| AcceptLanguage |
- Type
- string
- Properties
- Nillable
- Description
- List of HTTP Headers that specify the natural language, such as English, that the client understands.
- Example
- zh, en-US;q=0.8, en;q=0.6
|
| EventDate |
- Type
- dateTime
- Properties
- Nillable
- Description
- The time when the hijacking event was reported. For example, 2020-01-20T19:12:26.965Z. Milliseconds are the most granular setting.
|
| EventIdentifier |
- Type
- string
- Properties
- Nillable
- Description
- The unique ID of the event. For example, 0a4779b0-0da1-4619-a373-0a36991dff90.
|
| LoginKey |
- Type
- string
- Properties
- Nillable
- Description
- The string that ties together all events in a given user’s
login session. The session starts with a login event and ends with either a
logout event or the user session expiring.
For example, lUqjLPQTWRdvRG4.
|
| LoginType |
- Type
- picklist
- Properties
- Nillable, Restricted picklist
- Description
-
The type of login used to access
the session. Possible values are:
- AJAX
Toolkit
- Apex Office
Toolkit
- AppExchange
- Application
- AppStore
- Certificate-based
login
- Chatter Communities
Eternal User Third Party SSO
- Chatter Communities
External User
- Community
- Customer Service
Portal Third-Party SSO
- Customer Service
Portal
- DataJunction
- DB
Replication
- Employee Login to
Community
- Excel
Integration
- Help and
Training
- HOTP
YubiKey
- Lightning
Login
- Networks Portal API
Only
- Offline
Client
- Order
Center
- Other Apex
API
- Outlook
Integration
- Partner Portal
Third-Party SSO
- Partner
Portal
- Partner
Product
- Passwordless
Login
- Remote Access
2.0
- Remote Access
Client
- Sales
Anywhere
- Salesforce Outlook
Integration
- Salesforce.com
Website
- SAML Chatter
Communities External User SSO
- SAML Customer
Service Portal SSO
- SAML Idp Initiated
SSO
- SAML Partner Portal
SSO
- SAML Sfdc Initiated
SSO
- SAML Site
SSO
- Self-Service
- Signup
- Sync
- SysAdmin
Switch
- Third Party
SSO
- Validate
|
| LoginUrl |
- Type
- string
- Properties
- Nillable
- Description
- The URL of the login page. For example, login.salesforce.com.
|
| ReplayId |
- Type
- string
- Properties
- Nillable
- Description
- Represents an ID value that is populated by the system
and refers to the position of the event in the event stream. Replay ID values
aren’t guaranteed to be contiguous for consecutive events. A subscriber can
store a replay ID value and use it on resubscription to retrieve missed events
that are within the retention window.
|
| Score |
- Type
- double
- Properties
- Nillable
- Description
- Indicates that a user successfully logged into Salesforce during an identified credential stuffing attack. The value of this field is always 1.
|
| SessionKey |
- Type
- string
- Properties
- Nillable
- Description
- The user’s unique session ID. Use this value to identify
all user events within a session. When a user logs out and logs in again, a new
session is started.
For example, vMASKIU6AxEr+Op5.
|
| SourceIp |
- Type
- string
- Properties
- Nillable
- Description
- The source IP address of the unauthorized user that successfully logged in after the
credential stuffing attack. For example, 126.7.4.2.
|
| UserAgent |
- Type
- string
- Properties
- Nillable
- Description
- The User-Agent header of the HTTP request of the unauthorized login. For example,
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36.
|
| UserId |
- Type
- reference
- Properties
- Nillable
- Description
- The origin user’s unique ID. For example, 005000000000123.
|
| Username |
- Type
- string
- Properties
- Nillable
- Description
- The origin username in the format of
user@company.com at the time
the event was created.
|