| EventDate |
- Type
- dateTime
- Properties
- Filter, Sort
- Description
- Required. The time when the anomaly was reported. For example, 2020-01-20T19:12:26.965Z. Milliseconds are the most granular setting.
|
| EventIdentifier |
- Type
- string
- Properties
- Filter, Group, Sort
- Description
- Required. The unique ID of the event. For example,
0a4779b0-0da1-4619-a373-0a36991dff90.
|
| LoginKey |
- Type
- string
- Properties
- Group, Nillable, Sort
- Description
- The string that ties together all events in a given user’s
login session. The session starts with a login event and ends with either a
logout event or the user session expiring.
For example, lUqjLPQTWRdvRG4.
|
| Report |
- Type
- string
- Properties
- Group, Nillable, Sort
- Description
- The report ID for the report for which this anomaly event was detected. For example,
00OD0000001leVCMAY.
If this anomaly
resulted from a user executing an unsaved report,
the value of this field is null.
|
| Score |
- Type
- double
- Properties
- Nillable, Sort
- Description
- A number from 0 through 100 that represents the anomaly score for the report execution
or export tracked by this event. The anomaly score shows
how the user's current report activity is different from
their typical activity. A low score indicates that the
user's current report activity is similar to their usual
activity, a high score indicates that it's different.
|
| SecurityEventData |
- Type
- textarea
- Properties
- Nillable
- Description
- The set of features about the report activity that
triggered this anomaly event. While there are many
features that can trigger the event, this field contains
only the top five contributing ones.
Let’s say, for
example, that a user typically downloads 10 accounts
but then they deviate from that pattern and download
1,000 accounts. This event is triggered and the
contributing features are captured in this field.
Potential features include row count, column count,
average row size, the day of week, and the browser
used for the report activity. The data captured in
this field also shows how much a particular feature
contributed to this anomaly event being triggered,
represented as a percentage. The data is in JSON
format.
- Example
- This example shows that the average row count contributed more than 95% to the anomaly
being triggered. Other anomalous attributes, such as the
autonomous system, day of the week the report was run,
the browser used, and the number of columns, contributed
much
less.
1'contributions': [
2 {'featureContribution': '95.31 %',
3 'featureName': 'rowCount',
4 'featureValue': '584518'},
5 {'featureContribution': '2.00 %',
6 'featureName': 'autonomousSystem',
7 'featureValue': '53813'},
8 {'featureContribution': '1.42 %',
9 'featureName': 'dayOfWeek',
10 'featureValue': 'Tuesday'},
11 {'featureContribution': '1.21 %',
12 'featureName': 'userAgent',
13 'featureValue': 'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.132 Safari/537.36'},
14 {'featureContribution': '0.06 %',
15 'featureName': 'numberColumns',
16 'featureValue': '22'}]
|
| SessionKey |
- Type
- string
- Properties
- Filter, Group, Nillable, Sort
- Description
- The user’s unique session ID. Use this value to identify
all user events within a session. When a user logs out and logs in again, a new
session is started.
For example, vMASKIU6AxEr+Op5.
|
| SourceIp |
- Type
- string
- Properties
- Filter, Group, Nillable, Sort
- Description
- The source IP address of the client that logged in. For example,
126.7.4.2.
|
| UserId |
- Type
- reference
- Properties
- Filter, Group, Nillable, Sort
- Description
- The origin user’s unique ID. For example, 005000000000123.
|
| Username |
- Type
- string
- Properties
- Filter, Group, Nillable, Sort
- Description
- The origin username in the format of user@company.com at the time the
event was created.
|