ||
| otpdeletemembership | OTP removed | OTP Disabled | OTP member deleted test@example.com | OTP was disabled for test@example.com. | |||
| SubscribedDivision | otpcreatedivision | OTP added | OTP Enabled | OTP group added rs_jmt2 | OTP was enabled for rs_jmt2. | ||
| otpdeletedivision | OTP removed | OTP Disabled | OTP group deleted rs_jmt2 | OTP was disabled for rs_jmt2. | |||
| ClientCertificate | Client Certificate | Client Authentication | Create | Created | Create | test@example.com has downloaded their client certificate | test@example.com downloaded a certificate for their own use. |
| Revoke | Revoke | Revoke | test@example.com has revoked test@example.com's client certificate from the admin portal | test@example.com revoked their own certificate from the Admin Page. | |||
| Office365 Integration |
Office365 | Office365 | office365setup | Integration | Integration | Integration has been started | Office 365 Integration Started |
| office365setupfinished | Integration | Integration | Integration has been finished | Office 365 Integration Completed | |||
| office365useradded | User added | User Added | test@example.com was added to Office365 | Created test@example.com in Office 365. | |||
| office365userremoved | User removed | User Removed | test@example.com was removed from Office365 | Removed test@example.com from Office 365. | |||
| office365reset | Integration | Released | Integration has been reset. | Office 365 Integration Released | |||
| GsuiteIntegration | G Suite | G Suite | gsuitesetup | Integration | Integration | Integration has been started | G Suite Integration Started |
| gsuitesetupfinished | Integration | Integration | Integration has been finished | G Suite Integration Completed | |||
| gsuiteuseradded | User added | User Added | test@example.com was added to G Suite | Created test@example.com in G Suite. | |||
| gsuiteuserremoved | User removed | User Removed | test@example.com was removed from G Suite | Removed test@example.com from G Suite. | |||
| gsuitereset | Integration | Released | Integration has been reset. | G Suite Integration Released | |||
| Device | Device | Cookie Authentication Device | DeviceCreated | Created | Register | test@example.com has registered device test@example.com1 | test@example.com registered device test@example.com1. |
| DeviceDeleted | Deleted | Delete | test@example.com device test@example.com1 deleted | Deleted device test@example.com1 for test@example.com. | |||
| DesktopSsoConfig | Desktop SSO | Desktop SSO | desktopSso memeberadded |
User added | Member Added | test@example.com was added to Desktop SSO | Added test@example.com to Desktop SSO. |
| desktopSso memeberremoved |
User removed | Member Removed | test@example.com was removed from Desktop SSO | Removed test@example.com from Desktop SSO. | |||
| PushAuthConfig | Push Auth | Push Notification Authentication | pushauthmemberadded | User added | Member Added | test@example.com was added to Push Authentication | Added test@example.com to Push Notification Authentication. |
| pushauth memberremoved |
User removed | Member Removed | test@example.com was removed from Push Authentication | Removed test@example.com from Push Notification Authentication. | |||
| PushAuth Registration |
Push Auth | Push Notification Authentication | PushAuth DeviceRemoved |
device removed | Device Removed | test@example.com push auth device gs_sk's iPhone deleted | Deleted the push notification authentication device gs_sk's iPhone for test@example.com. |
| AssignedUser | fidoprimary createmembership |
FIDO auth created | FIDO Authentication - Member Added | FIDO member allocation test@example.com | Added test@example.com to FIDO Authentication. | ||
| fidoprimary deletemembership |
FIDO auth deleted | FIDO Authentication - Member Removed | FIDO member deleted test@example.com | Removed test@example.com from FIDO Authentication. | |||
| AssignedDivision | fidoprimary createdivision |
FIDO auth created | FIDO Authentication - Group Added | FIDO group added rs_jmt2 | Added rs_jmt2 to FIDO Authentication. | ||
| fidoprimary deletedivision |
FIDO auth deleted | FIDO Authentication - Group Removed | FIDO group deleted 1124 | Removed 1124 from FIDO Authentication. | |||
| Config | Config | Identity Provisioning Service | confcreated | created | Create | Config created | The identity provisioning service was added |
| confupdated | updated | Update | Config updated | The identity provisioning service was updated | |||
| ScimProvisioner | SCIM Provisioner | SCIM Provisioner | create | Created | Create | SCIM test created | Created SCIM test. |
| renewkey | Authentication key generation | Authentication Key Updated | SCIM test credential generated | Updated the authentication key for SCIM test. | |||
| delete | Deleted | Delete | SCIM test deleted | Deleted SCIM test. | |||
| FidoPrimary Authenticator |
FIDO Authenticator | FIDO Authenticator | fidoprimary authenticatordeleted |
deleted | Delete | test@example.com FIDO authenticator [f] deleted | test@example.com deleted the FIDO authenticator [f]. |
| fidoprimar yauthenticatorcreated |
created | Register | test@example.com FIDO authenticator [y] created | test@example.com registered the FIDO authenticator [y]. | |||
| fidoprimary authenticatorupdated |
updated | Update | test@example.com FIDO authenticator [yubico] updated | test@example.com updated the FIDO authenticator [yubico]. | |||
| FidoPrimaryConfig | FIDO Settings | fidoprimary assignmentcsvexported |
FIDO auth CSV generated | Authenticator List CSV Generation Success | FIDO auth test@example.com CSV generated | test@example.com successfully generated the FIDO authenticator list CSV. | |
| fidoprimary assignmentcsvdownloaded |
FIDO auth CSV downloaded | Authenticator List CSV Download Success | FIDO auth test@example.com CSV downloaded | test@example.com successfully downloaded the FIDO authenticator list CSV. | |||
| fidoprimary registrationcsvgenerated |
FIDO registration CSV generated | Authenticator Registration URL CSV Generation Success | FIDO registration test@example.com CSV generated | test@example.com successfully generated the FIDO authenticator registration URL CSV. | |||
| SIEMToken | SIEM Client | SIEM Client | siemtokencreated | created | Create | SIEM client eugene_test1 created | SIEM client eugene_test1 was created |
| siemtokenregenerated | regenerated | Regenerate | SIEM client eugene_test1 token regenerated | The authentication token for SIEM client eugene_test1 was regenerated | |||
| siemtokenrevoked | revoked | Delete | SIEM client eugene_test1 deleted | SIEM client eugene_test1 was deleted | |||
| CustomAccount | Custom App | Custom App | createcustomaccount | Created | Create | HRMOS Expense Personal Custom App Created | Created a personal custom app for HRMOS Expense. |
| CustomService | Custom App | Custom App | createcustomservice | Created | Create | ShopeeTestCustom1 Company Custom App Created | Created the in-house custom app ShopeeTestCustom1. |