Skip to main content

Event Types

All 551 events with OCSF mappings, grouped by Directory Insights service — same layout as the Directory Insights API event-type lists.

Services#

Access Management#

access_management · 7 events

Event Category Class Activity Type UID Fields
access_management_access_request Identity & Access Management (3) Entity Management (3004) Create (1) 300401 73
access_management_access_request_approval Identity & Access Management (3) Entity Management (3004) Update (3) 300403 80
access_management_access_request_settings_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 74
access_management_approval_flow_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 83
access_management_approval_flow_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 74
access_management_approval_flow_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 74
access_management_association_change Identity & Access Management (3) Entity Management (3004) Update (3) 300403 82

OCSF field mappings#

Legend

  • Description: what the OCSF field represents (from OCSF schema v1.8.0)
  • Source: raw JumpCloud event field(s) mapped via ${{placeholder}} template
  • Transform: fieldMappings entry applied at runtime (cast, enum, etc.)
  • Literal: static value set in the mapping template
  • Usage: event types in this service that include this field

Core

activity_id
  • Description: The normalized identifier of the activity that triggered the event.
  • Literal: 1, 3, 4
  • Usage: all events in this service
activity_name
  • Description: The event activity name, as defined by the activity_id.
  • Literal: Create, Delete, Update
  • Usage: all events in this service
category_name
  • Description: The event category name, as defined by category_uid value: Discovery.
  • Literal: Identity & Access Management
  • Usage: all events in this service
category_uid
  • Description: The category unique identifier of the event.
  • Literal: 3
  • Usage: all events in this service
class_name
  • Description: The event class name, as defined by class_uid value: User Inventory Info.
  • Literal: Entity Management
  • Usage: all events in this service
class_uid
  • Description: The unique identifier of a class. A class describes the attributes available in an event.
  • Literal: 3004
  • Usage: all events in this service
severity_id
  • Description: OCSF severity identifier for the event.
  • Literal: 1
  • Usage: all events in this service
status_detail
  • Description: The status detail contains additional information about the event/finding outcome.
  • Source: error_message
  • Usage: all events in this service
status_id
  • Description: Normalized status of the activity (1=Success, 2=Failure).
  • Source: success
  • Transform:
  • success → boolean_to_status_id; true→1, false→2 (all events in this service)
  • Usage: all events in this service
time
  • Description: Event time, in epoch milliseconds (OCSF time).
  • Source: timestamp
  • Transform:
  • timestamp → iso8601_to_epoch_millis (all events in this service)
  • Usage: all events in this service
type_uid
  • Description: The event/finding type ID. It identifies the event's semantics and structure. The value is calculated by the logging system as: class_uid * 100 + activity_id.
  • Literal: 300401, 300403, 300404
  • Usage: all events in this service

Metadata

metadata.event_code
  • Description: JumpCloud event type code.
  • Source: event_type
  • Usage: all events in this service
metadata.original_time
  • Description: The original event time as reported by the event source. For example, the time in the original format from system event log such as Syslog on Unix/Linux and the System event file on Windows. Omit if event is generated instead of collected via logs.
  • Source: server_timestamp
  • Usage: all events in this service
metadata.product.name
  • Description: Originating JumpCloud service that produced the event.
  • Source: service
  • Usage: all events in this service
metadata.tenant_uid
  • Description: JumpCloud organization (tenant) identifier.
  • Source: organization
  • Usage: all events in this service
metadata.uid
  • Description: Unique event identifier assigned by JumpCloud.
  • Source: id
  • Usage: all events in this service
metadata.version
  • Description: OCSF schema version used for this event.
  • Literal: 1.8.0
  • Usage: all events in this service

Actor

actor.user.email_addr
  • Description: Email address of the actor who initiated the event.
  • Source: initiated_by.email
  • Usage: access_management_access_request_approval, access_management_access_request_settings_update, access_management_approval_flow_create, access_management_approval_flow_delete, access_management_approval_flow_update, access_management_association_change
actor.user.name
  • Description: Display name of the actor who initiated the event.
  • Source: initiated_by.name, initiated_by.username
  • Usage: access_management_access_request, access_management_access_request_approval, access_management_approval_flow_create
actor.user.type_id
  • Description: OCSF user type of the actor (1=User, 2=Admin, 3=System, 4=Service).
  • Source: initiated_by.type
  • Transform:
  • initiated_by.type → enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (all events in this service)
  • Usage: all events in this service
actor.user.uid
  • Description: Unique identifier of the actor who initiated the event.
  • Source: initiated_by.id
  • Usage: all events in this service

Entity

entity.data.access_request_id
  • Description: JumpCloud extension data on the managed entity: access_request_id.
  • Source: access_request_id
  • Usage: access_management_access_request_approval, access_management_association_change
entity.data.association_attributes
  • Description: JumpCloud extension data on the managed entity: association_attributes.
  • Source: association.attributes
  • Usage: access_management_association_change
entity.data.association_from_name
  • Description: JumpCloud extension data on the managed entity: association_from_name.
  • Source: association.connection.from.name
  • Usage: access_management_association_change
entity.data.association_from_object_id
  • Description: JumpCloud extension data on the managed entity: association_from_object_id.
  • Source: association.connection.from.object_id
  • Usage: access_management_association_change
entity.data.association_from_type
  • Description: JumpCloud extension data on the managed entity: association_from_type.
  • Source: association.connection.from.type
  • Usage: access_management_association_change
entity.data.association_op
  • Description: JumpCloud extension data on the managed entity: association_op.
  • Source: association.op
  • Usage: access_management_association_change
entity.data.association_to_name
  • Description: JumpCloud extension data on the managed entity: association_to_name.
  • Source: association.connection.to.name
  • Usage: access_management_association_change
entity.data.association_to_object_id
  • Description: JumpCloud extension data on the managed entity: association_to_object_id.
  • Source: association.connection.to.object_id
  • Usage: access_management_association_change
entity.data.association_to_type
  • Description: JumpCloud extension data on the managed entity: association_to_type.
  • Source: association.connection.to.type
  • Usage: access_management_association_change
entity.data.changed_field
  • Description: JumpCloud extension data on the managed entity: changed_field.
  • Source: changes.field
  • Usage: all events in this service
entity.data.changes_from
  • Description: JumpCloud extension data on the managed entity: changes_from.
  • Source: changes.from
  • Usage: access_management_access_request, access_management_access_request_approval, access_management_access_request_settings_update, access_management_approval_flow_create, access_management_approval_flow_delete, access_management_association_change
entity.data.changes_from_LdapGroups_name
  • Description: JumpCloud extension data on the managed entity: changes_from_LdapGroups_name.
  • Source: changes.from.LdapGroups.name
  • Usage: access_management_approval_flow_update
entity.data.initiated_from_slack_app_id
  • Description: JumpCloud extension data on the managed entity: initiated_from_slack_app_id.
  • Source: initiated_from.slack.app_id
  • Usage: access_management_access_request_approval
entity.data.initiated_from_slack_source
  • Description: JumpCloud extension data on the managed entity: initiated_from_slack_source.
  • Source: initiated_from.slack.source
  • Usage: access_management_access_request_approval
entity.data.initiated_from_slack_team_id
  • Description: JumpCloud extension data on the managed entity: initiated_from_slack_team_id.
  • Source: initiated_from.slack.team_id
  • Usage: access_management_access_request_approval
entity.data.initiated_from_slack_user_id
  • Description: JumpCloud extension data on the managed entity: initiated_from_slack_user_id.
  • Source: initiated_from.slack.user_id
  • Usage: access_management_access_request_approval
entity.data.resource_id
  • Description: JumpCloud extension data on the managed entity: resource_id.
  • Source: resource.id
  • Usage: access_management_access_request
entity.data.resource_type
  • Description: JumpCloud extension data on the managed entity: resource_type.
  • Source: resource.type
  • Usage: access_management_access_request
entity.data.workflow.description
  • Description: JumpCloud extension data on the managed entity: workflow.description.
  • Source: workflow.description
  • Usage: access_management_access_request, access_management_access_request_approval, access_management_approval_flow_create, access_management_approval_flow_delete, access_management_approval_flow_update, access_management_association_change
entity.data.workflow.id
  • Description: JumpCloud extension data on the managed entity: workflow.id.
  • Source: workflow.id
  • Usage: access_management_access_request, access_management_access_request_approval, access_management_approval_flow_create, access_management_approval_flow_delete, access_management_approval_flow_update, access_management_association_change
entity.data.workflow.name
  • Description: JumpCloud extension data on the managed entity: workflow.name.
  • Source: workflow.name
  • Usage: access_management_access_request, access_management_access_request_approval, access_management_approval_flow_create, access_management_approval_flow_delete, access_management_approval_flow_update, access_management_association_change
entity.data.workflow.type
  • Description: JumpCloud extension data on the managed entity: workflow.type.
  • Source: workflow.type
  • Usage: access_management_access_request, access_management_access_request_approval, access_management_approval_flow_create, access_management_approval_flow_delete, access_management_approval_flow_update, access_management_association_change
entity.name
  • Description: The name of the managed entity. It should match the name of the specific entity object's name if populated, or the name of the managed entity if the type_id is 'Other'.
  • Source: resource.name
  • Usage: access_management_access_request_settings_update, access_management_approval_flow_create, access_management_approval_flow_delete, access_management_approval_flow_update
entity.type
  • Description: The managed entity type. For example: Policy, User, Organization, Device.
  • Source: resource.type
  • Usage: access_management_access_request_approval, access_management_access_request_settings_update, access_management_approval_flow_create, access_management_approval_flow_delete, access_management_approval_flow_update, access_management_association_change
entity.uid
  • Description: The identifier of the managed entity. It should match the uid of the specific entity's object UID if populated, or the source specific ID if the type_id is 'Other'.
  • Source: access_request_id, resource.id
  • Usage: all events in this service
entity_result.data.changes_to
  • Description: JumpCloud extension data on the managed entity: changes_to.
  • Source: changes.to
  • Usage: access_management_access_request, access_management_access_request_approval, access_management_access_request_settings_update, access_management_association_change
entity_result.data.changes_to_LdapGroups_name
  • Description: JumpCloud extension data on the managed entity: changes_to_LdapGroups_name.
  • Source: changes.to.LdapGroups.name
  • Usage: access_management_approval_flow_create, access_management_approval_flow_delete, access_management_approval_flow_update

Src Endpoint

src_endpoint.autonomous_system.name
  • Description: Organization name for the Autonomous System.
  • Source: asn.organization
  • Usage: all events in this service
src_endpoint.autonomous_system.number
  • Description: Unique number that the AS is identified by.
  • Source: asn.number
  • Transform:
  • asn.number → int (all events in this service)
  • Usage: all events in this service
src_endpoint.ip
  • Description: Source IP address the request originated from.
  • Source: client_ip
  • Usage: all events in this service
src_endpoint.location.city
  • Description: The name of the city.
  • Source: location.City.Name
  • Usage: all events in this service
src_endpoint.location.continent
  • Description: The name of the continent.
  • Source: geoip.continent_code
  • Usage: all events in this service
src_endpoint.location.country
  • Description: The ISO 3166-1 Alpha-2 country code.

    Note: The two letter country code should be capitalized. For example: US or CA.

  • Source: location.Country.IsoCode
  • Usage: all events in this service
src_endpoint.location.lat
  • Description: The geographical Latitude coordinate represented in Decimal Degrees (DD). For example: 42.361145.
  • Source: geoip.latitude
  • Transform:
  • geoip.latitude → double (all events in this service)
  • Usage: all events in this service
src_endpoint.location.long
  • Description: The geographical Longitude coordinate represented in Decimal Degrees (DD). For example: -71.057083.
  • Source: geoip.longitude
  • Transform:
  • geoip.longitude → double (all events in this service)
  • Usage: all events in this service
src_endpoint.location.region
  • Description: The alphanumeric code that identifies the principal subdivision (e.g. province or state) of the country. For example, 'CH-VD' for the Canton of Vaud, Switzerland
  • Source: location.Subdivisions.IsoCode
  • Usage: all events in this service

Http Request

http_request.user_agent
  • Description: The request header that identifies the operating system and web browser.
  • Source: user_agent
  • Usage: all events in this service

Observables

observables[].name
  • Description: The full name of the observable attribute. The name is a pointer/reference to an attribute within the OCSF event data. For example: file.name. Array attributes may be represented in one of three ways. For example: resources.uid, resources[].uid, resources[0].uid.
  • Literal: actor.user.email_addr, actor.user.name, actor.user.uid, http_request.user_agent, src_endpoint.ip, src_endpoint.location.country
  • Usage: all events in this service
observables[].type_id
  • Description: The observable value type identifier.
  • Literal: 14, 16, 2, 31, 4, 5
  • Usage: all events in this service
observables[].value
  • Description: The value associated with the observable attribute. The meaning of the value depends on the observable type.
    If the name refers to a scalar attribute, then the value is the value of the attribute.
    If the name refers to an object attribute, then the value is not populated.
  • Source: client_ip, geoip.country_code, initiated_by.email, initiated_by.id, initiated_by.name, initiated_by.username, location.Country.IsoCode, user_agent
  • Usage: all events in this service

Unmapped

unmapped.@timestamp
  • Description: JumpCloud Directory Insights field @timestamp preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: @timestamp
  • Usage: access_management_access_request, access_management_access_request_approval, access_management_access_request_settings_update, access_management_approval_flow_create, access_management_association_change
unmapped.@version
  • Description: JumpCloud Directory Insights field @version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: @version
  • Usage: all events in this service
unmapped.asn.network
  • Description: JumpCloud Directory Insights field asn.network preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: asn.network
  • Usage: all events in this service
unmapped.file_input_timestamp
  • Description: JumpCloud Directory Insights field file_input_timestamp preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: file_input_timestamp
  • Usage: access_management_access_request, access_management_access_request_approval, access_management_access_request_settings_update, access_management_approval_flow_create, access_management_association_change
unmapped.geoip.region_name
  • Description: JumpCloud Directory Insights field geoip.region_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.region_name
  • Usage: all events in this service
unmapped.geoip.timezone
  • Description: JumpCloud Directory Insights field geoip.timezone preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.timezone
  • Usage: all events in this service
unmapped.initiated_by.source_metadata.workflow.id
  • Description: JumpCloud Directory Insights field initiated_by.source_metadata.workflow.id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by.source_metadata.workflow.id
  • Usage: access_management_approval_flow_create
unmapped.initiated_by.source_metadata.workflow.run_id
  • Description: JumpCloud Directory Insights field initiated_by.source_metadata.workflow.run_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by.source_metadata.workflow.run_id
  • Usage: access_management_approval_flow_create
unmapped.initiated_by.source_metadata.workflow.type
  • Description: JumpCloud Directory Insights field initiated_by.source_metadata.workflow.type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by.source_metadata.workflow.type
  • Usage: access_management_approval_flow_create
unmapped.initiated_by_email_hash
  • Description: JumpCloud Directory Insights field initiated_by_email_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_email_hash
  • Usage: access_management_access_request_approval, access_management_access_request_settings_update, access_management_approval_flow_create, access_management_approval_flow_delete, access_management_approval_flow_update, access_management_association_change
unmapped.initiated_by_id_hash
  • Description: JumpCloud Directory Insights field initiated_by_id_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_id_hash
  • Usage: all events in this service
unmapped.initiated_by_name_hash
  • Description: JumpCloud Directory Insights field initiated_by_name_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_name_hash
  • Usage: access_management_approval_flow_create
unmapped.initiated_by_username_hash
  • Description: JumpCloud Directory Insights field initiated_by_username_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_username_hash
  • Usage: access_management_access_request, access_management_access_request_approval
unmapped.is_out_of_bound
  • Description: JumpCloud Directory Insights field is_out_of_bound preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: is_out_of_bound
  • Usage: all events in this service
unmapped.jc_application_name
  • Description: JumpCloud Directory Insights field jc_application_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_application_name
  • Usage: all events in this service
unmapped.jc_index_name
  • Description: JumpCloud Directory Insights field jc_index_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_index_name
  • Usage: access_management_access_request_approval, access_management_association_change
unmapped.jc_initiated_by_email
  • Description: JumpCloud Directory Insights field jc_initiated_by_email preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_initiated_by_email
  • Usage: access_management_access_request_settings_update, access_management_approval_flow_create, access_management_approval_flow_delete, access_management_approval_flow_update
unmapped.jc_initiated_by_username
  • Description: JumpCloud Directory Insights field jc_initiated_by_username preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_initiated_by_username
  • Usage: access_management_access_request_settings_update, access_management_approval_flow_create, access_management_approval_flow_delete, access_management_approval_flow_update
unmapped.jc_organization_name
  • Description: JumpCloud Directory Insights field jc_organization_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_organization_name
  • Usage: access_management_access_request_settings_update, access_management_approval_flow_create, access_management_approval_flow_delete, access_management_approval_flow_update
unmapped.jc_provider_id
  • Description: JumpCloud Directory Insights field jc_provider_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_provider_id
  • Usage: access_management_access_request_settings_update, access_management_approval_flow_create, access_management_approval_flow_delete, access_management_approval_flow_update
unmapped.jc_transformation_ts
  • Description: JumpCloud Directory Insights field jc_transformation_ts preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_transformation_ts
  • Usage: all events in this service
unmapped.location.Country.Name
  • Description: JumpCloud Directory Insights field location.Country.Name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: location.Country.Name
  • Usage: all events in this service
unmapped.location.Subdivisions.Name
  • Description: JumpCloud Directory Insights field location.Subdivisions.Name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: location.Subdivisions.Name
  • Usage: all events in this service
unmapped.pid
  • Description: JumpCloud Directory Insights field pid preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: pid
  • Usage: all events in this service
unmapped.provider
  • Description: JumpCloud Directory Insights field provider preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: provider
  • Usage: access_management_access_request_settings_update, access_management_approval_flow_create
unmapped.resource_id_hash
  • Description: JumpCloud Directory Insights field resource_id_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource_id_hash
  • Usage: access_management_access_request, access_management_access_request_approval, access_management_approval_flow_create, access_management_approval_flow_delete, access_management_approval_flow_update, access_management_association_change
unmapped.tags
  • Description: JumpCloud Directory Insights field tags preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: tags
  • Usage: access_management_access_request, access_management_access_request_approval, access_management_access_request_settings_update, access_management_approval_flow_create, access_management_association_change
unmapped.timestamp_source
  • Description: JumpCloud Directory Insights field timestamp_source preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: timestamp_source
  • Usage: all events in this service
unmapped.useragent.device
  • Description: JumpCloud Directory Insights field useragent.device preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.device
  • Usage: all events in this service
unmapped.useragent.major
  • Description: JumpCloud Directory Insights field useragent.major preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.major
  • Usage: all events in this service
unmapped.useragent.minor
  • Description: JumpCloud Directory Insights field useragent.minor preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.minor
  • Usage: all events in this service
unmapped.useragent.name
  • Description: JumpCloud Directory Insights field useragent.name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.name
  • Usage: all events in this service
unmapped.useragent.os
  • Description: JumpCloud Directory Insights field useragent.os preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os
  • Usage: all events in this service
unmapped.useragent.os_full
  • Description: JumpCloud Directory Insights field useragent.os_full preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_full
  • Usage: all events in this service
unmapped.useragent.os_major
  • Description: JumpCloud Directory Insights field useragent.os_major preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_major
  • Usage: all events in this service
unmapped.useragent.os_minor
  • Description: JumpCloud Directory Insights field useragent.os_minor preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_minor
  • Usage: all events in this service
unmapped.useragent.os_name
  • Description: JumpCloud Directory Insights field useragent.os_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_name
  • Usage: all events in this service
unmapped.useragent.os_patch
  • Description: JumpCloud Directory Insights field useragent.os_patch preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_patch
  • Usage: all events in this service
unmapped.useragent.os_version
  • Description: JumpCloud Directory Insights field useragent.os_version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_version
  • Usage: all events in this service
unmapped.useragent.patch
  • Description: JumpCloud Directory Insights field useragent.patch preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.patch
  • Usage: all events in this service
unmapped.useragent.version
  • Description: JumpCloud Directory Insights field useragent.version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.version
  • Usage: all events in this service
unmapped.workflow
  • Description: JumpCloud Directory Insights field workflow preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: workflow
  • Usage: access_management_access_request_settings_update

AI Admin#

ai_admin · 6 events

Event Category Class Activity Type UID Fields
redirect_uri_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 54
redirect_uri_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 56
redirect_uri_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 60
server_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 63
server_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 58
server_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 68

OCSF field mappings#

Legend

  • Description: what the OCSF field represents (from OCSF schema v1.8.0)
  • Source: raw JumpCloud event field(s) mapped via ${{placeholder}} template
  • Transform: fieldMappings entry applied at runtime (cast, enum, etc.)
  • Literal: static value set in the mapping template
  • Usage: event types in this service that include this field

Core

activity_id
  • Description: The normalized identifier of the activity that triggered the event.
  • Literal: 1, 3, 4
  • Usage: all events in this service
activity_name
  • Description: The event activity name, as defined by the activity_id.
  • Literal: Create, Delete, Update
  • Usage: all events in this service
category_name
  • Description: The event category name, as defined by category_uid value: Discovery.
  • Literal: Identity & Access Management
  • Usage: all events in this service
category_uid
  • Description: The category unique identifier of the event.
  • Literal: 3
  • Usage: all events in this service
class_name
  • Description: The event class name, as defined by class_uid value: User Inventory Info.
  • Literal: Entity Management
  • Usage: all events in this service
class_uid
  • Description: The unique identifier of a class. A class describes the attributes available in an event.
  • Literal: 3004
  • Usage: all events in this service
severity_id
  • Description: OCSF severity identifier for the event.
  • Literal: 1
  • Usage: all events in this service
status_id
  • Description: Normalized status of the activity (1=Success, 2=Failure).
  • Source: success
  • Transform:
  • success → boolean_to_status_id; true→1, false→2 (all events in this service)
  • Usage: all events in this service
time
  • Description: Event time, in epoch milliseconds (OCSF time).
  • Source: timestamp
  • Transform:
  • timestamp → iso8601_to_epoch_millis (all events in this service)
  • Usage: all events in this service
type_uid
  • Description: The event/finding type ID. It identifies the event's semantics and structure. The value is calculated by the logging system as: class_uid * 100 + activity_id.
  • Literal: 300401, 300403, 300404
  • Usage: all events in this service

Metadata

metadata.event_code
  • Description: JumpCloud event type code.
  • Source: event_type
  • Usage: all events in this service
metadata.product.name
  • Description: Originating JumpCloud service that produced the event.
  • Source: service
  • Usage: all events in this service
metadata.tenant_uid
  • Description: JumpCloud organization (tenant) identifier.
  • Source: organization
  • Usage: all events in this service
metadata.uid
  • Description: Unique event identifier assigned by JumpCloud.
  • Source: id
  • Usage: all events in this service
metadata.version
  • Description: OCSF schema version used for this event.
  • Literal: 1.8.0
  • Usage: all events in this service

Actor

actor.user.email_addr
  • Description: Email address of the actor who initiated the event.
  • Source: initiated_by.email
  • Usage: all events in this service
actor.user.type_id
  • Description: OCSF user type of the actor (1=User, 2=Admin, 3=System, 4=Service).
  • Source: initiated_by.type
  • Transform:
  • initiated_by.type → enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (all events in this service)
  • Usage: all events in this service
actor.user.uid
  • Description: Unique identifier of the actor who initiated the event.
  • Source: initiated_by.id
  • Usage: all events in this service

Entity

entity.data.application_id
  • Description: JumpCloud extension data on the managed entity: application_id.
  • Source: resource.application_id
  • Usage: server_create, server_update
entity.data.auth_config.api_token
  • Description: JumpCloud extension data on the managed entity: auth_config.api_token.
  • Source: resource.auth_config.api_token
  • Usage: server_create, server_update
entity.data.auth_config.oauth.client_id
  • Description: JumpCloud extension data on the managed entity: auth_config.oauth.client_id.
  • Source: resource.auth_config.oauth.client_id
  • Usage: server_create, server_update
entity.data.auth_config.oauth.client_secret
  • Description: JumpCloud extension data on the managed entity: auth_config.oauth.client_secret.
  • Source: resource.auth_config.oauth.client_secret
  • Usage: server_update
entity.data.auth_config.oauth.client_secret_hint
  • Description: JumpCloud extension data on the managed entity: auth_config.oauth.client_secret_hint.
  • Source: resource.auth_config.oauth.client_secret_hint
  • Usage: server_create, server_update
entity.data.auth_config.oauth.scope
  • Description: JumpCloud extension data on the managed entity: auth_config.oauth.scope.
  • Source: resource.auth_config.oauth.scope
  • Usage: server_create, server_update
entity.data.auth_method
  • Description: JumpCloud extension data on the managed entity: auth_method.
  • Source: auth_method
  • Usage: all events in this service
entity.data.changed_field
  • Description: JumpCloud extension data on the managed entity: changed_field.
  • Source: changes.field
  • Usage: redirect_uri_delete, redirect_uri_update, server_delete, server_update
entity.data.changes_from
  • Description: JumpCloud extension data on the managed entity: changes_from.
  • Source: changes.from
  • Usage: redirect_uri_delete, redirect_uri_update, server_update
entity.data.changes_from_api_token
  • Description: JumpCloud extension data on the managed entity: changes_from_api_token.
  • Source: changes.from.api_token
  • Usage: server_delete
entity.data.changes_from_oauth
  • Description: JumpCloud extension data on the managed entity: changes_from_oauth.
  • Source: changes.from.oauth
  • Usage: server_delete
entity.data.description
  • Description: JumpCloud extension data on the managed entity: description.
  • Source: resource.description
  • Usage: redirect_uri_update
entity.data.prefix
  • Description: JumpCloud extension data on the managed entity: prefix.
  • Source: resource.prefix
  • Usage: server_create, server_update
entity.data.target_url
  • Description: JumpCloud extension data on the managed entity: target_url.
  • Source: resource.target_url
  • Usage: server_create, server_update
entity.data.uri
  • Description: JumpCloud extension data on the managed entity: uri.
  • Source: resource.uri
  • Usage: redirect_uri_create, redirect_uri_update
entity.name
  • Description: The name of the managed entity. It should match the name of the specific entity object's name if populated, or the name of the managed entity if the type_id is 'Other'.
  • Source: resource.name
  • Usage: redirect_uri_update, server_create, server_update
entity.org.uid
  • Description: The unique identifier of the organization, Oracle Cloud Tenancy, Google Cloud Organization, or AWS Organization. For example, an AWS Org ID or Oracle Cloud Domain ID .
  • Source: resource.organization_id
  • Usage: all events in this service
entity.uid
  • Description: The identifier of the managed entity. It should match the uid of the specific entity's object UID if populated, or the source specific ID if the type_id is 'Other'.
  • Source: resource.id
  • Usage: all events in this service
entity_result.data.changes_to
  • Description: JumpCloud extension data on the managed entity: changes_to.
  • Source: changes.to
  • Usage: redirect_uri_delete, redirect_uri_update, server_delete
entity_result.data.changes_to_client_id
  • Description: JumpCloud extension data on the managed entity: changes_to_client_id.
  • Source: changes.to.client_id
  • Usage: server_update
entity_result.data.changes_to_client_secret_hint
  • Description: JumpCloud extension data on the managed entity: changes_to_client_secret_hint.
  • Source: changes.to.client_secret_hint
  • Usage: server_update
entity_result.data.changes_to_scope
  • Description: JumpCloud extension data on the managed entity: changes_to_scope.
  • Source: changes.to.scope
  • Usage: server_update

Src Endpoint

src_endpoint.ip
  • Description: Source IP address the request originated from.
  • Source: client_ip
  • Usage: all events in this service
src_endpoint.location.city
  • Description: The name of the city.
  • Source: geoip.city
  • Usage: all events in this service
src_endpoint.location.continent
  • Description: The name of the continent.
  • Source: geoip.continent_code
  • Usage: all events in this service
src_endpoint.location.country
  • Description: The ISO 3166-1 Alpha-2 country code.

    Note: The two letter country code should be capitalized. For example: US or CA.

  • Source: geoip.country_code
  • Usage: all events in this service
src_endpoint.location.lat
  • Description: The geographical Latitude coordinate represented in Decimal Degrees (DD). For example: 42.361145.
  • Source: geoip.latitude
  • Transform:
  • geoip.latitude → double (all events in this service)
  • Usage: all events in this service
src_endpoint.location.long
  • Description: The geographical Longitude coordinate represented in Decimal Degrees (DD). For example: -71.057083.
  • Source: geoip.longitude
  • Transform:
  • geoip.longitude → double (all events in this service)
  • Usage: all events in this service
src_endpoint.location.region
  • Description: The alphanumeric code that identifies the principal subdivision (e.g. province or state) of the country. For example, 'CH-VD' for the Canton of Vaud, Switzerland
  • Source: geoip.region_code
  • Usage: all events in this service

Http Request

http_request.user_agent
  • Description: The request header that identifies the operating system and web browser.
  • Source: useragent.raw
  • Usage: all events in this service

Observables

observables[].name
  • Description: The full name of the observable attribute. The name is a pointer/reference to an attribute within the OCSF event data. For example: file.name. Array attributes may be represented in one of three ways. For example: resources.uid, resources[].uid, resources[0].uid.
  • Literal: actor.user.email_addr, actor.user.uid, http_request.user_agent, src_endpoint.ip, src_endpoint.location.country
  • Usage: all events in this service
observables[].type_id
  • Description: The observable value type identifier.
  • Literal: 14, 16, 2, 31, 5
  • Usage: all events in this service
observables[].value
  • Description: The value associated with the observable attribute. The meaning of the value depends on the observable type.
    If the name refers to a scalar attribute, then the value is the value of the attribute.
    If the name refers to an object attribute, then the value is not populated.
  • Source: client_ip, geoip.country_code, initiated_by.email, initiated_by.id, useragent.raw
  • Usage: all events in this service

Unmapped

unmapped.changes
  • Description: JumpCloud Directory Insights field changes preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes
  • Usage: redirect_uri_create, server_create
unmapped.geoip.region_name
  • Description: JumpCloud Directory Insights field geoip.region_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.region_name
  • Usage: all events in this service
unmapped.geoip.timezone
  • Description: JumpCloud Directory Insights field geoip.timezone preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.timezone
  • Usage: all events in this service
unmapped.initiated_by.source
  • Description: JumpCloud Directory Insights field initiated_by.source preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by.source
  • Usage: all events in this service
unmapped.initiated_by.source_metadata
  • Description: JumpCloud Directory Insights field initiated_by.source_metadata preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by.source_metadata
  • Usage: all events in this service
unmapped.is_out_of_bound
  • Description: JumpCloud Directory Insights field is_out_of_bound preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: is_out_of_bound
  • Usage: all events in this service
unmapped.jc_organization_name
  • Description: JumpCloud Directory Insights field jc_organization_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_organization_name
  • Usage: redirect_uri_update, server_create, server_delete, server_update
unmapped.jc_provider_id
  • Description: JumpCloud Directory Insights field jc_provider_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_provider_id
  • Usage: server_create, server_delete, server_update
unmapped.jc_transformation_ts
  • Description: JumpCloud Directory Insights field jc_transformation_ts preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_transformation_ts
  • Usage: all events in this service
unmapped.jcdataprevious
  • Description: JumpCloud Directory Insights field jcdataprevious preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jcdataprevious
  • Usage: redirect_uri_delete, redirect_uri_update
unmapped.provider
  • Description: JumpCloud Directory Insights field provider preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: provider
  • Usage: all events in this service
unmapped.useragent.device
  • Description: JumpCloud Directory Insights field useragent.device preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.device
  • Usage: all events in this service
unmapped.useragent.major
  • Description: JumpCloud Directory Insights field useragent.major preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.major
  • Usage: all events in this service
unmapped.useragent.minor
  • Description: JumpCloud Directory Insights field useragent.minor preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.minor
  • Usage: all events in this service
unmapped.useragent.name
  • Description: JumpCloud Directory Insights field useragent.name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.name
  • Usage: all events in this service
unmapped.useragent.os
  • Description: JumpCloud Directory Insights field useragent.os preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os
  • Usage: all events in this service
unmapped.useragent.os_full
  • Description: JumpCloud Directory Insights field useragent.os_full preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_full
  • Usage: all events in this service
unmapped.useragent.os_major
  • Description: JumpCloud Directory Insights field useragent.os_major preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_major
  • Usage: all events in this service
unmapped.useragent.os_minor
  • Description: JumpCloud Directory Insights field useragent.os_minor preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_minor
  • Usage: all events in this service
unmapped.useragent.os_name
  • Description: JumpCloud Directory Insights field useragent.os_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_name
  • Usage: all events in this service
unmapped.useragent.os_patch
  • Description: JumpCloud Directory Insights field useragent.os_patch preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_patch
  • Usage: all events in this service
unmapped.useragent.os_version
  • Description: JumpCloud Directory Insights field useragent.os_version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_version
  • Usage: all events in this service
unmapped.useragent.patch
  • Description: JumpCloud Directory Insights field useragent.patch preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.patch
  • Usage: all events in this service
unmapped.useragent.version
  • Description: JumpCloud Directory Insights field useragent.version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.version
  • Usage: all events in this service

AI Gateway#

aigw · 3 events

Event Category Class Activity Type UID Fields
aigw_session_activity Application Activity (6) API Activity (6003) Read (2) 600302 54
aigw_session_closed Identity & Access Management (3) Authentication (3002) Logoff (2) 300202 55
aigw_session_opened Identity & Access Management (3) Authentication (3002) Logon (1) 300201 57

OCSF field mappings#

Legend

  • Description: what the OCSF field represents (from OCSF schema v1.8.0)
  • Source: raw JumpCloud event field(s) mapped via ${{placeholder}} template
  • Transform: fieldMappings entry applied at runtime (cast, enum, etc.)
  • Literal: static value set in the mapping template
  • Usage: event types in this service that include this field

Core

activity_id
  • Description: The normalized identifier of the activity that triggered the event.
  • Literal: 1, 2
  • Usage: all events in this service
activity_name
  • Description: The event activity name, as defined by the activity_id.
  • Literal: Logoff, Logon, Read
  • Usage: all events in this service
category_name
  • Description: The event category name, as defined by category_uid value: Discovery.
  • Literal: Application Activity, Identity & Access Management
  • Usage: all events in this service
category_uid
  • Description: The category unique identifier of the event.
  • Literal: 3, 6
  • Usage: all events in this service
class_name
  • Description: The event class name, as defined by class_uid value: User Inventory Info.
  • Literal: API Activity, Authentication
  • Usage: all events in this service
class_uid
  • Description: The unique identifier of a class. A class describes the attributes available in an event.
  • Literal: 3002, 6003
  • Usage: all events in this service
severity_id
  • Description: OCSF severity identifier for the event.
  • Literal: 1
  • Usage: all events in this service
status_detail
  • Description: The status detail contains additional information about the event/finding outcome.
  • Source: aigw_detail.outcome
  • Usage: aigw_session_activity
status_id
  • Description: Normalized status of the activity (1=Success, 2=Failure).
  • Source: success
  • Transform:
  • success → boolean_to_status_id; true→1, false→2 (all events in this service)
  • Usage: all events in this service
time
  • Description: Event time, in epoch milliseconds (OCSF time).
  • Source: timestamp
  • Usage: all events in this service
type_uid
  • Description: The event/finding type ID. It identifies the event's semantics and structure. The value is calculated by the logging system as: class_uid * 100 + activity_id.
  • Literal: 300201, 300202, 600302
  • Usage: all events in this service

Metadata

metadata.event_code
  • Description: JumpCloud event type code.
  • Source: event_type
  • Usage: all events in this service
metadata.processed_time
  • Description: The event processed time, such as an ETL operation.
  • Source: jc_transformation_ts
  • Usage: all events in this service
metadata.product.name
  • Description: Originating JumpCloud service that produced the event.
  • Source: service
  • Usage: all events in this service
metadata.tenant_uid
  • Description: JumpCloud organization (tenant) identifier.
  • Source: organization
  • Usage: all events in this service
metadata.uid
  • Description: Unique event identifier assigned by JumpCloud.
  • Source: id
  • Usage: all events in this service
metadata.version
  • Description: OCSF schema version used for this event.
  • Literal: 1.8.0
  • Usage: all events in this service

Actor

actor.user.email_addr
  • Description: Email address of the actor who initiated the event.
  • Source: initiated_by.email
  • Usage: aigw_session_activity
actor.user.type_id
  • Description: OCSF user type of the actor (1=User, 2=Admin, 3=System, 4=Service).
  • Source: initiated_by.type
  • Usage: aigw_session_activity
actor.user.uid
  • Description: Unique identifier of the actor who initiated the event.
  • Source: initiated_by.id
  • Usage: aigw_session_activity

User

user.email_addr
  • Description: Email address of the user associated with the event.
  • Source: initiated_by.email
  • Usage: aigw_session_closed, aigw_session_opened
user.type_id
  • Description: OCSF user type (1=User, 2=Admin, 3=System, 4=Service).
  • Source: initiated_by.type
  • Usage: aigw_session_closed, aigw_session_opened
user.uid
  • Description: Unique identifier of the user associated with the event.
  • Source: initiated_by.id
  • Usage: aigw_session_closed, aigw_session_opened

Src Endpoint

src_endpoint.autonomous_system.name
  • Description: Organization name for the Autonomous System.
  • Source: asn.organization
  • Usage: aigw_session_closed, aigw_session_opened
src_endpoint.autonomous_system.number
  • Description: Unique number that the AS is identified by.
  • Source: asn.number
  • Transform:
  • asn.number → int (aigw_session_closed, aigw_session_opened)
  • Usage: aigw_session_closed, aigw_session_opened
src_endpoint.ip
  • Description: Source IP address the request originated from.
  • Source: client_ip
  • Usage: all events in this service
src_endpoint.location.city
  • Description: The name of the city.
  • Source: geoip.city
  • Usage: all events in this service
src_endpoint.location.continent
  • Description: The name of the continent.
  • Source: geoip.continent_code
  • Usage: all events in this service
src_endpoint.location.country
  • Description: The ISO 3166-1 Alpha-2 country code.

    Note: The two letter country code should be capitalized. For example: US or CA.

  • Source: geoip.country_code
  • Usage: all events in this service
src_endpoint.location.lat
  • Description: The geographical Latitude coordinate represented in Decimal Degrees (DD). For example: 42.361145.
  • Source: geoip.latitude
  • Transform:
  • geoip.latitude → double (all events in this service)
  • Usage: all events in this service
src_endpoint.location.long
  • Description: The geographical Longitude coordinate represented in Decimal Degrees (DD). For example: -71.057083.
  • Source: geoip.longitude
  • Transform:
  • geoip.longitude → double (all events in this service)
  • Usage: all events in this service
src_endpoint.location.region
  • Description: The alphanumeric code that identifies the principal subdivision (e.g. province or state) of the country. For example, 'CH-VD' for the Canton of Vaud, Switzerland
  • Source: geoip.region_code
  • Usage: all events in this service

Http Request

http_request.user_agent
  • Description: The request header that identifies the operating system and web browser.
  • Source: useragent.raw
  • Usage: all events in this service

Observables

observables[].name
  • Description: The full name of the observable attribute. The name is a pointer/reference to an attribute within the OCSF event data. For example: file.name. Array attributes may be represented in one of three ways. For example: resources.uid, resources[].uid, resources[0].uid.
  • Literal: actor.user.email_addr, actor.user.uid, http_request.user_agent, src_endpoint.ip, src_endpoint.location.country, user.email_addr, user.uid
  • Usage: all events in this service
observables[].type_id
  • Description: The observable value type identifier.
  • Literal: 14, 16, 2, 31, 5
  • Usage: all events in this service
observables[].value
  • Description: The value associated with the observable attribute. The meaning of the value depends on the observable type.
    If the name refers to a scalar attribute, then the value is the value of the attribute.
    If the name refers to an object attribute, then the value is not populated.
  • Source: client_ip, geoip.country_code, initiated_by.email, initiated_by.id, useragent.raw
  • Usage: all events in this service

Other

api.operation
  • Description: Verb/Operation associated with the request
  • Source: aigw_detail.activity_kind
  • Usage: aigw_session_activity
api.request.uid
  • Description: The unique request identifier.
  • Source: aigw_detail.mcp_session_id
  • Usage: aigw_session_activity
auth_protocol
  • Description: The authentication protocol as defined by the caption of auth_protocol_id. In the case of Other, it is defined by the event source.
  • Source: auth_method
  • Usage: aigw_session_closed, aigw_session_opened
duration
  • Description: The event duration or aggregate time, the amount of time the event covers from start_time to end_time in milliseconds.
  • Source: aigw_detail.duration_ms
  • Usage: aigw_session_activity, aigw_session_opened
session.expiration_reason
  • Description: The reason which triggered the session expiration.
  • Source: aigw_detail.close_reason
  • Usage: aigw_session_closed
session.uid
  • Description: The unique identifier of the session.
  • Source: aigw_detail.mcp_session_id
  • Usage: aigw_session_closed, aigw_session_opened

Unmapped

unmapped.@version
  • Description: JumpCloud Directory Insights field @version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: @version
  • Usage: all events in this service
unmapped.aigw_detail.backend_tool_name
  • Description: JumpCloud Directory Insights field aigw_detail.backend_tool_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: aigw_detail.backend_tool_name
  • Usage: aigw_session_activity
unmapped.aigw_detail.backends.name
  • Description: JumpCloud Directory Insights field aigw_detail.backends.name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: aigw_detail.backends.name
  • Usage: aigw_session_opened
unmapped.aigw_detail.backends.server_object_id
  • Description: JumpCloud Directory Insights field aigw_detail.backends.server_object_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: aigw_detail.backends.server_object_id
  • Usage: aigw_session_opened
unmapped.aigw_detail.server_object_id
  • Description: JumpCloud Directory Insights field aigw_detail.server_object_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: aigw_detail.server_object_id
  • Usage: aigw_session_activity
unmapped.aigw_detail.tool_name
  • Description: JumpCloud Directory Insights field aigw_detail.tool_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: aigw_detail.tool_name
  • Usage: aigw_session_activity
unmapped.aigw_detail.transport
  • Description: JumpCloud Directory Insights field aigw_detail.transport preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: aigw_detail.transport
  • Usage: aigw_session_opened
unmapped.asn.error
  • Description: JumpCloud Directory Insights field asn.error preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: asn.error
  • Usage: aigw_session_opened
unmapped.asn.ip_address
  • Description: JumpCloud Directory Insights field asn.ip_address preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: asn.ip_address
  • Usage: aigw_session_opened
unmapped.asn.network
  • Description: JumpCloud Directory Insights field asn.network preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: asn.network
  • Usage: aigw_session_closed, aigw_session_opened
unmapped.auth_method
  • Description: JumpCloud Directory Insights field auth_method preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: auth_method
  • Usage: aigw_session_activity
unmapped.geoip.region_name
  • Description: JumpCloud Directory Insights field geoip.region_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.region_name
  • Usage: all events in this service
unmapped.geoip.timezone
  • Description: JumpCloud Directory Insights field geoip.timezone preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.timezone
  • Usage: all events in this service
unmapped.initiated_by.source
  • Description: JumpCloud Directory Insights field initiated_by.source preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by.source
  • Usage: all events in this service
unmapped.initiated_by.source_metadata
  • Description: JumpCloud Directory Insights field initiated_by.source_metadata preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by.source_metadata
  • Usage: all events in this service
unmapped.initiated_by_id_hash
  • Description: JumpCloud Directory Insights field initiated_by_id_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_id_hash
  • Usage: all events in this service
unmapped.is_out_of_bound
  • Description: JumpCloud Directory Insights field is_out_of_bound preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: is_out_of_bound
  • Usage: all events in this service
unmapped.provider
  • Description: JumpCloud Directory Insights field provider preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: provider
  • Usage: all events in this service
unmapped.resource.id
  • Description: JumpCloud Directory Insights field resource.id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.id
  • Usage: all events in this service
unmapped.resource.name
  • Description: JumpCloud Directory Insights field resource.name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.name
  • Usage: all events in this service
unmapped.resource.type
  • Description: JumpCloud Directory Insights field resource.type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.type
  • Usage: all events in this service
unmapped.useragent.device
  • Description: JumpCloud Directory Insights field useragent.device preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.device
  • Usage: all events in this service
unmapped.useragent.major
  • Description: JumpCloud Directory Insights field useragent.major preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.major
  • Usage: aigw_session_closed
unmapped.useragent.minor
  • Description: JumpCloud Directory Insights field useragent.minor preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.minor
  • Usage: aigw_session_closed
unmapped.useragent.name
  • Description: JumpCloud Directory Insights field useragent.name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.name
  • Usage: all events in this service
unmapped.useragent.os
  • Description: JumpCloud Directory Insights field useragent.os preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os
  • Usage: all events in this service
unmapped.useragent.os_full
  • Description: JumpCloud Directory Insights field useragent.os_full preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_full
  • Usage: all events in this service
unmapped.useragent.os_name
  • Description: JumpCloud Directory Insights field useragent.os_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_name
  • Usage: all events in this service
unmapped.useragent.version
  • Description: JumpCloud Directory Insights field useragent.version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.version
  • Usage: aigw_session_closed

Alerts#

alert · 8 events

Event Category Class Activity Type UID Fields
alert_created Findings (2) Detection Finding (2004) Create (1) 200401 75
alert_status_updated Identity & Access Management (3) Entity Management (3004) Update (3) 300403 106
alert_updated Findings (2) Detection Finding (2004) Update (2) 200402 67
bulk_delete_alerts Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 45
bulk_update_alerts Identity & Access Management (3) Entity Management (3004) Update (3) 300403 47
rule_config_created Identity & Access Management (3) Entity Management (3004) Create (1) 300401 62
rule_config_deleted Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 54
rule_config_updated Identity & Access Management (3) Entity Management (3004) Update (3) 300403 82

OCSF field mappings#

Legend

  • Description: what the OCSF field represents (from OCSF schema v1.8.0)
  • Source: raw JumpCloud event field(s) mapped via ${{placeholder}} template
  • Transform: fieldMappings entry applied at runtime (cast, enum, etc.)
  • Literal: static value set in the mapping template
  • Usage: event types in this service that include this field

Core

activity_id
  • Description: The normalized identifier of the activity that triggered the event.
  • Literal: 1, 2, 3, 4
  • Usage: all events in this service
activity_name
  • Description: The event activity name, as defined by the activity_id.
  • Literal: Create, Delete, Update
  • Usage: all events in this service
category_name
  • Description: The event category name, as defined by category_uid value: Discovery.
  • Literal: Findings, Identity & Access Management
  • Usage: all events in this service
category_uid
  • Description: The category unique identifier of the event.
  • Literal: 2, 3
  • Usage: all events in this service
class_name
  • Description: The event class name, as defined by class_uid value: User Inventory Info.
  • Literal: Detection Finding, Entity Management
  • Usage: all events in this service
class_uid
  • Description: The unique identifier of a class. A class describes the attributes available in an event.
  • Literal: 2004, 3004
  • Usage: all events in this service
message
  • Description: The description of the event/finding, as defined by the source.
  • Source: bulk_ops_remark
  • Usage: bulk_delete_alerts, bulk_update_alerts
severity_id
  • Description: OCSF severity identifier for the event.
  • Literal: 1
  • Usage: all events in this service
status_detail
  • Description: The status detail contains additional information about the event/finding outcome.
  • Source: error_message
  • Usage: all events in this service
status_id
  • Description: Normalized status of the activity (1=Success, 2=Failure).
  • Source: success
  • Transform:
  • success → boolean_to_status_id; true→1, false→2 (all events in this service)
  • Usage: all events in this service
time
  • Description: Event time, in epoch milliseconds (OCSF time).
  • Source: timestamp
  • Transform:
  • timestamp → iso8601_to_epoch_millis (all events in this service)
  • Usage: all events in this service
type_uid
  • Description: The event/finding type ID. It identifies the event's semantics and structure. The value is calculated by the logging system as: class_uid * 100 + activity_id.
  • Literal: 200401, 200402, 300401, 300403, 300404
  • Usage: all events in this service

Metadata

metadata.event_code
  • Description: JumpCloud event type code.
  • Source: event_type
  • Usage: all events in this service
metadata.original_time
  • Description: The original event time as reported by the event source. For example, the time in the original format from system event log such as Syslog on Unix/Linux and the System event file on Windows. Omit if event is generated instead of collected via logs.
  • Source: server_timestamp
  • Usage: all events in this service
metadata.processed_time
  • Description: The event processed time, such as an ETL operation.
  • Source: jc_transformation_ts
  • Usage: all events in this service
metadata.product.name
  • Description: Originating JumpCloud service that produced the event.
  • Source: service
  • Usage: all events in this service
metadata.tenant_uid
  • Description: JumpCloud organization (tenant) identifier.
  • Source: organization
  • Usage: all events in this service
metadata.uid
  • Description: Unique event identifier assigned by JumpCloud.
  • Source: id
  • Usage: all events in this service
metadata.version
  • Description: OCSF schema version used for this event.
  • Literal: 1.8.0
  • Usage: all events in this service

Actor

actor.user.email_addr
  • Description: Email address of the actor who initiated the event.
  • Source: initiated_by.email
  • Usage: alert_status_updated, bulk_delete_alerts, bulk_update_alerts, rule_config_created, rule_config_deleted, rule_config_updated
actor.user.type_id
  • Description: OCSF user type of the actor (1=User, 2=Admin, 3=System, 4=Service).
  • Source: initiated_by.type
  • Transform:
  • initiated_by.type → enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (alert_status_updated, bulk_delete_alerts, bulk_update_alerts, rule_config_created, rule_config_deleted, rule_config_updated)
  • Usage: alert_status_updated, bulk_delete_alerts, bulk_update_alerts, rule_config_created, rule_config_deleted, rule_config_updated
actor.user.uid
  • Description: Unique identifier of the actor who initiated the event.
  • Source: initiated_by.id
  • Usage: alert_status_updated, bulk_delete_alerts, bulk_update_alerts, rule_config_created, rule_config_deleted, rule_config_updated

Entity

entity.data.alerts_enabled
  • Description: JumpCloud extension data on the managed entity: alerts_enabled.
  • Source: alerts_enabled
  • Usage: rule_config_created, rule_config_deleted, rule_config_updated
entity.data.category
  • Description: JumpCloud extension data on the managed entity: category.
  • Source: category
  • Usage: alert_status_updated
entity.data.changed_field
  • Description: JumpCloud extension data on the managed entity: changed_field.
  • Source: changes.field
  • Usage: alert_status_updated, bulk_update_alerts, rule_config_updated
entity.data.changes_from
  • Description: JumpCloud extension data on the managed entity: changes_from.
  • Source: changes.from
  • Usage: alert_status_updated, rule_config_updated
entity.data.changes_removed.condition_object_id
  • Description: JumpCloud extension data on the managed entity: changes_removed.condition_object_id.
  • Source: changes.removed.condition_object_id
  • Usage: rule_config_updated
entity.data.changes_removed.filter_name
  • Description: JumpCloud extension data on the managed entity: changes_removed.filter_name.
  • Source: changes.removed.filter_name
  • Usage: rule_config_updated
entity.data.changes_removed.match_type
  • Description: JumpCloud extension data on the managed entity: changes_removed.match_type.
  • Source: changes.removed.match_type
  • Usage: rule_config_updated
entity.data.changes_removed.value
  • Description: JumpCloud extension data on the managed entity: changes_removed.value.
  • Source: changes.removed.value
  • Usage: rule_config_updated
entity.data.condition_object_id
  • Description: JumpCloud extension data on the managed entity: condition_object_id.
  • Source: rule_conditions.condition_object_id
  • Usage: rule_config_created, rule_config_updated
entity.data.context.already_expired
  • Description: JumpCloud extension data on the managed entity: context.already_expired.
  • Source: resource.context.already_expired
  • Usage: alert_status_updated
entity.data.context.app_id
  • Description: JumpCloud extension data on the managed entity: context.app_id.
  • Source: resource.context.app_id
  • Usage: alert_status_updated
entity.data.context.app_name
  • Description: JumpCloud extension data on the managed entity: context.app_name.
  • Source: resource.context.app_name
  • Usage: alert_status_updated
entity.data.context.certificates.certificate_name
  • Description: JumpCloud extension data on the managed entity: context.certificates.certificate_name.
  • Source: resource.context.certificates.certificate_name
  • Usage: alert_status_updated
entity.data.context.certificates.certificate_type
  • Description: JumpCloud extension data on the managed entity: context.certificates.certificate_type.
  • Source: resource.context.certificates.certificate_type
  • Usage: alert_status_updated
entity.data.context.certificates.expiry_date
  • Description: JumpCloud extension data on the managed entity: context.certificates.expiry_date.
  • Source: resource.context.certificates.expiry_date
  • Usage: alert_status_updated
entity.data.context.certificates.id
  • Description: JumpCloud extension data on the managed entity: context.certificates.id.
  • Source: resource.context.certificates.id
  • Usage: alert_status_updated
entity.data.context.command_id
  • Description: JumpCloud extension data on the managed entity: context.command_id.
  • Source: resource.context.command_id
  • Usage: alert_status_updated
entity.data.context.command_name
  • Description: JumpCloud extension data on the managed entity: context.command_name.
  • Source: resource.context.command_name
  • Usage: alert_status_updated
entity.data.context.condition_id
  • Description: JumpCloud extension data on the managed entity: context.condition_id.
  • Source: resource.context.condition_id
  • Usage: alert_status_updated
entity.data.context.days_until_expiry
  • Description: JumpCloud extension data on the managed entity: context.days_until_expiry.
  • Source: resource.context.days_until_expiry
  • Usage: alert_status_updated
entity.data.context.device.display_name
  • Description: JumpCloud extension data on the managed entity: context.device.display_name.
  • Source: resource.context.device.display_name
  • Usage: alert_status_updated
entity.data.context.device.id
  • Description: JumpCloud extension data on the managed entity: context.device.id.
  • Source: resource.context.device.id
  • Usage: alert_status_updated
entity.data.context.device_group.name
  • Description: JumpCloud extension data on the managed entity: context.device_group.name.
  • Source: resource.context.device_group.name
  • Usage: alert_status_updated
entity.data.context.device_id
  • Description: JumpCloud extension data on the managed entity: context.device_id.
  • Source: resource.context.device_id
  • Usage: alert_status_updated
entity.data.context.di_event
  • Description: JumpCloud extension data on the managed entity: context.di_event.
  • Source: resource.context.di_event
  • Usage: alert_status_updated
entity.data.context.event_description
  • Description: JumpCloud extension data on the managed entity: context.event_description.
  • Source: resource.context.event_description
  • Usage: alert_status_updated
entity.data.context.existing_condition
  • Description: JumpCloud extension data on the managed entity: context.existing_condition.
  • Source: resource.context.existing_condition
  • Usage: alert_status_updated
entity.data.context.expires_at
  • Description: JumpCloud extension data on the managed entity: context.expires_at.
  • Source: resource.context.expires_at
  • Usage: alert_status_updated
entity.data.context.href_enabled
  • Description: JumpCloud extension data on the managed entity: context.href_enabled.
  • Source: resource.context.href_enabled
  • Usage: alert_status_updated
entity.data.context.label
  • Description: JumpCloud extension data on the managed entity: context.label.
  • Source: resource.context.label
  • Usage: alert_status_updated
entity.data.context.last_contact_time
  • Description: JumpCloud extension data on the managed entity: context.last_contact_time.
  • Source: resource.context.last_contact_time
  • Usage: alert_status_updated
entity.data.context.name
  • Description: JumpCloud extension data on the managed entity: context.name.
  • Source: resource.context.name
  • Usage: alert_status_updated
entity.data.context.notify_config.channel_object_ids
  • Description: JumpCloud extension data on the managed entity: context.notify_config.channel_object_ids.
  • Source: resource.context.notify_config.channel_object_ids
  • Usage: alert_status_updated
entity.data.context.notify_config.notify_on_acknowledgment
  • Description: JumpCloud extension data on the managed entity: context.notify_config.notify_on_acknowledgment.
  • Source: resource.context.notify_config.notify_on_acknowledgment
  • Usage: alert_status_updated
entity.data.context.notify_config.notify_on_resolution
  • Description: JumpCloud extension data on the managed entity: context.notify_config.notify_on_resolution.
  • Source: resource.context.notify_config.notify_on_resolution
  • Usage: alert_status_updated
entity.data.context.notify_config.notify_on_violation
  • Description: JumpCloud extension data on the managed entity: context.notify_config.notify_on_violation.
  • Source: resource.context.notify_config.notify_on_violation
  • Usage: alert_status_updated
entity.data.context.notify_config.notify_primary_user_of_device
  • Description: JumpCloud extension data on the managed entity: context.notify_config.notify_primary_user_of_device.
  • Source: resource.context.notify_config.notify_primary_user_of_device
  • Usage: alert_status_updated
entity.data.context.notify_config.primary_user_email
  • Description: JumpCloud extension data on the managed entity: context.notify_config.primary_user_email.
  • Source: resource.context.notify_config.primary_user_email
  • Usage: alert_status_updated
entity.data.context.notify_config.primary_user_id
  • Description: JumpCloud extension data on the managed entity: context.notify_config.primary_user_id.
  • Source: resource.context.notify_config.primary_user_id
  • Usage: alert_status_updated
entity.data.context.notify_config.primary_user_resolved
  • Description: JumpCloud extension data on the managed entity: context.notify_config.primary_user_resolved.
  • Source: resource.context.notify_config.primary_user_resolved
  • Usage: alert_status_updated
entity.data.context.policy_id
  • Description: JumpCloud extension data on the managed entity: context.policy_id.
  • Source: resource.context.policy_id
  • Usage: alert_status_updated
entity.data.context.policy_name
  • Description: JumpCloud extension data on the managed entity: context.policy_name.
  • Source: resource.context.policy_name
  • Usage: alert_status_updated
entity.data.context.poll_event_type
  • Description: JumpCloud extension data on the managed entity: context.poll_event_type.
  • Source: resource.context.poll_event_type
  • Usage: alert_status_updated
entity.data.context.raw_event_key
  • Description: JumpCloud extension data on the managed entity: context.raw_event_key.
  • Source: resource.context.raw_event_key
  • Usage: alert_status_updated
entity.data.context.resolution_condition
  • Description: JumpCloud extension data on the managed entity: context.resolution_condition.
  • Source: resource.context.resolution_condition
  • Usage: alert_status_updated
entity.data.context.resource_id
  • Description: JumpCloud extension data on the managed entity: context.resource_id.
  • Source: resource.context.resource_id
  • Usage: alert_status_updated
entity.data.context.resource_type
  • Description: JumpCloud extension data on the managed entity: context.resource_type.
  • Source: resource.context.resource_type
  • Usage: alert_status_updated
entity.data.context.rule_name
  • Description: JumpCloud extension data on the managed entity: context.rule_name.
  • Source: resource.context.rule_name
  • Usage: alert_status_updated
entity.data.context.rule_object_id
  • Description: JumpCloud extension data on the managed entity: context.rule_object_id.
  • Source: resource.context.rule_object_id
  • Usage: alert_status_updated
entity.data.context.rule_template_name
  • Description: JumpCloud extension data on the managed entity: context.rule_template_name.
  • Source: resource.context.rule_template_name
  • Usage: alert_status_updated
entity.data.context.source_name
  • Description: JumpCloud extension data on the managed entity: context.source_name.
  • Source: resource.context.source_name
  • Usage: alert_status_updated
entity.data.context.source_url
  • Description: JumpCloud extension data on the managed entity: context.source_url.
  • Source: resource.context.source_url
  • Usage: alert_status_updated
entity.data.context.template_type
  • Description: JumpCloud extension data on the managed entity: context.template_type.
  • Source: resource.context.template_type
  • Usage: alert_status_updated
entity.data.context.threshold_value
  • Description: JumpCloud extension data on the managed entity: context.threshold_value.
  • Source: resource.context.threshold_value
  • Usage: alert_status_updated
entity.data.context.type
  • Description: JumpCloud extension data on the managed entity: context.type.
  • Source: resource.context.type
  • Usage: alert_status_updated
entity.data.context.uptime_total_seconds
  • Description: JumpCloud extension data on the managed entity: context.uptime_total_seconds.
  • Source: resource.context.uptime_total_seconds
  • Usage: alert_status_updated
entity.data.context.user_id
  • Description: JumpCloud extension data on the managed entity: context.user_id.
  • Source: resource.context.user_id
  • Usage: alert_status_updated
entity.data.context.violation_condition
  • Description: JumpCloud extension data on the managed entity: context.violation_condition.
  • Source: resource.context.violation_condition
  • Usage: alert_status_updated
entity.data.correlation.id
  • Description: JumpCloud extension data on the managed entity: correlation.id.
  • Source: correlation.id
  • Usage: rule_config_created, rule_config_deleted, rule_config_updated
entity.data.created_by_object_id
  • Description: JumpCloud extension data on the managed entity: created_by_object_id.
  • Source: created_by_object_id
  • Usage: rule_config_created, rule_config_deleted, rule_config_updated
entity.data.enable_bootstrap
  • Description: JumpCloud extension data on the managed entity: enable_bootstrap.
  • Source: enable_bootstrap
  • Usage: rule_config_created, rule_config_deleted, rule_config_updated
entity.data.event_types
  • Description: JumpCloud extension data on the managed entity: event_types.
  • Source: event_filters.event_types
  • Usage: rule_config_created, rule_config_updated
entity.data.filter_name
  • Description: JumpCloud extension data on the managed entity: filter_name.
  • Source: rule_conditions.filter_name
  • Usage: rule_config_created, rule_config_updated
entity.data.filter_source
  • Description: JumpCloud extension data on the managed entity: filter_source.
  • Source: event_filters.filter_source
  • Usage: rule_config_created, rule_config_updated
entity.data.initiated_from_slack_app_id
  • Description: JumpCloud extension data on the managed entity: initiated_from_slack_app_id.
  • Source: initiated_from.slack.app_id
  • Usage: alert_status_updated
entity.data.initiated_from_slack_channel_id
  • Description: JumpCloud extension data on the managed entity: initiated_from_slack_channel_id.
  • Source: initiated_from.slack.channel_id
  • Usage: alert_status_updated
entity.data.initiated_from_slack_channel_name
  • Description: JumpCloud extension data on the managed entity: initiated_from_slack_channel_name.
  • Source: initiated_from.slack.channel_name
  • Usage: alert_status_updated
entity.data.initiated_from_slack_source
  • Description: JumpCloud extension data on the managed entity: initiated_from_slack_source.
  • Source: initiated_from.slack.source
  • Usage: alert_status_updated
entity.data.initiated_from_slack_team_id
  • Description: JumpCloud extension data on the managed entity: initiated_from_slack_team_id.
  • Source: initiated_from.slack.team_id
  • Usage: alert_status_updated
entity.data.initiated_from_slack_user_id
  • Description: JumpCloud extension data on the managed entity: initiated_from_slack_user_id.
  • Source: initiated_from.slack.user_id
  • Usage: alert_status_updated
entity.data.match_type
  • Description: JumpCloud extension data on the managed entity: match_type.
  • Source: rule_conditions.match_type
  • Usage: rule_config_created, rule_config_updated
entity.data.notification_channel_object_ids
  • Description: JumpCloud extension data on the managed entity: notification_channel_object_ids.
  • Source: notification_channel_object_ids
  • Usage: rule_config_created, rule_config_deleted, rule_config_updated
entity.data.notify_on_acknowledgment
  • Description: JumpCloud extension data on the managed entity: notify_on_acknowledgment.
  • Source: notify_on_acknowledgment
  • Usage: rule_config_created, rule_config_deleted, rule_config_updated
entity.data.notify_on_resolution
  • Description: JumpCloud extension data on the managed entity: notify_on_resolution.
  • Source: notify_on_resolution
  • Usage: rule_config_created, rule_config_deleted, rule_config_updated
entity.data.notify_on_violation
  • Description: JumpCloud extension data on the managed entity: notify_on_violation.
  • Source: notify_on_violation
  • Usage: rule_config_created, rule_config_deleted, rule_config_updated
entity.data.reference_fields
  • Description: JumpCloud extension data on the managed entity: reference_fields.
  • Source: event_filters.reference_fields
  • Usage: rule_config_created, rule_config_updated
entity.data.reference_id
  • Description: JumpCloud extension data on the managed entity: reference_id.
  • Source: resource.reference_id
  • Usage: alert_status_updated
entity.data.removed_event_filters_event_types
  • Description: JumpCloud extension data on the managed entity: removed_event_filters_event_types.
  • Source: changes.removed_event_filters.event_types
  • Usage: rule_config_updated
entity.data.removed_event_filters_filter_source
  • Description: JumpCloud extension data on the managed entity: removed_event_filters_filter_source.
  • Source: changes.removed_event_filters.filter_source
  • Usage: rule_config_updated
entity.data.removed_event_filters_reference_fields
  • Description: JumpCloud extension data on the managed entity: removed_event_filters_reference_fields.
  • Source: changes.removed_event_filters.reference_fields
  • Usage: rule_config_updated
entity.data.removed_event_filters_violation_condition
  • Description: JumpCloud extension data on the managed entity: removed_event_filters_violation_condition.
  • Source: changes.removed_event_filters.violation_condition
  • Usage: rule_config_updated
entity.data.rule_event_type
  • Description: JumpCloud extension data on the managed entity: rule_event_type.
  • Source: rule_event_type
  • Usage: rule_config_created, rule_config_deleted, rule_config_updated
entity.data.rule_severity
  • Description: JumpCloud extension data on the managed entity: rule_severity.
  • Source: rule_severity
  • Usage: rule_config_created, rule_config_deleted, rule_config_updated
entity.data.rule_status
  • Description: JumpCloud extension data on the managed entity: rule_status.
  • Source: rule_status
  • Usage: rule_config_created, rule_config_deleted, rule_config_updated
entity.data.rule_type
  • Description: JumpCloud extension data on the managed entity: rule_type.
  • Source: rule_type
  • Usage: rule_config_created, rule_config_deleted, rule_config_updated
entity.data.source_id
  • Description: JumpCloud extension data on the managed entity: source_id.
  • Source: resource.source_id
  • Usage: alert_status_updated
entity.data.value
  • Description: JumpCloud extension data on the managed entity: value.
  • Source: rule_conditions.value
  • Usage: rule_config_created, rule_config_updated
entity.data.violation_condition
  • Description: JumpCloud extension data on the managed entity: violation_condition.
  • Source: event_filters.violation_condition
  • Usage: rule_config_created, rule_config_updated
entity.name
  • Description: The name of the managed entity. It should match the name of the specific entity object's name if populated, or the name of the managed entity if the type_id is 'Other'.
  • Source: resource.source_name
  • Usage: alert_status_updated
entity.type
  • Description: The managed entity type. For example: Policy, User, Organization, Device.
  • Source: resource.source_type, rule_category
  • Usage: alert_status_updated, rule_config_created, rule_config_deleted, rule_config_updated
entity.uid
  • Description: The identifier of the managed entity. It should match the uid of the specific entity's object UID if populated, or the source specific ID if the type_id is 'Other'.
  • Source: resource.alert_object_id, rule_object_id
  • Usage: alert_status_updated, rule_config_created, rule_config_deleted, rule_config_updated
entity_result.data.added_event_filters_event_types
  • Description: JumpCloud extension data on the managed entity: added_event_filters_event_types.
  • Source: changes.added_event_filters.event_types
  • Usage: rule_config_updated
entity_result.data.added_event_filters_filter_source
  • Description: JumpCloud extension data on the managed entity: added_event_filters_filter_source.
  • Source: changes.added_event_filters.filter_source
  • Usage: rule_config_updated
entity_result.data.added_event_filters_reference_fields
  • Description: JumpCloud extension data on the managed entity: added_event_filters_reference_fields.
  • Source: changes.added_event_filters.reference_fields
  • Usage: rule_config_updated
entity_result.data.added_event_filters_violation_condition
  • Description: JumpCloud extension data on the managed entity: added_event_filters_violation_condition.
  • Source: changes.added_event_filters.violation_condition
  • Usage: rule_config_updated
entity_result.data.added_notification_channels
  • Description: JumpCloud extension data on the managed entity: added_notification_channels.
  • Source: changes.added_notification_channels
  • Usage: rule_config_updated
entity_result.data.changes_added.condition_object_id
  • Description: JumpCloud extension data on the managed entity: changes_added.condition_object_id.
  • Source: changes.added.condition_object_id
  • Usage: rule_config_updated
entity_result.data.changes_added.filter_name
  • Description: JumpCloud extension data on the managed entity: changes_added.filter_name.
  • Source: changes.added.filter_name
  • Usage: rule_config_updated
entity_result.data.changes_added.match_type
  • Description: JumpCloud extension data on the managed entity: changes_added.match_type.
  • Source: changes.added.match_type
  • Usage: rule_config_updated
entity_result.data.changes_added.value
  • Description: JumpCloud extension data on the managed entity: changes_added.value.
  • Source: changes.added.value
  • Usage: rule_config_updated
entity_result.data.changes_to
  • Description: JumpCloud extension data on the managed entity: changes_to.
  • Source: changes.to
  • Usage: alert_status_updated, bulk_update_alerts, rule_config_updated

Src Endpoint

src_endpoint.autonomous_system.name
  • Description: Organization name for the Autonomous System.
  • Source: asn.organization
  • Usage: bulk_delete_alerts, bulk_update_alerts
src_endpoint.autonomous_system.number
  • Description: Unique number that the AS is identified by.
  • Source: asn.number
  • Transform:
  • asn.number → int (bulk_delete_alerts, bulk_update_alerts)
  • Usage: bulk_delete_alerts, bulk_update_alerts
src_endpoint.ip
  • Description: Source IP address the request originated from.
  • Source: client_ip
  • Usage: alert_status_updated, bulk_delete_alerts, bulk_update_alerts, rule_config_created, rule_config_deleted, rule_config_updated
src_endpoint.location.city
  • Description: The name of the city.
  • Source: geoip.city
  • Usage: alert_status_updated, bulk_delete_alerts, bulk_update_alerts, rule_config_created, rule_config_deleted, rule_config_updated
src_endpoint.location.continent
  • Description: The name of the continent.
  • Source: geoip.continent_code
  • Usage: alert_status_updated, bulk_delete_alerts, bulk_update_alerts, rule_config_created, rule_config_deleted, rule_config_updated
src_endpoint.location.country
  • Description: The ISO 3166-1 Alpha-2 country code.

    Note: The two letter country code should be capitalized. For example: US or CA.

  • Source: geoip.country_code
  • Usage: alert_status_updated, bulk_delete_alerts, bulk_update_alerts, rule_config_created, rule_config_deleted, rule_config_updated
src_endpoint.location.lat
  • Description: The geographical Latitude coordinate represented in Decimal Degrees (DD). For example: 42.361145.
  • Source: geoip.latitude
  • Transform:
  • geoip.latitude → double (alert_status_updated, bulk_delete_alerts, bulk_update_alerts, rule_config_created, rule_config_deleted, rule_config_updated)
  • Usage: alert_status_updated, bulk_delete_alerts, bulk_update_alerts, rule_config_created, rule_config_deleted, rule_config_updated
src_endpoint.location.long
  • Description: The geographical Longitude coordinate represented in Decimal Degrees (DD). For example: -71.057083.
  • Source: geoip.longitude
  • Transform:
  • geoip.longitude → double (alert_status_updated, bulk_delete_alerts, bulk_update_alerts, rule_config_created, rule_config_deleted, rule_config_updated)
  • Usage: alert_status_updated, bulk_delete_alerts, bulk_update_alerts, rule_config_created, rule_config_deleted, rule_config_updated
src_endpoint.location.region
  • Description: The alphanumeric code that identifies the principal subdivision (e.g. province or state) of the country. For example, 'CH-VD' for the Canton of Vaud, Switzerland
  • Source: geoip.region_code
  • Usage: alert_status_updated, bulk_delete_alerts, bulk_update_alerts, rule_config_created, rule_config_deleted, rule_config_updated

Http Request

http_request.user_agent
  • Description: The request header that identifies the operating system and web browser.
  • Source: user_agent
  • Usage: alert_status_updated, bulk_delete_alerts, bulk_update_alerts, rule_config_created, rule_config_deleted, rule_config_updated

Observables

observables[].name
  • Description: The full name of the observable attribute. The name is a pointer/reference to an attribute within the OCSF event data. For example: file.name. Array attributes may be represented in one of three ways. For example: resources.uid, resources[].uid, resources[0].uid.
  • Literal: actor.user.email_addr, actor.user.uid, http_request.user_agent, src_endpoint.ip, src_endpoint.location.country, src_url
  • Usage: all events in this service
observables[].type_id
  • Description: The observable value type identifier.
  • Literal: 14, 16, 2, 31, 5, 6
  • Usage: all events in this service
observables[].value
  • Description: The value associated with the observable attribute. The meaning of the value depends on the observable type.
    If the name refers to a scalar attribute, then the value is the value of the attribute.
    If the name refers to an object attribute, then the value is not populated.
  • Source: client_ip, geoip.country_code, initiated_by.email, initiated_by.id, resource.context.source_url, user_agent
  • Usage: all events in this service

Other

finding_info.analytic.name
  • Description: The name of the analytic that generated the finding.
  • Source: resource.context.rule_name
  • Usage: alert_created, alert_updated
finding_info.desc
  • Description: The description of the reported finding.
  • Source: resource.context.event_description
  • Usage: alert_created, alert_updated
finding_info.title
  • Description: A title or a brief phrase summarizing the reported finding.
  • Source: resource.source_name
  • Usage: alert_created, alert_updated
finding_info.uid
  • Description: The unique identifier of the reported finding.
  • Source: resource.alert_object_id
  • Usage: alert_created, alert_updated
policy.uid
  • Description: A unique identifier of the policy instance.
  • Source: resource.context.rule_object_id
  • Usage: alert_created, alert_updated
severity
  • Description: The event/finding severity, normalized to the caption of the severity_id value. In the case of 'Other', it is defined by the source.
  • Source: severity
  • Usage: alert_created, alert_status_updated, alert_updated
src_url
  • Description: A Url link used to access the original incident.
  • Source: resource.context.source_url
  • Usage: alert_created, alert_updated
status
  • Description: The event status, normalized to the caption of the status_id value. In the case of 'Other', it is defined by the event source.
  • Source: status
  • Usage: alert_created, alert_status_updated, alert_updated

Unmapped

unmapped.@version
  • Description: JumpCloud Directory Insights field @version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: @version
  • Usage: all events in this service
unmapped.asn.network
  • Description: JumpCloud Directory Insights field asn.network preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: asn.network
  • Usage: bulk_delete_alerts, bulk_update_alerts
unmapped.category
  • Description: JumpCloud Directory Insights field category preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: category
  • Usage: alert_created, alert_updated
unmapped.client_ip
  • Description: JumpCloud Directory Insights field client_ip preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: client_ip
  • Usage: alert_created, alert_updated
unmapped.file_input_timestamp
  • Description: JumpCloud Directory Insights field file_input_timestamp preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: file_input_timestamp
  • Usage: bulk_delete_alerts, bulk_update_alerts
unmapped.geoip.city
  • Description: JumpCloud Directory Insights field geoip.city preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.city
  • Usage: alert_created
unmapped.geoip.continent_code
  • Description: JumpCloud Directory Insights field geoip.continent_code preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.continent_code
  • Usage: alert_created
unmapped.geoip.country_code
  • Description: JumpCloud Directory Insights field geoip.country_code preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.country_code
  • Usage: alert_created
unmapped.geoip.latitude
  • Description: JumpCloud Directory Insights field geoip.latitude preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.latitude
  • Usage: alert_created
unmapped.geoip.longitude
  • Description: JumpCloud Directory Insights field geoip.longitude preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.longitude
  • Usage: alert_created
unmapped.geoip.region_code
  • Description: JumpCloud Directory Insights field geoip.region_code preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.region_code
  • Usage: alert_created
unmapped.geoip.region_name
  • Description: JumpCloud Directory Insights field geoip.region_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.region_name
  • Usage: alert_created, alert_status_updated, bulk_delete_alerts, bulk_update_alerts, rule_config_created, rule_config_deleted, rule_config_updated
unmapped.geoip.timezone
  • Description: JumpCloud Directory Insights field geoip.timezone preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.timezone
  • Usage: alert_created, alert_status_updated, bulk_delete_alerts, bulk_update_alerts, rule_config_created, rule_config_deleted, rule_config_updated
unmapped.initiated_by
  • Description: JumpCloud Directory Insights field initiated_by preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by
  • Usage: alert_created, alert_updated
unmapped.initiated_by_email_hash
  • Description: JumpCloud Directory Insights field initiated_by_email_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_email_hash
  • Usage: alert_status_updated, bulk_delete_alerts, bulk_update_alerts, rule_config_created, rule_config_deleted, rule_config_updated
unmapped.initiated_by_id_hash
  • Description: JumpCloud Directory Insights field initiated_by_id_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_id_hash
  • Usage: alert_status_updated, bulk_delete_alerts, bulk_update_alerts, rule_config_created, rule_config_deleted, rule_config_updated
unmapped.is_out_of_bound
  • Description: JumpCloud Directory Insights field is_out_of_bound preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: is_out_of_bound
  • Usage: all events in this service
unmapped.jc_application_name
  • Description: JumpCloud Directory Insights field jc_application_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_application_name
  • Usage: all events in this service
unmapped.resource.context.already_expired
  • Description: JumpCloud Directory Insights field resource.context.already_expired preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.already_expired
  • Usage: alert_created, alert_updated
unmapped.resource.context.certificates.certificate_name
  • Description: JumpCloud Directory Insights field resource.context.certificates.certificate_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.certificates.certificate_name
  • Usage: alert_created, alert_updated
unmapped.resource.context.certificates.certificate_type
  • Description: JumpCloud Directory Insights field resource.context.certificates.certificate_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.certificates.certificate_type
  • Usage: alert_created, alert_updated
unmapped.resource.context.certificates.expiry_date
  • Description: JumpCloud Directory Insights field resource.context.certificates.expiry_date preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.certificates.expiry_date
  • Usage: alert_created, alert_updated
unmapped.resource.context.certificates.id
  • Description: JumpCloud Directory Insights field resource.context.certificates.id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.certificates.id
  • Usage: alert_created, alert_updated
unmapped.resource.context.condition_id
  • Description: JumpCloud Directory Insights field resource.context.condition_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.condition_id
  • Usage: alert_created, alert_updated
unmapped.resource.context.days_until_expiry
  • Description: JumpCloud Directory Insights field resource.context.days_until_expiry preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.days_until_expiry
  • Usage: alert_created, alert_updated
unmapped.resource.context.di_event
  • Description: JumpCloud Directory Insights field resource.context.di_event preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.di_event
  • Usage: alert_created, alert_updated
unmapped.resource.context.existing_condition
  • Description: JumpCloud Directory Insights field resource.context.existing_condition preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.existing_condition
  • Usage: alert_created, alert_updated
unmapped.resource.context.expires_at
  • Description: JumpCloud Directory Insights field resource.context.expires_at preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.expires_at
  • Usage: alert_created, alert_updated
unmapped.resource.context.key1
  • Description: JumpCloud Directory Insights field resource.context.key1 preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.key1
  • Usage: alert_created
unmapped.resource.context.key2
  • Description: JumpCloud Directory Insights field resource.context.key2 preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.key2
  • Usage: alert_created
unmapped.resource.context.label
  • Description: JumpCloud Directory Insights field resource.context.label preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.label
  • Usage: alert_created, alert_updated
unmapped.resource.context.notify_config.channel_object_ids
  • Description: JumpCloud Directory Insights field resource.context.notify_config.channel_object_ids preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.notify_config.channel_object_ids
  • Usage: alert_created, alert_updated
unmapped.resource.context.notify_config.notify_on_acknowledgment
  • Description: JumpCloud Directory Insights field resource.context.notify_config.notify_on_acknowledgment preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.notify_config.notify_on_acknowledgment
  • Usage: alert_created, alert_updated
unmapped.resource.context.notify_config.notify_on_resolution
  • Description: JumpCloud Directory Insights field resource.context.notify_config.notify_on_resolution preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.notify_config.notify_on_resolution
  • Usage: alert_created, alert_updated
unmapped.resource.context.notify_config.notify_on_violation
  • Description: JumpCloud Directory Insights field resource.context.notify_config.notify_on_violation preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.notify_config.notify_on_violation
  • Usage: alert_created, alert_updated
unmapped.resource.context.poll_event_type
  • Description: JumpCloud Directory Insights field resource.context.poll_event_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.poll_event_type
  • Usage: alert_created, alert_updated
unmapped.resource.context.raw_event_key
  • Description: JumpCloud Directory Insights field resource.context.raw_event_key preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.raw_event_key
  • Usage: alert_created, alert_updated
unmapped.resource.context.resolution_condition
  • Description: JumpCloud Directory Insights field resource.context.resolution_condition preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.resolution_condition
  • Usage: alert_created, alert_updated
unmapped.resource.context.resource_id
  • Description: JumpCloud Directory Insights field resource.context.resource_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.resource_id
  • Usage: alert_created, alert_updated
unmapped.resource.context.resource_type
  • Description: JumpCloud Directory Insights field resource.context.resource_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.resource_type
  • Usage: alert_created, alert_updated
unmapped.resource.context.rule_template_name
  • Description: JumpCloud Directory Insights field resource.context.rule_template_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.rule_template_name
  • Usage: alert_created, alert_updated
unmapped.resource.context.source_name
  • Description: JumpCloud Directory Insights field resource.context.source_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.source_name
  • Usage: alert_created, alert_updated
unmapped.resource.context.template_type
  • Description: JumpCloud Directory Insights field resource.context.template_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.template_type
  • Usage: alert_created, alert_updated
unmapped.resource.context.threshold_value
  • Description: JumpCloud Directory Insights field resource.context.threshold_value preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.threshold_value
  • Usage: alert_created, alert_updated
unmapped.resource.context.type
  • Description: JumpCloud Directory Insights field resource.context.type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.type
  • Usage: alert_updated
unmapped.resource.context.uptime_total_seconds
  • Description: JumpCloud Directory Insights field resource.context.uptime_total_seconds preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.uptime_total_seconds
  • Usage: alert_updated
unmapped.resource.context.violation_condition
  • Description: JumpCloud Directory Insights field resource.context.violation_condition preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.violation_condition
  • Usage: alert_created, alert_updated
unmapped.resource.reference_id
  • Description: JumpCloud Directory Insights field resource.reference_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.reference_id
  • Usage: alert_created, alert_updated
unmapped.resource.source_id
  • Description: JumpCloud Directory Insights field resource.source_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.source_id
  • Usage: alert_created, alert_updated
unmapped.resource.source_type
  • Description: JumpCloud Directory Insights field resource.source_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.source_type
  • Usage: alert_created, alert_updated
unmapped.timestamp_source
  • Description: JumpCloud Directory Insights field timestamp_source preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: timestamp_source
  • Usage: all events in this service
unmapped.user_agent
  • Description: JumpCloud Directory Insights field user_agent preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: user_agent
  • Usage: alert_created, alert_updated

Asset Management#

asset_management · 9 events

Event Category Class Activity Type UID Fields
asset_management_asset_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 84
asset_management_asset_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 57
asset_management_asset_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 47
asset_management_disable Identity & Access Management (3) Entity Management (3004) Disable (9) 300409 51
asset_management_enable Identity & Access Management (3) Entity Management (3004) Enable (8) 300408 52
asset_management_field_setting_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 56
asset_management_field_setting_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 49
asset_management_field_setting_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 52
asset_management_general_settings_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 54

OCSF field mappings#

Legend

  • Description: what the OCSF field represents (from OCSF schema v1.8.0)
  • Source: raw JumpCloud event field(s) mapped via ${{placeholder}} template
  • Transform: fieldMappings entry applied at runtime (cast, enum, etc.)
  • Literal: static value set in the mapping template
  • Usage: event types in this service that include this field

Core

activity_id
  • Description: The normalized identifier of the activity that triggered the event.
  • Literal: 1, 3, 4, 8, 9
  • Usage: all events in this service
activity_name
  • Description: The event activity name, as defined by the activity_id.
  • Literal: Create, Delete, Disable, Enable, Update
  • Usage: all events in this service
category_name
  • Description: The event category name, as defined by category_uid value: Discovery.
  • Literal: Identity & Access Management
  • Usage: all events in this service
category_uid
  • Description: The category unique identifier of the event.
  • Literal: 3
  • Usage: all events in this service
class_name
  • Description: The event class name, as defined by class_uid value: User Inventory Info.
  • Literal: Entity Management
  • Usage: all events in this service
class_uid
  • Description: The unique identifier of a class. A class describes the attributes available in an event.
  • Literal: 3004
  • Usage: all events in this service
message
  • Description: The description of the event/finding, as defined by the source.
  • Source: detail
  • Usage: all events in this service
severity_id
  • Description: OCSF severity identifier for the event.
  • Literal: 1
  • Usage: all events in this service
status_detail
  • Description: The status detail contains additional information about the event/finding outcome.
  • Source: error_message
  • Usage: all events in this service
status_id
  • Description: Normalized status of the activity (1=Success, 2=Failure).
  • Source: success
  • Transform:
  • success → boolean_to_status_id; true→1, false→2 (all events in this service)
  • Usage: all events in this service
time
  • Description: Event time, in epoch milliseconds (OCSF time).
  • Source: timestamp
  • Transform:
  • timestamp → iso8601_to_epoch_millis (all events in this service)
  • Usage: all events in this service
type_uid
  • Description: The event/finding type ID. It identifies the event's semantics and structure. The value is calculated by the logging system as: class_uid * 100 + activity_id.
  • Literal: 300401, 300403, 300404, 300408, 300409
  • Usage: all events in this service

Metadata

metadata.event_code
  • Description: JumpCloud event type code.
  • Source: event_type
  • Usage: all events in this service
metadata.original_time
  • Description: The original event time as reported by the event source. For example, the time in the original format from system event log such as Syslog on Unix/Linux and the System event file on Windows. Omit if event is generated instead of collected via logs.
  • Source: server_timestamp
  • Usage: all events in this service
metadata.processed_time
  • Description: The event processed time, such as an ETL operation.
  • Source: jc_transformation_ts
  • Usage: all events in this service
metadata.product.name
  • Description: Originating JumpCloud service that produced the event.
  • Source: service
  • Usage: all events in this service
metadata.tenant_uid
  • Description: JumpCloud organization (tenant) identifier.
  • Source: organization
  • Usage: all events in this service
metadata.uid
  • Description: Unique event identifier assigned by JumpCloud.
  • Source: id
  • Usage: all events in this service
metadata.version
  • Description: OCSF schema version used for this event.
  • Literal: 1.8.0
  • Usage: all events in this service

Actor

actor.user.email_addr
  • Description: Email address of the actor who initiated the event.
  • Source: initiated_by.email
  • Usage: all events in this service
actor.user.type_id
  • Description: OCSF user type of the actor (1=User, 2=Admin, 3=System, 4=Service).
  • Source: initiated_by.type
  • Transform:
  • initiated_by.type → enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (all events in this service)
  • Usage: all events in this service
actor.user.uid
  • Description: Unique identifier of the actor who initiated the event.
  • Source: initiated_by.id
  • Usage: all events in this service

Entity

entity.data.agent_status
  • Description: JumpCloud extension data on the managed entity: agent_status.
  • Source: resource.agent_status
  • Usage: asset_management_asset_create
entity.data.agent_version
  • Description: JumpCloud extension data on the managed entity: agent_version.
  • Source: resource.agent_version
  • Usage: asset_management_asset_create
entity.data.battery_current_capacity
  • Description: JumpCloud extension data on the managed entity: battery_current_capacity.
  • Source: resource.battery_current_capacity
  • Usage: asset_management_asset_create
entity.data.battery_max_capacity
  • Description: JumpCloud extension data on the managed entity: battery_max_capacity.
  • Source: resource.battery_max_capacity
  • Usage: asset_management_asset_create
entity.data.changed_field
  • Description: JumpCloud extension data on the managed entity: changed_field.
  • Source: changes.field
  • Usage: asset_management_asset_update, asset_management_field_setting_update, asset_management_general_settings_update
entity.data.changes_from
  • Description: JumpCloud extension data on the managed entity: changes_from.
  • Source: changes.from
  • Usage: asset_management_asset_update, asset_management_field_setting_update, asset_management_general_settings_update
entity.data.country
  • Description: JumpCloud extension data on the managed entity: country.
  • Source: resource.country
  • Usage: asset_management_asset_create
entity.data.currency_code
  • Description: JumpCloud extension data on the managed entity: currency_code.
  • Source: resource.currency_code
  • Usage: asset_management_asset_create
entity.data.data_source
  • Description: JumpCloud extension data on the managed entity: data_source.
  • Source: resource.data_source
  • Usage: asset_management_asset_create, asset_management_asset_delete
entity.data.deployed_at
  • Description: JumpCloud extension data on the managed entity: deployed_at.
  • Source: resource.deployed_at
  • Usage: asset_management_asset_create
entity.data.device_groups
  • Description: JumpCloud extension data on the managed entity: device_groups.
  • Source: resource.device_groups
  • Usage: asset_management_asset_create
entity.data.disk_encrypted
  • Description: JumpCloud extension data on the managed entity: disk_encrypted.
  • Source: resource.disk_encrypted
  • Usage: asset_management_asset_create
entity.data.field_type
  • Description: JumpCloud extension data on the managed entity: field_type.
  • Source: resource.type
  • Usage: asset_management_field_setting_create, asset_management_field_setting_delete, asset_management_field_setting_update
entity.data.mandatory
  • Description: JumpCloud extension data on the managed entity: mandatory.
  • Source: resource.mandatory
  • Usage: asset_management_field_setting_create
entity.data.mdm_provider
  • Description: JumpCloud extension data on the managed entity: mdm_provider.
  • Source: resource.mdm_provider
  • Usage: asset_management_asset_create
entity.data.mfa_status
  • Description: JumpCloud extension data on the managed entity: mfa_status.
  • Source: resource.mfa_status
  • Usage: asset_management_asset_create
entity.data.multiple
  • Description: JumpCloud extension data on the managed entity: multiple.
  • Source: resource.multiple
  • Usage: asset_management_field_setting_create
entity.data.options_id
  • Description: JumpCloud extension data on the managed entity: options_id.
  • Source: resource.options.id
  • Usage: asset_management_field_setting_create
entity.data.options_value
  • Description: JumpCloud extension data on the managed entity: options_value.
  • Source: resource.options.value
  • Usage: asset_management_field_setting_create
entity.data.ownership_type
  • Description: JumpCloud extension data on the managed entity: ownership_type.
  • Source: resource.ownership_type
  • Usage: asset_management_asset_create
entity.data.po_number
  • Description: JumpCloud extension data on the managed entity: po_number.
  • Source: resource.po_number
  • Usage: asset_management_asset_create
entity.data.purchase_cost
  • Description: JumpCloud extension data on the managed entity: purchase_cost.
  • Source: resource.purchase_cost
  • Usage: asset_management_asset_create
entity.data.purchased_at
  • Description: JumpCloud extension data on the managed entity: purchased_at.
  • Source: resource.purchased_at
  • Usage: asset_management_asset_create
entity.data.section
  • Description: JumpCloud extension data on the managed entity: section.
  • Source: resource.section
  • Usage: asset_management_field_setting_create
entity.data.status
  • Description: JumpCloud extension data on the managed entity: status.
  • Source: resource.status
  • Usage: asset_management_asset_create
entity.data.supplier
  • Description: JumpCloud extension data on the managed entity: supplier.
  • Source: resource.supplier
  • Usage: asset_management_asset_create
entity.data.system_insights_enabled
  • Description: JumpCloud extension data on the managed entity: system_insights_enabled.
  • Source: resource.system_insights_enabled
  • Usage: asset_management_asset_create
entity.data.tag
  • Description: JumpCloud extension data on the managed entity: tag.
  • Source: resource.tag
  • Usage: asset_management_asset_create
entity.data.tooltip
  • Description: JumpCloud extension data on the managed entity: tooltip.
  • Source: resource.tooltip
  • Usage: asset_management_field_setting_create
entity.data.unique
  • Description: JumpCloud extension data on the managed entity: unique.
  • Source: resource.unique
  • Usage: asset_management_field_setting_create
entity.data.users
  • Description: JumpCloud extension data on the managed entity: users.
  • Source: resource.users
  • Usage: asset_management_asset_create
entity.data.warranty_expired_at
  • Description: JumpCloud extension data on the managed entity: warranty_expired_at.
  • Source: resource.warranty_expired_at
  • Usage: asset_management_asset_create
entity.data.warranty_period_months
  • Description: JumpCloud extension data on the managed entity: warranty_period_months.
  • Source: resource.warranty_period_months
  • Usage: asset_management_asset_create
entity.device.hw_info.cpu_type
  • Description: The processor type. For example: x86 Family 6 Model 37 Stepping 5.
  • Source: resource.cpu
  • Usage: asset_management_asset_create
entity.device.hw_info.ram_size
  • Description: The total amount of installed RAM, in Megabytes. For example: 2048.
  • Source: resource.rammb
  • Usage: asset_management_asset_create
entity.device.hw_info.serial_number
  • Description: The device manufacturer serial number.
  • Source: resource.serial
  • Usage: asset_management_asset_create
entity.device.is_managed
  • Description: The event occurred on a managed device.
  • Source: resource.mdm_status
  • Usage: asset_management_asset_create
entity.device.last_seen_time
  • Description: The most recent discovery time of the device.
  • Source: resource.last_contact
  • Usage: asset_management_asset_create
entity.device.model
  • Description: The model of the device. For example ThinkPad X1 Carbon.
  • Source: resource.model
  • Usage: asset_management_asset_create
entity.device.os.name
  • Description: The operating system name.
  • Source: resource.os
  • Usage: asset_management_asset_create
entity.device.os.type
  • Description: The type of the operating system.
  • Source: resource.os_family
  • Usage: asset_management_asset_create
entity.device.os.version
  • Description: The version of the OS running on the device that originated the event. For example: "Windows 10", "OS X 10.7", or "iOS 9".
  • Source: resource.os_version
  • Usage: asset_management_asset_create
entity.device.owner.name
  • Description: The username. For example, janedoe1.
  • Source: resource.owner_user
  • Usage: asset_management_asset_create
entity.device.type
  • Description: The device type. For example: unknown, server, desktop, laptop, tablet, mobile, virtual, browser, or other.
  • Source: resource.type
  • Usage: asset_management_asset_create, asset_management_asset_delete
entity.device.uid
  • Description: The unique identifier of the device. For example the Windows TargetSID or AWS EC2 ARN.
  • Source: resource.system_id
  • Usage: asset_management_asset_create
entity.device.vendor_name
  • Description: The vendor for the device. For example Dell or Lenovo.
  • Source: resource.vendor
  • Usage: asset_management_asset_create
entity.name
  • Description: The name of the managed entity. It should match the name of the specific entity object's name if populated, or the name of the managed entity if the type_id is 'Other'.
  • Source: resource.label, resource.name
  • Usage: asset_management_asset_create, asset_management_asset_delete, asset_management_field_setting_create, asset_management_field_setting_delete, asset_management_field_setting_update
entity.type
  • Description: The managed entity type. For example: Policy, User, Organization, Device.
  • Source: resource.asset_type, resource.scope, resource.type
  • Usage: asset_management_asset_create, asset_management_asset_delete, asset_management_asset_update, asset_management_field_setting_create, asset_management_field_setting_delete, asset_management_field_setting_update
entity.uid
  • Description: The identifier of the managed entity. It should match the uid of the specific entity's object UID if populated, or the source specific ID if the type_id is 'Other'.
  • Source: resource.id, service
  • Usage: all events in this service
entity_result.data.changes_to
  • Description: JumpCloud extension data on the managed entity: changes_to.
  • Source: changes.to
  • Usage: asset_management_asset_update, asset_management_field_setting_update, asset_management_general_settings_update

Src Endpoint

src_endpoint.autonomous_system.name
  • Description: Organization name for the Autonomous System.
  • Source: asn.organization
  • Usage: asset_management_asset_create, asset_management_asset_delete, asset_management_disable, asset_management_enable, asset_management_field_setting_create, asset_management_field_setting_delete, asset_management_field_setting_update, asset_management_general_settings_update
src_endpoint.autonomous_system.number
  • Description: Unique number that the AS is identified by.
  • Source: asn.number
  • Transform:
  • asn.number → int (asset_management_asset_create, asset_management_asset_delete, asset_management_disable, asset_management_enable, asset_management_field_setting_create, asset_management_field_setting_delete, asset_management_field_setting_update, asset_management_general_settings_update)
  • Usage: asset_management_asset_create, asset_management_asset_delete, asset_management_disable, asset_management_enable, asset_management_field_setting_create, asset_management_field_setting_delete, asset_management_field_setting_update, asset_management_general_settings_update
src_endpoint.ip
  • Description: Source IP address the request originated from.
  • Source: client_ip
  • Usage: all events in this service
src_endpoint.location.city
  • Description: The name of the city.
  • Source: geoip.city
  • Usage: all events in this service
src_endpoint.location.continent
  • Description: The name of the continent.
  • Source: geoip.continent_code
  • Usage: all events in this service
src_endpoint.location.country
  • Description: The ISO 3166-1 Alpha-2 country code.

    Note: The two letter country code should be capitalized. For example: US or CA.

  • Source: geoip.country_code
  • Usage: all events in this service
src_endpoint.location.lat
  • Description: The geographical Latitude coordinate represented in Decimal Degrees (DD). For example: 42.361145.
  • Source: geoip.latitude
  • Transform:
  • geoip.latitude → double (all events in this service)
  • Usage: all events in this service
src_endpoint.location.long
  • Description: The geographical Longitude coordinate represented in Decimal Degrees (DD). For example: -71.057083.
  • Source: geoip.longitude
  • Transform:
  • geoip.longitude → double (all events in this service)
  • Usage: all events in this service
src_endpoint.location.region
  • Description: The alphanumeric code that identifies the principal subdivision (e.g. province or state) of the country. For example, 'CH-VD' for the Canton of Vaud, Switzerland
  • Source: geoip.region_code
  • Usage: all events in this service

Http Request

http_request.user_agent
  • Description: The request header that identifies the operating system and web browser.
  • Source: user_agent
  • Usage: all events in this service

Observables

observables[].name
  • Description: The full name of the observable attribute. The name is a pointer/reference to an attribute within the OCSF event data. For example: file.name. Array attributes may be represented in one of three ways. For example: resources.uid, resources[].uid, resources[0].uid.
  • Literal: actor.user.email_addr, actor.user.uid, entity.device.hw_info.serial_number, entity.device.owner.name, entity.device.uid, http_request.user_agent, src_endpoint.ip, src_endpoint.location.country
  • Usage: all events in this service
observables[].type_id
  • Description: The observable value type identifier.
  • Literal: 14, 16, 2, 31, 37, 4, 47, 5
  • Usage: all events in this service
observables[].value
  • Description: The value associated with the observable attribute. The meaning of the value depends on the observable type.
    If the name refers to a scalar attribute, then the value is the value of the attribute.
    If the name refers to an object attribute, then the value is not populated.
  • Source: client_ip, geoip.country_code, initiated_by.email, initiated_by.id, resource.owner_user, resource.serial, resource.system_id, user_agent
  • Usage: all events in this service

Unmapped

unmapped.@version
  • Description: JumpCloud Directory Insights field @version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: @version
  • Usage: all events in this service
unmapped.asn.network
  • Description: JumpCloud Directory Insights field asn.network preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: asn.network
  • Usage: asset_management_asset_create, asset_management_asset_delete, asset_management_disable, asset_management_enable, asset_management_field_setting_create, asset_management_field_setting_delete, asset_management_field_setting_update, asset_management_general_settings_update
unmapped.geoip.region_name
  • Description: JumpCloud Directory Insights field geoip.region_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.region_name
  • Usage: all events in this service
unmapped.geoip.timezone
  • Description: JumpCloud Directory Insights field geoip.timezone preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.timezone
  • Usage: all events in this service
unmapped.initiated_by_email_hash
  • Description: JumpCloud Directory Insights field initiated_by_email_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_email_hash
  • Usage: all events in this service
unmapped.initiated_by_id_hash
  • Description: JumpCloud Directory Insights field initiated_by_id_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_id_hash
  • Usage: all events in this service
unmapped.is_out_of_bound
  • Description: JumpCloud Directory Insights field is_out_of_bound preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: is_out_of_bound
  • Usage: all events in this service
unmapped.jc_application_name
  • Description: JumpCloud Directory Insights field jc_application_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_application_name
  • Usage: all events in this service
unmapped.jc_initiated_by_email
  • Description: JumpCloud Directory Insights field jc_initiated_by_email preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_initiated_by_email
  • Usage: asset_management_asset_delete, asset_management_disable, asset_management_enable, asset_management_general_settings_update
unmapped.jc_initiated_by_id
  • Description: JumpCloud Directory Insights field jc_initiated_by_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_initiated_by_id
  • Usage: asset_management_asset_delete, asset_management_disable, asset_management_enable, asset_management_general_settings_update
unmapped.jc_initiated_by_username
  • Description: JumpCloud Directory Insights field jc_initiated_by_username preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_initiated_by_username
  • Usage: asset_management_asset_delete, asset_management_disable, asset_management_enable, asset_management_general_settings_update
unmapped.jc_organization_name
  • Description: JumpCloud Directory Insights field jc_organization_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_organization_name
  • Usage: asset_management_asset_delete, asset_management_disable, asset_management_enable, asset_management_general_settings_update
unmapped.jc_provider_id
  • Description: JumpCloud Directory Insights field jc_provider_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_provider_id
  • Usage: asset_management_enable
unmapped.jc_system_display_name
  • Description: JumpCloud Directory Insights field jc_system_display_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_system_display_name
  • Usage: asset_management_asset_delete, asset_management_disable, asset_management_enable, asset_management_general_settings_update
unmapped.jc_system_hostname
  • Description: JumpCloud Directory Insights field jc_system_hostname preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_system_hostname
  • Usage: asset_management_asset_delete, asset_management_disable, asset_management_enable, asset_management_general_settings_update
unmapped.resource_id_hash
  • Description: JumpCloud Directory Insights field resource_id_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource_id_hash
  • Usage: asset_management_asset_create, asset_management_asset_delete, asset_management_asset_update, asset_management_field_setting_create, asset_management_field_setting_delete, asset_management_field_setting_update
unmapped.resource_name_hash
  • Description: JumpCloud Directory Insights field resource_name_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource_name_hash
  • Usage: asset_management_asset_delete
unmapped.timestamp_source
  • Description: JumpCloud Directory Insights field timestamp_source preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: timestamp_source
  • Usage: all events in this service

Directory — Command and Policy Events#

directory_command_policy · 35 events

Event Category Class Activity Type UID Fields
authnfallbackpolicy_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 45
authnfallbackpolicy_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 69
authnfallbackpolicy_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 53
authnpolicy_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 73
authnpolicy_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 66
authnpolicy_mfa_factor_selection_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 64
authnpolicy_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 56
background_access_file System Activity (1) Process Activity (1007) Open (3) 100703 66
background_access_shell System Activity (1) Process Activity (1007) Launch (1) 100701 51
command_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 43
command_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 71
command_result System Activity (1) Scheduled Job Activity (1006) Start (6) 100606 38
command_run Identity & Access Management (3) Entity Management (3004) Update (3) 300403 67
command_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 63
commandresult_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 63
commandtemplate_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 55
commandtemplate_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 59
commandtemplate_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 59
configuredpolicytemplate_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 66
configuredpolicytemplate_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 62
file_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 61
file_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 64
file_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 68
iplist_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 43
iplist_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 60
iplist_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 66
passwordpolicy_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 54
passwordpolicy_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 53
passwordpolicy_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 53
policy_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 48
policy_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 48
policy_result Discovery (5) Device Config State Change (5019) Log (1) 501901 37
policy_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 49
policygrouptemplate_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 63
policygrouptemplate_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 60

OCSF field mappings#

Legend

  • Description: what the OCSF field represents (from OCSF schema v1.8.0)
  • Source: raw JumpCloud event field(s) mapped via ${{placeholder}} template
  • Transform: fieldMappings entry applied at runtime (cast, enum, etc.)
  • Literal: static value set in the mapping template
  • Usage: event types in this service that include this field

Core

activity_id
  • Description: The normalized identifier of the activity that triggered the event.
  • Literal: 1, 3, 4, 6
  • Usage: all events in this service
activity_name
  • Description: The event activity name, as defined by the activity_id.
  • Literal: Create, Delete, Launch, Log, Open, Start, Update
  • Usage: all events in this service
category_name
  • Description: The event category name, as defined by category_uid value: Discovery.
  • Literal: Discovery, Identity & Access Management, System Activity
  • Usage: all events in this service
category_uid
  • Description: The category unique identifier of the event.
  • Literal: 1, 3, 5
  • Usage: all events in this service
class_name
  • Description: The event class name, as defined by class_uid value: User Inventory Info.
  • Literal: Device Config State Change, Entity Management, Process Activity, Scheduled Job Activity
  • Usage: all events in this service
class_uid
  • Description: The unique identifier of a class. A class describes the attributes available in an event.
  • Literal: 1006, 1007, 3004, 5019
  • Usage: all events in this service
message
  • Description: The description of the event/finding, as defined by the source.
  • Source: message
  • Usage: background_access_file, background_access_shell
severity_id
  • Description: OCSF severity identifier for the event.
  • Literal: 1
  • Usage: all events in this service
status_detail
  • Description: The status detail contains additional information about the event/finding outcome.
  • Source: error_message
  • Usage: 29 events: authnfallbackpolicy_delete, authnfallbackpolicy_update, authnpolicy_create, authnpolicy_delete, authnpolicy_mfa_factor_selection_update, authnpolicy_update, background_access_file, background_access_shell, ... (+21 more)
status_id
  • Description: Normalized status of the activity (1=Success, 2=Failure).
  • Source: success
  • Transform:
  • success → boolean_to_status_id; true→1, false→2 (26 events: authnfallbackpolicy_delete, authnfallbackpolicy_update, authnpolicy_mfa_factor_selection_update, background_access_file, background_access_shell, command_delete, command_result, command_run, ... (+18 more))
  • Usage: 26 events: authnfallbackpolicy_delete, authnfallbackpolicy_update, authnpolicy_mfa_factor_selection_update, background_access_file, background_access_shell, command_delete, command_result, command_run, ... (+18 more)
time
  • Description: Event time, in epoch milliseconds (OCSF time).
  • Source: timestamp
  • Transform:
  • timestamp → iso8601_to_epoch_millis (all events in this service)
  • Usage: all events in this service
type_uid
  • Description: The event/finding type ID. It identifies the event's semantics and structure. The value is calculated by the logging system as: class_uid * 100 + activity_id.
  • Literal: 100606, 100701, 100703, 300401, 300403, 300404, 501901
  • Usage: all events in this service

Metadata

metadata.event_code
  • Description: JumpCloud event type code.
  • Source: event_type
  • Usage: all events in this service
metadata.original_time
  • Description: The original event time as reported by the event source. For example, the time in the original format from system event log such as Syslog on Unix/Linux and the System event file on Windows. Omit if event is generated instead of collected via logs.
  • Source: server_timestamp
  • Usage: background_access_file, background_access_shell, command_result, passwordpolicy_create, passwordpolicy_delete, passwordpolicy_update, policy_result
metadata.processed_time
  • Description: The event processed time, such as an ETL operation.
  • Source: jc_transformation_ts
  • Usage: 26 events: authnfallbackpolicy_delete, authnfallbackpolicy_update, authnpolicy_mfa_factor_selection_update, background_access_file, background_access_shell, command_delete, command_result, command_run, ... (+18 more)
metadata.product.name
  • Description: Originating JumpCloud service that produced the event.
  • Source: service
  • Usage: all events in this service
metadata.tenant_uid
  • Description: JumpCloud organization (tenant) identifier.
  • Source: organization
  • Usage: all events in this service
metadata.uid
  • Description: Unique event identifier assigned by JumpCloud.
  • Source: id
  • Usage: all events in this service
metadata.version
  • Description: OCSF schema version used for this event.
  • Literal: 1.8.0
  • Usage: all events in this service

Actor

actor.user.email_addr
  • Description: Email address of the actor who initiated the event.
  • Source: initiated_by.email
  • Usage: 33 events (missing: command_result, policy_result)
actor.user.name
  • Description: Display name of the actor who initiated the event.
  • Source: initiated_by.name
  • Usage: background_access_file, background_access_shell, command_run
actor.user.type_id
  • Description: OCSF user type of the actor (1=User, 2=Admin, 3=System, 4=Service).
  • Source: initiated_by.type
  • Transform:
  • initiated_by.type → enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (33 events (missing: command_result, policy_result))
  • Usage: 33 events (missing: command_result, policy_result)
actor.user.uid
  • Description: Unique identifier of the actor who initiated the event.
  • Source: initiated_by.id
  • Usage: 33 events (missing: command_result, policy_result)

Device

device.hostname
  • Description: The device hostname.
  • Source: system.hostname
  • Usage: background_access_file, background_access_shell
device.hw_info.serial_number
  • Description: The device manufacturer serial number.
  • Source: system.serialno
  • Usage: background_access_file, background_access_shell
device.name
  • Description: The alternate device name, ordinarily as assigned by an administrator.

    Note: The Name could be any other string that helps to identify the device, such as a phone number; for example 310-555-1234.

  • Source: system.displayName
  • Usage: background_access_file, background_access_shell
device.uid
  • Description: The unique identifier of the device. For example the Windows TargetSID or AWS EC2 ARN.
  • Source: resource.id, system.id
  • Usage: background_access_file, background_access_shell, command_result, policy_result

Entity

entity.data.auth_method
  • Description: JumpCloud extension data on the managed entity: auth_method.
  • Source: auth_method
  • Usage: 28 events: authnfallbackpolicy_create, authnfallbackpolicy_delete, authnfallbackpolicy_update, authnpolicy_create, authnpolicy_delete, authnpolicy_mfa_factor_selection_update, authnpolicy_update, command_create, ... (+20 more)
entity.data.changed_field
  • Description: JumpCloud extension data on the managed entity: changed_field.
  • Source: changes.field
  • Usage: 27 events: authnfallbackpolicy_create, authnfallbackpolicy_delete, authnfallbackpolicy_update, authnpolicy_create, authnpolicy_delete, authnpolicy_mfa_factor_selection_update, authnpolicy_update, command_create, ... (+19 more)
entity.data.changes_from
  • Description: JumpCloud extension data on the managed entity: changes_from.
  • Source: changes.from
  • Usage: authnpolicy_mfa_factor_selection_update, command_delete, command_update, commandtemplate_delete, file_delete, file_update, iplist_delete, iplist_update, policy_delete, policy_update
entity.data.changes_from_all_deviceEncrypted
  • Description: JumpCloud extension data on the managed entity: changes_from_all_deviceEncrypted.
  • Source: changes.from.all.deviceEncrypted
  • Usage: authnpolicy_delete
entity.data.changes_from_all_deviceManaged
  • Description: JumpCloud extension data on the managed entity: changes_from_all_deviceManaged.
  • Source: changes.from.all.deviceManaged
  • Usage: authnpolicy_delete, authnpolicy_update
entity.data.changes_from_all_ipAddressIn
  • Description: JumpCloud extension data on the managed entity: changes_from_all_ipAddressIn.
  • Source: changes.from.all.ipAddressIn
  • Usage: authnpolicy_delete, authnpolicy_update
entity.data.changes_from_all_locationIn_countries
  • Description: JumpCloud extension data on the managed entity: changes_from_all_locationIn_countries.
  • Source: changes.from.all.locationIn.countries
  • Usage: authnpolicy_delete, authnpolicy_update
entity.data.changes_from_any_deviceEncrypted
  • Description: JumpCloud extension data on the managed entity: changes_from_any_deviceEncrypted.
  • Source: changes.from.any.deviceEncrypted
  • Usage: authnpolicy_delete
entity.data.changes_from_any_deviceManaged
  • Description: JumpCloud extension data on the managed entity: changes_from_any_deviceManaged.
  • Source: changes.from.any.deviceManaged
  • Usage: authnpolicy_delete
entity.data.changes_from_any_not_ipAddressIn
  • Description: JumpCloud extension data on the managed entity: changes_from_any_not_ipAddressIn.
  • Source: changes.from.any.not.ipAddressIn
  • Usage: authnpolicy_delete
entity.data.changes_from_any_not_locationIn_countries
  • Description: JumpCloud extension data on the managed entity: changes_from_any_not_locationIn_countries.
  • Source: changes.from.any.not.locationIn.countries
  • Usage: authnpolicy_delete
entity.data.changes_from_exclusions
  • Description: JumpCloud extension data on the managed entity: changes_from_exclusions.
  • Source: changes.from.exclusions
  • Usage: authnpolicy_delete
entity.data.changes_from_id
  • Description: JumpCloud extension data on the managed entity: changes_from_id.
  • Source: changes.from.id
  • Usage: authnpolicy_delete
entity.data.changes_from_inclusions
  • Description: JumpCloud extension data on the managed entity: changes_from_inclusions.
  • Source: changes.from.inclusions
  • Usage: authnpolicy_delete
entity.data.changes_from_locationIn_countries
  • Description: JumpCloud extension data on the managed entity: changes_from_locationIn_countries.
  • Source: changes.from.locationIn.countries
  • Usage: authnpolicy_delete
entity.data.changes_from_mfaFactors
  • Description: JumpCloud extension data on the managed entity: changes_from_mfaFactors.
  • Source: changes.from.mfaFactors
  • Usage: authnfallbackpolicy_update
entity.data.changes_from_mfaFactors_id_data
  • Description: JumpCloud extension data on the managed entity: changes_from_mfaFactors_id_data.
  • Source: changes.from.mfaFactors.id.data
  • Usage: authnfallbackpolicy_delete
entity.data.changes_from_mfaFactors_id_type
  • Description: JumpCloud extension data on the managed entity: changes_from_mfaFactors_id_type.
  • Source: changes.from.mfaFactors.id.type
  • Usage: authnfallbackpolicy_delete
entity.data.changes_from_mfaFactors_type
  • Description: JumpCloud extension data on the managed entity: changes_from_mfaFactors_type.
  • Source: changes.from.mfaFactors.type
  • Usage: authnfallbackpolicy_delete
entity.data.changes_from_mfa_required
  • Description: JumpCloud extension data on the managed entity: changes_from_mfa_required.
  • Source: changes.from.mfa.required
  • Usage: authnfallbackpolicy_delete, authnfallbackpolicy_update, authnpolicy_delete
entity.data.changes_from_type
  • Description: JumpCloud extension data on the managed entity: changes_from_type.
  • Source: changes.from.type
  • Usage: authnpolicy_delete
entity.data.changes_from_userVerification_requirement
  • Description: JumpCloud extension data on the managed entity: changes_from_userVerification_requirement.
  • Source: changes.from.userVerification.requirement
  • Usage: authnfallbackpolicy_delete, authnfallbackpolicy_update
entity.data.changes_to
  • Description: JumpCloud extension data on the managed entity: changes_to.
  • Source: changes.to
  • Usage: policygrouptemplate_delete
entity.data.command
  • Description: JumpCloud extension data on the managed entity: command.
  • Source: resource.command
  • Usage: commandresult_delete
entity.data.initiated_by_provider
  • Description: JumpCloud extension data on the managed entity: initiated_by_provider.
  • Source: initiated_by.provider
  • Usage: 14 events: authnfallbackpolicy_delete, authnpolicy_mfa_factor_selection_update, command_run, command_update, commandtemplate_create, commandtemplate_delete, commandtemplate_update, configuredpolicytemplate_create, ... (+6 more)
entity.data.initiated_by_user_id
  • Description: JumpCloud extension data on the managed entity: initiated_by_user_id.
  • Source: initiated_by.user_id
  • Usage: command_run, file_delete, file_update
entity.data.metadata.action
  • Description: JumpCloud extension data on the managed entity: metadata.action.
  • Source: resource.metadata.action
  • Usage: authnpolicy_create, authnpolicy_delete, authnpolicy_update
entity.data.metadata.conditions
  • Description: JumpCloud extension data on the managed entity: metadata.conditions.
  • Source: resource.metadata.conditions
  • Usage: authnpolicy_create, authnpolicy_delete, authnpolicy_update
entity.data.metadata.resource_type
  • Description: JumpCloud extension data on the managed entity: metadata.resource_type.
  • Source: resource.metadata.resource_type
  • Usage: authnpolicy_create, authnpolicy_delete, authnpolicy_update
entity.data.metadata.targets
  • Description: JumpCloud extension data on the managed entity: metadata.targets.
  • Source: resource.metadata.targets
  • Usage: authnpolicy_create, authnpolicy_delete, authnpolicy_update
entity.data.os_meta_family
  • Description: JumpCloud extension data on the managed entity: os_meta_family.
  • Source: os_meta_family
  • Usage: policy_create, policy_delete, policy_update
entity.data.provider
  • Description: JumpCloud extension data on the managed entity: provider.
  • Source: provider
  • Usage: 27 events: authnfallbackpolicy_create, authnfallbackpolicy_delete, authnfallbackpolicy_update, authnpolicy_create, authnpolicy_delete, authnpolicy_mfa_factor_selection_update, authnpolicy_update, command_create, ... (+19 more)
entity.data.resourceType
  • Description: JumpCloud extension data on the managed entity: resourceType.
  • Source: resource.resourceType
  • Usage: authnfallbackpolicy_create, authnfallbackpolicy_delete, authnfallbackpolicy_update
entity.data.workflow_id
  • Description: JumpCloud extension data on the managed entity: workflow_id.
  • Source: initiated_by.source_metadata.workflow.id
  • Usage: command_run
entity.data.workflow_run_id
  • Description: JumpCloud extension data on the managed entity: workflow_run_id.
  • Source: initiated_by.source_metadata.workflow.run_id
  • Usage: command_run
entity.data.workflow_type
  • Description: JumpCloud extension data on the managed entity: workflow_type.
  • Source: initiated_by.source_metadata.workflow.type
  • Usage: command_run
entity.name
  • Description: The name of the managed entity. It should match the name of the specific entity object's name if populated, or the name of the managed entity if the type_id is 'Other'.
  • Source: resource.name
  • Usage: 23 events: authnpolicy_create, authnpolicy_delete, authnpolicy_mfa_factor_selection_update, authnpolicy_update, command_create, command_delete, command_run, command_update, ... (+15 more)
entity.type
  • Description: The managed entity type. For example: Policy, User, Organization, Device.
  • Source: resource.type
  • Usage: 31 events: authnfallbackpolicy_create, authnfallbackpolicy_delete, authnfallbackpolicy_update, authnpolicy_create, authnpolicy_delete, authnpolicy_mfa_factor_selection_update, authnpolicy_update, command_create, ... (+23 more)
entity.uid
  • Description: The identifier of the managed entity. It should match the uid of the specific entity's object UID if populated, or the source specific ID if the type_id is 'Other'.
  • Source: resource.id
  • Usage: 27 events: authnpolicy_create, authnpolicy_delete, authnpolicy_mfa_factor_selection_update, authnpolicy_update, command_delete, command_run, command_update, commandresult_delete, ... (+19 more)
entity_result.data.changes_to
  • Description: JumpCloud extension data on the managed entity: changes_to.
  • Source: changes.to
  • Usage: 14 events: authnpolicy_mfa_factor_selection_update, authnpolicy_update, command_create, command_update, commandtemplate_create, commandtemplate_update, configuredpolicytemplate_delete, file_create, ... (+6 more)
entity_result.data.changes_to_all_deviceManaged
  • Description: JumpCloud extension data on the managed entity: changes_to_all_deviceManaged.
  • Source: changes.to.all.deviceManaged
  • Usage: authnpolicy_create
entity_result.data.changes_to_all_ipAddressIn
  • Description: JumpCloud extension data on the managed entity: changes_to_all_ipAddressIn.
  • Source: changes.to.all.ipAddressIn
  • Usage: authnpolicy_create
entity_result.data.changes_to_all_locationIn_countries
  • Description: JumpCloud extension data on the managed entity: changes_to_all_locationIn_countries.
  • Source: changes.to.all.locationIn.countries
  • Usage: authnpolicy_create
entity_result.data.changes_to_all_operatingSystemIn
  • Description: JumpCloud extension data on the managed entity: changes_to_all_operatingSystemIn.
  • Source: changes.to.all.operatingSystemIn
  • Usage: authnpolicy_create
entity_result.data.changes_to_any_deviceEncrypted
  • Description: JumpCloud extension data on the managed entity: changes_to_any_deviceEncrypted.
  • Source: changes.to.any.deviceEncrypted
  • Usage: authnpolicy_create
entity_result.data.changes_to_any_deviceManaged
  • Description: JumpCloud extension data on the managed entity: changes_to_any_deviceManaged.
  • Source: changes.to.any.deviceManaged
  • Usage: authnpolicy_create
entity_result.data.changes_to_any_ipAddressIn
  • Description: JumpCloud extension data on the managed entity: changes_to_any_ipAddressIn.
  • Source: changes.to.any.ipAddressIn
  • Usage: authnpolicy_create
entity_result.data.changes_to_any_locationIn_countries
  • Description: JumpCloud extension data on the managed entity: changes_to_any_locationIn_countries.
  • Source: changes.to.any.locationIn.countries
  • Usage: authnpolicy_create
entity_result.data.changes_to_any_not_ipAddressIn
  • Description: JumpCloud extension data on the managed entity: changes_to_any_not_ipAddressIn.
  • Source: changes.to.any.not.ipAddressIn
  • Usage: authnpolicy_create
entity_result.data.changes_to_any_not_locationIn_countries
  • Description: JumpCloud extension data on the managed entity: changes_to_any_not_locationIn_countries.
  • Source: changes.to.any.not.locationIn.countries
  • Usage: authnpolicy_create
entity_result.data.changes_to_any_operatingSystemIn
  • Description: JumpCloud extension data on the managed entity: changes_to_any_operatingSystemIn.
  • Source: changes.to.any.operatingSystemIn
  • Usage: authnpolicy_create
entity_result.data.changes_to_configFieldID
  • Description: JumpCloud extension data on the managed entity: changes_to_configFieldID.
  • Source: changes.to.configFieldID
  • Usage: configuredpolicytemplate_create
entity_result.data.changes_to_configFieldName
  • Description: JumpCloud extension data on the managed entity: changes_to_configFieldName.
  • Source: changes.to.configFieldName
  • Usage: configuredpolicytemplate_create
entity_result.data.changes_to_deviceManaged
  • Description: JumpCloud extension data on the managed entity: changes_to_deviceManaged.
  • Source: changes.to.deviceManaged
  • Usage: authnpolicy_create
entity_result.data.changes_to_exclusions
  • Description: JumpCloud extension data on the managed entity: changes_to_exclusions.
  • Source: changes.to.exclusions
  • Usage: authnpolicy_create
entity_result.data.changes_to_id
  • Description: JumpCloud extension data on the managed entity: changes_to_id.
  • Source: changes.to.id
  • Usage: authnpolicy_create
entity_result.data.changes_to_inclusions
  • Description: JumpCloud extension data on the managed entity: changes_to_inclusions.
  • Source: changes.to.inclusions
  • Usage: authnpolicy_create
entity_result.data.changes_to_ipAddressIn
  • Description: JumpCloud extension data on the managed entity: changes_to_ipAddressIn.
  • Source: changes.to.ipAddressIn
  • Usage: authnpolicy_create
entity_result.data.changes_to_locationIn_countries
  • Description: JumpCloud extension data on the managed entity: changes_to_locationIn_countries.
  • Source: changes.to.locationIn.countries
  • Usage: authnpolicy_create
entity_result.data.changes_to_mfaFactors
  • Description: JumpCloud extension data on the managed entity: changes_to_mfaFactors.
  • Source: changes.to.mfaFactors
  • Usage: authnfallbackpolicy_create, authnfallbackpolicy_update
entity_result.data.changes_to_mfa_required
  • Description: JumpCloud extension data on the managed entity: changes_to_mfa_required.
  • Source: changes.to.mfa.required
  • Usage: authnfallbackpolicy_create, authnfallbackpolicy_update, authnpolicy_create
entity_result.data.changes_to_nanos
  • Description: JumpCloud extension data on the managed entity: changes_to_nanos.
  • Source: changes.to.nanos
  • Usage: commandresult_delete
entity_result.data.changes_to_not_ipAddressIn
  • Description: JumpCloud extension data on the managed entity: changes_to_not_ipAddressIn.
  • Source: changes.to.not.ipAddressIn
  • Usage: authnpolicy_create
entity_result.data.changes_to_operatingSystemIn
  • Description: JumpCloud extension data on the managed entity: changes_to_operatingSystemIn.
  • Source: changes.to.operatingSystemIn
  • Usage: authnpolicy_create
entity_result.data.changes_to_seconds
  • Description: JumpCloud extension data on the managed entity: changes_to_seconds.
  • Source: changes.to.seconds
  • Usage: commandresult_delete
entity_result.data.changes_to_sensitive
  • Description: JumpCloud extension data on the managed entity: changes_to_sensitive.
  • Source: changes.to.sensitive
  • Usage: configuredpolicytemplate_create
entity_result.data.changes_to_type
  • Description: JumpCloud extension data on the managed entity: changes_to_type.
  • Source: changes.to.type
  • Usage: authnpolicy_create
entity_result.data.changes_to_userVerification_requirement
  • Description: JumpCloud extension data on the managed entity: changes_to_userVerification_requirement.
  • Source: changes.to.userVerification.requirement
  • Usage: authnfallbackpolicy_create, authnfallbackpolicy_update
entity_result.data.changes_to_value
  • Description: JumpCloud extension data on the managed entity: changes_to_value.
  • Source: changes.to.value
  • Usage: configuredpolicytemplate_create

Src Endpoint

src_endpoint.autonomous_system.name
  • Description: Organization name for the Autonomous System.
  • Source: asn.organization
  • Usage: 16 events: authnfallbackpolicy_delete, authnpolicy_mfa_factor_selection_update, command_delete, command_run, commandresult_delete, commandtemplate_create, commandtemplate_delete, commandtemplate_update, ... (+8 more)
src_endpoint.autonomous_system.number
  • Description: Unique number that the AS is identified by.
  • Source: asn.number
  • Transform:
  • asn.number → int (16 events: authnfallbackpolicy_delete, authnpolicy_mfa_factor_selection_update, command_delete, command_run, commandresult_delete, commandtemplate_create, commandtemplate_delete, commandtemplate_update, ... (+8 more))
  • Usage: 16 events: authnfallbackpolicy_delete, authnpolicy_mfa_factor_selection_update, command_delete, command_run, commandresult_delete, commandtemplate_create, commandtemplate_delete, commandtemplate_update, ... (+8 more)
src_endpoint.ip
  • Description: Source IP address the request originated from.
  • Source: client_ip
  • Usage: 31 events: authnfallbackpolicy_create, authnfallbackpolicy_delete, authnfallbackpolicy_update, authnpolicy_create, authnpolicy_delete, authnpolicy_mfa_factor_selection_update, authnpolicy_update, command_create, ... (+23 more)
src_endpoint.location.city
  • Description: The name of the city.
  • Source: geoip.city
  • Usage: 18 events: authnfallbackpolicy_delete, authnpolicy_mfa_factor_selection_update, command_delete, command_run, command_update, commandresult_delete, commandtemplate_create, commandtemplate_delete, ... (+10 more)
src_endpoint.location.continent
  • Description: The name of the continent.
  • Source: geoip.continent_code
  • Usage: 28 events: authnfallbackpolicy_create, authnfallbackpolicy_delete, authnfallbackpolicy_update, authnpolicy_create, authnpolicy_delete, authnpolicy_mfa_factor_selection_update, authnpolicy_update, command_create, ... (+20 more)
src_endpoint.location.country
  • Description: The ISO 3166-1 Alpha-2 country code.

    Note: The two letter country code should be capitalized. For example: US or CA.

  • Source: geoip.country_code
  • Usage: 28 events: authnfallbackpolicy_create, authnfallbackpolicy_delete, authnfallbackpolicy_update, authnpolicy_create, authnpolicy_delete, authnpolicy_mfa_factor_selection_update, authnpolicy_update, command_create, ... (+20 more)
src_endpoint.location.lat
  • Description: The geographical Latitude coordinate represented in Decimal Degrees (DD). For example: 42.361145.
  • Source: geoip.latitude
  • Transform:
  • geoip.latitude → double (28 events: authnfallbackpolicy_create, authnfallbackpolicy_delete, authnfallbackpolicy_update, authnpolicy_create, authnpolicy_delete, authnpolicy_mfa_factor_selection_update, authnpolicy_update, command_create, ... (+20 more))
  • Usage: 28 events: authnfallbackpolicy_create, authnfallbackpolicy_delete, authnfallbackpolicy_update, authnpolicy_create, authnpolicy_delete, authnpolicy_mfa_factor_selection_update, authnpolicy_update, command_create, ... (+20 more)
src_endpoint.location.long
  • Description: The geographical Longitude coordinate represented in Decimal Degrees (DD). For example: -71.057083.
  • Source: geoip.longitude
  • Transform:
  • geoip.longitude → double (28 events: authnfallbackpolicy_create, authnfallbackpolicy_delete, authnfallbackpolicy_update, authnpolicy_create, authnpolicy_delete, authnpolicy_mfa_factor_selection_update, authnpolicy_update, command_create, ... (+20 more))
  • Usage: 28 events: authnfallbackpolicy_create, authnfallbackpolicy_delete, authnfallbackpolicy_update, authnpolicy_create, authnpolicy_delete, authnpolicy_mfa_factor_selection_update, authnpolicy_update, command_create, ... (+20 more)
src_endpoint.location.region
  • Description: The alphanumeric code that identifies the principal subdivision (e.g. province or state) of the country. For example, 'CH-VD' for the Canton of Vaud, Switzerland
  • Source: geoip.region_code
  • Usage: 28 events: authnfallbackpolicy_create, authnfallbackpolicy_delete, authnfallbackpolicy_update, authnpolicy_create, authnpolicy_delete, authnpolicy_mfa_factor_selection_update, authnpolicy_update, command_create, ... (+20 more)

Http Request

http_request.user_agent
  • Description: The request header that identifies the operating system and web browser.
  • Source: user_agent
  • Usage: 21 events: authnfallbackpolicy_delete, authnpolicy_mfa_factor_selection_update, command_delete, command_run, command_update, commandresult_delete, commandtemplate_create, commandtemplate_delete, ... (+13 more)

Observables

observables[].name
  • Description: The full name of the observable attribute. The name is a pointer/reference to an attribute within the OCSF event data. For example: file.name. Array attributes may be represented in one of three ways. For example: resources.uid, resources[].uid, resources[0].uid.
  • Literal: actor.user.email_addr, actor.user.name, actor.user.uid, device.hostname, device.hw_info.serial_number, device.uid, http_request.user_agent, process.cmd_line, src_endpoint.ip, src_endpoint.location.country
  • Usage: all events in this service
observables[].type_id
  • Description: The observable value type identifier.
  • Literal: 1, 13, 14, 16, 2, 31, 37, 4, 47, 5
  • Usage: all events in this service
observables[].value
  • Description: The value associated with the observable attribute. The meaning of the value depends on the observable type.
    If the name refers to a scalar attribute, then the value is the value of the attribute.
    If the name refers to an object attribute, then the value is not populated.
  • Source: admin_info.email, admin_info.id, admin_info.name, client_ip, commands.command, geoip.country_code, initiated_by.email, initiated_by.id, initiated_by.name, resource.id, system.hostname, system.id, system.serialno, user_agent
  • Usage: all events in this service

Other

job.desc
  • Description: The description of the job.
  • Source: resource.command_id
  • Usage: command_result
job.name
  • Description: The name of the job.
  • Source: resource.command_name
  • Usage: command_result
policy.name
  • Description: The policy name. For example: AdministratorAccess Policy.
  • Source: resource.policy_name
  • Usage: policy_result
policy.uid
  • Description: A unique identifier of the policy instance.
  • Source: resource.policy_id
  • Usage: policy_result
process.cmd_line
  • Description: The full command line used to launch an application, service, process, or job. For example: ssh user@10.0.0.10. If the command line is unavailable or missing, the empty string '' is to be used.
  • Source: commands.command
  • Usage: background_access_shell
process.created_time
  • Description: The time when the process was created/started.
  • Source: commands.timestamp
  • Usage: background_access_file, background_access_shell
state
  • Description: The normalized state of a security finding.
  • Source: state
  • Usage: policy_result

Unmapped

unmapped.@timestamp
  • Description: JumpCloud Directory Insights field @timestamp preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: @timestamp
  • Usage: 15 events: authnfallbackpolicy_create, authnfallbackpolicy_update, authnpolicy_create, authnpolicy_delete, authnpolicy_update, command_create, command_delete, command_result, ... (+7 more)
unmapped.@version
  • Description: JumpCloud Directory Insights field @version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: @version
  • Usage: all events in this service
unmapped.asn.error
  • Description: JumpCloud Directory Insights field asn.error preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: asn.error
  • Usage: background_access_file, background_access_shell
unmapped.asn.ip_address
  • Description: JumpCloud Directory Insights field asn.ip_address preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: asn.ip_address
  • Usage: background_access_file, background_access_shell
unmapped.asn.network
  • Description: JumpCloud Directory Insights field asn.network preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: asn.network
  • Usage: 17 events: authnfallbackpolicy_delete, authnpolicy_mfa_factor_selection_update, background_access_file, command_delete, command_run, commandresult_delete, commandtemplate_create, commandtemplate_delete, ... (+9 more)
unmapped.asn.number
  • Description: JumpCloud Directory Insights field asn.number preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: asn.number
  • Usage: background_access_file
unmapped.asn.organization
  • Description: JumpCloud Directory Insights field asn.organization preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: asn.organization
  • Usage: background_access_file
unmapped.client_ip
  • Description: JumpCloud Directory Insights field client_ip preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: client_ip
  • Usage: background_access_file, background_access_shell, command_result, policy_result
unmapped.commands.type
  • Description: JumpCloud Directory Insights field commands.type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: commands.type
  • Usage: background_access_file
unmapped.correlation
  • Description: JumpCloud Directory Insights field correlation preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: correlation
  • Usage: command_delete, command_update
unmapped.correlation.id
  • Description: JumpCloud Directory Insights field correlation.id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: correlation.id
  • Usage: background_access_file, background_access_shell
unmapped.correlation.session_duration
  • Description: JumpCloud Directory Insights field correlation.session_duration preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: correlation.session_duration
  • Usage: background_access_file, background_access_shell
unmapped.correlation.type
  • Description: JumpCloud Directory Insights field correlation.type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: correlation.type
  • Usage: background_access_file, background_access_shell
unmapped.exit_code
  • Description: JumpCloud Directory Insights field exit_code preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: exit_code
  • Usage: command_result
unmapped.file_input_timestamp
  • Description: JumpCloud Directory Insights field file_input_timestamp preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: file_input_timestamp
  • Usage: 16 events: authnfallbackpolicy_create, authnfallbackpolicy_update, authnpolicy_create, authnpolicy_delete, authnpolicy_update, background_access_file, command_create, command_delete, ... (+8 more)
unmapped.geoip.city
  • Description: JumpCloud Directory Insights field geoip.city preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.city
  • Usage: background_access_file
unmapped.geoip.continent_code
  • Description: JumpCloud Directory Insights field geoip.continent_code preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.continent_code
  • Usage: background_access_file
unmapped.geoip.country_code
  • Description: JumpCloud Directory Insights field geoip.country_code preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.country_code
  • Usage: background_access_file
unmapped.geoip.error
  • Description: JumpCloud Directory Insights field geoip.error preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.error
  • Usage: background_access_file, background_access_shell
unmapped.geoip.ip_address
  • Description: JumpCloud Directory Insights field geoip.ip_address preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.ip_address
  • Usage: background_access_file, background_access_shell
unmapped.geoip.latitude
  • Description: JumpCloud Directory Insights field geoip.latitude preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.latitude
  • Usage: background_access_file
unmapped.geoip.longitude
  • Description: JumpCloud Directory Insights field geoip.longitude preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.longitude
  • Usage: background_access_file
unmapped.geoip.region_code
  • Description: JumpCloud Directory Insights field geoip.region_code preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.region_code
  • Usage: background_access_file
unmapped.geoip.region_name
  • Description: JumpCloud Directory Insights field geoip.region_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.region_name
  • Usage: 29 events: authnfallbackpolicy_create, authnfallbackpolicy_delete, authnfallbackpolicy_update, authnpolicy_create, authnpolicy_delete, authnpolicy_mfa_factor_selection_update, authnpolicy_update, background_access_file, ... (+21 more)
unmapped.geoip.timezone
  • Description: JumpCloud Directory Insights field geoip.timezone preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.timezone
  • Usage: 29 events: authnfallbackpolicy_create, authnfallbackpolicy_delete, authnfallbackpolicy_update, authnpolicy_create, authnpolicy_delete, authnpolicy_mfa_factor_selection_update, authnpolicy_update, background_access_file, ... (+21 more)
unmapped.initiated_by
  • Description: JumpCloud Directory Insights field initiated_by preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by
  • Usage: command_result, policy_result
unmapped.initiated_by.hostname
  • Description: JumpCloud Directory Insights field initiated_by.hostname preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by.hostname
  • Usage: background_access_file, background_access_shell
unmapped.initiated_by.uid
  • Description: JumpCloud Directory Insights field initiated_by.uid preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by.uid
  • Usage: background_access_file, background_access_shell
unmapped.initiated_by.username
  • Description: JumpCloud Directory Insights field initiated_by.username preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by.username
  • Usage: background_access_file, background_access_shell
unmapped.initiated_by_email_hash
  • Description: JumpCloud Directory Insights field initiated_by_email_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_email_hash
  • Usage: 24 events: authnfallbackpolicy_delete, authnfallbackpolicy_update, authnpolicy_mfa_factor_selection_update, background_access_file, background_access_shell, command_delete, command_run, command_update, ... (+16 more)
unmapped.initiated_by_id_hash
  • Description: JumpCloud Directory Insights field initiated_by_id_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_id_hash
  • Usage: 24 events: authnfallbackpolicy_delete, authnfallbackpolicy_update, authnpolicy_mfa_factor_selection_update, background_access_file, background_access_shell, command_delete, command_run, command_update, ... (+16 more)
unmapped.initiated_by_name_hash
  • Description: JumpCloud Directory Insights field initiated_by_name_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_name_hash
  • Usage: command_run
unmapped.is_out_of_bound
  • Description: JumpCloud Directory Insights field is_out_of_bound preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: is_out_of_bound
  • Usage: 25 events: authnfallbackpolicy_delete, authnpolicy_mfa_factor_selection_update, background_access_file, background_access_shell, command_delete, command_result, command_run, command_update, ... (+17 more)
unmapped.jc_application_name
  • Description: JumpCloud Directory Insights field jc_application_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_application_name
  • Usage: 25 events: authnfallbackpolicy_delete, authnpolicy_mfa_factor_selection_update, background_access_file, background_access_shell, command_delete, command_result, command_run, command_update, ... (+17 more)
unmapped.jc_initiated_by_email
  • Description: JumpCloud Directory Insights field jc_initiated_by_email preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_initiated_by_email
  • Usage: authnfallbackpolicy_delete, command_delete, commandtemplate_delete, commandtemplate_update, iplist_update, passwordpolicy_create, passwordpolicy_delete
unmapped.jc_initiated_by_username
  • Description: JumpCloud Directory Insights field jc_initiated_by_username preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_initiated_by_username
  • Usage: authnfallbackpolicy_delete, command_delete, commandtemplate_delete, commandtemplate_update, iplist_update, passwordpolicy_create, passwordpolicy_delete
unmapped.jc_organization_name
  • Description: JumpCloud Directory Insights field jc_organization_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_organization_name
  • Usage: authnfallbackpolicy_delete, command_delete, commandtemplate_delete, commandtemplate_update, iplist_update, passwordpolicy_create, passwordpolicy_delete
unmapped.jc_provider_id
  • Description: JumpCloud Directory Insights field jc_provider_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_provider_id
  • Usage: authnfallbackpolicy_delete, command_delete, commandtemplate_delete, commandtemplate_update, passwordpolicy_create, passwordpolicy_delete
unmapped.message_chain
  • Description: JumpCloud Directory Insights field message_chain preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: message_chain
  • Usage: background_access_file, command_delete, command_result, command_update
unmapped.previous_state
  • Description: JumpCloud Directory Insights field previous_state preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: previous_state
  • Usage: policy_result
unmapped.resource.policy_template_id
  • Description: JumpCloud Directory Insights field resource.policy_template_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.policy_template_id
  • Usage: policy_result
unmapped.resource.policy_template_name
  • Description: JumpCloud Directory Insights field resource.policy_template_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.policy_template_name
  • Usage: policy_result
unmapped.resource.type
  • Description: JumpCloud Directory Insights field resource.type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.type
  • Usage: command_result, policy_result
unmapped.resource_id_hash
  • Description: JumpCloud Directory Insights field resource_id_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource_id_hash
  • Usage: 22 events: authnpolicy_mfa_factor_selection_update, command_delete, command_result, command_run, command_update, commandresult_delete, commandtemplate_create, commandtemplate_delete, ... (+14 more)
unmapped.system_id_hash
  • Description: JumpCloud Directory Insights field system_id_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: system_id_hash
  • Usage: background_access_file
unmapped.tags
  • Description: JumpCloud Directory Insights field tags preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: tags
  • Usage: 16 events: authnfallbackpolicy_create, authnfallbackpolicy_update, authnpolicy_create, authnpolicy_delete, authnpolicy_update, background_access_file, command_create, command_delete, ... (+8 more)
unmapped.timestamp_source
  • Description: JumpCloud Directory Insights field timestamp_source preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: timestamp_source
  • Usage: background_access_file, background_access_shell, command_result, passwordpolicy_create, passwordpolicy_delete, passwordpolicy_update, policy_result
unmapped.user_agent
  • Description: JumpCloud Directory Insights field user_agent preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: user_agent
  • Usage: background_access_file, background_access_shell, command_result, policy_result
unmapped.useragent.device
  • Description: JumpCloud Directory Insights field useragent.device preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.device
  • Usage: 31 events: authnfallbackpolicy_create, authnfallbackpolicy_delete, authnfallbackpolicy_update, authnpolicy_create, authnpolicy_delete, authnpolicy_mfa_factor_selection_update, authnpolicy_update, command_create, ... (+23 more)
unmapped.useragent.major
  • Description: JumpCloud Directory Insights field useragent.major preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.major
  • Usage: 24 events: authnfallbackpolicy_delete, authnpolicy_create, authnpolicy_delete, authnpolicy_mfa_factor_selection_update, authnpolicy_update, command_delete, command_run, command_update, ... (+16 more)
unmapped.useragent.minor
  • Description: JumpCloud Directory Insights field useragent.minor preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.minor
  • Usage: 24 events: authnfallbackpolicy_delete, authnpolicy_create, authnpolicy_delete, authnpolicy_mfa_factor_selection_update, authnpolicy_update, command_delete, command_run, command_update, ... (+16 more)
unmapped.useragent.name
  • Description: JumpCloud Directory Insights field useragent.name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.name
  • Usage: 31 events: authnfallbackpolicy_create, authnfallbackpolicy_delete, authnfallbackpolicy_update, authnpolicy_create, authnpolicy_delete, authnpolicy_mfa_factor_selection_update, authnpolicy_update, command_create, ... (+23 more)
unmapped.useragent.os
  • Description: JumpCloud Directory Insights field useragent.os preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os
  • Usage: 31 events: authnfallbackpolicy_create, authnfallbackpolicy_delete, authnfallbackpolicy_update, authnpolicy_create, authnpolicy_delete, authnpolicy_mfa_factor_selection_update, authnpolicy_update, command_create, ... (+23 more)
unmapped.useragent.os_full
  • Description: JumpCloud Directory Insights field useragent.os_full preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_full
  • Usage: 31 events: authnfallbackpolicy_create, authnfallbackpolicy_delete, authnfallbackpolicy_update, authnpolicy_create, authnpolicy_delete, authnpolicy_mfa_factor_selection_update, authnpolicy_update, command_create, ... (+23 more)
unmapped.useragent.os_major
  • Description: JumpCloud Directory Insights field useragent.os_major preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_major
  • Usage: 18 events: authnfallbackpolicy_delete, authnpolicy_mfa_factor_selection_update, command_delete, command_run, command_update, commandresult_delete, configuredpolicytemplate_create, configuredpolicytemplate_delete, ... (+10 more)
unmapped.useragent.os_minor
  • Description: JumpCloud Directory Insights field useragent.os_minor preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_minor
  • Usage: 17 events: authnfallbackpolicy_delete, authnpolicy_mfa_factor_selection_update, command_delete, command_run, command_update, commandresult_delete, configuredpolicytemplate_create, configuredpolicytemplate_delete, ... (+9 more)
unmapped.useragent.os_name
  • Description: JumpCloud Directory Insights field useragent.os_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_name
  • Usage: 31 events: authnfallbackpolicy_create, authnfallbackpolicy_delete, authnfallbackpolicy_update, authnpolicy_create, authnpolicy_delete, authnpolicy_mfa_factor_selection_update, authnpolicy_update, command_create, ... (+23 more)
unmapped.useragent.os_patch
  • Description: JumpCloud Directory Insights field useragent.os_patch preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_patch
  • Usage: 17 events: authnfallbackpolicy_delete, authnpolicy_mfa_factor_selection_update, command_delete, command_run, command_update, commandresult_delete, configuredpolicytemplate_create, configuredpolicytemplate_delete, ... (+9 more)
unmapped.useragent.os_version
  • Description: JumpCloud Directory Insights field useragent.os_version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_version
  • Usage: 18 events: authnfallbackpolicy_delete, authnpolicy_mfa_factor_selection_update, command_delete, command_run, command_update, commandresult_delete, configuredpolicytemplate_create, configuredpolicytemplate_delete, ... (+10 more)
unmapped.useragent.patch
  • Description: JumpCloud Directory Insights field useragent.patch preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.patch
  • Usage: 21 events: authnfallbackpolicy_delete, authnpolicy_create, authnpolicy_delete, authnpolicy_mfa_factor_selection_update, authnpolicy_update, command_delete, command_run, command_update, ... (+13 more)
unmapped.useragent.version
  • Description: JumpCloud Directory Insights field useragent.version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.version
  • Usage: 24 events: authnfallbackpolicy_delete, authnpolicy_create, authnpolicy_delete, authnpolicy_mfa_factor_selection_update, authnpolicy_update, command_delete, command_run, command_update, ... (+16 more)
unmapped.username
  • Description: JumpCloud Directory Insights field username preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: username
  • Usage: background_access_file, background_access_shell

Directory — Integrations#

directory_integrations · 56 events

Event Category Class Activity Type UID Fields
account_resync_failure Application Activity (6) API Activity (6003) Update (3) 600303 70
account_resync_initiated Application Activity (6) API Activity (6003) Update (3) 600303 71
activedirectory_agent_activate Identity & Access Management (3) Entity Management (3004) Enable (8) 300408 56
activedirectory_agent_active Identity & Access Management (3) Entity Management (3004) Enable (8) 300408 57
activedirectory_agent_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 66
activedirectory_agent_deleted Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 60
activedirectory_agent_inactive Identity & Access Management (3) Entity Management (3004) Disable (9) 300409 56
activedirectory_config_selection_updated Identity & Access Management (3) Entity Management (3004) Update (3) 300403 61
activedirectory_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 47
activedirectory_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 70
activedirectory_domain_delegated_password_change Identity & Access Management (3) Entity Management (3004) Update (3) 300403 62
activedirectory_primary_agent_switch Identity & Access Management (3) Entity Management (3004) Update (3) 300403 54
attributemappings_add Identity & Access Management (3) Entity Management (3004) Create (1) 300401 82
attributemappings_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 93
attributemappings_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 87
connector_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 72
connector_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 73
connector_execute Application Activity (6) API Activity (6003) Read (2) 600302 54
connector_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 70
duo_configuration_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 65
duoaccount_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 62
duoapplication_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 64
duoapplication_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 62
duoapplication_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 62
gsuite_directory_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 65
gsuite_directory_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 65
gsuite_directory_reactivate Identity & Access Management (3) Entity Management (3004) Enable (8) 300408 61
gsuite_directory_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 62
idm_integration_activate Identity & Access Management (3) Entity Management (3004) Activate (10) 300410 111
idm_integration_auth Identity & Access Management (3) Authentication (3002) Logon (1) 300201 68
idm_integration_deactivate Identity & Access Management (3) Entity Management (3004) Deactivate (11) 300411 73
idm_integration_reauth Identity & Access Management (3) Entity Management (3004) Update (3) 300403 82
idm_integration_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 107
idp_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 54
idp_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 63
idp_routing_policy_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 70
idp_routing_policy_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 66
idp_routing_policy_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 64
idp_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 64
idsource_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 53
idsource_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 72
idsource_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 72
integration_default_domain_add Identity & Access Management (3) Entity Management (3004) Update (3) 300403 56
integration_default_domain_delete Identity & Access Management (3) Entity Management (3004) Update (3) 300403 56
integration_default_domain_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 56
integration_domain_add Identity & Access Management (3) Entity Management (3004) Update (3) 300403 65
integration_domain_delete Identity & Access Management (3) Entity Management (3004) Update (3) 300403 63
ldap_server_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 60
o365_directory_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 65
o365_directory_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 65
o365_directory_reactivate Identity & Access Management (3) Entity Management (3004) Activate (10) 300410 65
o365_directory_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 66
sambadomain_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 55
sambadomain_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 65
sambadomain_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 68
workday_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 60

OCSF field mappings#

Legend

  • Description: what the OCSF field represents (from OCSF schema v1.8.0)
  • Source: raw JumpCloud event field(s) mapped via ${{placeholder}} template
  • Transform: fieldMappings entry applied at runtime (cast, enum, etc.)
  • Literal: static value set in the mapping template
  • Usage: event types in this service that include this field

Core

activity_id
  • Description: The normalized identifier of the activity that triggered the event.
  • Literal: 1, 10, 11, 2, 3, 4, 8, 9
  • Usage: all events in this service
activity_name
  • Description: The event activity name, as defined by the activity_id.
  • Literal: Activate, Create, Deactivate, Delete, Disable, Enable, Logon, Read, Update
  • Usage: all events in this service
category_name
  • Description: The event category name, as defined by category_uid value: Discovery.
  • Literal: Application Activity, Identity & Access Management
  • Usage: all events in this service
category_uid
  • Description: The category unique identifier of the event.
  • Literal: 3, 6
  • Usage: all events in this service
class_name
  • Description: The event class name, as defined by class_uid value: User Inventory Info.
  • Literal: API Activity, Authentication, Entity Management
  • Usage: all events in this service
class_uid
  • Description: The unique identifier of a class. A class describes the attributes available in an event.
  • Literal: 3002, 3004, 6003
  • Usage: all events in this service
severity_id
  • Description: OCSF severity identifier for the event.
  • Literal: 1
  • Usage: all events in this service
status_detail
  • Description: The status detail contains additional information about the event/finding outcome.
  • Source: error, error_message, message_chain.response_message
  • Usage: 54 events (missing: activedirectory_create, idp_create)
status_id
  • Description: Normalized status of the activity (1=Success, 2=Failure).
  • Source: success
  • Transform:
  • success → boolean_to_status_id; true→1, false→2 (54 events (missing: activedirectory_create, idp_create))
  • Usage: 54 events (missing: activedirectory_create, idp_create)
time
  • Description: Event time, in epoch milliseconds (OCSF time).
  • Source: timestamp
  • Transform:
  • timestamp → iso8601_to_epoch_millis (all events in this service)
  • Usage: all events in this service
type_uid
  • Description: The event/finding type ID. It identifies the event's semantics and structure. The value is calculated by the logging system as: class_uid * 100 + activity_id.
  • Literal: 300201, 300401, 300403, 300404, 300408, 300409, 300410, 300411, 600302, 600303
  • Usage: all events in this service

Metadata

metadata.event_code
  • Description: JumpCloud event type code.
  • Source: event_type
  • Usage: all events in this service
metadata.original_time
  • Description: The original event time as reported by the event source. For example, the time in the original format from system event log such as Syslog on Unix/Linux and the System event file on Windows. Omit if event is generated instead of collected via logs.
  • Source: server_timestamp
  • Usage: 26 events: account_resync_failure, account_resync_initiated, activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_deleted, activedirectory_agent_inactive, activedirectory_config_selection_updated, activedirectory_domain_delegated_password_change, ... (+18 more)
metadata.processed_time
  • Description: The event processed time, such as an ETL operation.
  • Source: jc_transformation_ts
  • Usage: 54 events (missing: activedirectory_create, idp_create)
metadata.product.name
  • Description: Originating JumpCloud service that produced the event.
  • Source: service
  • Usage: all events in this service
metadata.tenant_uid
  • Description: JumpCloud organization (tenant) identifier.
  • Source: organization
  • Usage: all events in this service
metadata.uid
  • Description: Unique event identifier assigned by JumpCloud.
  • Source: id
  • Usage: all events in this service
metadata.version
  • Description: OCSF schema version used for this event.
  • Literal: 1.8.0
  • Usage: all events in this service

Actor

actor.user.email_addr
  • Description: Email address of the actor who initiated the event.
  • Source: initiated_by.email
  • Usage: 48 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_agent_deleted, activedirectory_config_selection_updated, activedirectory_create, activedirectory_delete, activedirectory_domain_delegated_password_change, ... (+40 more)
actor.user.type_id
  • Description: OCSF user type of the actor (1=User, 2=Admin, 3=System, 4=Service).
  • Source: initiated_by.type
  • Transform:
  • initiated_by.type → enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (54 events (missing: activedirectory_primary_agent_switch, connector_execute))
  • Usage: 55 events (missing: connector_execute)
actor.user.uid
  • Description: Unique identifier of the actor who initiated the event.
  • Source: initiated_by.id
  • Usage: 54 events (missing: activedirectory_primary_agent_switch, connector_execute)

Entity

entity.data.account_object_id
  • Description: JumpCloud extension data on the managed entity: account_object_id.
  • Source: resource.account_object_id
  • Usage: integration_domain_add
entity.data.add.account_object_id
  • Description: JumpCloud extension data on the managed entity: add.account_object_id.
  • Source: changes.add.account_object_id
  • Usage: integration_domain_add
entity.data.add.default
  • Description: JumpCloud extension data on the managed entity: add.default.
  • Source: changes.add.default
  • Usage: integration_domain_add
entity.data.add.domain
  • Description: JumpCloud extension data on the managed entity: add.domain.
  • Source: changes.add.domain
  • Usage: integration_domain_add
entity.data.add.object_id
  • Description: JumpCloud extension data on the managed entity: add.object_id.
  • Source: changes.add.object_id
  • Usage: integration_domain_add
entity.data.add.resource_object_id
  • Description: JumpCloud extension data on the managed entity: add.resource_object_id.
  • Source: changes.add.resource_object_id
  • Usage: integration_domain_add
entity.data.agent_version
  • Description: JumpCloud extension data on the managed entity: agent_version.
  • Source: resource.version
  • Usage: activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_deleted, activedirectory_agent_inactive, activedirectory_domain_delegated_password_change, activedirectory_primary_agent_switch, idsource_create, idsource_delete, idsource_update
entity.data.application_display_name
  • Description: JumpCloud extension data on the managed entity: application_display_name.
  • Source: application.displayName
  • Usage: attributemappings_add, attributemappings_delete, attributemappings_update
entity.data.application_id
  • Description: JumpCloud extension data on the managed entity: application_id.
  • Source: application.id
  • Usage: attributemappings_add, attributemappings_delete, attributemappings_update
entity.data.application_name
  • Description: JumpCloud extension data on the managed entity: application_name.
  • Source: application.name
  • Usage: attributemappings_add, attributemappings_delete, attributemappings_update
entity.data.application_protocol
  • Description: JumpCloud extension data on the managed entity: application_protocol.
  • Source: application.name
  • Usage: idm_integration_activate, idm_integration_deactivate, idm_integration_reauth, idm_integration_update
entity.data.association_action_source
  • Description: JumpCloud extension data on the managed entity: association_action_source.
  • Source: association.action_source
  • Usage: activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_deleted, activedirectory_agent_inactive, activedirectory_config_selection_updated, activedirectory_domain_delegated_password_change, activedirectory_primary_agent_switch
entity.data.association_attributes
  • Description: JumpCloud extension data on the managed entity: association_attributes.
  • Source: association.attributes
  • Usage: activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_deleted, activedirectory_agent_inactive, activedirectory_config_selection_updated, activedirectory_domain_delegated_password_change, activedirectory_primary_agent_switch
entity.data.association_from_name
  • Description: JumpCloud extension data on the managed entity: association_from_name.
  • Source: association.connection.from.name
  • Usage: activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_deleted, activedirectory_agent_inactive, activedirectory_config_selection_updated, activedirectory_domain_delegated_password_change, activedirectory_primary_agent_switch
entity.data.association_from_object_id
  • Description: JumpCloud extension data on the managed entity: association_from_object_id.
  • Source: association.connection.from.object_id
  • Usage: activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_deleted, activedirectory_agent_inactive, activedirectory_config_selection_updated, activedirectory_domain_delegated_password_change, activedirectory_primary_agent_switch
entity.data.association_from_type
  • Description: JumpCloud extension data on the managed entity: association_from_type.
  • Source: association.connection.from.type
  • Usage: activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_deleted, activedirectory_agent_inactive, activedirectory_config_selection_updated, activedirectory_domain_delegated_password_change, activedirectory_primary_agent_switch
entity.data.association_op
  • Description: JumpCloud extension data on the managed entity: association_op.
  • Source: association.op
  • Usage: activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_deleted, activedirectory_agent_inactive, activedirectory_config_selection_updated, activedirectory_domain_delegated_password_change, activedirectory_primary_agent_switch
entity.data.association_to_name
  • Description: JumpCloud extension data on the managed entity: association_to_name.
  • Source: association.connection.to.name
  • Usage: activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_deleted, activedirectory_agent_inactive, activedirectory_config_selection_updated, activedirectory_domain_delegated_password_change, activedirectory_primary_agent_switch
entity.data.association_to_object_id
  • Description: JumpCloud extension data on the managed entity: association_to_object_id.
  • Source: association.connection.to.object_id
  • Usage: activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_deleted, activedirectory_agent_inactive, activedirectory_config_selection_updated, activedirectory_domain_delegated_password_change, activedirectory_primary_agent_switch
entity.data.association_to_type
  • Description: JumpCloud extension data on the managed entity: association_to_type.
  • Source: association.connection.to.type
  • Usage: activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_deleted, activedirectory_agent_inactive, activedirectory_config_selection_updated, activedirectory_domain_delegated_password_change, activedirectory_primary_agent_switch
entity.data.auth_method
  • Description: JumpCloud extension data on the managed entity: auth_method.
  • Source: auth_method
  • Usage: 48 events: activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_create, activedirectory_agent_deleted, activedirectory_agent_inactive, activedirectory_config_selection_updated, activedirectory_create, activedirectory_delete, ... (+40 more)
entity.data.authentication_header_key
  • Description: JumpCloud extension data on the managed entity: authentication_header_key.
  • Source: resource.authentication.header_key
  • Usage: connector_create, connector_delete, connector_update
entity.data.authentication_type
  • Description: JumpCloud extension data on the managed entity: authentication_type.
  • Source: resource.authentication.type
  • Usage: connector_create, connector_delete, connector_update
entity.data.authentication_username
  • Description: JumpCloud extension data on the managed entity: authentication_username.
  • Source: resource.authentication.username
  • Usage: connector_create, connector_delete, connector_update
entity.data.authentication_value_prefix
  • Description: JumpCloud extension data on the managed entity: authentication_value_prefix.
  • Source: resource.authentication.value_prefix
  • Usage: connector_create, connector_delete, connector_update
entity.data.base_url
  • Description: JumpCloud extension data on the managed entity: base_url.
  • Source: resource.base_url
  • Usage: connector_create, connector_delete, connector_update
entity.data.changed_field
  • Description: JumpCloud extension data on the managed entity: changed_field.
  • Source: changes.field
  • Usage: 43 events: activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_create, activedirectory_agent_inactive, activedirectory_config_selection_updated, activedirectory_create, activedirectory_delete, activedirectory_domain_delegated_password_change, ... (+35 more)
entity.data.changes_from
  • Description: JumpCloud extension data on the managed entity: changes_from.
  • Source: changes.from
  • Usage: 24 events: activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_inactive, activedirectory_config_selection_updated, activedirectory_delete, activedirectory_domain_delegated_password_change, activedirectory_primary_agent_switch, attributemappings_add, ... (+16 more)
entity.data.changes_from_destination
  • Description: JumpCloud extension data on the managed entity: changes_from_destination.
  • Source: changes.from.destination
  • Usage: attributemappings_delete, attributemappings_update
entity.data.changes_from_direction
  • Description: JumpCloud extension data on the managed entity: changes_from_direction.
  • Source: changes.from.direction
  • Usage: attributemappings_delete, attributemappings_update
entity.data.changes_from_required
  • Description: JumpCloud extension data on the managed entity: changes_from_required.
  • Source: changes.from.required
  • Usage: attributemappings_delete, attributemappings_update
entity.data.changes_from_source
  • Description: JumpCloud extension data on the managed entity: changes_from_source.
  • Source: changes.from.source
  • Usage: attributemappings_delete, attributemappings_update
entity.data.client_id
  • Description: JumpCloud extension data on the managed entity: client_id.
  • Source: client_id
  • Usage: attributemappings_add, attributemappings_delete, attributemappings_update, idm_integration_activate, idm_integration_deactivate, idm_integration_reauth, idm_integration_update
entity.data.connector_id
  • Description: JumpCloud extension data on the managed entity: connector_id.
  • Source: resource.connector_id
  • Usage: connector_create, connector_delete, connector_update
entity.data.correlation_id
  • Description: JumpCloud extension data on the managed entity: correlation_id.
  • Source: correlation.id
  • Usage: idm_integration_activate, idm_integration_deactivate, idm_integration_reauth, idm_integration_update
entity.data.correlation_type
  • Description: JumpCloud extension data on the managed entity: correlation_type.
  • Source: correlation.type
  • Usage: idm_integration_activate, idm_integration_deactivate, idm_integration_reauth, idm_integration_update
entity.data.custom_headers.X-API-KEY
  • Description: JumpCloud extension data on the managed entity: custom_headers.X-API-KEY.
  • Source: resource.custom_headers.X-API-KEY
  • Usage: connector_create
entity.data.custom_headers.custom
  • Description: JumpCloud extension data on the managed entity: custom_headers.custom.
  • Source: resource.custom_headers.custom
  • Usage: connector_create
entity.data.custom_headers.dsadsad
  • Description: JumpCloud extension data on the managed entity: custom_headers.dsadsad.
  • Source: resource.custom_headers.dsadsad
  • Usage: connector_create
entity.data.custom_headers.header
  • Description: JumpCloud extension data on the managed entity: custom_headers.header.
  • Source: resource.custom_headers.header
  • Usage: connector_create
entity.data.custom_headers.headerkey
  • Description: JumpCloud extension data on the managed entity: custom_headers.headerkey.
  • Source: resource.custom_headers.headerkey
  • Usage: connector_update
entity.data.custom_headers.headers
  • Description: JumpCloud extension data on the managed entity: custom_headers.headers.
  • Source: resource.custom_headers.headers
  • Usage: connector_create, connector_delete
entity.data.custom_headers.new
  • Description: JumpCloud extension data on the managed entity: custom_headers.new.
  • Source: resource.custom_headers.new
  • Usage: connector_create, connector_delete
entity.data.custom_headers.sdadasdads
  • Description: JumpCloud extension data on the managed entity: custom_headers.sdadasdads.
  • Source: resource.custom_headers.sdadasdads
  • Usage: connector_create, connector_delete, connector_update
entity.data.custom_headers.test
  • Description: JumpCloud extension data on the managed entity: custom_headers.test.
  • Source: resource.custom_headers.test
  • Usage: connector_delete
entity.data.custom_headers.x-amzn-custom
  • Description: JumpCloud extension data on the managed entity: custom_headers.x-amzn-custom.
  • Source: resource.custom_headers.x-amzn-custom
  • Usage: connector_create, connector_delete, connector_update
entity.data.custom_headers.x-amzn-key
  • Description: JumpCloud extension data on the managed entity: custom_headers.x-amzn-key.
  • Source: resource.custom_headers.x-amzn-key
  • Usage: connector_delete, connector_update
entity.data.custom_headers.x-amzn-test
  • Description: JumpCloud extension data on the managed entity: custom_headers.x-amzn-test.
  • Source: resource.custom_headers.x-amzn-test
  • Usage: connector_update
entity.data.custom_headers.x-gi-id
  • Description: JumpCloud extension data on the managed entity: custom_headers.x-gi-id.
  • Source: resource.custom_headers.x-gi-id
  • Usage: connector_create, connector_delete, connector_update
entity.data.custom_headers.x-header-2
  • Description: JumpCloud extension data on the managed entity: custom_headers.x-header-2.
  • Source: resource.custom_headers.x-header-2
  • Usage: connector_delete, connector_update
entity.data.custom_headers.x-jc-id
  • Description: JumpCloud extension data on the managed entity: custom_headers.x-jc-id.
  • Source: resource.custom_headers.x-jc-id
  • Usage: connector_create, connector_delete, connector_update
entity.data.custom_headers.x-team-id
  • Description: JumpCloud extension data on the managed entity: custom_headers.x-team-id.
  • Source: resource.custom_headers.x-team-id
  • Usage: connector_delete
entity.data.custom_headers.x-test
  • Description: JumpCloud extension data on the managed entity: custom_headers.x-test.
  • Source: resource.custom_headers.x-test
  • Usage: connector_create
entity.data.custom_headers.x-test-1
  • Description: JumpCloud extension data on the managed entity: custom_headers.x-test-1.
  • Source: resource.custom_headers.x-test-1
  • Usage: connector_delete, connector_update
entity.data.custom_headers.yes
  • Description: JumpCloud extension data on the managed entity: custom_headers.yes.
  • Source: resource.custom_headers.yes
  • Usage: connector_delete
entity.data.delegation_state
  • Description: JumpCloud extension data on the managed entity: delegation_state.
  • Source: resource.delegation_state
  • Usage: activedirectory_domain_delegated_password_change
entity.data.delete.account_object_id
  • Description: JumpCloud extension data on the managed entity: delete.account_object_id.
  • Source: changes.delete.account_object_id
  • Usage: integration_domain_delete
entity.data.delete.default
  • Description: JumpCloud extension data on the managed entity: delete.default.
  • Source: changes.delete.default
  • Usage: integration_domain_delete
entity.data.delete.domain
  • Description: JumpCloud extension data on the managed entity: delete.domain.
  • Source: changes.delete.domain
  • Usage: integration_domain_delete
entity.data.delete.object_id
  • Description: JumpCloud extension data on the managed entity: delete.object_id.
  • Source: changes.delete.object_id
  • Usage: integration_domain_delete
entity.data.delete.resource_object_id
  • Description: JumpCloud extension data on the managed entity: delete.resource_object_id.
  • Source: changes.delete.resource_object_id
  • Usage: integration_domain_delete
entity.data.destination
  • Description: JumpCloud extension data on the managed entity: destination.
  • Source: changes.destination
  • Usage: attributemappings_add, attributemappings_delete, attributemappings_update
entity.data.direction
  • Description: JumpCloud extension data on the managed entity: direction.
  • Source: changes.direction
  • Usage: attributemappings_add, attributemappings_delete, attributemappings_update
entity.data.dn
  • Description: JumpCloud extension data on the managed entity: dn.
  • Source: resource.dn
  • Usage: idsource_create, idsource_delete, idsource_update
entity.data.domain
  • Description: JumpCloud extension data on the managed entity: domain.
  • Source: resource.domain
  • Usage: activedirectory_agent_deleted, activedirectory_domain_delegated_password_change, activedirectory_primary_agent_switch
entity.data.idm_client_id
  • Description: JumpCloud extension data on the managed entity: idm_client_id.
  • Source: resource.idm_client_id
  • Usage: idm_integration_activate, idm_integration_deactivate, idm_integration_reauth, idm_integration_update
entity.data.ids
  • Description: JumpCloud extension data on the managed entity: ids.
  • Source: resource.ids
  • Usage: attributemappings_add, attributemappings_delete, attributemappings_update
entity.data.initiated_by_provider
  • Description: JumpCloud extension data on the managed entity: initiated_by_provider.
  • Source: initiated_by.provider
  • Usage: 26 events: duo_configuration_update, duoaccount_create, duoapplication_create, duoapplication_delete, gsuite_directory_create, gsuite_directory_delete, gsuite_directory_reactivate, gsuite_directory_update, ... (+18 more)
entity.data.initiated_by_source
  • Description: JumpCloud extension data on the managed entity: initiated_by_source.
  • Source: initiated_by.source
  • Usage: idp_create, idp_delete, idp_routing_policy_create, idp_routing_policy_delete, idp_routing_policy_update, idp_update
entity.data.initiated_by_source_name
  • Description: JumpCloud extension data on the managed entity: initiated_by_source_name.
  • Source: initiated_by.source_metadata.sourceName
  • Usage: attributemappings_add, attributemappings_delete, attributemappings_update
entity.data.initiated_by_user_id
  • Description: JumpCloud extension data on the managed entity: initiated_by_user_id.
  • Source: initiated_by.user_id
  • Usage: idm_integration_activate, idm_integration_reauth, idm_integration_update
entity.data.message_chain_message_details
  • Description: JumpCloud extension data on the managed entity: message_chain_message_details.
  • Source: message_chain.message_details
  • Usage: idm_integration_activate, idm_integration_deactivate, idm_integration_reauth, idm_integration_update
entity.data.message_chain_response_code
  • Description: JumpCloud extension data on the managed entity: message_chain_response_code.
  • Source: message_chain.response_code
  • Usage: idm_integration_activate, idm_integration_deactivate, idm_integration_reauth, idm_integration_update
entity.data.names
  • Description: JumpCloud extension data on the managed entity: names.
  • Source: resource.names
  • Usage: attributemappings_add, attributemappings_delete, attributemappings_update
entity.data.object_id
  • Description: JumpCloud extension data on the managed entity: object_id.
  • Source: resource.object_id
  • Usage: connector_create, connector_delete, connector_update
entity.data.primary_agent
  • Description: JumpCloud extension data on the managed entity: primary_agent.
  • Source: resource.primary_agent
  • Usage: activedirectory_agent_active
entity.data.provider
  • Description: JumpCloud extension data on the managed entity: provider.
  • Source: provider
  • Usage: 37 events: attributemappings_add, attributemappings_delete, attributemappings_update, duo_configuration_update, duoaccount_create, duoapplication_create, duoapplication_delete, gsuite_directory_create, ... (+29 more)
entity.data.required
  • Description: JumpCloud extension data on the managed entity: required.
  • Source: changes.required
  • Usage: attributemappings_add
entity.data.source
  • Description: JumpCloud extension data on the managed entity: source.
  • Source: changes.source
  • Usage: attributemappings_add, attributemappings_delete, attributemappings_update
entity.data.status
  • Description: JumpCloud extension data on the managed entity: status.
  • Source: resource.status
  • Usage: activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_inactive, activedirectory_primary_agent_switch, connector_create, connector_delete, connector_update
entity.device.hostname
  • Description: The device hostname.
  • Source: resource.hostname
  • Usage: activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_deleted, activedirectory_agent_inactive, activedirectory_domain_delegated_password_change, activedirectory_primary_agent_switch
entity.device.ip
  • Description: The device IP address, in either IPv4 or IPv6 format.
  • Source: resource.ipAddress, resource.source_ip
  • Usage: activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_deleted, activedirectory_agent_inactive, activedirectory_domain_delegated_password_change, activedirectory_primary_agent_switch, idsource_create, idsource_delete, idsource_update
entity.device.os.name
  • Description: The operating system name.
  • Source: resource.hostOSVersion, resource.host_os_version
  • Usage: activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_deleted, activedirectory_agent_inactive, activedirectory_domain_delegated_password_change, activedirectory_primary_agent_switch, idsource_delete, idsource_update
entity.device.type
  • Description: The device type. For example: unknown, server, desktop, laptop, tablet, mobile, virtual, browser, or other.
  • Source: resource.hostType, resource.host_type
  • Usage: activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_deleted, activedirectory_agent_inactive, activedirectory_domain_delegated_password_change, activedirectory_primary_agent_switch, idsource_delete, idsource_update
entity.name
  • Description: The name of the managed entity. It should match the name of the specific entity object's name if populated, or the name of the managed entity if the type_id is 'Other'.
  • Source: application.displayName, resource.domain, resource.name
  • Usage: 34 events: activedirectory_config_selection_updated, activedirectory_create, activedirectory_delete, attributemappings_add, attributemappings_delete, attributemappings_update, connector_create, connector_delete, ... (+26 more)
entity.type
  • Description: The managed entity type. For example: Policy, User, Organization, Device.
  • Source: resource.type
  • Usage: 52 events (missing: account_resync_failure, account_resync_initiated, connector_execute, idm_integration_auth)
entity.uid
  • Description: The identifier of the managed entity. It should match the uid of the specific entity's object UID if populated, or the source specific ID if the type_id is 'Other'.
  • Source: application.id, resource.id
  • Usage: 43 events: activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_create, activedirectory_agent_deleted, activedirectory_agent_inactive, activedirectory_config_selection_updated, activedirectory_create, activedirectory_delete, ... (+35 more)
entity_result.data.changes_to
  • Description: JumpCloud extension data on the managed entity: changes_to.
  • Source: changes.to
  • Usage: 34 events: activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_create, activedirectory_agent_inactive, activedirectory_config_selection_updated, activedirectory_create, activedirectory_domain_delegated_password_change, activedirectory_primary_agent_switch, ... (+26 more)
entity_result.data.changes_to_account_object_id
  • Description: JumpCloud extension data on the managed entity: changes_to_account_object_id.
  • Source: changes.to.account_object_id
  • Usage: integration_domain_add, integration_domain_delete
entity_result.data.changes_to_api_users_get_additionalHeaders
  • Description: JumpCloud extension data on the managed entity: changes_to_api_users_get_additionalHeaders.
  • Source: changes.to.api.users.get.additionalHeaders
  • Usage: idm_integration_activate
entity_result.data.changes_to_api_users_get_additionalHeaders_key
  • Description: JumpCloud extension data on the managed entity: changes_to_api_users_get_additionalHeaders_key.
  • Source: changes.to.api.users.get.additionalHeaders.key
  • Usage: idm_integration_update
entity_result.data.changes_to_api_users_get_additionalHeaders_sensitive
  • Description: JumpCloud extension data on the managed entity: changes_to_api_users_get_additionalHeaders_sensitive.
  • Source: changes.to.api.users.get.additionalHeaders.sensitive
  • Usage: idm_integration_update
entity_result.data.changes_to_api_users_get_additionalHeaders_value
  • Description: JumpCloud extension data on the managed entity: changes_to_api_users_get_additionalHeaders_value.
  • Source: changes.to.api.users.get.additionalHeaders.value
  • Usage: idm_integration_update
entity_result.data.changes_to_api_users_get_method
  • Description: JumpCloud extension data on the managed entity: changes_to_api_users_get_method.
  • Source: changes.to.api.users.get.method
  • Usage: idm_integration_activate, idm_integration_update
entity_result.data.changes_to_api_users_get_path
  • Description: JumpCloud extension data on the managed entity: changes_to_api_users_get_path.
  • Source: changes.to.api.users.get.path
  • Usage: idm_integration_activate, idm_integration_update
entity_result.data.changes_to_api_users_list_countField
  • Description: JumpCloud extension data on the managed entity: changes_to_api_users_list_countField.
  • Source: changes.to.api.users.list.countField
  • Usage: idm_integration_activate, idm_integration_update
entity_result.data.changes_to_api_users_list_cursorBased_count
  • Description: JumpCloud extension data on the managed entity: changes_to_api_users_list_cursorBased_count.
  • Source: changes.to.api.users.list.cursorBased.count
  • Usage: idm_integration_activate, idm_integration_update
entity_result.data.changes_to_api_users_list_cursorBased_cursor
  • Description: JumpCloud extension data on the managed entity: changes_to_api_users_list_cursorBased_cursor.
  • Source: changes.to.api.users.list.cursorBased.cursor
  • Usage: idm_integration_activate, idm_integration_update
entity_result.data.changes_to_api_users_list_cursorBased_cursorField
  • Description: JumpCloud extension data on the managed entity: changes_to_api_users_list_cursorBased_cursorField.
  • Source: changes.to.api.users.list.cursorBased.cursorField
  • Usage: idm_integration_activate, idm_integration_update
  • Description: JumpCloud extension data on the managed entity: changes_to_api_users_list_cursorBased_isLink.
  • Source: changes.to.api.users.list.cursorBased.isLink
  • Usage: idm_integration_activate, idm_integration_update
entity_result.data.changes_to_api_users_list_endpoint_additionalHeaders
  • Description: JumpCloud extension data on the managed entity: changes_to_api_users_list_endpoint_additionalHeaders.
  • Source: changes.to.api.users.list.endpoint.additionalHeaders
  • Usage: idm_integration_activate
entity_result.data.changes_to_api_users_list_endpoint_additionalHeaders_key
  • Description: JumpCloud extension data on the managed entity: changes_to_api_users_list_endpoint_additionalHeaders_key.
  • Source: changes.to.api.users.list.endpoint.additionalHeaders.key
  • Usage: idm_integration_update
entity_result.data.changes_to_api_users_list_endpoint_additionalHeaders_sensitive
  • Description: JumpCloud extension data on the managed entity: changes_to_api_users_list_endpoint_additionalHeaders_sensitive.
  • Source: changes.to.api.users.list.endpoint.additionalHeaders.sensitive
  • Usage: idm_integration_update
entity_result.data.changes_to_api_users_list_endpoint_additionalHeaders_value
  • Description: JumpCloud extension data on the managed entity: changes_to_api_users_list_endpoint_additionalHeaders_value.
  • Source: changes.to.api.users.list.endpoint.additionalHeaders.value
  • Usage: idm_integration_update
entity_result.data.changes_to_api_users_list_endpoint_method
  • Description: JumpCloud extension data on the managed entity: changes_to_api_users_list_endpoint_method.
  • Source: changes.to.api.users.list.endpoint.method
  • Usage: idm_integration_activate, idm_integration_update
entity_result.data.changes_to_api_users_list_endpoint_path
  • Description: JumpCloud extension data on the managed entity: changes_to_api_users_list_endpoint_path.
  • Source: changes.to.api.users.list.endpoint.path
  • Usage: idm_integration_activate, idm_integration_update
entity_result.data.changes_to_api_users_list_limit
  • Description: JumpCloud extension data on the managed entity: changes_to_api_users_list_limit.
  • Source: changes.to.api.users.list.limit
  • Usage: idm_integration_activate, idm_integration_update
entity_result.data.changes_to_api_users_list_noPagination
  • Description: JumpCloud extension data on the managed entity: changes_to_api_users_list_noPagination.
  • Source: changes.to.api.users.list.noPagination
  • Usage: idm_integration_activate, idm_integration_update
entity_result.data.changes_to_api_users_list_offset_count
  • Description: JumpCloud extension data on the managed entity: changes_to_api_users_list_offset_count.
  • Source: changes.to.api.users.list.offset.count
  • Usage: idm_integration_activate, idm_integration_update
entity_result.data.changes_to_api_users_list_offset_skip
  • Description: JumpCloud extension data on the managed entity: changes_to_api_users_list_offset_skip.
  • Source: changes.to.api.users.list.offset.skip
  • Usage: idm_integration_activate, idm_integration_update
entity_result.data.changes_to_api_users_list_offset_startIndex
  • Description: JumpCloud extension data on the managed entity: changes_to_api_users_list_offset_startIndex.
  • Source: changes.to.api.users.list.offset.startIndex
  • Usage: idm_integration_activate, idm_integration_update
entity_result.data.changes_to_api_users_list_pageBased_count
  • Description: JumpCloud extension data on the managed entity: changes_to_api_users_list_pageBased_count.
  • Source: changes.to.api.users.list.pageBased.count
  • Usage: idm_integration_activate, idm_integration_update
entity_result.data.changes_to_api_users_list_pageBased_index
  • Description: JumpCloud extension data on the managed entity: changes_to_api_users_list_pageBased_index.
  • Source: changes.to.api.users.list.pageBased.index
  • Usage: idm_integration_activate, idm_integration_update
entity_result.data.changes_to_api_users_list_resources
  • Description: JumpCloud extension data on the managed entity: changes_to_api_users_list_resources.
  • Source: changes.to.api.users.list.resources
  • Usage: idm_integration_activate, idm_integration_update
entity_result.data.changes_to_appliedOn
  • Description: JumpCloud extension data on the managed entity: changes_to_appliedOn.
  • Source: changes.to.appliedOn
  • Usage: idm_integration_activate
entity_result.data.changes_to_builtIn
  • Description: JumpCloud extension data on the managed entity: changes_to_builtIn.
  • Source: changes.to.builtIn
  • Usage: idm_integration_activate
entity_result.data.changes_to_data
  • Description: JumpCloud extension data on the managed entity: changes_to_data.
  • Source: changes.to.data
  • Usage: idm_integration_activate
entity_result.data.changes_to_default
  • Description: JumpCloud extension data on the managed entity: changes_to_default.
  • Source: changes.to.default
  • Usage: idm_integration_activate, integration_domain_add, integration_domain_delete
entity_result.data.changes_to_deleteUser
  • Description: JumpCloud extension data on the managed entity: changes_to_deleteUser.
  • Source: changes.to.deleteUser
  • Usage: idm_integration_activate
entity_result.data.changes_to_destination
  • Description: JumpCloud extension data on the managed entity: changes_to_destination.
  • Source: changes.to.destination
  • Usage: attributemappings_add, attributemappings_update, idm_integration_activate
entity_result.data.changes_to_direction
  • Description: JumpCloud extension data on the managed entity: changes_to_direction.
  • Source: changes.to.direction
  • Usage: attributemappings_add, attributemappings_update, idm_integration_activate
entity_result.data.changes_to_domain
  • Description: JumpCloud extension data on the managed entity: changes_to_domain.
  • Source: changes.to.domain
  • Usage: integration_domain_add, integration_domain_delete
entity_result.data.changes_to_editable
  • Description: JumpCloud extension data on the managed entity: changes_to_editable.
  • Source: changes.to.editable
  • Usage: idm_integration_activate
entity_result.data.changes_to_id
  • Description: JumpCloud extension data on the managed entity: changes_to_id.
  • Source: changes.to.id
  • Usage: idm_integration_activate
entity_result.data.changes_to_object_id
  • Description: JumpCloud extension data on the managed entity: changes_to_object_id.
  • Source: changes.to.object_id
  • Usage: integration_domain_add, integration_domain_delete
entity_result.data.changes_to_required
  • Description: JumpCloud extension data on the managed entity: changes_to_required.
  • Source: changes.to.required
  • Usage: attributemappings_add, attributemappings_update, idm_integration_activate
entity_result.data.changes_to_resource_object_id
  • Description: JumpCloud extension data on the managed entity: changes_to_resource_object_id.
  • Source: changes.to.resource_object_id
  • Usage: integration_domain_add
entity_result.data.changes_to_source
  • Description: JumpCloud extension data on the managed entity: changes_to_source.
  • Source: changes.to.source
  • Usage: attributemappings_add, attributemappings_update, idm_integration_activate
entity_result.data.changes_to_sourceType
  • Description: JumpCloud extension data on the managed entity: changes_to_sourceType.
  • Source: changes.to.sourceType
  • Usage: idm_integration_activate
entity_result.data.changes_to_target
  • Description: JumpCloud extension data on the managed entity: changes_to_target.
  • Source: changes.to.target
  • Usage: idm_integration_activate
entity_result.data.changes_to_template
  • Description: JumpCloud extension data on the managed entity: changes_to_template.
  • Source: changes.to.template
  • Usage: idm_integration_activate
entity_result.data.changes_to_type
  • Description: JumpCloud extension data on the managed entity: changes_to_type.
  • Source: changes.to.type
  • Usage: idm_integration_activate
entity_result.data.changes_to_userSchema_inactiveStatus_path
  • Description: JumpCloud extension data on the managed entity: changes_to_userSchema_inactiveStatus_path.
  • Source: changes.to.userSchema.inactiveStatus.path
  • Usage: idm_integration_activate, idm_integration_update
entity_result.data.changes_to_userSchema_inactiveStatus_values
  • Description: JumpCloud extension data on the managed entity: changes_to_userSchema_inactiveStatus_values.
  • Source: changes.to.userSchema.inactiveStatus.values
  • Usage: idm_integration_activate, idm_integration_update
entity_result.data.changes_to_userSchema_mappings_direction
  • Description: JumpCloud extension data on the managed entity: changes_to_userSchema_mappings_direction.
  • Source: changes.to.userSchema.mappings.direction
  • Usage: idm_integration_activate, idm_integration_update
entity_result.data.changes_to_userSchema_mappings_external_type
  • Description: JumpCloud extension data on the managed entity: changes_to_userSchema_mappings_external_type.
  • Source: changes.to.userSchema.mappings.external.type
  • Usage: idm_integration_activate, idm_integration_update
entity_result.data.changes_to_userSchema_mappings_external_value
  • Description: JumpCloud extension data on the managed entity: changes_to_userSchema_mappings_external_value.
  • Source: changes.to.userSchema.mappings.external.value
  • Usage: idm_integration_activate, idm_integration_update
entity_result.data.changes_to_userSchema_mappings_internal_type
  • Description: JumpCloud extension data on the managed entity: changes_to_userSchema_mappings_internal_type.
  • Source: changes.to.userSchema.mappings.internal.type
  • Usage: idm_integration_activate, idm_integration_update
entity_result.data.changes_to_userSchema_mappings_internal_value
  • Description: JumpCloud extension data on the managed entity: changes_to_userSchema_mappings_internal_value.
  • Source: changes.to.userSchema.mappings.internal.value
  • Usage: idm_integration_activate, idm_integration_update
entity_result.data.changes_to_userSchema_uniqueIdentifier
  • Description: JumpCloud extension data on the managed entity: changes_to_userSchema_uniqueIdentifier.
  • Source: changes.to.userSchema.uniqueIdentifier
  • Usage: idm_integration_activate, idm_integration_update

Src Endpoint

src_endpoint.autonomous_system.name
  • Description: Organization name for the Autonomous System.
  • Source: asn.organization
  • Usage: 35 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_delete, attributemappings_delete, attributemappings_update, connector_create, connector_delete, ... (+27 more)
src_endpoint.autonomous_system.number
  • Description: Unique number that the AS is identified by.
  • Source: asn.number
  • Transform:
  • asn.number → int (35 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_delete, attributemappings_delete, attributemappings_update, connector_create, connector_delete, ... (+27 more))
  • Usage: 35 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_delete, attributemappings_delete, attributemappings_update, connector_create, connector_delete, ... (+27 more)
src_endpoint.ip
  • Description: Source IP address the request originated from.
  • Source: client_ip
  • Usage: all events in this service
src_endpoint.location.city
  • Description: The name of the city.
  • Source: geoip.city
  • Usage: 42 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_config_selection_updated, activedirectory_delete, attributemappings_add, attributemappings_delete, attributemappings_update, ... (+34 more)
src_endpoint.location.continent
  • Description: The name of the continent.
  • Source: geoip.continent_code
  • Usage: 44 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_config_selection_updated, activedirectory_create, activedirectory_delete, attributemappings_add, attributemappings_delete, ... (+36 more)
src_endpoint.location.country
  • Description: The ISO 3166-1 Alpha-2 country code.

    Note: The two letter country code should be capitalized. For example: US or CA.

  • Source: geoip.country_code
  • Usage: 44 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_config_selection_updated, activedirectory_create, activedirectory_delete, attributemappings_add, attributemappings_delete, ... (+36 more)
src_endpoint.location.lat
  • Description: The geographical Latitude coordinate represented in Decimal Degrees (DD). For example: 42.361145.
  • Source: geoip.latitude
  • Transform:
  • geoip.latitude → double (44 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_config_selection_updated, activedirectory_create, activedirectory_delete, attributemappings_add, attributemappings_delete, ... (+36 more))
  • Usage: 44 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_config_selection_updated, activedirectory_create, activedirectory_delete, attributemappings_add, attributemappings_delete, ... (+36 more)
src_endpoint.location.long
  • Description: The geographical Longitude coordinate represented in Decimal Degrees (DD). For example: -71.057083.
  • Source: geoip.longitude
  • Transform:
  • geoip.longitude → double (44 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_config_selection_updated, activedirectory_create, activedirectory_delete, attributemappings_add, attributemappings_delete, ... (+36 more))
  • Usage: 44 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_config_selection_updated, activedirectory_create, activedirectory_delete, attributemappings_add, attributemappings_delete, ... (+36 more)
src_endpoint.location.region
  • Description: The alphanumeric code that identifies the principal subdivision (e.g. province or state) of the country. For example, 'CH-VD' for the Canton of Vaud, Switzerland
  • Source: geoip.region_code
  • Usage: 44 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_config_selection_updated, activedirectory_create, activedirectory_delete, attributemappings_add, attributemappings_delete, ... (+36 more)

Http Request

http_request.user_agent
  • Description: The request header that identifies the operating system and web browser.
  • Source: user_agent
  • Usage: 50 events: account_resync_failure, account_resync_initiated, activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_create, activedirectory_agent_deleted, activedirectory_agent_inactive, activedirectory_delete, ... (+42 more)

Observables

observables[].name
  • Description: The full name of the observable attribute. The name is a pointer/reference to an attribute within the OCSF event data. For example: file.name. Array attributes may be represented in one of three ways. For example: resources.uid, resources[].uid, resources[0].uid.
  • Literal: actor.user.email_addr, actor.user.uid, entity.device.hostname, entity.device.ip, http_request.user_agent, src_endpoint.ip, src_endpoint.location.country
  • Usage: all events in this service
observables[].type_id
  • Description: The observable value type identifier.
  • Literal: 1, 14, 16, 2, 31, 5
  • Usage: all events in this service
observables[].value
  • Description: The value associated with the observable attribute. The meaning of the value depends on the observable type.
    If the name refers to a scalar attribute, then the value is the value of the attribute.
    If the name refers to an object attribute, then the value is not populated.
  • Source: client_ip, geoip.country_code, initiated_by.email, initiated_by.id, resource.hostname, resource.ipAddress, resource.source_ip, user_agent
  • Usage: all events in this service

Resources

resources.type
  • Description: The resource type as defined by the event source.
  • Source: resource.type
  • Usage: account_resync_failure, account_resync_initiated

Other

api.request.uid
  • Description: The unique request identifier.
  • Source: correlation.id
  • Usage: account_resync_failure, account_resync_initiated
http_response.code
  • Description: The Hypertext Transfer Protocol (HTTP) status code returned from the web server to the client. For example, 200.
  • Source: status_code
  • Usage: connector_execute
service.name
  • Description: The name of the service.
  • Source: application.displayName
  • Usage: idm_integration_auth
service.uid
  • Description: The unique identifier of the service.
  • Source: application.id
  • Usage: idm_integration_auth

Unmapped

unmapped.@timestamp
  • Description: JumpCloud Directory Insights field @timestamp preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: @timestamp
  • Usage: 12 events: activedirectory_config_selection_updated, activedirectory_create, activedirectory_delete, activedirectory_domain_delegated_password_change, attributemappings_add, attributemappings_delete, attributemappings_update, idp_create, ... (+4 more)
unmapped.@version
  • Description: JumpCloud Directory Insights field @version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: @version
  • Usage: all events in this service
unmapped._datadog.ot-baggage-jc-request-start
  • Description: JumpCloud Directory Insights field _datadog.ot-baggage-jc-request-start preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: _datadog.ot-baggage-jc-request-start
  • Usage: idm_integration_reauth
unmapped._datadog.traceparent
  • Description: JumpCloud Directory Insights field _datadog.traceparent preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: _datadog.traceparent
  • Usage: idm_integration_reauth
unmapped._datadog.tracestate
  • Description: JumpCloud Directory Insights field _datadog.tracestate preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: _datadog.tracestate
  • Usage: idm_integration_reauth
unmapped._datadog.x-datadog-parent-id
  • Description: JumpCloud Directory Insights field _datadog.x-datadog-parent-id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: _datadog.x-datadog-parent-id
  • Usage: idm_integration_reauth
unmapped._datadog.x-datadog-sampling-priority
  • Description: JumpCloud Directory Insights field _datadog.x-datadog-sampling-priority preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: _datadog.x-datadog-sampling-priority
  • Usage: idm_integration_reauth
unmapped._datadog.x-datadog-tags
  • Description: JumpCloud Directory Insights field _datadog.x-datadog-tags preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: _datadog.x-datadog-tags
  • Usage: idm_integration_reauth
unmapped._datadog.x-datadog-trace-id
  • Description: JumpCloud Directory Insights field _datadog.x-datadog-trace-id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: _datadog.x-datadog-trace-id
  • Usage: idm_integration_reauth
unmapped.application.name
  • Description: JumpCloud Directory Insights field application.name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: application.name
  • Usage: idm_integration_auth
unmapped.application_id_hash
  • Description: JumpCloud Directory Insights field application_id_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: application_id_hash
  • Usage: attributemappings_delete, idm_integration_auth, idm_integration_deactivate, idm_integration_reauth, idm_integration_update
unmapped.application_name
  • Description: JumpCloud Directory Insights field application_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: application.name
  • Usage: account_resync_failure, account_resync_initiated
unmapped.asn.error
  • Description: JumpCloud Directory Insights field asn.error preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: asn.error
  • Usage: duo_configuration_update, duoapplication_create, idm_integration_update
unmapped.asn.ip_address
  • Description: JumpCloud Directory Insights field asn.ip_address preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: asn.ip_address
  • Usage: duo_configuration_update, duoapplication_create, idm_integration_update
unmapped.asn.network
  • Description: JumpCloud Directory Insights field asn.network preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: asn.network
  • Usage: 35 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_delete, attributemappings_delete, attributemappings_update, connector_create, connector_delete, ... (+27 more)
unmapped.auth_method
  • Description: JumpCloud Directory Insights field auth_method preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: auth_method
  • Usage: account_resync_failure, account_resync_initiated, idm_integration_auth
unmapped.caller_service
  • Description: JumpCloud Directory Insights field caller_service preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: caller_service
  • Usage: connector_execute
unmapped.changes
  • Description: JumpCloud Directory Insights field changes preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes
  • Usage: idm_integration_auth, idm_integration_deactivate
unmapped.client_id
  • Description: JumpCloud Directory Insights field client_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: client_id
  • Usage: account_resync_failure, account_resync_initiated, idm_integration_auth
unmapped.correlation
  • Description: JumpCloud Directory Insights field correlation preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: correlation
  • Usage: activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_deleted, activedirectory_agent_inactive, activedirectory_config_selection_updated, activedirectory_domain_delegated_password_change, activedirectory_primary_agent_switch, attributemappings_add, attributemappings_delete, attributemappings_update
unmapped.correlation.id
  • Description: JumpCloud Directory Insights field correlation.id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: correlation.id
  • Usage: idm_integration_auth
unmapped.correlation.type
  • Description: JumpCloud Directory Insights field correlation.type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: correlation.type
  • Usage: idm_integration_auth
unmapped.correlation_type
  • Description: JumpCloud Directory Insights field correlation_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: correlation.type
  • Usage: account_resync_failure, account_resync_initiated
unmapped.error_message
  • Description: JumpCloud Directory Insights field error_message preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: error_message
  • Usage: connector_execute
unmapped.file_input_timestamp
  • Description: JumpCloud Directory Insights field file_input_timestamp preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: file_input_timestamp
  • Usage: 12 events: activedirectory_config_selection_updated, activedirectory_create, activedirectory_delete, activedirectory_domain_delegated_password_change, attributemappings_add, attributemappings_delete, attributemappings_update, idp_create, ... (+4 more)
unmapped.geoip.region_name
  • Description: JumpCloud Directory Insights field geoip.region_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.region_name
  • Usage: 44 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_config_selection_updated, activedirectory_create, activedirectory_delete, attributemappings_add, attributemappings_delete, ... (+36 more)
unmapped.geoip.timezone
  • Description: JumpCloud Directory Insights field geoip.timezone preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.timezone
  • Usage: 44 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_config_selection_updated, activedirectory_create, activedirectory_delete, attributemappings_add, attributemappings_delete, ... (+36 more)
unmapped.initiated_by.source_metadata.sourceName
  • Description: JumpCloud Directory Insights field initiated_by.source_metadata.sourceName preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by.source_metadata.sourceName
  • Usage: account_resync_failure, account_resync_initiated
unmapped.initiated_by.type
  • Description: JumpCloud Directory Insights field initiated_by.type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by.type
  • Usage: connector_execute
unmapped.initiated_by_email_hash
  • Description: JumpCloud Directory Insights field initiated_by_email_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_email_hash
  • Usage: 46 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_agent_deleted, activedirectory_config_selection_updated, activedirectory_delete, activedirectory_domain_delegated_password_change, attributemappings_add, ... (+38 more)
unmapped.initiated_by_id_hash
  • Description: JumpCloud Directory Insights field initiated_by_id_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_id_hash
  • Usage: 52 events (missing: activedirectory_create, activedirectory_primary_agent_switch, connector_execute, idp_create)
unmapped.initiated_by_provider
  • Description: JumpCloud Directory Insights field initiated_by_provider preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by.provider
  • Usage: activedirectory_agent_create, activedirectory_delete
unmapped.is_out_of_bound
  • Description: JumpCloud Directory Insights field is_out_of_bound preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: is_out_of_bound
  • Usage: 50 events: account_resync_failure, account_resync_initiated, activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_create, activedirectory_agent_deleted, activedirectory_agent_inactive, activedirectory_delete, ... (+42 more)
unmapped.jc_application_name
  • Description: JumpCloud Directory Insights field jc_application_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_application_name
  • Usage: 50 events: account_resync_failure, account_resync_initiated, activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_create, activedirectory_agent_deleted, activedirectory_agent_inactive, activedirectory_delete, ... (+42 more)
unmapped.jc_initiated_by_email
  • Description: JumpCloud Directory Insights field jc_initiated_by_email preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_initiated_by_email
  • Usage: 23 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_agent_deleted, activedirectory_delete, attributemappings_delete, connector_create, connector_delete, ... (+15 more)
unmapped.jc_initiated_by_id
  • Description: JumpCloud Directory Insights field jc_initiated_by_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_initiated_by_id
  • Usage: attributemappings_delete, connector_create, connector_delete, connector_update
unmapped.jc_initiated_by_username
  • Description: JumpCloud Directory Insights field jc_initiated_by_username preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_initiated_by_username
  • Usage: 23 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_agent_deleted, activedirectory_delete, attributemappings_delete, connector_create, connector_delete, ... (+15 more)
unmapped.jc_organization_name
  • Description: JumpCloud Directory Insights field jc_organization_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_organization_name
  • Usage: 23 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_agent_deleted, activedirectory_delete, attributemappings_delete, connector_create, connector_delete, ... (+15 more)
unmapped.jc_provider_id
  • Description: JumpCloud Directory Insights field jc_provider_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_provider_id
  • Usage: 17 events: account_resync_initiated, activedirectory_agent_create, activedirectory_agent_deleted, activedirectory_delete, attributemappings_delete, gsuite_directory_create, gsuite_directory_delete, idm_integration_deactivate, ... (+9 more)
unmapped.jc_system_display_name
  • Description: JumpCloud Directory Insights field jc_system_display_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_system_display_name
  • Usage: attributemappings_delete, connector_create, connector_delete, connector_update
unmapped.jc_system_hostname
  • Description: JumpCloud Directory Insights field jc_system_hostname preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_system_hostname
  • Usage: attributemappings_delete, connector_create, connector_delete, connector_update
unmapped.message_chain.message_details
  • Description: JumpCloud Directory Insights field message_chain.message_details preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: message_chain.message_details
  • Usage: attributemappings_add, attributemappings_delete, attributemappings_update, idm_integration_auth, integration_default_domain_add, integration_default_domain_delete, integration_default_domain_update, integration_domain_add, integration_domain_delete
unmapped.message_chain.response_code
  • Description: JumpCloud Directory Insights field message_chain.response_code preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: message_chain.response_code
  • Usage: attributemappings_add, attributemappings_delete, attributemappings_update, idm_integration_auth, integration_default_domain_add, integration_default_domain_delete, integration_default_domain_update, integration_domain_add, integration_domain_delete
unmapped.message_chain.response_message
  • Description: JumpCloud Directory Insights field message_chain.response_message preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: message_chain.response_message
  • Usage: attributemappings_add, attributemappings_delete, attributemappings_update, integration_default_domain_add, integration_default_domain_delete, integration_default_domain_update, integration_domain_add, integration_domain_delete
unmapped.message_chain_message_details
  • Description: JumpCloud Directory Insights field message_chain_message_details preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: message_chain.message_details
  • Usage: account_resync_failure, account_resync_initiated, activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_deleted, activedirectory_agent_inactive, activedirectory_config_selection_updated, activedirectory_domain_delegated_password_change, activedirectory_primary_agent_switch
unmapped.message_chain_response_code
  • Description: JumpCloud Directory Insights field message_chain_response_code preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: message_chain.response_code
  • Usage: account_resync_failure, account_resync_initiated, activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_deleted, activedirectory_agent_inactive, activedirectory_config_selection_updated, activedirectory_domain_delegated_password_change, activedirectory_primary_agent_switch
unmapped.message_chain_response_message
  • Description: JumpCloud Directory Insights field message_chain_response_message preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: message_chain.response_message
  • Usage: account_resync_failure, account_resync_initiated, activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_deleted, activedirectory_agent_inactive, activedirectory_config_selection_updated, activedirectory_domain_delegated_password_change, activedirectory_primary_agent_switch
unmapped.msp_provider_id
  • Description: JumpCloud Directory Insights field msp_provider_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: provider
  • Usage: activedirectory_agent_create, activedirectory_agent_deleted, activedirectory_create, activedirectory_delete
unmapped.provider
  • Description: JumpCloud Directory Insights field provider preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: provider
  • Usage: idm_integration_auth
unmapped.resource.authentication.header_key
  • Description: JumpCloud Directory Insights field resource.authentication.header_key preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.authentication.header_key
  • Usage: connector_execute
unmapped.resource.authentication.type
  • Description: JumpCloud Directory Insights field resource.authentication.type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.authentication.type
  • Usage: connector_execute
unmapped.resource.authentication.username
  • Description: JumpCloud Directory Insights field resource.authentication.username preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.authentication.username
  • Usage: connector_execute
unmapped.resource.authentication.value_prefix
  • Description: JumpCloud Directory Insights field resource.authentication.value_prefix preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.authentication.value_prefix
  • Usage: connector_execute
unmapped.resource.base_url
  • Description: JumpCloud Directory Insights field resource.base_url preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.base_url
  • Usage: connector_execute
unmapped.resource.connector_id
  • Description: JumpCloud Directory Insights field resource.connector_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.connector_id
  • Usage: connector_execute
unmapped.resource.custom_headers.Header
  • Description: JumpCloud Directory Insights field resource.custom_headers.Header preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.custom_headers.Header
  • Usage: connector_execute
unmapped.resource.custom_headers.Headers
  • Description: JumpCloud Directory Insights field resource.custom_headers.Headers preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.custom_headers.Headers
  • Usage: connector_execute
unmapped.resource.custom_headers.New
  • Description: JumpCloud Directory Insights field resource.custom_headers.New preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.custom_headers.New
  • Usage: connector_execute
unmapped.resource.custom_headers.X-API-KEY
  • Description: JumpCloud Directory Insights field resource.custom_headers.X-API-KEY preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.custom_headers.X-API-KEY
  • Usage: connector_execute
unmapped.resource.custom_headers.X-Api-Key
  • Description: JumpCloud Directory Insights field resource.custom_headers.X-Api-Key preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.custom_headers.X-Api-Key
  • Usage: connector_execute
unmapped.resource.custom_headers.X-Jc-Id
  • Description: JumpCloud Directory Insights field resource.custom_headers.X-Jc-Id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.custom_headers.X-Jc-Id
  • Usage: connector_execute
unmapped.resource.custom_headers.header
  • Description: JumpCloud Directory Insights field resource.custom_headers.header preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.custom_headers.header
  • Usage: connector_execute
unmapped.resource.custom_headers.headers
  • Description: JumpCloud Directory Insights field resource.custom_headers.headers preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.custom_headers.headers
  • Usage: connector_execute
unmapped.resource.custom_headers.new
  • Description: JumpCloud Directory Insights field resource.custom_headers.new preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.custom_headers.new
  • Usage: connector_execute
unmapped.resource.id
  • Description: JumpCloud Directory Insights field resource.id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.id
  • Usage: connector_execute
unmapped.resource.idm_client_id
  • Description: JumpCloud Directory Insights field resource.idm_client_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.idm_client_id
  • Usage: idm_integration_auth
unmapped.resource.name
  • Description: JumpCloud Directory Insights field resource.name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.name
  • Usage: connector_execute
unmapped.resource.object_id
  • Description: JumpCloud Directory Insights field resource.object_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.object_id
  • Usage: connector_execute
unmapped.resource.status
  • Description: JumpCloud Directory Insights field resource.status preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.status
  • Usage: connector_execute
unmapped.resource.type
  • Description: JumpCloud Directory Insights field resource.type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.type
  • Usage: connector_execute, idm_integration_auth
unmapped.resource_id_hash
  • Description: JumpCloud Directory Insights field resource_id_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource_id_hash
  • Usage: 38 events: activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_create, activedirectory_agent_deleted, activedirectory_agent_inactive, activedirectory_config_selection_updated, activedirectory_delete, activedirectory_domain_delegated_password_change, ... (+30 more)
unmapped.resource_ids
  • Description: JumpCloud Directory Insights field resource_ids preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.ids
  • Usage: account_resync_failure, account_resync_initiated
unmapped.resource_name_hash
  • Description: JumpCloud Directory Insights field resource_name_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource_name_hash
  • Usage: attributemappings_delete, connector_create, connector_delete, connector_execute, connector_update
unmapped.tags
  • Description: JumpCloud Directory Insights field tags preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: tags
  • Usage: 12 events: activedirectory_config_selection_updated, activedirectory_create, activedirectory_delete, activedirectory_domain_delegated_password_change, attributemappings_add, attributemappings_delete, attributemappings_update, idp_create, ... (+4 more)
unmapped.timestamp_source
  • Description: JumpCloud Directory Insights field timestamp_source preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: timestamp_source
  • Usage: 26 events: account_resync_failure, account_resync_initiated, activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_deleted, activedirectory_agent_inactive, activedirectory_config_selection_updated, activedirectory_domain_delegated_password_change, ... (+18 more)
unmapped.useragent.device
  • Description: JumpCloud Directory Insights field useragent.device preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.device
  • Usage: 45 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_create, activedirectory_delete, attributemappings_add, attributemappings_delete, attributemappings_update, ... (+37 more)
unmapped.useragent.major
  • Description: JumpCloud Directory Insights field useragent.major preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.major
  • Usage: 44 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_create, activedirectory_delete, attributemappings_add, attributemappings_delete, attributemappings_update, ... (+36 more)
unmapped.useragent.minor
  • Description: JumpCloud Directory Insights field useragent.minor preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.minor
  • Usage: 44 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_create, activedirectory_delete, attributemappings_add, attributemappings_delete, attributemappings_update, ... (+36 more)
unmapped.useragent.name
  • Description: JumpCloud Directory Insights field useragent.name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.name
  • Usage: 45 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_create, activedirectory_delete, attributemappings_add, attributemappings_delete, attributemappings_update, ... (+37 more)
unmapped.useragent.os
  • Description: JumpCloud Directory Insights field useragent.os preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os
  • Usage: 45 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_create, activedirectory_delete, attributemappings_add, attributemappings_delete, attributemappings_update, ... (+37 more)
unmapped.useragent.os_full
  • Description: JumpCloud Directory Insights field useragent.os_full preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_full
  • Usage: 45 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_create, activedirectory_delete, attributemappings_add, attributemappings_delete, attributemappings_update, ... (+37 more)
unmapped.useragent.os_major
  • Description: JumpCloud Directory Insights field useragent.os_major preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_major
  • Usage: 42 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_delete, attributemappings_add, attributemappings_delete, attributemappings_update, duo_configuration_update, ... (+34 more)
unmapped.useragent.os_minor
  • Description: JumpCloud Directory Insights field useragent.os_minor preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_minor
  • Usage: 41 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_delete, attributemappings_add, attributemappings_delete, attributemappings_update, duo_configuration_update, ... (+33 more)
unmapped.useragent.os_name
  • Description: JumpCloud Directory Insights field useragent.os_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_name
  • Usage: 45 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_create, activedirectory_delete, attributemappings_add, attributemappings_delete, attributemappings_update, ... (+37 more)
unmapped.useragent.os_patch
  • Description: JumpCloud Directory Insights field useragent.os_patch preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_patch
  • Usage: 41 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_delete, attributemappings_add, attributemappings_delete, attributemappings_update, duo_configuration_update, ... (+33 more)
unmapped.useragent.os_version
  • Description: JumpCloud Directory Insights field useragent.os_version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_version
  • Usage: 42 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_delete, attributemappings_add, attributemappings_delete, attributemappings_update, duo_configuration_update, ... (+34 more)
unmapped.useragent.patch
  • Description: JumpCloud Directory Insights field useragent.patch preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.patch
  • Usage: 43 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_delete, attributemappings_add, attributemappings_delete, attributemappings_update, duo_configuration_update, ... (+35 more)
unmapped.useragent.version
  • Description: JumpCloud Directory Insights field useragent.version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.version
  • Usage: 44 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_create, activedirectory_delete, attributemappings_add, attributemappings_delete, attributemappings_update, ... (+36 more)
unmapped.version
  • Description: JumpCloud Directory Insights field version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: version
  • Usage: connector_create, connector_delete, connector_execute, connector_update

Directory — MTP/MSP Events#

directory_mtp · 29 events

Event Category Class Activity Type UID Fields
admin_lockout Identity & Access Management (3) Account Change (3001) Lock (9) 300109 68
admin_suspended Identity & Access Management (3) Account Change (3001) Disable (5) 300105 68
admin_unsuspend Identity & Access Management (3) Account Change (3001) Enable (2) 300102 64
autotask_billing_mapping_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 68
autotask_billing_mapping_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 67
autotask_billing_mapping_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 70
autotask_company_mapping_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 62
autotask_company_mapping_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 64
autotask_integration_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 60
autotask_integration_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 58
connectwise_billing_mapping_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 63
connectwise_billing_mapping_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 59
connectwise_billing_mapping_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 64
connectwise_company_mapping_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 62
connectwise_company_mapping_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 64
connectwise_integration_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 60
connectwise_integration_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 60
connectwise_integration_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 61
connectwise_settings_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 61
msp_ticket_create Application Activity (6) API Activity (6003) Create (1) 600301 34
mtp_download_invoice Identity & Access Management (3) Entity Management (3004) Read (2) 300402 61
partner_organization_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 38
provider_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 63
syncro_billing_mapping_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 67
syncro_billing_sync System Activity (1) Scheduled Job Activity (1006) Start (6) 100606 29
syncro_company_mapping_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 62
syncro_company_mapping_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 63
syncro_company_mapping_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 64
syncro_integration_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 60

OCSF field mappings#

Legend

  • Description: what the OCSF field represents (from OCSF schema v1.8.0)
  • Source: raw JumpCloud event field(s) mapped via ${{placeholder}} template
  • Transform: fieldMappings entry applied at runtime (cast, enum, etc.)
  • Literal: static value set in the mapping template
  • Usage: event types in this service that include this field

Core

activity_id
  • Description: The normalized identifier of the activity that triggered the event.
  • Literal: 1, 2, 3, 4, 5, 6, 9
  • Usage: all events in this service
activity_name
  • Description: The event activity name, as defined by the activity_id.
  • Literal: Create, Delete, Disable, Enable, Lock, Read, Start, Update
  • Usage: all events in this service
category_name
  • Description: The event category name, as defined by category_uid value: Discovery.
  • Literal: Application Activity, Identity & Access Management, System Activity
  • Usage: all events in this service
category_uid
  • Description: The category unique identifier of the event.
  • Literal: 1, 3, 6
  • Usage: all events in this service
class_name
  • Description: The event class name, as defined by class_uid value: User Inventory Info.
  • Literal: API Activity, Account Change, Entity Management, Scheduled Job Activity
  • Usage: all events in this service
class_uid
  • Description: The unique identifier of a class. A class describes the attributes available in an event.
  • Literal: 1006, 3001, 3004, 6003
  • Usage: all events in this service
severity_id
  • Description: OCSF severity identifier for the event.
  • Literal: 1
  • Usage: all events in this service
status_detail
  • Description: The status detail contains additional information about the event/finding outcome.
  • Source: error_message
  • Usage: all events in this service
status_id
  • Description: Normalized status of the activity (1=Success, 2=Failure).
  • Source: success
  • Transform:
  • success → boolean_to_status_id; true→1, false→2 (all events in this service)
  • Usage: all events in this service
time
  • Description: Event time, in epoch milliseconds (OCSF time).
  • Source: timestamp
  • Transform:
  • timestamp → iso8601_to_epoch_millis (all events in this service)
  • Usage: all events in this service
type_uid
  • Description: The event/finding type ID. It identifies the event's semantics and structure. The value is calculated by the logging system as: class_uid * 100 + activity_id.
  • Literal: 100606, 300102, 300105, 300109, 300401, 300402, 300403, 300404, 600301
  • Usage: all events in this service

Metadata

metadata.event_code
  • Description: JumpCloud event type code.
  • Source: event_type
  • Usage: all events in this service
metadata.original_time
  • Description: The original event time as reported by the event source. For example, the time in the original format from system event log such as Syslog on Unix/Linux and the System event file on Windows. Omit if event is generated instead of collected via logs.
  • Source: server_timestamp
  • Usage: msp_ticket_create, partner_organization_delete, syncro_billing_sync
metadata.processed_time
  • Description: The event processed time, such as an ETL operation.
  • Source: jc_transformation_ts
  • Usage: all events in this service
metadata.product.name
  • Description: Originating JumpCloud service that produced the event.
  • Source: service
  • Usage: all events in this service
metadata.tenant_uid
  • Description: JumpCloud organization (tenant) identifier.
  • Source: organization
  • Usage: all events in this service
metadata.uid
  • Description: Unique event identifier assigned by JumpCloud.
  • Source: id
  • Usage: all events in this service
metadata.version
  • Description: OCSF schema version used for this event.
  • Literal: 1.8.0
  • Usage: all events in this service

Actor

actor.invoked_by
  • Description: The name of the service that invoked the activity as described in the event.
  • Source: initiated_by.source
  • Usage: partner_organization_delete
actor.user.email_addr
  • Description: Email address of the actor who initiated the event.
  • Source: initiated_by.email
  • Usage: 26 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+18 more)
actor.user.org.uid
  • Description: The unique identifier of the organization, Oracle Cloud Tenancy, Google Cloud Organization, or AWS Organization. For example, an AWS Org ID or Oracle Cloud Domain ID .
  • Source: initiated_by.provider
  • Usage: 14 events: connectwise_billing_mapping_create, connectwise_billing_mapping_delete, connectwise_billing_mapping_update, connectwise_company_mapping_create, connectwise_company_mapping_update, connectwise_integration_create, connectwise_integration_delete, connectwise_integration_update, ... (+6 more)
actor.user.type_id
  • Description: OCSF user type of the actor (1=User, 2=Admin, 3=System, 4=Service).
  • Source: initiated_by.type
  • Transform:
  • initiated_by.type → enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (27 events (missing: msp_ticket_create, syncro_billing_sync))
  • Usage: 27 events (missing: msp_ticket_create, syncro_billing_sync)
actor.user.uid
  • Description: Unique identifier of the actor who initiated the event.
  • Source: initiated_by.id
  • Usage: 26 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+18 more)

User

user.account.is_disabled
  • Description: Indicates if the account is disabled.
  • Source: changes.from
  • Usage: admin_lockout
user.email_addr
  • Description: Email address of the user associated with the event.
  • Source: resource.email
  • Usage: admin_lockout, admin_suspended, admin_unsuspend
user.type_id
  • Description: OCSF user type (1=User, 2=Admin, 3=System, 4=Service).
  • Source: resource.type
  • Transform:
  • resource.type → enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (admin_lockout, admin_suspended, admin_unsuspend)
  • Usage: admin_lockout, admin_suspended, admin_unsuspend
user.uid
  • Description: Unique identifier of the user associated with the event.
  • Source: resource.id
  • Usage: admin_lockout, admin_suspended, admin_unsuspend

Entity

entity.data.auth_method
  • Description: JumpCloud extension data on the managed entity: auth_method.
  • Source: auth_method
  • Usage: 14 events: connectwise_billing_mapping_create, connectwise_billing_mapping_delete, connectwise_billing_mapping_update, connectwise_company_mapping_create, connectwise_company_mapping_update, connectwise_integration_create, connectwise_integration_delete, connectwise_integration_update, ... (+6 more)
entity.data.changed_field
  • Description: JumpCloud extension data on the managed entity: changed_field.
  • Source: changes.field
  • Usage: 22 events: autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, autotask_integration_delete, autotask_integration_update, connectwise_billing_mapping_create, ... (+14 more)
entity.data.changes_from
  • Description: JumpCloud extension data on the managed entity: changes_from.
  • Source: changes.from
  • Usage: autotask_billing_mapping_create, autotask_integration_delete, autotask_integration_update, connectwise_billing_mapping_create, connectwise_integration_delete, connectwise_integration_update, connectwise_settings_update, provider_update
entity.data.changes_from_id
  • Description: JumpCloud extension data on the managed entity: changes_from_id.
  • Source: changes.from.id
  • Usage: autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_delete, connectwise_billing_mapping_delete, connectwise_billing_mapping_update, connectwise_company_mapping_update, syncro_company_mapping_delete, syncro_company_mapping_update
entity.data.changes_from_name
  • Description: JumpCloud extension data on the managed entity: changes_from_name.
  • Source: changes.from.name
  • Usage: autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_delete, connectwise_billing_mapping_delete, connectwise_billing_mapping_update, connectwise_company_mapping_update, syncro_company_mapping_delete, syncro_company_mapping_update
entity.data.changes_from_nonBillableUsers
  • Description: JumpCloud extension data on the managed entity: changes_from_nonBillableUsers.
  • Source: changes.from.nonBillableUsers
  • Usage: autotask_billing_mapping_delete, autotask_billing_mapping_update
entity.data.origin
  • Description: JumpCloud extension data on the managed entity: origin.
  • Source: origin
  • Usage: partner_organization_delete
entity.data.provider
  • Description: JumpCloud extension data on the managed entity: provider.
  • Source: provider
  • Usage: 23 events: autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, autotask_integration_delete, autotask_integration_update, connectwise_billing_mapping_create, ... (+15 more)
entity.data.reason
  • Description: JumpCloud extension data on the managed entity: reason.
  • Source: reason
  • Usage: partner_organization_delete
entity.data.status
  • Description: JumpCloud extension data on the managed entity: status.
  • Source: status
  • Usage: partner_organization_delete
entity.name
  • Description: The name of the managed entity. It should match the name of the specific entity object's name if populated, or the name of the managed entity if the type_id is 'Other'.
  • Source: partner_name
  • Usage: partner_organization_delete
entity.type
  • Description: The managed entity type. For example: Policy, User, Organization, Device.
  • Source: resource.type
  • Usage: 23 events: autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, autotask_integration_delete, autotask_integration_update, connectwise_billing_mapping_create, ... (+15 more)
entity.uid
  • Description: The identifier of the managed entity. It should match the uid of the specific entity's object UID if populated, or the source specific ID if the type_id is 'Other'.
  • Source: resource.id
  • Usage: mtp_download_invoice, provider_update
entity_result.data.changes_to
  • Description: JumpCloud extension data on the managed entity: changes_to.
  • Source: changes.to
  • Usage: autotask_billing_mapping_delete, autotask_integration_update, connectwise_billing_mapping_delete, connectwise_integration_create, connectwise_integration_update, connectwise_settings_update, provider_update, syncro_integration_create
entity_result.data.changes_to_fields_line_item_id_kind
  • Description: JumpCloud extension data on the managed entity: changes_to_fields_line_item_id_kind.
  • Source: changes.to.fields.line_item_id.kind
  • Usage: syncro_billing_mapping_create
entity_result.data.changes_to_fields_line_item_id_numberValue
  • Description: JumpCloud extension data on the managed entity: changes_to_fields_line_item_id_numberValue.
  • Source: changes.to.fields.line_item_id.numberValue
  • Usage: syncro_billing_mapping_create
entity_result.data.changes_to_fields_line_item_name_kind
  • Description: JumpCloud extension data on the managed entity: changes_to_fields_line_item_name_kind.
  • Source: changes.to.fields.line_item_name.kind
  • Usage: syncro_billing_mapping_create
entity_result.data.changes_to_fields_line_item_name_stringValue
  • Description: JumpCloud extension data on the managed entity: changes_to_fields_line_item_name_stringValue.
  • Source: changes.to.fields.line_item_name.stringValue
  • Usage: syncro_billing_mapping_create
entity_result.data.changes_to_fields_schedule_id_numberValue
  • Description: JumpCloud extension data on the managed entity: changes_to_fields_schedule_id_numberValue.
  • Source: changes.to.fields.schedule_id.numberValue
  • Usage: syncro_billing_mapping_create
entity_result.data.changes_to_fields_schedule_name_stringValue
  • Description: JumpCloud extension data on the managed entity: changes_to_fields_schedule_name_stringValue.
  • Source: changes.to.fields.schedule_name.stringValue
  • Usage: syncro_billing_mapping_create
entity_result.data.changes_to_id
  • Description: JumpCloud extension data on the managed entity: changes_to_id.
  • Source: changes.to.id
  • Usage: autotask_billing_mapping_create, autotask_billing_mapping_update, autotask_company_mapping_create, connectwise_billing_mapping_create, connectwise_billing_mapping_update, connectwise_company_mapping_create, connectwise_company_mapping_update, syncro_billing_mapping_create, syncro_company_mapping_create, syncro_company_mapping_update
entity_result.data.changes_to_name
  • Description: JumpCloud extension data on the managed entity: changes_to_name.
  • Source: changes.to.name
  • Usage: autotask_billing_mapping_create, autotask_billing_mapping_update, autotask_company_mapping_create, connectwise_billing_mapping_create, connectwise_billing_mapping_update, connectwise_company_mapping_create, connectwise_company_mapping_update, syncro_billing_mapping_create, syncro_company_mapping_create, syncro_company_mapping_update
entity_result.data.changes_to_nonBillableUsers
  • Description: JumpCloud extension data on the managed entity: changes_to_nonBillableUsers.
  • Source: changes.to.nonBillableUsers
  • Usage: autotask_billing_mapping_create, autotask_billing_mapping_update
entity_result.data.changes_to_value
  • Description: JumpCloud extension data on the managed entity: changes_to_value.
  • Source: changes.to.value
  • Usage: autotask_billing_mapping_create, autotask_billing_mapping_update, autotask_company_mapping_create, connectwise_billing_mapping_create, connectwise_billing_mapping_update, connectwise_company_mapping_create, connectwise_company_mapping_update, syncro_company_mapping_create, syncro_company_mapping_update

Src Endpoint

src_endpoint.autonomous_system.name
  • Description: Organization name for the Autonomous System.
  • Source: asn.organization
  • Usage: 25 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+17 more)
src_endpoint.autonomous_system.number
  • Description: Unique number that the AS is identified by.
  • Source: asn.number
  • Transform:
  • asn.number → int (25 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+17 more))
  • Usage: 25 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+17 more)
src_endpoint.ip
  • Description: Source IP address the request originated from.
  • Source: client_ip
  • Usage: 28 events (missing: syncro_billing_sync)
src_endpoint.location.city
  • Description: The name of the city.
  • Source: geoip.city
  • Usage: 26 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+18 more)
src_endpoint.location.continent
  • Description: The name of the continent.
  • Source: geoip.continent_code
  • Usage: 26 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+18 more)
src_endpoint.location.country
  • Description: The ISO 3166-1 Alpha-2 country code.

    Note: The two letter country code should be capitalized. For example: US or CA.

  • Source: geoip.country_code
  • Usage: 26 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+18 more)
src_endpoint.location.lat
  • Description: The geographical Latitude coordinate represented in Decimal Degrees (DD). For example: 42.361145.
  • Source: geoip.latitude
  • Transform:
  • geoip.latitude → double (26 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+18 more))
  • Usage: 26 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+18 more)
src_endpoint.location.long
  • Description: The geographical Longitude coordinate represented in Decimal Degrees (DD). For example: -71.057083.
  • Source: geoip.longitude
  • Transform:
  • geoip.longitude → double (26 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+18 more))
  • Usage: 26 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+18 more)
src_endpoint.location.region
  • Description: The alphanumeric code that identifies the principal subdivision (e.g. province or state) of the country. For example, 'CH-VD' for the Canton of Vaud, Switzerland
  • Source: geoip.region_code
  • Usage: 26 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+18 more)

Http Request

http_request.user_agent
  • Description: The request header that identifies the operating system and web browser.
  • Source: user_agent
  • Usage: 28 events (missing: syncro_billing_sync)

Observables

observables[].name
  • Description: The full name of the observable attribute. The name is a pointer/reference to an attribute within the OCSF event data. For example: file.name. Array attributes may be represented in one of three ways. For example: resources.uid, resources[].uid, resources[0].uid.
  • Literal: actor.user.email_addr, actor.user.uid, http_request.user_agent, src_endpoint.ip, src_endpoint.location.country, user.email_addr, user.uid
  • Usage: 28 events (missing: syncro_billing_sync)
observables[].type_id
  • Description: The observable value type identifier.
  • Literal: 14, 16, 2, 31, 5
  • Usage: 28 events (missing: syncro_billing_sync)
observables[].value
  • Description: The value associated with the observable attribute. The meaning of the value depends on the observable type.
    If the name refers to a scalar attribute, then the value is the value of the attribute.
    If the name refers to an object attribute, then the value is not populated.
  • Source: client_ip, geoip.country_code, initiated_by.email, initiated_by.id, resource.email, resource.id, user_agent
  • Usage: 28 events (missing: syncro_billing_sync)

Other

api.request.uid
  • Description: The unique request identifier.
  • Source: ticketing_event_id
  • Usage: msp_ticket_create
api.service.name
  • Description: The name of the service.
  • Source: integration_type
  • Usage: msp_ticket_create
user_result.account.is_disabled
  • Description: Indicates if the account is disabled.
  • Source: changes.to
  • Usage: admin_lockout

Unmapped

unmapped.@timestamp
  • Description: JumpCloud Directory Insights field @timestamp preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: @timestamp
  • Usage: autotask_company_mapping_delete, msp_ticket_create, partner_organization_delete, syncro_billing_sync
unmapped.@version
  • Description: JumpCloud Directory Insights field @version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: @version
  • Usage: all events in this service
unmapped.asn.network
  • Description: JumpCloud Directory Insights field asn.network preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: asn.network
  • Usage: 23 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+15 more)
unmapped.auth_method
  • Description: JumpCloud Directory Insights field auth_method preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: auth_method
  • Usage: 13 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+5 more)
unmapped.changed_field
  • Description: JumpCloud Directory Insights field changed_field preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.field
  • Usage: admin_lockout, admin_suspended, admin_unsuspend
unmapped.changes
  • Description: JumpCloud Directory Insights field changes preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes
  • Usage: mtp_download_invoice
unmapped.changes_from
  • Description: JumpCloud Directory Insights field changes_from preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.from
  • Usage: admin_suspended, admin_unsuspend
unmapped.changes_to
  • Description: JumpCloud Directory Insights field changes_to preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to
  • Usage: admin_suspended, admin_unsuspend
unmapped.client_ip
  • Description: JumpCloud Directory Insights field client_ip preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: client_ip
  • Usage: syncro_billing_sync
unmapped.file_input_timestamp
  • Description: JumpCloud Directory Insights field file_input_timestamp preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: file_input_timestamp
  • Usage: autotask_company_mapping_delete, msp_ticket_create, partner_organization_delete, syncro_billing_sync
unmapped.geoip.region_name
  • Description: JumpCloud Directory Insights field geoip.region_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.region_name
  • Usage: 26 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+18 more)
unmapped.geoip.timezone
  • Description: JumpCloud Directory Insights field geoip.timezone preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.timezone
  • Usage: 26 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+18 more)
unmapped.initiated_by
  • Description: JumpCloud Directory Insights field initiated_by preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by
  • Usage: msp_ticket_create, syncro_billing_sync
unmapped.initiated_by_email_hash
  • Description: JumpCloud Directory Insights field initiated_by_email_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_email_hash
  • Usage: 26 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+18 more)
unmapped.initiated_by_id_hash
  • Description: JumpCloud Directory Insights field initiated_by_id_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_id_hash
  • Usage: 26 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+18 more)
unmapped.initiated_by_provider
  • Description: JumpCloud Directory Insights field initiated_by_provider preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by.provider
  • Usage: 12 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+4 more)
unmapped.is_out_of_bound
  • Description: JumpCloud Directory Insights field is_out_of_bound preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: is_out_of_bound
  • Usage: all events in this service
unmapped.jc_application_name
  • Description: JumpCloud Directory Insights field jc_application_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_application_name
  • Usage: all events in this service
unmapped.jc_initiated_by_email
  • Description: JumpCloud Directory Insights field jc_initiated_by_email preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_initiated_by_email
  • Usage: admin_lockout, admin_suspended, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, syncro_company_mapping_delete
unmapped.jc_initiated_by_username
  • Description: JumpCloud Directory Insights field jc_initiated_by_username preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_initiated_by_username
  • Usage: admin_lockout, admin_suspended, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, syncro_company_mapping_delete
unmapped.jc_organization_name
  • Description: JumpCloud Directory Insights field jc_organization_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_organization_name
  • Usage: admin_lockout, admin_suspended, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, syncro_company_mapping_delete
unmapped.jc_provider_id
  • Description: JumpCloud Directory Insights field jc_provider_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_provider_id
  • Usage: admin_lockout, admin_suspended, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update
unmapped.msp_provider_id
  • Description: JumpCloud Directory Insights field msp_provider_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: provider
  • Usage: admin_lockout, admin_suspended, admin_unsuspend, msp_ticket_create
unmapped.provider
  • Description: JumpCloud Directory Insights field provider preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: provider
  • Usage: syncro_billing_sync
unmapped.resource_id_hash
  • Description: JumpCloud Directory Insights field resource_id_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource_id_hash
  • Usage: admin_lockout, admin_suspended, admin_unsuspend, mtp_download_invoice, provider_update
unmapped.source_metadata_name
  • Description: JumpCloud Directory Insights field source_metadata_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by.source_metadata.name
  • Usage: partner_organization_delete
unmapped.tags
  • Description: JumpCloud Directory Insights field tags preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: tags
  • Usage: autotask_company_mapping_delete, msp_ticket_create, partner_organization_delete, syncro_billing_sync
unmapped.timestamp_source
  • Description: JumpCloud Directory Insights field timestamp_source preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: timestamp_source
  • Usage: msp_ticket_create, partner_organization_delete, syncro_billing_sync
unmapped.user_agent
  • Description: JumpCloud Directory Insights field user_agent preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: user_agent
  • Usage: syncro_billing_sync
unmapped.useragent.device
  • Description: JumpCloud Directory Insights field useragent.device preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.device
  • Usage: 26 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+18 more)
unmapped.useragent.major
  • Description: JumpCloud Directory Insights field useragent.major preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.major
  • Usage: 26 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+18 more)
unmapped.useragent.minor
  • Description: JumpCloud Directory Insights field useragent.minor preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.minor
  • Usage: 26 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+18 more)
unmapped.useragent.name
  • Description: JumpCloud Directory Insights field useragent.name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.name
  • Usage: 26 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+18 more)
unmapped.useragent.os
  • Description: JumpCloud Directory Insights field useragent.os preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os
  • Usage: 26 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+18 more)
unmapped.useragent.os_full
  • Description: JumpCloud Directory Insights field useragent.os_full preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_full
  • Usage: 26 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+18 more)
unmapped.useragent.os_major
  • Description: JumpCloud Directory Insights field useragent.os_major preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_major
  • Usage: 26 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+18 more)
unmapped.useragent.os_minor
  • Description: JumpCloud Directory Insights field useragent.os_minor preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_minor
  • Usage: 25 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+17 more)
unmapped.useragent.os_name
  • Description: JumpCloud Directory Insights field useragent.os_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_name
  • Usage: 26 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+18 more)
unmapped.useragent.os_patch
  • Description: JumpCloud Directory Insights field useragent.os_patch preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_patch
  • Usage: 25 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+17 more)
unmapped.useragent.os_version
  • Description: JumpCloud Directory Insights field useragent.os_version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_version
  • Usage: 26 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+18 more)
unmapped.useragent.patch
  • Description: JumpCloud Directory Insights field useragent.patch preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.patch
  • Usage: 26 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+18 more)
unmapped.useragent.version
  • Description: JumpCloud Directory Insights field useragent.version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.version
  • Usage: 26 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+18 more)

Directory — Object Events#

directory_object · 46 events

Event Category Class Activity Type UID Fields
application_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 50
application_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 57
application_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 50
association_change Identity & Access Management (3) Group Management (3006) Add User (3) 300603 35
group_create Identity & Access Management (3) Group Management (3006) Create (6) 300606 50
group_create_provision Application Activity (6) API Activity (6003) Create (1) 600301 46
group_delete Identity & Access Management (3) Group Management (3006) Delete (5) 300605 66
group_delete_provision Application Activity (6) API Activity (6003) Delete (4) 600304 45
group_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 77
group_update_provision Application Activity (6) API Activity (6003) Update (3) 600303 38
group_warning Identity & Access Management (3) Entity Management (3004) Update (3) 300403 35
integrationattribute_exclude Identity & Access Management (3) Entity Management (3004) Update (3) 300403 55
integrationattribute_include Identity & Access Management (3) Entity Management (3004) Update (3) 300403 44
invoice_download Identity & Access Management (3) Entity Management (3004) Read (2) 300402 58
jumpcloud_durt_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 68
jumpcloud_durt_enablement_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 35
jumpcloud_durt_registration Identity & Access Management (3) Entity Management (3004) Enroll (6) 300406 42
membership_create_provision Application Activity (6) API Activity (6003) Create (1) 600301 45
membership_delete_provision Application Activity (6) API Activity (6003) Delete (4) 600304 46
order_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 65
organization_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 87
organization_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 65
organization_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 87
provider_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 62
radius_radsec_certificate_upload Identity & Access Management (3) Entity Management (3004) Update (3) 300403 64
radiusserver_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 47
radiusserver_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 48
radiusserver_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 48
role_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 38
role_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 41
role_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 39
scheduled_import_job_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 68
scheduled_import_job_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 68
service_account_access_granted Identity & Access Management (3) User Access Management (3005) Assign Privileges (1) 300501 66
service_account_access_revoked Identity & Access Management (3) User Access Management (3005) Revoke Privileges (2) 300502 64
service_account_auth_config_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 82
service_account_auth_config_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 82
service_account_auth_config_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 43
service_account_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 65
service_account_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 83
service_account_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 66
system_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 60
system_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 48
system_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 54
user_group_admin_grant Identity & Access Management (3) Group Management (3006) Assign Privileges (1) 300601 70
user_group_admin_revoke Identity & Access Management (3) Group Management (3006) Revoke Privileges (2) 300602 69

OCSF field mappings#

Legend

  • Description: what the OCSF field represents (from OCSF schema v1.8.0)
  • Source: raw JumpCloud event field(s) mapped via ${{placeholder}} template
  • Transform: fieldMappings entry applied at runtime (cast, enum, etc.)
  • Literal: static value set in the mapping template
  • Usage: event types in this service that include this field

Core

activity_id
  • Description: The normalized identifier of the activity that triggered the event.
  • Literal: 1, 2, 3, 4, 5, 6
  • Usage: all events in this service
activity_name
  • Description: The event activity name, as defined by the activity_id.
  • Literal: Add User, Assign Privileges, Create, Delete, Enroll, Read, Revoke Privileges, Update
  • Usage: all events in this service
category_name
  • Description: The event category name, as defined by category_uid value: Discovery.
  • Literal: Application Activity, Identity & Access Management
  • Usage: all events in this service
category_uid
  • Description: The category unique identifier of the event.
  • Literal: 3, 6
  • Usage: all events in this service
class_name
  • Description: The event class name, as defined by class_uid value: User Inventory Info.
  • Literal: API Activity, Entity Management, Group Management, User Access Management
  • Usage: all events in this service
class_uid
  • Description: The unique identifier of a class. A class describes the attributes available in an event.
  • Literal: 3004, 3005, 3006, 6003
  • Usage: all events in this service
message
  • Description: The description of the event/finding, as defined by the source.
  • Source: error_message, message_chain.response_message
  • Usage: jumpcloud_durt_delete, jumpcloud_durt_enablement_update, jumpcloud_durt_registration, scheduled_import_job_create, scheduled_import_job_delete
severity_id
  • Description: OCSF severity identifier for the event.
  • Literal: 1
  • Usage: all events in this service
status_detail
  • Description: The status detail contains additional information about the event/finding outcome.
  • Source: error_message
  • Usage: 32 events: application_delete, group_create_provision, group_delete, group_delete_provision, group_update, group_update_provision, group_warning, integrationattribute_exclude, ... (+24 more)
status_id
  • Description: Normalized status of the activity (1=Success, 2=Failure).
  • Source: success
  • Transform:
  • success → boolean_to_status_id; true→1, false→2 (35 events: application_delete, association_change, group_create_provision, group_delete, group_delete_provision, group_update, group_update_provision, group_warning, ... (+27 more))
  • Usage: 35 events: application_delete, association_change, group_create_provision, group_delete, group_delete_provision, group_update, group_update_provision, group_warning, ... (+27 more)
time
  • Description: Event time, in epoch milliseconds (OCSF time).
  • Source: timestamp
  • Transform:
  • timestamp → iso8601_to_epoch_millis (all events in this service)
  • Usage: all events in this service
type_uid
  • Description: The event/finding type ID. It identifies the event's semantics and structure. The value is calculated by the logging system as: class_uid * 100 + activity_id.
  • Literal: 300401, 300402, 300403, 300404, 300406, 300501, 300502, 300601, 300602, 300603, 300605, 300606, 600301, 600303, 600304
  • Usage: all events in this service

Metadata

metadata.event_code
  • Description: JumpCloud event type code.
  • Source: event_type
  • Usage: all events in this service
metadata.original_time
  • Description: The original event time as reported by the event source. For example, the time in the original format from system event log such as Syslog on Unix/Linux and the System event file on Windows. Omit if event is generated instead of collected via logs.
  • Source: server_timestamp
  • Usage: 22 events: association_change, group_create_provision, group_delete_provision, group_update_provision, group_warning, jumpcloud_durt_delete, jumpcloud_durt_registration, membership_create_provision, ... (+14 more)
metadata.processed_time
  • Description: The event processed time, such as an ETL operation.
  • Source: jc_transformation_ts
  • Usage: 34 events: application_delete, group_create_provision, group_delete, group_delete_provision, group_update, group_update_provision, group_warning, integrationattribute_exclude, ... (+26 more)
metadata.product.name
  • Description: Originating JumpCloud service that produced the event.
  • Source: service
  • Usage: all events in this service
metadata.tenant_uid
  • Description: JumpCloud organization (tenant) identifier.
  • Source: organization
  • Usage: all events in this service
metadata.uid
  • Description: Unique event identifier assigned by JumpCloud.
  • Source: id
  • Usage: all events in this service
metadata.version
  • Description: OCSF schema version used for this event.
  • Literal: 1.8.0
  • Usage: all events in this service

Actor

actor.user.email_addr
  • Description: Email address of the actor who initiated the event.
  • Source: initiated_by.email
  • Usage: 35 events: application_create, application_delete, application_update, group_create, group_delete, group_update, integrationattribute_exclude, integrationattribute_include, ... (+27 more)
actor.user.name
  • Description: Display name of the actor who initiated the event.
  • Source: initiated_by.name, initiated_by.user_name, initiated_by.username
  • Usage: group_create_provision, jumpcloud_durt_delete, membership_create_provision, membership_delete_provision, service_account_access_granted, service_account_create, service_account_delete, system_create
actor.user.type_id
  • Description: OCSF user type of the actor (1=User, 2=Admin, 3=System, 4=Service).
  • Source: initiated_by.type
  • Transform:
  • initiated_by.type → enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (33 events: application_create, application_delete, application_update, group_delete, group_update, integrationattribute_exclude, integrationattribute_include, invoice_download, ... (+25 more))
  • Usage: 40 events: application_create, application_delete, application_update, association_change, group_create, group_create_provision, group_delete, group_update, ... (+32 more)
actor.user.uid
  • Description: Unique identifier of the actor who initiated the event.
  • Source: initiated_by.id
  • Usage: 35 events: application_create, application_delete, application_update, group_create, group_delete, group_update, integrationattribute_exclude, integrationattribute_include, ... (+27 more)

User

user.name
  • Description: The username. For example, janedoe1.
  • Source: association.connection.to.name, resource.name
  • Usage: association_change, service_account_access_granted, service_account_access_revoked
user.uid
  • Description: Unique identifier of the user associated with the event.
  • Source: association.connection.to.object_id, resource.objectId
  • Usage: association_change, service_account_access_granted, service_account_access_revoked

Entity

entity.data.authConfigList.apiKeyConfig.apiKeyPrefix
  • Description: JumpCloud extension data on the managed entity: authConfigList.apiKeyConfig.apiKeyPrefix.
  • Source: resource.authConfigList.apiKeyConfig.apiKeyPrefix
  • Usage: service_account_auth_config_create, service_account_auth_config_delete, service_account_delete
entity.data.authConfigList.apiKeyConfig.createdAt
  • Description: JumpCloud extension data on the managed entity: authConfigList.apiKeyConfig.createdAt.
  • Source: resource.authConfigList.apiKeyConfig.createdAt
  • Usage: service_account_auth_config_create, service_account_auth_config_delete, service_account_delete
entity.data.authConfigList.apiKeyConfig.expiresAt
  • Description: JumpCloud extension data on the managed entity: authConfigList.apiKeyConfig.expiresAt.
  • Source: resource.authConfigList.apiKeyConfig.expiresAt
  • Usage: service_account_auth_config_create, service_account_auth_config_delete, service_account_delete
entity.data.authConfigList.apiKeyConfig.lifetime
  • Description: JumpCloud extension data on the managed entity: authConfigList.apiKeyConfig.lifetime.
  • Source: resource.authConfigList.apiKeyConfig.lifetime
  • Usage: service_account_auth_config_create, service_account_auth_config_delete, service_account_delete
entity.data.authConfigList.apiKeyConfig.objectId
  • Description: JumpCloud extension data on the managed entity: authConfigList.apiKeyConfig.objectId.
  • Source: resource.authConfigList.apiKeyConfig.objectId
  • Usage: service_account_auth_config_create, service_account_auth_config_delete, service_account_delete
entity.data.authConfigList.apiKeyConfig.status
  • Description: JumpCloud extension data on the managed entity: authConfigList.apiKeyConfig.status.
  • Source: resource.authConfigList.apiKeyConfig.status
  • Usage: service_account_auth_config_create, service_account_auth_config_delete, service_account_delete
entity.data.authConfigList.authType
  • Description: JumpCloud extension data on the managed entity: authConfigList.authType.
  • Source: resource.authConfigList.authType
  • Usage: service_account_auth_config_create, service_account_auth_config_delete, service_account_auth_config_update, service_account_create, service_account_delete
entity.data.authConfigList.clientSecretConfig.clientId
  • Description: JumpCloud extension data on the managed entity: authConfigList.clientSecretConfig.clientId.
  • Source: resource.authConfigList.clientSecretConfig.clientId
  • Usage: service_account_auth_config_create, service_account_auth_config_delete, service_account_auth_config_update, service_account_create, service_account_delete
entity.data.authConfigList.clientSecretConfig.createdAt
  • Description: JumpCloud extension data on the managed entity: authConfigList.clientSecretConfig.createdAt.
  • Source: resource.authConfigList.clientSecretConfig.createdAt
  • Usage: service_account_auth_config_create, service_account_auth_config_delete, service_account_auth_config_update, service_account_create, service_account_delete
entity.data.authConfigList.clientSecretConfig.expiresAt
  • Description: JumpCloud extension data on the managed entity: authConfigList.clientSecretConfig.expiresAt.
  • Source: resource.authConfigList.clientSecretConfig.expiresAt
  • Usage: service_account_auth_config_create, service_account_auth_config_delete, service_account_auth_config_update, service_account_create, service_account_delete
entity.data.authConfigList.clientSecretConfig.lifetime
  • Description: JumpCloud extension data on the managed entity: authConfigList.clientSecretConfig.lifetime.
  • Source: resource.authConfigList.clientSecretConfig.lifetime
  • Usage: service_account_auth_config_create, service_account_auth_config_delete, service_account_auth_config_update, service_account_create, service_account_delete
entity.data.authConfigList.clientSecretConfig.objectId
  • Description: JumpCloud extension data on the managed entity: authConfigList.clientSecretConfig.objectId.
  • Source: resource.authConfigList.clientSecretConfig.objectId
  • Usage: service_account_auth_config_create, service_account_auth_config_delete, service_account_auth_config_update, service_account_create, service_account_delete
entity.data.authConfigList.clientSecretConfig.status
  • Description: JumpCloud extension data on the managed entity: authConfigList.clientSecretConfig.status.
  • Source: resource.authConfigList.clientSecretConfig.status
  • Usage: service_account_auth_config_create, service_account_auth_config_delete, service_account_auth_config_update, service_account_create, service_account_delete
entity.data.auth_method
  • Description: JumpCloud extension data on the managed entity: auth_method.
  • Source: auth_method
  • Usage: 27 events: application_create, application_delete, application_update, group_update, integrationattribute_exclude, integrationattribute_include, jumpcloud_durt_enablement_update, order_create, ... (+19 more)
entity.data.changed_field
  • Description: JumpCloud extension data on the managed entity: changed_field.
  • Source: changes.field
  • Usage: 27 events: application_create, application_delete, application_update, group_update, group_warning, integrationattribute_exclude, integrationattribute_include, jumpcloud_durt_enablement_update, ... (+19 more)
entity.data.changes_from
  • Description: JumpCloud extension data on the managed entity: changes_from.
  • Source: changes.from
  • Usage: 13 events: application_delete, application_update, group_warning, integrationattribute_exclude, jumpcloud_durt_enablement_update, radiusserver_delete, radiusserver_update, role_delete, ... (+5 more)
entity.data.changes_from_allowUnenrolledMFAPasswordReset
  • Description: JumpCloud extension data on the managed entity: changes_from_allowUnenrolledMFAPasswordReset.
  • Source: changes.from.allowUnenrolledMFAPasswordReset
  • Usage: organization_delete
entity.data.changes_from_allowUsernameSubstring
  • Description: JumpCloud extension data on the managed entity: changes_from_allowUsernameSubstring.
  • Source: changes.from.allowUsernameSubstring
  • Usage: organization_delete
entity.data.changes_from_applicationImport
  • Description: JumpCloud extension data on the managed entity: changes_from_applicationImport.
  • Source: changes.from.applicationImport
  • Usage: organization_delete
entity.data.changes_from_cookieExpirationType
  • Description: JumpCloud extension data on the managed entity: changes_from_cookieExpirationType.
  • Source: changes.from.cookieExpirationType
  • Usage: organization_delete
entity.data.changes_from_csvImport
  • Description: JumpCloud extension data on the managed entity: changes_from_csvImport.
  • Source: changes.from.csvImport
  • Usage: organization_delete
entity.data.changes_from_daysAfterExpirationToSelfRecover
  • Description: JumpCloud extension data on the managed entity: changes_from_daysAfterExpirationToSelfRecover.
  • Source: changes.from.daysAfterExpirationToSelfRecover
  • Usage: organization_delete
entity.data.changes_from_daysBeforeExpirationToForceReset
  • Description: JumpCloud extension data on the managed entity: changes_from_daysBeforeExpirationToForceReset.
  • Source: changes.from.daysBeforeExpirationToForceReset
  • Usage: organization_delete
entity.data.changes_from_directoryInsightsPremium_createdAt
  • Description: JumpCloud extension data on the managed entity: changes_from_directoryInsightsPremium_createdAt.
  • Source: changes.from.directoryInsightsPremium.createdAt
  • Usage: organization_delete
entity.data.changes_from_directoryInsightsPremium_enabled
  • Description: JumpCloud extension data on the managed entity: changes_from_directoryInsightsPremium_enabled.
  • Source: changes.from.directoryInsightsPremium.enabled
  • Usage: organization_delete
entity.data.changes_from_directoryInsightsPremium_updatedAt
  • Description: JumpCloud extension data on the managed entity: changes_from_directoryInsightsPremium_updatedAt.
  • Source: changes.from.directoryInsightsPremium.updatedAt
  • Usage: organization_delete
entity.data.changes_from_disallowCommonlyUsedPasswords
  • Description: JumpCloud extension data on the managed entity: changes_from_disallowCommonlyUsedPasswords.
  • Source: changes.from.disallowCommonlyUsedPasswords
  • Usage: organization_delete
entity.data.changes_from_disallowSequentialOrRepetitiveChars
  • Description: JumpCloud extension data on the managed entity: changes_from_disallowSequentialOrRepetitiveChars.
  • Source: changes.from.disallowSequentialOrRepetitiveChars
  • Usage: organization_delete
entity.data.changes_from_effectiveDate
  • Description: JumpCloud extension data on the managed entity: changes_from_effectiveDate.
  • Source: changes.from.effectiveDate
  • Usage: organization_delete
entity.data.changes_from_enableDaysAfterExpirationToSelfRecover
  • Description: JumpCloud extension data on the managed entity: changes_from_enableDaysAfterExpirationToSelfRecover.
  • Source: changes.from.enableDaysAfterExpirationToSelfRecover
  • Usage: organization_delete
entity.data.changes_from_enableDaysBeforeExpirationToForceReset
  • Description: JumpCloud extension data on the managed entity: changes_from_enableDaysBeforeExpirationToForceReset.
  • Source: changes.from.enableDaysBeforeExpirationToForceReset
  • Usage: organization_delete
entity.data.changes_from_enableLockoutTimeInSeconds
  • Description: JumpCloud extension data on the managed entity: changes_from_enableLockoutTimeInSeconds.
  • Source: changes.from.enableLockoutTimeInSeconds
  • Usage: organization_delete
entity.data.changes_from_enableMaxHistory
  • Description: JumpCloud extension data on the managed entity: changes_from_enableMaxHistory.
  • Source: changes.from.enableMaxHistory
  • Usage: organization_delete
entity.data.changes_from_enableMaxLoginAttempts
  • Description: JumpCloud extension data on the managed entity: changes_from_enableMaxLoginAttempts.
  • Source: changes.from.enableMaxLoginAttempts
  • Usage: organization_delete
entity.data.changes_from_enableMinChangePeriodInDays
  • Description: JumpCloud extension data on the managed entity: changes_from_enableMinChangePeriodInDays.
  • Source: changes.from.enableMinChangePeriodInDays
  • Usage: organization_delete
entity.data.changes_from_enableMinLength
  • Description: JumpCloud extension data on the managed entity: changes_from_enableMinLength.
  • Source: changes.from.enableMinLength
  • Usage: organization_delete
entity.data.changes_from_enablePasswordExpirationInDays
  • Description: JumpCloud extension data on the managed entity: changes_from_enablePasswordExpirationInDays.
  • Source: changes.from.enablePasswordExpirationInDays
  • Usage: organization_delete
entity.data.changes_from_enableRecoveryEmail
  • Description: JumpCloud extension data on the managed entity: changes_from_enableRecoveryEmail.
  • Source: changes.from.enableRecoveryEmail
  • Usage: organization_delete
entity.data.changes_from_enableResetLockoutCounter
  • Description: JumpCloud extension data on the managed entity: changes_from_enableResetLockoutCounter.
  • Source: changes.from.enableResetLockoutCounter
  • Usage: organization_delete
entity.data.changes_from_filters_field
  • Description: JumpCloud extension data on the managed entity: changes_from_filters_field.
  • Source: changes.from.filters.field
  • Usage: group_update
entity.data.changes_from_filters_operator
  • Description: JumpCloud extension data on the managed entity: changes_from_filters_operator.
  • Source: changes.from.filters.operator
  • Usage: group_update
entity.data.changes_from_filters_value
  • Description: JumpCloud extension data on the managed entity: changes_from_filters_value.
  • Source: changes.from.filters.value
  • Usage: group_update
entity.data.changes_from_idleSessionDurationMinutes
  • Description: JumpCloud extension data on the managed entity: changes_from_idleSessionDurationMinutes.
  • Source: changes.from.idleSessionDurationMinutes
  • Usage: organization_delete
entity.data.changes_from_ldapGroups_name
  • Description: JumpCloud extension data on the managed entity: changes_from_ldapGroups_name.
  • Source: changes.from.ldapGroups.name
  • Usage: group_update
entity.data.changes_from_lockoutTimeInSeconds
  • Description: JumpCloud extension data on the managed entity: changes_from_lockoutTimeInSeconds.
  • Source: changes.from.lockoutTimeInSeconds
  • Usage: organization_delete
entity.data.changes_from_manualEntry
  • Description: JumpCloud extension data on the managed entity: changes_from_manualEntry.
  • Source: changes.from.manualEntry
  • Usage: organization_delete
entity.data.changes_from_maxHistory
  • Description: JumpCloud extension data on the managed entity: changes_from_maxHistory.
  • Source: changes.from.maxHistory
  • Usage: organization_delete
entity.data.changes_from_maxLoginAttempts
  • Description: JumpCloud extension data on the managed entity: changes_from_maxLoginAttempts.
  • Source: changes.from.maxLoginAttempts
  • Usage: organization_delete
entity.data.changes_from_minChangePeriodInDays
  • Description: JumpCloud extension data on the managed entity: changes_from_minChangePeriodInDays.
  • Source: changes.from.minChangePeriodInDays
  • Usage: organization_delete
entity.data.changes_from_minLength
  • Description: JumpCloud extension data on the managed entity: changes_from_minLength.
  • Source: changes.from.minLength
  • Usage: organization_delete
entity.data.changes_from_needsLowercase
  • Description: JumpCloud extension data on the managed entity: changes_from_needsLowercase.
  • Source: changes.from.needsLowercase
  • Usage: organization_delete
entity.data.changes_from_needsNumeric
  • Description: JumpCloud extension data on the managed entity: changes_from_needsNumeric.
  • Source: changes.from.needsNumeric
  • Usage: organization_delete
entity.data.changes_from_needsSymbolic
  • Description: JumpCloud extension data on the managed entity: changes_from_needsSymbolic.
  • Source: changes.from.needsSymbolic
  • Usage: organization_delete
entity.data.changes_from_needsUppercase
  • Description: JumpCloud extension data on the managed entity: changes_from_needsUppercase.
  • Source: changes.from.needsUppercase
  • Usage: organization_delete
entity.data.changes_from_passwordExpirationInDays
  • Description: JumpCloud extension data on the managed entity: changes_from_passwordExpirationInDays.
  • Source: changes.from.passwordExpirationInDays
  • Usage: organization_delete
entity.data.changes_from_queryType
  • Description: JumpCloud extension data on the managed entity: changes_from_queryType.
  • Source: changes.from.queryType
  • Usage: group_update
entity.data.changes_from_radius_reply_name
  • Description: JumpCloud extension data on the managed entity: changes_from_radius_reply_name.
  • Source: changes.from.radius.reply.name
  • Usage: group_update
entity.data.changes_from_radius_reply_value
  • Description: JumpCloud extension data on the managed entity: changes_from_radius_reply_value.
  • Source: changes.from.radius.reply.value
  • Usage: group_update
entity.data.changes_from_resetLockoutCounterMinutes
  • Description: JumpCloud extension data on the managed entity: changes_from_resetLockoutCounterMinutes.
  • Source: changes.from.resetLockoutCounterMinutes
  • Usage: organization_delete
entity.data.changes_from_searchFilters
  • Description: JumpCloud extension data on the managed entity: changes_from_searchFilters.
  • Source: changes.from.searchFilters
  • Usage: group_update
entity.data.changes_from_systemInsights_createdAt
  • Description: JumpCloud extension data on the managed entity: changes_from_systemInsights_createdAt.
  • Source: changes.from.systemInsights.createdAt
  • Usage: organization_delete
entity.data.changes_from_systemInsights_enableNewDarwin
  • Description: JumpCloud extension data on the managed entity: changes_from_systemInsights_enableNewDarwin.
  • Source: changes.from.systemInsights.enableNewDarwin
  • Usage: organization_delete
entity.data.changes_from_systemInsights_enableNewLinux
  • Description: JumpCloud extension data on the managed entity: changes_from_systemInsights_enableNewLinux.
  • Source: changes.from.systemInsights.enableNewLinux
  • Usage: organization_delete
entity.data.changes_from_systemInsights_enableNewWindows
  • Description: JumpCloud extension data on the managed entity: changes_from_systemInsights_enableNewWindows.
  • Source: changes.from.systemInsights.enableNewWindows
  • Usage: organization_delete
entity.data.changes_from_systemInsights_enabled
  • Description: JumpCloud extension data on the managed entity: changes_from_systemInsights_enabled.
  • Source: changes.from.systemInsights.enabled
  • Usage: organization_delete
entity.data.changes_from_systemInsights_updatedAt
  • Description: JumpCloud extension data on the managed entity: changes_from_systemInsights_updatedAt.
  • Source: changes.from.systemInsights.updatedAt
  • Usage: organization_delete
entity.data.correlation_id
  • Description: JumpCloud extension data on the managed entity: correlation_id.
  • Source: correlation.id
  • Usage: scheduled_import_job_create, scheduled_import_job_delete
entity.data.correlation_type
  • Description: JumpCloud extension data on the managed entity: correlation_type.
  • Source: correlation.type
  • Usage: scheduled_import_job_create, scheduled_import_job_delete
entity.data.createdAt
  • Description: JumpCloud extension data on the managed entity: createdAt.
  • Source: resource.createdAt
  • Usage: service_account_auth_config_create, service_account_auth_config_delete, service_account_auth_config_update, service_account_create, service_account_delete
entity.data.credential_id
  • Description: JumpCloud extension data on the managed entity: credential_id.
  • Source: resource.deleted_credentials.credential_id
  • Usage: jumpcloud_durt_delete
entity.data.credential_os
  • Description: JumpCloud extension data on the managed entity: credential_os.
  • Source: resource.deleted_credentials.os
  • Usage: jumpcloud_durt_delete
entity.data.device_name
  • Description: JumpCloud extension data on the managed entity: device_name.
  • Source: resource.name
  • Usage: system_create
entity.data.direction
  • Description: JumpCloud extension data on the managed entity: direction.
  • Source: resource.direction
  • Usage: integrationattribute_exclude, integrationattribute_include
entity.data.display_label
  • Description: JumpCloud extension data on the managed entity: display_label.
  • Source: resource.displayLabel
  • Usage: application_create, application_delete, application_update
entity.data.enrollment_type
  • Description: JumpCloud extension data on the managed entity: enrollment_type.
  • Source: resource.enrollment_type
  • Usage: jumpcloud_durt_registration, system_create
entity.data.management_mode
  • Description: JumpCloud extension data on the managed entity: management_mode.
  • Source: resource.management_mode
  • Usage: system_create
entity.data.mdm_vendor
  • Description: JumpCloud extension data on the managed entity: mdm_vendor.
  • Source: resource.mdm_vendor
  • Usage: jumpcloud_durt_registration
entity.data.orgId
  • Description: JumpCloud extension data on the managed entity: orgId.
  • Source: resource.orgId
  • Usage: service_account_auth_config_create, service_account_auth_config_delete, service_account_auth_config_update
entity.data.ownership_type
  • Description: JumpCloud extension data on the managed entity: ownership_type.
  • Source: resource.ownership_type
  • Usage: system_create
entity.data.providerId
  • Description: JumpCloud extension data on the managed entity: providerId.
  • Source: resource.providerId
  • Usage: service_account_auth_config_create, service_account_auth_config_delete, service_account_auth_config_update
entity.data.reason
  • Description: JumpCloud extension data on the managed entity: reason.
  • Source: resource.reason
  • Usage: jumpcloud_durt_delete
entity.data.roleId
  • Description: JumpCloud extension data on the managed entity: roleId.
  • Source: resource.roleId
  • Usage: service_account_auth_config_create, service_account_auth_config_delete, service_account_auth_config_update, service_account_create, service_account_delete
entity.data.roleName
  • Description: JumpCloud extension data on the managed entity: roleName.
  • Source: resource.roleName
  • Usage: service_account_auth_config_create, service_account_auth_config_delete, service_account_auth_config_update, service_account_create, service_account_delete
entity.data.scheduled_job_id
  • Description: JumpCloud extension data on the managed entity: scheduled_job_id.
  • Source: changes.delete.scheduled_job_id
  • Usage: scheduled_import_job_delete
entity.data.slug
  • Description: JumpCloud extension data on the managed entity: slug.
  • Source: resource.name
  • Usage: application_create, application_delete, application_update
entity.data.subscription_productCode
  • Description: JumpCloud extension data on the managed entity: subscription_productCode.
  • Source: resource.subscription.productCode
  • Usage: order_create
entity.data.system_user_id
  • Description: JumpCloud extension data on the managed entity: system_user_id.
  • Source: resource.deleted_credentials.system_user_id
  • Usage: jumpcloud_durt_delete
entity.device.hostname
  • Description: The device hostname.
  • Source: resource.hostname
  • Usage: system_create, system_delete, system_update
entity.device.os.type
  • Description: The type of the operating system.
  • Source: system.osFamily
  • Usage: system_create
entity.device.os.version
  • Description: The version of the OS running on the device that originated the event. For example: "Windows 10", "OS X 10.7", or "iOS 9".
  • Source: system.osVersion
  • Usage: system_create
entity.device.uid
  • Description: The unique identifier of the device. For example the Windows TargetSID or AWS EC2 ARN.
  • Source: resource.deleted_credentials.system_id, resource.id, system.id
  • Usage: jumpcloud_durt_delete, jumpcloud_durt_registration, system_create, system_delete, system_update
entity.name
  • Description: The name of the managed entity. It should match the name of the specific entity object's name if populated, or the name of the managed entity if the type_id is 'Other'.
  • Source: resource.displayName, resource.name, system.displayName
  • Usage: 23 events: application_create, application_delete, application_update, group_update, group_warning, organization_create, organization_delete, organization_update, ... (+15 more)
entity.type
  • Description: The managed entity type. For example: Policy, User, Organization, Device.
  • Source: resource.type
  • Usage: 29 events: application_create, application_delete, application_update, group_update, group_warning, integrationattribute_exclude, integrationattribute_include, invoice_download, ... (+21 more)
entity.uid
  • Description: The identifier of the managed entity. It should match the uid of the specific entity's object UID if populated, or the source specific ID if the type_id is 'Other'.
  • Source: resource.account_object_id, resource.id, resource.objectId
  • Usage: 28 events: application_create, application_delete, application_update, group_update, group_warning, integrationattribute_exclude, integrationattribute_include, invoice_download, ... (+20 more)
entity_result.data.changes_to
  • Description: JumpCloud extension data on the managed entity: changes_to.
  • Source: changes.to
  • Usage: 16 events: application_create, application_update, group_warning, integrationattribute_exclude, integrationattribute_include, jumpcloud_durt_enablement_update, provider_create, radius_radsec_certificate_upload, ... (+8 more)
entity_result.data.changes_to_allowUnenrolledMFAPasswordReset
  • Description: JumpCloud extension data on the managed entity: changes_to_allowUnenrolledMFAPasswordReset.
  • Source: changes.to.allowUnenrolledMFAPasswordReset
  • Usage: organization_create, organization_update
entity_result.data.changes_to_allowUsernameSubstring
  • Description: JumpCloud extension data on the managed entity: changes_to_allowUsernameSubstring.
  • Source: changes.to.allowUsernameSubstring
  • Usage: organization_create, organization_update
entity_result.data.changes_to_annualPrice
  • Description: JumpCloud extension data on the managed entity: changes_to_annualPrice.
  • Source: changes.to.annualPrice
  • Usage: order_create
entity_result.data.changes_to_applicationImport
  • Description: JumpCloud extension data on the managed entity: changes_to_applicationImport.
  • Source: changes.to.applicationImport
  • Usage: organization_create, organization_update
entity_result.data.changes_to_cookieExpirationType
  • Description: JumpCloud extension data on the managed entity: changes_to_cookieExpirationType.
  • Source: changes.to.cookieExpirationType
  • Usage: organization_create, organization_update
entity_result.data.changes_to_csvImport
  • Description: JumpCloud extension data on the managed entity: changes_to_csvImport.
  • Source: changes.to.csvImport
  • Usage: organization_create, organization_update
entity_result.data.changes_to_daysAfterExpirationToSelfRecover
  • Description: JumpCloud extension data on the managed entity: changes_to_daysAfterExpirationToSelfRecover.
  • Source: changes.to.daysAfterExpirationToSelfRecover
  • Usage: organization_create, organization_update
entity_result.data.changes_to_daysBeforeExpirationToForceReset
  • Description: JumpCloud extension data on the managed entity: changes_to_daysBeforeExpirationToForceReset.
  • Source: changes.to.daysBeforeExpirationToForceReset
  • Usage: organization_create, organization_update
entity_result.data.changes_to_directoryInsightsPremium_createdAt
  • Description: JumpCloud extension data on the managed entity: changes_to_directoryInsightsPremium_createdAt.
  • Source: changes.to.directoryInsightsPremium.createdAt
  • Usage: organization_create, organization_update
entity_result.data.changes_to_directoryInsightsPremium_enabled
  • Description: JumpCloud extension data on the managed entity: changes_to_directoryInsightsPremium_enabled.
  • Source: changes.to.directoryInsightsPremium.enabled
  • Usage: organization_create, organization_update
entity_result.data.changes_to_directoryInsightsPremium_updatedAt
  • Description: JumpCloud extension data on the managed entity: changes_to_directoryInsightsPremium_updatedAt.
  • Source: changes.to.directoryInsightsPremium.updatedAt
  • Usage: organization_create, organization_update
entity_result.data.changes_to_disallowCommonlyUsedPasswords
  • Description: JumpCloud extension data on the managed entity: changes_to_disallowCommonlyUsedPasswords.
  • Source: changes.to.disallowCommonlyUsedPasswords
  • Usage: organization_create, organization_update
entity_result.data.changes_to_disallowSequentialOrRepetitiveChars
  • Description: JumpCloud extension data on the managed entity: changes_to_disallowSequentialOrRepetitiveChars.
  • Source: changes.to.disallowSequentialOrRepetitiveChars
  • Usage: organization_create, organization_update
entity_result.data.changes_to_effectiveDate
  • Description: JumpCloud extension data on the managed entity: changes_to_effectiveDate.
  • Source: changes.to.effectiveDate
  • Usage: organization_create, organization_update
entity_result.data.changes_to_enableDaysAfterExpirationToSelfRecover
  • Description: JumpCloud extension data on the managed entity: changes_to_enableDaysAfterExpirationToSelfRecover.
  • Source: changes.to.enableDaysAfterExpirationToSelfRecover
  • Usage: organization_create, organization_update
entity_result.data.changes_to_enableDaysBeforeExpirationToForceReset
  • Description: JumpCloud extension data on the managed entity: changes_to_enableDaysBeforeExpirationToForceReset.
  • Source: changes.to.enableDaysBeforeExpirationToForceReset
  • Usage: organization_create, organization_update
entity_result.data.changes_to_enableLockoutTimeInSeconds
  • Description: JumpCloud extension data on the managed entity: changes_to_enableLockoutTimeInSeconds.
  • Source: changes.to.enableLockoutTimeInSeconds
  • Usage: organization_create, organization_update
entity_result.data.changes_to_enableMaxHistory
  • Description: JumpCloud extension data on the managed entity: changes_to_enableMaxHistory.
  • Source: changes.to.enableMaxHistory
  • Usage: organization_create, organization_update
entity_result.data.changes_to_enableMaxLoginAttempts
  • Description: JumpCloud extension data on the managed entity: changes_to_enableMaxLoginAttempts.
  • Source: changes.to.enableMaxLoginAttempts
  • Usage: organization_create, organization_update
entity_result.data.changes_to_enableMinChangePeriodInDays
  • Description: JumpCloud extension data on the managed entity: changes_to_enableMinChangePeriodInDays.
  • Source: changes.to.enableMinChangePeriodInDays
  • Usage: organization_create, organization_update
entity_result.data.changes_to_enableMinLength
  • Description: JumpCloud extension data on the managed entity: changes_to_enableMinLength.
  • Source: changes.to.enableMinLength
  • Usage: organization_create, organization_update
entity_result.data.changes_to_enablePasswordExpirationInDays
  • Description: JumpCloud extension data on the managed entity: changes_to_enablePasswordExpirationInDays.
  • Source: changes.to.enablePasswordExpirationInDays
  • Usage: organization_create, organization_update
entity_result.data.changes_to_enableRecoveryEmail
  • Description: JumpCloud extension data on the managed entity: changes_to_enableRecoveryEmail.
  • Source: changes.to.enableRecoveryEmail
  • Usage: organization_create, organization_update
entity_result.data.changes_to_enableResetLockoutCounter
  • Description: JumpCloud extension data on the managed entity: changes_to_enableResetLockoutCounter.
  • Source: changes.to.enableResetLockoutCounter
  • Usage: organization_create, organization_update
entity_result.data.changes_to_features
  • Description: JumpCloud extension data on the managed entity: changes_to_features.
  • Source: changes.to.features
  • Usage: order_create
entity_result.data.changes_to_filters
  • Description: JumpCloud extension data on the managed entity: changes_to_filters.
  • Source: changes.to.filters
  • Usage: group_update
entity_result.data.changes_to_idleSessionDurationMinutes
  • Description: JumpCloud extension data on the managed entity: changes_to_idleSessionDurationMinutes.
  • Source: changes.to.idleSessionDurationMinutes
  • Usage: organization_create, organization_update
entity_result.data.changes_to_ldapGroups_name
  • Description: JumpCloud extension data on the managed entity: changes_to_ldapGroups_name.
  • Source: changes.to.ldapGroups.name
  • Usage: group_update
entity_result.data.changes_to_ldap_groups_name
  • Description: JumpCloud extension data on the managed entity: changes_to_ldap_groups_name.
  • Source: changes.to.ldap_groups.name
  • Usage: group_update
entity_result.data.changes_to_listPrice
  • Description: JumpCloud extension data on the managed entity: changes_to_listPrice.
  • Source: changes.to.listPrice
  • Usage: order_create
entity_result.data.changes_to_lockoutTimeInSeconds
  • Description: JumpCloud extension data on the managed entity: changes_to_lockoutTimeInSeconds.
  • Source: changes.to.lockoutTimeInSeconds
  • Usage: organization_create, organization_update
entity_result.data.changes_to_manualEntry
  • Description: JumpCloud extension data on the managed entity: changes_to_manualEntry.
  • Source: changes.to.manualEntry
  • Usage: organization_create, organization_update
entity_result.data.changes_to_maxHistory
  • Description: JumpCloud extension data on the managed entity: changes_to_maxHistory.
  • Source: changes.to.maxHistory
  • Usage: organization_create, organization_update
entity_result.data.changes_to_maxLoginAttempts
  • Description: JumpCloud extension data on the managed entity: changes_to_maxLoginAttempts.
  • Source: changes.to.maxLoginAttempts
  • Usage: organization_create, organization_update
entity_result.data.changes_to_minChangePeriodInDays
  • Description: JumpCloud extension data on the managed entity: changes_to_minChangePeriodInDays.
  • Source: changes.to.minChangePeriodInDays
  • Usage: organization_create, organization_update
entity_result.data.changes_to_minLength
  • Description: JumpCloud extension data on the managed entity: changes_to_minLength.
  • Source: changes.to.minLength
  • Usage: organization_create, organization_update
entity_result.data.changes_to_needsLowercase
  • Description: JumpCloud extension data on the managed entity: changes_to_needsLowercase.
  • Source: changes.to.needsLowercase
  • Usage: organization_create, organization_update
entity_result.data.changes_to_needsNumeric
  • Description: JumpCloud extension data on the managed entity: changes_to_needsNumeric.
  • Source: changes.to.needsNumeric
  • Usage: organization_create, organization_update
entity_result.data.changes_to_needsSymbolic
  • Description: JumpCloud extension data on the managed entity: changes_to_needsSymbolic.
  • Source: changes.to.needsSymbolic
  • Usage: organization_create, organization_update
entity_result.data.changes_to_needsUppercase
  • Description: JumpCloud extension data on the managed entity: changes_to_needsUppercase.
  • Source: changes.to.needsUppercase
  • Usage: organization_create, organization_update
entity_result.data.changes_to_oneTimePrice
  • Description: JumpCloud extension data on the managed entity: changes_to_oneTimePrice.
  • Source: changes.to.oneTimePrice
  • Usage: order_create
entity_result.data.changes_to_passwordExpirationInDays
  • Description: JumpCloud extension data on the managed entity: changes_to_passwordExpirationInDays.
  • Source: changes.to.passwordExpirationInDays
  • Usage: organization_create, organization_update
entity_result.data.changes_to_posix_groups
  • Description: JumpCloud extension data on the managed entity: changes_to_posix_groups.
  • Source: changes.to.posix_groups
  • Usage: group_update
entity_result.data.changes_to_productCode
  • Description: JumpCloud extension data on the managed entity: changes_to_productCode.
  • Source: changes.to.productCode
  • Usage: order_create
entity_result.data.changes_to_queryType
  • Description: JumpCloud extension data on the managed entity: changes_to_queryType.
  • Source: changes.to.queryType
  • Usage: group_update
entity_result.data.changes_to_radius_reply_name
  • Description: JumpCloud extension data on the managed entity: changes_to_radius_reply_name.
  • Source: changes.to.radius.reply.name
  • Usage: group_update
entity_result.data.changes_to_radius_reply_tempId
  • Description: JumpCloud extension data on the managed entity: changes_to_radius_reply_tempId.
  • Source: changes.to.radius.reply.tempId
  • Usage: group_update
entity_result.data.changes_to_radius_reply_value
  • Description: JumpCloud extension data on the managed entity: changes_to_radius_reply_value.
  • Source: changes.to.radius.reply.value
  • Usage: group_update
entity_result.data.changes_to_resetLockoutCounterMinutes
  • Description: JumpCloud extension data on the managed entity: changes_to_resetLockoutCounterMinutes.
  • Source: changes.to.resetLockoutCounterMinutes
  • Usage: organization_create, organization_update
entity_result.data.changes_to_sambaEnabled
  • Description: JumpCloud extension data on the managed entity: changes_to_sambaEnabled.
  • Source: changes.to.sambaEnabled
  • Usage: group_update
entity_result.data.changes_to_samba_enabled
  • Description: JumpCloud extension data on the managed entity: changes_to_samba_enabled.
  • Source: changes.to.samba_enabled
  • Usage: group_update
entity_result.data.changes_to_searchFilters
  • Description: JumpCloud extension data on the managed entity: changes_to_searchFilters.
  • Source: changes.to.searchFilters
  • Usage: group_update
entity_result.data.changes_to_sudo
  • Description: JumpCloud extension data on the managed entity: changes_to_sudo.
  • Source: changes.to.sudo
  • Usage: group_update
entity_result.data.changes_to_systemInsights_createdAt
  • Description: JumpCloud extension data on the managed entity: changes_to_systemInsights_createdAt.
  • Source: changes.to.systemInsights.createdAt
  • Usage: organization_create, organization_update
entity_result.data.changes_to_systemInsights_enableNewDarwin
  • Description: JumpCloud extension data on the managed entity: changes_to_systemInsights_enableNewDarwin.
  • Source: changes.to.systemInsights.enableNewDarwin
  • Usage: organization_create, organization_update
entity_result.data.changes_to_systemInsights_enableNewLinux
  • Description: JumpCloud extension data on the managed entity: changes_to_systemInsights_enableNewLinux.
  • Source: changes.to.systemInsights.enableNewLinux
  • Usage: organization_create, organization_update
entity_result.data.changes_to_systemInsights_enableNewWindows
  • Description: JumpCloud extension data on the managed entity: changes_to_systemInsights_enableNewWindows.
  • Source: changes.to.systemInsights.enableNewWindows
  • Usage: organization_create, organization_update
entity_result.data.changes_to_systemInsights_enabled
  • Description: JumpCloud extension data on the managed entity: changes_to_systemInsights_enabled.
  • Source: changes.to.systemInsights.enabled
  • Usage: organization_create, organization_update
entity_result.data.changes_to_systemInsights_updatedAt
  • Description: JumpCloud extension data on the managed entity: changes_to_systemInsights_updatedAt.
  • Source: changes.to.systemInsights.updatedAt
  • Usage: organization_create, organization_update
entity_result.data.scheduled_job_id
  • Description: JumpCloud extension data on the managed entity: scheduled_job_id.
  • Source: changes.add.scheduled_job_id
  • Usage: scheduled_import_job_create

Src Endpoint

src_endpoint.autonomous_system.name
  • Description: Organization name for the Autonomous System.
  • Source: asn.organization
  • Usage: 15 events: jumpcloud_durt_delete, order_create, provider_create, radius_radsec_certificate_upload, scheduled_import_job_create, scheduled_import_job_delete, service_account_access_granted, service_account_access_revoked, ... (+7 more)
src_endpoint.autonomous_system.number
  • Description: Unique number that the AS is identified by.
  • Source: asn.number
  • Transform:
  • asn.number → int (15 events: jumpcloud_durt_delete, order_create, provider_create, radius_radsec_certificate_upload, scheduled_import_job_create, scheduled_import_job_delete, service_account_access_granted, service_account_access_revoked, ... (+7 more))
  • Usage: 15 events: jumpcloud_durt_delete, order_create, provider_create, radius_radsec_certificate_upload, scheduled_import_job_create, scheduled_import_job_delete, service_account_access_granted, service_account_access_revoked, ... (+7 more)
src_endpoint.ip
  • Description: Source IP address the request originated from.
  • Source: client_ip
  • Usage: 42 events (missing: association_change, jumpcloud_durt_enablement_update, jumpcloud_durt_registration, organization_delete)
src_endpoint.location.city
  • Description: The name of the city.
  • Source: geoip.city
  • Usage: 20 events: application_delete, group_delete, integrationattribute_exclude, invoice_download, jumpcloud_durt_delete, order_create, provider_create, radius_radsec_certificate_upload, ... (+12 more)
src_endpoint.location.continent
  • Description: The name of the continent.
  • Source: geoip.continent_code
  • Usage: 32 events: application_create, application_delete, application_update, group_create, group_delete, group_update, integrationattribute_exclude, integrationattribute_include, ... (+24 more)
src_endpoint.location.country
  • Description: The ISO 3166-1 Alpha-2 country code.

    Note: The two letter country code should be capitalized. For example: US or CA.

  • Source: geoip.country_code
  • Usage: 32 events: application_create, application_delete, application_update, group_create, group_delete, group_update, integrationattribute_exclude, integrationattribute_include, ... (+24 more)
src_endpoint.location.lat
  • Description: The geographical Latitude coordinate represented in Decimal Degrees (DD). For example: 42.361145.
  • Source: geoip.latitude
  • Transform:
  • geoip.latitude → double (32 events: application_create, application_delete, application_update, group_create, group_delete, group_update, integrationattribute_exclude, integrationattribute_include, ... (+24 more))
  • Usage: 32 events: application_create, application_delete, application_update, group_create, group_delete, group_update, integrationattribute_exclude, integrationattribute_include, ... (+24 more)
src_endpoint.location.long
  • Description: The geographical Longitude coordinate represented in Decimal Degrees (DD). For example: -71.057083.
  • Source: geoip.longitude
  • Transform:
  • geoip.longitude → double (32 events: application_create, application_delete, application_update, group_create, group_delete, group_update, integrationattribute_exclude, integrationattribute_include, ... (+24 more))
  • Usage: 32 events: application_create, application_delete, application_update, group_create, group_delete, group_update, integrationattribute_exclude, integrationattribute_include, ... (+24 more)
src_endpoint.location.region
  • Description: The alphanumeric code that identifies the principal subdivision (e.g. province or state) of the country. For example, 'CH-VD' for the Canton of Vaud, Switzerland
  • Source: geoip.region_code
  • Usage: 30 events: application_create, application_delete, application_update, group_create, group_delete, group_update, integrationattribute_exclude, integrationattribute_include, ... (+22 more)

Http Request

http_request.user_agent
  • Description: The request header that identifies the operating system and web browser.
  • Source: user_agent
  • Usage: 28 events: group_create_provision, group_delete, group_delete_provision, group_update_provision, group_warning, integrationattribute_exclude, jumpcloud_durt_delete, jumpcloud_durt_registration, ... (+20 more)

Observables

observables[].name
  • Description: The full name of the observable attribute. The name is a pointer/reference to an attribute within the OCSF event data. For example: file.name. Array attributes may be represented in one of three ways. For example: resources.uid, resources[].uid, resources[0].uid.
  • Literal: actor.user.email_addr, actor.user.name, actor.user.uid, entity.device.hostname, entity.device.uid, group.name, group.uid, http_request.user_agent, resource.uid, src_endpoint.ip, src_endpoint.location.country, subgroup.name, subgroup.uid, user.name, user.uid
  • Usage: 45 events (missing: organization_delete)
observables[].type_id
  • Description: The observable value type identifier.
  • Literal: 1, 10, 14, 16, 2, 31, 32, 33, 4, 47, 5
  • Usage: 45 events (missing: organization_delete)
observables[].value
  • Description: The value associated with the observable attribute. The meaning of the value depends on the observable type.
    If the name refers to a scalar attribute, then the value is the value of the attribute.
    If the name refers to an object attribute, then the value is not populated.
  • Source: association.connection.from.name, association.connection.from.object_id, association.connection.to.name, association.connection.to.object_id, changes.organizationId, client_ip, geoip.country_code, initiated_by.email, initiated_by.id, initiated_by.name, initiated_by.user_name, initiated_by.username, resource.deleted_credentials.system_id, resource.hostname, resource.id, resource.name, resource.objectId, system.id, system_group.id, system_group.name, user_agent
  • Usage: 45 events (missing: organization_delete)

Resources

resources.type
  • Description: The resource type as defined by the event source.
  • Source: resource.type
  • Usage: group_create_provision, group_delete_provision, group_update_provision, membership_create_provision, membership_delete_provision

Other

action
  • Description: The normalized caption of action_id.
  • Source: association.op
  • Usage: association_change
group.name
  • Description: The group name.
  • Source: association.connection.from.name, resource.name
  • Usage: association_change, group_create, group_delete, user_group_admin_grant, user_group_admin_revoke
group.type
  • Description: The type of the group.
  • Source: association.connection.from.type, resource.type
  • Usage: association_change, group_create, group_delete, user_group_admin_grant, user_group_admin_revoke
group.uid
  • Description: The unique identifier of the group. For example, for Windows events this is the security identifier (SID) of the group. Another example, pool id or desktop id that the device belongs to.
  • Source: association.connection.from.object_id, resource.id
  • Usage: association_change, group_create, group_delete, user_group_admin_grant, user_group_admin_revoke
resource.uid
  • Description: The unique identifier of the resource.
  • Source: changes.organizationId
  • Usage: service_account_access_granted, service_account_access_revoked
subgroup.name
  • Description: The group name.
  • Source: system_group.name
  • Usage: user_group_admin_grant, user_group_admin_revoke
subgroup.type
  • Description: The type of the group.
  • Source: system_group.type
  • Usage: user_group_admin_grant, user_group_admin_revoke
subgroup.uid
  • Description: The unique identifier of the group. For example, for Windows events this is the security identifier (SID) of the group. Another example, pool id or desktop id that the device belongs to.
  • Source: system_group.id
  • Usage: user_group_admin_grant, user_group_admin_revoke

Unmapped

unmapped.@timestamp
  • Description: JumpCloud Directory Insights field @timestamp preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: @timestamp
  • Usage: 18 events: application_create, application_delete, application_update, association_change, group_create, group_delete, group_update, integrationattribute_exclude, ... (+10 more)
unmapped.@version
  • Description: JumpCloud Directory Insights field @version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: @version
  • Usage: all events in this service
unmapped.application_id
  • Description: JumpCloud Directory Insights field application_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: application.id
  • Usage: group_create_provision, membership_create_provision, membership_delete_provision
unmapped.application_id_hash
  • Description: JumpCloud Directory Insights field application_id_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: application_id_hash
  • Usage: membership_delete_provision
unmapped.application_name
  • Description: JumpCloud Directory Insights field application_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: application.name
  • Usage: group_create_provision, group_delete_provision, group_update_provision, membership_create_provision, membership_delete_provision, scheduled_import_job_create, scheduled_import_job_delete
unmapped.application_type
  • Description: JumpCloud Directory Insights field application_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: application.type
  • Usage: group_create_provision, membership_create_provision, membership_delete_provision
unmapped.asn.error
  • Description: JumpCloud Directory Insights field asn.error preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: asn.error
  • Usage: system_create
unmapped.asn.ip_address
  • Description: JumpCloud Directory Insights field asn.ip_address preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: asn.ip_address
  • Usage: system_create
unmapped.asn.network
  • Description: JumpCloud Directory Insights field asn.network preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: asn.network
  • Usage: 15 events: jumpcloud_durt_delete, order_create, provider_create, radius_radsec_certificate_upload, scheduled_import_job_create, scheduled_import_job_delete, service_account_access_granted, service_account_access_revoked, ... (+7 more)
unmapped.association_action_source
  • Description: JumpCloud Directory Insights field association_action_source preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: association.action_source
  • Usage: association_change
unmapped.association_attributes
  • Description: JumpCloud Directory Insights field association_attributes preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: association.attributes
  • Usage: association_change
unmapped.association_to_type
  • Description: JumpCloud Directory Insights field association_to_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: association.connection.to.type
  • Usage: association_change
unmapped.auth_method
  • Description: JumpCloud Directory Insights field auth_method preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: auth_method
  • Usage: group_create, group_create_provision, group_delete, invoice_download, membership_create_provision, membership_delete_provision, service_account_access_granted, service_account_access_revoked, user_group_admin_grant, user_group_admin_revoke
unmapped.changes
  • Description: JumpCloud Directory Insights field changes preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes
  • Usage: invoice_download
unmapped.changes.from.ldapGroups.name
  • Description: JumpCloud Directory Insights field changes.from.ldapGroups.name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.from.ldapGroups.name
  • Usage: group_delete
unmapped.changes.from.role
  • Description: JumpCloud Directory Insights field changes.from.role preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.from.role
  • Usage: group_delete
unmapped.changes.to.filters
  • Description: JumpCloud Directory Insights field changes.to.filters preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to.filters
  • Usage: group_create
unmapped.changes.to.ldapGroups.name
  • Description: JumpCloud Directory Insights field changes.to.ldapGroups.name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to.ldapGroups.name
  • Usage: group_create
unmapped.changes.to.queryType
  • Description: JumpCloud Directory Insights field changes.to.queryType preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to.queryType
  • Usage: group_create
unmapped.changes_field
  • Description: JumpCloud Directory Insights field changes_field preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.field
  • Usage: group_create, group_delete, user_group_admin_grant, user_group_admin_revoke
unmapped.changes_from
  • Description: JumpCloud Directory Insights field changes_from preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.from
  • Usage: group_delete, user_group_admin_revoke
unmapped.changes_to
  • Description: JumpCloud Directory Insights field changes_to preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to
  • Usage: group_create, user_group_admin_grant, user_group_admin_revoke
unmapped.client_id
  • Description: JumpCloud Directory Insights field client_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: client_id
  • Usage: group_create_provision, group_delete_provision, group_update_provision, membership_create_provision, membership_delete_provision, scheduled_import_job_create, scheduled_import_job_delete
unmapped.client_ip
  • Description: JumpCloud Directory Insights field client_ip preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: client_ip
  • Usage: jumpcloud_durt_registration
unmapped.correlation
  • Description: JumpCloud Directory Insights field correlation preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: correlation
  • Usage: group_create_provision, group_delete_provision, group_update_provision, membership_create_provision, membership_delete_provision
unmapped.file_input_timestamp
  • Description: JumpCloud Directory Insights field file_input_timestamp preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: file_input_timestamp
  • Usage: 18 events: application_create, application_delete, application_update, association_change, group_create, group_delete, group_update, integrationattribute_exclude, ... (+10 more)
unmapped.geoip.region_name
  • Description: JumpCloud Directory Insights field geoip.region_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.region_name
  • Usage: 30 events: application_create, application_delete, application_update, group_create, group_delete, group_update, integrationattribute_exclude, integrationattribute_include, ... (+22 more)
unmapped.geoip.timezone
  • Description: JumpCloud Directory Insights field geoip.timezone preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.timezone
  • Usage: 32 events: application_create, application_delete, application_update, group_create, group_delete, group_update, integrationattribute_exclude, integrationattribute_include, ... (+24 more)
unmapped.initiated_by
  • Description: JumpCloud Directory Insights field initiated_by preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by
  • Usage: group_delete_provision, group_update_provision, scheduled_import_job_create, scheduled_import_job_delete, service_account_auth_config_update
unmapped.initiated_by.provider
  • Description: JumpCloud Directory Insights field initiated_by.provider preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by.provider
  • Usage: group_delete
unmapped.initiated_by.user_id
  • Description: JumpCloud Directory Insights field initiated_by.user_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by.user_id
  • Usage: group_delete
unmapped.initiated_by_email_hash
  • Description: JumpCloud Directory Insights field initiated_by_email_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_email_hash
  • Usage: 25 events: application_delete, group_delete, group_update, integrationattribute_exclude, invoice_download, jumpcloud_durt_delete, jumpcloud_durt_registration, order_create, ... (+17 more)
unmapped.initiated_by_id_hash
  • Description: JumpCloud Directory Insights field initiated_by_id_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_id_hash
  • Usage: 25 events: application_delete, group_delete, group_update, integrationattribute_exclude, invoice_download, jumpcloud_durt_delete, jumpcloud_durt_registration, order_create, ... (+17 more)
unmapped.initiated_by_name_hash
  • Description: JumpCloud Directory Insights field initiated_by_name_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_name_hash
  • Usage: group_create_provision, membership_create_provision, membership_delete_provision, service_account_access_granted, service_account_create, service_account_delete
unmapped.initiated_by_provider
  • Description: JumpCloud Directory Insights field initiated_by_provider preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by.provider
  • Usage: provider_create, user_group_admin_grant
unmapped.initiated_by_source
  • Description: JumpCloud Directory Insights field initiated_by_source preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by.source
  • Usage: group_create_provision, membership_create_provision, membership_delete_provision
unmapped.initiated_by_user_id
  • Description: JumpCloud Directory Insights field initiated_by_user_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by.user_id
  • Usage: invoice_download
unmapped.initiated_by_username_hash
  • Description: JumpCloud Directory Insights field initiated_by_username_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_username_hash
  • Usage: jumpcloud_durt_delete
unmapped.is_out_of_bound
  • Description: JumpCloud Directory Insights field is_out_of_bound preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: is_out_of_bound
  • Usage: 28 events: group_create_provision, group_delete, group_delete_provision, group_update_provision, group_warning, integrationattribute_exclude, jumpcloud_durt_delete, jumpcloud_durt_registration, ... (+20 more)
unmapped.jc_application_name
  • Description: JumpCloud Directory Insights field jc_application_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_application_name
  • Usage: 28 events: group_create_provision, group_delete, group_delete_provision, group_update_provision, group_warning, integrationattribute_exclude, jumpcloud_durt_delete, jumpcloud_durt_registration, ... (+20 more)
unmapped.jc_initiated_by_email
  • Description: JumpCloud Directory Insights field jc_initiated_by_email preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_initiated_by_email
  • Usage: 12 events: group_delete_provision, jumpcloud_durt_delete, jumpcloud_durt_registration, role_delete, scheduled_import_job_create, scheduled_import_job_delete, service_account_auth_config_create, service_account_auth_config_delete, ... (+4 more)
unmapped.jc_initiated_by_id
  • Description: JumpCloud Directory Insights field jc_initiated_by_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_initiated_by_id
  • Usage: group_delete_provision
unmapped.jc_initiated_by_username
  • Description: JumpCloud Directory Insights field jc_initiated_by_username preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_initiated_by_username
  • Usage: 12 events: group_delete_provision, jumpcloud_durt_delete, jumpcloud_durt_registration, role_delete, scheduled_import_job_create, scheduled_import_job_delete, service_account_auth_config_create, service_account_auth_config_delete, ... (+4 more)
unmapped.jc_organization_name
  • Description: JumpCloud Directory Insights field jc_organization_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_organization_name
  • Usage: 12 events: group_delete_provision, jumpcloud_durt_delete, jumpcloud_durt_registration, role_delete, scheduled_import_job_create, scheduled_import_job_delete, service_account_auth_config_create, service_account_auth_config_delete, ... (+4 more)
unmapped.jc_provider_id
  • Description: JumpCloud Directory Insights field jc_provider_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_provider_id
  • Usage: group_delete_provision, jumpcloud_durt_delete, jumpcloud_durt_registration, scheduled_import_job_create, scheduled_import_job_delete, service_account_auth_config_create, service_account_auth_config_delete, service_account_delete, user_group_admin_grant, user_group_admin_revoke
unmapped.jc_system_display_name
  • Description: JumpCloud Directory Insights field jc_system_display_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_system_display_name
  • Usage: group_delete_provision
unmapped.jc_system_hostname
  • Description: JumpCloud Directory Insights field jc_system_hostname preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_system_hostname
  • Usage: group_delete_provision
unmapped.message_chain_message_details
  • Description: JumpCloud Directory Insights field message_chain_message_details preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: message_chain.message_details
  • Usage: group_create_provision, group_delete_provision, group_update_provision, membership_create_provision, membership_delete_provision, scheduled_import_job_create, scheduled_import_job_delete
unmapped.message_chain_response_code
  • Description: JumpCloud Directory Insights field message_chain_response_code preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: message_chain.response_code
  • Usage: group_create_provision, group_delete_provision, group_update_provision, membership_create_provision, membership_delete_provision, scheduled_import_job_create, scheduled_import_job_delete
unmapped.message_chain_response_message
  • Description: JumpCloud Directory Insights field message_chain_response_message preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: message_chain.response_message
  • Usage: group_create_provision, group_delete_provision, group_update_provision, membership_create_provision, membership_delete_provision
unmapped.msp_provider_id
  • Description: JumpCloud Directory Insights field msp_provider_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: provider
  • Usage: 18 events: organization_delete, provider_create, radius_radsec_certificate_upload, radiusserver_create, radiusserver_delete, radiusserver_update, role_create, role_delete, ... (+10 more)
unmapped.provider
  • Description: JumpCloud Directory Insights field provider preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: provider
  • Usage: 14 events: application_create, application_delete, application_update, association_change, group_create, group_delete, group_update, integrationattribute_exclude, ... (+6 more)
unmapped.resource_email
  • Description: JumpCloud Directory Insights field resource_email preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.email
  • Usage: group_create_provision
unmapped.resource_group_email
  • Description: JumpCloud Directory Insights field resource_group_email preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.group_email
  • Usage: membership_create_provision, membership_delete_provision
unmapped.resource_group_id
  • Description: JumpCloud Directory Insights field resource_group_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.group_id
  • Usage: membership_create_provision, membership_delete_provision
unmapped.resource_group_name
  • Description: JumpCloud Directory Insights field resource_group_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.group_name
  • Usage: membership_create_provision, membership_delete_provision
unmapped.resource_id
  • Description: JumpCloud Directory Insights field resource_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.id
  • Usage: group_create_provision, group_delete_provision, group_update_provision
unmapped.resource_id_hash
  • Description: JumpCloud Directory Insights field resource_id_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource_id_hash
  • Usage: 21 events: application_delete, group_create_provision, group_delete, group_delete_provision, group_update, group_update_provision, group_warning, integrationattribute_exclude, ... (+13 more)
unmapped.resource_name
  • Description: JumpCloud Directory Insights field resource_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.name
  • Usage: group_create_provision
unmapped.resource_type
  • Description: JumpCloud Directory Insights field resource_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.type
  • Usage: service_account_access_granted, service_account_access_revoked
unmapped.resource_user_email
  • Description: JumpCloud Directory Insights field resource_user_email preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.user_email
  • Usage: membership_create_provision, membership_delete_provision
unmapped.resource_username
  • Description: JumpCloud Directory Insights field resource_username preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.username
  • Usage: group_create_provision, group_delete_provision, group_update_provision
unmapped.service_account_role_id
  • Description: JumpCloud Directory Insights field service_account_role_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.roleId
  • Usage: service_account_access_granted, service_account_access_revoked
unmapped.service_account_role_name
  • Description: JumpCloud Directory Insights field service_account_role_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.roleName
  • Usage: service_account_access_granted, service_account_access_revoked
unmapped.tags
  • Description: JumpCloud Directory Insights field tags preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: tags
  • Usage: 18 events: application_create, application_delete, application_update, association_change, group_create, group_delete, group_update, integrationattribute_exclude, ... (+10 more)
unmapped.timestamp_source
  • Description: JumpCloud Directory Insights field timestamp_source preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: timestamp_source
  • Usage: 22 events: association_change, group_create_provision, group_delete_provision, group_update_provision, group_warning, jumpcloud_durt_delete, jumpcloud_durt_registration, membership_create_provision, ... (+14 more)
unmapped.useragent.device
  • Description: JumpCloud Directory Insights field useragent.device preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.device
  • Usage: 32 events: application_create, application_delete, application_update, group_create, group_delete, group_update, integrationattribute_exclude, integrationattribute_include, ... (+24 more)
unmapped.useragent.major
  • Description: JumpCloud Directory Insights field useragent.major preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.major
  • Usage: 29 events: application_create, application_delete, application_update, group_create, group_delete, group_update, invoice_download, jumpcloud_durt_delete, ... (+21 more)
unmapped.useragent.minor
  • Description: JumpCloud Directory Insights field useragent.minor preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.minor
  • Usage: 29 events: application_create, application_delete, application_update, group_create, group_delete, group_update, invoice_download, jumpcloud_durt_delete, ... (+21 more)
unmapped.useragent.name
  • Description: JumpCloud Directory Insights field useragent.name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.name
  • Usage: 32 events: application_create, application_delete, application_update, group_create, group_delete, group_update, integrationattribute_exclude, integrationattribute_include, ... (+24 more)
unmapped.useragent.os
  • Description: JumpCloud Directory Insights field useragent.os preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os
  • Usage: 32 events: application_create, application_delete, application_update, group_create, group_delete, group_update, integrationattribute_exclude, integrationattribute_include, ... (+24 more)
unmapped.useragent.os_full
  • Description: JumpCloud Directory Insights field useragent.os_full preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_full
  • Usage: 32 events: application_create, application_delete, application_update, group_create, group_delete, group_update, integrationattribute_exclude, integrationattribute_include, ... (+24 more)
unmapped.useragent.os_major
  • Description: JumpCloud Directory Insights field useragent.os_major preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_major
  • Usage: 17 events: group_delete, group_update, invoice_download, jumpcloud_durt_delete, order_create, provider_create, radius_radsec_certificate_upload, scheduled_import_job_create, ... (+9 more)
unmapped.useragent.os_minor
  • Description: JumpCloud Directory Insights field useragent.os_minor preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_minor
  • Usage: 17 events: group_delete, group_update, invoice_download, jumpcloud_durt_delete, order_create, provider_create, radius_radsec_certificate_upload, scheduled_import_job_create, ... (+9 more)
unmapped.useragent.os_name
  • Description: JumpCloud Directory Insights field useragent.os_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_name
  • Usage: 32 events: application_create, application_delete, application_update, group_create, group_delete, group_update, integrationattribute_exclude, integrationattribute_include, ... (+24 more)
unmapped.useragent.os_patch
  • Description: JumpCloud Directory Insights field useragent.os_patch preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_patch
  • Usage: 17 events: group_delete, group_update, invoice_download, jumpcloud_durt_delete, order_create, provider_create, radius_radsec_certificate_upload, scheduled_import_job_create, ... (+9 more)
unmapped.useragent.os_version
  • Description: JumpCloud Directory Insights field useragent.os_version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_version
  • Usage: 17 events: group_delete, group_update, invoice_download, jumpcloud_durt_delete, order_create, provider_create, radius_radsec_certificate_upload, scheduled_import_job_create, ... (+9 more)
unmapped.useragent.patch
  • Description: JumpCloud Directory Insights field useragent.patch preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.patch
  • Usage: 20 events: application_create, application_delete, group_delete, group_update, invoice_download, jumpcloud_durt_delete, order_create, provider_create, ... (+12 more)
unmapped.useragent.version
  • Description: JumpCloud Directory Insights field useragent.version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.version
  • Usage: 29 events: application_create, application_delete, application_update, group_create, group_delete, group_update, invoice_download, jumpcloud_durt_delete, ... (+21 more)

Directory — User and Admin Events#

directory_user_admin · 98 events

Event Category Class Activity Type UID Fields
admin_access_granted Identity & Access Management (3) User Access Management (3005) Assign Privileges (1) 300501 61
admin_access_revoked Identity & Access Management (3) User Access Management (3005) Revoke Privileges (2) 300502 66
admin_apikey_created Identity & Access Management (3) Entity Management (3004) Create (1) 300401 46
admin_apikey_expired Identity & Access Management (3) Entity Management (3004) Deactivate (11) 300411 36
admin_apikey_expiring_soon Identity & Access Management (3) Entity Management (3004) Read (2) 300402 35
admin_apikey_revoked Identity & Access Management (3) Entity Management (3004) Disable (9) 300409 54
admin_create Identity & Access Management (3) Account Change (3001) Create (1) 300101 47
admin_delete Identity & Access Management (3) Account Change (3001) Delete (6) 300106 63
admin_login_attempt Identity & Access Management (3) Authentication (3002) Logon (1) 300201 49
admin_old_api_key_attempt Identity & Access Management (3) Authentication (3002) Logon (1) 300201 52
admin_password_change Identity & Access Management (3) Account Change (3001) Password Change (3) 300103 58
admin_password_reset_request Identity & Access Management (3) Account Change (3001) Password Reset (4) 300104 58
admin_password_set Identity & Access Management (3) Account Change (3001) Password Change (3) 300103 59
admin_role_granted Identity & Access Management (3) User Access Management (3005) Assign Privileges (1) 300501 64
admin_role_revoked Identity & Access Management (3) User Access Management (3005) Revoke Privileges (2) 300502 64
admin_totp_disable Identity & Access Management (3) Account Change (3001) MFA Factor Disable (11) 300111 62
admin_totp_finish_enrollment Identity & Access Management (3) Account Change (3001) MFA Factor Enable (10) 300110 57
admin_totp_start_enrollment Identity & Access Management (3) Account Change (3001) MFA Factor Enable (10) 300110 57
admin_update Identity & Access Management (3) Account Change (3001) Other (99) 300199 48
feature_settings_change Identity & Access Management (3) Entity Management (3004) Update (3) 300403 61
jumpcloud_protect_device_activation Identity & Access Management (3) Entity Management (3004) Activate (10) 300410 70
jumpcloud_protect_device_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 79
jumpcloud_protect_device_enrollment Identity & Access Management (3) Entity Management (3004) Enroll (6) 300406 74
jumpcloud_protect_device_push_verification Identity & Access Management (3) Authentication (3002) Other (99) 300299 67
jumpcloud_protect_device_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 70
minimum_mfa_compliance_state_changed Identity & Access Management (3) Entity Management (3004) Update (3) 300403 62
minimum_mfa_policy_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 63
minimum_mfa_policy_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 66
nli_settings_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 47
push_configuration_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 65
push_mfa_attempt_failed Identity & Access Management (3) Authentication (3002) Logon (1) 300201 42
registered_mobile_secret_generated Identity & Access Management (3) Entity Management (3004) Create (1) 300401 51
registered_mobile_secret_revoked Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 51
registered_mobile_secret_rotated Identity & Access Management (3) Entity Management (3004) Update (3) 300403 52
sms_configuration_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 66
sms_otp_delete_enrollment Identity & Access Management (3) Entity Management (3004) Unenroll (7) 300407 66
sms_otp_finish_enrollment Identity & Access Management (3) Entity Management (3004) Enroll (6) 300406 69
sms_otp_start_enrollment Identity & Access Management (3) Entity Management (3004) Enroll (6) 300406 66
sms_twilio_configuration_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 67
sms_twilio_configuration_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 65
sms_twilio_configuration_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 63
sms_twilio_excluded_user_groups_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 67
totp_configuration_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 61
totp_delete_enrollment Identity & Access Management (3) Account Change (3001) MFA Factor Disable (11) 300111 38
totp_finish_enrollment Identity & Access Management (3) Account Change (3001) MFA Factor Enable (10) 300110 63
totp_start_enrollment Identity & Access Management (3) Account Change (3001) MFA Factor Enable (10) 300110 61
trial_resume Identity & Access Management (3) Entity Management (3004) Resume (13) 300413 60
trial_start Identity & Access Management (3) Entity Management (3004) Create (1) 300401 57
trial_stop Identity & Access Management (3) Entity Management (3004) Disable (9) 300409 60
unified_mfa_totp_delete_enrollment Identity & Access Management (3) Account Change (3001) MFA Factor Disable (11) 300111 69
unified_mfa_totp_enrollment Identity & Access Management (3) Account Change (3001) MFA Factor Enable (10) 300110 60
unified_mfa_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 54
unified_mfa_user_update Identity & Access Management (3) Account Change (3001) MFA Factor Enable (10) 300110 60
user_activated Identity & Access Management (3) Account Change (3001) Enable (2) 300102 53
user_activation_email Network Activity (4) Email Activity (4009) Send (1) 400901 67
user_activation_schedule_create System Activity (1) Scheduled Job Activity (1006) Create (1) 100601 53
user_activation_schedule_delete System Activity (1) Scheduled Job Activity (1006) Delete (3) 100603 49
user_admin_grant Identity & Access Management (3) User Access Management (3005) Assign Privileges (1) 300501 72
user_admin_granted Identity & Access Management (3) User Access Management (3005) Assign Privileges (1) 300501 71
user_admin_revoke Identity & Access Management (3) User Access Management (3005) Revoke Privileges (2) 300502 72
user_admin_revoked Identity & Access Management (3) User Access Management (3005) Revoke Privileges (2) 300502 81
user_create Identity & Access Management (3) Account Change (3001) Create (1) 300101 59
user_create_provision Application Activity (6) Application Lifecycle (6002) Install (1) 600201 59
user_deactivated Identity & Access Management (3) Account Change (3001) Disable (5) 300105 40
user_delegated_authority_update Identity & Access Management (3) Account Change (3001) Other (99) 300199 64
user_delete Identity & Access Management (3) Account Change (3001) Delete (6) 300106 47
user_delete_provision Application Activity (6) Application Lifecycle (6002) Remove (2) 600202 35
user_deprovision Application Activity (6) Application Lifecycle (6002) Remove (2) 600202 56
user_import_completed System Activity (1) Scheduled Job Activity (1006) Other (99) 100699 35
user_import_error Application Activity (6) Application Error (6008) General Error (1) 600801 39
user_import_skipped System Activity (1) Scheduled Job Activity (1006) Other (99) 100699 40
user_import_started System Activity (1) Scheduled Job Activity (1006) Start (6) 100606 35
user_import_stopped Application Activity (6) Application Error (6008) General Error (1) 600801 36
user_login_attempt Identity & Access Management (3) Authentication (3002) Logon (1) 300201 66
user_lookup_provision Application Activity (6) API Activity (6003) Read (2) 600302 37
user_mfa_exclusion_expired Identity & Access Management (3) Account Change (3001) Other (99) 300199 38
user_password_expired Identity & Access Management (3) Account Change (3001) Other (99) 300199 33
user_password_reset_email Network Activity (4) Email Activity (4009) Send (1) 400901 59
user_password_reset_request Identity & Access Management (3) Account Change (3001) Password Reset (4) 300104 64
user_password_set Identity & Access Management (3) Account Change (3001) Password Change (3) 300103 59
user_password_update_provision Identity & Access Management (3) Account Change (3001) Password Change (3) 300103 47
user_password_warning_email Network Activity (4) Email Activity (4009) Send (1) 400901 36
user_suspended Identity & Access Management (3) Account Change (3001) Disable (5) 300105 34
user_suspension_schedule_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 46
user_suspension_schedule_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 49
user_transfer_in Identity & Access Management (3) Account Change (3001) Other (99) 300199 54
user_transfer_out Identity & Access Management (3) Account Change (3001) Other (99) 300199 54
user_unlocked Identity & Access Management (3) Account Change (3001) Unlock (12) 300112 68
user_update Identity & Access Management (3) Account Change (3001) Other (99) 300199 81
user_update_password_provision Identity & Access Management (3) Account Change (3001) Password Change (3) 300103 50
user_update_provision Identity & Access Management (3) Account Change (3001) Other (99) 300199 73
user_update_provision_manager Application Activity (6) API Activity (6003) Update (3) 600303 38
webauthn_configuration_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 57
webauthnconfig_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 59
webauthncredential_beginregistration Identity & Access Management (3) Account Change (3001) MFA Factor Enable (10) 300110 73
webauthncredential_delete Identity & Access Management (3) Account Change (3001) MFA Factor Disable (11) 300111 67
webauthncredential_finishregistration Identity & Access Management (3) Account Change (3001) MFA Factor Enable (10) 300110 71
webauthncredential_update Identity & Access Management (3) Account Change (3001) Other (99) 300199 65

OCSF field mappings#

Legend

  • Description: what the OCSF field represents (from OCSF schema v1.8.0)
  • Source: raw JumpCloud event field(s) mapped via ${{placeholder}} template
  • Transform: fieldMappings entry applied at runtime (cast, enum, etc.)
  • Literal: static value set in the mapping template
  • Usage: event types in this service that include this field

Core

activity_id
  • Description: The normalized identifier of the activity that triggered the event.
  • Literal: 1, 10, 11, 12, 13, 2, 3, 4, 5, 6, 7, 9, 99
  • Usage: all events in this service
activity_name
  • Description: The event activity name, as defined by the activity_id.
  • Literal: Activate, Assign Privileges, Create, Deactivate, Delete, Disable, Enable, Enroll, General Error, Install, Logon, MFA Factor Disable, MFA Factor Enable, Other, Password Change, Password Reset, Read, Remove, Resume, Revoke Privileges, Send, Start, Unenroll, Unlock, Update
  • Usage: all events in this service
category_name
  • Description: The event category name, as defined by category_uid value: Discovery.
  • Literal: Application Activity, Identity & Access Management, Network Activity, System Activity
  • Usage: all events in this service
category_uid
  • Description: The category unique identifier of the event.
  • Literal: 1, 3, 4, 6
  • Usage: all events in this service
class_name
  • Description: The event class name, as defined by class_uid value: User Inventory Info.
  • Literal: API Activity, Account Change, Application Error, Application Lifecycle, Authentication, Email Activity, Entity Management, Scheduled Job Activity, User Access Management
  • Usage: all events in this service
class_uid
  • Description: The unique identifier of a class. A class describes the attributes available in an event.
  • Literal: 1006, 3001, 3002, 3004, 3005, 4009, 6002, 6003, 6008
  • Usage: all events in this service
message
  • Description: The description of the event/finding, as defined by the source.
  • Source: message_chain.message_details, message_chain.response_message
  • Usage: 15 events: user_create_provision, user_delete_provision, user_deprovision, user_import_completed, user_import_error, user_import_skipped, user_import_started, user_import_stopped, ... (+7 more)
severity_id
  • Description: OCSF severity identifier for the event.
  • Literal: 1
  • Usage: all events in this service
status_detail
  • Description: The status detail contains additional information about the event/finding outcome.
  • Source: error_message, message_chain.response_message
  • Usage: 87 events: admin_access_granted, admin_access_revoked, admin_apikey_expired, admin_apikey_expiring_soon, admin_delete, admin_old_api_key_attempt, admin_password_change, admin_password_reset_request, ... (+79 more)
status_id
  • Description: Normalized status of the activity (1=Success, 2=Failure).
  • Source: success
  • Transform:
  • success → boolean_to_status_id; true→1, false→2 (93 events (missing: admin_apikey_revoked, admin_create, admin_update, user_create, user_delete))
  • Usage: 93 events (missing: admin_apikey_revoked, admin_create, admin_update, user_create, user_delete)
time
  • Description: Event time, in epoch milliseconds (OCSF time).
  • Source: timestamp
  • Transform:
  • timestamp → iso8601_to_epoch_millis (all events in this service)
  • Usage: all events in this service
type_uid
  • Description: The event/finding type ID. It identifies the event's semantics and structure. The value is calculated by the logging system as: class_uid * 100 + activity_id.
  • Literal: 100601, 100603, 100606, 100699, 300101, 300102, 300103, 300104, 300105, 300106, 300110, 300111, 300112, 300199, 300201, 300299, 300401, 300402, 300403, 300404, 300406, 300407, 300409, 300410, 300411, 300413, 300501, 300502, 400901, 600201, 600202, 600302, 600303, 600801
  • Usage: all events in this service

Metadata

metadata.event_code
  • Description: JumpCloud event type code.
  • Source: event_type
  • Usage: all events in this service
metadata.original_time
  • Description: The original event time as reported by the event source. For example, the time in the original format from system event log such as Syslog on Unix/Linux and the System event file on Windows. Omit if event is generated instead of collected via logs.
  • Source: server_timestamp
  • Usage: 44 events: feature_settings_change, jumpcloud_protect_device_activation, jumpcloud_protect_device_delete, jumpcloud_protect_device_enrollment, jumpcloud_protect_device_push_verification, jumpcloud_protect_device_update, minimum_mfa_compliance_state_changed, minimum_mfa_policy_create, ... (+36 more)
metadata.processed_time
  • Description: The event processed time, such as an ETL operation.
  • Source: jc_transformation_ts
  • Usage: 84 events: admin_access_granted, admin_access_revoked, admin_apikey_expired, admin_apikey_expiring_soon, admin_delete, admin_old_api_key_attempt, admin_password_change, admin_password_reset_request, ... (+76 more)
metadata.product.name
  • Description: Originating JumpCloud service that produced the event.
  • Source: service
  • Usage: all events in this service
metadata.tenant_uid
  • Description: JumpCloud organization (tenant) identifier.
  • Source: organization
  • Usage: all events in this service
metadata.uid
  • Description: Unique event identifier assigned by JumpCloud.
  • Source: id
  • Usage: all events in this service
metadata.version
  • Description: OCSF schema version used for this event.
  • Literal: 1.8.0
  • Usage: all events in this service

Actor

actor.user.email_addr
  • Description: Email address of the actor who initiated the event.
  • Source: initiated_by.email
  • Usage: 62 events: admin_access_granted, admin_access_revoked, admin_apikey_created, admin_apikey_revoked, admin_create, admin_delete, admin_password_change, admin_password_reset_request, ... (+54 more)
actor.user.name
  • Description: Display name of the actor who initiated the event.
  • Source: initiated_by.name, initiated_by.username
  • Usage: 20 events: jumpcloud_protect_device_activation, jumpcloud_protect_device_delete, jumpcloud_protect_device_enrollment, jumpcloud_protect_device_update, minimum_mfa_compliance_state_changed, sms_otp_delete_enrollment, sms_otp_finish_enrollment, sms_otp_start_enrollment, ... (+12 more)
actor.user.type_id
  • Description: OCSF user type of the actor (1=User, 2=Admin, 3=System, 4=Service).
  • Source: initiated_by.type
  • Transform:
  • initiated_by.type → enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (81 events: admin_access_granted, admin_access_revoked, admin_apikey_created, admin_apikey_expired, admin_apikey_expiring_soon, admin_apikey_revoked, admin_create, admin_delete, ... (+73 more))
  • Usage: 82 events: admin_access_granted, admin_access_revoked, admin_apikey_created, admin_apikey_expired, admin_apikey_expiring_soon, admin_apikey_revoked, admin_create, admin_delete, ... (+74 more)
actor.user.uid
  • Description: Unique identifier of the actor who initiated the event.
  • Source: initiated_by.id
  • Usage: 73 events: admin_access_granted, admin_access_revoked, admin_apikey_created, admin_apikey_revoked, admin_create, admin_delete, admin_password_change, admin_password_reset_request, ... (+65 more)

User

user.email_addr
  • Description: Email address of the user associated with the event.
  • Source: changes.to.user.name, initiated_by.email, initiated_by.username, resource.email
  • Usage: 19 events: admin_access_granted, admin_access_revoked, admin_create, admin_delete, admin_login_attempt, admin_old_api_key_attempt, admin_password_change, admin_password_reset_request, ... (+11 more)
user.name
  • Description: The username. For example, janedoe1.
  • Source: auth_mfa_context.jumpcloud_protect_device.username, changes.to.user.display_name, resource.username, verification_context.jumpcloud_protect_device.username
  • Usage: 30 events: jumpcloud_protect_device_push_verification, push_mfa_attempt_failed, totp_delete_enrollment, totp_finish_enrollment, totp_start_enrollment, unified_mfa_totp_delete_enrollment, unified_mfa_totp_enrollment, unified_mfa_user_update, ... (+22 more)
user.type
  • Description: The type of the user. For example, System, AWS IAM User, etc.
  • Source: resource.type
  • Usage: 12 events: user_mfa_exclusion_expired, user_password_expired, user_password_reset_request, user_password_set, user_password_update_provision, user_suspended, user_transfer_in, user_transfer_out, ... (+4 more)
user.type_id
  • Description: OCSF user type (1=User, 2=Admin, 3=System, 4=Service).
  • Source: initiated_by.type, resource.type
  • Transform:
  • initiated_by.type → enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (admin_login_attempt, admin_old_api_key_attempt, jumpcloud_protect_device_push_verification, user_login_attempt)
  • resource.type → enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (26 events: admin_access_granted, admin_access_revoked, admin_create, admin_delete, admin_password_change, admin_password_reset_request, admin_password_set, admin_totp_disable, ... (+18 more))
  • Usage: 30 events: admin_access_granted, admin_access_revoked, admin_create, admin_delete, admin_login_attempt, admin_old_api_key_attempt, admin_password_change, admin_password_reset_request, ... (+22 more)
user.uid
  • Description: Unique identifier of the user associated with the event.
  • Source: auth_mfa_context.jumpcloud_protect_device.user_id, changes.to.user.id, initiated_by.id, resource.id, resource.userId, resource.user_id, verification_context.jumpcloud_protect_device.user_id
  • Usage: 49 events: admin_access_granted, admin_access_revoked, admin_create, admin_delete, admin_login_attempt, admin_old_api_key_attempt, admin_password_change, admin_password_reset_request, ... (+41 more)

Device

device.model
  • Description: The model of the device. For example ThinkPad X1 Carbon.
  • Source: auth_mfa_context.jumpcloud_protect_device.model, verification_context.jumpcloud_protect_device.model
  • Usage: jumpcloud_protect_device_push_verification, push_mfa_attempt_failed
device.os.type
  • Description: The type of the operating system.
  • Source: auth_mfa_context.jumpcloud_protect_device.os, verification_context.jumpcloud_protect_device.os
  • Usage: jumpcloud_protect_device_push_verification, push_mfa_attempt_failed
device.os.version
  • Description: The version of the OS running on the device that originated the event. For example: "Windows 10", "OS X 10.7", or "iOS 9".
  • Source: auth_mfa_context.jumpcloud_protect_device.os_version, verification_context.jumpcloud_protect_device.os_version
  • Usage: jumpcloud_protect_device_push_verification, push_mfa_attempt_failed
device.uid
  • Description: The unique identifier of the device. For example the Windows TargetSID or AWS EC2 ARN.
  • Source: auth_mfa_context.jumpcloud_protect_device.id, verification_context.jumpcloud_protect_device.id
  • Usage: jumpcloud_protect_device_push_verification, push_mfa_attempt_failed
device.vendor_name
  • Description: The vendor for the device. For example Dell or Lenovo.
  • Source: auth_mfa_context.jumpcloud_protect_device.make, verification_context.jumpcloud_protect_device.make
  • Usage: jumpcloud_protect_device_push_verification, push_mfa_attempt_failed

Entity

entity.data.active_secret_id
  • Description: JumpCloud extension data on the managed entity: active_secret_id.
  • Source: resource.active_secret_id
  • Usage: registered_mobile_secret_rotated
entity.data.app_version
  • Description: JumpCloud extension data on the managed entity: app_version.
  • Source: resource.metadata.jumpcloud_protect_device.app_version
  • Usage: jumpcloud_protect_device_activation, jumpcloud_protect_device_delete, jumpcloud_protect_device_enrollment, jumpcloud_protect_device_update
entity.data.auth_method
  • Description: JumpCloud extension data on the managed entity: auth_method.
  • Source: auth_method
  • Usage: 30 events: admin_apikey_created, admin_apikey_expired, admin_apikey_expiring_soon, admin_apikey_revoked, feature_settings_change, jumpcloud_protect_device_activation, jumpcloud_protect_device_delete, jumpcloud_protect_device_enrollment, ... (+22 more)
entity.data.changed_field
  • Description: JumpCloud extension data on the managed entity: changed_field.
  • Source: changes.field
  • Usage: 23 events: admin_apikey_revoked, feature_settings_change, jumpcloud_protect_device_activation, jumpcloud_protect_device_delete, jumpcloud_protect_device_enrollment, jumpcloud_protect_device_update, minimum_mfa_policy_create, minimum_mfa_policy_update, ... (+15 more)
entity.data.changes_from
  • Description: JumpCloud extension data on the managed entity: changes_from.
  • Source: changes.from
  • Usage: 18 events: admin_apikey_revoked, feature_settings_change, jumpcloud_protect_device_activation, jumpcloud_protect_device_delete, jumpcloud_protect_device_update, minimum_mfa_policy_update, nli_settings_update, push_configuration_update, ... (+10 more)
entity.data.createdAt
  • Description: JumpCloud extension data on the managed entity: createdAt.
  • Source: resource.createdAt
  • Usage: admin_apikey_revoked
entity.data.enrollment_type
  • Description: JumpCloud extension data on the managed entity: enrollment_type.
  • Source: resource.enrollment_type
  • Usage: registered_mobile_secret_generated, registered_mobile_secret_revoked, registered_mobile_secret_rotated
entity.data.expireAt
  • Description: JumpCloud extension data on the managed entity: expireAt.
  • Source: resource.expireAt
  • Usage: admin_apikey_expired, admin_apikey_expiring_soon, admin_apikey_revoked
entity.data.initiated_by_source
  • Description: JumpCloud extension data on the managed entity: initiated_by_source.
  • Source: initiated_by.source
  • Usage: jumpcloud_protect_device_activation, jumpcloud_protect_device_delete, jumpcloud_protect_device_enrollment
entity.data.label
  • Description: JumpCloud extension data on the managed entity: label.
  • Source: resource.label
  • Usage: registered_mobile_secret_generated, registered_mobile_secret_revoked, registered_mobile_secret_rotated
entity.data.masked_phone_number
  • Description: JumpCloud extension data on the managed entity: masked_phone_number.
  • Source: resource.masked_phone_number
  • Usage: sms_otp_delete_enrollment, sms_otp_finish_enrollment, sms_otp_start_enrollment
entity.data.prefix
  • Description: JumpCloud extension data on the managed entity: prefix.
  • Source: resource.prefix
  • Usage: admin_apikey_expired, admin_apikey_expiring_soon, admin_apikey_revoked
entity.data.previous_compliance_state
  • Description: JumpCloud extension data on the managed entity: previous_compliance_state.
  • Source: previous_compliance_state
  • Usage: minimum_mfa_compliance_state_changed
entity.data.provider
  • Description: JumpCloud extension data on the managed entity: provider.
  • Source: provider
  • Usage: webauthn_configuration_update, webauthnconfig_update
entity.data.revokedAt
  • Description: JumpCloud extension data on the managed entity: revokedAt.
  • Source: resource.revokedAt
  • Usage: admin_apikey_revoked
entity.data.settings_name
  • Description: JumpCloud extension data on the managed entity: settings_name.
  • Source: resource.settings.name
  • Usage: feature_settings_change
entity.data.settings_value
  • Description: JumpCloud extension data on the managed entity: settings_value.
  • Source: resource.settings.value
  • Usage: feature_settings_change
entity.data.trigger
  • Description: JumpCloud extension data on the managed entity: trigger.
  • Source: trigger
  • Usage: minimum_mfa_compliance_state_changed
entity.data.userEmail
  • Description: JumpCloud extension data on the managed entity: userEmail.
  • Source: resource.userEmail
  • Usage: admin_apikey_revoked
entity.data.userId
  • Description: JumpCloud extension data on the managed entity: userId.
  • Source: resource.userId
  • Usage: admin_apikey_revoked
entity.data.user_id
  • Description: JumpCloud extension data on the managed entity: user_id.
  • Source: resource.user_id
  • Usage: jumpcloud_protect_device_activation, jumpcloud_protect_device_delete, jumpcloud_protect_device_enrollment, jumpcloud_protect_device_update, sms_otp_delete_enrollment, sms_otp_finish_enrollment, sms_otp_start_enrollment
entity.device.model
  • Description: The model of the device. For example ThinkPad X1 Carbon.
  • Source: resource.metadata.jumpcloud_protect_device.model
  • Usage: jumpcloud_protect_device_activation, jumpcloud_protect_device_delete, jumpcloud_protect_device_enrollment, jumpcloud_protect_device_update
entity.device.os.type
  • Description: The type of the operating system.
  • Source: resource.metadata.jumpcloud_protect_device.os
  • Usage: jumpcloud_protect_device_activation, jumpcloud_protect_device_delete, jumpcloud_protect_device_enrollment, jumpcloud_protect_device_update
entity.device.os.version
  • Description: The version of the OS running on the device that originated the event. For example: "Windows 10", "OS X 10.7", or "iOS 9".
  • Source: resource.metadata.jumpcloud_protect_device.os_version
  • Usage: jumpcloud_protect_device_activation, jumpcloud_protect_device_delete, jumpcloud_protect_device_enrollment, jumpcloud_protect_device_update
entity.device.vendor_name
  • Description: The vendor for the device. For example Dell or Lenovo.
  • Source: resource.metadata.jumpcloud_protect_device.make
  • Usage: jumpcloud_protect_device_activation, jumpcloud_protect_device_delete, jumpcloud_protect_device_enrollment, jumpcloud_protect_device_update
entity.name
  • Description: The name of the managed entity. It should match the name of the specific entity object's name if populated, or the name of the managed entity if the type_id is 'Other'.
  • Source: resource.name
  • Usage: feature_settings_change, trial_resume, trial_start, trial_stop
entity.org.uid
  • Description: The unique identifier of the organization, Oracle Cloud Tenancy, Google Cloud Organization, or AWS Organization. For example, an AWS Org ID or Oracle Cloud Domain ID .
  • Source: organization_object_id
  • Usage: minimum_mfa_compliance_state_changed
entity.type
  • Description: The managed entity type. For example: Policy, User, Organization, Device.
  • Source: resource.category, resource.type
  • Usage: 29 events: admin_apikey_created, admin_apikey_expired, admin_apikey_expiring_soon, admin_apikey_revoked, feature_settings_change, jumpcloud_protect_device_activation, jumpcloud_protect_device_delete, jumpcloud_protect_device_enrollment, ... (+21 more)
entity.uid
  • Description: The identifier of the managed entity. It should match the uid of the specific entity's object UID if populated, or the source specific ID if the type_id is 'Other'.
  • Source: resource.id, user_object_id
  • Usage: 19 events: jumpcloud_protect_device_activation, jumpcloud_protect_device_delete, jumpcloud_protect_device_enrollment, jumpcloud_protect_device_update, minimum_mfa_compliance_state_changed, minimum_mfa_policy_create, minimum_mfa_policy_update, registered_mobile_secret_generated, ... (+11 more)
entity_result.data.changes_to
  • Description: JumpCloud extension data on the managed entity: changes_to.
  • Source: changes.to
  • Usage: 21 events: admin_apikey_revoked, feature_settings_change, jumpcloud_protect_device_activation, jumpcloud_protect_device_enrollment, jumpcloud_protect_device_update, minimum_mfa_policy_create, minimum_mfa_policy_update, nli_settings_update, ... (+13 more)
entity_result.data.new_compliance_state
  • Description: JumpCloud extension data on the managed entity: new_compliance_state.
  • Source: new_compliance_state
  • Usage: minimum_mfa_compliance_state_changed

Src Endpoint

src_endpoint.autonomous_system.name
  • Description: Organization name for the Autonomous System.
  • Source: asn.organization
  • Usage: 36 events: admin_access_revoked, admin_password_set, admin_role_granted, admin_role_revoked, admin_totp_disable, jumpcloud_protect_device_activation, jumpcloud_protect_device_delete, jumpcloud_protect_device_enrollment, ... (+28 more)
src_endpoint.autonomous_system.number
  • Description: Unique number that the AS is identified by.
  • Source: asn.number
  • Transform:
  • asn.number → int (36 events: admin_access_revoked, admin_password_set, admin_role_granted, admin_role_revoked, admin_totp_disable, jumpcloud_protect_device_activation, jumpcloud_protect_device_delete, jumpcloud_protect_device_enrollment, ... (+28 more))
  • Usage: 36 events: admin_access_revoked, admin_password_set, admin_role_granted, admin_role_revoked, admin_totp_disable, jumpcloud_protect_device_activation, jumpcloud_protect_device_delete, jumpcloud_protect_device_enrollment, ... (+28 more)
src_endpoint.ip
  • Description: Source IP address the request originated from.
  • Source: client_ip
  • Usage: 87 events: admin_access_granted, admin_access_revoked, admin_apikey_created, admin_apikey_expired, admin_apikey_expiring_soon, admin_apikey_revoked, admin_create, admin_delete, ... (+79 more)
src_endpoint.location.city
  • Description: The name of the city.
  • Source: geoip.city, location.City.Name
  • Usage: 60 events: admin_access_granted, admin_access_revoked, admin_delete, admin_old_api_key_attempt, admin_password_change, admin_password_reset_request, admin_password_set, admin_role_granted, ... (+52 more)
src_endpoint.location.continent
  • Description: The name of the continent.
  • Source: geoip.continent_code
  • Usage: 71 events: admin_access_granted, admin_access_revoked, admin_apikey_created, admin_apikey_revoked, admin_create, admin_delete, admin_login_attempt, admin_old_api_key_attempt, ... (+63 more)
src_endpoint.location.country
  • Description: The ISO 3166-1 Alpha-2 country code.

    Note: The two letter country code should be capitalized. For example: US or CA.

  • Source: geoip.country_code, location.Country.IsoCode
  • Usage: 71 events: admin_access_granted, admin_access_revoked, admin_apikey_created, admin_apikey_revoked, admin_create, admin_delete, admin_login_attempt, admin_old_api_key_attempt, ... (+63 more)
src_endpoint.location.lat
  • Description: The geographical Latitude coordinate represented in Decimal Degrees (DD). For example: 42.361145.
  • Source: geoip.latitude
  • Transform:
  • geoip.latitude → double (71 events: admin_access_granted, admin_access_revoked, admin_apikey_created, admin_apikey_revoked, admin_create, admin_delete, admin_login_attempt, admin_old_api_key_attempt, ... (+63 more))
  • Usage: 71 events: admin_access_granted, admin_access_revoked, admin_apikey_created, admin_apikey_revoked, admin_create, admin_delete, admin_login_attempt, admin_old_api_key_attempt, ... (+63 more)
src_endpoint.location.long
  • Description: The geographical Longitude coordinate represented in Decimal Degrees (DD). For example: -71.057083.
  • Source: geoip.longitude
  • Transform:
  • geoip.longitude → double (71 events: admin_access_granted, admin_access_revoked, admin_apikey_created, admin_apikey_revoked, admin_create, admin_delete, admin_login_attempt, admin_old_api_key_attempt, ... (+63 more))
  • Usage: 71 events: admin_access_granted, admin_access_revoked, admin_apikey_created, admin_apikey_revoked, admin_create, admin_delete, admin_login_attempt, admin_old_api_key_attempt, ... (+63 more)
src_endpoint.location.region
  • Description: The alphanumeric code that identifies the principal subdivision (e.g. province or state) of the country. For example, 'CH-VD' for the Canton of Vaud, Switzerland
  • Source: geoip.region_code, location.Subdivisions.IsoCode
  • Usage: 70 events: admin_access_granted, admin_access_revoked, admin_apikey_created, admin_apikey_revoked, admin_create, admin_delete, admin_login_attempt, admin_old_api_key_attempt, ... (+62 more)

Http Request

http_request.user_agent
  • Description: The request header that identifies the operating system and web browser.
  • Source: user_agent, useragent.device
  • Usage: 62 events: admin_access_granted, admin_access_revoked, admin_apikey_expired, admin_apikey_expiring_soon, admin_delete, admin_password_set, admin_role_granted, admin_role_revoked, ... (+54 more)

Observables

observables[].name
  • Description: The full name of the observable attribute. The name is a pointer/reference to an attribute within the OCSF event data. For example: file.name. Array attributes may be represented in one of three ways. For example: resources.uid, resources[].uid, resources[0].uid.
  • Literal: actor.user.email_addr, actor.user.name, actor.user.uid, device.uid, email.to, email.uid, http_request.user_agent, resources.uid, src_endpoint.ip, src_endpoint.location.country, user.email_addr, user.name, user.uid
  • Usage: 90 events (missing: user_create_provision, user_delete_provision, user_deprovision, user_import_completed, user_import_error...)
observables[].type_id
  • Description: The observable value type identifier.
  • Literal: 10, 14, 16, 2, 31, 4, 41, 47, 5
  • Usage: 90 events (missing: user_create_provision, user_delete_provision, user_deprovision, user_import_completed, user_import_error...)
observables[].value
  • Description: The value associated with the observable attribute. The meaning of the value depends on the observable type.
    If the name refers to a scalar attribute, then the value is the value of the attribute.
    If the name refers to an object attribute, then the value is not populated.
  • Source: auth_mfa_context.jumpcloud_protect_device.id, auth_mfa_context.jumpcloud_protect_device.user_id, auth_mfa_context.jumpcloud_protect_device.username, changes.to.user.display_name, changes.to.user.id, changes.to.user.name, client_ip, geoip.country_code, initiated_by.email, initiated_by.id, initiated_by.name, initiated_by.username, location.Country.IsoCode, resource.email, resource.id, resource.recipient_email, resource.userId, resource.user_id, resource.username, user_agent, useragent.device, verification_context.jumpcloud_protect_device.id, verification_context.jumpcloud_protect_device.user_id, verification_context.jumpcloud_protect_device.username
  • Usage: 90 events (missing: user_create_provision, user_delete_provision, user_deprovision, user_import_completed, user_import_error...)

Resources

resources.uid
  • Description: The unique identifier of the resource.
  • Source: resource.id
  • Usage: user_update_provision_manager

Other

api.request.uid
  • Description: The unique request identifier.
  • Source: client_id
  • Usage: user_update_provision_manager
api.response.code
  • Description: The numeric response sent to a request.
  • Source: message_chain.response_code
  • Transform:
  • message_chain.response_code → int (user_lookup_provision)
  • Usage: user_lookup_provision
api.service.name
  • Description: The name of the service.
  • Source: application.name
  • Usage: user_lookup_provision, user_update_provision_manager
app.name
  • Description: The name of the product.
  • Source: application.name
  • Usage: user_create_provision, user_delete_provision, user_deprovision
app.uid
  • Description: The unique identifier of the product.
  • Source: application.id
  • Usage: user_create_provision, user_deprovision
auth_factors.factor_type
  • Description: The type of authentication factor used in an authentication attempt.
  • Source: resource.metadata.credentialType
  • Usage: webauthncredential_delete, webauthncredential_finishregistration, webauthncredential_update
direction_id
  • Description:

    The direction of the email relative to the scanning host or organization.

    Email scanned at an internet gateway might be characterized as inbound to the organization from the Internet, outbound from the organization to the Internet, or internal within the organization. Email scanned at a workstation might be characterized as inbound to, or outbound from the workstation.
  • Usage: user_activation_email, user_password_reset_email, user_password_warning_email
email.to
  • Description: The machine-readable email header To values, as defined by RFC 5322. For example example.user@usersdomain.com
  • Source: resource.recipient_email
  • Usage: user_password_reset_email
email.uid
  • Description: The unique identifier of the email thread.
  • Source: resource.id
  • Usage: user_password_reset_email, user_password_warning_email
is_mfa
  • Description: Indicates whether Multi Factor Authentication was used during authentication.
  • Source: mfa
  • Usage: admin_login_attempt, user_login_attempt
job.desc
  • Description: The description of the job.
  • Source: resource.type
  • Usage: user_activation_schedule_create, user_activation_schedule_delete, user_import_completed, user_import_skipped, user_import_started
job.name
  • Description: The name of the job.
  • Source: application.name
  • Usage: user_import_completed, user_import_skipped, user_import_started
status_code
  • Description: The event status code, as reported by the event source.

    For example, in a Windows Failed Authentication event, this would be the value of 'Failure Code', e.g. 0x18.
  • Source: message_chain.response_code
  • Usage: user_update_password_provision, user_update_provision, user_update_provision_manager

Unmapped

unmapped.@timestamp
  • Description: JumpCloud Directory Insights field @timestamp preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: @timestamp
  • Usage: 40 events: admin_apikey_created, admin_apikey_expiring_soon, admin_apikey_revoked, admin_create, admin_delete, admin_login_attempt, admin_old_api_key_attempt, admin_password_change, ... (+32 more)
unmapped.@version
  • Description: JumpCloud Directory Insights field @version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: @version
  • Usage: all events in this service
unmapped.access_request_id
  • Description: JumpCloud Directory Insights field access_request_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: access_request_id
  • Usage: user_admin_revoked
unmapped.access_type
  • Description: JumpCloud Directory Insights field access_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: access_type
  • Usage: user_admin_granted, user_admin_revoked
unmapped.api_endpoint
  • Description: JumpCloud Directory Insights field api_endpoint preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.name
  • Usage: admin_old_api_key_attempt
unmapped.app_version
  • Description: JumpCloud Directory Insights field app_version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: auth_mfa_context.jumpcloud_protect_device.app_version, verification_context.jumpcloud_protect_device.app_version
  • Usage: jumpcloud_protect_device_push_verification, push_mfa_attempt_failed
unmapped.application_id
  • Description: JumpCloud Directory Insights field application_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: application.id
  • Usage: user_activated, user_import_completed, user_import_error, user_import_skipped, user_import_started, user_import_stopped, user_password_update_provision, user_suspended, user_update, user_update_provision
unmapped.application_name
  • Description: JumpCloud Directory Insights field application_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: application.name
  • Usage: user_activated, user_import_error, user_import_stopped, user_password_update_provision, user_suspended, user_update, user_update_provision
unmapped.application_type
  • Description: JumpCloud Directory Insights field application_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: application.type
  • Usage: user_create_provision, user_deprovision, user_password_update_provision
unmapped.asn.error
  • Description: JumpCloud Directory Insights field asn.error preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: asn.error
  • Usage: admin_access_revoked, minimum_mfa_policy_update
unmapped.asn.ip_address
  • Description: JumpCloud Directory Insights field asn.ip_address preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: asn.ip_address
  • Usage: admin_access_revoked, minimum_mfa_policy_update
unmapped.asn.network
  • Description: JumpCloud Directory Insights field asn.network preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: asn.network
  • Usage: 36 events: admin_access_revoked, admin_password_set, admin_role_granted, admin_role_revoked, admin_totp_disable, jumpcloud_protect_device_activation, jumpcloud_protect_device_delete, jumpcloud_protect_device_enrollment, ... (+28 more)
unmapped.association_action_source
  • Description: JumpCloud Directory Insights field association_action_source preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: association.action_source
  • Usage: user_update_password_provision
unmapped.association_attributes
  • Description: JumpCloud Directory Insights field association_attributes preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: association.attributes
  • Usage: user_update_password_provision
unmapped.association_connection_from_name
  • Description: JumpCloud Directory Insights field association_connection_from_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: association.connection.from.name
  • Usage: user_update_password_provision
unmapped.association_connection_from_object_id
  • Description: JumpCloud Directory Insights field association_connection_from_object_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: association.connection.from.object_id
  • Usage: user_update_password_provision
unmapped.association_connection_from_type
  • Description: JumpCloud Directory Insights field association_connection_from_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: association.connection.from.type
  • Usage: user_update_password_provision
unmapped.association_connection_to_name
  • Description: JumpCloud Directory Insights field association_connection_to_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: association.connection.to.name
  • Usage: user_update_password_provision
unmapped.association_connection_to_object_id
  • Description: JumpCloud Directory Insights field association_connection_to_object_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: association.connection.to.object_id
  • Usage: user_update_password_provision
unmapped.association_connection_to_type
  • Description: JumpCloud Directory Insights field association_connection_to_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: association.connection.to.type
  • Usage: user_update_password_provision
unmapped.association_op
  • Description: JumpCloud Directory Insights field association_op preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: association.op
  • Usage: user_update_password_provision
unmapped.auth_context_amr
  • Description: JumpCloud Directory Insights field auth_context_amr preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: auth_context.identity_provider.authentication_method_reference
  • Usage: user_login_attempt
unmapped.auth_context_idp_id
  • Description: JumpCloud Directory Insights field auth_context_idp_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: auth_context.identity_provider.id
  • Usage: user_login_attempt
unmapped.auth_context_idp_name
  • Description: JumpCloud Directory Insights field auth_context_idp_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: auth_context.identity_provider.name
  • Usage: user_login_attempt
unmapped.auth_context_idp_success
  • Description: JumpCloud Directory Insights field auth_context_idp_success preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: auth_context.auth_methods.identity_provider.success
  • Usage: user_login_attempt
unmapped.auth_context_idp_type
  • Description: JumpCloud Directory Insights field auth_context_idp_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: auth_context.identity_provider.type
  • Usage: user_login_attempt
unmapped.auth_context_idp_user_id
  • Description: JumpCloud Directory Insights field auth_context_idp_user_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: auth_context.identity_provider.user_id
  • Usage: user_login_attempt
unmapped.auth_context_password_success
  • Description: JumpCloud Directory Insights field auth_context_password_success preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: auth_context.auth_methods.password.success
  • Usage: user_login_attempt
unmapped.auth_context_policy_action
  • Description: JumpCloud Directory Insights field auth_context_policy_action preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: auth_context.policies_applied.metadata.action
  • Usage: user_login_attempt
unmapped.auth_context_policy_conditions
  • Description: JumpCloud Directory Insights field auth_context_policy_conditions preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: auth_context.policies_applied.metadata.conditions
  • Usage: user_login_attempt
unmapped.auth_context_policy_id
  • Description: JumpCloud Directory Insights field auth_context_policy_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: auth_context.policies_applied.id
  • Usage: user_login_attempt
unmapped.auth_context_policy_name
  • Description: JumpCloud Directory Insights field auth_context_policy_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: auth_context.policies_applied.name
  • Usage: user_login_attempt
unmapped.auth_context_policy_resource_type
  • Description: JumpCloud Directory Insights field auth_context_policy_resource_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: auth_context.policies_applied.metadata.resource_type
  • Usage: user_login_attempt
unmapped.auth_context_policy_targets
  • Description: JumpCloud Directory Insights field auth_context_policy_targets preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: auth_context.policies_applied.metadata.targets
  • Usage: user_login_attempt
unmapped.auth_method
  • Description: JumpCloud Directory Insights field auth_method preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: auth_method
  • Usage: 45 events: admin_access_granted, admin_access_revoked, admin_create, admin_delete, admin_old_api_key_attempt, admin_password_change, admin_password_reset_request, admin_role_granted, ... (+37 more)
unmapped.auth_mfa_resource
  • Description: JumpCloud Directory Insights field auth_mfa_resource preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: auth_mfa_context.resource
  • Usage: push_mfa_attempt_failed
unmapped.changed_field
  • Description: JumpCloud Directory Insights field changed_field preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.field
  • Usage: 40 events: admin_access_granted, admin_access_revoked, admin_create, admin_delete, admin_password_change, admin_role_granted, admin_role_revoked, admin_update, ... (+32 more)
unmapped.changes
  • Description: JumpCloud Directory Insights field changes preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes
  • Usage: admin_old_api_key_attempt, admin_password_reset_request, sms_twilio_configuration_delete, user_activation_email, user_password_warning_email, user_transfer_in, user_transfer_out
unmapped.changes.from
  • Description: JumpCloud Directory Insights field changes.from preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.from
  • Usage: user_deprovision
unmapped.changes.to.costCenter
  • Description: JumpCloud Directory Insights field changes.to.costCenter preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to.costCenter
  • Usage: user_create_provision, user_deprovision
unmapped.changes.to.department
  • Description: JumpCloud Directory Insights field changes.to.department preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to.department
  • Usage: user_create_provision, user_deprovision
unmapped.changes.to.description
  • Description: JumpCloud Directory Insights field changes.to.description preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to.description
  • Usage: user_create_provision
unmapped.changes.to.display
  • Description: JumpCloud Directory Insights field changes.to.display preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to.display
  • Usage: user_create_provision
unmapped.changes.to.displayName
  • Description: JumpCloud Directory Insights field changes.to.displayName preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to.displayName
  • Usage: user_create_provision
unmapped.changes.to.familyName
  • Description: JumpCloud Directory Insights field changes.to.familyName preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to.familyName
  • Usage: user_create_provision
unmapped.changes.to.givenName
  • Description: JumpCloud Directory Insights field changes.to.givenName preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to.givenName
  • Usage: user_create_provision
unmapped.changes.to.locality
  • Description: JumpCloud Directory Insights field changes.to.locality preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to.locality
  • Usage: user_deprovision
unmapped.changes.to.organization
  • Description: JumpCloud Directory Insights field changes.to.organization preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to.organization
  • Usage: user_create_provision, user_deprovision
unmapped.changes.to.region
  • Description: JumpCloud Directory Insights field changes.to.region preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to.region
  • Usage: user_deprovision
unmapped.changes.to.streetAddress
  • Description: JumpCloud Directory Insights field changes.to.streetAddress preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to.streetAddress
  • Usage: user_deprovision
unmapped.changes.to.title
  • Description: JumpCloud Directory Insights field changes.to.title preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to.title
  • Usage: user_create_provision
unmapped.changes.to.value
  • Description: JumpCloud Directory Insights field changes.to.value preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to.value
  • Usage: user_create_provision, user_deprovision
unmapped.changes_from
  • Description: JumpCloud Directory Insights field changes_from preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.from
  • Usage: 24 events: admin_access_granted, admin_access_revoked, admin_delete, admin_role_revoked, admin_update, totp_delete_enrollment, totp_finish_enrollment, unified_mfa_totp_delete_enrollment, ... (+16 more)
unmapped.changes_from_from__id
  • Description: JumpCloud Directory Insights field changes_from_from__id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.from._id
  • Usage: user_update
unmapped.changes_from_from_country
  • Description: JumpCloud Directory Insights field changes_from_from_country preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.from.country
  • Usage: user_update
unmapped.changes_from_from_extendedAddress
  • Description: JumpCloud Directory Insights field changes_from_from_extendedAddress preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.from.extendedAddress
  • Usage: user_update
unmapped.changes_from_from_field
  • Description: JumpCloud Directory Insights field changes_from_from_field preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.from.field
  • Usage: user_update
unmapped.changes_from_from_id
  • Description: JumpCloud Directory Insights field changes_from_from_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.from.id
  • Usage: user_update
unmapped.changes_from_from_locality
  • Description: JumpCloud Directory Insights field changes_from_from_locality preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.from.locality
  • Usage: user_update
unmapped.changes_from_from_nanos
  • Description: JumpCloud Directory Insights field changes_from_from_nanos preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.from.nanos
  • Usage: webauthncredential_delete
unmapped.changes_from_from_number
  • Description: JumpCloud Directory Insights field changes_from_from_number preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.from.number
  • Usage: user_update
unmapped.changes_from_from_poBox
  • Description: JumpCloud Directory Insights field changes_from_from_poBox preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.from.poBox
  • Usage: user_update
unmapped.changes_from_from_postalCode
  • Description: JumpCloud Directory Insights field changes_from_from_postalCode preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.from.postalCode
  • Usage: user_update
unmapped.changes_from_from_region
  • Description: JumpCloud Directory Insights field changes_from_from_region preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.from.region
  • Usage: user_update
unmapped.changes_from_from_seconds
  • Description: JumpCloud Directory Insights field changes_from_from_seconds preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.from.seconds
  • Usage: webauthncredential_delete
unmapped.changes_from_from_streetAddress
  • Description: JumpCloud Directory Insights field changes_from_from_streetAddress preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.from.streetAddress
  • Usage: user_update
unmapped.changes_from_from_type
  • Description: JumpCloud Directory Insights field changes_from_from_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.from.type
  • Usage: user_update
unmapped.changes_to
  • Description: JumpCloud Directory Insights field changes_to preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to
  • Usage: 26 events: admin_access_granted, admin_access_revoked, admin_create, admin_role_granted, admin_update, totp_delete_enrollment, totp_finish_enrollment, unified_mfa_totp_delete_enrollment, ... (+18 more)
unmapped.changes_to_country
  • Description: JumpCloud Directory Insights field changes_to_country preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to.country
  • Usage: user_create, user_create_provision, user_deprovision
unmapped.changes_to_employee_number
  • Description: JumpCloud Directory Insights field changes_to_employee_number preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to.employeeNumber
  • Usage: user_create_provision, user_deprovision
unmapped.changes_to_extended_address
  • Description: JumpCloud Directory Insights field changes_to_extended_address preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to.extendedAddress
  • Usage: user_create
unmapped.changes_to_field
  • Description: JumpCloud Directory Insights field changes_to_field preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to.field
  • Usage: user_create
unmapped.changes_to_id
  • Description: JumpCloud Directory Insights field changes_to_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to.id
  • Usage: user_create
unmapped.changes_to_locality
  • Description: JumpCloud Directory Insights field changes_to_locality preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to.locality
  • Usage: user_create
unmapped.changes_to_manager_id
  • Description: JumpCloud Directory Insights field changes_to_manager_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to.manager.managerId
  • Usage: user_create_provision
unmapped.changes_to_name
  • Description: JumpCloud Directory Insights field changes_to_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to.name
  • Usage: user_create
unmapped.changes_to_number
  • Description: JumpCloud Directory Insights field changes_to_number preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to.number
  • Usage: user_create
unmapped.changes_to_po_box
  • Description: JumpCloud Directory Insights field changes_to_po_box preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to.poBox
  • Usage: user_create
unmapped.changes_to_postal_code
  • Description: JumpCloud Directory Insights field changes_to_postal_code preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to.postalCode
  • Usage: user_create
unmapped.changes_to_primary
  • Description: JumpCloud Directory Insights field changes_to_primary preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to.primary
  • Usage: user_create_provision, user_deprovision
unmapped.changes_to_region
  • Description: JumpCloud Directory Insights field changes_to_region preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to.region
  • Usage: user_create
unmapped.changes_to_street_address
  • Description: JumpCloud Directory Insights field changes_to_street_address preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to.streetAddress
  • Usage: user_create
unmapped.changes_to_to__id
  • Description: JumpCloud Directory Insights field changes_to_to__id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to._id
  • Usage: user_update
unmapped.changes_to_to_attestation
  • Description: JumpCloud Directory Insights field changes_to_to_attestation preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to.attestation
  • Usage: webauthncredential_beginregistration
unmapped.changes_to_to_authenticatorSelection_authenticator_attachment
  • Description: JumpCloud Directory Insights field changes_to_to_authenticatorSelection_authenticator_attachment preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to.authenticatorSelection.authenticator_attachment
  • Usage: webauthncredential_beginregistration
unmapped.changes_to_to_authenticatorSelection_user_verification
  • Description: JumpCloud Directory Insights field changes_to_to_authenticatorSelection_user_verification preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to.authenticatorSelection.user_verification
  • Usage: webauthncredential_beginregistration
unmapped.changes_to_to_challenge
  • Description: JumpCloud Directory Insights field changes_to_to_challenge preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to.challenge
  • Usage: webauthncredential_beginregistration
unmapped.changes_to_to_country
  • Description: JumpCloud Directory Insights field changes_to_to_country preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to.country
  • Usage: user_update
unmapped.changes_to_to_extendedAddress
  • Description: JumpCloud Directory Insights field changes_to_to_extendedAddress preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to.extendedAddress
  • Usage: user_update
unmapped.changes_to_to_field
  • Description: JumpCloud Directory Insights field changes_to_to_field preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to.field
  • Usage: user_update
unmapped.changes_to_to_id
  • Description: JumpCloud Directory Insights field changes_to_to_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to.id
  • Usage: user_update
unmapped.changes_to_to_locality
  • Description: JumpCloud Directory Insights field changes_to_to_locality preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to.locality
  • Usage: user_update
unmapped.changes_to_to_nanos
  • Description: JumpCloud Directory Insights field changes_to_to_nanos preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to.nanos
  • Usage: webauthncredential_finishregistration
unmapped.changes_to_to_number
  • Description: JumpCloud Directory Insights field changes_to_to_number preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to.number
  • Usage: user_update
unmapped.changes_to_to_poBox
  • Description: JumpCloud Directory Insights field changes_to_to_poBox preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to.poBox
  • Usage: user_update
unmapped.changes_to_to_postalCode
  • Description: JumpCloud Directory Insights field changes_to_to_postalCode preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to.postalCode
  • Usage: user_update
unmapped.changes_to_to_pubKeyCredParams_alg
  • Description: JumpCloud Directory Insights field changes_to_to_pubKeyCredParams_alg preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to.pubKeyCredParams.alg
  • Usage: webauthncredential_beginregistration
unmapped.changes_to_to_pubKeyCredParams_type
  • Description: JumpCloud Directory Insights field changes_to_to_pubKeyCredParams_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to.pubKeyCredParams.type
  • Usage: webauthncredential_beginregistration
unmapped.changes_to_to_region
  • Description: JumpCloud Directory Insights field changes_to_to_region preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to.region
  • Usage: user_update
unmapped.changes_to_to_rp_id
  • Description: JumpCloud Directory Insights field changes_to_to_rp_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to.rp.id
  • Usage: webauthncredential_beginregistration
unmapped.changes_to_to_rp_name
  • Description: JumpCloud Directory Insights field changes_to_to_rp_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to.rp.name
  • Usage: webauthncredential_beginregistration
unmapped.changes_to_to_seconds
  • Description: JumpCloud Directory Insights field changes_to_to_seconds preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to.seconds
  • Usage: webauthncredential_finishregistration
unmapped.changes_to_to_streetAddress
  • Description: JumpCloud Directory Insights field changes_to_to_streetAddress preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to.streetAddress
  • Usage: user_update
unmapped.changes_to_to_timout
  • Description: JumpCloud Directory Insights field changes_to_to_timout preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to.timout
  • Usage: webauthncredential_beginregistration
unmapped.changes_to_to_type
  • Description: JumpCloud Directory Insights field changes_to_to_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to.type
  • Usage: user_update
unmapped.changes_to_type
  • Description: JumpCloud Directory Insights field changes_to_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to.type
  • Usage: user_create, user_create_provision, user_deprovision
unmapped.changes_to_value
  • Description: JumpCloud Directory Insights field changes_to_value preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to.value
  • Usage: user_create
unmapped.client_id
  • Description: JumpCloud Directory Insights field client_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: client_id
  • Usage: user_create_provision, user_delete_provision, user_deprovision, user_import_completed, user_import_error, user_import_skipped, user_import_started, user_import_stopped, user_lookup_provision, user_password_update_provision
unmapped.client_ip
  • Description: JumpCloud Directory Insights field client_ip preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: client_ip
  • Usage: user_activation_schedule_create, user_activation_schedule_delete, user_create_provision, user_delete_provision, user_deprovision, user_import_error, user_import_skipped
unmapped.correlation
  • Description: JumpCloud Directory Insights field correlation preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: correlation
  • Usage: 12 events: user_activated, user_create_provision, user_deactivated, user_delegated_authority_update, user_delete_provision, user_deprovision, user_transfer_in, user_transfer_out, ... (+4 more)
unmapped.correlation_id
  • Description: JumpCloud Directory Insights field correlation_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: correlation.id
  • Usage: user_import_completed, user_import_error, user_import_skipped, user_import_started, user_import_stopped
unmapped.correlation_type
  • Description: JumpCloud Directory Insights field correlation_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: correlation.type
  • Usage: user_import_completed, user_import_error, user_import_skipped, user_import_started, user_import_stopped
unmapped.credential_id
  • Description: JumpCloud Directory Insights field credential_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.id
  • Usage: webauthncredential_delete, webauthncredential_finishregistration, webauthncredential_update
unmapped.email_type
  • Description: JumpCloud Directory Insights field email_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.email_type
  • Usage: user_activation_email, user_password_reset_email
unmapped.expiry
  • Description: JumpCloud Directory Insights field expiry preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: expiry
  • Usage: user_admin_granted, user_admin_revoked
unmapped.file_input_timestamp
  • Description: JumpCloud Directory Insights field file_input_timestamp preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: file_input_timestamp
  • Usage: 40 events: admin_apikey_created, admin_apikey_expiring_soon, admin_apikey_revoked, admin_create, admin_delete, admin_login_attempt, admin_old_api_key_attempt, admin_password_change, ... (+32 more)
unmapped.g_suite_name
  • Description: JumpCloud Directory Insights field g_suite_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: g_suite.name
  • Usage: user_admin_grant, user_admin_revoke
unmapped.g_suite_type
  • Description: JumpCloud Directory Insights field g_suite_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: g_suite.type
  • Usage: user_admin_grant, user_admin_revoke
unmapped.geoip.city
  • Description: JumpCloud Directory Insights field geoip.city preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.city
  • Usage: user_activation_schedule_create, user_activation_schedule_delete
unmapped.geoip.continent_code
  • Description: JumpCloud Directory Insights field geoip.continent_code preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.continent_code
  • Usage: user_activation_schedule_create, user_activation_schedule_delete
unmapped.geoip.country_code
  • Description: JumpCloud Directory Insights field geoip.country_code preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.country_code
  • Usage: user_activation_schedule_create, user_activation_schedule_delete
unmapped.geoip.latitude
  • Description: JumpCloud Directory Insights field geoip.latitude preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.latitude
  • Usage: user_activation_schedule_create, user_activation_schedule_delete
unmapped.geoip.longitude
  • Description: JumpCloud Directory Insights field geoip.longitude preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.longitude
  • Usage: user_activation_schedule_create, user_activation_schedule_delete
unmapped.geoip.region_code
  • Description: JumpCloud Directory Insights field geoip.region_code preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.region_code
  • Usage: user_activation_schedule_create, user_activation_schedule_delete
unmapped.geoip.region_name
  • Description: JumpCloud Directory Insights field geoip.region_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.region_name
  • Usage: 72 events: admin_access_granted, admin_access_revoked, admin_apikey_created, admin_apikey_revoked, admin_create, admin_delete, admin_login_attempt, admin_old_api_key_attempt, ... (+64 more)
unmapped.geoip.timezone
  • Description: JumpCloud Directory Insights field geoip.timezone preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.timezone
  • Usage: 73 events: admin_access_granted, admin_access_revoked, admin_apikey_created, admin_apikey_revoked, admin_create, admin_delete, admin_login_attempt, admin_old_api_key_attempt, ... (+65 more)
unmapped.host
  • Description: JumpCloud Directory Insights field host preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: host
  • Usage: user_update_provision
unmapped.idm_client_id
  • Description: JumpCloud Directory Insights field idm_client_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: idm_client_id
  • Usage: user_update_provision
unmapped.idm_client_id_hash
  • Description: JumpCloud Directory Insights field idm_client_id_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: idm_client_id_hash
  • Usage: user_update_provision
unmapped.initiated_by
  • Description: JumpCloud Directory Insights field initiated_by preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by
  • Usage: push_mfa_attempt_failed, totp_delete_enrollment, totp_finish_enrollment, totp_start_enrollment, unified_mfa_totp_delete_enrollment, unified_mfa_totp_enrollment, unified_mfa_user_update, user_delete_provision, user_update_provision_manager
unmapped.initiated_by.provider
  • Description: JumpCloud Directory Insights field initiated_by.provider preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by.provider
  • Usage: admin_delete, sms_configuration_update, sms_twilio_configuration_create, sms_twilio_configuration_delete, sms_twilio_configuration_update, sms_twilio_excluded_user_groups_update, user_activation_email, user_delegated_authority_update
unmapped.initiated_by.source
  • Description: JumpCloud Directory Insights field initiated_by.source preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by.source
  • Usage: user_activation_email
unmapped.initiated_by.source_metadata.applicationID
  • Description: JumpCloud Directory Insights field initiated_by.source_metadata.applicationID preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by.source_metadata.applicationID
  • Usage: user_import_skipped
unmapped.initiated_by.source_metadata.sourceName
  • Description: JumpCloud Directory Insights field initiated_by.source_metadata.sourceName preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by.source_metadata.sourceName
  • Usage: user_create_provision, user_deprovision
unmapped.initiated_by.user_id
  • Description: JumpCloud Directory Insights field initiated_by.user_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by.user_id
  • Usage: sms_configuration_update
unmapped.initiated_by_administrator
  • Description: JumpCloud Directory Insights field initiated_by_administrator preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by.administrator
  • Usage: user_login_attempt
unmapped.initiated_by_application_id
  • Description: JumpCloud Directory Insights field initiated_by_application_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by.source_metadata.applicationID
  • Usage: user_suspended, user_update, user_update_password_provision
unmapped.initiated_by_email_hash
  • Description: JumpCloud Directory Insights field initiated_by_email_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_email_hash
  • Usage: 56 events: admin_access_granted, admin_access_revoked, admin_delete, admin_old_api_key_attempt, admin_password_change, admin_password_reset_request, admin_password_set, admin_role_granted, ... (+48 more)
unmapped.initiated_by_id
  • Description: JumpCloud Directory Insights field initiated_by_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by.id
  • Usage: unified_mfa_user_update
unmapped.initiated_by_id_hash
  • Description: JumpCloud Directory Insights field initiated_by_id_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_id_hash
  • Usage: 66 events: admin_access_granted, admin_access_revoked, admin_delete, admin_old_api_key_attempt, admin_password_change, admin_password_reset_request, admin_password_set, admin_role_granted, ... (+58 more)
unmapped.initiated_by_name
  • Description: JumpCloud Directory Insights field initiated_by_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by.name
  • Usage: user_create_provision, user_deprovision
unmapped.initiated_by_name_hash
  • Description: JumpCloud Directory Insights field initiated_by_name_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_name_hash
  • Usage: user_create_provision, user_deprovision, user_password_update_provision, user_update_provision
unmapped.initiated_by_provider
  • Description: JumpCloud Directory Insights field initiated_by_provider preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by.provider
  • Usage: 14 events: admin_access_granted, admin_access_revoked, admin_apikey_created, admin_apikey_expired, admin_apikey_expiring_soon, admin_apikey_revoked, admin_old_api_key_attempt, admin_role_granted, ... (+6 more)
unmapped.initiated_by_source
  • Description: JumpCloud Directory Insights field initiated_by_source preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by.source
  • Usage: 14 events: user_activated, user_create_provision, user_deactivated, user_deprovision, user_import_completed, user_import_error, user_import_skipped, user_import_started, ... (+6 more)
unmapped.initiated_by_source_application_id
  • Description: JumpCloud Directory Insights field initiated_by_source_application_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by.source_metadata.applicationID
  • Usage: user_activated
unmapped.initiated_by_source_metadata_name
  • Description: JumpCloud Directory Insights field initiated_by_source_metadata_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by.source_metadata.name
  • Usage: user_unlocked
unmapped.initiated_by_source_name
  • Description: JumpCloud Directory Insights field initiated_by_source_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by.source_metadata.name, initiated_by.source_metadata.sourceName
  • Usage: 12 events: user_activated, user_deactivated, user_import_completed, user_import_error, user_import_skipped, user_import_started, user_import_stopped, user_password_update_provision, ... (+4 more)
unmapped.initiated_by_type
  • Description: JumpCloud Directory Insights field initiated_by_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by.type
  • Usage: user_create_provision, user_deprovision, user_import_error, user_import_stopped
unmapped.initiated_by_user_id
  • Description: JumpCloud Directory Insights field initiated_by_user_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by.user_id
  • Usage: admin_password_set, push_configuration_update
unmapped.initiated_by_username_hash
  • Description: JumpCloud Directory Insights field initiated_by_username_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_username_hash
  • Usage: 18 events: jumpcloud_protect_device_activation, jumpcloud_protect_device_delete, jumpcloud_protect_device_enrollment, jumpcloud_protect_device_update, minimum_mfa_compliance_state_changed, sms_otp_delete_enrollment, sms_otp_finish_enrollment, sms_otp_start_enrollment, ... (+10 more)
unmapped.is_out_of_bound
  • Description: JumpCloud Directory Insights field is_out_of_bound preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: is_out_of_bound
  • Usage: 62 events: admin_access_granted, admin_access_revoked, admin_apikey_expired, admin_apikey_expiring_soon, admin_delete, admin_password_set, admin_role_granted, admin_role_revoked, ... (+54 more)
unmapped.jc_application_name
  • Description: JumpCloud Directory Insights field jc_application_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_application_name
  • Usage: 62 events: admin_access_granted, admin_access_revoked, admin_apikey_expired, admin_apikey_expiring_soon, admin_delete, admin_password_set, admin_role_granted, admin_role_revoked, ... (+54 more)
unmapped.jc_index_name
  • Description: JumpCloud Directory Insights field jc_index_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_index_name
  • Usage: jumpcloud_protect_device_delete, totp_finish_enrollment, totp_start_enrollment
unmapped.jc_initiated_by_email
  • Description: JumpCloud Directory Insights field jc_initiated_by_email preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_initiated_by_email
  • Usage: 17 events: admin_apikey_expired, admin_password_set, admin_totp_disable, jumpcloud_protect_device_activation, jumpcloud_protect_device_delete, jumpcloud_protect_device_enrollment, push_mfa_attempt_failed, sms_configuration_update, ... (+9 more)
unmapped.jc_initiated_by_username
  • Description: JumpCloud Directory Insights field jc_initiated_by_username preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_initiated_by_username
  • Usage: 17 events: admin_apikey_expired, admin_password_set, admin_totp_disable, jumpcloud_protect_device_activation, jumpcloud_protect_device_delete, jumpcloud_protect_device_enrollment, push_mfa_attempt_failed, sms_configuration_update, ... (+9 more)
unmapped.jc_organization_id
  • Description: JumpCloud Directory Insights field jc_organization_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_organization_id
  • Usage: jumpcloud_protect_device_delete, totp_finish_enrollment, totp_start_enrollment
unmapped.jc_organization_name
  • Description: JumpCloud Directory Insights field jc_organization_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_organization_name
  • Usage: 17 events: admin_apikey_expired, admin_password_set, admin_totp_disable, jumpcloud_protect_device_activation, jumpcloud_protect_device_delete, jumpcloud_protect_device_enrollment, push_mfa_attempt_failed, sms_configuration_update, ... (+9 more)
unmapped.jc_provider_id
  • Description: JumpCloud Directory Insights field jc_provider_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_provider_id
  • Usage: 14 events: admin_apikey_expired, admin_password_set, jumpcloud_protect_device_delete, jumpcloud_protect_device_enrollment, push_mfa_attempt_failed, sms_configuration_update, sms_otp_finish_enrollment, sms_otp_start_enrollment, ... (+6 more)
unmapped.ldap_server_name
  • Description: JumpCloud Directory Insights field ldap_server_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: ldap_server.name
  • Usage: user_admin_grant, user_admin_revoke
unmapped.ldap_server_type
  • Description: JumpCloud Directory Insights field ldap_server_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: ldap_server.type
  • Usage: user_admin_grant, user_admin_revoke
unmapped.location.Country.Name
  • Description: JumpCloud Directory Insights field location.Country.Name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: location.Country.Name
  • Usage: user_admin_granted, user_admin_revoked
unmapped.location.Subdivisions.Name
  • Description: JumpCloud Directory Insights field location.Subdivisions.Name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: location.Subdivisions.Name
  • Usage: user_admin_granted, user_admin_revoked
unmapped.message_chain
  • Description: JumpCloud Directory Insights field message_chain preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: message_chain
  • Usage: user_activated, user_deactivated, user_delegated_authority_update, user_transfer_in, user_unlocked
unmapped.message_chain_message_details
  • Description: JumpCloud Directory Insights field message_chain_message_details preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: message_chain.message_details
  • Usage: user_create_provision, user_delete_provision, user_deprovision, user_import_completed, user_import_error, user_import_skipped, user_import_started, user_import_stopped
unmapped.message_chain_response_code
  • Description: JumpCloud Directory Insights field message_chain_response_code preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: message_chain.response_code
  • Usage: user_create_provision, user_delete_provision, user_deprovision, user_import_completed, user_import_error, user_import_skipped, user_import_started, user_import_stopped
unmapped.message_details
  • Description: JumpCloud Directory Insights field message_details preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: message_chain.message_details
  • Usage: user_lookup_provision, user_password_update_provision
unmapped.msp_provider_id
  • Description: JumpCloud Directory Insights field msp_provider_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: provider
  • Usage: 33 events: admin_access_granted, admin_access_revoked, admin_apikey_created, admin_apikey_expired, admin_apikey_expiring_soon, admin_apikey_revoked, admin_role_granted, admin_role_revoked, ... (+25 more)
unmapped.office_365_name
  • Description: JumpCloud Directory Insights field office_365_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: office_365.name
  • Usage: user_admin_grant
unmapped.office_365_type
  • Description: JumpCloud Directory Insights field office_365_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: office_365.type
  • Usage: user_admin_grant, user_admin_revoke
unmapped.pid
  • Description: JumpCloud Directory Insights field pid preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: pid
  • Usage: user_admin_granted, user_admin_revoked
unmapped.provider
  • Description: JumpCloud Directory Insights field provider preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: provider
  • Usage: 35 events: admin_create, admin_delete, admin_login_attempt, admin_old_api_key_attempt, admin_password_change, admin_password_reset_request, admin_password_set, admin_totp_finish_enrollment, ... (+27 more)
unmapped.provider_id
  • Description: JumpCloud Directory Insights field provider_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.providerId
  • Usage: admin_role_granted, admin_role_revoked
unmapped.push_status
  • Description: JumpCloud Directory Insights field push_status preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: push_status.status
  • Usage: jumpcloud_protect_device_push_verification
unmapped.recipient_email
  • Description: JumpCloud Directory Insights field recipient_email preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.recipient_email
  • Usage: user_activation_email
unmapped.resource_id
  • Description: JumpCloud Directory Insights field resource_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.id
  • Usage: 13 events: unified_mfa_update, user_activation_email, user_activation_schedule_create, user_activation_schedule_delete, user_create_provision, user_delete_provision, user_deprovision, user_import_completed, ... (+5 more)
unmapped.resource_id_hash
  • Description: JumpCloud Directory Insights field resource_id_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource_id_hash
  • Usage: 64 events: admin_access_granted, admin_access_revoked, admin_delete, admin_password_change, admin_password_reset_request, admin_password_set, admin_totp_disable, admin_totp_finish_enrollment, ... (+56 more)
unmapped.resource_name
  • Description: JumpCloud Directory Insights field resource_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.name
  • Usage: user_admin_grant, user_admin_revoke
unmapped.resource_type
  • Description: JumpCloud Directory Insights field resource_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.type
  • Usage: 17 events: admin_old_api_key_attempt, admin_role_granted, admin_role_revoked, user_activation_email, user_create_provision, user_delete_provision, user_deprovision, user_import_error, ... (+9 more)
unmapped.resource_username
  • Description: JumpCloud Directory Insights field resource_username preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.username
  • Usage: 14 events: unified_mfa_update, user_activation_email, user_create_provision, user_delete_provision, user_deprovision, user_import_completed, user_import_error, user_import_skipped, ... (+6 more)
unmapped.resource_username_hash
  • Description: JumpCloud Directory Insights field resource_username_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource_username_hash
  • Usage: 29 events: totp_delete_enrollment, totp_finish_enrollment, totp_start_enrollment, unified_mfa_totp_delete_enrollment, unified_mfa_totp_enrollment, unified_mfa_user_update, user_activation_email, user_admin_grant, ... (+21 more)
unmapped.response_code
  • Description: JumpCloud Directory Insights field response_code preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: message_chain.response_code
  • Usage: user_password_update_provision
unmapped.role_id
  • Description: JumpCloud Directory Insights field role_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.roleId
  • Usage: admin_role_granted, admin_role_revoked
unmapped.system_display_name
  • Description: JumpCloud Directory Insights field system_display_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: system.displayName
  • Usage: user_admin_granted, user_admin_revoked
unmapped.system_group_id
  • Description: JumpCloud Directory Insights field system_group_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: system_group.id
  • Usage: user_admin_grant
unmapped.system_group_name
  • Description: JumpCloud Directory Insights field system_group_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: system_group.name
  • Usage: user_admin_grant
unmapped.system_group_type
  • Description: JumpCloud Directory Insights field system_group_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: system_group.type
  • Usage: user_admin_grant
unmapped.system_hostname
  • Description: JumpCloud Directory Insights field system_hostname preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: system.hostname
  • Usage: user_admin_granted, user_admin_revoked
unmapped.system_id
  • Description: JumpCloud Directory Insights field system_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: system.id
  • Usage: user_admin_granted, user_admin_revoked
unmapped.system_type
  • Description: JumpCloud Directory Insights field system_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: system.type
  • Usage: user_admin_granted, user_admin_revoked
unmapped.tags
  • Description: JumpCloud Directory Insights field tags preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: tags
  • Usage: 40 events: admin_apikey_created, admin_apikey_expiring_soon, admin_apikey_revoked, admin_create, admin_delete, admin_login_attempt, admin_old_api_key_attempt, admin_password_change, ... (+32 more)
unmapped.target_resource_type
  • Description: JumpCloud Directory Insights field target_resource_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: target_resource.type
  • Usage: admin_login_attempt, user_login_attempt
unmapped.timestamp_source
  • Description: JumpCloud Directory Insights field timestamp_source preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: timestamp_source
  • Usage: 44 events: feature_settings_change, jumpcloud_protect_device_activation, jumpcloud_protect_device_delete, jumpcloud_protect_device_enrollment, jumpcloud_protect_device_push_verification, jumpcloud_protect_device_update, minimum_mfa_compliance_state_changed, minimum_mfa_policy_create, ... (+36 more)
unmapped.type
  • Description: JumpCloud Directory Insights field type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: type
  • Usage: user_update_provision
unmapped.user_action
  • Description: JumpCloud Directory Insights field user_action preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: user_action.action
  • Usage: jumpcloud_protect_device_push_verification
unmapped.user_agent
  • Description: JumpCloud Directory Insights field user_agent preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: user_agent
  • Usage: user_activation_email, user_create_provision, user_delete_provision, user_deprovision, user_import_error, user_import_skipped, user_password_warning_email
unmapped.useragent.build
  • Description: JumpCloud Directory Insights field useragent.build preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.build
  • Usage: jumpcloud_protect_device_delete, totp_finish_enrollment, totp_start_enrollment
unmapped.useragent.device
  • Description: JumpCloud Directory Insights field useragent.device preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.device
  • Usage: 64 events: admin_access_granted, admin_access_revoked, admin_apikey_created, admin_apikey_revoked, admin_create, admin_delete, admin_login_attempt, admin_old_api_key_attempt, ... (+56 more)
unmapped.useragent.major
  • Description: JumpCloud Directory Insights field useragent.major preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.major
  • Usage: 72 events: admin_access_granted, admin_access_revoked, admin_apikey_created, admin_apikey_revoked, admin_create, admin_delete, admin_login_attempt, admin_old_api_key_attempt, ... (+64 more)
unmapped.useragent.minor
  • Description: JumpCloud Directory Insights field useragent.minor preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.minor
  • Usage: 72 events: admin_access_granted, admin_access_revoked, admin_apikey_created, admin_apikey_revoked, admin_create, admin_delete, admin_login_attempt, admin_old_api_key_attempt, ... (+64 more)
unmapped.useragent.name
  • Description: JumpCloud Directory Insights field useragent.name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.name
  • Usage: 77 events: admin_access_granted, admin_access_revoked, admin_apikey_created, admin_apikey_revoked, admin_create, admin_delete, admin_login_attempt, admin_old_api_key_attempt, ... (+69 more)
unmapped.useragent.os
  • Description: JumpCloud Directory Insights field useragent.os preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os
  • Usage: 77 events: admin_access_granted, admin_access_revoked, admin_apikey_created, admin_apikey_revoked, admin_create, admin_delete, admin_login_attempt, admin_old_api_key_attempt, ... (+69 more)
unmapped.useragent.os_full
  • Description: JumpCloud Directory Insights field useragent.os_full preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_full
  • Usage: 77 events: admin_access_granted, admin_access_revoked, admin_apikey_created, admin_apikey_revoked, admin_create, admin_delete, admin_login_attempt, admin_old_api_key_attempt, ... (+69 more)
unmapped.useragent.os_major
  • Description: JumpCloud Directory Insights field useragent.os_major preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_major
  • Usage: 56 events: admin_access_granted, admin_access_revoked, admin_delete, admin_login_attempt, admin_password_change, admin_password_reset_request, admin_role_granted, admin_role_revoked, ... (+48 more)
unmapped.useragent.os_minor
  • Description: JumpCloud Directory Insights field useragent.os_minor preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_minor
  • Usage: 56 events: admin_access_granted, admin_access_revoked, admin_delete, admin_login_attempt, admin_password_change, admin_password_reset_request, admin_role_granted, admin_role_revoked, ... (+48 more)
unmapped.useragent.os_name
  • Description: JumpCloud Directory Insights field useragent.os_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_name
  • Usage: 77 events: admin_access_granted, admin_access_revoked, admin_apikey_created, admin_apikey_revoked, admin_create, admin_delete, admin_login_attempt, admin_old_api_key_attempt, ... (+69 more)
unmapped.useragent.os_patch
  • Description: JumpCloud Directory Insights field useragent.os_patch preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_patch
  • Usage: 55 events: admin_access_granted, admin_access_revoked, admin_delete, admin_login_attempt, admin_password_change, admin_password_reset_request, admin_role_granted, admin_role_revoked, ... (+47 more)
unmapped.useragent.os_version
  • Description: JumpCloud Directory Insights field useragent.os_version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_version
  • Usage: 56 events: admin_access_granted, admin_access_revoked, admin_delete, admin_login_attempt, admin_password_change, admin_password_reset_request, admin_role_granted, admin_role_revoked, ... (+48 more)
unmapped.useragent.patch
  • Description: JumpCloud Directory Insights field useragent.patch preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.patch
  • Usage: 60 events: admin_access_granted, admin_access_revoked, admin_apikey_created, admin_apikey_revoked, admin_delete, admin_login_attempt, admin_password_change, admin_password_reset_request, ... (+52 more)
unmapped.useragent.version
  • Description: JumpCloud Directory Insights field useragent.version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.version
  • Usage: 72 events: admin_access_granted, admin_access_revoked, admin_apikey_created, admin_apikey_revoked, admin_create, admin_delete, admin_login_attempt, admin_old_api_key_attempt, ... (+64 more)
unmapped.verification_device_ip
  • Description: JumpCloud Directory Insights field verification_device_ip preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: verification_context.device_ip_address
  • Usage: jumpcloud_protect_device_push_verification
unmapped.workflow
  • Description: JumpCloud Directory Insights field workflow preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: workflow
  • Usage: user_admin_revoked
unmapped.workflow_desc
  • Description: JumpCloud Directory Insights field workflow_desc preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: workflow.desc
  • Usage: user_update_provision
unmapped.workflow_id
  • Description: JumpCloud Directory Insights field workflow_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: workflow.id
  • Usage: user_update_provision
unmapped.workflow_name
  • Description: JumpCloud Directory Insights field workflow_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: workflow.name
  • Usage: user_update_provision
unmapped.workflow_type
  • Description: JumpCloud Directory Insights field workflow_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: workflow.type
  • Usage: user_update_provision

GenAI#

genai · 12 events

Event Category Class Activity Type UID Fields
genai_ai_assistant_chat_created Identity & Access Management (3) Entity Management (3004) Create (1) 300401 64
genai_ai_assistant_chat_deleted Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 67
genai_ai_assistant_chat_message_sent Identity & Access Management (3) Entity Management (3004) Read (2) 300402 83
genai_ai_assistant_chat_updated Identity & Access Management (3) Entity Management (3004) Update (3) 300403 71
genai_ai_assistant_memory_deleted Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 69
genai_ai_assistant_org_rule_created Identity & Access Management (3) Entity Management (3004) Create (1) 300401 70
genai_ai_assistant_org_rule_deleted Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 68
genai_ai_assistant_org_rule_updated Identity & Access Management (3) Entity Management (3004) Update (3) 300403 64
genai_ai_assistant_org_settings_updated Identity & Access Management (3) Entity Management (3004) Update (3) 300403 68
genai_ai_search_executed Identity & Access Management (3) Entity Management (3004) Read (2) 300402 67
genai_mcp_manual_revoked Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 74
genai_mcp_session_created Identity & Access Management (3) Entity Management (3004) Create (1) 300401 73

OCSF field mappings#

Legend

  • Description: what the OCSF field represents (from OCSF schema v1.8.0)
  • Source: raw JumpCloud event field(s) mapped via ${{placeholder}} template
  • Transform: fieldMappings entry applied at runtime (cast, enum, etc.)
  • Literal: static value set in the mapping template
  • Usage: event types in this service that include this field

Core

activity_id
  • Description: The normalized identifier of the activity that triggered the event.
  • Literal: 1, 2, 3, 4
  • Usage: all events in this service
activity_name
  • Description: The event activity name, as defined by the activity_id.
  • Literal: Create, Delete, Read, Update
  • Usage: all events in this service
category_name
  • Description: The event category name, as defined by category_uid value: Discovery.
  • Literal: Identity & Access Management
  • Usage: all events in this service
category_uid
  • Description: The category unique identifier of the event.
  • Literal: 3
  • Usage: all events in this service
class_name
  • Description: The event class name, as defined by class_uid value: User Inventory Info.
  • Literal: Entity Management
  • Usage: all events in this service
class_uid
  • Description: The unique identifier of a class. A class describes the attributes available in an event.
  • Literal: 3004
  • Usage: all events in this service
severity_id
  • Description: OCSF severity identifier for the event.
  • Literal: 1
  • Usage: all events in this service
status_detail
  • Description: The status detail contains additional information about the event/finding outcome.
  • Source: error_message
  • Usage: all events in this service
status_id
  • Description: Normalized status of the activity (1=Success, 2=Failure).
  • Source: success
  • Transform:
  • success → boolean_to_status_id; true→1, false→2 (all events in this service)
  • Usage: all events in this service
time
  • Description: Event time, in epoch milliseconds (OCSF time).
  • Source: timestamp
  • Transform:
  • timestamp → iso8601_to_epoch_millis (all events in this service)
  • Usage: all events in this service
type_uid
  • Description: The event/finding type ID. It identifies the event's semantics and structure. The value is calculated by the logging system as: class_uid * 100 + activity_id.
  • Literal: 300401, 300402, 300403, 300404
  • Usage: all events in this service

Metadata

metadata.event_code
  • Description: JumpCloud event type code.
  • Source: event_type
  • Usage: all events in this service
metadata.processed_time
  • Description: The event processed time, such as an ETL operation.
  • Source: jc_transformation_ts
  • Usage: all events in this service
metadata.product.name
  • Description: Originating JumpCloud service that produced the event.
  • Source: service
  • Usage: all events in this service
metadata.tenant_uid
  • Description: JumpCloud organization (tenant) identifier.
  • Source: organization
  • Usage: all events in this service
metadata.uid
  • Description: Unique event identifier assigned by JumpCloud.
  • Source: id
  • Usage: all events in this service
metadata.version
  • Description: OCSF schema version used for this event.
  • Literal: 1.8.0
  • Usage: all events in this service

Actor

actor.user.email_addr
  • Description: Email address of the actor who initiated the event.
  • Source: initiated_by.email
  • Usage: all events in this service
actor.user.type_id
  • Description: OCSF user type of the actor (1=User, 2=Admin, 3=System, 4=Service).
  • Source: initiated_by.type
  • Transform:
  • initiated_by.type → enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (all events in this service)
  • Usage: all events in this service
actor.user.uid
  • Description: Unique identifier of the actor who initiated the event.
  • Source: initiated_by.id
  • Usage: all events in this service

Entity

entity.data.auth_method
  • Description: JumpCloud extension data on the managed entity: auth_method.
  • Source: auth_method
  • Usage: all events in this service
entity.data.categories
  • Description: JumpCloud extension data on the managed entity: categories.
  • Source: categories
  • Usage: genai_ai_assistant_chat_message_sent
entity.data.category
  • Description: JumpCloud extension data on the managed entity: category.
  • Source: resource.category
  • Usage: genai_ai_assistant_memory_deleted
entity.data.changed_field
  • Description: JumpCloud extension data on the managed entity: changed_field.
  • Source: changes.field
  • Usage: genai_ai_assistant_chat_created, genai_ai_assistant_chat_updated, genai_ai_assistant_org_rule_created, genai_ai_assistant_org_rule_updated, genai_ai_assistant_org_settings_updated, genai_ai_search_executed
entity.data.changes_from
  • Description: JumpCloud extension data on the managed entity: changes_from.
  • Source: changes.from
  • Usage: genai_ai_assistant_chat_updated, genai_ai_assistant_org_rule_updated, genai_ai_assistant_org_settings_updated
entity.data.client_id
  • Description: JumpCloud extension data on the managed entity: client_id.
  • Source: resource.client_id
  • Usage: genai_mcp_manual_revoked, genai_mcp_session_created
entity.data.client_name
  • Description: JumpCloud extension data on the managed entity: client_name.
  • Source: client_name
  • Usage: genai_mcp_manual_revoked, genai_mcp_session_created
entity.data.messageId
  • Description: JumpCloud extension data on the managed entity: messageId.
  • Source: resource.messageId
  • Usage: genai_ai_assistant_chat_message_sent
entity.data.org_id
  • Description: JumpCloud extension data on the managed entity: org_id.
  • Source: org_id
  • Usage: genai_mcp_manual_revoked, genai_mcp_session_created
entity.data.ruleText
  • Description: JumpCloud extension data on the managed entity: ruleText.
  • Source: resource.ruleText
  • Usage: genai_ai_assistant_org_rule_created, genai_ai_assistant_org_rule_deleted, genai_ai_assistant_org_rule_updated
entity.data.session_id
  • Description: JumpCloud extension data on the managed entity: session_id.
  • Source: session_id
  • Usage: genai_mcp_manual_revoked, genai_mcp_session_created
entity.data.tools_used.approved
  • Description: JumpCloud extension data on the managed entity: tools_used.approved.
  • Source: tools_used.approved
  • Usage: genai_ai_assistant_chat_message_sent
entity.data.tools_used.parameters.command
  • Description: JumpCloud extension data on the managed entity: tools_used.parameters.command.
  • Source: tools_used.parameters.command
  • Usage: genai_ai_assistant_chat_message_sent
entity.data.tools_used.parameters.commandType
  • Description: JumpCloud extension data on the managed entity: tools_used.parameters.commandType.
  • Source: tools_used.parameters.commandType
  • Usage: genai_ai_assistant_chat_message_sent
entity.data.tools_used.parameters.description
  • Description: JumpCloud extension data on the managed entity: tools_used.parameters.description.
  • Source: tools_used.parameters.description
  • Usage: genai_ai_assistant_chat_message_sent
entity.data.tools_used.parameters.exemptions.id
  • Description: JumpCloud extension data on the managed entity: tools_used.parameters.exemptions.id.
  • Source: tools_used.parameters.exemptions.id
  • Usage: genai_ai_assistant_chat_message_sent
entity.data.tools_used.parameters.exemptions.name
  • Description: JumpCloud extension data on the managed entity: tools_used.parameters.exemptions.name.
  • Source: tools_used.parameters.exemptions.name
  • Usage: genai_ai_assistant_chat_message_sent
entity.data.tools_used.parameters.exemptions.op
  • Description: JumpCloud extension data on the managed entity: tools_used.parameters.exemptions.op.
  • Source: tools_used.parameters.exemptions.op
  • Usage: genai_ai_assistant_chat_message_sent
entity.data.tools_used.parameters.exemptions.type
  • Description: JumpCloud extension data on the managed entity: tools_used.parameters.exemptions.type.
  • Source: tools_used.parameters.exemptions.type
  • Usage: genai_ai_assistant_chat_message_sent
entity.data.tools_used.parameters.filterOperator
  • Description: JumpCloud extension data on the managed entity: tools_used.parameters.filterOperator.
  • Source: tools_used.parameters.filterOperator
  • Usage: genai_ai_assistant_chat_message_sent
entity.data.tools_used.parameters.filters
  • Description: JumpCloud extension data on the managed entity: tools_used.parameters.filters.
  • Source: tools_used.parameters.filters
  • Usage: genai_ai_assistant_chat_message_sent
entity.data.tools_used.parameters.id
  • Description: JumpCloud extension data on the managed entity: tools_used.parameters.id.
  • Source: tools_used.parameters.id
  • Usage: genai_ai_assistant_chat_message_sent
entity.data.tools_used.parameters.intent
  • Description: JumpCloud extension data on the managed entity: tools_used.parameters.intent.
  • Source: tools_used.parameters.intent
  • Usage: genai_ai_assistant_chat_message_sent
entity.data.tools_used.parameters.interactionId
  • Description: JumpCloud extension data on the managed entity: tools_used.parameters.interactionId.
  • Source: tools_used.parameters.interactionId
  • Usage: genai_ai_assistant_chat_message_sent
entity.data.tools_used.parameters.limit
  • Description: JumpCloud extension data on the managed entity: tools_used.parameters.limit.
  • Source: tools_used.parameters.limit
  • Usage: genai_ai_assistant_chat_message_sent
entity.data.tools_used.parameters.name
  • Description: JumpCloud extension data on the managed entity: tools_used.parameters.name.
  • Source: tools_used.parameters.name
  • Usage: genai_ai_assistant_chat_message_sent
entity.data.tools_used.parameters.question
  • Description: JumpCloud extension data on the managed entity: tools_used.parameters.question.
  • Source: tools_used.parameters.question
  • Usage: genai_ai_assistant_chat_message_sent
entity.data.tools_used.parameters.search
  • Description: JumpCloud extension data on the managed entity: tools_used.parameters.search.
  • Source: tools_used.parameters.search
  • Usage: genai_ai_assistant_chat_message_sent
entity.data.tools_used.parameters.shellType
  • Description: JumpCloud extension data on the managed entity: tools_used.parameters.shellType.
  • Source: tools_used.parameters.shellType
  • Usage: genai_ai_assistant_chat_message_sent
entity.data.tools_used.parameters.skip
  • Description: JumpCloud extension data on the managed entity: tools_used.parameters.skip.
  • Source: tools_used.parameters.skip
  • Usage: genai_ai_assistant_chat_message_sent
entity.data.tools_used.parameters.systemIds
  • Description: JumpCloud extension data on the managed entity: tools_used.parameters.systemIds.
  • Source: tools_used.parameters.systemIds
  • Usage: genai_ai_assistant_chat_message_sent
entity.data.tools_used.parameters.title
  • Description: JumpCloud extension data on the managed entity: tools_used.parameters.title.
  • Source: tools_used.parameters.title
  • Usage: genai_ai_assistant_chat_message_sent
entity.data.tools_used.parameters.type
  • Description: JumpCloud extension data on the managed entity: tools_used.parameters.type.
  • Source: tools_used.parameters.type
  • Usage: genai_ai_assistant_chat_message_sent
entity.data.tools_used.tool_name
  • Description: JumpCloud extension data on the managed entity: tools_used.tool_name.
  • Source: tools_used.tool_name
  • Usage: genai_ai_assistant_chat_message_sent
entity.data.trigger
  • Description: JumpCloud extension data on the managed entity: trigger.
  • Source: trigger
  • Usage: genai_mcp_manual_revoked
entity.data.user_id
  • Description: JumpCloud extension data on the managed entity: user_id.
  • Source: user_id
  • Usage: genai_mcp_manual_revoked, genai_mcp_session_created
entity.data.user_prompt
  • Description: JumpCloud extension data on the managed entity: user_prompt.
  • Source: user_prompt
  • Usage: genai_ai_assistant_chat_message_sent
entity.name
  • Description: The name of the managed entity. It should match the name of the specific entity object's name if populated, or the name of the managed entity if the type_id is 'Other'.
  • Source: resource.name
  • Usage: genai_ai_assistant_chat_created, genai_ai_assistant_chat_deleted, genai_ai_assistant_chat_message_sent, genai_ai_assistant_chat_updated, genai_ai_assistant_memory_deleted, genai_ai_assistant_org_rule_created, genai_ai_assistant_org_rule_deleted, genai_ai_assistant_org_rule_updated, genai_mcp_manual_revoked, genai_mcp_session_created
entity.type
  • Description: The managed entity type. For example: Policy, User, Organization, Device.
  • Source: resource.type
  • Usage: all events in this service
entity.uid
  • Description: The identifier of the managed entity. It should match the uid of the specific entity's object UID if populated, or the source specific ID if the type_id is 'Other'.
  • Source: resource.id
  • Usage: all events in this service
entity_result.data.changes_to
  • Description: JumpCloud extension data on the managed entity: changes_to.
  • Source: changes.to
  • Usage: genai_ai_assistant_chat_created, genai_ai_assistant_chat_updated, genai_ai_assistant_org_rule_created, genai_ai_assistant_org_rule_updated, genai_ai_assistant_org_settings_updated, genai_ai_search_executed

Src Endpoint

src_endpoint.autonomous_system.name
  • Description: Organization name for the Autonomous System.
  • Source: asn.organization
  • Usage: 11 events (missing: genai_ai_assistant_chat_message_sent)
src_endpoint.autonomous_system.number
  • Description: Unique number that the AS is identified by.
  • Source: asn.number
  • Transform:
  • asn.number → int (11 events (missing: genai_ai_assistant_chat_message_sent))
  • Usage: 11 events (missing: genai_ai_assistant_chat_message_sent)
src_endpoint.ip
  • Description: Source IP address the request originated from.
  • Source: client_ip
  • Usage: all events in this service
src_endpoint.location.city
  • Description: The name of the city.
  • Source: geoip.city
  • Usage: all events in this service
src_endpoint.location.continent
  • Description: The name of the continent.
  • Source: geoip.continent_code
  • Usage: all events in this service
src_endpoint.location.country
  • Description: The ISO 3166-1 Alpha-2 country code.

    Note: The two letter country code should be capitalized. For example: US or CA.

  • Source: geoip.country_code
  • Usage: all events in this service
src_endpoint.location.lat
  • Description: The geographical Latitude coordinate represented in Decimal Degrees (DD). For example: 42.361145.
  • Source: geoip.latitude
  • Transform:
  • geoip.latitude → double (all events in this service)
  • Usage: all events in this service
src_endpoint.location.long
  • Description: The geographical Longitude coordinate represented in Decimal Degrees (DD). For example: -71.057083.
  • Source: geoip.longitude
  • Transform:
  • geoip.longitude → double (all events in this service)
  • Usage: all events in this service
src_endpoint.location.region
  • Description: The alphanumeric code that identifies the principal subdivision (e.g. province or state) of the country. For example, 'CH-VD' for the Canton of Vaud, Switzerland
  • Source: geoip.region_code
  • Usage: all events in this service

Http Request

http_request.user_agent
  • Description: The request header that identifies the operating system and web browser.
  • Source: user_agent
  • Usage: all events in this service

Observables

observables[].name
  • Description: The full name of the observable attribute. The name is a pointer/reference to an attribute within the OCSF event data. For example: file.name. Array attributes may be represented in one of three ways. For example: resources.uid, resources[].uid, resources[0].uid.
  • Literal: actor.user.email_addr, actor.user.uid, http_request.user_agent, src_endpoint.ip, src_endpoint.location.country
  • Usage: all events in this service
observables[].type_id
  • Description: The observable value type identifier.
  • Literal: 14, 16, 2, 31, 5
  • Usage: all events in this service
observables[].value
  • Description: The value associated with the observable attribute. The meaning of the value depends on the observable type.
    If the name refers to a scalar attribute, then the value is the value of the attribute.
    If the name refers to an object attribute, then the value is not populated.
  • Source: client_ip, geoip.country_code, initiated_by.email, initiated_by.id, user_agent
  • Usage: all events in this service

Unmapped

unmapped.@version
  • Description: JumpCloud Directory Insights field @version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: @version
  • Usage: all events in this service
unmapped.asn.error
  • Description: JumpCloud Directory Insights field asn.error preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: asn.error
  • Usage: genai_ai_assistant_chat_created
unmapped.asn.ip_address
  • Description: JumpCloud Directory Insights field asn.ip_address preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: asn.ip_address
  • Usage: genai_ai_assistant_chat_created
unmapped.asn.network
  • Description: JumpCloud Directory Insights field asn.network preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: asn.network
  • Usage: 11 events (missing: genai_ai_assistant_chat_message_sent)
unmapped.geoip.region_name
  • Description: JumpCloud Directory Insights field geoip.region_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.region_name
  • Usage: all events in this service
unmapped.geoip.timezone
  • Description: JumpCloud Directory Insights field geoip.timezone preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.timezone
  • Usage: all events in this service
unmapped.initiated_by_email_hash
  • Description: JumpCloud Directory Insights field initiated_by_email_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_email_hash
  • Usage: all events in this service
unmapped.initiated_by_id_hash
  • Description: JumpCloud Directory Insights field initiated_by_id_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_id_hash
  • Usage: all events in this service
unmapped.is_out_of_bound
  • Description: JumpCloud Directory Insights field is_out_of_bound preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: is_out_of_bound
  • Usage: all events in this service
unmapped.jc_application_name
  • Description: JumpCloud Directory Insights field jc_application_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_application_name
  • Usage: all events in this service
unmapped.jc_initiated_by_email
  • Description: JumpCloud Directory Insights field jc_initiated_by_email preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_initiated_by_email
  • Usage: genai_ai_assistant_chat_deleted, genai_ai_assistant_chat_updated, genai_ai_assistant_memory_deleted, genai_ai_assistant_org_rule_created, genai_ai_assistant_org_rule_deleted, genai_ai_assistant_org_settings_updated, genai_ai_search_executed, genai_mcp_manual_revoked, genai_mcp_session_created
unmapped.jc_initiated_by_id
  • Description: JumpCloud Directory Insights field jc_initiated_by_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_initiated_by_id
  • Usage: genai_ai_assistant_chat_deleted, genai_ai_assistant_chat_updated, genai_ai_assistant_memory_deleted, genai_ai_assistant_org_rule_created, genai_ai_assistant_org_rule_deleted, genai_ai_assistant_org_settings_updated, genai_ai_search_executed, genai_mcp_manual_revoked, genai_mcp_session_created
unmapped.jc_initiated_by_username
  • Description: JumpCloud Directory Insights field jc_initiated_by_username preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_initiated_by_username
  • Usage: genai_ai_assistant_chat_deleted, genai_ai_assistant_chat_updated, genai_ai_assistant_memory_deleted, genai_ai_assistant_org_rule_created, genai_ai_assistant_org_rule_deleted, genai_ai_assistant_org_settings_updated, genai_ai_search_executed, genai_mcp_manual_revoked, genai_mcp_session_created
unmapped.jc_organization_name
  • Description: JumpCloud Directory Insights field jc_organization_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_organization_name
  • Usage: genai_ai_assistant_chat_deleted, genai_ai_assistant_chat_updated, genai_ai_assistant_memory_deleted, genai_ai_assistant_org_rule_created, genai_ai_assistant_org_rule_deleted, genai_ai_assistant_org_settings_updated, genai_ai_search_executed, genai_mcp_manual_revoked, genai_mcp_session_created
unmapped.jc_provider_id
  • Description: JumpCloud Directory Insights field jc_provider_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_provider_id
  • Usage: genai_ai_assistant_chat_updated, genai_ai_assistant_memory_deleted, genai_mcp_manual_revoked, genai_mcp_session_created
unmapped.jc_system_display_name
  • Description: JumpCloud Directory Insights field jc_system_display_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_system_display_name
  • Usage: genai_ai_assistant_chat_deleted, genai_ai_assistant_chat_updated, genai_ai_assistant_memory_deleted, genai_ai_assistant_org_rule_created, genai_ai_assistant_org_rule_deleted, genai_ai_assistant_org_settings_updated, genai_ai_search_executed, genai_mcp_manual_revoked, genai_mcp_session_created
unmapped.jc_system_hostname
  • Description: JumpCloud Directory Insights field jc_system_hostname preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_system_hostname
  • Usage: genai_ai_assistant_chat_deleted, genai_ai_assistant_chat_updated, genai_ai_assistant_memory_deleted, genai_ai_assistant_org_rule_created, genai_ai_assistant_org_rule_deleted, genai_ai_assistant_org_settings_updated, genai_ai_search_executed, genai_mcp_manual_revoked, genai_mcp_session_created
unmapped.provider
  • Description: JumpCloud Directory Insights field provider preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: provider
  • Usage: all events in this service
unmapped.resource_id_hash
  • Description: JumpCloud Directory Insights field resource_id_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource_id_hash
  • Usage: all events in this service
unmapped.resource_name_hash
  • Description: JumpCloud Directory Insights field resource_name_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource_name_hash
  • Usage: genai_ai_assistant_chat_deleted, genai_ai_assistant_chat_updated, genai_ai_assistant_memory_deleted, genai_ai_assistant_org_rule_created, genai_ai_assistant_org_rule_deleted, genai_mcp_manual_revoked, genai_mcp_session_created
unmapped.useragent.device
  • Description: JumpCloud Directory Insights field useragent.device preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.device
  • Usage: all events in this service
unmapped.useragent.major
  • Description: JumpCloud Directory Insights field useragent.major preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.major
  • Usage: all events in this service
unmapped.useragent.minor
  • Description: JumpCloud Directory Insights field useragent.minor preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.minor
  • Usage: all events in this service
unmapped.useragent.name
  • Description: JumpCloud Directory Insights field useragent.name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.name
  • Usage: all events in this service
unmapped.useragent.os
  • Description: JumpCloud Directory Insights field useragent.os preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os
  • Usage: all events in this service
unmapped.useragent.os_full
  • Description: JumpCloud Directory Insights field useragent.os_full preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_full
  • Usage: all events in this service
unmapped.useragent.os_major
  • Description: JumpCloud Directory Insights field useragent.os_major preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_major
  • Usage: all events in this service
unmapped.useragent.os_minor
  • Description: JumpCloud Directory Insights field useragent.os_minor preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_minor
  • Usage: all events in this service
unmapped.useragent.os_name
  • Description: JumpCloud Directory Insights field useragent.os_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_name
  • Usage: all events in this service
unmapped.useragent.os_patch
  • Description: JumpCloud Directory Insights field useragent.os_patch preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_patch
  • Usage: all events in this service
unmapped.useragent.os_version
  • Description: JumpCloud Directory Insights field useragent.os_version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_version
  • Usage: all events in this service
unmapped.useragent.patch
  • Description: JumpCloud Directory Insights field useragent.patch preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.patch
  • Usage: all events in this service
unmapped.useragent.version
  • Description: JumpCloud Directory Insights field useragent.version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.version
  • Usage: all events in this service

Generic Directory Insights#

generic_di · 2 events

Event Category Class Activity Type UID Fields
risk_event_created Findings (2) Detection Finding (2004) Create (1) 200401 69
risk_event_resolved Identity & Access Management (3) Entity Management (3004) Update (3) 300403 59

OCSF field mappings#

Legend

  • Description: what the OCSF field represents (from OCSF schema v1.8.0)
  • Source: raw JumpCloud event field(s) mapped via ${{placeholder}} template
  • Transform: fieldMappings entry applied at runtime (cast, enum, etc.)
  • Literal: static value set in the mapping template
  • Usage: event types in this service that include this field

Core

activity_id
  • Description: The normalized identifier of the activity that triggered the event.
  • Literal: 1, 3
  • Usage: all events in this service
activity_name
  • Description: The event activity name, as defined by the activity_id.
  • Literal: Create, Update
  • Usage: all events in this service
category_name
  • Description: The event category name, as defined by category_uid value: Discovery.
  • Literal: Findings, Identity & Access Management
  • Usage: all events in this service
category_uid
  • Description: The category unique identifier of the event.
  • Literal: 2, 3
  • Usage: all events in this service
class_name
  • Description: The event class name, as defined by class_uid value: User Inventory Info.
  • Literal: Detection Finding, Entity Management
  • Usage: all events in this service
class_uid
  • Description: The unique identifier of a class. A class describes the attributes available in an event.
  • Literal: 2004, 3004
  • Usage: all events in this service
severity_id
  • Description: OCSF severity identifier for the event.
  • Literal: 1
  • Usage: all events in this service
status_detail
  • Description: The status detail contains additional information about the event/finding outcome.
  • Source: error_message
  • Usage: all events in this service
status_id
  • Description: Normalized status of the activity (1=Success, 2=Failure).
  • Source: success
  • Transform:
  • success → boolean_to_status_id; true→1, false→2 (all events in this service)
  • Usage: all events in this service
time
  • Description: Event time, in epoch milliseconds (OCSF time).
  • Source: timestamp
  • Transform:
  • timestamp → iso8601_to_epoch_millis (all events in this service)
  • Usage: all events in this service
type_uid
  • Description: The event/finding type ID. It identifies the event's semantics and structure. The value is calculated by the logging system as: class_uid * 100 + activity_id.
  • Literal: 200401, 300403
  • Usage: all events in this service

Metadata

metadata.event_code
  • Description: JumpCloud event type code.
  • Source: event_type
  • Usage: all events in this service
metadata.original_time
  • Description: The original event time as reported by the event source. For example, the time in the original format from system event log such as Syslog on Unix/Linux and the System event file on Windows. Omit if event is generated instead of collected via logs.
  • Source: server_timestamp
  • Usage: all events in this service
metadata.processed_time
  • Description: The event processed time, such as an ETL operation.
  • Source: jc_transformation_ts
  • Usage: all events in this service
metadata.product.name
  • Description: Originating JumpCloud service that produced the event.
  • Source: service
  • Usage: all events in this service
metadata.tenant_uid
  • Description: JumpCloud organization (tenant) identifier.
  • Source: organization
  • Usage: all events in this service
metadata.uid
  • Description: Unique event identifier assigned by JumpCloud.
  • Source: id
  • Usage: all events in this service
metadata.version
  • Description: OCSF schema version used for this event.
  • Literal: 1.8.0
  • Usage: all events in this service

Actor

actor.user.email_addr
  • Description: Email address of the actor who initiated the event.
  • Source: initiated_by.email
  • Usage: risk_event_resolved
actor.user.type_id
  • Description: OCSF user type of the actor (1=User, 2=Admin, 3=System, 4=Service).
  • Source: initiated_by.type
  • Transform:
  • initiated_by.type → enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (all events in this service)
  • Usage: all events in this service
actor.user.uid
  • Description: Unique identifier of the actor who initiated the event.
  • Source: initiated_by.id
  • Usage: risk_event_resolved

Entity

entity.data.changes_from
  • Description: JumpCloud extension data on the managed entity: changes_from.
  • Source: changes.from
  • Usage: risk_event_resolved
entity.name
  • Description: The name of the managed entity. It should match the name of the specific entity object's name if populated, or the name of the managed entity if the type_id is 'Other'.
  • Source: resource.name
  • Usage: risk_event_resolved
entity.type
  • Description: The managed entity type. For example: Policy, User, Organization, Device.
  • Source: resource.type
  • Usage: risk_event_resolved
entity.uid
  • Description: The identifier of the managed entity. It should match the uid of the specific entity's object UID if populated, or the source specific ID if the type_id is 'Other'.
  • Source: resource.id
  • Usage: risk_event_resolved
entity_result.data.changes_to
  • Description: JumpCloud extension data on the managed entity: changes_to.
  • Source: changes.to
  • Usage: risk_event_resolved
entity_result.data.resolution_status
  • Description: JumpCloud extension data on the managed entity: resolution_status.
  • Source: resource.context.resolution_status
  • Usage: risk_event_resolved

Src Endpoint

src_endpoint.autonomous_system.name
  • Description: Organization name for the Autonomous System.
  • Source: asn.organization
  • Usage: risk_event_resolved
src_endpoint.autonomous_system.number
  • Description: Unique number that the AS is identified by.
  • Source: asn.number
  • Usage: risk_event_resolved
src_endpoint.ip
  • Description: Source IP address the request originated from.
  • Source: client_ip
  • Usage: risk_event_resolved
src_endpoint.location.city
  • Description: The name of the city.
  • Source: geoip.city
  • Usage: risk_event_resolved
src_endpoint.location.continent
  • Description: The name of the continent.
  • Source: geoip.continent_code
  • Usage: risk_event_resolved
src_endpoint.location.country
  • Description: The ISO 3166-1 Alpha-2 country code.

    Note: The two letter country code should be capitalized. For example: US or CA.

  • Source: geoip.country_code
  • Usage: risk_event_resolved
src_endpoint.location.lat
  • Description: The geographical Latitude coordinate represented in Decimal Degrees (DD). For example: 42.361145.
  • Source: geoip.latitude
  • Transform:
  • geoip.latitude → double (risk_event_resolved)
  • Usage: risk_event_resolved
src_endpoint.location.long
  • Description: The geographical Longitude coordinate represented in Decimal Degrees (DD). For example: -71.057083.
  • Source: geoip.longitude
  • Transform:
  • geoip.longitude → double (risk_event_resolved)
  • Usage: risk_event_resolved
src_endpoint.location.region
  • Description: The alphanumeric code that identifies the principal subdivision (e.g. province or state) of the country. For example, 'CH-VD' for the Canton of Vaud, Switzerland
  • Source: geoip.region_code
  • Usage: risk_event_resolved

Http Request

http_request.user_agent
  • Description: The request header that identifies the operating system and web browser.
  • Source: user_agent
  • Usage: risk_event_resolved

Observables

observables[].name
  • Description: The full name of the observable attribute. The name is a pointer/reference to an attribute within the OCSF event data. For example: file.name. Array attributes may be represented in one of three ways. For example: resources.uid, resources[].uid, resources[0].uid.
  • Literal: actor.user.email_addr, actor.user.uid, http_request.user_agent, src_endpoint.ip, src_endpoint.location.country
  • Usage: risk_event_resolved
observables[].type_id
  • Description: The observable value type identifier.
  • Literal: 14, 16, 2, 31, 5
  • Usage: risk_event_resolved
observables[].value
  • Description: The value associated with the observable attribute. The meaning of the value depends on the observable type.
    If the name refers to a scalar attribute, then the value is the value of the attribute.
    If the name refers to an object attribute, then the value is not populated.
  • Source: client_ip, geoip.country_code, initiated_by.email, initiated_by.id, user_agent
  • Usage: risk_event_resolved

Other

finding_info.title
  • Description: A title or a brief phrase summarizing the reported finding.
  • Source: resource.name
  • Usage: risk_event_created
finding_info.uid
  • Description: The unique identifier of the reported finding.
  • Source: resource.id
  • Usage: risk_event_created
risk_level
  • Description: The risk level, normalized to the caption of the risk_level_id value.
  • Source: resource.context.risk_severity
  • Usage: risk_event_created
risk_score
  • Description: The risk score as reported by the event source.
  • Source: resource.context.risk_score
  • Usage: risk_event_created

Unmapped

unmapped.@version
  • Description: JumpCloud Directory Insights field @version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: @version
  • Usage: all events in this service
unmapped.asn.network
  • Description: JumpCloud Directory Insights field asn.network preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: asn.network
  • Usage: risk_event_resolved
unmapped.changes.field
  • Description: JumpCloud Directory Insights field changes.field preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.field
  • Usage: risk_event_resolved
unmapped.client_ip
  • Description: JumpCloud Directory Insights field client_ip preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: client_ip
  • Usage: risk_event_created
unmapped.geoip.region_name
  • Description: JumpCloud Directory Insights field geoip.region_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.region_name
  • Usage: risk_event_resolved
unmapped.geoip.timezone
  • Description: JumpCloud Directory Insights field geoip.timezone preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.timezone
  • Usage: risk_event_resolved
unmapped.initiated_by_email_hash
  • Description: JumpCloud Directory Insights field initiated_by_email_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_email_hash
  • Usage: risk_event_resolved
unmapped.initiated_by_id_hash
  • Description: JumpCloud Directory Insights field initiated_by_id_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_id_hash
  • Usage: risk_event_resolved
unmapped.is_out_of_bound
  • Description: JumpCloud Directory Insights field is_out_of_bound preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: is_out_of_bound
  • Usage: all events in this service
unmapped.jc_application_name
  • Description: JumpCloud Directory Insights field jc_application_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_application_name
  • Usage: all events in this service
unmapped.jc_initiated_by_email
  • Description: JumpCloud Directory Insights field jc_initiated_by_email preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_initiated_by_email
  • Usage: risk_event_resolved
unmapped.jc_initiated_by_id
  • Description: JumpCloud Directory Insights field jc_initiated_by_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_initiated_by_id
  • Usage: risk_event_resolved
unmapped.jc_initiated_by_username
  • Description: JumpCloud Directory Insights field jc_initiated_by_username preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_initiated_by_username
  • Usage: risk_event_resolved
unmapped.jc_organization_name
  • Description: JumpCloud Directory Insights field jc_organization_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_organization_name
  • Usage: risk_event_resolved
unmapped.jc_system_display_name
  • Description: JumpCloud Directory Insights field jc_system_display_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_system_display_name
  • Usage: risk_event_resolved
unmapped.jc_system_hostname
  • Description: JumpCloud Directory Insights field jc_system_hostname preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_system_hostname
  • Usage: risk_event_resolved
unmapped.resource.context.identity_identifier
  • Description: JumpCloud Directory Insights field resource.context.identity_identifier preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.identity_identifier
  • Usage: risk_event_created
unmapped.resource.context.identity_object_id
  • Description: JumpCloud Directory Insights field resource.context.identity_object_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.identity_object_id
  • Usage: risk_event_created
unmapped.resource.context.identity_type
  • Description: JumpCloud Directory Insights field resource.context.identity_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.identity_type
  • Usage: risk_event_created
unmapped.resource.context.resolution_state
  • Description: JumpCloud Directory Insights field resource.context.resolution_state preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.resolution_state
  • Usage: risk_event_created
unmapped.resource.context.resolution_status
  • Description: JumpCloud Directory Insights field resource.context.resolution_status preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.resolution_status
  • Usage: risk_event_created
unmapped.resource.context.risk_event_factors.description
  • Description: JumpCloud Directory Insights field resource.context.risk_event_factors.description preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.risk_event_factors.description
  • Usage: risk_event_created
unmapped.resource.context.risk_event_factors.metadata.application_id
  • Description: JumpCloud Directory Insights field resource.context.risk_event_factors.metadata.application_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.risk_event_factors.metadata.application_id
  • Usage: risk_event_created
unmapped.resource.context.risk_event_factors.metadata.application_name
  • Description: JumpCloud Directory Insights field resource.context.risk_event_factors.metadata.application_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.risk_event_factors.metadata.application_name
  • Usage: risk_event_created
unmapped.resource.context.risk_event_factors.metadata.baseline_mean
  • Description: JumpCloud Directory Insights field resource.context.risk_event_factors.metadata.baseline_mean preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.risk_event_factors.metadata.baseline_mean
  • Usage: risk_event_created
unmapped.resource.context.risk_event_factors.metadata.browser_name
  • Description: JumpCloud Directory Insights field resource.context.risk_event_factors.metadata.browser_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.risk_event_factors.metadata.browser_name
  • Usage: risk_event_created
unmapped.resource.context.risk_event_factors.metadata.current_failures
  • Description: JumpCloud Directory Insights field resource.context.risk_event_factors.metadata.current_failures preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.risk_event_factors.metadata.current_failures
  • Usage: risk_event_created
unmapped.resource.context.risk_event_factors.metadata.current_total
  • Description: JumpCloud Directory Insights field resource.context.risk_event_factors.metadata.current_total preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.risk_event_factors.metadata.current_total
  • Usage: risk_event_created
unmapped.resource.context.risk_event_factors.metadata.days_since_last_login
  • Description: JumpCloud Directory Insights field resource.context.risk_event_factors.metadata.days_since_last_login preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.risk_event_factors.metadata.days_since_last_login
  • Usage: risk_event_created
unmapped.resource.context.risk_event_factors.metadata.device_id
  • Description: JumpCloud Directory Insights field resource.context.risk_event_factors.metadata.device_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.risk_event_factors.metadata.device_id
  • Usage: risk_event_created
unmapped.resource.context.risk_event_factors.metadata.device_type
  • Description: JumpCloud Directory Insights field resource.context.risk_event_factors.metadata.device_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.risk_event_factors.metadata.device_type
  • Usage: risk_event_created
unmapped.resource.context.risk_event_factors.metadata.dormant_threshold_days
  • Description: JumpCloud Directory Insights field resource.context.risk_event_factors.metadata.dormant_threshold_days preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.risk_event_factors.metadata.dormant_threshold_days
  • Usage: risk_event_created
unmapped.resource.context.risk_event_factors.metadata.geoip_timezone_raw
  • Description: JumpCloud Directory Insights field resource.context.risk_event_factors.metadata.geoip_timezone_raw preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.risk_event_factors.metadata.geoip_timezone_raw
  • Usage: risk_event_created
unmapped.resource.context.risk_event_factors.metadata.hour_via_time_stats
  • Description: JumpCloud Directory Insights field resource.context.risk_event_factors.metadata.hour_via_time_stats preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.risk_event_factors.metadata.hour_via_time_stats
  • Usage: risk_event_created
unmapped.resource.context.risk_event_factors.metadata.last_successful_login
  • Description: JumpCloud Directory Insights field resource.context.risk_event_factors.metadata.last_successful_login preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.risk_event_factors.metadata.last_successful_login
  • Usage: risk_event_created
unmapped.resource.context.risk_event_factors.metadata.local_datetime
  • Description: JumpCloud Directory Insights field resource.context.risk_event_factors.metadata.local_datetime preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.risk_event_factors.metadata.local_datetime
  • Usage: risk_event_created
unmapped.resource.context.risk_event_factors.metadata.local_hour
  • Description: JumpCloud Directory Insights field resource.context.risk_event_factors.metadata.local_hour preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.risk_event_factors.metadata.local_hour
  • Usage: risk_event_created
unmapped.resource.context.risk_event_factors.metadata.min_required
  • Description: JumpCloud Directory Insights field resource.context.risk_event_factors.metadata.min_required preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.risk_event_factors.metadata.min_required
  • Usage: risk_event_created
unmapped.resource.context.risk_event_factors.metadata.multiplier
  • Description: JumpCloud Directory Insights field resource.context.risk_event_factors.metadata.multiplier preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.risk_event_factors.metadata.multiplier
  • Usage: risk_event_created
unmapped.resource.context.risk_event_factors.metadata.novel_hour
  • Description: JumpCloud Directory Insights field resource.context.risk_event_factors.metadata.novel_hour preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.risk_event_factors.metadata.novel_hour
  • Usage: risk_event_created
unmapped.resource.context.risk_event_factors.metadata.novel_weekday
  • Description: JumpCloud Directory Insights field resource.context.risk_event_factors.metadata.novel_weekday preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.risk_event_factors.metadata.novel_weekday
  • Usage: risk_event_created
unmapped.resource.context.risk_event_factors.metadata.os_name
  • Description: JumpCloud Directory Insights field resource.context.risk_event_factors.metadata.os_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.risk_event_factors.metadata.os_name
  • Usage: risk_event_created
unmapped.resource.context.risk_event_factors.metadata.threshold
  • Description: JumpCloud Directory Insights field resource.context.risk_event_factors.metadata.threshold preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.risk_event_factors.metadata.threshold
  • Usage: risk_event_created
unmapped.resource.context.risk_event_factors.metadata.timezone
  • Description: JumpCloud Directory Insights field resource.context.risk_event_factors.metadata.timezone preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.risk_event_factors.metadata.timezone
  • Usage: risk_event_created
unmapped.resource.context.risk_event_factors.metadata.ua_composite
  • Description: JumpCloud Directory Insights field resource.context.risk_event_factors.metadata.ua_composite preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.risk_event_factors.metadata.ua_composite
  • Usage: risk_event_created
unmapped.resource.context.risk_event_factors.metadata.utc_datetime
  • Description: JumpCloud Directory Insights field resource.context.risk_event_factors.metadata.utc_datetime preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.risk_event_factors.metadata.utc_datetime
  • Usage: risk_event_created
unmapped.resource.context.risk_event_factors.metadata.utc_hour
  • Description: JumpCloud Directory Insights field resource.context.risk_event_factors.metadata.utc_hour preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.risk_event_factors.metadata.utc_hour
  • Usage: risk_event_created
unmapped.resource.context.risk_event_factors.metadata.weekday_key
  • Description: JumpCloud Directory Insights field resource.context.risk_event_factors.metadata.weekday_key preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.risk_event_factors.metadata.weekday_key
  • Usage: risk_event_created
unmapped.resource.context.risk_event_factors.metadata.weekday_via_time_stats
  • Description: JumpCloud Directory Insights field resource.context.risk_event_factors.metadata.weekday_via_time_stats preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.risk_event_factors.metadata.weekday_via_time_stats
  • Usage: risk_event_created
unmapped.resource.context.risk_event_factors.severity
  • Description: JumpCloud Directory Insights field resource.context.risk_event_factors.severity preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.risk_event_factors.severity
  • Usage: risk_event_created
unmapped.resource.context.risk_event_factors.type
  • Description: JumpCloud Directory Insights field resource.context.risk_event_factors.type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.risk_event_factors.type
  • Usage: risk_event_created
unmapped.resource.context.risk_event_factors.weight
  • Description: JumpCloud Directory Insights field resource.context.risk_event_factors.weight preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.risk_event_factors.weight
  • Usage: risk_event_created
unmapped.resource.context.risk_event_object_id
  • Description: JumpCloud Directory Insights field resource.context.risk_event_object_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.risk_event_object_id
  • Usage: all events in this service
unmapped.resource.context.source_event_object_id
  • Description: JumpCloud Directory Insights field resource.context.source_event_object_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.source_event_object_id
  • Usage: risk_event_created
unmapped.resource.type
  • Description: JumpCloud Directory Insights field resource.type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.type
  • Usage: risk_event_created
unmapped.resource_id_hash
  • Description: JumpCloud Directory Insights field resource_id_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource_id_hash
  • Usage: all events in this service
unmapped.resource_name_hash
  • Description: JumpCloud Directory Insights field resource_name_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource_name_hash
  • Usage: risk_event_resolved
unmapped.timestamp_source
  • Description: JumpCloud Directory Insights field timestamp_source preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: timestamp_source
  • Usage: all events in this service
unmapped.user_agent
  • Description: JumpCloud Directory Insights field user_agent preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: user_agent
  • Usage: risk_event_created

LDAP#

ldap · 2 events

Event Category Class Activity Type UID Fields
ldap_bind Identity & Access Management (3) Authentication (3002) Logon (1) 300201 48
ldap_srch Application Activity (6) Datastore Activity (6005) Query (4) 600504 44

OCSF field mappings#

Legend

  • Description: what the OCSF field represents (from OCSF schema v1.8.0)
  • Source: raw JumpCloud event field(s) mapped via ${{placeholder}} template
  • Transform: fieldMappings entry applied at runtime (cast, enum, etc.)
  • Literal: static value set in the mapping template
  • Usage: event types in this service that include this field

Core

activity_id
  • Description: The normalized identifier of the activity that triggered the event.
  • Literal: 1, 4
  • Usage: all events in this service
activity_name
  • Description: The event activity name, as defined by the activity_id.
  • Literal: Logon, Query
  • Usage: all events in this service
category_name
  • Description: The event category name, as defined by category_uid value: Discovery.
  • Literal: Application Activity, Identity & Access Management
  • Usage: all events in this service
category_uid
  • Description: The category unique identifier of the event.
  • Literal: 3, 6
  • Usage: all events in this service
class_name
  • Description: The event class name, as defined by class_uid value: User Inventory Info.
  • Literal: Authentication, Datastore Activity
  • Usage: all events in this service
class_uid
  • Description: The unique identifier of a class. A class describes the attributes available in an event.
  • Literal: 3002, 6005
  • Usage: all events in this service
severity_id
  • Description: OCSF severity identifier for the event.
  • Literal: 1
  • Usage: all events in this service
status_detail
  • Description: The status detail contains additional information about the event/finding outcome.
  • Source: error_message
  • Usage: all events in this service
status_id
  • Description: Normalized status of the activity (1=Success, 2=Failure).
  • Source: success
  • Transform:
  • success → boolean_to_status_id; true→1, false→2 (ldap_bind)
  • Usage: ldap_bind
time
  • Description: Event time, in epoch milliseconds (OCSF time).
  • Source: timestamp
  • Transform:
  • timestamp → iso8601_to_epoch_millis (all events in this service)
  • Usage: all events in this service
type_uid
  • Description: The event/finding type ID. It identifies the event's semantics and structure. The value is calculated by the logging system as: class_uid * 100 + activity_id.
  • Literal: 300201, 600504
  • Usage: all events in this service

Metadata

metadata.event_code
  • Description: JumpCloud event type code.
  • Source: event_type
  • Usage: all events in this service
metadata.processed_time
  • Description: The event processed time, such as an ETL operation.
  • Source: jc_transformation_ts
  • Usage: all events in this service
metadata.product.name
  • Description: Originating JumpCloud service that produced the event.
  • Source: service
  • Usage: all events in this service
metadata.tenant_uid
  • Description: JumpCloud organization (tenant) identifier.
  • Source: organization
  • Usage: all events in this service
metadata.uid
  • Description: Unique event identifier assigned by JumpCloud.
  • Source: id
  • Usage: all events in this service
metadata.version
  • Description: OCSF schema version used for this event.
  • Literal: 1.8.0
  • Usage: all events in this service

Actor

actor.user.name
  • Description: Display name of the actor who initiated the event.
  • Source: initiated_by.username, username
  • Usage: all events in this service
actor.user.type_id
  • Description: OCSF user type of the actor (1=User, 2=Admin, 3=System, 4=Service).
  • Source: initiated_by.type
  • Transform:
  • initiated_by.type → enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (all events in this service)
  • Usage: all events in this service

User

user.name
  • Description: The username. For example, janedoe1.
  • Source: username
  • Usage: ldap_bind
user.uid
  • Description: Unique identifier of the user associated with the event.
  • Source: dn
  • Usage: ldap_bind

Src Endpoint

src_endpoint.ip
  • Description: Source IP address the request originated from.
  • Source: client_ip
  • Usage: all events in this service
src_endpoint.location.city
  • Description: The name of the city.
  • Source: geoip.city
  • Usage: ldap_bind
src_endpoint.location.continent
  • Description: The name of the continent.
  • Source: geoip.continent_code
  • Usage: ldap_bind
src_endpoint.location.country
  • Description: The ISO 3166-1 Alpha-2 country code.

    Note: The two letter country code should be capitalized. For example: US or CA.

  • Source: geoip.country_code
  • Usage: ldap_bind
src_endpoint.location.lat
  • Description: The geographical Latitude coordinate represented in Decimal Degrees (DD). For example: 42.361145.
  • Source: geoip.latitude
  • Transform:
  • geoip.latitude → double (ldap_bind)
  • Usage: ldap_bind
src_endpoint.location.long
  • Description: The geographical Longitude coordinate represented in Decimal Degrees (DD). For example: -71.057083.
  • Source: geoip.longitude
  • Transform:
  • geoip.longitude → double (ldap_bind)
  • Usage: ldap_bind
src_endpoint.location.region
  • Description: The alphanumeric code that identifies the principal subdivision (e.g. province or state) of the country. For example, 'CH-VD' for the Canton of Vaud, Switzerland
  • Source: geoip.region_code
  • Usage: ldap_bind

Http Request

http_request.user_agent
  • Description: The request header that identifies the operating system and web browser.
  • Source: user_agent
  • Usage: all events in this service

Observables

observables[].name
  • Description: The full name of the observable attribute. The name is a pointer/reference to an attribute within the OCSF event data. For example: file.name. Array attributes may be represented in one of three ways. For example: resources.uid, resources[].uid, resources[0].uid.
  • Literal: actor.user.name, http_request.user_agent, src_endpoint.ip, src_endpoint.location.country, user.name, user.uid
  • Usage: all events in this service
observables[].type_id
  • Description: The observable value type identifier.
  • Literal: 14, 16, 2, 31, 4
  • Usage: all events in this service
observables[].value
  • Description: The value associated with the observable attribute. The meaning of the value depends on the observable type.
    If the name refers to a scalar attribute, then the value is the value of the attribute.
    If the name refers to an object attribute, then the value is not populated.
  • Source: client_ip, dn, geoip.country_code, initiated_by.username, user_agent, username
  • Usage: all events in this service

Other

api.operation
  • Description: Verb/Operation associated with the request
  • Source: operation_type
  • Usage: ldap_srch
api.request.uid
  • Description: The unique request identifier.
  • Source: connection_id
  • Usage: ldap_srch
auth_protocol
  • Description: The authentication protocol as defined by the caption of auth_protocol_id. In the case of Other, it is defined by the event source.
  • Source: auth_method
  • Usage: ldap_bind
count
  • Description: The number of times that events in the same logical group occurred during the event Start Time to End Time period.
  • Source: number_of_results
  • Usage: ldap_srch
database.name
  • Description: The database name, ordinarily as assigned by a database administrator.
  • Source: service
  • Usage: ldap_srch
logon_type
  • Description: The logon type, normalized to the caption of the logon_type_id value. In the case of 'Other', it is defined by the event source.
  • Source: mech
  • Usage: ldap_bind
session.uid
  • Description: The unique identifier of the session.
  • Source: connection_id
  • Usage: ldap_bind
status_code
  • Description: The event status code, as reported by the event source.

    For example, in a Windows Failed Authentication event, this would be the value of 'Failure Code', e.g. 0x18.
  • Source: error_code
  • Usage: all events in this service

Unmapped

unmapped.@version
  • Description: JumpCloud Directory Insights field @version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: @version
  • Usage: all events in this service
unmapped.attr
  • Description: JumpCloud Directory Insights field attr preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: attr
  • Usage: ldap_srch
unmapped.auth_meta.auth_methods.password.success
  • Description: JumpCloud Directory Insights field auth_meta.auth_methods.password.success preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: auth_meta.auth_methods.password.success
  • Usage: ldap_bind
unmapped.base
  • Description: JumpCloud Directory Insights field base preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: base
  • Usage: ldap_srch
unmapped.deref
  • Description: JumpCloud Directory Insights field deref preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: deref
  • Usage: ldap_srch
unmapped.dn
  • Description: JumpCloud Directory Insights field dn preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: dn
  • Usage: ldap_srch
unmapped.filter
  • Description: JumpCloud Directory Insights field filter preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: filter
  • Usage: ldap_srch
unmapped.geoip.region_name
  • Description: JumpCloud Directory Insights field geoip.region_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.region_name
  • Usage: ldap_bind
unmapped.geoip.timezone
  • Description: JumpCloud Directory Insights field geoip.timezone preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.timezone
  • Usage: ldap_bind
unmapped.initiated_by.username
  • Description: JumpCloud Directory Insights field initiated_by.username preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by.username
  • Usage: ldap_srch
unmapped.initiated_by_username_hash
  • Description: JumpCloud Directory Insights field initiated_by_username_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_username_hash
  • Usage: all events in this service
unmapped.is_out_of_bound
  • Description: JumpCloud Directory Insights field is_out_of_bound preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: is_out_of_bound
  • Usage: all events in this service
unmapped.jc_application_name
  • Description: JumpCloud Directory Insights field jc_application_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_application_name
  • Usage: all events in this service
unmapped.operation_number
  • Description: JumpCloud Directory Insights field operation_number preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: operation_number
  • Usage: all events in this service
unmapped.operation_type
  • Description: JumpCloud Directory Insights field operation_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: operation_type
  • Usage: ldap_bind
unmapped.scope
  • Description: JumpCloud Directory Insights field scope preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: scope
  • Usage: ldap_srch
unmapped.start_tls
  • Description: JumpCloud Directory Insights field start_tls preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: start_tls
  • Usage: all events in this service
unmapped.success
  • Description: JumpCloud Directory Insights field success preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: success
  • Usage: ldap_srch
unmapped.tls_established
  • Description: JumpCloud Directory Insights field tls_established preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: tls_established
  • Usage: all events in this service
unmapped.username_hash
  • Description: JumpCloud Directory Insights field username_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: username_hash
  • Usage: all events in this service

MDM#

mdm · 11 events

Event Category Class Activity Type UID Fields
apple_ddm_status_receive Discovery (5) Device Config State Change (5019) Collect (2) 501902 110
apple_mdm_service_discovery Discovery (5) Device Config State Change (5019) Log (1) 501901 37
apple_policy_dispatch System Activity (1) Scheduled Job Activity (1006) Start (6) 100606 40
applemdm_commands_clearactivationlock Identity & Access Management (3) Entity Management (3004) Update (3) 300403 57
applemdm_devicemanagers_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 46
applemdm_devicemanagers_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 49
applemdm_devicemanagers_patch Identity & Access Management (3) Entity Management (3004) Update (3) 300403 62
applemdm_volumepurchaseprogram_locationspost Identity & Access Management (3) Entity Management (3004) Create (1) 300401 61
configuration_file_download Identity & Access Management (3) Entity Management (3004) Read (2) 300402 57
device_enrollment Identity & Access Management (3) Entity Management (3004) Enroll (6) 300406 49
mdm_command_result System Activity (1) Scheduled Job Activity (1006) Start (6) 100606 74

OCSF field mappings#

Legend

  • Description: what the OCSF field represents (from OCSF schema v1.8.0)
  • Source: raw JumpCloud event field(s) mapped via ${{placeholder}} template
  • Transform: fieldMappings entry applied at runtime (cast, enum, etc.)
  • Literal: static value set in the mapping template
  • Usage: event types in this service that include this field

Core

activity_id
  • Description: The normalized identifier of the activity that triggered the event.
  • Literal: 1, 2, 3, 4, 6
  • Usage: all events in this service
activity_name
  • Description: The event activity name, as defined by the activity_id.
  • Literal: Collect, Create, Delete, Enroll, Log, Read, Start, Update
  • Usage: all events in this service
category_name
  • Description: The event category name, as defined by category_uid value: Discovery.
  • Literal: Discovery, Identity & Access Management, System Activity
  • Usage: all events in this service
category_uid
  • Description: The category unique identifier of the event.
  • Literal: 1, 3, 5
  • Usage: all events in this service
class_name
  • Description: The event class name, as defined by class_uid value: User Inventory Info.
  • Literal: Device Config State Change, Entity Management, Scheduled Job Activity
  • Usage: all events in this service
class_uid
  • Description: The unique identifier of a class. A class describes the attributes available in an event.
  • Literal: 1006, 3004, 5019
  • Usage: all events in this service
message
  • Description: The description of the event/finding, as defined by the source.
  • Source: result
  • Usage: apple_ddm_status_receive, apple_mdm_service_discovery, apple_policy_dispatch, configuration_file_download, device_enrollment, mdm_command_result
severity_id
  • Description: OCSF severity identifier for the event.
  • Literal: 1
  • Usage: all events in this service
status_detail
  • Description: The status detail contains additional information about the event/finding outcome.
  • Source: error_message
  • Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost
status_id
  • Description: Normalized status of the activity (1=Success, 2=Failure).
  • Source: success
  • Transform:
  • success → boolean_to_status_id; true→1, false→2 (all events in this service)
  • Usage: all events in this service
time
  • Description: Event time, in epoch milliseconds (OCSF time).
  • Source: timestamp
  • Transform:
  • timestamp → iso8601_to_epoch_millis (all events in this service)
  • Usage: all events in this service
type_uid
  • Description: The event/finding type ID. It identifies the event's semantics and structure. The value is calculated by the logging system as: class_uid * 100 + activity_id.
  • Literal: 100606, 300401, 300402, 300403, 300404, 300406, 501901, 501902
  • Usage: all events in this service

Metadata

metadata.event_code
  • Description: JumpCloud event type code.
  • Source: event_type
  • Usage: all events in this service
metadata.original_time
  • Description: The original event time as reported by the event source. For example, the time in the original format from system event log such as Syslog on Unix/Linux and the System event file on Windows. Omit if event is generated instead of collected via logs.
  • Source: server_timestamp
  • Usage: configuration_file_download
metadata.processed_time
  • Description: The event processed time, such as an ETL operation.
  • Source: jc_transformation_ts
  • Usage: all events in this service
metadata.product.name
  • Description: Originating JumpCloud service that produced the event.
  • Source: service
  • Usage: all events in this service
metadata.tenant_uid
  • Description: JumpCloud organization (tenant) identifier.
  • Source: organization
  • Usage: all events in this service
metadata.uid
  • Description: Unique event identifier assigned by JumpCloud.
  • Source: id
  • Usage: all events in this service
metadata.version
  • Description: OCSF schema version used for this event.
  • Literal: 1.8.0
  • Usage: all events in this service

Actor

actor.user.email_addr
  • Description: Email address of the actor who initiated the event.
  • Source: initiated_by.email
  • Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost, configuration_file_download, device_enrollment
actor.user.name
  • Description: Display name of the actor who initiated the event.
  • Source: initiated_by.name
  • Usage: configuration_file_download, device_enrollment
actor.user.type_id
  • Description: OCSF user type of the actor (1=User, 2=Admin, 3=System, 4=Service).
  • Source: initiated_by.type
  • Transform:
  • initiated_by.type → enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (applemdm_commands_clearactivationlock, applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost, device_enrollment)
  • Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost, device_enrollment
actor.user.uid
  • Description: Unique identifier of the actor who initiated the event.
  • Source: initiated_by.id
  • Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost

Device

device.os.type
  • Description: The type of the operating system.
  • Source: mdm_type
  • Usage: apple_ddm_status_receive, apple_mdm_service_discovery, apple_policy_dispatch, mdm_command_result
device.uid
  • Description: The unique identifier of the device. For example the Windows TargetSID or AWS EC2 ARN.
  • Source: windows_device_uuid
  • Usage: apple_ddm_status_receive, apple_mdm_service_discovery, apple_policy_dispatch, mdm_command_result

Entity

entity.data.auth_method
  • Description: JumpCloud extension data on the managed entity: auth_method.
  • Source: auth_method
  • Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost
entity.data.changed_field
  • Description: JumpCloud extension data on the managed entity: changed_field.
  • Source: changes.field
  • Usage: applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost
entity.data.changes_from
  • Description: JumpCloud extension data on the managed entity: changes_from.
  • Source: changes.from
  • Usage: applemdm_devicemanagers_delete, applemdm_devicemanagers_patch
entity.data.mdm_device_manager_id
  • Description: JumpCloud extension data on the managed entity: mdm_device_manager_id.
  • Source: mdm_device_manager_id
  • Usage: configuration_file_download, device_enrollment
entity.device.uid
  • Description: The unique identifier of the device. For example the Windows TargetSID or AWS EC2 ARN.
  • Source: resource.device_object_id, windows_device_uuid
  • Usage: applemdm_commands_clearactivationlock, configuration_file_download, device_enrollment
entity.type
  • Description: The managed entity type. For example: Policy, User, Organization, Device.
  • Source: mdm_type, resource.type
  • Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost, configuration_file_download, device_enrollment
entity.uid
  • Description: The identifier of the managed entity. It should match the uid of the specific entity's object UID if populated, or the source specific ID if the type_id is 'Other'.
  • Source: mdm_device_id, resource.id
  • Usage: applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, configuration_file_download, device_enrollment
entity_result.data.changes_to
  • Description: JumpCloud extension data on the managed entity: changes_to.
  • Source: changes.to
  • Usage: applemdm_devicemanagers_create
entity_result.data.changes_to_nanos
  • Description: JumpCloud extension data on the managed entity: changes_to_nanos.
  • Source: changes.to.nanos
  • Usage: applemdm_volumepurchaseprogram_locationspost
entity_result.data.changes_to_seconds
  • Description: JumpCloud extension data on the managed entity: changes_to_seconds.
  • Source: changes.to.seconds
  • Usage: applemdm_volumepurchaseprogram_locationspost

Src Endpoint

src_endpoint.autonomous_system.name
  • Description: Organization name for the Autonomous System.
  • Source: asn.organization
  • Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost, configuration_file_download
src_endpoint.autonomous_system.number
  • Description: Unique number that the AS is identified by.
  • Source: asn.number
  • Transform:
  • asn.number → int (applemdm_commands_clearactivationlock, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost, configuration_file_download)
  • Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost, configuration_file_download
src_endpoint.ip
  • Description: Source IP address the request originated from.
  • Source: client_ip
  • Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost
src_endpoint.location.city
  • Description: The name of the city.
  • Source: geoip.city
  • Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost, configuration_file_download, device_enrollment
src_endpoint.location.continent
  • Description: The name of the continent.
  • Source: geoip.continent_code
  • Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost, configuration_file_download, device_enrollment
src_endpoint.location.country
  • Description: The ISO 3166-1 Alpha-2 country code.

    Note: The two letter country code should be capitalized. For example: US or CA.

  • Source: geoip.country_code
  • Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost, configuration_file_download, device_enrollment
src_endpoint.location.lat
  • Description: The geographical Latitude coordinate represented in Decimal Degrees (DD). For example: 42.361145.
  • Source: geoip.latitude
  • Transform:
  • geoip.latitude → double (applemdm_commands_clearactivationlock, applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost, configuration_file_download, device_enrollment)
  • Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost, configuration_file_download, device_enrollment
src_endpoint.location.long
  • Description: The geographical Longitude coordinate represented in Decimal Degrees (DD). For example: -71.057083.
  • Source: geoip.longitude
  • Transform:
  • geoip.longitude → double (applemdm_commands_clearactivationlock, applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost, configuration_file_download, device_enrollment)
  • Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost, configuration_file_download, device_enrollment
src_endpoint.location.region
  • Description: The alphanumeric code that identifies the principal subdivision (e.g. province or state) of the country. For example, 'CH-VD' for the Canton of Vaud, Switzerland
  • Source: geoip.region_code
  • Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost, configuration_file_download, device_enrollment

Http Request

http_request.user_agent
  • Description: The request header that identifies the operating system and web browser.
  • Source: user_agent
  • Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost

Observables

observables[].name
  • Description: The full name of the observable attribute. The name is a pointer/reference to an attribute within the OCSF event data. For example: file.name. Array attributes may be represented in one of three ways. For example: resources.uid, resources[].uid, resources[0].uid.
  • Literal: actor.user.email_addr, actor.user.name, actor.user.uid, device.uid, entity.device.uid, http_request.user_agent, job.cmd_line, src_endpoint.ip, src_endpoint.location.country
  • Usage: all events in this service
observables[].type_id
  • Description: The observable value type identifier.
  • Literal: 13, 14, 16, 2, 31, 4, 47, 5
  • Usage: all events in this service
observables[].value
  • Description: The value associated with the observable attribute. The meaning of the value depends on the observable type.
    If the name refers to a scalar attribute, then the value is the value of the attribute.
    If the name refers to an object attribute, then the value is not populated.
  • Source: client_ip, command.payload, geoip.country_code, initiated_by.email, initiated_by.id, initiated_by.name, mdm_device_id, resource.device_object_id, user_agent, windows_device_uuid
  • Usage: all events in this service

Other

action
  • Description: The normalized caption of action_id.
  • Source: action
  • Usage: apple_policy_dispatch
job.cmd_line
  • Description: The job command line.
  • Source: command.payload
  • Usage: mdm_command_result
job.desc
  • Description: The description of the job.
  • Source: request_type
  • Usage: apple_policy_dispatch, mdm_command_result
job.name
  • Description: The name of the job.
  • Source: policy_name
  • Usage: apple_policy_dispatch
job.run_state
  • Description: The run state of the job.
  • Source: status
  • Usage: apple_policy_dispatch, mdm_command_result
status
  • Description: The event status, normalized to the caption of the status_id value. In the case of 'Other', it is defined by the event source.
  • Source: status
  • Usage: apple_ddm_status_receive, apple_mdm_service_discovery, configuration_file_download, device_enrollment

Unmapped

unmapped.@version
  • Description: JumpCloud Directory Insights field @version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: @version
  • Usage: all events in this service
unmapped.activation_lock_bypass_code
  • Description: JumpCloud Directory Insights field activation_lock_bypass_code preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: activation_lock_bypass_code
  • Usage: mdm_command_result
unmapped.asn.network
  • Description: JumpCloud Directory Insights field asn.network preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: asn.network
  • Usage: applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost, configuration_file_download
unmapped.association_action_source
  • Description: JumpCloud Directory Insights field association_action_source preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: association_action_source
  • Usage: apple_ddm_status_receive, apple_mdm_service_discovery, apple_policy_dispatch, configuration_file_download, device_enrollment, mdm_command_result
unmapped.association_from_type
  • Description: JumpCloud Directory Insights field association_from_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: association_from_type
  • Usage: apple_ddm_status_receive, apple_mdm_service_discovery, apple_policy_dispatch, configuration_file_download, device_enrollment, mdm_command_result
unmapped.association_op
  • Description: JumpCloud Directory Insights field association_op preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: association_op
  • Usage: apple_ddm_status_receive, apple_mdm_service_discovery, apple_policy_dispatch, configuration_file_download, device_enrollment, mdm_command_result
unmapped.association_to_type
  • Description: JumpCloud Directory Insights field association_to_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: association_to_type
  • Usage: apple_ddm_status_receive, apple_mdm_service_discovery, apple_policy_dispatch, configuration_file_download, device_enrollment, mdm_command_result
unmapped.changes
  • Description: JumpCloud Directory Insights field changes preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes
  • Usage: applemdm_commands_clearactivationlock
unmapped.command
  • Description: JumpCloud Directory Insights field command preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: command
  • Usage: apple_ddm_status_receive, apple_mdm_service_discovery, apple_policy_dispatch, configuration_file_download, device_enrollment
unmapped.command.current_password
  • Description: JumpCloud Directory Insights field command.current_password preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: command.current_password
  • Usage: mdm_command_result
unmapped.command.data
  • Description: JumpCloud Directory Insights field command.data preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: command.data
  • Usage: mdm_command_result
unmapped.command.install_as_managed
  • Description: JumpCloud Directory Insights field command.install_as_managed preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: command.install_as_managed
  • Usage: mdm_command_result
unmapped.command.manifest.items.assets.kind
  • Description: JumpCloud Directory Insights field command.manifest.items.assets.kind preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: command.manifest.items.assets.kind
  • Usage: mdm_command_result
unmapped.command.manifest.items.assets.md5Size
  • Description: JumpCloud Directory Insights field command.manifest.items.assets.md5Size preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: command.manifest.items.assets.md5Size
  • Usage: mdm_command_result
unmapped.command.manifest.items.assets.md5s
  • Description: JumpCloud Directory Insights field command.manifest.items.assets.md5s preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: command.manifest.items.assets.md5s
  • Usage: mdm_command_result
unmapped.command.manifest.items.assets.url
  • Description: JumpCloud Directory Insights field command.manifest.items.assets.url preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: command.manifest.items.assets.url
  • Usage: mdm_command_result
unmapped.command.manifest.items.metadata.bundleIdentifier
  • Description: JumpCloud Directory Insights field command.manifest.items.metadata.bundleIdentifier preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: command.manifest.items.metadata.bundleIdentifier
  • Usage: mdm_command_result
unmapped.command.manifest.items.metadata.bundleVersion
  • Description: JumpCloud Directory Insights field command.manifest.items.metadata.bundleVersion preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: command.manifest.items.metadata.bundleVersion
  • Usage: mdm_command_result
unmapped.command.manifest.items.metadata.kind
  • Description: JumpCloud Directory Insights field command.manifest.items.metadata.kind preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: command.manifest.items.metadata.kind
  • Usage: mdm_command_result
unmapped.command.manifest.items.metadata.subtitle
  • Description: JumpCloud Directory Insights field command.manifest.items.metadata.subtitle preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: command.manifest.items.metadata.subtitle
  • Usage: mdm_command_result
unmapped.command.manifest.items.metadata.title
  • Description: JumpCloud Directory Insights field command.manifest.items.metadata.title preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: command.manifest.items.metadata.title
  • Usage: mdm_command_result
unmapped.command.new_password
  • Description: JumpCloud Directory Insights field command.new_password preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: command.new_password
  • Usage: mdm_command_result
unmapped.command.queries
  • Description: JumpCloud Directory Insights field command.queries preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: command.queries
  • Usage: mdm_command_result
unmapped.command_uuid
  • Description: JumpCloud Directory Insights field command_uuid preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: command_uuid
  • Usage: apple_ddm_status_receive, apple_mdm_service_discovery, apple_policy_dispatch, configuration_file_download, device_enrollment, mdm_command_result
unmapped.enabled
  • Description: JumpCloud Directory Insights field enabled preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: enabled
  • Usage: apple_mdm_service_discovery
unmapped.error_chain
  • Description: JumpCloud Directory Insights field error_chain preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: error_chain
  • Usage: apple_ddm_status_receive, apple_mdm_service_discovery, apple_policy_dispatch, configuration_file_download, device_enrollment, mdm_command_result
unmapped.geoip.city
  • Description: JumpCloud Directory Insights field geoip.city preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.city
  • Usage: mdm_command_result
unmapped.geoip.continent_code
  • Description: JumpCloud Directory Insights field geoip.continent_code preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.continent_code
  • Usage: mdm_command_result
unmapped.geoip.country_code
  • Description: JumpCloud Directory Insights field geoip.country_code preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.country_code
  • Usage: mdm_command_result
unmapped.geoip.latitude
  • Description: JumpCloud Directory Insights field geoip.latitude preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.latitude
  • Usage: mdm_command_result
unmapped.geoip.longitude
  • Description: JumpCloud Directory Insights field geoip.longitude preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.longitude
  • Usage: mdm_command_result
unmapped.geoip.region_code
  • Description: JumpCloud Directory Insights field geoip.region_code preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.region_code
  • Usage: mdm_command_result
unmapped.geoip.region_name
  • Description: JumpCloud Directory Insights field geoip.region_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.region_name
  • Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost, configuration_file_download, device_enrollment, mdm_command_result
unmapped.geoip.timezone
  • Description: JumpCloud Directory Insights field geoip.timezone preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.timezone
  • Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost, configuration_file_download, device_enrollment, mdm_command_result
unmapped.initiated_by
  • Description: JumpCloud Directory Insights field initiated_by preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by
  • Usage: apple_ddm_status_receive, apple_mdm_service_discovery, apple_policy_dispatch, mdm_command_result
unmapped.initiated_by.provider
  • Description: JumpCloud Directory Insights field initiated_by.provider preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by.provider
  • Usage: applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost
unmapped.initiated_by_email_hash
  • Description: JumpCloud Directory Insights field initiated_by_email_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_email_hash
  • Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost, configuration_file_download, device_enrollment
unmapped.initiated_by_id_hash
  • Description: JumpCloud Directory Insights field initiated_by_id_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_id_hash
  • Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost
unmapped.initiated_by_name_hash
  • Description: JumpCloud Directory Insights field initiated_by_name_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_name_hash
  • Usage: device_enrollment
unmapped.initiated_by_type
  • Description: JumpCloud Directory Insights field initiated_by_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_type
  • Usage: apple_ddm_status_receive, apple_mdm_service_discovery, apple_policy_dispatch, configuration_file_download, device_enrollment, mdm_command_result
unmapped.is_out_of_bound
  • Description: JumpCloud Directory Insights field is_out_of_bound preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: is_out_of_bound
  • Usage: apple_ddm_status_receive, apple_mdm_service_discovery, apple_policy_dispatch, applemdm_commands_clearactivationlock, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost, configuration_file_download, device_enrollment, mdm_command_result
unmapped.jc_application_name
  • Description: JumpCloud Directory Insights field jc_application_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_application_name
  • Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost
unmapped.jc_initiated_by_email
  • Description: JumpCloud Directory Insights field jc_initiated_by_email preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_initiated_by_email
  • Usage: configuration_file_download
unmapped.jc_initiated_by_username
  • Description: JumpCloud Directory Insights field jc_initiated_by_username preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_initiated_by_username
  • Usage: configuration_file_download
unmapped.jc_organization_name
  • Description: JumpCloud Directory Insights field jc_organization_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_organization_name
  • Usage: configuration_file_download
unmapped.jc_system_display_name
  • Description: JumpCloud Directory Insights field jc_system_display_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_system_display_name
  • Usage: configuration_file_download
unmapped.jc_system_hostname
  • Description: JumpCloud Directory Insights field jc_system_hostname preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_system_hostname
  • Usage: configuration_file_download
unmapped.mdm_device_manager_id
  • Description: JumpCloud Directory Insights field mdm_device_manager_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: mdm_device_manager_id
  • Usage: apple_ddm_status_receive, apple_mdm_service_discovery, apple_policy_dispatch, mdm_command_result
unmapped.policy_id
  • Description: JumpCloud Directory Insights field policy_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: policy_id
  • Usage: apple_policy_dispatch
unmapped.provider
  • Description: JumpCloud Directory Insights field provider preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: provider
  • Usage: applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost
unmapped.query_responses.available_device_capacity
  • Description: JumpCloud Directory Insights field query_responses.available_device_capacity preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: query_responses.available_device_capacity
  • Usage: mdm_command_result
unmapped.query_responses.device_capacity
  • Description: JumpCloud Directory Insights field query_responses.device_capacity preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: query_responses.device_capacity
  • Usage: mdm_command_result
unmapped.query_responses.device_name
  • Description: JumpCloud Directory Insights field query_responses.device_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: query_responses.device_name
  • Usage: mdm_command_result
unmapped.query_responses.is_apple_silicon
  • Description: JumpCloud Directory Insights field query_responses.is_apple_silicon preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: query_responses.is_apple_silicon
  • Usage: mdm_command_result
unmapped.query_responses.is_supervised
  • Description: JumpCloud Directory Insights field query_responses.is_supervised preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: query_responses.is_supervised
  • Usage: mdm_command_result
unmapped.query_responses.mdm_options
  • Description: JumpCloud Directory Insights field query_responses.mdm_options preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: query_responses.mdm_options
  • Usage: mdm_command_result
unmapped.query_responses.model_name
  • Description: JumpCloud Directory Insights field query_responses.model_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: query_responses.model_name
  • Usage: mdm_command_result
unmapped.query_responses.os_version
  • Description: JumpCloud Directory Insights field query_responses.os_version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: query_responses.os_version
  • Usage: mdm_command_result
unmapped.query_responses.product_name
  • Description: JumpCloud Directory Insights field query_responses.product_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: query_responses.product_name
  • Usage: mdm_command_result
unmapped.request_type
  • Description: JumpCloud Directory Insights field request_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: request_type
  • Usage: apple_ddm_status_receive, apple_mdm_service_discovery, configuration_file_download, device_enrollment
unmapped.resource_id_hash
  • Description: JumpCloud Directory Insights field resource_id_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource_id_hash
  • Usage: applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch
unmapped.security_info.is_recovery_lock_enabled
  • Description: JumpCloud Directory Insights field security_info.is_recovery_lock_enabled preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: security_info.is_recovery_lock_enabled
  • Usage: mdm_command_result
unmapped.security_info.management_status.enrolled_via_dep
  • Description: JumpCloud Directory Insights field security_info.management_status.enrolled_via_dep preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: security_info.management_status.enrolled_via_dep
  • Usage: mdm_command_result
unmapped.security_info.management_status.is_activation_lock_manageable
  • Description: JumpCloud Directory Insights field security_info.management_status.is_activation_lock_manageable preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: security_info.management_status.is_activation_lock_manageable
  • Usage: mdm_command_result
unmapped.security_info.management_status.is_user_enrollment
  • Description: JumpCloud Directory Insights field security_info.management_status.is_user_enrollment preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: security_info.management_status.is_user_enrollment
  • Usage: mdm_command_result
unmapped.security_info.management_status.user_approved_enrollment
  • Description: JumpCloud Directory Insights field security_info.management_status.user_approved_enrollment preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: security_info.management_status.user_approved_enrollment
  • Usage: mdm_command_result
unmapped.security_info.secure_boot.secure_boot_level
  • Description: JumpCloud Directory Insights field security_info.secure_boot.secure_boot_level preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: security_info.secure_boot.secure_boot_level
  • Usage: mdm_command_result
unmapped.status_report.Errors.Reasons.Code
  • Description: JumpCloud Directory Insights field status_report.Errors.Reasons.Code preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.Errors.Reasons.Code
  • Usage: apple_ddm_status_receive
unmapped.status_report.Errors.Reasons.Description
  • Description: JumpCloud Directory Insights field status_report.Errors.Reasons.Description preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.Errors.Reasons.Description
  • Usage: apple_ddm_status_receive
unmapped.status_report.Errors.StatusItem
  • Description: JumpCloud Directory Insights field status_report.Errors.StatusItem preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.Errors.StatusItem
  • Usage: apple_ddm_status_receive
unmapped.status_report.FullReport
  • Description: JumpCloud Directory Insights field status_report.FullReport preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.FullReport
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.account.list.caldav
  • Description: JumpCloud Directory Insights field status_report.StatusItems.account.list.caldav preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.account.list.caldav
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.account.list.carddav
  • Description: JumpCloud Directory Insights field status_report.StatusItems.account.list.carddav preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.account.list.carddav
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.account.list.exchange
  • Description: JumpCloud Directory Insights field status_report.StatusItems.account.list.exchange preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.account.list.exchange
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.account.list.google
  • Description: JumpCloud Directory Insights field status_report.StatusItems.account.list.google preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.account.list.google
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.account.list.ldap
  • Description: JumpCloud Directory Insights field status_report.StatusItems.account.list.ldap preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.account.list.ldap
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.account.list.mail.incoming
  • Description: JumpCloud Directory Insights field status_report.StatusItems.account.list.mail.incoming preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.account.list.mail.incoming
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.account.list.mail.outgoing
  • Description: JumpCloud Directory Insights field status_report.StatusItems.account.list.mail.outgoing preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.account.list.mail.outgoing
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.account.list.subscribed-calendar
  • Description: JumpCloud Directory Insights field status_report.StatusItems.account.list.subscribed-calendar preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.account.list.subscribed-calendar
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.app.managed.list
  • Description: JumpCloud Directory Insights field status_report.StatusItems.app.managed.list preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.app.managed.list
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.device.identifier.serial-number
  • Description: JumpCloud Directory Insights field status_report.StatusItems.device.identifier.serial-number preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.device.identifier.serial-number
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.device.identifier.udid
  • Description: JumpCloud Directory Insights field status_report.StatusItems.device.identifier.udid preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.device.identifier.udid
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.device.model.family
  • Description: JumpCloud Directory Insights field status_report.StatusItems.device.model.family preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.device.model.family
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.device.model.identifier
  • Description: JumpCloud Directory Insights field status_report.StatusItems.device.model.identifier preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.device.model.identifier
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.device.model.marketing-name
  • Description: JumpCloud Directory Insights field status_report.StatusItems.device.model.marketing-name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.device.model.marketing-name
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.device.model.number
  • Description: JumpCloud Directory Insights field status_report.StatusItems.device.model.number preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.device.model.number
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.device.operating-system.build-version
  • Description: JumpCloud Directory Insights field status_report.StatusItems.device.operating-system.build-version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.device.operating-system.build-version
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.device.operating-system.family
  • Description: JumpCloud Directory Insights field status_report.StatusItems.device.operating-system.family preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.device.operating-system.family
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.device.operating-system.marketing-name
  • Description: JumpCloud Directory Insights field status_report.StatusItems.device.operating-system.marketing-name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.device.operating-system.marketing-name
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.device.operating-system.supplemental.build-version
  • Description: JumpCloud Directory Insights field status_report.StatusItems.device.operating-system.supplemental.build-version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.device.operating-system.supplemental.build-version
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.device.operating-system.supplemental.extra-version
  • Description: JumpCloud Directory Insights field status_report.StatusItems.device.operating-system.supplemental.extra-version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.device.operating-system.supplemental.extra-version
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.device.operating-system.version
  • Description: JumpCloud Directory Insights field status_report.StatusItems.device.operating-system.version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.device.operating-system.version
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.diskmanagement.filevault.enabled
  • Description: JumpCloud Directory Insights field status_report.StatusItems.diskmanagement.filevault.enabled preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.diskmanagement.filevault.enabled
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.management.client-capabilities.supported-features
  • Description: JumpCloud Directory Insights field status_report.StatusItems.management.client-capabilities.supported-features preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.management.client-capabilities.supported-features
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.management.client-capabilities.supported-payloads.declarations.activations
  • Description: JumpCloud Directory Insights field status_report.StatusItems.management.client-capabilities.supported-payloads.declarations.activations preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.management.client-capabilities.supported-payloads.declarations.activations
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.management.client-capabilities.supported-payloads.declarations.assets
  • Description: JumpCloud Directory Insights field status_report.StatusItems.management.client-capabilities.supported-payloads.declarations.assets preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.management.client-capabilities.supported-payloads.declarations.assets
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.management.client-capabilities.supported-payloads.declarations.configurations
  • Description: JumpCloud Directory Insights field status_report.StatusItems.management.client-capabilities.supported-payloads.declarations.configurations preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.management.client-capabilities.supported-payloads.declarations.configurations
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.management.client-capabilities.supported-payloads.declarations.management
  • Description: JumpCloud Directory Insights field status_report.StatusItems.management.client-capabilities.supported-payloads.declarations.management preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.management.client-capabilities.supported-payloads.declarations.management
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.management.client-capabilities.supported-payloads.status-items
  • Description: JumpCloud Directory Insights field status_report.StatusItems.management.client-capabilities.supported-payloads.status-items preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.management.client-capabilities.supported-payloads.status-items
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.management.client-capabilities.supported-versions
  • Description: JumpCloud Directory Insights field status_report.StatusItems.management.client-capabilities.supported-versions preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.management.client-capabilities.supported-versions
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.management.declarations.activations.active
  • Description: JumpCloud Directory Insights field status_report.StatusItems.management.declarations.activations.active preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.management.declarations.activations.active
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.management.declarations.activations.identifier
  • Description: JumpCloud Directory Insights field status_report.StatusItems.management.declarations.activations.identifier preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.management.declarations.activations.identifier
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.management.declarations.activations.server-token
  • Description: JumpCloud Directory Insights field status_report.StatusItems.management.declarations.activations.server-token preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.management.declarations.activations.server-token
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.management.declarations.activations.valid
  • Description: JumpCloud Directory Insights field status_report.StatusItems.management.declarations.activations.valid preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.management.declarations.activations.valid
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.management.declarations.assets
  • Description: JumpCloud Directory Insights field status_report.StatusItems.management.declarations.assets preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.management.declarations.assets
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.management.declarations.configurations.active
  • Description: JumpCloud Directory Insights field status_report.StatusItems.management.declarations.configurations.active preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.management.declarations.configurations.active
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.management.declarations.configurations.identifier
  • Description: JumpCloud Directory Insights field status_report.StatusItems.management.declarations.configurations.identifier preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.management.declarations.configurations.identifier
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.management.declarations.configurations.server-token
  • Description: JumpCloud Directory Insights field status_report.StatusItems.management.declarations.configurations.server-token preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.management.declarations.configurations.server-token
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.management.declarations.configurations.valid
  • Description: JumpCloud Directory Insights field status_report.StatusItems.management.declarations.configurations.valid preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.management.declarations.configurations.valid
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.management.declarations.management
  • Description: JumpCloud Directory Insights field status_report.StatusItems.management.declarations.management preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.management.declarations.management
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.mdm.app._removed
  • Description: JumpCloud Directory Insights field status_report.StatusItems.mdm.app._removed preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.mdm.app._removed
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.mdm.app.external-version-id
  • Description: JumpCloud Directory Insights field status_report.StatusItems.mdm.app.external-version-id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.mdm.app.external-version-id
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.mdm.app.identifier
  • Description: JumpCloud Directory Insights field status_report.StatusItems.mdm.app.identifier preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.mdm.app.identifier
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.mdm.app.name
  • Description: JumpCloud Directory Insights field status_report.StatusItems.mdm.app.name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.mdm.app.name
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.mdm.app.short-version
  • Description: JumpCloud Directory Insights field status_report.StatusItems.mdm.app.short-version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.mdm.app.short-version
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.mdm.app.state
  • Description: JumpCloud Directory Insights field status_report.StatusItems.mdm.app.state preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.mdm.app.state
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.mdm.app.version
  • Description: JumpCloud Directory Insights field status_report.StatusItems.mdm.app.version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.mdm.app.version
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.package.list
  • Description: JumpCloud Directory Insights field status_report.StatusItems.package.list preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.package.list
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.passcode.is-compliant
  • Description: JumpCloud Directory Insights field status_report.StatusItems.passcode.is-compliant preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.passcode.is-compliant
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.passcode.is-present
  • Description: JumpCloud Directory Insights field status_report.StatusItems.passcode.is-present preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.passcode.is-present
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.services.background-task.code-signature
  • Description: JumpCloud Directory Insights field status_report.StatusItems.services.background-task.code-signature preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.services.background-task.code-signature
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.services.background-task.identifier
  • Description: JumpCloud Directory Insights field status_report.StatusItems.services.background-task.identifier preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.services.background-task.identifier
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.services.background-task.launchd.checksum
  • Description: JumpCloud Directory Insights field status_report.StatusItems.services.background-task.launchd.checksum preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.services.background-task.launchd.checksum
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.services.background-task.launchd.label
  • Description: JumpCloud Directory Insights field status_report.StatusItems.services.background-task.launchd.label preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.services.background-task.launchd.label
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.services.background-task.launchd.program
  • Description: JumpCloud Directory Insights field status_report.StatusItems.services.background-task.launchd.program preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.services.background-task.launchd.program
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.services.background-task.launchd.program-arguments
  • Description: JumpCloud Directory Insights field status_report.StatusItems.services.background-task.launchd.program-arguments preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.services.background-task.launchd.program-arguments
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.services.background-task.path
  • Description: JumpCloud Directory Insights field status_report.StatusItems.services.background-task.path preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.services.background-task.path
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.services.background-task.state
  • Description: JumpCloud Directory Insights field status_report.StatusItems.services.background-task.state preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.services.background-task.state
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.services.background-task.type
  • Description: JumpCloud Directory Insights field status_report.StatusItems.services.background-task.type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.services.background-task.type
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.services.background-task.uid
  • Description: JumpCloud Directory Insights field status_report.StatusItems.services.background-task.uid preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.services.background-task.uid
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.softwareupdate.beta-enrollment
  • Description: JumpCloud Directory Insights field status_report.StatusItems.softwareupdate.beta-enrollment preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.softwareupdate.beta-enrollment
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.softwareupdate.device-id
  • Description: JumpCloud Directory Insights field status_report.StatusItems.softwareupdate.device-id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.softwareupdate.device-id
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.softwareupdate.failure-reason.count
  • Description: JumpCloud Directory Insights field status_report.StatusItems.softwareupdate.failure-reason.count preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.softwareupdate.failure-reason.count
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.softwareupdate.failure-reason.reason
  • Description: JumpCloud Directory Insights field status_report.StatusItems.softwareupdate.failure-reason.reason preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.softwareupdate.failure-reason.reason
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.softwareupdate.failure-reason.timestamp
  • Description: JumpCloud Directory Insights field status_report.StatusItems.softwareupdate.failure-reason.timestamp preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.softwareupdate.failure-reason.timestamp
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.softwareupdate.install-reason.reason
  • Description: JumpCloud Directory Insights field status_report.StatusItems.softwareupdate.install-reason.reason preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.softwareupdate.install-reason.reason
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.softwareupdate.install-state
  • Description: JumpCloud Directory Insights field status_report.StatusItems.softwareupdate.install-state preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.softwareupdate.install-state
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.softwareupdate.pending-version.build-version
  • Description: JumpCloud Directory Insights field status_report.StatusItems.softwareupdate.pending-version.build-version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.softwareupdate.pending-version.build-version
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.softwareupdate.pending-version.os-version
  • Description: JumpCloud Directory Insights field status_report.StatusItems.softwareupdate.pending-version.os-version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.softwareupdate.pending-version.os-version
  • Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.softwareupdate.pending-version.softwareupdate.target-local-date-time
  • Description: JumpCloud Directory Insights field status_report.StatusItems.softwareupdate.pending-version.softwareupdate.target-local-date-time preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: status_report.StatusItems.softwareupdate.pending-version.softwareupdate.target-local-date-time
  • Usage: apple_ddm_status_receive
unmapped.system_id
  • Description: JumpCloud Directory Insights field system_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: system_id
  • Usage: apple_ddm_status_receive, apple_policy_dispatch
unmapped.timestamp_source
  • Description: JumpCloud Directory Insights field timestamp_source preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: timestamp_source
  • Usage: configuration_file_download
unmapped.useragent.device
  • Description: JumpCloud Directory Insights field useragent.device preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.device
  • Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost
unmapped.useragent.major
  • Description: JumpCloud Directory Insights field useragent.major preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.major
  • Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost
unmapped.useragent.minor
  • Description: JumpCloud Directory Insights field useragent.minor preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.minor
  • Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost
unmapped.useragent.name
  • Description: JumpCloud Directory Insights field useragent.name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.name
  • Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost
unmapped.useragent.os
  • Description: JumpCloud Directory Insights field useragent.os preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os
  • Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost
unmapped.useragent.os_full
  • Description: JumpCloud Directory Insights field useragent.os_full preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_full
  • Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost
unmapped.useragent.os_major
  • Description: JumpCloud Directory Insights field useragent.os_major preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_major
  • Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost
unmapped.useragent.os_minor
  • Description: JumpCloud Directory Insights field useragent.os_minor preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_minor
  • Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost
unmapped.useragent.os_name
  • Description: JumpCloud Directory Insights field useragent.os_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_name
  • Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost
unmapped.useragent.os_patch
  • Description: JumpCloud Directory Insights field useragent.os_patch preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_patch
  • Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost
unmapped.useragent.os_version
  • Description: JumpCloud Directory Insights field useragent.os_version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_version
  • Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost
unmapped.useragent.patch
  • Description: JumpCloud Directory Insights field useragent.patch preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.patch
  • Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost
unmapped.useragent.version
  • Description: JumpCloud Directory Insights field useragent.version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.version
  • Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost

Notifications#

notifications · 8 events

Event Category Class Activity Type UID Fields
notification_channel_created Identity & Access Management (3) Entity Management (3004) Create (1) 300401 62
notification_channel_deleted Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 60
notification_channel_updated Identity & Access Management (3) Entity Management (3004) Update (3) 300403 71
notification_send_emails_from_role_failure Application Activity (6) Application Error (6008) General Error (1) 600801 41
notification_send_failure Application Activity (6) Application Error (6008) General Error (1) 600801 31
notification_send_org_rate_limit_reached Application Activity (6) Application Error (6008) General Error (1) 600801 33
notification_triggered_by_webhook Network Activity (4) Email Activity (4009) Send (1) 400901 36
slack_notification_sent Network Activity (4) Email Activity (4009) Send (1) 400901 36

OCSF field mappings#

Legend

  • Description: what the OCSF field represents (from OCSF schema v1.8.0)
  • Source: raw JumpCloud event field(s) mapped via ${{placeholder}} template
  • Transform: fieldMappings entry applied at runtime (cast, enum, etc.)
  • Literal: static value set in the mapping template
  • Usage: event types in this service that include this field

Core

activity_id
  • Description: The normalized identifier of the activity that triggered the event.
  • Literal: 1, 3, 4
  • Usage: all events in this service
activity_name
  • Description: The event activity name, as defined by the activity_id.
  • Literal: Create, Delete, General Error, Send, Update
  • Usage: all events in this service
category_name
  • Description: The event category name, as defined by category_uid value: Discovery.
  • Literal: Application Activity, Identity & Access Management, Network Activity
  • Usage: all events in this service
category_uid
  • Description: The category unique identifier of the event.
  • Literal: 3, 4, 6
  • Usage: all events in this service
class_name
  • Description: The event class name, as defined by class_uid value: User Inventory Info.
  • Literal: Application Error, Email Activity, Entity Management
  • Usage: all events in this service
class_uid
  • Description: The unique identifier of a class. A class describes the attributes available in an event.
  • Literal: 3004, 4009, 6008
  • Usage: all events in this service
severity_id
  • Description: OCSF severity identifier for the event.
  • Literal: 1
  • Usage: all events in this service
status_detail
  • Description: The status detail contains additional information about the event/finding outcome.
  • Source: error, error_message
  • Usage: all events in this service
status_id
  • Description: Normalized status of the activity (1=Success, 2=Failure).
  • Source: success
  • Transform:
  • success → boolean_to_status_id; true→1, false→2 (all events in this service)
  • Usage: all events in this service
time
  • Description: Event time, in epoch milliseconds (OCSF time).
  • Source: timestamp
  • Transform:
  • timestamp → iso8601_to_epoch_millis (all events in this service)
  • Usage: all events in this service
type_uid
  • Description: The event/finding type ID. It identifies the event's semantics and structure. The value is calculated by the logging system as: class_uid * 100 + activity_id.
  • Literal: 300401, 300403, 300404, 400901, 600801
  • Usage: all events in this service

Metadata

metadata.event_code
  • Description: JumpCloud event type code.
  • Source: event_type
  • Usage: all events in this service
metadata.original_time
  • Description: The original event time as reported by the event source. For example, the time in the original format from system event log such as Syslog on Unix/Linux and the System event file on Windows. Omit if event is generated instead of collected via logs.
  • Source: server_timestamp
  • Usage: all events in this service
metadata.product.name
  • Description: Originating JumpCloud service that produced the event.
  • Source: service
  • Usage: all events in this service
metadata.tenant_uid
  • Description: JumpCloud organization (tenant) identifier.
  • Source: organization
  • Usage: all events in this service
metadata.uid
  • Description: Unique event identifier assigned by JumpCloud.
  • Source: id
  • Usage: all events in this service
metadata.version
  • Description: OCSF schema version used for this event.
  • Literal: 1.8.0
  • Usage: all events in this service

Actor

actor.user.email_addr
  • Description: Email address of the actor who initiated the event.
  • Source: initiated_by.email
  • Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated
actor.user.type_id
  • Description: OCSF user type of the actor (1=User, 2=Admin, 3=System, 4=Service).
  • Source: initiated_by.type
  • Transform:
  • initiated_by.type → enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (notification_channel_created, notification_channel_deleted, notification_channel_updated)
  • Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated
actor.user.uid
  • Description: Unique identifier of the actor who initiated the event.
  • Source: initiated_by.id
  • Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated

Entity

entity.data.address
  • Description: JumpCloud extension data on the managed entity: address.
  • Source: config.address
  • Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated
entity.data.changed_field
  • Description: JumpCloud extension data on the managed entity: changed_field.
  • Source: changes.field
  • Usage: notification_channel_updated
entity.data.changes_from
  • Description: JumpCloud extension data on the managed entity: changes_from.
  • Source: changes.from
  • Usage: notification_channel_updated
entity.data.changes_removed.address
  • Description: JumpCloud extension data on the managed entity: changes_removed.address.
  • Source: changes.removed.address
  • Usage: notification_channel_updated
entity.data.changes_removed.name
  • Description: JumpCloud extension data on the managed entity: changes_removed.name.
  • Source: changes.removed.name
  • Usage: notification_channel_updated
entity.data.changes_removed.object_id
  • Description: JumpCloud extension data on the managed entity: changes_removed.object_id.
  • Source: changes.removed.object_id
  • Usage: notification_channel_updated
entity.data.correlation.id
  • Description: JumpCloud extension data on the managed entity: correlation.id.
  • Source: correlation.id
  • Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated
entity.data.description
  • Description: JumpCloud extension data on the managed entity: description.
  • Source: resource.description
  • Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated
entity.data.name
  • Description: JumpCloud extension data on the managed entity: name.
  • Source: config.name
  • Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated
entity.data.object_id
  • Description: JumpCloud extension data on the managed entity: object_id.
  • Source: config.object_id
  • Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated
entity.data.role_object_id
  • Description: JumpCloud extension data on the managed entity: role_object_id.
  • Source: config.role_object_id
  • Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated
entity.name
  • Description: The name of the managed entity. It should match the name of the specific entity object's name if populated, or the name of the managed entity if the type_id is 'Other'.
  • Source: resource.name
  • Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated
entity.type
  • Description: The managed entity type. For example: Policy, User, Organization, Device.
  • Source: resource.type
  • Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated
entity.uid
  • Description: The identifier of the managed entity. It should match the uid of the specific entity's object UID if populated, or the source specific ID if the type_id is 'Other'.
  • Source: resource.id
  • Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated
entity_result.data.changes_added.address
  • Description: JumpCloud extension data on the managed entity: changes_added.address.
  • Source: changes.added.address
  • Usage: notification_channel_updated
entity_result.data.changes_added.name
  • Description: JumpCloud extension data on the managed entity: changes_added.name.
  • Source: changes.added.name
  • Usage: notification_channel_updated
entity_result.data.changes_added.object_id
  • Description: JumpCloud extension data on the managed entity: changes_added.object_id.
  • Source: changes.added.object_id
  • Usage: notification_channel_updated
entity_result.data.changes_added.role_object_id
  • Description: JumpCloud extension data on the managed entity: changes_added.role_object_id.
  • Source: changes.added.role_object_id
  • Usage: notification_channel_updated
entity_result.data.changes_to
  • Description: JumpCloud extension data on the managed entity: changes_to.
  • Source: changes.to
  • Usage: notification_channel_updated

Src Endpoint

src_endpoint.autonomous_system.name
  • Description: Organization name for the Autonomous System.
  • Source: asn.organization
  • Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated
src_endpoint.autonomous_system.number
  • Description: Unique number that the AS is identified by.
  • Source: asn.number
  • Transform:
  • asn.number → int (notification_channel_created, notification_channel_deleted, notification_channel_updated)
  • Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated
src_endpoint.ip
  • Description: Source IP address the request originated from.
  • Source: client_ip
  • Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated, notification_triggered_by_webhook, slack_notification_sent
src_endpoint.location.city
  • Description: The name of the city.
  • Source: geoip.city
  • Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated
src_endpoint.location.continent
  • Description: The name of the continent.
  • Source: geoip.continent_code
  • Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated
src_endpoint.location.country
  • Description: The ISO 3166-1 Alpha-2 country code.

    Note: The two letter country code should be capitalized. For example: US or CA.

  • Source: geoip.country_code
  • Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated
src_endpoint.location.lat
  • Description: The geographical Latitude coordinate represented in Decimal Degrees (DD). For example: 42.361145.
  • Source: geoip.latitude
  • Transform:
  • geoip.latitude → double (notification_channel_created, notification_channel_deleted, notification_channel_updated)
  • Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated
src_endpoint.location.long
  • Description: The geographical Longitude coordinate represented in Decimal Degrees (DD). For example: -71.057083.
  • Source: geoip.longitude
  • Transform:
  • geoip.longitude → double (notification_channel_created, notification_channel_deleted, notification_channel_updated)
  • Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated
src_endpoint.location.region
  • Description: The alphanumeric code that identifies the principal subdivision (e.g. province or state) of the country. For example, 'CH-VD' for the Canton of Vaud, Switzerland
  • Source: geoip.region_code
  • Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated

Http Request

http_request.user_agent
  • Description: The request header that identifies the operating system and web browser.
  • Source: user_agent
  • Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated

Observables

observables[].name
  • Description: The full name of the observable attribute. The name is a pointer/reference to an attribute within the OCSF event data. For example: file.name. Array attributes may be represented in one of three ways. For example: resources.uid, resources[].uid, resources[0].uid.
  • Literal: actor.user.email_addr, actor.user.uid, http_request.user_agent, src_endpoint.ip, src_endpoint.location.country
  • Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated, notification_triggered_by_webhook, slack_notification_sent
observables[].type_id
  • Description: The observable value type identifier.
  • Literal: 14, 16, 2, 31, 5
  • Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated, notification_triggered_by_webhook, slack_notification_sent
observables[].value
  • Description: The value associated with the observable attribute. The meaning of the value depends on the observable type.
    If the name refers to a scalar attribute, then the value is the value of the attribute.
    If the name refers to an object attribute, then the value is not populated.
  • Source: client_ip, geoip.country_code, initiated_by.email, initiated_by.id, user_agent
  • Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated, notification_triggered_by_webhook, slack_notification_sent

Other

direction_id
  • Description:

    The direction of the email relative to the scanning host or organization.

    Email scanned at an internet gateway might be characterized as inbound to the organization from the Internet, outbound from the organization to the Internet, or internal within the organization. Email scanned at a workstation might be characterized as inbound to, or outbound from the workstation.
  • Usage: notification_triggered_by_webhook, slack_notification_sent

Unmapped

unmapped.@version
  • Description: JumpCloud Directory Insights field @version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: @version
  • Usage: all events in this service
unmapped.asn.network
  • Description: JumpCloud Directory Insights field asn.network preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: asn.network
  • Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated
unmapped.client_ip
  • Description: JumpCloud Directory Insights field client_ip preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: client_ip
  • Usage: notification_send_emails_from_role_failure, notification_send_failure, notification_send_org_rate_limit_reached
unmapped.error_message
  • Description: JumpCloud Directory Insights field error_message preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: error_message
  • Usage: notification_send_emails_from_role_failure, notification_send_failure, notification_send_org_rate_limit_reached
unmapped.file_input_timestamp
  • Description: JumpCloud Directory Insights field file_input_timestamp preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: file_input_timestamp
  • Usage: notification_channel_created
unmapped.geoip.region_name
  • Description: JumpCloud Directory Insights field geoip.region_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.region_name
  • Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated
unmapped.geoip.timezone
  • Description: JumpCloud Directory Insights field geoip.timezone preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.timezone
  • Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated
unmapped.initiated_by
  • Description: JumpCloud Directory Insights field initiated_by preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by
  • Usage: notification_send_emails_from_role_failure, notification_send_failure, notification_send_org_rate_limit_reached, notification_triggered_by_webhook, slack_notification_sent
unmapped.initiated_by_email_hash
  • Description: JumpCloud Directory Insights field initiated_by_email_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_email_hash
  • Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated
unmapped.initiated_by_id_hash
  • Description: JumpCloud Directory Insights field initiated_by_id_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_id_hash
  • Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated
unmapped.is_out_of_bound
  • Description: JumpCloud Directory Insights field is_out_of_bound preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: is_out_of_bound
  • Usage: all events in this service
unmapped.jc_application_name
  • Description: JumpCloud Directory Insights field jc_application_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_application_name
  • Usage: all events in this service
unmapped.jc_initiated_by_email
  • Description: JumpCloud Directory Insights field jc_initiated_by_email preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_initiated_by_email
  • Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated, notification_send_emails_from_role_failure
unmapped.jc_initiated_by_id
  • Description: JumpCloud Directory Insights field jc_initiated_by_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_initiated_by_id
  • Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated, notification_send_emails_from_role_failure
unmapped.jc_initiated_by_username
  • Description: JumpCloud Directory Insights field jc_initiated_by_username preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_initiated_by_username
  • Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated, notification_send_emails_from_role_failure
unmapped.jc_organization_name
  • Description: JumpCloud Directory Insights field jc_organization_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_organization_name
  • Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated, notification_send_emails_from_role_failure
unmapped.jc_provider_id
  • Description: JumpCloud Directory Insights field jc_provider_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_provider_id
  • Usage: notification_channel_created, notification_channel_updated, notification_send_emails_from_role_failure
unmapped.jc_system_display_name
  • Description: JumpCloud Directory Insights field jc_system_display_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_system_display_name
  • Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated, notification_send_emails_from_role_failure
unmapped.jc_system_hostname
  • Description: JumpCloud Directory Insights field jc_system_hostname preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_system_hostname
  • Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated, notification_send_emails_from_role_failure
unmapped.jc_transformation_ts
  • Description: JumpCloud Directory Insights field jc_transformation_ts preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_transformation_ts
  • Usage: all events in this service
unmapped.notification_type
  • Description: JumpCloud Directory Insights field notification_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: notification_type
  • Usage: notification_send_emails_from_role_failure, notification_send_failure, notification_send_org_rate_limit_reached, notification_triggered_by_webhook, slack_notification_sent
unmapped.resource.id
  • Description: JumpCloud Directory Insights field resource.id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.id
  • Usage: notification_send_emails_from_role_failure, notification_send_failure, notification_send_org_rate_limit_reached, notification_triggered_by_webhook, slack_notification_sent
unmapped.resource.name
  • Description: JumpCloud Directory Insights field resource.name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.name
  • Usage: notification_send_emails_from_role_failure, notification_send_failure, notification_send_org_rate_limit_reached, notification_triggered_by_webhook, slack_notification_sent
unmapped.resource.type
  • Description: JumpCloud Directory Insights field resource.type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.type
  • Usage: notification_send_emails_from_role_failure, notification_send_failure, notification_send_org_rate_limit_reached, notification_triggered_by_webhook, slack_notification_sent
unmapped.resource_id
  • Description: JumpCloud Directory Insights field resource_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource_id
  • Usage: notification_send_emails_from_role_failure, notification_send_org_rate_limit_reached, notification_triggered_by_webhook, slack_notification_sent
unmapped.resource_id_hash
  • Description: JumpCloud Directory Insights field resource_id_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource_id_hash
  • Usage: all events in this service
unmapped.resource_name_hash
  • Description: JumpCloud Directory Insights field resource_name_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource_name_hash
  • Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated, notification_send_emails_from_role_failure
unmapped.resource_type
  • Description: JumpCloud Directory Insights field resource_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource_type
  • Usage: notification_send_emails_from_role_failure, notification_send_org_rate_limit_reached, notification_triggered_by_webhook, slack_notification_sent
unmapped.timestamp_source
  • Description: JumpCloud Directory Insights field timestamp_source preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: timestamp_source
  • Usage: all events in this service
unmapped.user_agent
  • Description: JumpCloud Directory Insights field user_agent preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: user_agent
  • Usage: notification_send_emails_from_role_failure, notification_send_failure, notification_send_org_rate_limit_reached, notification_triggered_by_webhook, slack_notification_sent

Object Storage#

object_storage · 4 events

Event Category Class Activity Type UID Fields
object_storage_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 31
object_storage_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 61
object_storage_get_download_url_request Identity & Access Management (3) Entity Management (3004) Read (2) 300402 33
object_storage_upload_validation_result Identity & Access Management (3) Entity Management (3004) Create (1) 300401 31

OCSF field mappings#

Legend

  • Description: what the OCSF field represents (from OCSF schema v1.8.0)
  • Source: raw JumpCloud event field(s) mapped via ${{placeholder}} template
  • Transform: fieldMappings entry applied at runtime (cast, enum, etc.)
  • Literal: static value set in the mapping template
  • Usage: event types in this service that include this field

Core

activity_id
  • Description: The normalized identifier of the activity that triggered the event.
  • Literal: 1, 2, 4
  • Usage: all events in this service
activity_name
  • Description: The event activity name, as defined by the activity_id.
  • Literal: Create, Delete, Read
  • Usage: all events in this service
category_name
  • Description: The event category name, as defined by category_uid value: Discovery.
  • Literal: Identity & Access Management
  • Usage: all events in this service
category_uid
  • Description: The category unique identifier of the event.
  • Literal: 3
  • Usage: all events in this service
class_name
  • Description: The event class name, as defined by class_uid value: User Inventory Info.
  • Literal: Entity Management
  • Usage: all events in this service
class_uid
  • Description: The unique identifier of a class. A class describes the attributes available in an event.
  • Literal: 3004
  • Usage: all events in this service
severity_id
  • Description: OCSF severity identifier for the event.
  • Literal: 1
  • Usage: all events in this service
status_id
  • Description: Normalized status of the activity (1=Success, 2=Failure).
  • Source: result
  • Transform:
  • result → boolean_to_status_id; true→1, false→2 (object_storage_create, object_storage_delete, object_storage_upload_validation_result)
  • Usage: object_storage_create, object_storage_delete, object_storage_upload_validation_result
time
  • Description: Event time, in epoch milliseconds (OCSF time).
  • Source: timestamp
  • Transform:
  • timestamp → iso8601_to_epoch_millis (all events in this service)
  • Usage: all events in this service
type_uid
  • Description: The event/finding type ID. It identifies the event's semantics and structure. The value is calculated by the logging system as: class_uid * 100 + activity_id.
  • Literal: 300401, 300402, 300404
  • Usage: all events in this service

Metadata

metadata.event_code
  • Description: JumpCloud event type code.
  • Source: event_type
  • Usage: all events in this service
metadata.original_time
  • Description: The original event time as reported by the event source. For example, the time in the original format from system event log such as Syslog on Unix/Linux and the System event file on Windows. Omit if event is generated instead of collected via logs.
  • Source: server_timestamp
  • Usage: object_storage_delete, object_storage_get_download_url_request, object_storage_upload_validation_result
metadata.processed_time
  • Description: The event processed time, such as an ETL operation.
  • Source: jc_transformation_ts
  • Usage: all events in this service
metadata.product.name
  • Description: Originating JumpCloud service that produced the event.
  • Source: service
  • Usage: all events in this service
metadata.tenant_uid
  • Description: JumpCloud organization (tenant) identifier.
  • Source: organization
  • Usage: all events in this service
metadata.uid
  • Description: Unique event identifier assigned by JumpCloud.
  • Source: id
  • Usage: all events in this service
metadata.version
  • Description: OCSF schema version used for this event.
  • Literal: 1.8.0
  • Usage: all events in this service

Actor

actor.user.email_addr
  • Description: Email address of the actor who initiated the event.
  • Source: initiated_by.email
  • Usage: object_storage_delete
actor.user.type_id
  • Description: OCSF user type of the actor (1=User, 2=Admin, 3=System, 4=Service).
  • Source: initiated_by.type
  • Usage: object_storage_delete
actor.user.uid
  • Description: Unique identifier of the actor who initiated the event.
  • Source: initiated_by.id
  • Usage: object_storage_delete

Entity

entity.data.referrer_object_id
  • Description: JumpCloud extension data on the managed entity: referrer_object_id.
  • Source: referrer_object_id
  • Usage: object_storage_create, object_storage_delete, object_storage_get_download_url_request
entity.data.sha_256_checksum
  • Description: JumpCloud extension data on the managed entity: sha_256_checksum.
  • Source: object_storage_item_version_sha_256_sum
  • Usage: all events in this service
entity.data.system_object_id
  • Description: JumpCloud extension data on the managed entity: system_object_id.
  • Source: system_object_id
  • Usage: object_storage_create, object_storage_get_download_url_request
entity.data.total_software_item_count
  • Description: JumpCloud extension data on the managed entity: total_software_item_count.
  • Source: total_software_item_count
  • Usage: object_storage_create, object_storage_delete
entity.data.total_space_used
  • Description: JumpCloud extension data on the managed entity: total_space_used.
  • Source: total_space_used
  • Usage: object_storage_create, object_storage_delete
entity.data.version_object_id
  • Description: JumpCloud extension data on the managed entity: version_object_id.
  • Source: object_storage_item_version_object_id
  • Usage: all events in this service
entity.data.version_size_bytes
  • Description: JumpCloud extension data on the managed entity: version_size_bytes.
  • Source: object_storage_item_version_size
  • Usage: all events in this service
entity.name
  • Description: The name of the managed entity. It should match the name of the specific entity object's name if populated, or the name of the managed entity if the type_id is 'Other'.
  • Source: object_storage_item_version_name
  • Usage: all events in this service
entity.type
  • Description: The managed entity type. For example: Policy, User, Organization, Device.
  • Source: referrer_type
  • Usage: object_storage_create, object_storage_delete, object_storage_get_download_url_request
entity.uid
  • Description: The identifier of the managed entity. It should match the uid of the specific entity's object UID if populated, or the source specific ID if the type_id is 'Other'.
  • Source: object_storage_item_object_id
  • Usage: all events in this service

Src Endpoint

src_endpoint.autonomous_system.name
  • Description: Organization name for the Autonomous System.
  • Source: asn.organization
  • Usage: object_storage_delete
src_endpoint.autonomous_system.number
  • Description: Unique number that the AS is identified by.
  • Source: asn.number
  • Usage: object_storage_delete
src_endpoint.ip
  • Description: Source IP address the request originated from.
  • Source: client_ip
  • Usage: object_storage_delete
src_endpoint.location.city
  • Description: The name of the city.
  • Source: geoip.city
  • Usage: object_storage_delete
src_endpoint.location.continent
  • Description: The name of the continent.
  • Source: geoip.continent_code
  • Usage: object_storage_delete
src_endpoint.location.country
  • Description: The ISO 3166-1 Alpha-2 country code.

    Note: The two letter country code should be capitalized. For example: US or CA.

  • Source: geoip.country_code
  • Usage: object_storage_delete
src_endpoint.location.lat
  • Description: The geographical Latitude coordinate represented in Decimal Degrees (DD). For example: 42.361145.
  • Source: geoip.latitude
  • Transform:
  • geoip.latitude → double (object_storage_delete)
  • Usage: object_storage_delete
src_endpoint.location.long
  • Description: The geographical Longitude coordinate represented in Decimal Degrees (DD). For example: -71.057083.
  • Source: geoip.longitude
  • Transform:
  • geoip.longitude → double (object_storage_delete)
  • Usage: object_storage_delete
src_endpoint.location.region
  • Description: The alphanumeric code that identifies the principal subdivision (e.g. province or state) of the country. For example, 'CH-VD' for the Canton of Vaud, Switzerland
  • Source: geoip.region_code
  • Usage: object_storage_delete

Http Request

http_request.user_agent
  • Description: The request header that identifies the operating system and web browser.
  • Source: user_agent
  • Usage: object_storage_delete

Observables

observables[].name
  • Description: The full name of the observable attribute. The name is a pointer/reference to an attribute within the OCSF event data. For example: file.name. Array attributes may be represented in one of three ways. For example: resources.uid, resources[].uid, resources[0].uid.
  • Literal: actor.user.email_addr, actor.user.uid, http_request.user_agent, src_endpoint.ip, src_endpoint.location.country
  • Usage: object_storage_delete
observables[].type_id
  • Description: The observable value type identifier.
  • Literal: 14, 16, 2, 31, 5
  • Usage: object_storage_delete
observables[].value
  • Description: The value associated with the observable attribute. The meaning of the value depends on the observable type.
    If the name refers to a scalar attribute, then the value is the value of the attribute.
    If the name refers to an object attribute, then the value is not populated.
  • Source: client_ip, geoip.country_code, initiated_by.email, initiated_by.id, user_agent
  • Usage: object_storage_delete

Unmapped

unmapped.@version
  • Description: JumpCloud Directory Insights field @version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: @version
  • Usage: all events in this service
unmapped.asn.network
  • Description: JumpCloud Directory Insights field asn.network preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: asn.network
  • Usage: object_storage_delete
unmapped.client_ip
  • Description: JumpCloud Directory Insights field client_ip preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: client_ip
  • Usage: object_storage_create, object_storage_get_download_url_request, object_storage_upload_validation_result
unmapped.error_message
  • Description: JumpCloud Directory Insights field error_message preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: error_message
  • Usage: all events in this service
unmapped.geoip.region_name
  • Description: JumpCloud Directory Insights field geoip.region_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.region_name
  • Usage: object_storage_delete
unmapped.geoip.timezone
  • Description: JumpCloud Directory Insights field geoip.timezone preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.timezone
  • Usage: object_storage_delete
unmapped.initiated_by
  • Description: JumpCloud Directory Insights field initiated_by preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by
  • Usage: object_storage_create, object_storage_get_download_url_request, object_storage_upload_validation_result
unmapped.initiated_by_email_hash
  • Description: JumpCloud Directory Insights field initiated_by_email_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_email_hash
  • Usage: object_storage_delete
unmapped.initiated_by_id_hash
  • Description: JumpCloud Directory Insights field initiated_by_id_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_id_hash
  • Usage: object_storage_delete
unmapped.is_out_of_bound
  • Description: JumpCloud Directory Insights field is_out_of_bound preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: is_out_of_bound
  • Usage: object_storage_delete, object_storage_get_download_url_request, object_storage_upload_validation_result
unmapped.jc_application_name
  • Description: JumpCloud Directory Insights field jc_application_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_application_name
  • Usage: object_storage_delete, object_storage_get_download_url_request, object_storage_upload_validation_result
unmapped.jc_initiated_by_email
  • Description: JumpCloud Directory Insights field jc_initiated_by_email preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_initiated_by_email
  • Usage: object_storage_delete
unmapped.jc_initiated_by_id
  • Description: JumpCloud Directory Insights field jc_initiated_by_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_initiated_by_id
  • Usage: object_storage_delete
unmapped.jc_initiated_by_username
  • Description: JumpCloud Directory Insights field jc_initiated_by_username preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_initiated_by_username
  • Usage: object_storage_delete
unmapped.jc_organization_name
  • Description: JumpCloud Directory Insights field jc_organization_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_organization_name
  • Usage: object_storage_delete
unmapped.jc_provider_id
  • Description: JumpCloud Directory Insights field jc_provider_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_provider_id
  • Usage: object_storage_delete
unmapped.jc_system_display_name
  • Description: JumpCloud Directory Insights field jc_system_display_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_system_display_name
  • Usage: object_storage_delete
unmapped.jc_system_hostname
  • Description: JumpCloud Directory Insights field jc_system_hostname preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_system_hostname
  • Usage: object_storage_delete
unmapped.provider
  • Description: JumpCloud Directory Insights field provider preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: provider
  • Usage: object_storage_delete
unmapped.success
  • Description: JumpCloud Directory Insights field success preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: success
  • Usage: all events in this service
unmapped.timestamp_source
  • Description: JumpCloud Directory Insights field timestamp_source preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: timestamp_source
  • Usage: object_storage_delete, object_storage_get_download_url_request, object_storage_upload_validation_result
unmapped.user_agent
  • Description: JumpCloud Directory Insights field user_agent preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: user_agent
  • Usage: object_storage_get_download_url_request, object_storage_upload_validation_result

Password Manager#

password_manager · 72 events

Event Category Class Activity Type UID Fields
passwordmanager_app_unlock Identity & Access Management (3) Authentication (3002) Logon (1) 300201 52
passwordmanager_app_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 51
passwordmanager_backup_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 48
passwordmanager_backup_disable Identity & Access Management (3) Entity Management (3004) Disable (9) 300409 58
passwordmanager_backup_enable Identity & Access Management (3) Entity Management (3004) Enable (8) 300408 67
passwordmanager_backup_key_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 67
passwordmanager_backup_key_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 63
passwordmanager_backup_key_regenerate Identity & Access Management (3) Entity Management (3004) Update (3) 300403 63
passwordmanager_backup_request Identity & Access Management (3) Entity Management (3004) Create (1) 300401 51
passwordmanager_backup_request_approve Identity & Access Management (3) Entity Management (3004) Update (3) 300403 62
passwordmanager_backup_request_cancel Identity & Access Management (3) Entity Management (3004) Update (3) 300403 48
passwordmanager_backup_request_reject Identity & Access Management (3) Entity Management (3004) Update (3) 300403 68
passwordmanager_backup_request_restore Identity & Access Management (3) Entity Management (3004) Update (3) 300403 48
passwordmanager_batch_folder_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 55
passwordmanager_disable Identity & Access Management (3) Entity Management (3004) Disable (9) 300409 69
passwordmanager_enable Identity & Access Management (3) Entity Management (3004) Enable (8) 300408 67
passwordmanager_extension_pair Identity & Access Management (3) Entity Management (3004) Enroll (6) 300406 48
passwordmanager_extension_settings_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 51
passwordmanager_extension_site_exclusion Identity & Access Management (3) Entity Management (3004) Create (1) 300401 43
passwordmanager_extension_unlock Identity & Access Management (3) Entity Management (3004) Read (2) 300402 48
passwordmanager_folder_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 70
passwordmanager_folder_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 46
passwordmanager_folder_force_sync System Activity (1) Scheduled Job Activity (1006) Start (6) 100606 43
passwordmanager_folder_group_add Identity & Access Management (3) Entity Management (3004) Update (3) 300403 74
passwordmanager_folder_group_remove Identity & Access Management (3) Entity Management (3004) Update (3) 300403 72
passwordmanager_folder_group_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 70
passwordmanager_folder_member_add Identity & Access Management (3) Group Management (3006) Add User (3) 300603 50
passwordmanager_folder_member_remove Identity & Access Management (3) Group Management (3006) Remove User (4) 300604 73
passwordmanager_folder_member_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 74
passwordmanager_folder_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 69
passwordmanager_force_sync Identity & Access Management (3) Entity Management (3004) Update (3) 300403 52
passwordmanager_get_item_secret Identity & Access Management (3) Entity Management (3004) Read (2) 300402 36
passwordmanager_item_add Identity & Access Management (3) Entity Management (3004) Update (3) 300403 52
passwordmanager_item_autofill Identity & Access Management (3) Entity Management (3004) Read (2) 300402 35
passwordmanager_item_copy Identity & Access Management (3) Entity Management (3004) Read (2) 300402 45
passwordmanager_item_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 39
passwordmanager_item_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 38
passwordmanager_item_history_restore Identity & Access Management (3) Entity Management (3004) Update (3) 300403 55
passwordmanager_item_history_reveal Identity & Access Management (3) Entity Management (3004) Read (2) 300402 49
passwordmanager_item_move Identity & Access Management (3) Entity Management (3004) Move (5) 300405 58
passwordmanager_item_remove Identity & Access Management (3) Entity Management (3004) Update (3) 300403 52
passwordmanager_item_reveal Identity & Access Management (3) Entity Management (3004) Read (2) 300402 48
passwordmanager_item_settings_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 55
passwordmanager_item_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 61
passwordmanager_items_export Identity & Access Management (3) Entity Management (3004) Read (2) 300402 43
passwordmanager_items_import Identity & Access Management (3) Entity Management (3004) Create (1) 300401 45
passwordmanager_local_backup_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 47
passwordmanager_local_backup_path_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 55
passwordmanager_local_backup_restore System Activity (1) Scheduled Job Activity (1006) Start (6) 100606 50
passwordmanager_migration_complete System Activity (1) Scheduled Job Activity (1006) Update (2) 100602 38
passwordmanager_migration_start System Activity (1) Scheduled Job Activity (1006) Start (6) 100606 38
passwordmanager_mini_launch System Activity (1) Scheduled Job Activity (1006) Start (6) 100606 52
passwordmanager_paranoid_mode_disable Identity & Access Management (3) Entity Management (3004) Disable (9) 300409 55
passwordmanager_paranoid_mode_enable Identity & Access Management (3) Entity Management (3004) Enable (8) 300408 55
passwordmanager_pincode_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 55
passwordmanager_policy_export_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 71
passwordmanager_sharedfolders_policy_group_add Identity & Access Management (3) Entity Management (3004) Update (3) 300403 66
passwordmanager_sharedfolders_policy_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 65
passwordmanager_sharedfolders_policy_user_add Identity & Access Management (3) Entity Management (3004) Update (3) 300403 69
passwordmanager_sharedfolders_policy_user_remove Identity & Access Management (3) Entity Management (3004) Update (3) 300403 65
passwordmanager_user_activate Identity & Access Management (3) Account Change (3001) Enable (2) 300102 52
passwordmanager_user_deactivate Identity & Access Management (3) Account Change (3001) Disable (5) 300105 53
passwordmanager_user_device_pair Identity & Access Management (3) Account Change (3001) Other (99) 300199 48
passwordmanager_user_device_unpair Identity & Access Management (3) Account Change (3001) Other (99) 300199 53
passwordmanager_user_disable Identity & Access Management (3) Account Change (3001) Disable (5) 300105 39
passwordmanager_user_enable Identity & Access Management (3) Account Change (3001) Enable (2) 300102 45
passwordmanager_user_migration Identity & Access Management (3) Account Change (3001) Other (99) 300199 40
passwordmanager_user_re-enable Identity & Access Management (3) Account Change (3001) Enable (2) 300102 43
passwordmanager_user_reactivate Identity & Access Management (3) Account Change (3001) Enable (2) 300102 55
passwordmanager_user_remove Identity & Access Management (3) Account Change (3001) Delete (6) 300106 34
passwordmanager_user_signup Identity & Access Management (3) Account Change (3001) Create (1) 300101 53
passwordmanager_user_update Identity & Access Management (3) Account Change (3001) Other (99) 300199 40

OCSF field mappings#

Legend

  • Description: what the OCSF field represents (from OCSF schema v1.8.0)
  • Source: raw JumpCloud event field(s) mapped via ${{placeholder}} template
  • Transform: fieldMappings entry applied at runtime (cast, enum, etc.)
  • Literal: static value set in the mapping template
  • Usage: event types in this service that include this field

Core

activity_id
  • Description: The normalized identifier of the activity that triggered the event.
  • Literal: 1, 2, 3, 4, 5, 6, 8, 9, 99
  • Usage: all events in this service
activity_name
  • Description: The event activity name, as defined by the activity_id.
  • Literal: Add User, Create, Delete, Disable, Enable, Enroll, Logon, Move, Other, Read, Remove User, Start, Update
  • Usage: all events in this service
category_name
  • Description: The event category name, as defined by category_uid value: Discovery.
  • Literal: Identity & Access Management, System Activity
  • Usage: all events in this service
category_uid
  • Description: The category unique identifier of the event.
  • Literal: 1, 3
  • Usage: all events in this service
class_name
  • Description: The event class name, as defined by class_uid value: User Inventory Info.
  • Literal: Account Change, Authentication, Entity Management, Group Management, Scheduled Job Activity
  • Usage: all events in this service
class_uid
  • Description: The unique identifier of a class. A class describes the attributes available in an event.
  • Literal: 1006, 3001, 3002, 3004, 3006
  • Usage: all events in this service
severity_id
  • Description: OCSF severity identifier for the event.
  • Literal: 1
  • Usage: all events in this service
status_detail
  • Description: The status detail contains additional information about the event/finding outcome.
  • Source: error_message
  • Usage: 71 events (missing: passwordmanager_item_autofill)
status_id
  • Description: Normalized status of the activity (1=Success, 2=Failure).
  • Source: success
  • Transform:
  • success → boolean_to_status_id; true→1, false→2 (all events in this service)
  • Usage: all events in this service
time
  • Description: Event time, in epoch milliseconds (OCSF time).
  • Source: timestamp
  • Transform:
  • timestamp → iso8601_to_epoch_millis (all events in this service)
  • Usage: all events in this service
type_uid
  • Description: The event/finding type ID. It identifies the event's semantics and structure. The value is calculated by the logging system as: class_uid * 100 + activity_id.
  • Literal: 100602, 100606, 300101, 300102, 300105, 300106, 300199, 300201, 300401, 300402, 300403, 300404, 300405, 300406, 300408, 300409, 300603, 300604
  • Usage: all events in this service

Metadata

metadata.event_code
  • Description: JumpCloud event type code.
  • Source: event_type
  • Usage: all events in this service
metadata.original_time
  • Description: The original event time as reported by the event source. For example, the time in the original format from system event log such as Syslog on Unix/Linux and the System event file on Windows. Omit if event is generated instead of collected via logs.
  • Source: server_timestamp
  • Usage: passwordmanager_get_item_secret, passwordmanager_item_create, passwordmanager_item_delete, passwordmanager_item_update, passwordmanager_migration_complete, passwordmanager_migration_start, passwordmanager_user_migration
metadata.processed_time
  • Description: The event processed time, such as an ETL operation.
  • Source: jc_transformation_ts
  • Usage: 71 events (missing: passwordmanager_item_autofill)
metadata.product.name
  • Description: Originating JumpCloud service that produced the event.
  • Source: service
  • Usage: all events in this service
metadata.tenant_uid
  • Description: JumpCloud organization (tenant) identifier.
  • Source: organization
  • Usage: all events in this service
metadata.uid
  • Description: Unique event identifier assigned by JumpCloud.
  • Source: id
  • Usage: all events in this service
metadata.version
  • Description: OCSF schema version used for this event.
  • Literal: 1.8.0
  • Usage: all events in this service

Actor

actor.user.email_addr
  • Description: Email address of the actor who initiated the event.
  • Source: initiated_by.email
  • Usage: 61 events: passwordmanager_app_unlock, passwordmanager_app_update, passwordmanager_backup_create, passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, ... (+53 more)
actor.user.name
  • Description: Display name of the actor who initiated the event.
  • Source: initiated_by.username
  • Usage: 50 events: passwordmanager_app_update, passwordmanager_backup_create, passwordmanager_backup_request, passwordmanager_backup_request_cancel, passwordmanager_backup_request_restore, passwordmanager_batch_folder_delete, passwordmanager_extension_pair, passwordmanager_extension_settings_update, ... (+42 more)
actor.user.type_id
  • Description: OCSF user type of the actor (1=User, 2=Admin, 3=System, 4=Service).
  • Source: initiated_by.type
  • Transform:
  • initiated_by.type → enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (71 events (missing: passwordmanager_get_item_secret))
  • Usage: 71 events (missing: passwordmanager_get_item_secret)
actor.user.uid
  • Description: Unique identifier of the actor who initiated the event.
  • Source: initiated_by.id
  • Usage: 66 events (missing: passwordmanager_get_item_secret, passwordmanager_user_disable, passwordmanager_user_enable, passwordmanager_user_re-enable, passwordmanager_user_remove...)

User

user.email_addr
  • Description: Email address of the user associated with the event.
  • Source: association.connection.to.email
  • Usage: passwordmanager_folder_member_remove
user.name
  • Description: The username. For example, janedoe1.
  • Source: association.connection.to.name, initiated_by.username, resource.username
  • Usage: 15 events: passwordmanager_app_unlock, passwordmanager_folder_member_add, passwordmanager_folder_member_remove, passwordmanager_user_activate, passwordmanager_user_deactivate, passwordmanager_user_device_pair, passwordmanager_user_device_unpair, passwordmanager_user_disable, ... (+7 more)
user.type_id
  • Description: OCSF user type (1=User, 2=Admin, 3=System, 4=Service).
  • Source: resource.type
  • Transform:
  • resource.type → enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (12 events: passwordmanager_user_activate, passwordmanager_user_deactivate, passwordmanager_user_device_pair, passwordmanager_user_device_unpair, passwordmanager_user_disable, passwordmanager_user_enable, passwordmanager_user_migration, passwordmanager_user_re-enable, ... (+4 more))
  • Usage: 12 events: passwordmanager_user_activate, passwordmanager_user_deactivate, passwordmanager_user_device_pair, passwordmanager_user_device_unpair, passwordmanager_user_disable, passwordmanager_user_enable, passwordmanager_user_migration, passwordmanager_user_re-enable, ... (+4 more)
user.uid
  • Description: Unique identifier of the user associated with the event.
  • Source: association.connection.to.object_id, resource.id
  • Usage: 14 events: passwordmanager_folder_member_add, passwordmanager_folder_member_remove, passwordmanager_user_activate, passwordmanager_user_deactivate, passwordmanager_user_device_pair, passwordmanager_user_device_unpair, passwordmanager_user_disable, passwordmanager_user_enable, ... (+6 more)

Device

device.hostname
  • Description: The device hostname.
  • Source: resource.name
  • Usage: passwordmanager_app_unlock
device.uid
  • Description: The unique identifier of the device. For example the Windows TargetSID or AWS EC2 ARN.
  • Source: resource.id
  • Usage: passwordmanager_app_unlock

Entity

entity.data.associated_group_name
  • Description: JumpCloud extension data on the managed entity: associated_group_name.
  • Source: association.connection.to.name
  • Usage: passwordmanager_folder_group_add, passwordmanager_folder_group_remove, passwordmanager_folder_group_update, passwordmanager_folder_member_update
entity.data.associated_group_type
  • Description: JumpCloud extension data on the managed entity: associated_group_type.
  • Source: association.connection.to.type
  • Usage: passwordmanager_folder_group_add, passwordmanager_folder_group_remove, passwordmanager_folder_group_update, passwordmanager_folder_member_update
entity.data.associated_group_uid
  • Description: JumpCloud extension data on the managed entity: associated_group_uid.
  • Source: association.connection.to.object_id
  • Usage: passwordmanager_folder_group_add, passwordmanager_folder_group_remove, passwordmanager_folder_group_update, passwordmanager_folder_member_update
entity.data.association_from_name
  • Description: JumpCloud extension data on the managed entity: association_from_name.
  • Source: association.connection.from.name
  • Usage: passwordmanager_backup_request, passwordmanager_disable, passwordmanager_enable
entity.data.association_from_object_id
  • Description: JumpCloud extension data on the managed entity: association_from_object_id.
  • Source: association.connection.from.object_id
  • Usage: passwordmanager_backup_request, passwordmanager_disable, passwordmanager_enable
entity.data.association_from_type
  • Description: JumpCloud extension data on the managed entity: association_from_type.
  • Source: association.connection.from.type
  • Usage: passwordmanager_backup_request, passwordmanager_disable, passwordmanager_enable
entity.data.association_op
  • Description: JumpCloud extension data on the managed entity: association_op.
  • Source: association.op
  • Usage: passwordmanager_backup_request, passwordmanager_disable, passwordmanager_enable, passwordmanager_item_add, passwordmanager_item_move, passwordmanager_item_remove, passwordmanager_item_update, passwordmanager_sharedfolders_policy_group_add, passwordmanager_sharedfolders_policy_user_add, passwordmanager_sharedfolders_policy_user_remove
entity.data.association_to_name
  • Description: JumpCloud extension data on the managed entity: association_to_name.
  • Source: association.connection.to.name
  • Usage: passwordmanager_sharedfolders_policy_group_add, passwordmanager_sharedfolders_policy_user_add, passwordmanager_sharedfolders_policy_user_remove
entity.data.association_to_object_id
  • Description: JumpCloud extension data on the managed entity: association_to_object_id.
  • Source: association.connection.to.object_id
  • Usage: passwordmanager_backup_request, passwordmanager_sharedfolders_policy_group_add, passwordmanager_sharedfolders_policy_user_add, passwordmanager_sharedfolders_policy_user_remove
entity.data.association_to_type
  • Description: JumpCloud extension data on the managed entity: association_to_type.
  • Source: association.connection.to.type
  • Usage: passwordmanager_backup_request, passwordmanager_sharedfolders_policy_group_add, passwordmanager_sharedfolders_policy_user_add, passwordmanager_sharedfolders_policy_user_remove
entity.data.auth_method
  • Description: JumpCloud extension data on the managed entity: auth_method.
  • Source: auth_method
  • Usage: 20 events: passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_backup_request_approve, passwordmanager_backup_request_reject, passwordmanager_disable, ... (+12 more)
entity.data.calling_service
  • Description: JumpCloud extension data on the managed entity: calling_service.
  • Source: calling_service
  • Usage: passwordmanager_get_item_secret
entity.data.changed_field
  • Description: JumpCloud extension data on the managed entity: changed_field.
  • Source: changes.field
  • Usage: 17 events: passwordmanager_app_update, passwordmanager_backup_request_approve, passwordmanager_backup_request_cancel, passwordmanager_backup_request_reject, passwordmanager_backup_request_restore, passwordmanager_disable, passwordmanager_extension_settings_update, passwordmanager_folder_group_add, ... (+9 more)
entity.data.changed_from
  • Description: JumpCloud extension data on the managed entity: changed_from.
  • Source: changes.from
  • Usage: passwordmanager_extension_settings_update, passwordmanager_item_settings_update, passwordmanager_policy_export_update, passwordmanager_sharedfolders_policy_update
entity.data.changes_from
  • Description: JumpCloud extension data on the managed entity: changes_from.
  • Source: changes.from
  • Usage: 11 events: passwordmanager_app_update, passwordmanager_backup_request_approve, passwordmanager_backup_request_cancel, passwordmanager_backup_request_reject, passwordmanager_backup_request_restore, passwordmanager_folder_group_add, passwordmanager_folder_group_remove, passwordmanager_folder_group_update, ... (+3 more)
entity.data.created_at
  • Description: JumpCloud extension data on the managed entity: created_at.
  • Source: additional_data.CreatedAt
  • Usage: passwordmanager_item_create
entity.data.deleted_at
  • Description: JumpCloud extension data on the managed entity: deleted_at.
  • Source: additional_data.DeletedAt
  • Usage: passwordmanager_item_delete
entity.data.deleted_folder_id
  • Description: JumpCloud extension data on the managed entity: deleted_folder_id.
  • Source: changes.id
  • Usage: passwordmanager_batch_folder_delete
entity.data.deleted_folder_name
  • Description: JumpCloud extension data on the managed entity: deleted_folder_name.
  • Source: changes.name
  • Usage: passwordmanager_batch_folder_delete
entity.data.deleted_folder_type
  • Description: JumpCloud extension data on the managed entity: deleted_folder_type.
  • Source: changes.type
  • Usage: passwordmanager_batch_folder_delete
entity.data.description
  • Description: JumpCloud extension data on the managed entity: description.
  • Source: additional_data.Description, additional_data.description
  • Usage: passwordmanager_item_create, passwordmanager_item_delete, passwordmanager_item_update
entity.data.event_schema_version
  • Description: JumpCloud extension data on the managed entity: event_schema_version.
  • Source: version
  • Usage: passwordmanager_get_item_secret, passwordmanager_item_create, passwordmanager_item_delete, passwordmanager_item_update
entity.data.initiator_provider
  • Description: JumpCloud extension data on the managed entity: initiator_provider.
  • Source: initiated_by.provider
  • Usage: passwordmanager_backup_request_reject
entity.data.initiator_user_id
  • Description: JumpCloud extension data on the managed entity: initiator_user_id.
  • Source: initiated_by.user_id
  • Usage: passwordmanager_backup_request_reject
entity.data.provider
  • Description: JumpCloud extension data on the managed entity: provider.
  • Source: provider
  • Usage: passwordmanager_backup_request_reject, passwordmanager_policy_export_update, passwordmanager_sharedfolders_policy_group_add, passwordmanager_sharedfolders_policy_update, passwordmanager_sharedfolders_policy_user_add, passwordmanager_sharedfolders_policy_user_remove
entity.data.resource_id
  • Description: JumpCloud extension data on the managed entity: resource_id.
  • Source: resource.id
  • Usage: passwordmanager_item_move
entity.data.resource_name
  • Description: JumpCloud extension data on the managed entity: resource_name.
  • Source: resource.name
  • Usage: passwordmanager_item_move
entity.data.resource_type
  • Description: JumpCloud extension data on the managed entity: resource_type.
  • Source: resource.type
  • Usage: passwordmanager_item_move
entity.data.secret_id
  • Description: JumpCloud extension data on the managed entity: secret_id.
  • Source: secret_id
  • Usage: passwordmanager_get_item_secret
entity.data.target_object_id
  • Description: JumpCloud extension data on the managed entity: target_object_id.
  • Source: target_object_id
  • Usage: passwordmanager_get_item_secret
entity.data.updated_at
  • Description: JumpCloud extension data on the managed entity: updated_at.
  • Source: additional_data.UpdatedAt, additional_data.updated_at
  • Usage: passwordmanager_item_create, passwordmanager_item_update
entity.data.useragent_device
  • Description: JumpCloud extension data on the managed entity: useragent_device.
  • Source: useragent.device
  • Usage: 12 events: passwordmanager_item_add, passwordmanager_item_autofill, passwordmanager_item_copy, passwordmanager_item_history_restore, passwordmanager_item_history_reveal, passwordmanager_item_move, passwordmanager_item_remove, passwordmanager_item_reveal, ... (+4 more)
entity.data.useragent_name
  • Description: JumpCloud extension data on the managed entity: useragent_name.
  • Source: useragent.name
  • Usage: 12 events: passwordmanager_item_add, passwordmanager_item_autofill, passwordmanager_item_copy, passwordmanager_item_history_restore, passwordmanager_item_history_reveal, passwordmanager_item_move, passwordmanager_item_remove, passwordmanager_item_reveal, ... (+4 more)
entity.data.useragent_os
  • Description: JumpCloud extension data on the managed entity: useragent_os.
  • Source: useragent.os
  • Usage: 12 events: passwordmanager_item_add, passwordmanager_item_autofill, passwordmanager_item_copy, passwordmanager_item_history_restore, passwordmanager_item_history_reveal, passwordmanager_item_move, passwordmanager_item_remove, passwordmanager_item_reveal, ... (+4 more)
entity.data.useragent_os_full
  • Description: JumpCloud extension data on the managed entity: useragent_os_full.
  • Source: useragent.os_full
  • Usage: 12 events: passwordmanager_item_add, passwordmanager_item_autofill, passwordmanager_item_copy, passwordmanager_item_history_restore, passwordmanager_item_history_reveal, passwordmanager_item_move, passwordmanager_item_remove, passwordmanager_item_reveal, ... (+4 more)
entity.data.useragent_os_name
  • Description: JumpCloud extension data on the managed entity: useragent_os_name.
  • Source: useragent.os_name
  • Usage: 12 events: passwordmanager_item_add, passwordmanager_item_autofill, passwordmanager_item_copy, passwordmanager_item_history_restore, passwordmanager_item_history_reveal, passwordmanager_item_move, passwordmanager_item_remove, passwordmanager_item_reveal, ... (+4 more)
entity.device.hostname
  • Description: The device hostname.
  • Source: resource.name
  • Usage: passwordmanager_app_update, passwordmanager_backup_create, passwordmanager_backup_request, passwordmanager_batch_folder_delete, passwordmanager_force_sync, passwordmanager_local_backup_path_update, passwordmanager_paranoid_mode_disable, passwordmanager_paranoid_mode_enable, passwordmanager_pincode_update
entity.device.uid
  • Description: The unique identifier of the device. For example the Windows TargetSID or AWS EC2 ARN.
  • Source: resource.id
  • Usage: passwordmanager_app_update, passwordmanager_backup_create, passwordmanager_backup_request, passwordmanager_batch_folder_delete, passwordmanager_local_backup_path_update
entity.name
  • Description: The name of the managed entity. It should match the name of the specific entity object's name if populated, or the name of the managed entity if the type_id is 'Other'.
  • Source: additional_data.ItemName, association.connection.from.name, resource.name
  • Usage: 38 events: passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_backup_request_approve, passwordmanager_backup_request_cancel, passwordmanager_backup_request_reject, passwordmanager_backup_request_restore, ... (+30 more)
entity.type
  • Description: The managed entity type. For example: Policy, User, Organization, Device.
  • Source: additional_data.ItemType, association.connection.from.type, resource.type, target_type
  • Usage: 51 events: passwordmanager_app_update, passwordmanager_backup_create, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_backup_request, passwordmanager_backup_request_approve, ... (+43 more)
entity.uid
  • Description: The identifier of the managed entity. It should match the uid of the specific entity's object UID if populated, or the source specific ID if the type_id is 'Other'.
  • Source: association.connection.from.object_id, item_id, resource.id
  • Usage: 43 events: passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_backup_request_approve, passwordmanager_backup_request_cancel, passwordmanager_backup_request_reject, passwordmanager_backup_request_restore, ... (+35 more)
entity.version
  • Description: The version of the managed entity. For example: 1.2.3.
  • Source: resource.name
  • Usage: passwordmanager_extension_pair, passwordmanager_extension_settings_update, passwordmanager_extension_unlock
entity_result.data.changed_to
  • Description: JumpCloud extension data on the managed entity: changed_to.
  • Source: changes.to
  • Usage: passwordmanager_extension_settings_update, passwordmanager_item_settings_update, passwordmanager_policy_export_update, passwordmanager_sharedfolders_policy_update
entity_result.data.changes_to
  • Description: JumpCloud extension data on the managed entity: changes_to.
  • Source: changes.to
  • Usage: 12 events: passwordmanager_app_update, passwordmanager_backup_request_approve, passwordmanager_backup_request_cancel, passwordmanager_backup_request_reject, passwordmanager_backup_request_restore, passwordmanager_disable, passwordmanager_folder_group_add, passwordmanager_folder_group_remove, ... (+4 more)
entity_result.name
  • Description: The name of the managed entity. It should match the name of the specific entity object's name if populated, or the name of the managed entity if the type_id is 'Other'.
  • Source: association.connection.to.name
  • Usage: passwordmanager_item_add, passwordmanager_item_move, passwordmanager_item_remove, passwordmanager_item_update
entity_result.type
  • Description: The managed entity type. For example: Policy, User, Organization, Device.
  • Source: association.connection.to.type
  • Usage: passwordmanager_item_add, passwordmanager_item_move, passwordmanager_item_remove, passwordmanager_item_update
entity_result.uid
  • Description: The identifier of the managed entity. It should match the uid of the specific entity's object UID if populated, or the source specific ID if the type_id is 'Other'.
  • Source: association.connection.to.object_id
  • Usage: passwordmanager_item_add, passwordmanager_item_move, passwordmanager_item_remove, passwordmanager_item_update

Src Endpoint

src_endpoint.autonomous_system.name
  • Description: Organization name for the Autonomous System.
  • Source: asn.organization
  • Usage: 26 events: passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_backup_request_approve, passwordmanager_backup_request_reject, passwordmanager_batch_folder_delete, ... (+18 more)
src_endpoint.autonomous_system.number
  • Description: Unique number that the AS is identified by.
  • Source: asn.number
  • Transform:
  • asn.number → int (26 events: passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_backup_request_approve, passwordmanager_backup_request_reject, passwordmanager_batch_folder_delete, ... (+18 more))
  • Usage: 26 events: passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_backup_request_approve, passwordmanager_backup_request_reject, passwordmanager_batch_folder_delete, ... (+18 more)
src_endpoint.ip
  • Description: Source IP address the request originated from.
  • Source: client_ip
  • Usage: 67 events (missing: passwordmanager_folder_force_sync, passwordmanager_local_backup_restore, passwordmanager_migration_complete, passwordmanager_migration_start, passwordmanager_mini_launch)
src_endpoint.location.city
  • Description: The name of the city.
  • Source: geoip.city
  • Usage: 29 events: passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_backup_request_approve, passwordmanager_backup_request_reject, passwordmanager_batch_folder_delete, ... (+21 more)
src_endpoint.location.continent
  • Description: The name of the continent.
  • Source: geoip.continent_code
  • Usage: 29 events: passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_backup_request_approve, passwordmanager_backup_request_reject, passwordmanager_batch_folder_delete, ... (+21 more)
src_endpoint.location.country
  • Description: The ISO 3166-1 Alpha-2 country code.

    Note: The two letter country code should be capitalized. For example: US or CA.

  • Source: geoip.country_code
  • Usage: 29 events: passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_backup_request_approve, passwordmanager_backup_request_reject, passwordmanager_batch_folder_delete, ... (+21 more)
src_endpoint.location.lat
  • Description: The geographical Latitude coordinate represented in Decimal Degrees (DD). For example: 42.361145.
  • Source: geoip.latitude
  • Transform:
  • geoip.latitude → double (29 events: passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_backup_request_approve, passwordmanager_backup_request_reject, passwordmanager_batch_folder_delete, ... (+21 more))
  • Usage: 29 events: passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_backup_request_approve, passwordmanager_backup_request_reject, passwordmanager_batch_folder_delete, ... (+21 more)
src_endpoint.location.long
  • Description: The geographical Longitude coordinate represented in Decimal Degrees (DD). For example: -71.057083.
  • Source: geoip.longitude
  • Transform:
  • geoip.longitude → double (21 events: passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_backup_request_approve, passwordmanager_backup_request_reject, passwordmanager_batch_folder_delete, ... (+13 more))
  • Usage: 29 events: passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_backup_request_approve, passwordmanager_backup_request_reject, passwordmanager_batch_folder_delete, ... (+21 more)
src_endpoint.location.region
  • Description: The alphanumeric code that identifies the principal subdivision (e.g. province or state) of the country. For example, 'CH-VD' for the Canton of Vaud, Switzerland
  • Source: geoip.region_code
  • Usage: 29 events: passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_backup_request_approve, passwordmanager_backup_request_reject, passwordmanager_batch_folder_delete, ... (+21 more)

Http Request

http_request.user_agent
  • Description: The request header that identifies the operating system and web browser.
  • Source: user_agent
  • Usage: 63 events: passwordmanager_app_unlock, passwordmanager_app_update, passwordmanager_backup_create, passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, ... (+55 more)

Observables

observables[].name
  • Description: The full name of the observable attribute. The name is a pointer/reference to an attribute within the OCSF event data. For example: file.name. Array attributes may be represented in one of three ways. For example: resources.uid, resources[].uid, resources[0].uid.
  • Literal: actor.user.email_addr, actor.user.name, actor.user.uid, device.hostname, device.uid, entity.device.hostname, entity.device.uid, group.name, group.uid, http_request.user_agent, src_endpoint.ip, src_endpoint.location.country, user.email_addr, user.name, user.uid
  • Usage: all events in this service
observables[].type_id
  • Description: The observable value type identifier.
  • Literal: 1, 14, 16, 2, 31, 32, 33, 4, 47, 5
  • Usage: all events in this service
observables[].value
  • Description: The value associated with the observable attribute. The meaning of the value depends on the observable type.
    If the name refers to a scalar attribute, then the value is the value of the attribute.
    If the name refers to an object attribute, then the value is not populated.
  • Source: association.connection.from.name, association.connection.from.object_id, association.connection.to.email, association.connection.to.id, association.connection.to.name, association.connection.to.object_id, client_ip, geoip.country_code, initiated_by.email, initiated_by.id, initiated_by.username, resource.id, resource.name, resource.username, user_agent
  • Usage: all events in this service

Other

action
  • Description: The normalized caption of action_id.
  • Source: association.op
  • Usage: passwordmanager_folder_group_add, passwordmanager_folder_group_remove, passwordmanager_folder_group_update, passwordmanager_folder_member_add, passwordmanager_folder_member_remove, passwordmanager_folder_member_update
group.name
  • Description: The group name.
  • Source: resource.name
  • Usage: passwordmanager_folder_member_add, passwordmanager_folder_member_remove
group.type
  • Description: The type of the group.
  • Source: resource.type
  • Usage: passwordmanager_folder_member_add, passwordmanager_folder_member_remove
group.uid
  • Description: The unique identifier of the group. For example, for Windows events this is the security identifier (SID) of the group. Another example, pool id or desktop id that the device belongs to.
  • Source: resource.id
  • Usage: passwordmanager_folder_member_add, passwordmanager_folder_member_remove
job.desc
  • Description: The description of the job.
  • Source: resource.type
  • Usage: passwordmanager_folder_force_sync, passwordmanager_local_backup_restore, passwordmanager_migration_complete, passwordmanager_migration_start, passwordmanager_mini_launch
job.name
  • Description: The name of the job.
  • Source: resource.name
  • Usage: passwordmanager_folder_force_sync, passwordmanager_local_backup_restore, passwordmanager_mini_launch

Unmapped

unmapped.@timestamp
  • Description: JumpCloud Directory Insights field @timestamp preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: @timestamp
  • Usage: 31 events: passwordmanager_app_unlock, passwordmanager_backup_create, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_request_reject, passwordmanager_disable, passwordmanager_folder_create, passwordmanager_folder_member_add, ... (+23 more)
unmapped.@version
  • Description: JumpCloud Directory Insights field @version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: @version
  • Usage: all events in this service
unmapped.asn.error
  • Description: JumpCloud Directory Insights field asn.error preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: asn.error
  • Usage: 23 events: passwordmanager_app_unlock, passwordmanager_app_update, passwordmanager_backup_create, passwordmanager_backup_request, passwordmanager_backup_request_cancel, passwordmanager_backup_request_restore, passwordmanager_extension_pair, passwordmanager_extension_settings_update, ... (+15 more)
unmapped.asn.ip_address
  • Description: JumpCloud Directory Insights field asn.ip_address preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: asn.ip_address
  • Usage: 23 events: passwordmanager_app_unlock, passwordmanager_app_update, passwordmanager_backup_create, passwordmanager_backup_request, passwordmanager_backup_request_cancel, passwordmanager_backup_request_restore, passwordmanager_extension_pair, passwordmanager_extension_settings_update, ... (+15 more)
unmapped.asn.network
  • Description: JumpCloud Directory Insights field asn.network preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: asn.network
  • Usage: 18 events: passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_backup_request_approve, passwordmanager_backup_request_reject, passwordmanager_batch_folder_delete, passwordmanager_disable, ... (+10 more)
unmapped.asn_number
  • Description: JumpCloud Directory Insights field asn_number preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: asn.number
  • Usage: passwordmanager_mini_launch
unmapped.asn_organization
  • Description: JumpCloud Directory Insights field asn_organization preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: asn.organization
  • Usage: passwordmanager_mini_launch
unmapped.association_connection_to_email
  • Description: JumpCloud Directory Insights field association_connection_to_email preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: association.connection.to.email
  • Usage: passwordmanager_folder_member_update
unmapped.association_connection_to_id
  • Description: JumpCloud Directory Insights field association_connection_to_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: association.connection.to.id
  • Usage: passwordmanager_folder_member_update
unmapped.association_from_name
  • Description: JumpCloud Directory Insights field association_from_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: association.connection.from.name
  • Usage: passwordmanager_user_device_pair, passwordmanager_user_device_unpair
unmapped.association_from_object_id
  • Description: JumpCloud Directory Insights field association_from_object_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: association.connection.from.object_id
  • Usage: passwordmanager_user_device_pair, passwordmanager_user_device_unpair
unmapped.association_from_type
  • Description: JumpCloud Directory Insights field association_from_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: association.connection.from.type
  • Usage: passwordmanager_user_device_pair, passwordmanager_user_device_unpair
unmapped.association_op
  • Description: JumpCloud Directory Insights field association_op preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: association.op
  • Usage: passwordmanager_user_device_pair, passwordmanager_user_device_unpair, passwordmanager_user_enable
unmapped.association_to_name
  • Description: JumpCloud Directory Insights field association_to_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: association.connection.to.name
  • Usage: passwordmanager_user_device_pair, passwordmanager_user_device_unpair, passwordmanager_user_enable
unmapped.association_to_object_id
  • Description: JumpCloud Directory Insights field association_to_object_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: association.connection.to.object_id
  • Usage: passwordmanager_user_device_pair, passwordmanager_user_device_unpair, passwordmanager_user_enable
unmapped.association_to_type
  • Description: JumpCloud Directory Insights field association_to_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: association.connection.to.type
  • Usage: passwordmanager_folder_member_add, passwordmanager_folder_member_remove, passwordmanager_user_device_pair, passwordmanager_user_device_unpair, passwordmanager_user_enable
unmapped.auth_method
  • Description: JumpCloud Directory Insights field auth_method preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: auth_method
  • Usage: passwordmanager_folder_member_remove, passwordmanager_user_disable, passwordmanager_user_enable, passwordmanager_user_re-enable, passwordmanager_user_remove, passwordmanager_user_update
unmapped.changed_field
  • Description: JumpCloud Directory Insights field changed_field preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.field
  • Usage: passwordmanager_user_activate, passwordmanager_user_disable, passwordmanager_user_re-enable, passwordmanager_user_reactivate, passwordmanager_user_update
unmapped.changes_field
  • Description: JumpCloud Directory Insights field changes_field preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.field
  • Usage: passwordmanager_folder_member_remove
unmapped.changes_from
  • Description: JumpCloud Directory Insights field changes_from preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.from
  • Usage: passwordmanager_folder_member_remove
unmapped.changes_to
  • Description: JumpCloud Directory Insights field changes_to preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to
  • Usage: passwordmanager_folder_member_remove, passwordmanager_user_activate, passwordmanager_user_disable, passwordmanager_user_re-enable, passwordmanager_user_reactivate, passwordmanager_user_update
unmapped.city
  • Description: JumpCloud Directory Insights field city preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.city
  • Usage: passwordmanager_local_backup_restore, passwordmanager_mini_launch
unmapped.client_ip
  • Description: JumpCloud Directory Insights field client_ip preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: client_ip
  • Usage: passwordmanager_folder_force_sync, passwordmanager_local_backup_restore, passwordmanager_migration_complete, passwordmanager_migration_start, passwordmanager_mini_launch
unmapped.continent_code
  • Description: JumpCloud Directory Insights field continent_code preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.continent_code
  • Usage: passwordmanager_local_backup_restore, passwordmanager_mini_launch
unmapped.country_code
  • Description: JumpCloud Directory Insights field country_code preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.country_code
  • Usage: passwordmanager_local_backup_restore, passwordmanager_mini_launch
unmapped.error
  • Description: JumpCloud Directory Insights field error preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.error
  • Usage: passwordmanager_folder_create, passwordmanager_folder_delete, passwordmanager_folder_force_sync, passwordmanager_folder_group_add, passwordmanager_folder_member_add, passwordmanager_folder_update, passwordmanager_local_backup_create
unmapped.file_input_timestamp
  • Description: JumpCloud Directory Insights field file_input_timestamp preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: file_input_timestamp
  • Usage: 35 events: passwordmanager_app_unlock, passwordmanager_backup_create, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_request_reject, passwordmanager_disable, passwordmanager_extension_pair, passwordmanager_extension_settings_update, ... (+27 more)
unmapped.geoip.error
  • Description: JumpCloud Directory Insights field geoip.error preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.error
  • Usage: 25 events: passwordmanager_app_unlock, passwordmanager_app_update, passwordmanager_backup_create, passwordmanager_backup_request, passwordmanager_backup_request_cancel, passwordmanager_backup_request_restore, passwordmanager_extension_pair, passwordmanager_extension_settings_update, ... (+17 more)
unmapped.geoip.ip_address
  • Description: JumpCloud Directory Insights field geoip.ip_address preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.ip_address
  • Usage: 25 events: passwordmanager_app_unlock, passwordmanager_app_update, passwordmanager_backup_create, passwordmanager_backup_request, passwordmanager_backup_request_cancel, passwordmanager_backup_request_restore, passwordmanager_extension_pair, passwordmanager_extension_settings_update, ... (+17 more)
unmapped.geoip.region_name
  • Description: JumpCloud Directory Insights field geoip.region_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.region_name
  • Usage: 21 events: passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_backup_request_approve, passwordmanager_backup_request_reject, passwordmanager_batch_folder_delete, ... (+13 more)
unmapped.geoip.timezone
  • Description: JumpCloud Directory Insights field geoip.timezone preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.timezone
  • Usage: 21 events: passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_backup_request_approve, passwordmanager_backup_request_reject, passwordmanager_batch_folder_delete, ... (+13 more)
unmapped.initiated_by.provider
  • Description: JumpCloud Directory Insights field initiated_by.provider preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by.provider
  • Usage: passwordmanager_policy_export_update, passwordmanager_sharedfolders_policy_group_add, passwordmanager_sharedfolders_policy_update
unmapped.initiated_by.user_id
  • Description: JumpCloud Directory Insights field initiated_by.user_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by.user_id
  • Usage: passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_disable, passwordmanager_policy_export_update, passwordmanager_sharedfolders_policy_group_add, passwordmanager_sharedfolders_policy_update, passwordmanager_sharedfolders_policy_user_add, passwordmanager_sharedfolders_policy_user_remove
unmapped.initiated_by_email_hash
  • Description: JumpCloud Directory Insights field initiated_by_email_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_email_hash
  • Usage: 60 events: passwordmanager_app_unlock, passwordmanager_app_update, passwordmanager_backup_create, passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, ... (+52 more)
unmapped.initiated_by_id_hash
  • Description: JumpCloud Directory Insights field initiated_by_id_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_id_hash
  • Usage: 65 events (missing: passwordmanager_get_item_secret, passwordmanager_item_autofill, passwordmanager_user_disable, passwordmanager_user_enable, passwordmanager_user_re-enable...)
unmapped.initiated_by_username_hash
  • Description: JumpCloud Directory Insights field initiated_by_username_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_username_hash
  • Usage: 50 events: passwordmanager_app_unlock, passwordmanager_app_update, passwordmanager_backup_create, passwordmanager_backup_request, passwordmanager_backup_request_cancel, passwordmanager_backup_request_restore, passwordmanager_batch_folder_delete, passwordmanager_extension_pair, ... (+42 more)
unmapped.ip_address
  • Description: JumpCloud Directory Insights field ip_address preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.ip_address
  • Usage: passwordmanager_folder_create, passwordmanager_folder_delete, passwordmanager_folder_force_sync, passwordmanager_folder_group_add, passwordmanager_folder_member_add, passwordmanager_folder_update, passwordmanager_local_backup_create
unmapped.is_out_of_bound
  • Description: JumpCloud Directory Insights field is_out_of_bound preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: is_out_of_bound
  • Usage: 68 events (missing: passwordmanager_item_autofill, passwordmanager_item_history_reveal, passwordmanager_items_export, passwordmanager_user_device_pair)
unmapped.jc_application_name
  • Description: JumpCloud Directory Insights field jc_application_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_application_name
  • Usage: 68 events (missing: passwordmanager_item_autofill, passwordmanager_item_history_reveal, passwordmanager_items_export, passwordmanager_user_device_pair)
unmapped.jc_initiated_by_email
  • Description: JumpCloud Directory Insights field jc_initiated_by_email preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_initiated_by_email
  • Usage: 34 events: passwordmanager_app_unlock, passwordmanager_app_update, passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_enable, ... (+26 more)
unmapped.jc_initiated_by_username
  • Description: JumpCloud Directory Insights field jc_initiated_by_username preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_initiated_by_username
  • Usage: 34 events: passwordmanager_app_unlock, passwordmanager_app_update, passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_enable, ... (+26 more)
unmapped.jc_organization_name
  • Description: JumpCloud Directory Insights field jc_organization_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_organization_name
  • Usage: 34 events: passwordmanager_app_unlock, passwordmanager_app_update, passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_enable, ... (+26 more)
unmapped.jc_provider_id
  • Description: JumpCloud Directory Insights field jc_provider_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_provider_id
  • Usage: 26 events: passwordmanager_app_unlock, passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_enable, passwordmanager_folder_create, ... (+18 more)
unmapped.latitude
  • Description: JumpCloud Directory Insights field latitude preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.latitude
  • Usage: passwordmanager_local_backup_restore, passwordmanager_mini_launch
unmapped.longitude
  • Description: JumpCloud Directory Insights field longitude preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.longitude
  • Usage: passwordmanager_local_backup_restore, passwordmanager_mini_launch
unmapped.network
  • Description: JumpCloud Directory Insights field network preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: asn.network
  • Usage: passwordmanager_folder_create, passwordmanager_folder_group_add, passwordmanager_folder_group_remove, passwordmanager_folder_group_update, passwordmanager_folder_member_remove, passwordmanager_folder_member_update, passwordmanager_folder_update, passwordmanager_mini_launch
unmapped.region_code
  • Description: JumpCloud Directory Insights field region_code preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.region_code
  • Usage: passwordmanager_local_backup_restore, passwordmanager_mini_launch
unmapped.region_name
  • Description: JumpCloud Directory Insights field region_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.region_name
  • Usage: passwordmanager_folder_create, passwordmanager_folder_group_add, passwordmanager_folder_group_remove, passwordmanager_folder_group_update, passwordmanager_folder_member_remove, passwordmanager_folder_member_update, passwordmanager_folder_update, passwordmanager_local_backup_path_update, passwordmanager_local_backup_restore, passwordmanager_mini_launch
unmapped.resource_id
  • Description: JumpCloud Directory Insights field resource_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.id
  • Usage: passwordmanager_folder_force_sync, passwordmanager_migration_complete, passwordmanager_migration_start, passwordmanager_mini_launch
unmapped.resource_id_hash
  • Description: JumpCloud Directory Insights field resource_id_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource_id_hash
  • Usage: 65 events (missing: passwordmanager_backup_disable, passwordmanager_extension_site_exclusion, passwordmanager_get_item_secret, passwordmanager_item_autofill, passwordmanager_item_create...)
unmapped.resource_type
  • Description: JumpCloud Directory Insights field resource_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.type
  • Usage: passwordmanager_app_unlock
unmapped.resource_username_hash
  • Description: JumpCloud Directory Insights field resource_username_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource_username_hash
  • Usage: 12 events: passwordmanager_user_activate, passwordmanager_user_deactivate, passwordmanager_user_device_pair, passwordmanager_user_device_unpair, passwordmanager_user_disable, passwordmanager_user_enable, passwordmanager_user_migration, passwordmanager_user_re-enable, ... (+4 more)
unmapped.tags
  • Description: JumpCloud Directory Insights field tags preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: tags
  • Usage: 35 events: passwordmanager_app_unlock, passwordmanager_backup_create, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_request_reject, passwordmanager_disable, passwordmanager_extension_pair, passwordmanager_extension_settings_update, ... (+27 more)
unmapped.timestamp
  • Description: JumpCloud Directory Insights field timestamp preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: @timestamp
  • Usage: passwordmanager_extension_pair, passwordmanager_extension_settings_update, passwordmanager_extension_unlock, passwordmanager_force_sync
unmapped.timestamp_source
  • Description: JumpCloud Directory Insights field timestamp_source preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: timestamp_source
  • Usage: passwordmanager_get_item_secret, passwordmanager_item_create, passwordmanager_item_delete, passwordmanager_item_update, passwordmanager_migration_complete, passwordmanager_migration_start, passwordmanager_user_migration
unmapped.timezone
  • Description: JumpCloud Directory Insights field timezone preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.timezone
  • Usage: passwordmanager_folder_create, passwordmanager_folder_group_add, passwordmanager_folder_group_remove, passwordmanager_folder_group_update, passwordmanager_folder_member_remove, passwordmanager_folder_member_update, passwordmanager_folder_update, passwordmanager_local_backup_path_update, passwordmanager_local_backup_restore, passwordmanager_mini_launch
unmapped.user_agent
  • Description: JumpCloud Directory Insights field user_agent preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: user_agent
  • Usage: passwordmanager_folder_force_sync, passwordmanager_local_backup_restore, passwordmanager_migration_complete, passwordmanager_migration_start, passwordmanager_mini_launch
unmapped.useragent.device
  • Description: JumpCloud Directory Insights field useragent.device preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.device
  • Usage: 41 events: passwordmanager_app_unlock, passwordmanager_app_update, passwordmanager_backup_create, passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, ... (+33 more)
unmapped.useragent.major
  • Description: JumpCloud Directory Insights field useragent.major preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.major
  • Usage: 21 events: passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_backup_request_approve, passwordmanager_backup_request_reject, passwordmanager_disable, ... (+13 more)
unmapped.useragent.minor
  • Description: JumpCloud Directory Insights field useragent.minor preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.minor
  • Usage: 21 events: passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_backup_request_approve, passwordmanager_backup_request_reject, passwordmanager_disable, ... (+13 more)
unmapped.useragent.name
  • Description: JumpCloud Directory Insights field useragent.name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.name
  • Usage: 41 events: passwordmanager_app_unlock, passwordmanager_app_update, passwordmanager_backup_create, passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, ... (+33 more)
unmapped.useragent.os
  • Description: JumpCloud Directory Insights field useragent.os preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os
  • Usage: 41 events: passwordmanager_app_unlock, passwordmanager_app_update, passwordmanager_backup_create, passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, ... (+33 more)
unmapped.useragent.os_full
  • Description: JumpCloud Directory Insights field useragent.os_full preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_full
  • Usage: 41 events: passwordmanager_app_unlock, passwordmanager_app_update, passwordmanager_backup_create, passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, ... (+33 more)
unmapped.useragent.os_major
  • Description: JumpCloud Directory Insights field useragent.os_major preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_major
  • Usage: 21 events: passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_backup_request_approve, passwordmanager_backup_request_reject, passwordmanager_disable, ... (+13 more)
unmapped.useragent.os_minor
  • Description: JumpCloud Directory Insights field useragent.os_minor preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_minor
  • Usage: 21 events: passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_backup_request_approve, passwordmanager_backup_request_reject, passwordmanager_disable, ... (+13 more)
unmapped.useragent.os_name
  • Description: JumpCloud Directory Insights field useragent.os_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_name
  • Usage: 41 events: passwordmanager_app_unlock, passwordmanager_app_update, passwordmanager_backup_create, passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, ... (+33 more)
unmapped.useragent.os_patch
  • Description: JumpCloud Directory Insights field useragent.os_patch preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_patch
  • Usage: 21 events: passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_backup_request_approve, passwordmanager_backup_request_reject, passwordmanager_disable, ... (+13 more)
unmapped.useragent.os_version
  • Description: JumpCloud Directory Insights field useragent.os_version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_version
  • Usage: 21 events: passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_backup_request_approve, passwordmanager_backup_request_reject, passwordmanager_disable, ... (+13 more)
unmapped.useragent.patch
  • Description: JumpCloud Directory Insights field useragent.patch preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.patch
  • Usage: 21 events: passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_backup_request_approve, passwordmanager_backup_request_reject, passwordmanager_disable, ... (+13 more)
unmapped.useragent.version
  • Description: JumpCloud Directory Insights field useragent.version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.version
  • Usage: 21 events: passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_backup_request_approve, passwordmanager_backup_request_reject, passwordmanager_disable, ... (+13 more)
unmapped.useragent_device
  • Description: JumpCloud Directory Insights field useragent_device preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.device
  • Usage: passwordmanager_extension_pair, passwordmanager_extension_settings_update, passwordmanager_extension_site_exclusion, passwordmanager_extension_unlock, passwordmanager_force_sync, passwordmanager_paranoid_mode_disable, passwordmanager_paranoid_mode_enable, passwordmanager_pincode_update
unmapped.useragent_name
  • Description: JumpCloud Directory Insights field useragent_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.name
  • Usage: passwordmanager_extension_pair, passwordmanager_extension_settings_update, passwordmanager_extension_site_exclusion, passwordmanager_extension_unlock, passwordmanager_force_sync, passwordmanager_paranoid_mode_disable, passwordmanager_paranoid_mode_enable, passwordmanager_pincode_update
unmapped.useragent_os
  • Description: JumpCloud Directory Insights field useragent_os preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os
  • Usage: passwordmanager_extension_pair, passwordmanager_extension_settings_update, passwordmanager_extension_site_exclusion, passwordmanager_extension_unlock, passwordmanager_force_sync, passwordmanager_paranoid_mode_disable, passwordmanager_paranoid_mode_enable, passwordmanager_pincode_update
unmapped.useragent_os_full
  • Description: JumpCloud Directory Insights field useragent_os_full preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_full
  • Usage: passwordmanager_extension_pair, passwordmanager_extension_settings_update, passwordmanager_extension_site_exclusion, passwordmanager_extension_unlock, passwordmanager_force_sync, passwordmanager_paranoid_mode_disable, passwordmanager_paranoid_mode_enable, passwordmanager_pincode_update
unmapped.useragent_os_name
  • Description: JumpCloud Directory Insights field useragent_os_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_name
  • Usage: passwordmanager_extension_pair, passwordmanager_extension_settings_update, passwordmanager_extension_site_exclusion, passwordmanager_extension_unlock, passwordmanager_force_sync, passwordmanager_paranoid_mode_disable, passwordmanager_paranoid_mode_enable, passwordmanager_pincode_update
unmapped.version
  • Description: JumpCloud Directory Insights field version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: version
  • Usage: passwordmanager_migration_complete, passwordmanager_migration_start, passwordmanager_user_migration

Password Vault#

password_vault · 47 events

Event Category Class Activity Type UID Fields
passwordvault_credential_add Identity & Access Management (3) Entity Management (3004) Create (1) 300401 51
passwordvault_credential_archive Identity & Access Management (3) Entity Management (3004) Suspend (12) 300412 39
passwordvault_credential_autofill Identity & Access Management (3) Entity Management (3004) Read (2) 300402 39
passwordvault_credential_copy Identity & Access Management (3) Entity Management (3004) Read (2) 300402 40
passwordvault_credential_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 39
passwordvault_credential_duplicate Identity & Access Management (3) Entity Management (3004) Create (1) 300401 39
passwordvault_credential_export Identity & Access Management (3) Entity Management (3004) Read (2) 300402 42
passwordvault_credential_history_reveal Identity & Access Management (3) Entity Management (3004) Read (2) 300402 42
passwordvault_credential_import Identity & Access Management (3) Entity Management (3004) Create (1) 300401 36
passwordvault_credential_reveal Identity & Access Management (3) Entity Management (3004) Read (2) 300402 40
passwordvault_credential_shareuser Identity & Access Management (3) Entity Management (3004) Update (3) 300403 49
passwordvault_credential_shareusergroup Identity & Access Management (3) Entity Management (3004) Update (3) 300403 52
passwordvault_credential_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 47
passwordvault_credential_viewdetail Identity & Access Management (3) Entity Management (3004) Read (2) 300402 39
passwordvault_credential_viewsecret Identity & Access Management (3) Entity Management (3004) Read (2) 300402 39
passwordvault_enable Identity & Access Management (3) Entity Management (3004) Enable (8) 300408 64
passwordvault_group_disable Identity & Access Management (3) Entity Management (3004) Disable (9) 300409 43
passwordvault_personalfolder_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 43
passwordvault_personalfolder_credential_add Identity & Access Management (3) Entity Management (3004) Update (3) 300403 42
passwordvault_personalfolder_credential_remove Identity & Access Management (3) Entity Management (3004) Update (3) 300403 46
passwordvault_personalfolder_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 39
passwordvault_personalfolder_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 42
passwordvault_personalfolder_website_add Identity & Access Management (3) Entity Management (3004) Update (3) 300403 47
passwordvault_personalfolder_website_remove Identity & Access Management (3) Entity Management (3004) Update (3) 300403 51
passwordvault_sharedfolder_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 43
passwordvault_sharedfolder_credential_add Identity & Access Management (3) Entity Management (3004) Update (3) 300403 51
passwordvault_sharedfolder_credential_remove Identity & Access Management (3) Entity Management (3004) Update (3) 300403 49
passwordvault_sharedfolder_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 42
passwordvault_sharedfolder_group_add Identity & Access Management (3) Entity Management (3004) Update (3) 300403 48
passwordvault_sharedfolder_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 42
passwordvault_sharedfolder_user_add Identity & Access Management (3) Entity Management (3004) Update (3) 300403 49
passwordvault_sharedfolder_user_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 53
passwordvault_sharedfolder_website_add Identity & Access Management (3) Entity Management (3004) Update (3) 300403 51
passwordvault_sharedfolder_website_remove Identity & Access Management (3) Entity Management (3004) Update (3) 300403 43
passwordvault_user_disable Identity & Access Management (3) Account Change (3001) Disable (5) 300105 42
passwordvault_user_enable Identity & Access Management (3) Account Change (3001) Enable (2) 300102 40
passwordvault_website_add Identity & Access Management (3) Entity Management (3004) Create (1) 300401 51
passwordvault_website_archive Identity & Access Management (3) Entity Management (3004) Deactivate (11) 300411 39
passwordvault_website_connect Identity & Access Management (3) Entity Management (3004) Read (2) 300402 42
passwordvault_website_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 43
passwordvault_website_duplicate Identity & Access Management (3) Entity Management (3004) Create (1) 300401 43
passwordvault_website_linkcredential Identity & Access Management (3) Entity Management (3004) Update (3) 300403 52
passwordvault_website_shareuser Identity & Access Management (3) Entity Management (3004) Update (3) 300403 49
passwordvault_website_shareusergroup Identity & Access Management (3) Entity Management (3004) Update (3) 300403 48
passwordvault_website_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 51
passwordvault_website_viewdetails Identity & Access Management (3) Entity Management (3004) Read (2) 300402 43
passwordvault_websites_export Identity & Access Management (3) Entity Management (3004) Read (2) 300402 36

OCSF field mappings#

Legend

  • Description: what the OCSF field represents (from OCSF schema v1.8.0)
  • Source: raw JumpCloud event field(s) mapped via ${{placeholder}} template
  • Transform: fieldMappings entry applied at runtime (cast, enum, etc.)
  • Literal: static value set in the mapping template
  • Usage: event types in this service that include this field

Core

activity_id
  • Description: The normalized identifier of the activity that triggered the event.
  • Literal: 1, 11, 12, 2, 3, 4, 5, 8, 9
  • Usage: all events in this service
activity_name
  • Description: The event activity name, as defined by the activity_id.
  • Literal: Create, Deactivate, Delete, Disable, Enable, Read, Suspend, Update
  • Usage: all events in this service
category_name
  • Description: The event category name, as defined by category_uid value: Discovery.
  • Literal: Identity & Access Management
  • Usage: all events in this service
category_uid
  • Description: The category unique identifier of the event.
  • Literal: 3
  • Usage: all events in this service
class_name
  • Description: The event class name, as defined by class_uid value: User Inventory Info.
  • Literal: Account Change, Entity Management
  • Usage: all events in this service
class_uid
  • Description: The unique identifier of a class. A class describes the attributes available in an event.
  • Literal: 3001, 3004
  • Usage: all events in this service
severity_id
  • Description: OCSF severity identifier for the event.
  • Literal: 1
  • Usage: all events in this service
status_detail
  • Description: The status detail contains additional information about the event/finding outcome.
  • Source: error_message
  • Usage: all events in this service
status_id
  • Description: Normalized status of the activity (1=Success, 2=Failure).
  • Source: success
  • Transform:
  • success → boolean_to_status_id; true→1, false→2 (all events in this service)
  • Usage: all events in this service
time
  • Description: Event time, in epoch milliseconds (OCSF time).
  • Source: timestamp
  • Transform:
  • timestamp → iso8601_to_epoch_millis (all events in this service)
  • Usage: all events in this service
type_uid
  • Description: The event/finding type ID. It identifies the event's semantics and structure. The value is calculated by the logging system as: class_uid * 100 + activity_id.
  • Literal: 300102, 300105, 300401, 300402, 300403, 300404, 300408, 300409, 300411, 300412
  • Usage: all events in this service

Metadata

metadata.event_code
  • Description: JumpCloud event type code.
  • Source: event_type
  • Usage: all events in this service
metadata.original_time
  • Description: The original event time as reported by the event source. For example, the time in the original format from system event log such as Syslog on Unix/Linux and the System event file on Windows. Omit if event is generated instead of collected via logs.
  • Source: server_timestamp
  • Usage: all events in this service
metadata.processed_time
  • Description: The event processed time, such as an ETL operation.
  • Source: jc_transformation_ts
  • Usage: all events in this service
metadata.product.name
  • Description: Originating JumpCloud service that produced the event.
  • Source: service
  • Usage: all events in this service
metadata.tenant_uid
  • Description: JumpCloud organization (tenant) identifier.
  • Source: organization
  • Usage: all events in this service
metadata.uid
  • Description: Unique event identifier assigned by JumpCloud.
  • Source: id
  • Usage: all events in this service
metadata.version
  • Description: OCSF schema version used for this event.
  • Literal: 1.8.0
  • Usage: all events in this service

Actor

actor.user.email_addr
  • Description: Email address of the actor who initiated the event.
  • Source: initiated_by.email
  • Usage: all events in this service
actor.user.name
  • Description: Display name of the actor who initiated the event.
  • Source: initiated_by.username
  • Usage: 42 events: passwordvault_credential_add, passwordvault_credential_archive, passwordvault_credential_autofill, passwordvault_credential_copy, passwordvault_credential_delete, passwordvault_credential_duplicate, passwordvault_credential_export, passwordvault_credential_history_reveal, ... (+34 more)
actor.user.type_id
  • Description: OCSF user type of the actor (1=User, 2=Admin, 3=System, 4=Service).
  • Source: initiated_by.type
  • Transform:
  • initiated_by.type → enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (all events in this service)
  • Usage: all events in this service
actor.user.uid
  • Description: Unique identifier of the actor who initiated the event.
  • Source: initiated_by.id
  • Usage: all events in this service

User

user.email_addr
  • Description: Email address of the user associated with the event.
  • Source: resource.name
  • Usage: passwordvault_user_disable, passwordvault_user_enable
user.type_id
  • Description: OCSF user type (1=User, 2=Admin, 3=System, 4=Service).
  • Source: resource.type
  • Transform:
  • resource.type → enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (passwordvault_user_disable, passwordvault_user_enable)
  • Usage: passwordvault_user_disable, passwordvault_user_enable
user.uid
  • Description: Unique identifier of the user associated with the event.
  • Source: resource.id
  • Usage: passwordvault_user_disable, passwordvault_user_enable

Entity

entity.data.action_source
  • Description: JumpCloud extension data on the managed entity: action_source.
  • Source: association.action_source
  • Usage: 20 events: passwordvault_credential_add, passwordvault_credential_shareuser, passwordvault_credential_shareusergroup, passwordvault_credential_update, passwordvault_personalfolder_credential_add, passwordvault_personalfolder_credential_remove, passwordvault_personalfolder_website_add, passwordvault_personalfolder_website_remove, ... (+12 more)
entity.data.association_attributes
  • Description: JumpCloud extension data on the managed entity: association_attributes.
  • Source: association.attributes
  • Usage: 20 events: passwordvault_credential_add, passwordvault_credential_shareuser, passwordvault_credential_shareusergroup, passwordvault_credential_update, passwordvault_personalfolder_credential_add, passwordvault_personalfolder_credential_remove, passwordvault_personalfolder_website_add, passwordvault_personalfolder_website_remove, ... (+12 more)
entity.data.association_from_name
  • Description: JumpCloud extension data on the managed entity: association_from_name.
  • Source: association.connection.from.name
  • Usage: 14 events: passwordvault_credential_add, passwordvault_credential_shareuser, passwordvault_credential_shareusergroup, passwordvault_personalfolder_website_add, passwordvault_personalfolder_website_remove, passwordvault_sharedfolder_credential_add, passwordvault_sharedfolder_group_add, passwordvault_sharedfolder_user_add, ... (+6 more)
entity.data.association_from_object_id
  • Description: JumpCloud extension data on the managed entity: association_from_object_id.
  • Source: association.connection.from.object_id
  • Usage: 16 events: passwordvault_credential_add, passwordvault_credential_shareuser, passwordvault_credential_shareusergroup, passwordvault_personalfolder_credential_remove, passwordvault_personalfolder_website_add, passwordvault_personalfolder_website_remove, passwordvault_sharedfolder_credential_add, passwordvault_sharedfolder_credential_remove, ... (+8 more)
entity.data.association_from_type
  • Description: JumpCloud extension data on the managed entity: association_from_type.
  • Source: association.connection.from.type
  • Usage: 16 events: passwordvault_credential_add, passwordvault_credential_shareuser, passwordvault_credential_shareusergroup, passwordvault_personalfolder_credential_remove, passwordvault_personalfolder_website_add, passwordvault_personalfolder_website_remove, passwordvault_sharedfolder_credential_add, passwordvault_sharedfolder_credential_remove, ... (+8 more)
entity.data.association_op
  • Description: JumpCloud extension data on the managed entity: association_op.
  • Source: association.op
  • Usage: 16 events: passwordvault_credential_add, passwordvault_credential_shareuser, passwordvault_credential_shareusergroup, passwordvault_personalfolder_credential_remove, passwordvault_personalfolder_website_add, passwordvault_personalfolder_website_remove, passwordvault_sharedfolder_credential_add, passwordvault_sharedfolder_credential_remove, ... (+8 more)
entity.data.association_to_email
  • Description: JumpCloud extension data on the managed entity: association_to_email.
  • Source: association.connection.to.email
  • Usage: passwordvault_credential_shareuser, passwordvault_sharedfolder_user_add, passwordvault_sharedfolder_user_update, passwordvault_website_shareuser
entity.data.association_to_name
  • Description: JumpCloud extension data on the managed entity: association_to_name.
  • Source: association.connection.to.name
  • Usage: 11 events: passwordvault_credential_shareuser, passwordvault_credential_shareusergroup, passwordvault_personalfolder_credential_remove, passwordvault_sharedfolder_credential_add, passwordvault_sharedfolder_credential_remove, passwordvault_sharedfolder_group_add, passwordvault_sharedfolder_user_add, passwordvault_sharedfolder_user_update, ... (+3 more)
entity.data.association_to_object_id
  • Description: JumpCloud extension data on the managed entity: association_to_object_id.
  • Source: association.connection.to.object_id
  • Usage: 20 events: passwordvault_credential_add, passwordvault_credential_shareuser, passwordvault_credential_shareusergroup, passwordvault_credential_update, passwordvault_personalfolder_credential_add, passwordvault_personalfolder_credential_remove, passwordvault_personalfolder_website_add, passwordvault_personalfolder_website_remove, ... (+12 more)
entity.data.association_to_type
  • Description: JumpCloud extension data on the managed entity: association_to_type.
  • Source: association.connection.to.type
  • Usage: 20 events: passwordvault_credential_add, passwordvault_credential_shareuser, passwordvault_credential_shareusergroup, passwordvault_credential_update, passwordvault_personalfolder_credential_add, passwordvault_personalfolder_credential_remove, passwordvault_personalfolder_website_add, passwordvault_personalfolder_website_remove, ... (+12 more)
entity.data.auth_method
  • Description: JumpCloud extension data on the managed entity: auth_method.
  • Source: auth_method
  • Usage: passwordvault_enable
entity.data.changed_field
  • Description: JumpCloud extension data on the managed entity: changed_field.
  • Source: changes.field
  • Usage: passwordvault_credential_update, passwordvault_enable, passwordvault_personalfolder_update, passwordvault_sharedfolder_update, passwordvault_website_update
entity.data.changes_from
  • Description: JumpCloud extension data on the managed entity: changes_from.
  • Source: changes.from
  • Usage: passwordvault_credential_update, passwordvault_enable, passwordvault_personalfolder_update, passwordvault_sharedfolder_update, passwordvault_website_update
entity.data.connection.from
  • Description: JumpCloud extension data on the managed entity: connection.from.
  • Source: association.connection.from
  • Usage: passwordvault_credential_update, passwordvault_personalfolder_credential_add, passwordvault_sharedfolder_website_remove, passwordvault_website_update
entity.data.display_name
  • Description: JumpCloud extension data on the managed entity: display_name.
  • Source: resource.displayName
  • Usage: passwordvault_credential_copy, passwordvault_credential_reveal
entity.name
  • Description: The name of the managed entity. It should match the name of the specific entity object's name if populated, or the name of the managed entity if the type_id is 'Other'.
  • Source: resource.name
  • Usage: 38 events: passwordvault_credential_add, passwordvault_credential_archive, passwordvault_credential_autofill, passwordvault_credential_copy, passwordvault_credential_delete, passwordvault_credential_duplicate, passwordvault_credential_history_reveal, passwordvault_credential_reveal, ... (+30 more)
entity.org.uid
  • Description: The unique identifier of the organization, Oracle Cloud Tenancy, Google Cloud Organization, or AWS Organization. For example, an AWS Org ID or Oracle Cloud Domain ID .
  • Source: resource.id
  • Usage: passwordvault_credential_export, passwordvault_credential_import
entity.type
  • Description: The managed entity type. For example: Policy, User, Organization, Device.
  • Source: resource.type
  • Usage: 45 events (missing: passwordvault_user_disable, passwordvault_user_enable)
entity.uid
  • Description: The identifier of the managed entity. It should match the uid of the specific entity's object UID if populated, or the source specific ID if the type_id is 'Other'.
  • Source: resource.id
  • Usage: 43 events (missing: passwordvault_credential_export, passwordvault_credential_import, passwordvault_user_disable, passwordvault_user_enable)
entity_result.data.changes_to
  • Description: JumpCloud extension data on the managed entity: changes_to.
  • Source: changes.to
  • Usage: passwordvault_credential_update, passwordvault_enable, passwordvault_personalfolder_update, passwordvault_sharedfolder_update, passwordvault_website_update

Src Endpoint

src_endpoint.autonomous_system.name
  • Description: Organization name for the Autonomous System.
  • Source: asn.organization
  • Usage: passwordvault_enable
src_endpoint.autonomous_system.number
  • Description: Unique number that the AS is identified by.
  • Source: asn.number
  • Transform:
  • asn.number → int (passwordvault_enable)
  • Usage: passwordvault_enable
src_endpoint.ip
  • Description: Source IP address the request originated from.
  • Source: client_ip
  • Usage: all events in this service
src_endpoint.location.city
  • Description: The name of the city.
  • Source: geoip.city
  • Usage: passwordvault_enable
src_endpoint.location.continent
  • Description: The name of the continent.
  • Source: geoip.continent_code
  • Usage: passwordvault_enable
src_endpoint.location.country
  • Description: The ISO 3166-1 Alpha-2 country code.

    Note: The two letter country code should be capitalized. For example: US or CA.

  • Source: geoip.country_code
  • Usage: passwordvault_enable
src_endpoint.location.lat
  • Description: The geographical Latitude coordinate represented in Decimal Degrees (DD). For example: 42.361145.
  • Source: geoip.latitude
  • Transform:
  • geoip.latitude → double (passwordvault_enable)
  • Usage: passwordvault_enable
src_endpoint.location.long
  • Description: The geographical Longitude coordinate represented in Decimal Degrees (DD). For example: -71.057083.
  • Source: geoip.longitude
  • Transform:
  • geoip.longitude → double (passwordvault_enable)
  • Usage: passwordvault_enable
src_endpoint.location.region
  • Description: The alphanumeric code that identifies the principal subdivision (e.g. province or state) of the country. For example, 'CH-VD' for the Canton of Vaud, Switzerland
  • Source: geoip.region_code
  • Usage: passwordvault_enable

Http Request

http_request.user_agent
  • Description: The request header that identifies the operating system and web browser.
  • Source: user_agent
  • Usage: all events in this service

Observables

observables[].name
  • Description: The full name of the observable attribute. The name is a pointer/reference to an attribute within the OCSF event data. For example: file.name. Array attributes may be represented in one of three ways. For example: resources.uid, resources[].uid, resources[0].uid.
  • Literal: actor.user.email_addr, actor.user.name, actor.user.uid, http_request.user_agent, src_endpoint.ip, src_endpoint.location.country, user.email_addr, user.uid
  • Usage: all events in this service
observables[].type_id
  • Description: The observable value type identifier.
  • Literal: 14, 16, 2, 31, 4, 5
  • Usage: all events in this service
observables[].value
  • Description: The value associated with the observable attribute. The meaning of the value depends on the observable type.
    If the name refers to a scalar attribute, then the value is the value of the attribute.
    If the name refers to an object attribute, then the value is not populated.
  • Source: client_ip, geoip.country_code, initiated_by.email, initiated_by.id, initiated_by.username, resource.id, resource.name, user_agent
  • Usage: all events in this service

Unmapped

unmapped.@version
  • Description: JumpCloud Directory Insights field @version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: @version
  • Usage: all events in this service
unmapped.asn.network
  • Description: JumpCloud Directory Insights field asn.network preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: asn.network
  • Usage: passwordvault_enable
unmapped.changed_field
  • Description: JumpCloud Directory Insights field changed_field preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.field
  • Usage: passwordvault_user_disable, passwordvault_user_enable
unmapped.changes_from
  • Description: JumpCloud Directory Insights field changes_from preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.from
  • Usage: passwordvault_user_disable, passwordvault_user_enable
unmapped.changes_to
  • Description: JumpCloud Directory Insights field changes_to preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to
  • Usage: passwordvault_user_disable, passwordvault_user_enable
unmapped.geoip.region_name
  • Description: JumpCloud Directory Insights field geoip.region_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.region_name
  • Usage: passwordvault_enable
unmapped.geoip.timezone
  • Description: JumpCloud Directory Insights field geoip.timezone preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.timezone
  • Usage: passwordvault_enable
unmapped.initiated_by.administrator
  • Description: JumpCloud Directory Insights field initiated_by.administrator preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by.administrator
  • Usage: all events in this service
unmapped.initiated_by_email_hash
  • Description: JumpCloud Directory Insights field initiated_by_email_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_email_hash
  • Usage: all events in this service
unmapped.initiated_by_id_hash
  • Description: JumpCloud Directory Insights field initiated_by_id_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_id_hash
  • Usage: all events in this service
unmapped.initiated_by_username_hash
  • Description: JumpCloud Directory Insights field initiated_by_username_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_username_hash
  • Usage: 42 events: passwordvault_credential_add, passwordvault_credential_archive, passwordvault_credential_autofill, passwordvault_credential_copy, passwordvault_credential_delete, passwordvault_credential_duplicate, passwordvault_credential_export, passwordvault_credential_history_reveal, ... (+34 more)
unmapped.is_out_of_bound
  • Description: JumpCloud Directory Insights field is_out_of_bound preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: is_out_of_bound
  • Usage: all events in this service
unmapped.jc_application_name
  • Description: JumpCloud Directory Insights field jc_application_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_application_name
  • Usage: all events in this service
unmapped.jc_initiated_by_email
  • Description: JumpCloud Directory Insights field jc_initiated_by_email preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_initiated_by_email
  • Usage: 20 events: passwordvault_credential_add, passwordvault_credential_export, passwordvault_credential_history_reveal, passwordvault_credential_shareusergroup, passwordvault_group_disable, passwordvault_personalfolder_create, passwordvault_personalfolder_website_remove, passwordvault_sharedfolder_create, ... (+12 more)
unmapped.jc_initiated_by_username
  • Description: JumpCloud Directory Insights field jc_initiated_by_username preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_initiated_by_username
  • Usage: 20 events: passwordvault_credential_add, passwordvault_credential_export, passwordvault_credential_history_reveal, passwordvault_credential_shareusergroup, passwordvault_group_disable, passwordvault_personalfolder_create, passwordvault_personalfolder_website_remove, passwordvault_sharedfolder_create, ... (+12 more)
unmapped.jc_organization_name
  • Description: JumpCloud Directory Insights field jc_organization_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_organization_name
  • Usage: 20 events: passwordvault_credential_add, passwordvault_credential_export, passwordvault_credential_history_reveal, passwordvault_credential_shareusergroup, passwordvault_group_disable, passwordvault_personalfolder_create, passwordvault_personalfolder_website_remove, passwordvault_sharedfolder_create, ... (+12 more)
unmapped.jc_provider_id
  • Description: JumpCloud Directory Insights field jc_provider_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_provider_id
  • Usage: 15 events: passwordvault_credential_add, passwordvault_credential_export, passwordvault_credential_shareusergroup, passwordvault_group_disable, passwordvault_personalfolder_create, passwordvault_personalfolder_website_remove, passwordvault_sharedfolder_create, passwordvault_sharedfolder_user_update, ... (+7 more)
unmapped.resource_id_hash
  • Description: JumpCloud Directory Insights field resource_id_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource_id_hash
  • Usage: all events in this service
unmapped.timestamp_source
  • Description: JumpCloud Directory Insights field timestamp_source preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: timestamp_source
  • Usage: all events in this service
unmapped.useragent.device
  • Description: JumpCloud Directory Insights field useragent.device preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.device
  • Usage: passwordvault_enable
unmapped.useragent.major
  • Description: JumpCloud Directory Insights field useragent.major preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.major
  • Usage: passwordvault_enable
unmapped.useragent.minor
  • Description: JumpCloud Directory Insights field useragent.minor preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.minor
  • Usage: passwordvault_enable
unmapped.useragent.name
  • Description: JumpCloud Directory Insights field useragent.name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.name
  • Usage: passwordvault_enable
unmapped.useragent.os
  • Description: JumpCloud Directory Insights field useragent.os preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os
  • Usage: passwordvault_enable
unmapped.useragent.os_full
  • Description: JumpCloud Directory Insights field useragent.os_full preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_full
  • Usage: passwordvault_enable
unmapped.useragent.os_major
  • Description: JumpCloud Directory Insights field useragent.os_major preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_major
  • Usage: passwordvault_enable
unmapped.useragent.os_minor
  • Description: JumpCloud Directory Insights field useragent.os_minor preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_minor
  • Usage: passwordvault_enable
unmapped.useragent.os_name
  • Description: JumpCloud Directory Insights field useragent.os_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_name
  • Usage: passwordvault_enable
unmapped.useragent.os_patch
  • Description: JumpCloud Directory Insights field useragent.os_patch preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_patch
  • Usage: passwordvault_enable
unmapped.useragent.os_version
  • Description: JumpCloud Directory Insights field useragent.os_version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_version
  • Usage: passwordvault_enable
unmapped.useragent.patch
  • Description: JumpCloud Directory Insights field useragent.patch preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.patch
  • Usage: passwordvault_enable
unmapped.useragent.version
  • Description: JumpCloud Directory Insights field useragent.version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.version
  • Usage: passwordvault_enable

RADIUS#

radius · 1 event

Event Category Class Activity Type UID Fields
radius_auth_attempt Identity & Access Management (3) Authentication (3002) Logon (1) 300201 50

OCSF field mappings#

Legend

  • Description: what the OCSF field represents (from OCSF schema v1.8.0)
  • Source: raw JumpCloud event field(s) mapped via ${{placeholder}} template
  • Transform: fieldMappings entry applied at runtime (cast, enum, etc.)
  • Literal: static value set in the mapping template
  • Usage: event types in this service that include this field

Core

activity_id
  • Description: The normalized identifier of the activity that triggered the event.
  • Literal: 1
  • Usage: all events in this service
activity_name
  • Description: The event activity name, as defined by the activity_id.
  • Literal: Logon
  • Usage: all events in this service
category_name
  • Description: The event category name, as defined by category_uid value: Discovery.
  • Literal: Identity & Access Management
  • Usage: all events in this service
category_uid
  • Description: The category unique identifier of the event.
  • Literal: 3
  • Usage: all events in this service
class_name
  • Description: The event class name, as defined by class_uid value: User Inventory Info.
  • Literal: Authentication
  • Usage: all events in this service
class_uid
  • Description: The unique identifier of a class. A class describes the attributes available in an event.
  • Literal: 3002
  • Usage: all events in this service
severity_id
  • Description: OCSF severity identifier for the event.
  • Literal: 1
  • Usage: all events in this service
status_id
  • Description: Normalized status of the activity (1=Success, 2=Failure).
  • Source: success
  • Transform:
  • success → boolean_to_status_id; true→1, false→2 (all events in this service)
  • Usage: all events in this service
time
  • Description: Event time, in epoch milliseconds (OCSF time).
  • Source: timestamp
  • Transform:
  • timestamp → iso8601_to_epoch_millis (all events in this service)
  • Usage: all events in this service
type_uid
  • Description: The event/finding type ID. It identifies the event's semantics and structure. The value is calculated by the logging system as: class_uid * 100 + activity_id.
  • Literal: 300201
  • Usage: all events in this service

Metadata

metadata.event_code
  • Description: JumpCloud event type code.
  • Source: event_type
  • Usage: all events in this service
metadata.processed_time
  • Description: The event processed time, such as an ETL operation.
  • Source: jc_transformation_ts
  • Usage: all events in this service
metadata.product.name
  • Description: Originating JumpCloud service that produced the event.
  • Source: service
  • Usage: all events in this service
metadata.tenant_uid
  • Description: JumpCloud organization (tenant) identifier.
  • Source: organization
  • Usage: all events in this service
metadata.uid
  • Description: Unique event identifier assigned by JumpCloud.
  • Source: id
  • Usage: all events in this service
metadata.version
  • Description: OCSF schema version used for this event.
  • Literal: 1.8.0
  • Usage: all events in this service

Actor

actor.user.type_id
  • Description: OCSF user type of the actor (1=User, 2=Admin, 3=System, 4=Service).
  • Source: initiated_by.type
  • Transform:
  • initiated_by.type → enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (all events in this service)
  • Usage: all events in this service

User

user.email_addr
  • Description: Email address of the user associated with the event.
  • Source: initiated_by.username
  • Usage: all events in this service
user.name
  • Description: The username. For example, janedoe1.
  • Source: username
  • Usage: all events in this service

Src Endpoint

src_endpoint.ip
  • Description: Source IP address the request originated from.
  • Source: client_ip
  • Usage: all events in this service
src_endpoint.location.city
  • Description: The name of the city.
  • Source: geoip.city
  • Usage: all events in this service
src_endpoint.location.continent
  • Description: The name of the continent.
  • Source: geoip.continent_code
  • Usage: all events in this service
src_endpoint.location.country
  • Description: The ISO 3166-1 Alpha-2 country code.

    Note: The two letter country code should be capitalized. For example: US or CA.

  • Source: geoip.country_code
  • Usage: all events in this service
src_endpoint.location.lat
  • Description: The geographical Latitude coordinate represented in Decimal Degrees (DD). For example: 42.361145.
  • Source: geoip.latitude
  • Transform:
  • geoip.latitude → double (all events in this service)
  • Usage: all events in this service
src_endpoint.location.long
  • Description: The geographical Longitude coordinate represented in Decimal Degrees (DD). For example: -71.057083.
  • Source: geoip.longitude
  • Transform:
  • geoip.longitude → double (all events in this service)
  • Usage: all events in this service
src_endpoint.location.region
  • Description: The alphanumeric code that identifies the principal subdivision (e.g. province or state) of the country. For example, 'CH-VD' for the Canton of Vaud, Switzerland
  • Source: geoip.region_code
  • Usage: all events in this service

Http Request

http_request.user_agent
  • Description: The request header that identifies the operating system and web browser.
  • Source: user_agent
  • Usage: all events in this service

Observables

observables[].name
  • Description: The full name of the observable attribute. The name is a pointer/reference to an attribute within the OCSF event data. For example: file.name. Array attributes may be represented in one of three ways. For example: resources.uid, resources[].uid, resources[0].uid.
  • Literal: http_request.user_agent, src_endpoint.ip, src_endpoint.location.country, user.email_addr, user.name
  • Usage: all events in this service
observables[].type_id
  • Description: The observable value type identifier.
  • Literal: 14, 16, 2, 4, 5
  • Usage: all events in this service
observables[].value
  • Description: The value associated with the observable attribute. The meaning of the value depends on the observable type.
    If the name refers to a scalar attribute, then the value is the value of the attribute.
    If the name refers to an object attribute, then the value is not populated.
  • Source: client_ip, geoip.country_code, initiated_by.username, user_agent, username
  • Usage: all events in this service

Other

auth_protocol
  • Description: The authentication protocol as defined by the caption of auth_protocol_id. In the case of Other, it is defined by the event source.
  • Source: auth_type
  • Usage: all events in this service
is_mfa
  • Description: Indicates whether Multi Factor Authentication was used during authentication.
  • Source: mfa
  • Usage: all events in this service
raw_data
  • Description: The raw event/finding data as received from the source.
  • Source: event.original
  • Usage: all events in this service

Unmapped

unmapped.@version
  • Description: JumpCloud Directory Insights field @version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: @version
  • Usage: all events in this service
unmapped.auth_meta.auth_idp
  • Description: JumpCloud Directory Insights field auth_meta.auth_idp preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: auth_meta.auth_idp
  • Usage: all events in this service
unmapped.auth_meta.device_cert_enabled
  • Description: JumpCloud Directory Insights field auth_meta.device_cert_enabled preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: auth_meta.device_cert_enabled
  • Usage: all events in this service
unmapped.auth_meta.user_cert_enabled
  • Description: JumpCloud Directory Insights field auth_meta.user_cert_enabled preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: auth_meta.user_cert_enabled
  • Usage: all events in this service
unmapped.auth_meta.user_password_enabled
  • Description: JumpCloud Directory Insights field auth_meta.user_password_enabled preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: auth_meta.user_password_enabled
  • Usage: all events in this service
unmapped.auth_meta.userid_type
  • Description: JumpCloud Directory Insights field auth_meta.userid_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: auth_meta.userid_type
  • Usage: all events in this service
unmapped.geoip.region_name
  • Description: JumpCloud Directory Insights field geoip.region_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.region_name
  • Usage: all events in this service
unmapped.geoip.timezone
  • Description: JumpCloud Directory Insights field geoip.timezone preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.timezone
  • Usage: all events in this service
unmapped.initiated_by_username_hash
  • Description: JumpCloud Directory Insights field initiated_by_username_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_username_hash
  • Usage: all events in this service
unmapped.is_out_of_bound
  • Description: JumpCloud Directory Insights field is_out_of_bound preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: is_out_of_bound
  • Usage: all events in this service
unmapped.log.file.path
  • Description: JumpCloud Directory Insights field log.file.path preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: log.file.path
  • Usage: all events in this service
unmapped.mfa_meta.type
  • Description: JumpCloud Directory Insights field mfa_meta.type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: mfa_meta.type
  • Usage: all events in this service
unmapped.nas_mfa_state
  • Description: JumpCloud Directory Insights field nas_mfa_state preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: nas_mfa_state
  • Usage: all events in this service
unmapped.protocol
  • Description: JumpCloud Directory Insights field protocol preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: protocol
  • Usage: all events in this service
unmapped.radsec
  • Description: JumpCloud Directory Insights field radsec preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: radsec
  • Usage: all events in this service
unmapped.require_tls_auth
  • Description: JumpCloud Directory Insights field require_tls_auth preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: require_tls_auth
  • Usage: all events in this service
unmapped.username_hash
  • Description: JumpCloud Directory Insights field username_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: username_hash
  • Usage: all events in this service

Reports#

reports · 13 events

Event Category Class Activity Type UID Fields
custom_report_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 85
custom_report_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 79
custom_report_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 104
report_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 63
report_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 63
report_export Identity & Access Management (3) Entity Management (3004) Read (2) 300402 66
report_run Identity & Access Management (3) Entity Management (3004) Read (2) 300402 71
report_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 86
scheduled_report_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 70
scheduled_report_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 70
scheduled_report_run_failed System Activity (1) Scheduled Job Activity (1006) Start (6) 100606 39
scheduled_report_run_success System Activity (1) Scheduled Job Activity (1006) Start (6) 100606 36
scheduled_report_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 77

OCSF field mappings#

Legend

  • Description: what the OCSF field represents (from OCSF schema v1.8.0)
  • Source: raw JumpCloud event field(s) mapped via ${{placeholder}} template
  • Transform: fieldMappings entry applied at runtime (cast, enum, etc.)
  • Literal: static value set in the mapping template
  • Usage: event types in this service that include this field

Core

activity_id
  • Description: The normalized identifier of the activity that triggered the event.
  • Literal: 1, 2, 3, 4, 6
  • Usage: all events in this service
activity_name
  • Description: The event activity name, as defined by the activity_id.
  • Literal: Create, Delete, Read, Start, Update
  • Usage: all events in this service
category_name
  • Description: The event category name, as defined by category_uid value: Discovery.
  • Literal: Identity & Access Management, System Activity
  • Usage: all events in this service
category_uid
  • Description: The category unique identifier of the event.
  • Literal: 1, 3
  • Usage: all events in this service
class_name
  • Description: The event class name, as defined by class_uid value: User Inventory Info.
  • Literal: Entity Management, Scheduled Job Activity
  • Usage: all events in this service
class_uid
  • Description: The unique identifier of a class. A class describes the attributes available in an event.
  • Literal: 1006, 3004
  • Usage: all events in this service
severity_id
  • Description: OCSF severity identifier for the event.
  • Literal: 1
  • Usage: all events in this service
status_detail
  • Description: The status detail contains additional information about the event/finding outcome.
  • Source: error_message
  • Usage: all events in this service
status_id
  • Description: Normalized status of the activity (1=Success, 2=Failure).
  • Source: success
  • Transform:
  • success → boolean_to_status_id; true→1, false→2 (all events in this service)
  • Usage: all events in this service
time
  • Description: Event time, in epoch milliseconds (OCSF time).
  • Source: timestamp
  • Transform:
  • timestamp → iso8601_to_epoch_millis (all events in this service)
  • Usage: all events in this service
type_uid
  • Description: The event/finding type ID. It identifies the event's semantics and structure. The value is calculated by the logging system as: class_uid * 100 + activity_id.
  • Literal: 100606, 300401, 300402, 300403, 300404
  • Usage: all events in this service

Metadata

metadata.event_code
  • Description: JumpCloud event type code.
  • Source: event_type
  • Usage: all events in this service
metadata.original_time
  • Description: The original event time as reported by the event source. For example, the time in the original format from system event log such as Syslog on Unix/Linux and the System event file on Windows. Omit if event is generated instead of collected via logs.
  • Source: server_timestamp
  • Usage: all events in this service
metadata.processed_time
  • Description: The event processed time, such as an ETL operation.
  • Source: jc_transformation_ts
  • Usage: all events in this service
metadata.product.name
  • Description: Originating JumpCloud service that produced the event.
  • Source: service
  • Usage: all events in this service
metadata.tenant_uid
  • Description: JumpCloud organization (tenant) identifier.
  • Source: organization
  • Usage: all events in this service
metadata.uid
  • Description: Unique event identifier assigned by JumpCloud.
  • Source: id
  • Usage: all events in this service
metadata.version
  • Description: OCSF schema version used for this event.
  • Literal: 1.8.0
  • Usage: all events in this service

Actor

actor.user.email_addr
  • Description: Email address of the actor who initiated the event.
  • Source: initiated_by.email
  • Usage: 11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more)
actor.user.name
  • Description: Display name of the actor who initiated the event.
  • Source: initiated_by.name
  • Usage: report_run
actor.user.type_id
  • Description: OCSF user type of the actor (1=User, 2=Admin, 3=System, 4=Service).
  • Source: initiated_by.type
  • Transform:
  • initiated_by.type → enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more))
  • Usage: 11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more)
actor.user.uid
  • Description: Unique identifier of the actor who initiated the event.
  • Source: initiated_by.id
  • Usage: 11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more)

Entity

entity.data.auth_method
  • Description: JumpCloud extension data on the managed entity: auth_method.
  • Source: auth_method
  • Usage: 11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more)
entity.data.changed_field
  • Description: JumpCloud extension data on the managed entity: changed_field.
  • Source: changes.field
  • Usage: custom_report_update, report_update
entity.data.changes_from_aggregations
  • Description: JumpCloud extension data on the managed entity: changes_from_aggregations.
  • Source: changes.from.aggregations
  • Usage: custom_report_update, report_update
entity.data.changes_from_fields_exclude
  • Description: JumpCloud extension data on the managed entity: changes_from_fields_exclude.
  • Source: changes.from.fields.exclude
  • Usage: custom_report_update, report_update
entity.data.changes_from_fields_include
  • Description: JumpCloud extension data on the managed entity: changes_from_fields_include.
  • Source: changes.from.fields.include
  • Usage: custom_report_update, report_update
entity.data.changes_from_filters_field
  • Description: JumpCloud extension data on the managed entity: changes_from_filters_field.
  • Source: changes.from.filters.field
  • Usage: custom_report_update, report_update
entity.data.changes_from_filters_filters
  • Description: JumpCloud extension data on the managed entity: changes_from_filters_filters.
  • Source: changes.from.filters.filters
  • Usage: custom_report_update, report_update
entity.data.changes_from_filters_operation
  • Description: JumpCloud extension data on the managed entity: changes_from_filters_operation.
  • Source: changes.from.filters.operation
  • Usage: custom_report_update, report_update
entity.data.changes_from_filters_value
  • Description: JumpCloud extension data on the managed entity: changes_from_filters_value.
  • Source: changes.from.filters.value
  • Usage: custom_report_update, report_update
entity.data.changes_from_limit
  • Description: JumpCloud extension data on the managed entity: changes_from_limit.
  • Source: changes.from.limit
  • Usage: custom_report_update, report_update
entity.data.changes_from_requestCache
  • Description: JumpCloud extension data on the managed entity: changes_from_requestCache.
  • Source: changes.from.requestCache
  • Usage: custom_report_update, report_update
entity.data.changes_from_sort
  • Description: JumpCloud extension data on the managed entity: changes_from_sort.
  • Source: changes.from.sort
  • Usage: custom_report_update
entity.data.changes_from_sort_field
  • Description: JumpCloud extension data on the managed entity: changes_from_sort_field.
  • Source: changes.from.sort.field
  • Usage: report_update
entity.data.changes_from_sort_order
  • Description: JumpCloud extension data on the managed entity: changes_from_sort_order.
  • Source: changes.from.sort.order
  • Usage: report_update
entity.data.columns
  • Description: JumpCloud extension data on the managed entity: columns.
  • Source: resource.columns
  • Usage: custom_report_create, custom_report_delete, custom_report_update
entity.data.configuration.column_settings.fixed
  • Description: JumpCloud extension data on the managed entity: configuration.column_settings.fixed.
  • Source: resource.configuration.column_settings.fixed
  • Usage: report_create, report_delete, report_run, report_update
entity.data.configurations
  • Description: JumpCloud extension data on the managed entity: configurations.
  • Source: resource.configurations
  • Usage: report_run
entity.data.cron_expression
  • Description: JumpCloud extension data on the managed entity: cron_expression.
  • Source: resource.cron_expression
  • Usage: scheduled_report_create, scheduled_report_delete, scheduled_report_update
entity.data.description
  • Description: JumpCloud extension data on the managed entity: description.
  • Source: resource.description
  • Usage: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_run, report_update
entity.data.export_mechanism
  • Description: JumpCloud extension data on the managed entity: export_mechanism.
  • Source: resource.export_mechanism
  • Usage: report_export
entity.data.export_method
  • Description: JumpCloud extension data on the managed entity: export_method.
  • Source: resource.export_method
  • Usage: report_export
entity.data.export_type
  • Description: JumpCloud extension data on the managed entity: export_type.
  • Source: resource.export_type
  • Usage: report_export, scheduled_report_create, scheduled_report_delete, scheduled_report_update
entity.data.filters.field
  • Description: JumpCloud extension data on the managed entity: filters.field.
  • Source: resource.filters.field
  • Usage: custom_report_create, custom_report_delete, custom_report_update
entity.data.filters.operation
  • Description: JumpCloud extension data on the managed entity: filters.operation.
  • Source: resource.filters.operation
  • Usage: custom_report_create, custom_report_delete, custom_report_update
entity.data.filters.value
  • Description: JumpCloud extension data on the managed entity: filters.value.
  • Source: resource.filters.value
  • Usage: custom_report_create, custom_report_delete, custom_report_update
entity.data.is_active
  • Description: JumpCloud extension data on the managed entity: is_active.
  • Source: resource.is_active
  • Usage: scheduled_report_create, scheduled_report_delete, scheduled_report_update
entity.data.new_value
  • Description: JumpCloud extension data on the managed entity: new_value.
  • Source: changes.new_value
  • Usage: custom_report_update
entity.data.old_value
  • Description: JumpCloud extension data on the managed entity: old_value.
  • Source: changes.old_value
  • Usage: custom_report_update
entity.data.recipient_count
  • Description: JumpCloud extension data on the managed entity: recipient_count.
  • Source: resource.recipient_count
  • Usage: scheduled_report_create, scheduled_report_delete, scheduled_report_update
entity.data.report_id
  • Description: JumpCloud extension data on the managed entity: report_id.
  • Source: resource.report_id
  • Usage: scheduled_report_create, scheduled_report_delete, scheduled_report_update
entity.data.report_type
  • Description: JumpCloud extension data on the managed entity: report_type.
  • Source: resource.report_type
  • Usage: scheduled_report_create, scheduled_report_delete, scheduled_report_update
entity.data.resources
  • Description: JumpCloud extension data on the managed entity: resources.
  • Source: resource.resources
  • Usage: report_create, report_delete, report_export, report_run, report_update
entity.data.schedule_frequency
  • Description: JumpCloud extension data on the managed entity: schedule_frequency.
  • Source: resource.schedule_frequency
  • Usage: scheduled_report_create, scheduled_report_delete, scheduled_report_update
entity.data.schedule_time
  • Description: JumpCloud extension data on the managed entity: schedule_time.
  • Source: resource.schedule_time
  • Usage: scheduled_report_create, scheduled_report_delete, scheduled_report_update
entity.data.search_request.aggregations
  • Description: JumpCloud extension data on the managed entity: search_request.aggregations.
  • Source: resource.search_request.aggregations
  • Usage: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update
entity.data.search_request.fields.exclude
  • Description: JumpCloud extension data on the managed entity: search_request.fields.exclude.
  • Source: resource.search_request.fields.exclude
  • Usage: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update
entity.data.search_request.fields.include
  • Description: JumpCloud extension data on the managed entity: search_request.fields.include.
  • Source: resource.search_request.fields.include
  • Usage: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update
entity.data.search_request.filters.field
  • Description: JumpCloud extension data on the managed entity: search_request.filters.field.
  • Source: resource.search_request.filters.field
  • Usage: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update
entity.data.search_request.filters.filters
  • Description: JumpCloud extension data on the managed entity: search_request.filters.filters.
  • Source: resource.search_request.filters.filters
  • Usage: custom_report_delete, custom_report_update, report_create, report_delete, report_update
entity.data.search_request.filters.filters.field
  • Description: JumpCloud extension data on the managed entity: search_request.filters.filters.field.
  • Source: resource.search_request.filters.filters.field
  • Usage: custom_report_create, report_export, report_run
entity.data.search_request.filters.filters.filters
  • Description: JumpCloud extension data on the managed entity: search_request.filters.filters.filters.
  • Source: resource.search_request.filters.filters.filters
  • Usage: report_export, report_run
entity.data.search_request.filters.filters.filters.field
  • Description: JumpCloud extension data on the managed entity: search_request.filters.filters.filters.field.
  • Source: resource.search_request.filters.filters.filters.field
  • Usage: custom_report_create
entity.data.search_request.filters.filters.filters.filters
  • Description: JumpCloud extension data on the managed entity: search_request.filters.filters.filters.filters.
  • Source: resource.search_request.filters.filters.filters.filters
  • Usage: custom_report_create
entity.data.search_request.filters.filters.filters.operation
  • Description: JumpCloud extension data on the managed entity: search_request.filters.filters.filters.operation.
  • Source: resource.search_request.filters.filters.filters.operation
  • Usage: custom_report_create
entity.data.search_request.filters.filters.filters.value
  • Description: JumpCloud extension data on the managed entity: search_request.filters.filters.filters.value.
  • Source: resource.search_request.filters.filters.filters.value
  • Usage: custom_report_create
entity.data.search_request.filters.filters.operation
  • Description: JumpCloud extension data on the managed entity: search_request.filters.filters.operation.
  • Source: resource.search_request.filters.filters.operation
  • Usage: custom_report_create, report_export, report_run
entity.data.search_request.filters.filters.value
  • Description: JumpCloud extension data on the managed entity: search_request.filters.filters.value.
  • Source: resource.search_request.filters.filters.value
  • Usage: custom_report_create, report_export, report_run
entity.data.search_request.filters.operation
  • Description: JumpCloud extension data on the managed entity: search_request.filters.operation.
  • Source: resource.search_request.filters.operation
  • Usage: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update
entity.data.search_request.filters.value
  • Description: JumpCloud extension data on the managed entity: search_request.filters.value.
  • Source: resource.search_request.filters.value
  • Usage: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update
entity.data.search_request.limit
  • Description: JumpCloud extension data on the managed entity: search_request.limit.
  • Source: resource.search_request.limit
  • Usage: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_run, report_update
entity.data.search_request.metadata.context
  • Description: JumpCloud extension data on the managed entity: search_request.metadata.context.
  • Source: resource.search_request.metadata.context
  • Usage: custom_report_delete
entity.data.search_request.metadata.context.key
  • Description: JumpCloud extension data on the managed entity: search_request.metadata.context.key.
  • Source: resource.search_request.metadata.context.key
  • Usage: custom_report_update
entity.data.search_request.metadata.context.value
  • Description: JumpCloud extension data on the managed entity: search_request.metadata.context.value.
  • Source: resource.search_request.metadata.context.value
  • Usage: custom_report_update
entity.data.search_request.metadata.source
  • Description: JumpCloud extension data on the managed entity: search_request.metadata.source.
  • Source: resource.search_request.metadata.source
  • Usage: custom_report_update
entity.data.search_request.requestCache
  • Description: JumpCloud extension data on the managed entity: search_request.requestCache.
  • Source: resource.search_request.requestCache
  • Usage: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_update
entity.data.search_request.sort.field
  • Description: JumpCloud extension data on the managed entity: search_request.sort.field.
  • Source: resource.search_request.sort.field
  • Usage: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update
entity.data.search_request.sort.order
  • Description: JumpCloud extension data on the managed entity: search_request.sort.order.
  • Source: resource.search_request.sort.order
  • Usage: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update
entity.data.secondary_objects
  • Description: JumpCloud extension data on the managed entity: secondary_objects.
  • Source: resource.secondary_objects
  • Usage: custom_report_create, custom_report_delete, custom_report_update
entity.data.temporal_schedule_id
  • Description: JumpCloud extension data on the managed entity: temporal_schedule_id.
  • Source: resource.temporal_schedule_id
  • Usage: scheduled_report_create, scheduled_report_delete, scheduled_report_update
entity.data.time_zone
  • Description: JumpCloud extension data on the managed entity: time_zone.
  • Source: resource.time_zone
  • Usage: scheduled_report_create, scheduled_report_delete, scheduled_report_update
entity.name
  • Description: The name of the managed entity. It should match the name of the specific entity object's name if populated, or the name of the managed entity if the type_id is 'Other'.
  • Source: resource.display_name, resource.name
  • Usage: 11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more)
entity.type
  • Description: The managed entity type. For example: Policy, User, Organization, Device.
  • Source: resource.primary_object
  • Usage: custom_report_create, custom_report_delete, custom_report_update
entity.uid
  • Description: The identifier of the managed entity. It should match the uid of the specific entity's object UID if populated, or the source specific ID if the type_id is 'Other'.
  • Source: resource.id
  • Usage: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_run, report_update, scheduled_report_create, scheduled_report_delete, scheduled_report_update
entity_result.data.changes_to_aggregations
  • Description: JumpCloud extension data on the managed entity: changes_to_aggregations.
  • Source: changes.to.aggregations
  • Usage: custom_report_update, report_update
entity_result.data.changes_to_fields_exclude
  • Description: JumpCloud extension data on the managed entity: changes_to_fields_exclude.
  • Source: changes.to.fields.exclude
  • Usage: custom_report_update, report_update
entity_result.data.changes_to_fields_include
  • Description: JumpCloud extension data on the managed entity: changes_to_fields_include.
  • Source: changes.to.fields.include
  • Usage: custom_report_update, report_update
entity_result.data.changes_to_filters_field
  • Description: JumpCloud extension data on the managed entity: changes_to_filters_field.
  • Source: changes.to.filters.field
  • Usage: custom_report_update, report_update
entity_result.data.changes_to_filters_filters
  • Description: JumpCloud extension data on the managed entity: changes_to_filters_filters.
  • Source: changes.to.filters.filters
  • Usage: custom_report_update, report_update
entity_result.data.changes_to_filters_operation
  • Description: JumpCloud extension data on the managed entity: changes_to_filters_operation.
  • Source: changes.to.filters.operation
  • Usage: custom_report_update, report_update
entity_result.data.changes_to_filters_value
  • Description: JumpCloud extension data on the managed entity: changes_to_filters_value.
  • Source: changes.to.filters.value
  • Usage: custom_report_update, report_update
entity_result.data.changes_to_limit
  • Description: JumpCloud extension data on the managed entity: changes_to_limit.
  • Source: changes.to.limit
  • Usage: custom_report_update, report_update
entity_result.data.changes_to_requestCache
  • Description: JumpCloud extension data on the managed entity: changes_to_requestCache.
  • Source: changes.to.requestCache
  • Usage: custom_report_update, report_update
entity_result.data.changes_to_sort
  • Description: JumpCloud extension data on the managed entity: changes_to_sort.
  • Source: changes.to.sort
  • Usage: custom_report_update
entity_result.data.changes_to_sort_field
  • Description: JumpCloud extension data on the managed entity: changes_to_sort_field.
  • Source: changes.to.sort.field
  • Usage: report_update
entity_result.data.changes_to_sort_order
  • Description: JumpCloud extension data on the managed entity: changes_to_sort_order.
  • Source: changes.to.sort.order
  • Usage: report_update

Src Endpoint

src_endpoint.autonomous_system.name
  • Description: Organization name for the Autonomous System.
  • Source: asn.organization
  • Usage: custom_report_create, custom_report_delete, custom_report_update, scheduled_report_create, scheduled_report_delete, scheduled_report_update
src_endpoint.autonomous_system.number
  • Description: Unique number that the AS is identified by.
  • Source: asn.number
  • Transform:
  • asn.number → int (custom_report_create, custom_report_delete, custom_report_update, scheduled_report_create, scheduled_report_delete, scheduled_report_update)
  • Usage: custom_report_create, custom_report_delete, custom_report_update, scheduled_report_create, scheduled_report_delete, scheduled_report_update
src_endpoint.ip
  • Description: Source IP address the request originated from.
  • Source: client_ip
  • Usage: 11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more)
src_endpoint.location.city
  • Description: The name of the city.
  • Source: geoip.city
  • Usage: 11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more)
src_endpoint.location.continent
  • Description: The name of the continent.
  • Source: geoip.continent_code
  • Usage: 11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more)
src_endpoint.location.country
  • Description: The ISO 3166-1 Alpha-2 country code.

    Note: The two letter country code should be capitalized. For example: US or CA.

  • Source: geoip.country_code
  • Usage: 11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more)
src_endpoint.location.lat
  • Description: The geographical Latitude coordinate represented in Decimal Degrees (DD). For example: 42.361145.
  • Source: geoip.latitude
  • Transform:
  • geoip.latitude → double (11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more))
  • Usage: 11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more)
src_endpoint.location.long
  • Description: The geographical Longitude coordinate represented in Decimal Degrees (DD). For example: -71.057083.
  • Source: geoip.longitude
  • Transform:
  • geoip.longitude → double (11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more))
  • Usage: 11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more)
src_endpoint.location.region
  • Description: The alphanumeric code that identifies the principal subdivision (e.g. province or state) of the country. For example, 'CH-VD' for the Canton of Vaud, Switzerland
  • Source: geoip.region_code
  • Usage: 11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more)

Http Request

http_request.user_agent
  • Description: The request header that identifies the operating system and web browser.
  • Source: user_agent
  • Usage: custom_report_create, custom_report_delete, custom_report_update, scheduled_report_create, scheduled_report_delete, scheduled_report_update

Observables

observables[].name
  • Description: The full name of the observable attribute. The name is a pointer/reference to an attribute within the OCSF event data. For example: file.name. Array attributes may be represented in one of three ways. For example: resources.uid, resources[].uid, resources[0].uid.
  • Literal: actor.user.email_addr, actor.user.name, actor.user.uid, http_request.user_agent, src_endpoint.ip, src_endpoint.location.country
  • Usage: 11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more)
observables[].type_id
  • Description: The observable value type identifier.
  • Literal: 14, 16, 2, 31, 4, 5
  • Usage: 11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more)
observables[].value
  • Description: The value associated with the observable attribute. The meaning of the value depends on the observable type.
    If the name refers to a scalar attribute, then the value is the value of the attribute.
    If the name refers to an object attribute, then the value is not populated.
  • Source: client_ip, geoip.country_code, initiated_by.email, initiated_by.id, initiated_by.name, user_agent
  • Usage: 11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more)

Other

end_time
  • Description: The end time of a time period, or the time of the most recent event included in the aggregate event.
  • Source: completed_at
  • Usage: scheduled_report_run_failed, scheduled_report_run_success
job.name
  • Description: The name of the job.
  • Source: display_name
  • Usage: scheduled_report_run_failed, scheduled_report_run_success

Unmapped

unmapped.@version
  • Description: JumpCloud Directory Insights field @version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: @version
  • Usage: all events in this service
unmapped.artifact_id
  • Description: JumpCloud Directory Insights field artifact_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: artifact_id
  • Usage: scheduled_report_run_success
unmapped.asn.network
  • Description: JumpCloud Directory Insights field asn.network preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: asn.network
  • Usage: custom_report_create, custom_report_delete, custom_report_update, scheduled_report_create, scheduled_report_delete, scheduled_report_update
unmapped.client_ip
  • Description: JumpCloud Directory Insights field client_ip preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: client_ip
  • Usage: scheduled_report_run_failed, scheduled_report_run_success
unmapped.export_type
  • Description: JumpCloud Directory Insights field export_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: export_type
  • Usage: scheduled_report_run_failed, scheduled_report_run_success
unmapped.file_size
  • Description: JumpCloud Directory Insights field file_size preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: file_size
  • Usage: scheduled_report_run_success
unmapped.geoip.error
  • Description: JumpCloud Directory Insights field geoip.error preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.error
  • Usage: report_export, report_run
unmapped.geoip.ip_address
  • Description: JumpCloud Directory Insights field geoip.ip_address preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.ip_address
  • Usage: report_export, report_run
unmapped.geoip.region_name
  • Description: JumpCloud Directory Insights field geoip.region_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.region_name
  • Usage: 11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more)
unmapped.geoip.timezone
  • Description: JumpCloud Directory Insights field geoip.timezone preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.timezone
  • Usage: 11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more)
unmapped.initiated_by
  • Description: JumpCloud Directory Insights field initiated_by preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by
  • Usage: scheduled_report_run_failed, scheduled_report_run_success
unmapped.initiated_by_email_hash
  • Description: JumpCloud Directory Insights field initiated_by_email_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_email_hash
  • Usage: 11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more)
unmapped.initiated_by_id_hash
  • Description: JumpCloud Directory Insights field initiated_by_id_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_id_hash
  • Usage: 11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more)
unmapped.initiated_by_name_hash
  • Description: JumpCloud Directory Insights field initiated_by_name_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_name_hash
  • Usage: report_run
unmapped.is_out_of_bound
  • Description: JumpCloud Directory Insights field is_out_of_bound preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: is_out_of_bound
  • Usage: custom_report_create, custom_report_delete, custom_report_update, scheduled_report_create, scheduled_report_delete, scheduled_report_run_failed, scheduled_report_run_success, scheduled_report_update
unmapped.jc_application_name
  • Description: JumpCloud Directory Insights field jc_application_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_application_name
  • Usage: custom_report_create, custom_report_delete, custom_report_update, scheduled_report_create, scheduled_report_delete, scheduled_report_run_failed, scheduled_report_run_success, scheduled_report_update
unmapped.jc_initiated_by_email
  • Description: JumpCloud Directory Insights field jc_initiated_by_email preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_initiated_by_email
  • Usage: scheduled_report_run_failed, scheduled_report_update
unmapped.jc_initiated_by_id
  • Description: JumpCloud Directory Insights field jc_initiated_by_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_initiated_by_id
  • Usage: scheduled_report_run_failed, scheduled_report_update
unmapped.jc_initiated_by_username
  • Description: JumpCloud Directory Insights field jc_initiated_by_username preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_initiated_by_username
  • Usage: scheduled_report_run_failed, scheduled_report_update
unmapped.jc_organization_name
  • Description: JumpCloud Directory Insights field jc_organization_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_organization_name
  • Usage: scheduled_report_run_failed, scheduled_report_update
unmapped.jc_provider_id
  • Description: JumpCloud Directory Insights field jc_provider_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_provider_id
  • Usage: scheduled_report_run_failed, scheduled_report_update
unmapped.jc_system_display_name
  • Description: JumpCloud Directory Insights field jc_system_display_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_system_display_name
  • Usage: scheduled_report_run_failed, scheduled_report_update
unmapped.jc_system_hostname
  • Description: JumpCloud Directory Insights field jc_system_hostname preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_system_hostname
  • Usage: scheduled_report_run_failed, scheduled_report_update
unmapped.provider
  • Description: JumpCloud Directory Insights field provider preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: provider
  • Usage: report_export, report_run
unmapped.report_id
  • Description: JumpCloud Directory Insights field report_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: report_id
  • Usage: scheduled_report_run_success
unmapped.resource_id_hash
  • Description: JumpCloud Directory Insights field resource_id_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource_id_hash
  • Usage: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_run, report_update, scheduled_report_create, scheduled_report_delete, scheduled_report_update
unmapped.resource_name_hash
  • Description: JumpCloud Directory Insights field resource_name_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource_name_hash
  • Usage: custom_report_create
unmapped.row_count
  • Description: JumpCloud Directory Insights field row_count preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: row_count
  • Usage: scheduled_report_run_success
unmapped.schedule_frequency
  • Description: JumpCloud Directory Insights field schedule_frequency preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: schedule_frequency
  • Usage: scheduled_report_run_failed, scheduled_report_run_success
unmapped.scheduled_report_id
  • Description: JumpCloud Directory Insights field scheduled_report_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: scheduled_report_id
  • Usage: scheduled_report_run_failed, scheduled_report_run_success
unmapped.temporal_schedule_id
  • Description: JumpCloud Directory Insights field temporal_schedule_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: temporal_schedule_id
  • Usage: scheduled_report_run_failed, scheduled_report_run_success
unmapped.timestamp_source
  • Description: JumpCloud Directory Insights field timestamp_source preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: timestamp_source
  • Usage: all events in this service
unmapped.user_agent
  • Description: JumpCloud Directory Insights field user_agent preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: user_agent
  • Usage: scheduled_report_run_failed, scheduled_report_run_success
unmapped.useragent.device
  • Description: JumpCloud Directory Insights field useragent.device preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.device
  • Usage: 11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more)
unmapped.useragent.major
  • Description: JumpCloud Directory Insights field useragent.major preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.major
  • Usage: 11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more)
unmapped.useragent.minor
  • Description: JumpCloud Directory Insights field useragent.minor preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.minor
  • Usage: 11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more)
unmapped.useragent.name
  • Description: JumpCloud Directory Insights field useragent.name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.name
  • Usage: 11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more)
unmapped.useragent.os
  • Description: JumpCloud Directory Insights field useragent.os preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os
  • Usage: 11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more)
unmapped.useragent.os_full
  • Description: JumpCloud Directory Insights field useragent.os_full preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_full
  • Usage: 11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more)
unmapped.useragent.os_major
  • Description: JumpCloud Directory Insights field useragent.os_major preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_major
  • Usage: custom_report_create, custom_report_delete, custom_report_update, scheduled_report_create, scheduled_report_delete, scheduled_report_update
unmapped.useragent.os_minor
  • Description: JumpCloud Directory Insights field useragent.os_minor preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_minor
  • Usage: custom_report_create, custom_report_delete, custom_report_update, scheduled_report_create, scheduled_report_delete, scheduled_report_update
unmapped.useragent.os_name
  • Description: JumpCloud Directory Insights field useragent.os_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_name
  • Usage: 11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more)
unmapped.useragent.os_patch
  • Description: JumpCloud Directory Insights field useragent.os_patch preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_patch
  • Usage: custom_report_create, custom_report_delete, custom_report_update, scheduled_report_create, scheduled_report_delete, scheduled_report_update
unmapped.useragent.os_version
  • Description: JumpCloud Directory Insights field useragent.os_version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_version
  • Usage: custom_report_create, custom_report_delete, custom_report_update, scheduled_report_create, scheduled_report_delete, scheduled_report_update
unmapped.useragent.patch
  • Description: JumpCloud Directory Insights field useragent.patch preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.patch
  • Usage: custom_report_create, custom_report_delete, custom_report_update, scheduled_report_create, scheduled_report_delete, scheduled_report_update
unmapped.useragent.version
  • Description: JumpCloud Directory Insights field useragent.version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.version
  • Usage: 11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more)
unmapped.workflow_execution_id
  • Description: JumpCloud Directory Insights field workflow_execution_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: workflow_execution_id
  • Usage: scheduled_report_run_failed, scheduled_report_run_success

SaaS Management#

saas_management · 16 events

Event Category Class Activity Type UID Fields
saas_management_account_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 40
saas_management_account_discover Discovery (5) User Inventory Info (5003) Collect (2) 500302 42
saas_management_account_user_assign Identity & Access Management (3) Entity Management (3004) Update (3) 300403 45
saas_management_application_access_restriction_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 68
saas_management_application_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 43
saas_management_application_discover Discovery (5) Software Inventory Info (5020) Collect (2) 502002 30
saas_management_application_review Identity & Access Management (3) Entity Management (3004) Update (3) 300403 63
saas_management_application_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 68
saas_management_connector_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 41
saas_management_connector_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 39
saas_management_connector_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 42
saas_management_disable Identity & Access Management (3) Entity Management (3004) Disable (9) 300409 41
saas_management_enable Identity & Access Management (3) Entity Management (3004) Enable (8) 300408 43
saas_management_login_event Identity & Access Management (3) Authentication (3002) Logon (1) 300201 38
saas_management_settings_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 54
saas_management_tenant_discover Discovery (5) Cloud Resources Inventory Info (5023) Collect (2) 502302 31

OCSF field mappings#

Legend

  • Description: what the OCSF field represents (from OCSF schema v1.8.0)
  • Source: raw JumpCloud event field(s) mapped via ${{placeholder}} template
  • Transform: fieldMappings entry applied at runtime (cast, enum, etc.)
  • Literal: static value set in the mapping template
  • Usage: event types in this service that include this field

Core

activity_id
  • Description: The normalized identifier of the activity that triggered the event.
  • Literal: 1, 2, 3, 4, 8, 9
  • Usage: all events in this service
activity_name
  • Description: The event activity name, as defined by the activity_id.
  • Literal: Collect, Create, Delete, Disable, Enable, Logon, Update
  • Usage: all events in this service
category_name
  • Description: The event category name, as defined by category_uid value: Discovery.
  • Literal: Discovery, Identity & Access Management
  • Usage: all events in this service
category_uid
  • Description: The category unique identifier of the event.
  • Literal: 3, 5
  • Usage: all events in this service
class_name
  • Description: The event class name, as defined by class_uid value: User Inventory Info.
  • Literal: Authentication, Cloud Resources Inventory Info, Entity Management, Software Inventory Info, User Inventory Info
  • Usage: all events in this service
class_uid
  • Description: The unique identifier of a class. A class describes the attributes available in an event.
  • Literal: 3002, 3004, 5003, 5020, 5023
  • Usage: all events in this service
message
  • Description: The description of the event/finding, as defined by the source.
  • Source: detail
  • Usage: all events in this service
severity_id
  • Description: OCSF severity identifier for the event.
  • Literal: 1
  • Usage: all events in this service
status_detail
  • Description: The status detail contains additional information about the event/finding outcome.
  • Source: error_message
  • Usage: all events in this service
status_id
  • Description: Normalized status of the activity (1=Success, 2=Failure).
  • Source: success
  • Transform:
  • success → boolean_to_status_id; true→1, false→2 (all events in this service)
  • Usage: all events in this service
time
  • Description: Event time, in epoch milliseconds (OCSF time).
  • Source: timestamp
  • Transform:
  • timestamp → iso8601_to_epoch_millis (all events in this service)
  • Usage: all events in this service
type_uid
  • Description: The event/finding type ID. It identifies the event's semantics and structure. The value is calculated by the logging system as: class_uid * 100 + activity_id.
  • Literal: 300201, 300401, 300403, 300404, 300408, 300409, 500302, 502002, 502302
  • Usage: all events in this service

Metadata

metadata.event_code
  • Description: JumpCloud event type code.
  • Source: event_type
  • Usage: all events in this service
metadata.original_time
  • Description: The original event time as reported by the event source. For example, the time in the original format from system event log such as Syslog on Unix/Linux and the System event file on Windows. Omit if event is generated instead of collected via logs.
  • Source: server_timestamp
  • Usage: saas_management_account_discover, saas_management_application_access_restriction_update, saas_management_application_discover, saas_management_application_review, saas_management_application_update, saas_management_enable, saas_management_login_event
metadata.processed_time
  • Description: The event processed time, such as an ETL operation.
  • Source: jc_transformation_ts
  • Usage: all events in this service
metadata.product.name
  • Description: Originating JumpCloud service that produced the event.
  • Source: service
  • Usage: all events in this service
metadata.tenant_uid
  • Description: JumpCloud organization (tenant) identifier.
  • Source: organization
  • Usage: all events in this service
metadata.uid
  • Description: Unique event identifier assigned by JumpCloud.
  • Source: id
  • Usage: all events in this service
metadata.version
  • Description: OCSF schema version used for this event.
  • Literal: 1.8.0
  • Usage: all events in this service

Actor

actor.user.email_addr
  • Description: Email address of the actor who initiated the event.
  • Source: initiated_by.email
  • Usage: 12 events: saas_management_account_delete, saas_management_account_user_assign, saas_management_application_access_restriction_update, saas_management_application_delete, saas_management_application_review, saas_management_application_update, saas_management_connector_create, saas_management_connector_delete, ... (+4 more)
actor.user.full_name
  • Description: The full name of the user, as reported by the product.
  • Source: initiated_by.name
  • Usage: saas_management_application_access_restriction_update, saas_management_application_update, saas_management_connector_create
actor.user.name
  • Description: Display name of the actor who initiated the event.
  • Source: initiated_by.username
  • Usage: saas_management_disable, saas_management_enable, saas_management_settings_update
actor.user.type_id
  • Description: OCSF user type of the actor (1=User, 2=Admin, 3=System, 4=Service).
  • Source: initiated_by.type
  • Transform:
  • initiated_by.type → enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (12 events: saas_management_account_delete, saas_management_account_user_assign, saas_management_application_access_restriction_update, saas_management_application_delete, saas_management_application_review, saas_management_application_update, saas_management_connector_create, saas_management_connector_delete, ... (+4 more))
  • Usage: 12 events: saas_management_account_delete, saas_management_account_user_assign, saas_management_application_access_restriction_update, saas_management_application_delete, saas_management_application_review, saas_management_application_update, saas_management_connector_create, saas_management_connector_delete, ... (+4 more)
actor.user.uid
  • Description: Unique identifier of the actor who initiated the event.
  • Source: initiated_by.id
  • Usage: 12 events: saas_management_account_delete, saas_management_account_user_assign, saas_management_application_access_restriction_update, saas_management_application_delete, saas_management_application_review, saas_management_application_update, saas_management_connector_create, saas_management_connector_delete, ... (+4 more)

User

user.email_addr
  • Description: Email address of the user associated with the event.
  • Source: resource.account_email, resource.account_identifier
  • Usage: saas_management_account_discover, saas_management_login_event
user.name
  • Description: The username. For example, janedoe1.
  • Source: resource.account_username
  • Usage: saas_management_account_discover
user.uid
  • Description: Unique identifier of the user associated with the event.
  • Source: resource.account_id, resource.user_id
  • Usage: saas_management_account_discover, saas_management_login_event

Entity

entity.data.access_restriction
  • Description: JumpCloud extension data on the managed entity: access_restriction.
  • Source: resource.access_restriction
  • Usage: saas_management_application_access_restriction_update, saas_management_application_review, saas_management_application_update
entity.data.account_count
  • Description: JumpCloud extension data on the managed entity: account_count.
  • Source: resource.account_count
  • Usage: saas_management_application_delete
entity.data.alternative_button_text
  • Description: JumpCloud extension data on the managed entity: alternative_button_text.
  • Source: resource.alternative_button_text
  • Usage: saas_management_application_access_restriction_update, saas_management_application_update
entity.data.alternative_button_url
  • Description: JumpCloud extension data on the managed entity: alternative_button_url.
  • Source: resource.alternative_button_url
  • Usage: saas_management_application_access_restriction_update, saas_management_application_update
entity.data.application_account_count
  • Description: JumpCloud extension data on the managed entity: application_account_count.
  • Source: resource.application_account_count
  • Usage: saas_management_application_delete
entity.data.application_category
  • Description: JumpCloud extension data on the managed entity: application_category.
  • Source: resource.application_category
  • Usage: saas_management_application_access_restriction_update, saas_management_application_review, saas_management_application_update
entity.data.application_name
  • Description: JumpCloud extension data on the managed entity: application_name.
  • Source: resource.application_name
  • Usage: saas_management_account_delete, saas_management_account_user_assign
entity.data.application_owner
  • Description: JumpCloud extension data on the managed entity: application_owner.
  • Source: resource.application_owner
  • Usage: saas_management_application_delete
entity.data.application_status
  • Description: JumpCloud extension data on the managed entity: application_status.
  • Source: resource.application_status
  • Usage: saas_management_application_delete
entity.data.block_restriction_message
  • Description: JumpCloud extension data on the managed entity: block_restriction_message.
  • Source: resource.block_restriction_message
  • Usage: saas_management_settings_update
entity.data.catalog_app_id
  • Description: JumpCloud extension data on the managed entity: catalog_app_id.
  • Source: resource.catalog_app_id
  • Usage: saas_management_application_access_restriction_update, saas_management_application_delete, saas_management_application_review, saas_management_application_update
entity.data.changed_field
  • Description: JumpCloud extension data on the managed entity: changed_field.
  • Source: changes.field
  • Usage: saas_management_account_user_assign, saas_management_application_access_restriction_update, saas_management_application_review, saas_management_application_update, saas_management_connector_update, saas_management_settings_update
entity.data.changes_from
  • Description: JumpCloud extension data on the managed entity: changes_from.
  • Source: changes.from
  • Usage: saas_management_application_access_restriction_update, saas_management_application_review, saas_management_application_update, saas_management_connector_update, saas_management_settings_update
entity.data.default_access_restriction
  • Description: JumpCloud extension data on the managed entity: default_access_restriction.
  • Source: resource.default_access_restriction
  • Usage: saas_management_settings_update
entity.data.discovered_apps_notification_frequency
  • Description: JumpCloud extension data on the managed entity: discovered_apps_notification_frequency.
  • Source: resource.discovered_apps_notification_frequency
  • Usage: saas_management_settings_update
entity.data.excluded_group_ids
  • Description: JumpCloud extension data on the managed entity: excluded_group_ids.
  • Source: resource.excluded_group_ids
  • Usage: saas_management_settings_update
entity.data.former_employee_auto_delete_period
  • Description: JumpCloud extension data on the managed entity: former_employee_auto_delete_period.
  • Source: resource.former_employee_auto_delete_period
  • Usage: saas_management_settings_update
entity.data.is_enabled
  • Description: JumpCloud extension data on the managed entity: is_enabled.
  • Source: resource.is_enabled
  • Usage: saas_management_settings_update
entity.data.owner_user_email
  • Description: JumpCloud extension data on the managed entity: owner_user_email.
  • Source: resource.owner_user.email
  • Usage: saas_management_application_access_restriction_update, saas_management_application_review, saas_management_application_update
entity.data.owner_user_id
  • Description: JumpCloud extension data on the managed entity: owner_user_id.
  • Source: resource.owner_user.id
  • Usage: saas_management_application_access_restriction_update, saas_management_application_review, saas_management_application_update
entity.data.owner_user_name
  • Description: JumpCloud extension data on the managed entity: owner_user_name.
  • Source: resource.owner_user.name
  • Usage: saas_management_application_access_restriction_update, saas_management_application_review, saas_management_application_update
entity.data.status
  • Description: JumpCloud extension data on the managed entity: status.
  • Source: resource.status
  • Usage: saas_management_application_access_restriction_update, saas_management_application_review, saas_management_application_update
entity.data.tracked_domains
  • Description: JumpCloud extension data on the managed entity: tracked_domains.
  • Source: resource.tracked_domains
  • Usage: saas_management_settings_update
entity.data.unapproved_accounts_notification_frequency
  • Description: JumpCloud extension data on the managed entity: unapproved_accounts_notification_frequency.
  • Source: resource.unapproved_accounts_notification_frequency
  • Usage: saas_management_settings_update
entity.data.upcoming_renewal_notification_frequency
  • Description: JumpCloud extension data on the managed entity: upcoming_renewal_notification_frequency.
  • Source: resource.upcoming_renewal_notification_frequency
  • Usage: saas_management_settings_update
entity.data.warning_restriction_message
  • Description: JumpCloud extension data on the managed entity: warning_restriction_message.
  • Source: resource.warning_restriction_message
  • Usage: saas_management_settings_update
entity.name
  • Description: The name of the managed entity. It should match the name of the specific entity object's name if populated, or the name of the managed entity if the type_id is 'Other'.
  • Source: resource.application_name, resource.connector_name
  • Usage: saas_management_application_access_restriction_update, saas_management_application_delete, saas_management_application_review, saas_management_application_update, saas_management_connector_create, saas_management_connector_delete, saas_management_connector_update
entity.type
  • Description: The managed entity type. For example: Policy, User, Organization, Device.
  • Source: resource.connector_type
  • Usage: saas_management_connector_create, saas_management_connector_delete, saas_management_connector_update
entity.uid
  • Description: The identifier of the managed entity. It should match the uid of the specific entity's object UID if populated, or the source specific ID if the type_id is 'Other'.
  • Source: resource.account_id, resource.application_id, resource.connector_id, service
  • Usage: 12 events: saas_management_account_delete, saas_management_account_user_assign, saas_management_application_access_restriction_update, saas_management_application_delete, saas_management_application_review, saas_management_application_update, saas_management_connector_create, saas_management_connector_delete, ... (+4 more)
entity.user.email_addr
  • Description: The user's primary email address.
  • Source: resource.account_email
  • Usage: saas_management_account_delete, saas_management_account_user_assign
entity.user.name
  • Description: The username. For example, janedoe1.
  • Source: resource.account_username
  • Usage: saas_management_account_delete, saas_management_account_user_assign
entity_result.data.changes_to
  • Description: JumpCloud extension data on the managed entity: changes_to.
  • Source: changes.to
  • Usage: saas_management_account_user_assign, saas_management_application_access_restriction_update, saas_management_application_review, saas_management_application_update, saas_management_connector_update, saas_management_settings_update
entity_result.user.email_addr
  • Description: The user's primary email address.
  • Source: resource.user_email
  • Usage: saas_management_account_user_assign
entity_result.user.name
  • Description: The username. For example, janedoe1.
  • Source: resource.user_display_name
  • Usage: saas_management_account_user_assign
entity_result.user.uid
  • Description: The unique user identifier. For example, the Windows user SID, ActiveDirectory DN or AWS user ARN.
  • Source: resource.user_id
  • Usage: saas_management_account_user_assign

Src Endpoint

src_endpoint.autonomous_system.name
  • Description: Organization name for the Autonomous System.
  • Source: asn.organization
  • Usage: saas_management_application_access_restriction_update, saas_management_application_review, saas_management_application_update
src_endpoint.autonomous_system.number
  • Description: Unique number that the AS is identified by.
  • Source: asn.number
  • Transform:
  • asn.number → int (saas_management_application_access_restriction_update, saas_management_application_review, saas_management_application_update)
  • Usage: saas_management_application_access_restriction_update, saas_management_application_review, saas_management_application_update
src_endpoint.ip
  • Description: Source IP address the request originated from.
  • Source: client_ip
  • Usage: 12 events: saas_management_account_delete, saas_management_account_user_assign, saas_management_application_access_restriction_update, saas_management_application_delete, saas_management_application_review, saas_management_application_update, saas_management_connector_create, saas_management_connector_delete, ... (+4 more)
src_endpoint.location.city
  • Description: The name of the city.
  • Source: geoip.city
  • Usage: 12 events: saas_management_account_delete, saas_management_account_user_assign, saas_management_application_access_restriction_update, saas_management_application_delete, saas_management_application_review, saas_management_application_update, saas_management_connector_create, saas_management_connector_delete, ... (+4 more)
src_endpoint.location.continent
  • Description: The name of the continent.
  • Source: geoip.continent_code
  • Usage: 12 events: saas_management_account_delete, saas_management_account_user_assign, saas_management_application_access_restriction_update, saas_management_application_delete, saas_management_application_review, saas_management_application_update, saas_management_connector_create, saas_management_connector_delete, ... (+4 more)
src_endpoint.location.country
  • Description: The ISO 3166-1 Alpha-2 country code.

    Note: The two letter country code should be capitalized. For example: US or CA.

  • Source: geoip.country_code
  • Usage: 12 events: saas_management_account_delete, saas_management_account_user_assign, saas_management_application_access_restriction_update, saas_management_application_delete, saas_management_application_review, saas_management_application_update, saas_management_connector_create, saas_management_connector_delete, ... (+4 more)
src_endpoint.location.lat
  • Description: The geographical Latitude coordinate represented in Decimal Degrees (DD). For example: 42.361145.
  • Source: geoip.latitude
  • Transform:
  • geoip.latitude → double (12 events: saas_management_account_delete, saas_management_account_user_assign, saas_management_application_access_restriction_update, saas_management_application_delete, saas_management_application_review, saas_management_application_update, saas_management_connector_create, saas_management_connector_delete, ... (+4 more))
  • Usage: 12 events: saas_management_account_delete, saas_management_account_user_assign, saas_management_application_access_restriction_update, saas_management_application_delete, saas_management_application_review, saas_management_application_update, saas_management_connector_create, saas_management_connector_delete, ... (+4 more)
src_endpoint.location.long
  • Description: The geographical Longitude coordinate represented in Decimal Degrees (DD). For example: -71.057083.
  • Source: geoip.longitude
  • Transform:
  • geoip.longitude → double (12 events: saas_management_account_delete, saas_management_account_user_assign, saas_management_application_access_restriction_update, saas_management_application_delete, saas_management_application_review, saas_management_application_update, saas_management_connector_create, saas_management_connector_delete, ... (+4 more))
  • Usage: 12 events: saas_management_account_delete, saas_management_account_user_assign, saas_management_application_access_restriction_update, saas_management_application_delete, saas_management_application_review, saas_management_application_update, saas_management_connector_create, saas_management_connector_delete, ... (+4 more)
src_endpoint.location.region
  • Description: The alphanumeric code that identifies the principal subdivision (e.g. province or state) of the country. For example, 'CH-VD' for the Canton of Vaud, Switzerland
  • Source: geoip.region_code
  • Usage: 12 events: saas_management_account_delete, saas_management_account_user_assign, saas_management_application_access_restriction_update, saas_management_application_delete, saas_management_application_review, saas_management_application_update, saas_management_connector_create, saas_management_connector_delete, ... (+4 more)

Http Request

http_request.user_agent
  • Description: The request header that identifies the operating system and web browser.
  • Source: user_agent
  • Usage: saas_management_application_access_restriction_update, saas_management_application_review, saas_management_application_update

Observables

observables[].name
  • Description: The full name of the observable attribute. The name is a pointer/reference to an attribute within the OCSF event data. For example: file.name. Array attributes may be represented in one of three ways. For example: resources.uid, resources[].uid, resources[0].uid.
  • Literal: actor.user.email_addr, actor.user.name, actor.user.uid, cloud.account.name, cloud.account.uid, entity.user.email_addr, entity.user.name, entity_result.user.email_addr, entity_result.user.name, entity_result.user.uid, http_request.user_agent, src_endpoint.ip, src_endpoint.location.country, user.email_addr, user.name, user.uid
  • Usage: 15 events (missing: saas_management_application_discover)
observables[].type_id
  • Description: The observable value type identifier.
  • Literal: 14, 16, 2, 31, 34, 35, 4, 5
  • Usage: 15 events (missing: saas_management_application_discover)
observables[].value
  • Description: The value associated with the observable attribute. The meaning of the value depends on the observable type.
    If the name refers to a scalar attribute, then the value is the value of the attribute.
    If the name refers to an object attribute, then the value is not populated.
  • Source: client_ip, geoip.country_code, initiated_by.email, initiated_by.id, initiated_by.username, resource.account_email, resource.account_id, resource.account_identifier, resource.account_username, resource.tenant_display_name, resource.tenant_id, resource.user_display_name, resource.user_email, resource.user_id, user_agent
  • Usage: 15 events (missing: saas_management_application_discover)

Other

cloud.account.name
  • Description: The name of the account (e.g. GCP Project name , Linux Account name or AWS Account name).
  • Source: resource.tenant_display_name
  • Usage: saas_management_login_event, saas_management_tenant_discover
cloud.account.uid
  • Description: The unique identifier of the account (e.g. AWS Account ID , OCID , GCP Project ID , Azure Subscription ID , Google Workspace Customer ID , or M365 Tenant UID).
  • Source: resource.tenant_id
  • Usage: saas_management_tenant_discover
product.name
  • Description: The name of the product.
  • Source: resource.application_name
  • Usage: saas_management_application_discover
product.uid
  • Description: The unique identifier of the product.
  • Source: resource.application_id
  • Usage: saas_management_application_discover
service.name
  • Description: The name of the service.
  • Source: resource.application_name
  • Usage: saas_management_login_event

Unmapped

unmapped.@version
  • Description: JumpCloud Directory Insights field @version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: @version
  • Usage: all events in this service
unmapped.asn.network
  • Description: JumpCloud Directory Insights field asn.network preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: asn.network
  • Usage: saas_management_application_access_restriction_update, saas_management_application_review, saas_management_application_update
unmapped.client_ip
  • Description: JumpCloud Directory Insights field client_ip preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: client_ip
  • Usage: saas_management_account_discover, saas_management_application_discover, saas_management_login_event, saas_management_tenant_discover
unmapped.file_input_timestamp
  • Description: JumpCloud Directory Insights field file_input_timestamp preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: file_input_timestamp
  • Usage: saas_management_application_access_restriction_update, saas_management_application_update
unmapped.geoip.region_name
  • Description: JumpCloud Directory Insights field geoip.region_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.region_name
  • Usage: 12 events: saas_management_account_delete, saas_management_account_user_assign, saas_management_application_access_restriction_update, saas_management_application_delete, saas_management_application_review, saas_management_application_update, saas_management_connector_create, saas_management_connector_delete, ... (+4 more)
unmapped.geoip.timezone
  • Description: JumpCloud Directory Insights field geoip.timezone preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.timezone
  • Usage: 12 events: saas_management_account_delete, saas_management_account_user_assign, saas_management_application_access_restriction_update, saas_management_application_delete, saas_management_application_review, saas_management_application_update, saas_management_connector_create, saas_management_connector_delete, ... (+4 more)
unmapped.initiated_by
  • Description: JumpCloud Directory Insights field initiated_by preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by
  • Usage: saas_management_account_discover, saas_management_application_discover, saas_management_login_event, saas_management_tenant_discover
unmapped.initiated_by.hostname
  • Description: JumpCloud Directory Insights field initiated_by.hostname preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by.hostname
  • Usage: saas_management_disable, saas_management_enable, saas_management_settings_update
unmapped.initiated_by.uid
  • Description: JumpCloud Directory Insights field initiated_by.uid preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by.uid
  • Usage: saas_management_disable, saas_management_enable, saas_management_settings_update
unmapped.initiated_by_email_hash
  • Description: JumpCloud Directory Insights field initiated_by_email_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_email_hash
  • Usage: 12 events: saas_management_account_delete, saas_management_account_user_assign, saas_management_application_access_restriction_update, saas_management_application_delete, saas_management_application_review, saas_management_application_update, saas_management_connector_create, saas_management_connector_delete, ... (+4 more)
unmapped.initiated_by_id_hash
  • Description: JumpCloud Directory Insights field initiated_by_id_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_id_hash
  • Usage: 12 events: saas_management_account_delete, saas_management_account_user_assign, saas_management_application_access_restriction_update, saas_management_application_delete, saas_management_application_review, saas_management_application_update, saas_management_connector_create, saas_management_connector_delete, ... (+4 more)
unmapped.initiated_by_name_hash
  • Description: JumpCloud Directory Insights field initiated_by_name_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_name_hash
  • Usage: saas_management_application_access_restriction_update, saas_management_application_update, saas_management_connector_create
unmapped.initiated_by_username_hash
  • Description: JumpCloud Directory Insights field initiated_by_username_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_username_hash
  • Usage: saas_management_disable, saas_management_enable, saas_management_settings_update
unmapped.is_out_of_bound
  • Description: JumpCloud Directory Insights field is_out_of_bound preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: is_out_of_bound
  • Usage: saas_management_application_access_restriction_update, saas_management_application_discover, saas_management_application_review, saas_management_application_update
unmapped.jc_application_name
  • Description: JumpCloud Directory Insights field jc_application_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_application_name
  • Usage: saas_management_application_access_restriction_update, saas_management_application_discover, saas_management_application_review, saas_management_application_update
unmapped.jc_initiated_by_email
  • Description: JumpCloud Directory Insights field jc_initiated_by_email preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_initiated_by_email
  • Usage: saas_management_application_access_restriction_update, saas_management_application_review, saas_management_application_update
unmapped.jc_initiated_by_id
  • Description: JumpCloud Directory Insights field jc_initiated_by_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_initiated_by_id
  • Usage: saas_management_application_access_restriction_update, saas_management_application_review, saas_management_application_update
unmapped.jc_initiated_by_username
  • Description: JumpCloud Directory Insights field jc_initiated_by_username preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_initiated_by_username
  • Usage: saas_management_application_access_restriction_update, saas_management_application_review, saas_management_application_update
unmapped.jc_organization_name
  • Description: JumpCloud Directory Insights field jc_organization_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_organization_name
  • Usage: saas_management_application_access_restriction_update, saas_management_application_review, saas_management_application_update
unmapped.jc_provider_id
  • Description: JumpCloud Directory Insights field jc_provider_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_provider_id
  • Usage: saas_management_application_access_restriction_update, saas_management_application_review, saas_management_application_update
unmapped.jc_system_display_name
  • Description: JumpCloud Directory Insights field jc_system_display_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_system_display_name
  • Usage: saas_management_application_access_restriction_update, saas_management_application_review, saas_management_application_update
unmapped.jc_system_hostname
  • Description: JumpCloud Directory Insights field jc_system_hostname preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_system_hostname
  • Usage: saas_management_application_access_restriction_update, saas_management_application_review, saas_management_application_update
unmapped.resource.application_category
  • Description: JumpCloud Directory Insights field resource.application_category preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.application_category
  • Usage: saas_management_application_discover
unmapped.resource.application_name
  • Description: JumpCloud Directory Insights field resource.application_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.application_name
  • Usage: saas_management_account_discover
unmapped.resource.catalog_app_id
  • Description: JumpCloud Directory Insights field resource.catalog_app_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.catalog_app_id
  • Usage: saas_management_application_discover
unmapped.resource.discovery_info.browser_id
  • Description: JumpCloud Directory Insights field resource.discovery_info.browser_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.discovery_info.browser_id
  • Usage: saas_management_account_discover, saas_management_login_event
unmapped.resource.discovery_info.browser_type
  • Description: JumpCloud Directory Insights field resource.discovery_info.browser_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.discovery_info.browser_type
  • Usage: saas_management_account_discover, saas_management_login_event
unmapped.resource.discovery_info.browser_version
  • Description: JumpCloud Directory Insights field resource.discovery_info.browser_version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.discovery_info.browser_version
  • Usage: saas_management_account_discover, saas_management_login_event
unmapped.resource.discovery_info.connector_id
  • Description: JumpCloud Directory Insights field resource.discovery_info.connector_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.discovery_info.connector_id
  • Usage: saas_management_account_discover, saas_management_tenant_discover
unmapped.resource.discovery_info.connector_name
  • Description: JumpCloud Directory Insights field resource.discovery_info.connector_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.discovery_info.connector_name
  • Usage: saas_management_account_discover, saas_management_tenant_discover
unmapped.resource.discovery_info.connector_type
  • Description: JumpCloud Directory Insights field resource.discovery_info.connector_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.discovery_info.connector_type
  • Usage: saas_management_account_discover, saas_management_tenant_discover
unmapped.resource.discovery_info.discovery_type
  • Description: JumpCloud Directory Insights field resource.discovery_info.discovery_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.discovery_info.discovery_type
  • Usage: saas_management_account_discover, saas_management_login_event, saas_management_tenant_discover
unmapped.resource.discovery_info.extension_version
  • Description: JumpCloud Directory Insights field resource.discovery_info.extension_version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.discovery_info.extension_version
  • Usage: saas_management_account_discover, saas_management_login_event
unmapped.resource.discovery_info.source_event_id
  • Description: JumpCloud Directory Insights field resource.discovery_info.source_event_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.discovery_info.source_event_id
  • Usage: saas_management_account_discover
unmapped.resource.discovery_info.user_agent_name
  • Description: JumpCloud Directory Insights field resource.discovery_info.user_agent_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.discovery_info.user_agent_name
  • Usage: saas_management_account_discover
unmapped.resource.discovery_info.user_agent_os
  • Description: JumpCloud Directory Insights field resource.discovery_info.user_agent_os preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.discovery_info.user_agent_os
  • Usage: saas_management_account_discover
unmapped.resource.discovery_info.user_agent_version
  • Description: JumpCloud Directory Insights field resource.discovery_info.user_agent_version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.discovery_info.user_agent_version
  • Usage: saas_management_account_discover
unmapped.resource.login_at
  • Description: JumpCloud Directory Insights field resource.login_at preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.login_at
  • Usage: saas_management_login_event
unmapped.resource.login_type
  • Description: JumpCloud Directory Insights field resource.login_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.login_type
  • Usage: saas_management_login_event
unmapped.resource.sso_provider
  • Description: JumpCloud Directory Insights field resource.sso_provider preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.sso_provider
  • Usage: saas_management_login_event
unmapped.resource.tenant_application_name
  • Description: JumpCloud Directory Insights field resource.tenant_application_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.tenant_application_name
  • Usage: saas_management_tenant_discover
unmapped.timestamp_source
  • Description: JumpCloud Directory Insights field timestamp_source preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: timestamp_source
  • Usage: saas_management_account_discover, saas_management_application_access_restriction_update, saas_management_application_discover, saas_management_application_review, saas_management_application_update, saas_management_enable, saas_management_login_event
unmapped.user_agent
  • Description: JumpCloud Directory Insights field user_agent preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: user_agent
  • Usage: saas_management_application_discover

Slack Integration#

slack_integration · 2 events

Event Category Class Activity Type UID Fields
slack_integration_added Application Activity (6) Application Lifecycle (6002) Install (1) 600201 58
slack_integration_removed Application Activity (6) Application Lifecycle (6002) Remove (2) 600202 58

OCSF field mappings#

Legend

  • Description: what the OCSF field represents (from OCSF schema v1.8.0)
  • Source: raw JumpCloud event field(s) mapped via ${{placeholder}} template
  • Transform: fieldMappings entry applied at runtime (cast, enum, etc.)
  • Literal: static value set in the mapping template
  • Usage: event types in this service that include this field

Core

activity_id
  • Description: The normalized identifier of the activity that triggered the event.
  • Literal: 1, 2
  • Usage: all events in this service
activity_name
  • Description: The event activity name, as defined by the activity_id.
  • Literal: Install, Remove
  • Usage: all events in this service
category_name
  • Description: The event category name, as defined by category_uid value: Discovery.
  • Literal: Application Activity
  • Usage: all events in this service
category_uid
  • Description: The category unique identifier of the event.
  • Literal: 6
  • Usage: all events in this service
class_name
  • Description: The event class name, as defined by class_uid value: User Inventory Info.
  • Literal: Application Lifecycle
  • Usage: all events in this service
class_uid
  • Description: The unique identifier of a class. A class describes the attributes available in an event.
  • Literal: 6002
  • Usage: all events in this service
severity_id
  • Description: OCSF severity identifier for the event.
  • Literal: 1
  • Usage: all events in this service
status_detail
  • Description: The status detail contains additional information about the event/finding outcome.
  • Source: error_message
  • Usage: all events in this service
status_id
  • Description: Normalized status of the activity (1=Success, 2=Failure).
  • Source: success
  • Transform:
  • success → boolean_to_status_id; true→1, false→2 (all events in this service)
  • Usage: all events in this service
time
  • Description: Event time, in epoch milliseconds (OCSF time).
  • Source: timestamp
  • Transform:
  • timestamp → iso8601_to_epoch_millis (all events in this service)
  • Usage: all events in this service
type_uid
  • Description: The event/finding type ID. It identifies the event's semantics and structure. The value is calculated by the logging system as: class_uid * 100 + activity_id.
  • Literal: 600201, 600202
  • Usage: all events in this service

Metadata

metadata.event_code
  • Description: JumpCloud event type code.
  • Source: event_type
  • Usage: all events in this service
metadata.original_time
  • Description: The original event time as reported by the event source. For example, the time in the original format from system event log such as Syslog on Unix/Linux and the System event file on Windows. Omit if event is generated instead of collected via logs.
  • Source: server_timestamp
  • Usage: all events in this service
metadata.processed_time
  • Description: The event processed time, such as an ETL operation.
  • Source: jc_transformation_ts
  • Usage: all events in this service
metadata.product.name
  • Description: Originating JumpCloud service that produced the event.
  • Source: service
  • Usage: all events in this service
metadata.tenant_uid
  • Description: JumpCloud organization (tenant) identifier.
  • Source: organization
  • Usage: all events in this service
metadata.uid
  • Description: Unique event identifier assigned by JumpCloud.
  • Source: id
  • Usage: all events in this service
metadata.version
  • Description: OCSF schema version used for this event.
  • Literal: 1.8.0
  • Usage: all events in this service

Actor

actor.user.email_addr
  • Description: Email address of the actor who initiated the event.
  • Source: initiated_by.email
  • Usage: all events in this service
actor.user.type_id
  • Description: OCSF user type of the actor (1=User, 2=Admin, 3=System, 4=Service).
  • Source: initiated_by.type
  • Transform:
  • initiated_by.type → enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (all events in this service)
  • Usage: all events in this service
actor.user.uid
  • Description: Unique identifier of the actor who initiated the event.
  • Source: initiated_by.id
  • Usage: all events in this service

Observables

observables[].name
  • Description: The full name of the observable attribute. The name is a pointer/reference to an attribute within the OCSF event data. For example: file.name. Array attributes may be represented in one of three ways. For example: resources.uid, resources[].uid, resources[0].uid.
  • Literal: actor.user.email_addr, actor.user.uid
  • Usage: all events in this service
observables[].type_id
  • Description: The observable value type identifier.
  • Literal: 31, 5
  • Usage: all events in this service
observables[].value
  • Description: The value associated with the observable attribute. The meaning of the value depends on the observable type.
    If the name refers to a scalar attribute, then the value is the value of the attribute.
    If the name refers to an object attribute, then the value is not populated.
  • Source: initiated_by.email, initiated_by.id
  • Usage: all events in this service

Other

app.name
  • Description: The name of the product.
  • Source: resource.context.slack_workspace_name
  • Usage: all events in this service
app.uid
  • Description: The unique identifier of the product.
  • Source: resource.id
  • Usage: all events in this service

Unmapped

unmapped.@version
  • Description: JumpCloud Directory Insights field @version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: @version
  • Usage: all events in this service
unmapped.asn.error
  • Description: JumpCloud Directory Insights field asn.error preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: asn.error
  • Usage: all events in this service
unmapped.asn.ip_address
  • Description: JumpCloud Directory Insights field asn.ip_address preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: asn.ip_address
  • Usage: all events in this service
unmapped.asn.network
  • Description: JumpCloud Directory Insights field asn.network preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: asn.network
  • Usage: all events in this service
unmapped.asn.number
  • Description: JumpCloud Directory Insights field asn.number preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: asn.number
  • Usage: all events in this service
unmapped.asn.organization
  • Description: JumpCloud Directory Insights field asn.organization preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: asn.organization
  • Usage: all events in this service
unmapped.client_ip
  • Description: JumpCloud Directory Insights field client_ip preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: client_ip
  • Usage: all events in this service
unmapped.geoip.city
  • Description: JumpCloud Directory Insights field geoip.city preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.city
  • Usage: all events in this service
unmapped.geoip.continent_code
  • Description: JumpCloud Directory Insights field geoip.continent_code preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.continent_code
  • Usage: all events in this service
unmapped.geoip.country_code
  • Description: JumpCloud Directory Insights field geoip.country_code preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.country_code
  • Usage: all events in this service
unmapped.geoip.latitude
  • Description: JumpCloud Directory Insights field geoip.latitude preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.latitude
  • Usage: all events in this service
unmapped.geoip.longitude
  • Description: JumpCloud Directory Insights field geoip.longitude preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.longitude
  • Usage: all events in this service
unmapped.geoip.region_code
  • Description: JumpCloud Directory Insights field geoip.region_code preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.region_code
  • Usage: all events in this service
unmapped.geoip.region_name
  • Description: JumpCloud Directory Insights field geoip.region_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.region_name
  • Usage: all events in this service
unmapped.geoip.timezone
  • Description: JumpCloud Directory Insights field geoip.timezone preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.timezone
  • Usage: all events in this service
unmapped.initiated_by_email_hash
  • Description: JumpCloud Directory Insights field initiated_by_email_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_email_hash
  • Usage: all events in this service
unmapped.initiated_by_id_hash
  • Description: JumpCloud Directory Insights field initiated_by_id_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_id_hash
  • Usage: all events in this service
unmapped.is_out_of_bound
  • Description: JumpCloud Directory Insights field is_out_of_bound preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: is_out_of_bound
  • Usage: all events in this service
unmapped.jc_application_name
  • Description: JumpCloud Directory Insights field jc_application_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_application_name
  • Usage: all events in this service
unmapped.jc_initiated_by_email
  • Description: JumpCloud Directory Insights field jc_initiated_by_email preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_initiated_by_email
  • Usage: all events in this service
unmapped.jc_initiated_by_id
  • Description: JumpCloud Directory Insights field jc_initiated_by_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_initiated_by_id
  • Usage: all events in this service
unmapped.jc_initiated_by_username
  • Description: JumpCloud Directory Insights field jc_initiated_by_username preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_initiated_by_username
  • Usage: all events in this service
unmapped.jc_organization_name
  • Description: JumpCloud Directory Insights field jc_organization_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_organization_name
  • Usage: all events in this service
unmapped.jc_provider_id
  • Description: JumpCloud Directory Insights field jc_provider_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_provider_id
  • Usage: all events in this service
unmapped.jc_system_display_name
  • Description: JumpCloud Directory Insights field jc_system_display_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_system_display_name
  • Usage: all events in this service
unmapped.jc_system_hostname
  • Description: JumpCloud Directory Insights field jc_system_hostname preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_system_hostname
  • Usage: all events in this service
unmapped.resource.type
  • Description: JumpCloud Directory Insights field resource.type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.type
  • Usage: all events in this service
unmapped.resource_id_hash
  • Description: JumpCloud Directory Insights field resource_id_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource_id_hash
  • Usage: all events in this service
unmapped.slack_workspace_domain
  • Description: JumpCloud Directory Insights field slack_workspace_domain preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.slack_workspace_domain
  • Usage: all events in this service
unmapped.slack_workspace_id
  • Description: JumpCloud Directory Insights field slack_workspace_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.context.slack_workspace_id
  • Usage: all events in this service
unmapped.timestamp_source
  • Description: JumpCloud Directory Insights field timestamp_source preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: timestamp_source
  • Usage: all events in this service
unmapped.user_agent
  • Description: JumpCloud Directory Insights field user_agent preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: user_agent
  • Usage: all events in this service

Software#

software · 7 events

Event Category Class Activity Type UID Fields
software_add Application Activity (6) Application Lifecycle (6002) Install (1) 600201 72
software_add_request Identity & Access Management (3) Entity Management (3004) Create (1) 300401 42
software_change Application Activity (6) Application Lifecycle (6002) Update (8) 600208 62
software_change_request Identity & Access Management (3) Entity Management (3004) Update (3) 300403 43
software_remove Application Activity (6) Application Lifecycle (6002) Remove (2) 600202 65
software_remove_request Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 42
software_status_update Application Activity (6) Application Lifecycle (6002) Update (8) 600208 37

OCSF field mappings#

Legend

  • Description: what the OCSF field represents (from OCSF schema v1.8.0)
  • Source: raw JumpCloud event field(s) mapped via ${{placeholder}} template
  • Transform: fieldMappings entry applied at runtime (cast, enum, etc.)
  • Literal: static value set in the mapping template
  • Usage: event types in this service that include this field

Core

activity_id
  • Description: The normalized identifier of the activity that triggered the event.
  • Literal: 1, 2, 3, 4, 8
  • Usage: all events in this service
activity_name
  • Description: The event activity name, as defined by the activity_id.
  • Literal: Create, Delete, Install, Remove, Update
  • Usage: all events in this service
category_name
  • Description: The event category name, as defined by category_uid value: Discovery.
  • Literal: Application Activity, Identity & Access Management
  • Usage: all events in this service
category_uid
  • Description: The category unique identifier of the event.
  • Literal: 3, 6
  • Usage: all events in this service
class_name
  • Description: The event class name, as defined by class_uid value: User Inventory Info.
  • Literal: Application Lifecycle, Entity Management
  • Usage: all events in this service
class_uid
  • Description: The unique identifier of a class. A class describes the attributes available in an event.
  • Literal: 3004, 6002
  • Usage: all events in this service
severity_id
  • Description: OCSF severity identifier for the event.
  • Literal: 1
  • Usage: all events in this service
status_detail
  • Description: The status detail contains additional information about the event/finding outcome.
  • Source: error_message
  • Usage: software_add, software_change, software_remove, software_status_update
status_id
  • Description: Normalized status of the activity (1=Success, 2=Failure).
  • Source: success
  • Transform:
  • success → boolean_to_status_id; true→1, false→2 (all events in this service)
  • Usage: all events in this service
time
  • Description: Event time, in epoch milliseconds (OCSF time).
  • Source: timestamp
  • Transform:
  • timestamp → iso8601_to_epoch_millis (all events in this service)
  • Usage: all events in this service
type_uid
  • Description: The event/finding type ID. It identifies the event's semantics and structure. The value is calculated by the logging system as: class_uid * 100 + activity_id.
  • Literal: 300401, 300403, 300404, 600201, 600202, 600208
  • Usage: all events in this service

Metadata

metadata.event_code
  • Description: JumpCloud event type code.
  • Source: event_type
  • Usage: all events in this service
metadata.original_time
  • Description: The original event time as reported by the event source. For example, the time in the original format from system event log such as Syslog on Unix/Linux and the System event file on Windows. Omit if event is generated instead of collected via logs.
  • Source: server_timestamp
  • Usage: all events in this service
metadata.product.name
  • Description: Originating JumpCloud service that produced the event.
  • Source: service
  • Usage: all events in this service
metadata.tenant_uid
  • Description: JumpCloud organization (tenant) identifier.
  • Source: organization
  • Usage: all events in this service
metadata.uid
  • Description: Unique event identifier assigned by JumpCloud.
  • Source: id
  • Usage: all events in this service
metadata.version
  • Description: OCSF schema version used for this event.
  • Literal: 1.8.0
  • Usage: all events in this service

Actor

actor.user.email_addr
  • Description: Email address of the actor who initiated the event.
  • Source: initiated_by.email
  • Usage: software_add, software_add_request, software_change, software_change_request, software_remove, software_remove_request
actor.user.type_id
  • Description: OCSF user type of the actor (1=User, 2=Admin, 3=System, 4=Service).
  • Source: initiated_by.type
  • Transform:
  • initiated_by.type → enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (software_add, software_add_request, software_change, software_change_request, software_remove, software_remove_request)
  • Usage: software_add, software_add_request, software_change, software_change_request, software_remove, software_remove_request
actor.user.uid
  • Description: Unique identifier of the actor who initiated the event.
  • Source: initiated_by.id
  • Usage: software_add, software_add_request, software_change, software_change_request, software_remove, software_remove_request

Entity

entity.data.app_management_source
  • Description: JumpCloud extension data on the managed entity: app_management_source.
  • Source: app_management_source
  • Usage: software_add_request, software_change_request, software_remove_request
entity.data.application_display_name
  • Description: JumpCloud extension data on the managed entity: application_display_name.
  • Source: application.display_name
  • Usage: software_add_request, software_change_request, software_remove_request
entity.data.application_id
  • Description: JumpCloud extension data on the managed entity: application_id.
  • Source: application.id
  • Usage: software_add_request, software_change_request, software_remove_request
entity.data.changes
  • Description: JumpCloud extension data on the managed entity: changes.
  • Source: changes
  • Usage: software_change_request
entity.data.package_manager
  • Description: JumpCloud extension data on the managed entity: package_manager.
  • Source: application.package_manager
  • Usage: software_add_request, software_change_request, software_remove_request
entity.name
  • Description: The name of the managed entity. It should match the name of the specific entity object's name if populated, or the name of the managed entity if the type_id is 'Other'.
  • Source: resource.display_name
  • Usage: software_add_request, software_change_request, software_remove_request
entity.type
  • Description: The managed entity type. For example: Policy, User, Organization, Device.
  • Source: resource.type
  • Usage: software_add_request, software_change_request, software_remove_request
entity.uid
  • Description: The identifier of the managed entity. It should match the uid of the specific entity's object UID if populated, or the source specific ID if the type_id is 'Other'.
  • Source: resource.id
  • Usage: software_add_request, software_change_request, software_remove_request

Src Endpoint

src_endpoint.ip
  • Description: Source IP address the request originated from.
  • Source: client_ip
  • Usage: software_add_request, software_change_request, software_remove_request
src_endpoint.location.continent
  • Description: The name of the continent.
  • Source: geoip.continent_code
  • Usage: software_add_request, software_change_request, software_remove_request
src_endpoint.location.country
  • Description: The ISO 3166-1 Alpha-2 country code.

    Note: The two letter country code should be capitalized. For example: US or CA.

  • Source: geoip.country_code
  • Usage: software_add_request, software_change_request, software_remove_request
src_endpoint.location.lat
  • Description: The geographical Latitude coordinate represented in Decimal Degrees (DD). For example: 42.361145.
  • Source: geoip.latitude
  • Transform:
  • geoip.latitude → double (software_add_request, software_change_request, software_remove_request)
  • Usage: software_add_request, software_change_request, software_remove_request
src_endpoint.location.long
  • Description: The geographical Longitude coordinate represented in Decimal Degrees (DD). For example: -71.057083.
  • Source: geoip.longitude
  • Transform:
  • geoip.longitude → double (software_add_request, software_change_request, software_remove_request)
  • Usage: software_add_request, software_change_request, software_remove_request
src_endpoint.location.region
  • Description: The alphanumeric code that identifies the principal subdivision (e.g. province or state) of the country. For example, 'CH-VD' for the Canton of Vaud, Switzerland
  • Source: geoip.region_code
  • Usage: software_add_request, software_change_request, software_remove_request

Observables

observables[].name
  • Description: The full name of the observable attribute. The name is a pointer/reference to an attribute within the OCSF event data. For example: file.name. Array attributes may be represented in one of three ways. For example: resources.uid, resources[].uid, resources[0].uid.
  • Literal: actor.user.email_addr, actor.user.uid, src_endpoint.ip, src_endpoint.location.country
  • Usage: software_add, software_add_request, software_change, software_change_request, software_remove, software_remove_request
observables[].type_id
  • Description: The observable value type identifier.
  • Literal: 14, 2, 31, 5
  • Usage: software_add, software_add_request, software_change, software_change_request, software_remove, software_remove_request
observables[].value
  • Description: The value associated with the observable attribute. The meaning of the value depends on the observable type.
    If the name refers to a scalar attribute, then the value is the value of the attribute.
    If the name refers to an object attribute, then the value is not populated.
  • Source: client_ip, geoip.country_code, initiated_by.email, initiated_by.id
  • Usage: software_add, software_add_request, software_change, software_change_request, software_remove, software_remove_request

Other

app.name
  • Description: The name of the product.
  • Source: application.display_name, application.name, resource.app_name
  • Usage: software_add, software_change, software_remove, software_status_update
app.path
  • Description: The installation path of the product.
  • Source: application.path
  • Usage: software_add, software_remove
app.uid
  • Description: The unique identifier of the product.
  • Source: resource.app_id, resource.id
  • Usage: software_add, software_change, software_remove, software_status_update
app.vendor_name
  • Description: The name of the vendor of the product.
  • Source: app_management_source, application.publisher
  • Usage: software_add, software_remove, software_status_update
app.version
  • Description: The version of the product, as defined by the event source. For example: 2013.1.3-beta.
  • Source: application.version
  • Usage: software_add, software_remove

Unmapped

unmapped.@timestamp
  • Description: JumpCloud Directory Insights field @timestamp preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: @timestamp
  • Usage: software_add_request, software_change_request, software_remove_request
unmapped.@version
  • Description: JumpCloud Directory Insights field @version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: @version
  • Usage: all events in this service
unmapped.application.package_manager
  • Description: JumpCloud Directory Insights field application.package_manager preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: application.package_manager
  • Usage: software_add, software_change, software_remove
unmapped.application.uninstall_string
  • Description: JumpCloud Directory Insights field application.uninstall_string preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: application.uninstall_string
  • Usage: software_add, software_remove
unmapped.application_id_hash
  • Description: JumpCloud Directory Insights field application_id_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: application_id_hash
  • Usage: software_add, software_remove
unmapped.asn.error
  • Description: JumpCloud Directory Insights field asn.error preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: asn.error
  • Usage: software_add, software_change
unmapped.asn.ip_address
  • Description: JumpCloud Directory Insights field asn.ip_address preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: asn.ip_address
  • Usage: software_add, software_change
unmapped.asn.network
  • Description: JumpCloud Directory Insights field asn.network preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: asn.network
  • Usage: software_add, software_change, software_remove
unmapped.asn.number
  • Description: JumpCloud Directory Insights field asn.number preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: asn.number
  • Usage: software_add, software_change, software_remove
unmapped.asn.organization
  • Description: JumpCloud Directory Insights field asn.organization preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: asn.organization
  • Usage: software_add, software_change, software_remove
unmapped.changes
  • Description: JumpCloud Directory Insights field changes preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes
  • Usage: software_add, software_remove
unmapped.changes.field
  • Description: JumpCloud Directory Insights field changes.field preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.field
  • Usage: software_change, software_status_update
unmapped.changes.from
  • Description: JumpCloud Directory Insights field changes.from preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.from
  • Usage: software_change, software_status_update
unmapped.changes.to
  • Description: JumpCloud Directory Insights field changes.to preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to
  • Usage: software_change, software_status_update
unmapped.client_ip
  • Description: JumpCloud Directory Insights field client_ip preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: client_ip
  • Usage: software_add, software_change, software_remove, software_status_update
unmapped.file_input_timestamp
  • Description: JumpCloud Directory Insights field file_input_timestamp preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: file_input_timestamp
  • Usage: software_add, software_add_request, software_change_request, software_remove_request
unmapped.geoip.city
  • Description: JumpCloud Directory Insights field geoip.city preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.city
  • Usage: software_add, software_change, software_remove
unmapped.geoip.continent_code
  • Description: JumpCloud Directory Insights field geoip.continent_code preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.continent_code
  • Usage: software_add, software_change, software_remove
unmapped.geoip.country_code
  • Description: JumpCloud Directory Insights field geoip.country_code preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.country_code
  • Usage: software_add, software_change, software_remove
unmapped.geoip.latitude
  • Description: JumpCloud Directory Insights field geoip.latitude preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.latitude
  • Usage: software_add, software_change, software_remove
unmapped.geoip.longitude
  • Description: JumpCloud Directory Insights field geoip.longitude preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.longitude
  • Usage: software_add, software_change, software_remove
unmapped.geoip.region_code
  • Description: JumpCloud Directory Insights field geoip.region_code preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.region_code
  • Usage: software_add, software_change, software_remove
unmapped.geoip.region_name
  • Description: JumpCloud Directory Insights field geoip.region_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.region_name
  • Usage: software_add, software_add_request, software_change, software_change_request, software_remove, software_remove_request
unmapped.geoip.timezone
  • Description: JumpCloud Directory Insights field geoip.timezone preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.timezone
  • Usage: software_add, software_add_request, software_change, software_change_request, software_remove, software_remove_request
unmapped.initiated_by
  • Description: JumpCloud Directory Insights field initiated_by preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by
  • Usage: software_status_update
unmapped.initiated_by_email_hash
  • Description: JumpCloud Directory Insights field initiated_by_email_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_email_hash
  • Usage: software_add, software_change, software_remove
unmapped.initiated_by_id_hash
  • Description: JumpCloud Directory Insights field initiated_by_id_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_id_hash
  • Usage: software_add, software_change, software_remove
unmapped.is_out_of_bound
  • Description: JumpCloud Directory Insights field is_out_of_bound preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: is_out_of_bound
  • Usage: software_add, software_change, software_remove, software_status_update
unmapped.jc_application_name
  • Description: JumpCloud Directory Insights field jc_application_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_application_name
  • Usage: software_add, software_change, software_remove, software_status_update
unmapped.jc_initiated_by_email
  • Description: JumpCloud Directory Insights field jc_initiated_by_email preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_initiated_by_email
  • Usage: software_add
unmapped.jc_initiated_by_username
  • Description: JumpCloud Directory Insights field jc_initiated_by_username preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_initiated_by_username
  • Usage: software_add
unmapped.jc_organization_name
  • Description: JumpCloud Directory Insights field jc_organization_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_organization_name
  • Usage: software_add
unmapped.jc_provider_id
  • Description: JumpCloud Directory Insights field jc_provider_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_provider_id
  • Usage: software_add
unmapped.jc_transformation_ts
  • Description: JumpCloud Directory Insights field jc_transformation_ts preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_transformation_ts
  • Usage: software_add, software_change, software_remove, software_status_update
unmapped.provider
  • Description: JumpCloud Directory Insights field provider preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: provider
  • Usage: software_add, software_change, software_remove
unmapped.resource.application_type
  • Description: JumpCloud Directory Insights field resource.application_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.application_type
  • Usage: software_add, software_change, software_remove
unmapped.resource.display_name
  • Description: JumpCloud Directory Insights field resource.display_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.display_name
  • Usage: software_add, software_change, software_remove
unmapped.resource.enterprise_id
  • Description: JumpCloud Directory Insights field resource.enterprise_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.enterprise_id
  • Usage: software_add, software_change, software_remove
unmapped.resource.id
  • Description: JumpCloud Directory Insights field resource.id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.id
  • Usage: software_status_update
unmapped.resource.install_type
  • Description: JumpCloud Directory Insights field resource.install_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.install_type
  • Usage: software_add, software_change, software_remove
unmapped.resource.managed_configuration
  • Description: JumpCloud Directory Insights field resource.managed_configuration preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.managed_configuration
  • Usage: software_add, software_change, software_remove
unmapped.resource.package_manager
  • Description: JumpCloud Directory Insights field resource.package_manager preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.package_manager
  • Usage: software_add, software_change, software_remove
unmapped.resource.runtime_permissions
  • Description: JumpCloud Directory Insights field resource.runtime_permissions preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.runtime_permissions
  • Usage: software_add, software_change, software_remove
unmapped.resource.system_id
  • Description: JumpCloud Directory Insights field resource.system_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.system_id
  • Usage: software_status_update
unmapped.resource.type
  • Description: JumpCloud Directory Insights field resource.type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.type
  • Usage: software_add, software_change, software_remove, software_status_update
unmapped.resource.update_mode
  • Description: JumpCloud Directory Insights field resource.update_mode preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.update_mode
  • Usage: software_add, software_change, software_remove
unmapped.resource_id_hash
  • Description: JumpCloud Directory Insights field resource_id_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource_id_hash
  • Usage: software_add, software_change, software_remove, software_status_update
unmapped.state
  • Description: JumpCloud Directory Insights field state preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: state
  • Usage: software_status_update
unmapped.system.hostname
  • Description: JumpCloud Directory Insights field system.hostname preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: system.hostname
  • Usage: software_add, software_remove
unmapped.system.id
  • Description: JumpCloud Directory Insights field system.id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: system.id
  • Usage: software_add, software_remove
unmapped.tags
  • Description: JumpCloud Directory Insights field tags preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: tags
  • Usage: software_add_request, software_change_request, software_remove_request
unmapped.timestamp_source
  • Description: JumpCloud Directory Insights field timestamp_source preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: timestamp_source
  • Usage: all events in this service
unmapped.update_trigger
  • Description: JumpCloud Directory Insights field update_trigger preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: update_trigger
  • Usage: software_status_update
unmapped.user_agent
  • Description: JumpCloud Directory Insights field user_agent preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: user_agent
  • Usage: software_add, software_change, software_remove, software_status_update

SSO#

sso · 1 event

Event Category Class Activity Type UID Fields
sso_auth Identity & Access Management (3) Authentication (3002) Logon (1) 300201 67

OCSF field mappings#

Legend

  • Description: what the OCSF field represents (from OCSF schema v1.8.0)
  • Source: raw JumpCloud event field(s) mapped via ${{placeholder}} template
  • Transform: fieldMappings entry applied at runtime (cast, enum, etc.)
  • Literal: static value set in the mapping template
  • Usage: event types in this service that include this field

Core

activity_id
  • Description: The normalized identifier of the activity that triggered the event.
  • Literal: 1
  • Usage: all events in this service
activity_name
  • Description: The event activity name, as defined by the activity_id.
  • Literal: Logon
  • Usage: all events in this service
category_name
  • Description: The event category name, as defined by category_uid value: Discovery.
  • Literal: Identity & Access Management
  • Usage: all events in this service
category_uid
  • Description: The category unique identifier of the event.
  • Literal: 3
  • Usage: all events in this service
class_name
  • Description: The event class name, as defined by class_uid value: User Inventory Info.
  • Literal: Authentication
  • Usage: all events in this service
class_uid
  • Description: The unique identifier of a class. A class describes the attributes available in an event.
  • Literal: 3002
  • Usage: all events in this service
severity_id
  • Description: OCSF severity identifier for the event.
  • Literal: 1
  • Usage: all events in this service
status_detail
  • Description: The status detail contains additional information about the event/finding outcome.
  • Source: error_message
  • Usage: all events in this service
status_id
  • Description: Normalized status of the activity (1=Success, 2=Failure).
  • Source: sso_token_success
  • Transform:
  • sso_token_success → boolean_to_status_id; true→1, false→2 (all events in this service)
  • Usage: all events in this service
time
  • Description: Event time, in epoch milliseconds (OCSF time).
  • Source: timestamp
  • Transform:
  • timestamp → iso8601_to_epoch_millis (all events in this service)
  • Usage: all events in this service
type_uid
  • Description: The event/finding type ID. It identifies the event's semantics and structure. The value is calculated by the logging system as: class_uid * 100 + activity_id.
  • Literal: 300201
  • Usage: all events in this service

Metadata

metadata.event_code
  • Description: JumpCloud event type code.
  • Source: event_type
  • Usage: all events in this service
metadata.original_time
  • Description: The original event time as reported by the event source. For example, the time in the original format from system event log such as Syslog on Unix/Linux and the System event file on Windows. Omit if event is generated instead of collected via logs.
  • Source: server_timestamp
  • Usage: all events in this service
metadata.product.name
  • Description: Originating JumpCloud service that produced the event.
  • Source: service
  • Usage: all events in this service
metadata.tenant_uid
  • Description: JumpCloud organization (tenant) identifier.
  • Source: organization
  • Usage: all events in this service
metadata.uid
  • Description: Unique event identifier assigned by JumpCloud.
  • Source: id
  • Usage: all events in this service
metadata.version
  • Description: OCSF schema version used for this event.
  • Literal: 1.8.0
  • Usage: all events in this service

Actor

actor.user.type_id
  • Description: OCSF user type of the actor (1=User, 2=Admin, 3=System, 4=Service).
  • Source: initiated_by.type
  • Transform:
  • initiated_by.type → enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (all events in this service)
  • Usage: all events in this service
actor.user.uid
  • Description: Unique identifier of the actor who initiated the event.
  • Source: initiated_by.id
  • Usage: all events in this service

User

user.email_addr
  • Description: Email address of the user associated with the event.
  • Source: initiated_by.username
  • Usage: all events in this service

Src Endpoint

src_endpoint.ip
  • Description: Source IP address the request originated from.
  • Source: client_ip
  • Usage: all events in this service
src_endpoint.location.continent
  • Description: The name of the continent.
  • Source: geoip.continent_code
  • Usage: all events in this service
src_endpoint.location.country
  • Description: The ISO 3166-1 Alpha-2 country code.

    Note: The two letter country code should be capitalized. For example: US or CA.

  • Source: geoip.country_code
  • Usage: all events in this service
src_endpoint.location.lat
  • Description: The geographical Latitude coordinate represented in Decimal Degrees (DD). For example: 42.361145.
  • Source: geoip.latitude
  • Transform:
  • geoip.latitude → double (all events in this service)
  • Usage: all events in this service
src_endpoint.location.long
  • Description: The geographical Longitude coordinate represented in Decimal Degrees (DD). For example: -71.057083.
  • Source: geoip.longitude
  • Transform:
  • geoip.longitude → double (all events in this service)
  • Usage: all events in this service
src_endpoint.location.region
  • Description: The alphanumeric code that identifies the principal subdivision (e.g. province or state) of the country. For example, 'CH-VD' for the Canton of Vaud, Switzerland
  • Source: geoip.region_code
  • Usage: all events in this service

Observables

observables[].name
  • Description: The full name of the observable attribute. The name is a pointer/reference to an attribute within the OCSF event data. For example: file.name. Array attributes may be represented in one of three ways. For example: resources.uid, resources[].uid, resources[0].uid.
  • Literal: actor.user.uid, src_endpoint.ip, src_endpoint.location.country, user.email_addr
  • Usage: all events in this service
observables[].type_id
  • Description: The observable value type identifier.
  • Literal: 14, 2, 31, 5
  • Usage: all events in this service
observables[].value
  • Description: The value associated with the observable attribute. The meaning of the value depends on the observable type.
    If the name refers to a scalar attribute, then the value is the value of the attribute.
    If the name refers to an object attribute, then the value is not populated.
  • Source: client_ip, geoip.country_code, initiated_by.id, initiated_by.username
  • Usage: all events in this service

Other

auth_protocol
  • Description: The authentication protocol as defined by the caption of auth_protocol_id. In the case of Other, it is defined by the event source.
  • Source: application.sso_type
  • Usage: all events in this service
is_mfa
  • Description: Indicates whether Multi Factor Authentication was used during authentication.
  • Source: mfa
  • Usage: all events in this service
service.name
  • Description: The name of the service.
  • Source: application.display_label
  • Usage: all events in this service
service.uid
  • Description: The unique identifier of the service.
  • Source: application.id
  • Usage: all events in this service

Unmapped

unmapped.@timestamp
  • Description: JumpCloud Directory Insights field @timestamp preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: @timestamp
  • Usage: all events in this service
unmapped.@version
  • Description: JumpCloud Directory Insights field @version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: @version
  • Usage: all events in this service
unmapped.application.name
  • Description: JumpCloud Directory Insights field application.name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: application.name
  • Usage: all events in this service
unmapped.application.sso_url
  • Description: JumpCloud Directory Insights field application.sso_url preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: application.sso_url
  • Usage: all events in this service
unmapped.auth_context.auth_methods.totp.success
  • Description: JumpCloud Directory Insights field auth_context.auth_methods.totp.success preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: auth_context.auth_methods.totp.success
  • Usage: all events in this service
unmapped.auth_context.policies_applied.id
  • Description: JumpCloud Directory Insights field auth_context.policies_applied.id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: auth_context.policies_applied.id
  • Usage: all events in this service
unmapped.auth_context.policies_applied.metadata.action
  • Description: JumpCloud Directory Insights field auth_context.policies_applied.metadata.action preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: auth_context.policies_applied.metadata.action
  • Usage: all events in this service
unmapped.auth_context.policies_applied.metadata.conditions
  • Description: JumpCloud Directory Insights field auth_context.policies_applied.metadata.conditions preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: auth_context.policies_applied.metadata.conditions
  • Usage: all events in this service
unmapped.auth_context.policies_applied.metadata.resource_type
  • Description: JumpCloud Directory Insights field auth_context.policies_applied.metadata.resource_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: auth_context.policies_applied.metadata.resource_type
  • Usage: all events in this service
unmapped.auth_context.policies_applied.metadata.targets
  • Description: JumpCloud Directory Insights field auth_context.policies_applied.metadata.targets preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: auth_context.policies_applied.metadata.targets
  • Usage: all events in this service
unmapped.auth_context.policies_applied.name
  • Description: JumpCloud Directory Insights field auth_context.policies_applied.name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: auth_context.policies_applied.name
  • Usage: all events in this service
unmapped.file_input_timestamp
  • Description: JumpCloud Directory Insights field file_input_timestamp preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: file_input_timestamp
  • Usage: all events in this service
unmapped.geoip.region_name
  • Description: JumpCloud Directory Insights field geoip.region_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.region_name
  • Usage: all events in this service
unmapped.geoip.timezone
  • Description: JumpCloud Directory Insights field geoip.timezone preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.timezone
  • Usage: all events in this service
unmapped.idp_initiated
  • Description: JumpCloud Directory Insights field idp_initiated preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: idp_initiated
  • Usage: all events in this service
unmapped.initiated_by.administrator
  • Description: JumpCloud Directory Insights field initiated_by.administrator preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by.administrator
  • Usage: all events in this service
unmapped.mfa_meta.type
  • Description: JumpCloud Directory Insights field mfa_meta.type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: mfa_meta.type
  • Usage: all events in this service
unmapped.provider
  • Description: JumpCloud Directory Insights field provider preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: provider
  • Usage: all events in this service
unmapped.tags
  • Description: JumpCloud Directory Insights field tags preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: tags
  • Usage: all events in this service
unmapped.target_resource.type
  • Description: JumpCloud Directory Insights field target_resource.type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: target_resource.type
  • Usage: all events in this service
unmapped.timestamp_source
  • Description: JumpCloud Directory Insights field timestamp_source preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: timestamp_source
  • Usage: all events in this service
unmapped.useragent.device
  • Description: JumpCloud Directory Insights field useragent.device preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.device
  • Usage: all events in this service
unmapped.useragent.major
  • Description: JumpCloud Directory Insights field useragent.major preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.major
  • Usage: all events in this service
unmapped.useragent.minor
  • Description: JumpCloud Directory Insights field useragent.minor preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.minor
  • Usage: all events in this service
unmapped.useragent.name
  • Description: JumpCloud Directory Insights field useragent.name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.name
  • Usage: all events in this service
unmapped.useragent.os
  • Description: JumpCloud Directory Insights field useragent.os preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os
  • Usage: all events in this service
unmapped.useragent.os_full
  • Description: JumpCloud Directory Insights field useragent.os_full preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_full
  • Usage: all events in this service
unmapped.useragent.os_major
  • Description: JumpCloud Directory Insights field useragent.os_major preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_major
  • Usage: all events in this service
unmapped.useragent.os_minor
  • Description: JumpCloud Directory Insights field useragent.os_minor preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_minor
  • Usage: all events in this service
unmapped.useragent.os_name
  • Description: JumpCloud Directory Insights field useragent.os_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_name
  • Usage: all events in this service
unmapped.useragent.os_patch
  • Description: JumpCloud Directory Insights field useragent.os_patch preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_patch
  • Usage: all events in this service
unmapped.useragent.os_version
  • Description: JumpCloud Directory Insights field useragent.os_version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_version
  • Usage: all events in this service
unmapped.useragent.patch
  • Description: JumpCloud Directory Insights field useragent.patch preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.patch
  • Usage: all events in this service
unmapped.useragent.version
  • Description: JumpCloud Directory Insights field useragent.version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.version
  • Usage: all events in this service

Systems#

systems · 51 events

Event Category Class Activity Type UID Fields
device_command Identity & Access Management (3) Entity Management (3004) Update (3) 300403 59
google_emm_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 50
google_emm_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 48
google_emm_enrollment_token_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 55
google_emm_enrollment_token_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 56
google_emm_enterprise_upgrade Identity & Access Management (3) Entity Management (3004) Update (3) 300403 47
google_emm_lost_mode_disabled Identity & Access Management (3) Entity Management (3004) Disable (9) 300409 34
google_emm_lost_mode_enabled Identity & Access Management (3) Entity Management (3004) Enable (8) 300408 34
google_emm_lost_mode_outgoing_phone_call Identity & Access Management (3) Entity Management (3004) Update (3) 300403 38
google_emm_patch Identity & Access Management (3) Entity Management (3004) Update (3) 300403 49
google_emm_policy_bind Identity & Access Management (3) Entity Management (3004) Update (3) 300403 29
google_emm_policy_unbind Identity & Access Management (3) Entity Management (3004) Update (3) 300403 29
google_emm_reset_password_recently Identity & Access Management (3) Entity Management (3004) Update (3) 300403 34
google_emm_stop_lost_mode_user_attempt Identity & Access Management (3) Entity Management (3004) Update (3) 300403 38
google_emm_sw_app_bind Application Activity (6) Application Lifecycle (6002) Install (1) 600201 29
google_emm_sw_app_unbind Application Activity (6) Application Lifecycle (6002) Remove (2) 600202 30
google_emm_user_exit_lost_mode_recently Identity & Access Management (3) Entity Management (3004) Update (3) 300403 36
linux_commands_devicelock Identity & Access Management (3) Entity Management (3004) Update (3) 300403 58
linux_commands_erasedevice Identity & Access Management (3) Entity Management (3004) Update (3) 300403 66
linux_commands_restartdevice Identity & Access Management (3) Entity Management (3004) Update (3) 300403 62
linux_commands_shutdowndevice Identity & Access Management (3) Entity Management (3004) Update (3) 300403 61
login_attempt Identity & Access Management (3) Authentication (3002) Logon (1) 300201 66
os_major_rollback Identity & Access Management (3) Entity Management (3004) Update (3) 300403 32
os_major_upgrade Identity & Access Management (3) Entity Management (3004) Update (3) 300403 53
os_minor_rollback Identity & Access Management (3) Entity Management (3004) Update (3) 300403 44
os_minor_upgrade Identity & Access Management (3) Entity Management (3004) Update (3) 300403 53
recovery_lock_auto_rotation_success System Activity (1) Scheduled Job Activity (1006) Start (6) 100606 44
recovery_lock_cleared_success System Activity (1) Scheduled Job Activity (1006) Start (6) 100606 38
recovery_lock_password_viewed Identity & Access Management (3) Entity Management (3004) Read (2) 300402 47
recovery_lock_set_success System Activity (1) Scheduled Job Activity (1006) Start (6) 100606 36
remote_assist_settings Identity & Access Management (3) Entity Management (3004) Update (3) 300403 57
remote_session_end Identity & Access Management (3) Entity Management (3004) Deactivate (11) 300411 52
remote_session_feedback Identity & Access Management (3) Entity Management (3004) Update (3) 300403 58
remote_session_join Identity & Access Management (3) Entity Management (3004) Read (2) 300402 65
remote_session_launch_token Identity & Access Management (3) Entity Management (3004) Create (1) 300401 65
remote_session_rejoin Identity & Access Management (3) Entity Management (3004) Resume (13) 300413 59
remote_session_start Identity & Access Management (3) Entity Management (3004) Create (1) 300401 51
system_admin_grant Identity & Access Management (3) User Access Management (3005) Assign Privileges (1) 300501 52
system_admin_revoke Identity & Access Management (3) User Access Management (3005) Revoke Privileges (2) 300502 52
system_fde_key_decrypt Identity & Access Management (3) Entity Management (3004) Read (2) 300402 64
system_fde_key_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 44
system_group_admin_grant Identity & Access Management (3) Group Management (3006) Assign Privileges (1) 300601 58
system_group_admin_revoke Identity & Access Management (3) Group Management (3006) Revoke Privileges (2) 300602 66
user_lockout Identity & Access Management (3) Account Change (3001) Lock (9) 300109 51
user_password_change Identity & Access Management (3) Account Change (3001) Password Change (3) 300103 73
windows_commands_devicelock Identity & Access Management (3) Entity Management (3004) Update (3) 300403 66
windows_commands_erasedevice Identity & Access Management (3) Entity Management (3004) Update (3) 300403 61
windows_commands_restartdevice Identity & Access Management (3) Entity Management (3004) Update (3) 300403 63
windows_commands_shutdowndevice Identity & Access Management (3) Entity Management (3004) Update (3) 300403 61
windows_patch_export Identity & Access Management (3) Entity Management (3004) Read (2) 300402 45
windows_patch_install Identity & Access Management (3) Entity Management (3004) Update (3) 300403 48

OCSF field mappings#

Legend

  • Description: what the OCSF field represents (from OCSF schema v1.8.0)
  • Source: raw JumpCloud event field(s) mapped via ${{placeholder}} template
  • Transform: fieldMappings entry applied at runtime (cast, enum, etc.)
  • Literal: static value set in the mapping template
  • Usage: event types in this service that include this field

Core

activity_id
  • Description: The normalized identifier of the activity that triggered the event.
  • Literal: 1, 11, 13, 2, 3, 4, 6, 8, 9
  • Usage: all events in this service
activity_name
  • Description: The event activity name, as defined by the activity_id.
  • Literal: Assign Privileges, Create, Deactivate, Delete, Disable, Enable, Install, Lock, Logon, Password Change, Read, Remove, Resume, Revoke Privileges, Start, Update
  • Usage: all events in this service
category_name
  • Description: The event category name, as defined by category_uid value: Discovery.
  • Literal: Application Activity, Identity & Access Management, System Activity
  • Usage: all events in this service
category_uid
  • Description: The category unique identifier of the event.
  • Literal: 1, 3, 6
  • Usage: all events in this service
class_name
  • Description: The event class name, as defined by class_uid value: User Inventory Info.
  • Literal: Account Change, Application Lifecycle, Authentication, Entity Management, Group Management, Scheduled Job Activity, User Access Management
  • Usage: all events in this service
class_uid
  • Description: The unique identifier of a class. A class describes the attributes available in an event.
  • Literal: 1006, 3001, 3002, 3004, 3005, 3006, 6002
  • Usage: all events in this service
message
  • Description: The description of the event/finding, as defined by the source.
  • Source: message, result
  • Usage: 11 events: login_attempt, recovery_lock_auto_rotation_success, recovery_lock_cleared_success, recovery_lock_password_viewed, recovery_lock_set_success, remote_session_end, remote_session_feedback, remote_session_join, ... (+3 more)
severity_id
  • Description: OCSF severity identifier for the event.
  • Literal: 1
  • Usage: all events in this service
status_detail
  • Description: The status detail contains additional information about the event/finding outcome.
  • Source: error_message
  • Usage: 44 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_lost_mode_disabled, google_emm_lost_mode_enabled, ... (+36 more)
status_id
  • Description: Normalized status of the activity (1=Success, 2=Failure).
  • Source: success
  • Transform:
  • success → boolean_to_status_id; true→1, false→2 (48 events (missing: os_major_rollback, system_admin_grant, system_admin_revoke))
  • Usage: 48 events (missing: os_major_rollback, system_admin_grant, system_admin_revoke)
time
  • Description: Event time, in epoch milliseconds (OCSF time).
  • Source: timestamp
  • Transform:
  • timestamp → iso8601_to_epoch_millis (all events in this service)
  • Usage: all events in this service
type_uid
  • Description: The event/finding type ID. It identifies the event's semantics and structure. The value is calculated by the logging system as: class_uid * 100 + activity_id.
  • Literal: 100606, 300103, 300109, 300201, 300401, 300402, 300403, 300404, 300408, 300409, 300411, 300413, 300501, 300502, 300601, 300602, 600201, 600202
  • Usage: all events in this service

Metadata

metadata.event_code
  • Description: JumpCloud event type code.
  • Source: event_type
  • Usage: all events in this service
metadata.original_time
  • Description: The original event time as reported by the event source. For example, the time in the original format from system event log such as Syslog on Unix/Linux and the System event file on Windows. Omit if event is generated instead of collected via logs.
  • Source: server_timestamp, system_timestamp
  • Usage: 35 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_lost_mode_disabled, google_emm_lost_mode_enabled, ... (+27 more)
metadata.processed_time
  • Description: The event processed time, such as an ETL operation.
  • Source: jc_transformation_ts
  • Usage: 48 events (missing: os_major_rollback, system_admin_grant, system_admin_revoke)
metadata.product.name
  • Description: Originating JumpCloud service that produced the event.
  • Source: service
  • Usage: all events in this service
metadata.tenant_uid
  • Description: JumpCloud organization (tenant) identifier.
  • Source: organization
  • Usage: all events in this service
metadata.uid
  • Description: Unique event identifier assigned by JumpCloud.
  • Source: id
  • Usage: all events in this service
metadata.version
  • Description: OCSF schema version used for this event.
  • Literal: 1.8.0
  • Usage: all events in this service

Actor

actor.user.domain
  • Description: The domain where the user is defined. For example: the LDAP or Active Directory domain.
  • Source: initiated_by.hostname
  • Usage: remote_assist_settings, remote_session_end, remote_session_feedback, remote_session_join, remote_session_launch_token, remote_session_rejoin, remote_session_start
actor.user.email_addr
  • Description: Email address of the actor who initiated the event.
  • Source: initiated_by.email
  • Usage: 31 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_patch, linux_commands_devicelock, ... (+23 more)
actor.user.full_name
  • Description: The full name of the user, as reported by the product.
  • Source: initiated_by.name
  • Usage: remote_assist_settings, remote_session_end, remote_session_feedback, remote_session_join, remote_session_launch_token, remote_session_rejoin, remote_session_start
actor.user.name
  • Description: Display name of the actor who initiated the event.
  • Source: initiated_by.name, initiated_by.username
  • Usage: 11 events: login_attempt, remote_assist_settings, remote_session_end, remote_session_feedback, remote_session_join, remote_session_launch_token, remote_session_rejoin, remote_session_start, ... (+3 more)
actor.user.type_id
  • Description: OCSF user type of the actor (1=User, 2=Admin, 3=System, 4=Service).
  • Source: initiated_by.type
  • Transform:
  • initiated_by.type → enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (39 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_lost_mode_disabled, google_emm_lost_mode_enabled, ... (+31 more))
  • Usage: 39 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_lost_mode_disabled, google_emm_lost_mode_enabled, ... (+31 more)
actor.user.uid
  • Description: Unique identifier of the actor who initiated the event.
  • Source: initiated_by.id, initiated_by.uid
  • Usage: 31 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_patch, linux_commands_devicelock, ... (+23 more)

User

user.full_name
  • Description: The full name of the user, as reported by the product.
  • Source: user.name
  • Usage: system_admin_grant, system_admin_revoke, system_group_admin_grant
user.name
  • Description: The username. For example, janedoe1.
  • Source: resource.username, user.username, username
  • Usage: login_attempt, system_admin_grant, system_admin_revoke, system_group_admin_grant, user_lockout, user_password_change
user.type
  • Description: The type of the user. For example, System, AWS IAM User, etc.
  • Source: resource.type, user.type
  • Usage: system_admin_grant, system_admin_revoke, system_group_admin_grant, user_lockout, user_password_change
user.uid
  • Description: Unique identifier of the user associated with the event.
  • Source: resource.id, user.id
  • Usage: system_admin_grant, system_admin_revoke, system_group_admin_grant, user_lockout, user_password_change

Device

device.hostname
  • Description: The device hostname.
  • Source: system.hostname
  • Usage: login_attempt, user_lockout, user_password_change
device.name
  • Description: The alternate device name, ordinarily as assigned by an administrator.

    Note: The Name could be any other string that helps to identify the device, such as a phone number; for example 310-555-1234.

  • Source: system.displayName
  • Usage: login_attempt, user_lockout, user_password_change
device.os.type
  • Description: The type of the operating system.
  • Source: mdm_type, system.osFamily
  • Usage: login_attempt, recovery_lock_auto_rotation_success, recovery_lock_cleared_success, recovery_lock_set_success
device.uid
  • Description: The unique identifier of the device. For example the Windows TargetSID or AWS EC2 ARN.
  • Source: system.id, windows_device_uuid
  • Usage: login_attempt, recovery_lock_auto_rotation_success, recovery_lock_cleared_success, recovery_lock_set_success, user_lockout, user_password_change

Entity

entity.data.admin_email
  • Description: JumpCloud extension data on the managed entity: admin_email.
  • Source: admin_info.email
  • Usage: remote_session_end, remote_session_feedback, remote_session_join, remote_session_launch_token, remote_session_rejoin, remote_session_start
entity.data.admin_id
  • Description: JumpCloud extension data on the managed entity: admin_id.
  • Source: admin_info.id
  • Usage: remote_session_end, remote_session_feedback, remote_session_join, remote_session_launch_token, remote_session_rejoin, remote_session_start
entity.data.admin_name
  • Description: JumpCloud extension data on the managed entity: admin_name.
  • Source: admin_info.name
  • Usage: remote_session_end, remote_session_feedback, remote_session_join, remote_session_launch_token, remote_session_rejoin, remote_session_start
entity.data.auth_method
  • Description: JumpCloud extension data on the managed entity: auth_method.
  • Source: auth_method
  • Usage: linux_commands_devicelock, linux_commands_erasedevice, linux_commands_restartdevice, linux_commands_shutdowndevice, system_fde_key_decrypt, windows_commands_devicelock, windows_commands_erasedevice, windows_commands_restartdevice, windows_commands_shutdowndevice
entity.data.background_access_enabled
  • Description: JumpCloud extension data on the managed entity: background_access_enabled.
  • Source: changes.from.background_access_enabled
  • Usage: remote_assist_settings
entity.data.changed_field
  • Description: JumpCloud extension data on the managed entity: changed_field.
  • Source: changes.field
  • Usage: os_major_rollback, os_major_upgrade, os_minor_rollback, os_minor_upgrade, system_fde_key_update
entity.data.changes_from
  • Description: JumpCloud extension data on the managed entity: changes_from.
  • Source: changes.from
  • Usage: os_major_rollback, os_major_upgrade, os_minor_rollback, os_minor_upgrade, remote_assist_settings
entity.data.command
  • Description: JumpCloud extension data on the managed entity: command.
  • Source: command
  • Usage: device_command
entity.data.device_count
  • Description: JumpCloud extension data on the managed entity: device_count.
  • Source: device_count
  • Usage: windows_patch_install
entity.data.directive_count
  • Description: JumpCloud extension data on the managed entity: directive_count.
  • Source: directive_count
  • Usage: windows_patch_install
entity.data.enrollment_type
  • Description: JumpCloud extension data on the managed entity: enrollment_type.
  • Source: resource.enrollment_type
  • Usage: google_emm_lost_mode_disabled, google_emm_lost_mode_enabled, google_emm_lost_mode_outgoing_phone_call, google_emm_reset_password_recently, google_emm_stop_lost_mode_user_attempt, google_emm_user_exit_lost_mode_recently
entity.data.experience_survey_enabled
  • Description: JumpCloud extension data on the managed entity: experience_survey_enabled.
  • Source: changes.from.experience_survey_enabled
  • Usage: remote_assist_settings
entity.data.feedback
  • Description: JumpCloud extension data on the managed entity: feedback.
  • Source: message_chain.feedback
  • Usage: remote_session_feedback
entity.data.format
  • Description: JumpCloud extension data on the managed entity: format.
  • Source: format
  • Usage: windows_patch_export
entity.data.initiated_by_provider
  • Description: JumpCloud extension data on the managed entity: initiated_by_provider.
  • Source: initiated_by.provider
  • Usage: windows_commands_erasedevice, windows_commands_restartdevice
entity.data.install_type
  • Description: JumpCloud extension data on the managed entity: install_type.
  • Source: install_type
  • Usage: windows_patch_install
entity.data.management_mode
  • Description: JumpCloud extension data on the managed entity: management_mode.
  • Source: resource.management_mode
  • Usage: google_emm_lost_mode_outgoing_phone_call, google_emm_stop_lost_mode_user_attempt
entity.data.notes
  • Description: JumpCloud extension data on the managed entity: notes.
  • Source: message_chain.notes
  • Usage: remote_session_feedback
entity.data.operation_type
  • Description: JumpCloud extension data on the managed entity: operation_type.
  • Source: operation_type
  • Usage: windows_patch_install
entity.data.ownership_type
  • Description: JumpCloud extension data on the managed entity: ownership_type.
  • Source: resource.ownership_type
  • Usage: google_emm_lost_mode_outgoing_phone_call, google_emm_stop_lost_mode_user_attempt
entity.data.patch_count
  • Description: JumpCloud extension data on the managed entity: patch_count.
  • Source: patch_count
  • Usage: windows_patch_export
entity.data.provider
  • Description: JumpCloud extension data on the managed entity: provider.
  • Source: provider
  • Usage: device_command, google_emm_create, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_patch, linux_commands_erasedevice, windows_commands_erasedevice, windows_commands_restartdevice
entity.data.rating
  • Description: JumpCloud extension data on the managed entity: rating.
  • Source: message_chain.rating
  • Usage: remote_session_feedback
entity.data.remote_assist_enabled
  • Description: JumpCloud extension data on the managed entity: remote_assist_enabled.
  • Source: changes.from.remote_assist_enabled
  • Usage: remote_assist_settings
entity.data.session_duration
  • Description: JumpCloud extension data on the managed entity: session_duration.
  • Source: correlation.session_duration
  • Usage: remote_session_end, remote_session_feedback, remote_session_join, remote_session_launch_token, remote_session_rejoin, remote_session_start
entity.data.session_timeout_duration
  • Description: JumpCloud extension data on the managed entity: session_timeout_duration.
  • Source: changes.from.session_timeout_duration
  • Usage: remote_assist_settings
entity.data.silent_assist_enabled
  • Description: JumpCloud extension data on the managed entity: silent_assist_enabled.
  • Source: changes.from.silent_assist_enabled
  • Usage: remote_assist_settings
entity.data.status
  • Description: JumpCloud extension data on the managed entity: status.
  • Source: status
  • Usage: recovery_lock_password_viewed
entity.data.tags
  • Description: JumpCloud extension data on the managed entity: tags.
  • Source: tags
  • Usage: google_emm_create, google_emm_delete, os_major_upgrade, os_minor_upgrade
entity.data.target_type
  • Description: JumpCloud extension data on the managed entity: target_type.
  • Source: target_type
  • Usage: windows_patch_install
entity.data.workflow_id
  • Description: JumpCloud extension data on the managed entity: workflow_id.
  • Source: initiated_by.source_metadata.workflow.id
  • Usage: windows_commands_devicelock
entity.data.workflow_run_id
  • Description: JumpCloud extension data on the managed entity: workflow_run_id.
  • Source: initiated_by.source_metadata.workflow.run_id
  • Usage: windows_commands_devicelock
entity.data.workflow_type
  • Description: JumpCloud extension data on the managed entity: workflow_type.
  • Source: initiated_by.source_metadata.workflow.type
  • Usage: windows_commands_devicelock
entity.device.hostname
  • Description: The device hostname.
  • Source: resource.hostname, system.hostname
  • Usage: 20 events: linux_commands_devicelock, linux_commands_erasedevice, linux_commands_restartdevice, linux_commands_shutdowndevice, os_major_rollback, os_major_upgrade, os_minor_rollback, os_minor_upgrade, ... (+12 more)
entity.device.hw_info.serial_number
  • Description: The device manufacturer serial number.
  • Source: system.serialno
  • Usage: remote_session_end, remote_session_feedback, remote_session_join, remote_session_launch_token, remote_session_rejoin, remote_session_start
entity.device.name
  • Description: The alternate device name, ordinarily as assigned by an administrator.

    Note: The Name could be any other string that helps to identify the device, such as a phone number; for example 310-555-1234.

  • Source: resource.displayName, system.displayName
  • Usage: 24 events: device_command, google_emm_lost_mode_disabled, google_emm_lost_mode_enabled, google_emm_lost_mode_outgoing_phone_call, google_emm_reset_password_recently, google_emm_stop_lost_mode_user_attempt, google_emm_user_exit_lost_mode_recently, linux_commands_devicelock, ... (+16 more)
entity.device.os.type
  • Description: The type of the operating system.
  • Source: system.osFamily
  • Usage: 12 events: device_command, google_emm_enterprise_upgrade, google_emm_lost_mode_disabled, google_emm_lost_mode_enabled, google_emm_lost_mode_outgoing_phone_call, google_emm_reset_password_recently, google_emm_stop_lost_mode_user_attempt, google_emm_user_exit_lost_mode_recently, ... (+4 more)
entity.device.uid
  • Description: The unique identifier of the device. For example the Windows TargetSID or AWS EC2 ARN.
  • Source: resource.id, system.id
  • Usage: 27 events: device_command, google_emm_lost_mode_disabled, google_emm_lost_mode_enabled, google_emm_lost_mode_outgoing_phone_call, google_emm_reset_password_recently, google_emm_stop_lost_mode_user_attempt, google_emm_user_exit_lost_mode_recently, linux_commands_devicelock, ... (+19 more)
entity.name
  • Description: The name of the managed entity. It should match the name of the specific entity object's name if populated, or the name of the managed entity if the type_id is 'Other'.
  • Source: resource.displayName, resource.name
  • Usage: google_emm_create, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_patch, google_emm_policy_bind, google_emm_policy_unbind, windows_commands_devicelock, windows_commands_restartdevice, windows_commands_shutdowndevice
entity.type
  • Description: The managed entity type. For example: Policy, User, Organization, Device.
  • Source: correlation.type, mdm_type, resource.type
  • Usage: 36 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_lost_mode_disabled, google_emm_lost_mode_enabled, ... (+28 more)
entity.uid
  • Description: The identifier of the managed entity. It should match the uid of the specific entity's object UID if populated, or the source specific ID if the type_id is 'Other'.
  • Source: correlation.id, mdm_device_id, organization, resource.id
  • Usage: 16 events: google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_patch, google_emm_policy_bind, google_emm_policy_unbind, ... (+8 more)
entity_result.data.background_access_enabled
  • Description: JumpCloud extension data on the managed entity: background_access_enabled.
  • Source: changes.to.background_access_enabled
  • Usage: remote_assist_settings
entity_result.data.changes_to
  • Description: JumpCloud extension data on the managed entity: changes_to.
  • Source: changes.to
  • Usage: os_major_rollback, os_major_upgrade, os_minor_rollback, os_minor_upgrade, remote_assist_settings
entity_result.data.experience_survey_enabled
  • Description: JumpCloud extension data on the managed entity: experience_survey_enabled.
  • Source: changes.to.experience_survey_enabled
  • Usage: remote_assist_settings
entity_result.data.remote_assist_enabled
  • Description: JumpCloud extension data on the managed entity: remote_assist_enabled.
  • Source: changes.to.remote_assist_enabled
  • Usage: remote_assist_settings
entity_result.data.session_timeout_duration
  • Description: JumpCloud extension data on the managed entity: session_timeout_duration.
  • Source: changes.to.session_timeout_duration
  • Usage: remote_assist_settings
entity_result.data.silent_assist_enabled
  • Description: JumpCloud extension data on the managed entity: silent_assist_enabled.
  • Source: changes.to.silent_assist_enabled
  • Usage: remote_assist_settings

Src Endpoint

src_endpoint.autonomous_system.name
  • Description: Organization name for the Autonomous System.
  • Source: asn.organization
  • Usage: 20 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_patch, linux_commands_erasedevice, ... (+12 more)
src_endpoint.autonomous_system.number
  • Description: Unique number that the AS is identified by.
  • Source: asn.number
  • Transform:
  • asn.number → int (20 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_patch, linux_commands_erasedevice, ... (+12 more))
  • Usage: 20 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_patch, linux_commands_erasedevice, ... (+12 more)
src_endpoint.ip
  • Description: Source IP address the request originated from.
  • Source: client_ip
  • Usage: 37 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_patch, linux_commands_devicelock, ... (+29 more)
src_endpoint.location.city
  • Description: The name of the city.
  • Source: geoip.city
  • Usage: 25 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_patch, linux_commands_devicelock, ... (+17 more)
src_endpoint.location.continent
  • Description: The name of the continent.
  • Source: geoip.continent_code
  • Usage: 29 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_patch, linux_commands_devicelock, ... (+21 more)
src_endpoint.location.country
  • Description: The ISO 3166-1 Alpha-2 country code.

    Note: The two letter country code should be capitalized. For example: US or CA.

  • Source: geoip.country_code
  • Usage: 29 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_patch, linux_commands_devicelock, ... (+21 more)
src_endpoint.location.lat
  • Description: The geographical Latitude coordinate represented in Decimal Degrees (DD). For example: 42.361145.
  • Source: geoip.latitude
  • Transform:
  • geoip.latitude → double (29 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_patch, linux_commands_devicelock, ... (+21 more))
  • Usage: 29 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_patch, linux_commands_devicelock, ... (+21 more)
src_endpoint.location.long
  • Description: The geographical Longitude coordinate represented in Decimal Degrees (DD). For example: -71.057083.
  • Source: geoip.longitude
  • Transform:
  • geoip.longitude → double (29 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_patch, linux_commands_devicelock, ... (+21 more))
  • Usage: 29 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_patch, linux_commands_devicelock, ... (+21 more)
src_endpoint.location.region
  • Description: The alphanumeric code that identifies the principal subdivision (e.g. province or state) of the country. For example, 'CH-VD' for the Canton of Vaud, Switzerland
  • Source: geoip.region_code
  • Usage: 29 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_patch, linux_commands_devicelock, ... (+21 more)

Http Request

http_request.user_agent
  • Description: The request header that identifies the operating system and web browser.
  • Source: user_agent, useragent.device
  • Usage: 23 events: linux_commands_devicelock, linux_commands_erasedevice, linux_commands_restartdevice, linux_commands_shutdowndevice, remote_assist_settings, remote_session_end, remote_session_join, remote_session_launch_token, ... (+15 more)

Observables

observables[].name
  • Description: The full name of the observable attribute. The name is a pointer/reference to an attribute within the OCSF event data. For example: file.name. Array attributes may be represented in one of three ways. For example: resources.uid, resources[].uid, resources[0].uid.
  • Literal: actor.user.email_addr, actor.user.name, actor.user.uid, device.hostname, device.uid, entity.device.hostname, entity.device.hw_info.serial_number, entity.device.uid, group.name, group.uid, http_request.user_agent, resource.name, resource.uid, src_endpoint.ip, src_endpoint.location.country, user.name, user.uid
  • Usage: 47 events (missing: google_emm_policy_bind, google_emm_policy_unbind, google_emm_sw_app_bind, google_emm_sw_app_unbind)
observables[].type_id
  • Description: The observable value type identifier.
  • Literal: 1, 10, 14, 16, 2, 31, 32, 33, 37, 38, 4, 47, 5
  • Usage: 47 events (missing: google_emm_policy_bind, google_emm_policy_unbind, google_emm_sw_app_bind, google_emm_sw_app_unbind)
observables[].value
  • Description: The value associated with the observable attribute. The meaning of the value depends on the observable type.
    If the name refers to a scalar attribute, then the value is the value of the attribute.
    If the name refers to an object attribute, then the value is not populated.
  • Source: client_ip, geoip.country_code, initiated_by.email, initiated_by.id, initiated_by.name, initiated_by.uid, initiated_by.username, mdm_device_id, resource.displayName, resource.hostname, resource.id, resource.name, resource.username, system.hostname, system.id, system.serialno, user.id, user.username, user_agent, useragent.device, username, windows_device_uuid
  • Usage: 47 events (missing: google_emm_policy_bind, google_emm_policy_unbind, google_emm_sw_app_bind, google_emm_sw_app_unbind)

Other

app.name
  • Description: The name of the product.
  • Source: resource.name
  • Usage: google_emm_sw_app_bind, google_emm_sw_app_unbind
app.uid
  • Description: The unique identifier of the product.
  • Source: resource.id
  • Usage: google_emm_sw_app_bind, google_emm_sw_app_unbind
group.name
  • Description: The group name.
  • Source: resource.name
  • Usage: system_group_admin_grant, system_group_admin_revoke
group.type
  • Description: The type of the group.
  • Source: resource.type
  • Usage: system_group_admin_grant, system_group_admin_revoke
group.uid
  • Description: The unique identifier of the group. For example, for Windows events this is the security identifier (SID) of the group. Another example, pool id or desktop id that the device belongs to.
  • Source: resource.id
  • Usage: system_group_admin_grant, system_group_admin_revoke
job.desc
  • Description: The description of the job.
  • Source: request_type
  • Usage: recovery_lock_auto_rotation_success, recovery_lock_cleared_success, recovery_lock_set_success
job.run_state
  • Description: The run state of the job.
  • Source: status
  • Usage: recovery_lock_auto_rotation_success, recovery_lock_cleared_success, recovery_lock_set_success
resource.name
  • Description: The name of the resource.
  • Source: resource.displayName
  • Usage: system_admin_grant, system_admin_revoke
resource.type
  • Description: The resource type as defined by the event source.
  • Source: resource.type
  • Usage: system_admin_grant, system_admin_revoke
resource.uid
  • Description: The unique identifier of the resource.
  • Source: resource.id
  • Usage: system_admin_grant, system_admin_revoke

Unmapped

unmapped.@timestamp
  • Description: JumpCloud Directory Insights field @timestamp preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: @timestamp
  • Usage: linux_commands_erasedevice, system_admin_grant, system_admin_revoke, user_lockout, user_password_change, windows_commands_erasedevice
unmapped.@version
  • Description: JumpCloud Directory Insights field @version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: @version
  • Usage: all events in this service
unmapped.asn
  • Description: JumpCloud Directory Insights field asn preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: asn
  • Usage: linux_commands_restartdevice, linux_commands_shutdowndevice, os_major_upgrade, os_minor_rollback, os_minor_upgrade
unmapped.asn.error
  • Description: JumpCloud Directory Insights field asn.error preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: asn.error
  • Usage: os_major_upgrade, os_minor_rollback, os_minor_upgrade, remote_session_end, remote_session_join, remote_session_launch_token, remote_session_rejoin, remote_session_start
unmapped.asn.ip_address
  • Description: JumpCloud Directory Insights field asn.ip_address preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: asn.ip_address
  • Usage: os_major_upgrade, os_minor_rollback, os_minor_upgrade, remote_session_end, remote_session_join, remote_session_launch_token, remote_session_rejoin, remote_session_start
unmapped.asn.network
  • Description: JumpCloud Directory Insights field asn.network preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: asn.network
  • Usage: 19 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_patch, linux_commands_erasedevice, ... (+11 more)
unmapped.association_action_source
  • Description: JumpCloud Directory Insights field association_action_source preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: association_action_source
  • Usage: recovery_lock_auto_rotation_success, recovery_lock_cleared_success, recovery_lock_password_viewed, recovery_lock_set_success
unmapped.association_from_type
  • Description: JumpCloud Directory Insights field association_from_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: association_from_type
  • Usage: recovery_lock_auto_rotation_success, recovery_lock_cleared_success, recovery_lock_password_viewed, recovery_lock_set_success
unmapped.association_op
  • Description: JumpCloud Directory Insights field association_op preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: association_op
  • Usage: recovery_lock_auto_rotation_success, recovery_lock_cleared_success, recovery_lock_password_viewed, recovery_lock_set_success
unmapped.association_to_type
  • Description: JumpCloud Directory Insights field association_to_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: association_to_type
  • Usage: recovery_lock_auto_rotation_success, recovery_lock_cleared_success, recovery_lock_password_viewed, recovery_lock_set_success
unmapped.auth_method
  • Description: JumpCloud Directory Insights field auth_method preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: auth_method
  • Usage: system_admin_grant, system_admin_revoke, system_group_admin_grant, system_group_admin_revoke, user_password_change
unmapped.changed_field
  • Description: JumpCloud Directory Insights field changed_field preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.field
  • Usage: user_password_change
unmapped.changes
  • Description: JumpCloud Directory Insights field changes preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes
  • Usage: linux_commands_erasedevice, user_lockout, windows_commands_devicelock, windows_commands_erasedevice, windows_commands_restartdevice, windows_commands_shutdowndevice
unmapped.changes_from
  • Description: JumpCloud Directory Insights field changes_from preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.from
  • Usage: user_password_change
unmapped.changes_to
  • Description: JumpCloud Directory Insights field changes_to preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to
  • Usage: user_password_change
unmapped.client_ip
  • Description: JumpCloud Directory Insights field client_ip preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: client_ip
  • Usage: google_emm_lost_mode_disabled, google_emm_lost_mode_enabled, google_emm_lost_mode_outgoing_phone_call, google_emm_policy_bind, google_emm_policy_unbind, google_emm_reset_password_recently, google_emm_stop_lost_mode_user_attempt, google_emm_sw_app_bind, google_emm_sw_app_unbind, google_emm_user_exit_lost_mode_recently
unmapped.command
  • Description: JumpCloud Directory Insights field command preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: command
  • Usage: recovery_lock_auto_rotation_success, recovery_lock_cleared_success, recovery_lock_password_viewed, recovery_lock_set_success
unmapped.command_uuid
  • Description: JumpCloud Directory Insights field command_uuid preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: command_uuid
  • Usage: recovery_lock_auto_rotation_success, recovery_lock_cleared_success, recovery_lock_password_viewed, recovery_lock_set_success
unmapped.error_chain
  • Description: JumpCloud Directory Insights field error_chain preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: error_chain
  • Usage: recovery_lock_auto_rotation_success, recovery_lock_cleared_success, recovery_lock_password_viewed, recovery_lock_set_success
unmapped.file_input_timestamp
  • Description: JumpCloud Directory Insights field file_input_timestamp preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: file_input_timestamp
  • Usage: 18 events: google_emm_create, google_emm_delete, linux_commands_erasedevice, login_attempt, os_major_rollback, os_major_upgrade, os_minor_upgrade, remote_assist_settings, ... (+10 more)
unmapped.geoip
  • Description: JumpCloud Directory Insights field geoip preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip
  • Usage: linux_commands_devicelock, linux_commands_restartdevice, linux_commands_shutdowndevice, login_attempt, os_major_rollback, os_major_upgrade, os_minor_rollback, os_minor_upgrade
unmapped.geoip.error
  • Description: JumpCloud Directory Insights field geoip.error preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.error
  • Usage: os_major_upgrade, os_minor_rollback, os_minor_upgrade, remote_session_end, remote_session_join, remote_session_launch_token, remote_session_rejoin, remote_session_start
unmapped.geoip.ip_address
  • Description: JumpCloud Directory Insights field geoip.ip_address preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.ip_address
  • Usage: os_major_upgrade, os_minor_rollback, os_minor_upgrade, remote_session_end, remote_session_join, remote_session_launch_token, remote_session_rejoin, remote_session_start
unmapped.geoip.region_name
  • Description: JumpCloud Directory Insights field geoip.region_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.region_name
  • Usage: 29 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_patch, linux_commands_devicelock, ... (+21 more)
unmapped.geoip.timezone
  • Description: JumpCloud Directory Insights field geoip.timezone preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.timezone
  • Usage: 29 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_patch, linux_commands_devicelock, ... (+21 more)
unmapped.initiated_by
  • Description: JumpCloud Directory Insights field initiated_by preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by
  • Usage: 11 events: google_emm_policy_bind, google_emm_policy_unbind, google_emm_sw_app_bind, google_emm_sw_app_unbind, os_major_upgrade, os_minor_rollback, os_minor_upgrade, recovery_lock_auto_rotation_success, ... (+3 more)
unmapped.initiated_by_email_hash
  • Description: JumpCloud Directory Insights field initiated_by_email_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_email_hash
  • Usage: 26 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_patch, linux_commands_devicelock, ... (+18 more)
unmapped.initiated_by_id_hash
  • Description: JumpCloud Directory Insights field initiated_by_id_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_id_hash
  • Usage: 26 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_patch, linux_commands_devicelock, ... (+18 more)
unmapped.initiated_by_name_hash
  • Description: JumpCloud Directory Insights field initiated_by_name_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_name_hash
  • Usage: login_attempt, windows_commands_devicelock
unmapped.initiated_by_type
  • Description: JumpCloud Directory Insights field initiated_by_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_type
  • Usage: recovery_lock_auto_rotation_success, recovery_lock_cleared_success, recovery_lock_password_viewed, recovery_lock_set_success
unmapped.initiated_by_uid
  • Description: JumpCloud Directory Insights field initiated_by_uid preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by.uid
  • Usage: remote_session_feedback
unmapped.initiated_by_user_id
  • Description: JumpCloud Directory Insights field initiated_by_user_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by.user_id
  • Usage: linux_commands_erasedevice, system_group_admin_grant, system_group_admin_revoke, windows_commands_erasedevice
unmapped.initiated_by_username_hash
  • Description: JumpCloud Directory Insights field initiated_by_username_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_username_hash
  • Usage: login_attempt, remote_session_end, remote_session_join, remote_session_launch_token, user_lockout, user_password_change
unmapped.is_out_of_bound
  • Description: JumpCloud Directory Insights field is_out_of_bound preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: is_out_of_bound
  • Usage: 46 events (missing: os_major_rollback, remote_session_feedback, system_admin_grant, system_admin_revoke, windows_commands_erasedevice)
unmapped.jc_application_name
  • Description: JumpCloud Directory Insights field jc_application_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_application_name
  • Usage: 42 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_lost_mode_disabled, google_emm_lost_mode_enabled, ... (+34 more)
unmapped.jc_initiated_by_email
  • Description: JumpCloud Directory Insights field jc_initiated_by_email preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_initiated_by_email
  • Usage: 11 events: device_command, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, login_attempt, os_major_upgrade, os_minor_upgrade, recovery_lock_auto_rotation_success, recovery_lock_password_viewed, ... (+3 more)
unmapped.jc_initiated_by_id
  • Description: JumpCloud Directory Insights field jc_initiated_by_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_initiated_by_id
  • Usage: device_command, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, login_attempt, os_major_upgrade, os_minor_upgrade, remote_assist_settings, system_fde_key_update
unmapped.jc_initiated_by_username
  • Description: JumpCloud Directory Insights field jc_initiated_by_username preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_initiated_by_username
  • Usage: device_command, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, os_major_upgrade, os_minor_upgrade, recovery_lock_auto_rotation_success, recovery_lock_password_viewed, remote_assist_settings, system_fde_key_decrypt, system_fde_key_update
unmapped.jc_organization_name
  • Description: JumpCloud Directory Insights field jc_organization_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_organization_name
  • Usage: device_command, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, os_major_upgrade, os_minor_upgrade, recovery_lock_auto_rotation_success, recovery_lock_password_viewed, remote_assist_settings, system_fde_key_decrypt, system_fde_key_update
unmapped.jc_provider_id
  • Description: JumpCloud Directory Insights field jc_provider_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_provider_id
  • Usage: device_command, google_emm_enrollment_token_delete, os_major_upgrade, os_minor_upgrade, recovery_lock_auto_rotation_success, recovery_lock_password_viewed, remote_assist_settings, system_fde_key_decrypt, system_fde_key_update
unmapped.jc_system_display_name
  • Description: JumpCloud Directory Insights field jc_system_display_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_system_display_name
  • Usage: device_command, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, os_major_upgrade, os_minor_upgrade, recovery_lock_auto_rotation_success, recovery_lock_password_viewed, remote_assist_settings, system_fde_key_update
unmapped.jc_system_hostname
  • Description: JumpCloud Directory Insights field jc_system_hostname preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_system_hostname
  • Usage: device_command, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, os_major_upgrade, os_minor_upgrade, recovery_lock_auto_rotation_success, recovery_lock_password_viewed, remote_assist_settings, system_fde_key_update
unmapped.mdm_device_manager_id
  • Description: JumpCloud Directory Insights field mdm_device_manager_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: mdm_device_manager_id
  • Usage: recovery_lock_auto_rotation_success, recovery_lock_cleared_success, recovery_lock_password_viewed, recovery_lock_set_success
unmapped.message_chain
  • Description: JumpCloud Directory Insights field message_chain preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: message_chain
  • Usage: remote_session_join, remote_session_launch_token, remote_session_rejoin, user_password_change
unmapped.privilege_field
  • Description: JumpCloud Directory Insights field privilege_field preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.field
  • Usage: system_admin_grant, system_admin_revoke, system_group_admin_grant, system_group_admin_revoke
unmapped.privilege_from
  • Description: JumpCloud Directory Insights field privilege_from preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.from
  • Usage: system_admin_revoke, system_group_admin_revoke
unmapped.privilege_to
  • Description: JumpCloud Directory Insights field privilege_to preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: changes.to
  • Usage: system_admin_grant, system_group_admin_grant
unmapped.process_name
  • Description: JumpCloud Directory Insights field process_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: process_name
  • Usage: login_attempt
unmapped.provider
  • Description: JumpCloud Directory Insights field provider preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: provider
  • Usage: system_admin_grant, system_admin_revoke, system_group_admin_revoke, user_lockout, user_password_change
unmapped.repeat_count
  • Description: JumpCloud Directory Insights field repeat_count preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: repeat_count
  • Usage: login_attempt
unmapped.request_type
  • Description: JumpCloud Directory Insights field request_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: request_type
  • Usage: recovery_lock_password_viewed
unmapped.resource_id_hash
  • Description: JumpCloud Directory Insights field resource_id_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource_id_hash
  • Usage: 34 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_lost_mode_disabled, google_emm_lost_mode_enabled, ... (+26 more)
unmapped.resource_name
  • Description: JumpCloud Directory Insights field resource_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.name
  • Usage: system_admin_grant, system_admin_revoke
unmapped.resource_name_hash
  • Description: JumpCloud Directory Insights field resource_name_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource_name_hash
  • Usage: device_command, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_lost_mode_outgoing_phone_call, google_emm_patch, google_emm_stop_lost_mode_user_attempt, google_emm_sw_app_unbind, google_emm_user_exit_lost_mode_recently
unmapped.resource_type
  • Description: JumpCloud Directory Insights field resource_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.type
  • Usage: google_emm_sw_app_bind, google_emm_sw_app_unbind
unmapped.resource_username_hash
  • Description: JumpCloud Directory Insights field resource_username_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource_username_hash
  • Usage: user_lockout, user_password_change
unmapped.system.correlation.id
  • Description: JumpCloud Directory Insights field system.correlation.id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: system.correlation.id
  • Usage: login_attempt
unmapped.system.correlation.session_duration
  • Description: JumpCloud Directory Insights field system.correlation.session_duration preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: system.correlation.session_duration
  • Usage: login_attempt
unmapped.system.correlation.type
  • Description: JumpCloud Directory Insights field system.correlation.type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: system.correlation.type
  • Usage: login_attempt
unmapped.system.message_chain.feedback
  • Description: JumpCloud Directory Insights field system.message_chain.feedback preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: system.message_chain.feedback
  • Usage: login_attempt
unmapped.system.message_chain.message_details
  • Description: JumpCloud Directory Insights field system.message_chain.message_details preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: system.message_chain.message_details
  • Usage: login_attempt
unmapped.system.message_chain.notes
  • Description: JumpCloud Directory Insights field system.message_chain.notes preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: system.message_chain.notes
  • Usage: login_attempt
unmapped.system.message_chain.rating
  • Description: JumpCloud Directory Insights field system.message_chain.rating preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: system.message_chain.rating
  • Usage: login_attempt
unmapped.system.message_chain.response_code
  • Description: JumpCloud Directory Insights field system.message_chain.response_code preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: system.message_chain.response_code
  • Usage: login_attempt
unmapped.system.message_chain.response_message
  • Description: JumpCloud Directory Insights field system.message_chain.response_message preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: system.message_chain.response_message
  • Usage: login_attempt
unmapped.system_id_hash
  • Description: JumpCloud Directory Insights field system_id_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: system_id_hash
  • Usage: device_command, google_emm_lost_mode_outgoing_phone_call, google_emm_stop_lost_mode_user_attempt, google_emm_user_exit_lost_mode_recently, os_major_upgrade, os_minor_rollback, os_minor_upgrade, remote_session_join, remote_session_launch_token, system_fde_key_update
unmapped.tags
  • Description: JumpCloud Directory Insights field tags preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: tags
  • Usage: 13 events: linux_commands_erasedevice, os_major_rollback, remote_assist_settings, remote_session_feedback, remote_session_join, remote_session_launch_token, remote_session_rejoin, system_admin_grant, ... (+5 more)
unmapped.testing_event
  • Description: JumpCloud Directory Insights field testing_event preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: testing_event
  • Usage: user_password_change
unmapped.timestamp_source
  • Description: JumpCloud Directory Insights field timestamp_source preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: timestamp_source
  • Usage: 35 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_lost_mode_disabled, google_emm_lost_mode_enabled, ... (+27 more)
unmapped.user_agent
  • Description: JumpCloud Directory Insights field user_agent preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: user_agent
  • Usage: 21 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_lost_mode_disabled, google_emm_lost_mode_enabled, ... (+13 more)
unmapped.user_group_id
  • Description: JumpCloud Directory Insights field user_group_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: user_group.id
  • Usage: system_group_admin_revoke
unmapped.user_group_name
  • Description: JumpCloud Directory Insights field user_group_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: user_group.name
  • Usage: system_group_admin_revoke
unmapped.user_group_type
  • Description: JumpCloud Directory Insights field user_group_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: user_group.type
  • Usage: system_group_admin_revoke
unmapped.useragent.device
  • Description: JumpCloud Directory Insights field useragent.device preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.device
  • Usage: 11 events: linux_commands_devicelock, linux_commands_erasedevice, linux_commands_restartdevice, linux_commands_shutdowndevice, system_fde_key_decrypt, system_group_admin_grant, system_group_admin_revoke, windows_commands_devicelock, ... (+3 more)
unmapped.useragent.major
  • Description: JumpCloud Directory Insights field useragent.major preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.major
  • Usage: 14 events: linux_commands_devicelock, linux_commands_erasedevice, linux_commands_restartdevice, linux_commands_shutdowndevice, system_admin_grant, system_admin_revoke, system_fde_key_decrypt, system_group_admin_grant, ... (+6 more)
unmapped.useragent.minor
  • Description: JumpCloud Directory Insights field useragent.minor preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.minor
  • Usage: 14 events: linux_commands_devicelock, linux_commands_erasedevice, linux_commands_restartdevice, linux_commands_shutdowndevice, system_admin_grant, system_admin_revoke, system_fde_key_decrypt, system_group_admin_grant, ... (+6 more)
unmapped.useragent.name
  • Description: JumpCloud Directory Insights field useragent.name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.name
  • Usage: 14 events: linux_commands_devicelock, linux_commands_erasedevice, linux_commands_restartdevice, linux_commands_shutdowndevice, system_admin_grant, system_admin_revoke, system_fde_key_decrypt, system_group_admin_grant, ... (+6 more)
unmapped.useragent.os
  • Description: JumpCloud Directory Insights field useragent.os preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os
  • Usage: 14 events: linux_commands_devicelock, linux_commands_erasedevice, linux_commands_restartdevice, linux_commands_shutdowndevice, system_admin_grant, system_admin_revoke, system_fde_key_decrypt, system_group_admin_grant, ... (+6 more)
unmapped.useragent.os_full
  • Description: JumpCloud Directory Insights field useragent.os_full preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_full
  • Usage: 14 events: linux_commands_devicelock, linux_commands_erasedevice, linux_commands_restartdevice, linux_commands_shutdowndevice, system_admin_grant, system_admin_revoke, system_fde_key_decrypt, system_group_admin_grant, ... (+6 more)
unmapped.useragent.os_major
  • Description: JumpCloud Directory Insights field useragent.os_major preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_major
  • Usage: 11 events: linux_commands_devicelock, linux_commands_erasedevice, linux_commands_restartdevice, linux_commands_shutdowndevice, system_fde_key_decrypt, system_group_admin_revoke, user_password_change, windows_commands_devicelock, ... (+3 more)
unmapped.useragent.os_minor
  • Description: JumpCloud Directory Insights field useragent.os_minor preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_minor
  • Usage: 11 events: linux_commands_devicelock, linux_commands_erasedevice, linux_commands_restartdevice, linux_commands_shutdowndevice, system_fde_key_decrypt, system_group_admin_revoke, user_password_change, windows_commands_devicelock, ... (+3 more)
unmapped.useragent.os_name
  • Description: JumpCloud Directory Insights field useragent.os_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_name
  • Usage: 14 events: linux_commands_devicelock, linux_commands_erasedevice, linux_commands_restartdevice, linux_commands_shutdowndevice, system_admin_grant, system_admin_revoke, system_fde_key_decrypt, system_group_admin_grant, ... (+6 more)
unmapped.useragent.os_patch
  • Description: JumpCloud Directory Insights field useragent.os_patch preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_patch
  • Usage: 11 events: linux_commands_devicelock, linux_commands_erasedevice, linux_commands_restartdevice, linux_commands_shutdowndevice, system_fde_key_decrypt, system_group_admin_revoke, user_password_change, windows_commands_devicelock, ... (+3 more)
unmapped.useragent.os_version
  • Description: JumpCloud Directory Insights field useragent.os_version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.os_version
  • Usage: 11 events: linux_commands_devicelock, linux_commands_erasedevice, linux_commands_restartdevice, linux_commands_shutdowndevice, system_fde_key_decrypt, system_group_admin_revoke, user_password_change, windows_commands_devicelock, ... (+3 more)
unmapped.useragent.patch
  • Description: JumpCloud Directory Insights field useragent.patch preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.patch
  • Usage: 12 events: linux_commands_devicelock, linux_commands_erasedevice, linux_commands_restartdevice, linux_commands_shutdowndevice, system_fde_key_decrypt, system_group_admin_grant, system_group_admin_revoke, user_password_change, ... (+4 more)
unmapped.useragent.version
  • Description: JumpCloud Directory Insights field useragent.version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: useragent.version
  • Usage: 14 events: linux_commands_devicelock, linux_commands_erasedevice, linux_commands_restartdevice, linux_commands_shutdowndevice, system_admin_grant, system_admin_revoke, system_fde_key_decrypt, system_group_admin_grant, ... (+6 more)
unmapped.username
  • Description: JumpCloud Directory Insights field username preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: username
  • Usage: remote_session_end, remote_session_feedback, remote_session_join, remote_session_launch_token, remote_session_rejoin, remote_session_start
unmapped.username_hash
  • Description: JumpCloud Directory Insights field username_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: username_hash
  • Usage: login_attempt
unmapped.windows_device_uuid
  • Description: JumpCloud Directory Insights field windows_device_uuid preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: windows_device_uuid
  • Usage: recovery_lock_password_viewed
unmapped.windows_meta.elevated
  • Description: JumpCloud Directory Insights field windows_meta.elevated preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: windows_meta.elevated
  • Usage: login_attempt
unmapped.windows_meta.logon_type
  • Description: JumpCloud Directory Insights field windows_meta.logon_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: windows_meta.logon_type
  • Usage: login_attempt
unmapped.windows_meta.user_process
  • Description: JumpCloud Directory Insights field windows_meta.user_process preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: windows_meta.user_process
  • Usage: login_attempt
unmapped.windows_meta.user_services
  • Description: JumpCloud Directory Insights field windows_meta.user_services preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: windows_meta.user_services
  • Usage: login_attempt
unmapped.windows_meta.user_tasks
  • Description: JumpCloud Directory Insights field windows_meta.user_tasks preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: windows_meta.user_tasks
  • Usage: login_attempt

Workflow#

workflow · 5 events

Event Category Class Activity Type UID Fields
workflow_create Identity & Access Management (3) Entity Management (3004) Create (1) 300401 920
workflow_delete Identity & Access Management (3) Entity Management (3004) Delete (4) 300404 924
workflow_run System Activity (1) Scheduled Job Activity (1006) Start (6) 100606 37
workflow_run_rate_limited System Activity (1) Scheduled Job Activity (1006) Start (6) 100606 35
workflow_update Identity & Access Management (3) Entity Management (3004) Update (3) 300403 552

OCSF field mappings#

Legend

  • Description: what the OCSF field represents (from OCSF schema v1.8.0)
  • Source: raw JumpCloud event field(s) mapped via ${{placeholder}} template
  • Transform: fieldMappings entry applied at runtime (cast, enum, etc.)
  • Literal: static value set in the mapping template
  • Usage: event types in this service that include this field

Core

activity_id
  • Description: The normalized identifier of the activity that triggered the event.
  • Literal: 1, 3, 4, 6
  • Usage: all events in this service
activity_name
  • Description: The event activity name, as defined by the activity_id.
  • Literal: Create, Delete, Start, Update
  • Usage: all events in this service
category_name
  • Description: The event category name, as defined by category_uid value: Discovery.
  • Literal: Identity & Access Management, System Activity
  • Usage: all events in this service
category_uid
  • Description: The category unique identifier of the event.
  • Literal: 1, 3
  • Usage: all events in this service
class_name
  • Description: The event class name, as defined by class_uid value: User Inventory Info.
  • Literal: Entity Management, Scheduled Job Activity
  • Usage: all events in this service
class_uid
  • Description: The unique identifier of a class. A class describes the attributes available in an event.
  • Literal: 1006, 3004
  • Usage: all events in this service
severity_id
  • Description: OCSF severity identifier for the event.
  • Literal: 1
  • Usage: all events in this service
status_detail
  • Description: The status detail contains additional information about the event/finding outcome.
  • Source: error_message
  • Usage: all events in this service
status_id
  • Description: Normalized status of the activity (1=Success, 2=Failure).
  • Source: success
  • Transform:
  • success → boolean_to_status_id; true→1, false→2 (all events in this service)
  • Usage: all events in this service
time
  • Description: Event time, in epoch milliseconds (OCSF time).
  • Source: timestamp
  • Transform:
  • timestamp → iso8601_to_epoch_millis (all events in this service)
  • Usage: all events in this service
type_uid
  • Description: The event/finding type ID. It identifies the event's semantics and structure. The value is calculated by the logging system as: class_uid * 100 + activity_id.
  • Literal: 100606, 300401, 300403, 300404
  • Usage: all events in this service

Metadata

metadata.event_code
  • Description: JumpCloud event type code.
  • Source: event_type
  • Usage: all events in this service
metadata.original_time
  • Description: The original event time as reported by the event source. For example, the time in the original format from system event log such as Syslog on Unix/Linux and the System event file on Windows. Omit if event is generated instead of collected via logs.
  • Source: server_timestamp
  • Usage: all events in this service
metadata.product.name
  • Description: Originating JumpCloud service that produced the event.
  • Source: service
  • Usage: all events in this service
metadata.tenant_uid
  • Description: JumpCloud organization (tenant) identifier.
  • Source: organization
  • Usage: all events in this service
metadata.uid
  • Description: Unique event identifier assigned by JumpCloud.
  • Source: id
  • Usage: all events in this service
metadata.version
  • Description: OCSF schema version used for this event.
  • Literal: 1.8.0
  • Usage: all events in this service

Actor

actor.user.type_id
  • Description: OCSF user type of the actor (1=User, 2=Admin, 3=System, 4=Service).
  • Source: initiated_by.type
  • Transform:
  • initiated_by.type → enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (all events in this service)
  • Usage: all events in this service
actor.user.uid
  • Description: Unique identifier of the actor who initiated the event.
  • Source: initiated_by.id
  • Usage: all events in this service

Entity

entity.data.auth_method
  • Description: JumpCloud extension data on the managed entity: auth_method.
  • Source: auth_method
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.changed_field
  • Description: JumpCloud extension data on the managed entity: changed_field.
  • Source: changes.field
  • Usage: workflow_update
entity.data.changes_from_do_activateUser_call
  • Description: JumpCloud extension data on the managed entity: changes_from_do_activateUser_call.
  • Source: changes.from.do.activateUser.call
  • Usage: workflow_update
entity.data.changes_from_do_activateUser_metadata_displayLabels_email
  • Description: JumpCloud extension data on the managed entity: changes_from_do_activateUser_metadata_displayLabels_email.
  • Source: changes.from.do.activateUser.metadata.displayLabels.email
  • Usage: workflow_update
entity.data.changes_from_do_activateUser_metadata_displayLabels_user
  • Description: JumpCloud extension data on the managed entity: changes_from_do_activateUser_metadata_displayLabels_user.
  • Source: changes.from.do.activateUser.metadata.displayLabels.user
  • Usage: workflow_update
entity.data.changes_from_do_activateUser_metadata_inputModes_email
  • Description: JumpCloud extension data on the managed entity: changes_from_do_activateUser_metadata_inputModes_email.
  • Source: changes.from.do.activateUser.metadata.inputModes.email
  • Usage: workflow_update
entity.data.changes_from_do_activateUser_metadata_inputModes_user
  • Description: JumpCloud extension data on the managed entity: changes_from_do_activateUser_metadata_inputModes_user.
  • Source: changes.from.do.activateUser.metadata.inputModes.user
  • Usage: workflow_update
entity.data.changes_from_do_activateUser_with_bodyParams_email
  • Description: JumpCloud extension data on the managed entity: changes_from_do_activateUser_with_bodyParams_email.
  • Source: changes.from.do.activateUser.with.bodyParams.email
  • Usage: workflow_update
entity.data.changes_from_do_activateUser_with_operationId
  • Description: JumpCloud extension data on the managed entity: changes_from_do_activateUser_with_operationId.
  • Source: changes.from.do.activateUser.with.operationId
  • Usage: workflow_update
entity.data.changes_from_do_activateUser_with_pathParams_id
  • Description: JumpCloud extension data on the managed entity: changes_from_do_activateUser_with_pathParams_id.
  • Source: changes.from.do.activateUser.with.pathParams.id
  • Usage: workflow_update
entity.data.changes_from_do_activateUser_with_version
  • Description: JumpCloud extension data on the managed entity: changes_from_do_activateUser_with_version.
  • Source: changes.from.do.activateUser.with.version
  • Usage: workflow_update
entity.data.changes_from_do_callConnector_call
  • Description: JumpCloud extension data on the managed entity: changes_from_do_callConnector_call.
  • Source: changes.from.do.callConnector.call
  • Usage: workflow_update
entity.data.changes_from_do_callConnector_with_body_data
  • Description: JumpCloud extension data on the managed entity: changes_from_do_callConnector_with_body_data.
  • Source: changes.from.do.callConnector.with.body.data
  • Usage: workflow_update
entity.data.changes_from_do_callConnector_with_body_id
  • Description: JumpCloud extension data on the managed entity: changes_from_do_callConnector_with_body_id.
  • Source: changes.from.do.callConnector.with.body.id
  • Usage: workflow_update
entity.data.changes_from_do_callConnector_with_body_timestamp
  • Description: JumpCloud extension data on the managed entity: changes_from_do_callConnector_with_body_timestamp.
  • Source: changes.from.do.callConnector.with.body.timestamp
  • Usage: workflow_update
entity.data.changes_from_do_callConnector_with_endpointPath
  • Description: JumpCloud extension data on the managed entity: changes_from_do_callConnector_with_endpointPath.
  • Source: changes.from.do.callConnector.with.endpointPath
  • Usage: workflow_update
entity.data.changes_from_do_callConnector_with_headers_Accept
  • Description: JumpCloud extension data on the managed entity: changes_from_do_callConnector_with_headers_Accept.
  • Source: changes.from.do.callConnector.with.headers.Accept
  • Usage: workflow_update
entity.data.changes_from_do_callConnector_with_headers_EWrwer
  • Description: JumpCloud extension data on the managed entity: changes_from_do_callConnector_with_headers_EWrwer.
  • Source: changes.from.do.callConnector.with.headers.EWrwer
  • Usage: workflow_update
entity.data.changes_from_do_callConnector_with_headers_ew
  • Description: JumpCloud extension data on the managed entity: changes_from_do_callConnector_with_headers_ew.
  • Source: changes.from.do.callConnector.with.headers.ew
  • Usage: workflow_update
entity.data.changes_from_do_callConnector_with_headers_ewe
  • Description: JumpCloud extension data on the managed entity: changes_from_do_callConnector_with_headers_ewe.
  • Source: changes.from.do.callConnector.with.headers.ewe
  • Usage: workflow_update
entity.data.changes_from_do_callConnector_with_httpMethod
  • Description: JumpCloud extension data on the managed entity: changes_from_do_callConnector_with_httpMethod.
  • Source: changes.from.do.callConnector.with.httpMethod
  • Usage: workflow_update
entity.data.changes_from_do_callConnector_with_id
  • Description: JumpCloud extension data on the managed entity: changes_from_do_callConnector_with_id.
  • Source: changes.from.do.callConnector.with.id
  • Usage: workflow_update
entity.data.changes_from_do_checkActivated_call
  • Description: JumpCloud extension data on the managed entity: changes_from_do_checkActivated_call.
  • Source: changes.from.do.checkActivated.call
  • Usage: workflow_update
entity.data.changes_from_do_checkActivated_if
  • Description: JumpCloud extension data on the managed entity: changes_from_do_checkActivated_if.
  • Source: changes.from.do.checkActivated.if
  • Usage: workflow_update
entity.data.changes_from_do_checkActivated_with_operationId
  • Description: JumpCloud extension data on the managed entity: changes_from_do_checkActivated_with_operationId.
  • Source: changes.from.do.checkActivated.with.operationId
  • Usage: workflow_update
entity.data.changes_from_do_checkActivated_with_pathParams_id
  • Description: JumpCloud extension data on the managed entity: changes_from_do_checkActivated_with_pathParams_id.
  • Source: changes.from.do.checkActivated.with.pathParams.id
  • Usage: workflow_update
entity.data.changes_from_do_checkActivated_with_queryParams_fields
  • Description: JumpCloud extension data on the managed entity: changes_from_do_checkActivated_with_queryParams_fields.
  • Source: changes.from.do.checkActivated.with.queryParams.fields
  • Usage: workflow_update
entity.data.changes_from_do_checkActivated_with_version
  • Description: JumpCloud extension data on the managed entity: changes_from_do_checkActivated_with_version.
  • Source: changes.from.do.checkActivated.with.version
  • Usage: workflow_update
entity.data.changes_from_do_checkDelegatedAuthorityExists_call
  • Description: JumpCloud extension data on the managed entity: changes_from_do_checkDelegatedAuthorityExists_call.
  • Source: changes.from.do.checkDelegatedAuthorityExists.call
  • Usage: workflow_update
entity.data.changes_from_do_checkDelegatedAuthorityExists_if
  • Description: JumpCloud extension data on the managed entity: changes_from_do_checkDelegatedAuthorityExists_if.
  • Source: changes.from.do.checkDelegatedAuthorityExists.if
  • Usage: workflow_update
entity.data.changes_from_do_checkDelegatedAuthorityExists_with_operationId
  • Description: JumpCloud extension data on the managed entity: changes_from_do_checkDelegatedAuthorityExists_with_operationId.
  • Source: changes.from.do.checkDelegatedAuthorityExists.with.operationId
  • Usage: workflow_update
entity.data.changes_from_do_checkDelegatedAuthorityExists_with_pathParams_id
  • Description: JumpCloud extension data on the managed entity: changes_from_do_checkDelegatedAuthorityExists_with_pathParams_id.
  • Source: changes.from.do.checkDelegatedAuthorityExists.with.pathParams.id
  • Usage: workflow_update
entity.data.changes_from_do_checkDelegatedAuthorityExists_with_queryParams_fields
  • Description: JumpCloud extension data on the managed entity: changes_from_do_checkDelegatedAuthorityExists_with_queryParams_fields.
  • Source: changes.from.do.checkDelegatedAuthorityExists.with.queryParams.fields
  • Usage: workflow_update
entity.data.changes_from_do_checkDelegatedAuthorityExists_with_version
  • Description: JumpCloud extension data on the managed entity: changes_from_do_checkDelegatedAuthorityExists_with_version.
  • Source: changes.from.do.checkDelegatedAuthorityExists.with.version
  • Usage: workflow_update
entity.data.changes_from_do_checkPasswordDate_call
  • Description: JumpCloud extension data on the managed entity: changes_from_do_checkPasswordDate_call.
  • Source: changes.from.do.checkPasswordDate.call
  • Usage: workflow_update
entity.data.changes_from_do_checkPasswordDate_if
  • Description: JumpCloud extension data on the managed entity: changes_from_do_checkPasswordDate_if.
  • Source: changes.from.do.checkPasswordDate.if
  • Usage: workflow_update
entity.data.changes_from_do_checkPasswordDate_with_operationId
  • Description: JumpCloud extension data on the managed entity: changes_from_do_checkPasswordDate_with_operationId.
  • Source: changes.from.do.checkPasswordDate.with.operationId
  • Usage: workflow_update
entity.data.changes_from_do_checkPasswordDate_with_pathParams_id
  • Description: JumpCloud extension data on the managed entity: changes_from_do_checkPasswordDate_with_pathParams_id.
  • Source: changes.from.do.checkPasswordDate.with.pathParams.id
  • Usage: workflow_update
entity.data.changes_from_do_checkPasswordDate_with_queryParams_fields
  • Description: JumpCloud extension data on the managed entity: changes_from_do_checkPasswordDate_with_queryParams_fields.
  • Source: changes.from.do.checkPasswordDate.with.queryParams.fields
  • Usage: workflow_update
entity.data.changes_from_do_checkPasswordDate_with_version
  • Description: JumpCloud extension data on the managed entity: changes_from_do_checkPasswordDate_with_version.
  • Source: changes.from.do.checkPasswordDate.with.version
  • Usage: workflow_update
entity.data.changes_from_do_getUser_call
  • Description: JumpCloud extension data on the managed entity: changes_from_do_getUser_call.
  • Source: changes.from.do.getUser.call
  • Usage: workflow_update
entity.data.changes_from_do_getUser_with_operationId
  • Description: JumpCloud extension data on the managed entity: changes_from_do_getUser_with_operationId.
  • Source: changes.from.do.getUser.with.operationId
  • Usage: workflow_update
entity.data.changes_from_do_getUser_with_pathParams_id
  • Description: JumpCloud extension data on the managed entity: changes_from_do_getUser_with_pathParams_id.
  • Source: changes.from.do.getUser.with.pathParams.id
  • Usage: workflow_update
entity.data.changes_from_do_getUser_with_version
  • Description: JumpCloud extension data on the managed entity: changes_from_do_getUser_with_version.
  • Source: changes.from.do.getUser.with.version
  • Usage: workflow_update
entity.data.changes_from_do_removeDelegatedAuthority_call
  • Description: JumpCloud extension data on the managed entity: changes_from_do_removeDelegatedAuthority_call.
  • Source: changes.from.do.removeDelegatedAuthority.call
  • Usage: workflow_update
entity.data.changes_from_do_removeDelegatedAuthority_if
  • Description: JumpCloud extension data on the managed entity: changes_from_do_removeDelegatedAuthority_if.
  • Source: changes.from.do.removeDelegatedAuthority.if
  • Usage: workflow_update
entity.data.changes_from_do_removeDelegatedAuthority_with_bodyParams_delegatedAuthority
  • Description: JumpCloud extension data on the managed entity: changes_from_do_removeDelegatedAuthority_with_bodyParams_delegatedAuthority.
  • Source: changes.from.do.removeDelegatedAuthority.with.bodyParams.delegatedAuthority
  • Usage: workflow_update
entity.data.changes_from_do_removeDelegatedAuthority_with_operationId
  • Description: JumpCloud extension data on the managed entity: changes_from_do_removeDelegatedAuthority_with_operationId.
  • Source: changes.from.do.removeDelegatedAuthority.with.operationId
  • Usage: workflow_update
entity.data.changes_from_do_removeDelegatedAuthority_with_pathParams_id
  • Description: JumpCloud extension data on the managed entity: changes_from_do_removeDelegatedAuthority_with_pathParams_id.
  • Source: changes.from.do.removeDelegatedAuthority.with.pathParams.id
  • Usage: workflow_update
entity.data.changes_from_do_removeDelegatedAuthority_with_version
  • Description: JumpCloud extension data on the managed entity: changes_from_do_removeDelegatedAuthority_with_version.
  • Source: changes.from.do.removeDelegatedAuthority.with.version
  • Usage: workflow_update
entity.data.changes_from_do_sendEmailAddresses_call
  • Description: JumpCloud extension data on the managed entity: changes_from_do_sendEmailAddresses_call.
  • Source: changes.from.do.sendEmailAddresses.call
  • Usage: workflow_update
entity.data.changes_from_do_sendEmailAddresses_with_message_body
  • Description: JumpCloud extension data on the managed entity: changes_from_do_sendEmailAddresses_with_message_body.
  • Source: changes.from.do.sendEmailAddresses.with.message.body
  • Usage: workflow_update
entity.data.changes_from_do_sendEmailAddresses_with_message_subject
  • Description: JumpCloud extension data on the managed entity: changes_from_do_sendEmailAddresses_with_message_subject.
  • Source: changes.from.do.sendEmailAddresses.with.message.subject
  • Usage: workflow_update
entity.data.changes_from_do_sendEmailAddresses_with_recipients_to_addresses
  • Description: JumpCloud extension data on the managed entity: changes_from_do_sendEmailAddresses_with_recipients_to_addresses.
  • Source: changes.from.do.sendEmailAddresses.with.recipients.to_addresses
  • Usage: workflow_update
entity.data.changes_from_do_systemusersGet_call
  • Description: JumpCloud extension data on the managed entity: changes_from_do_systemusersGet_call.
  • Source: changes.from.do.systemusersGet.call
  • Usage: workflow_update
entity.data.changes_from_do_systemusersGet_with_operationId
  • Description: JumpCloud extension data on the managed entity: changes_from_do_systemusersGet_with_operationId.
  • Source: changes.from.do.systemusersGet.with.operationId
  • Usage: workflow_update
entity.data.changes_from_do_systemusersGet_with_pathParams_id
  • Description: JumpCloud extension data on the managed entity: changes_from_do_systemusersGet_with_pathParams_id.
  • Source: changes.from.do.systemusersGet.with.pathParams.id
  • Usage: workflow_update
entity.data.changes_from_do_systemusersGet_with_queryParams_fields
  • Description: JumpCloud extension data on the managed entity: changes_from_do_systemusersGet_with_queryParams_fields.
  • Source: changes.from.do.systemusersGet.with.queryParams.fields
  • Usage: workflow_update
entity.data.changes_from_do_systemusersGet_with_version
  • Description: JumpCloud extension data on the managed entity: changes_from_do_systemusersGet_with_version.
  • Source: changes.from.do.systemusersGet.with.version
  • Usage: workflow_update
entity.data.changes_from_do_updateIsApproved_call
  • Description: JumpCloud extension data on the managed entity: changes_from_do_updateIsApproved_call.
  • Source: changes.from.do.updateIsApproved.call
  • Usage: workflow_update
entity.data.changes_from_do_updateIsApproved_if
  • Description: JumpCloud extension data on the managed entity: changes_from_do_updateIsApproved_if.
  • Source: changes.from.do.updateIsApproved.if
  • Usage: workflow_update
entity.data.changes_from_do_updateIsApproved_with_bodyParams_attributes
  • Description: JumpCloud extension data on the managed entity: changes_from_do_updateIsApproved_with_bodyParams_attributes.
  • Source: changes.from.do.updateIsApproved.with.bodyParams.attributes
  • Usage: workflow_update
entity.data.changes_from_do_updateIsApproved_with_operationId
  • Description: JumpCloud extension data on the managed entity: changes_from_do_updateIsApproved_with_operationId.
  • Source: changes.from.do.updateIsApproved.with.operationId
  • Usage: workflow_update
entity.data.changes_from_do_updateIsApproved_with_pathParams_id
  • Description: JumpCloud extension data on the managed entity: changes_from_do_updateIsApproved_with_pathParams_id.
  • Source: changes.from.do.updateIsApproved.with.pathParams.id
  • Usage: workflow_update
entity.data.changes_from_do_updateIsApproved_with_version
  • Description: JumpCloud extension data on the managed entity: changes_from_do_updateIsApproved_with_version.
  • Source: changes.from.do.updateIsApproved.with.version
  • Usage: workflow_update
entity.data.changes_from_schedule_frequency
  • Description: JumpCloud extension data on the managed entity: changes_from_schedule_frequency.
  • Source: changes.from.schedule.frequency
  • Usage: workflow_update
entity.data.changes_from_schedule_interval
  • Description: JumpCloud extension data on the managed entity: changes_from_schedule_interval.
  • Source: changes.from.schedule.interval
  • Usage: workflow_update
entity.data.changes_from_schedule_on_one_with_condition
  • Description: JumpCloud extension data on the managed entity: changes_from_schedule_on_one_with_condition.
  • Source: changes.from.schedule.on.one.with.condition
  • Usage: workflow_update
entity.data.changes_from_schedule_on_one_with_source
  • Description: JumpCloud extension data on the managed entity: changes_from_schedule_on_one_with_source.
  • Source: changes.from.schedule.on.one.with.source
  • Usage: workflow_update
entity.data.changes_from_schedule_on_one_with_type
  • Description: JumpCloud extension data on the managed entity: changes_from_schedule_on_one_with_type.
  • Source: changes.from.schedule.on.one.with.type
  • Usage: workflow_update
entity.data.changes_from_schedule_start_date
  • Description: JumpCloud extension data on the managed entity: changes_from_schedule_start_date.
  • Source: changes.from.schedule.start_date
  • Usage: workflow_update
entity.data.changes_from_schedule_start_time
  • Description: JumpCloud extension data on the managed entity: changes_from_schedule_start_time.
  • Source: changes.from.schedule.start_time
  • Usage: workflow_update
entity.data.changes_from_schedule_timezone
  • Description: JumpCloud extension data on the managed entity: changes_from_schedule_timezone.
  • Source: changes.from.schedule.timezone
  • Usage: workflow_update
entity.data.description
  • Description: JumpCloud extension data on the managed entity: description.
  • Source: resource.description
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.Fetch_User_Details.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.Fetch_User_Details.call.
  • Source: resource.dsl.do.Fetch_User_Details.call
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.Fetch_User_Details.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.Fetch_User_Details.with.operationId.
  • Source: resource.dsl.do.Fetch_User_Details.with.operationId
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.Fetch_User_Details.with.pathParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.Fetch_User_Details.with.pathParams.id.
  • Source: resource.dsl.do.Fetch_User_Details.with.pathParams.id
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.Fetch_User_Details.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.Fetch_User_Details.with.version.
  • Source: resource.dsl.do.Fetch_User_Details.with.version
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.Step1_UpdateCommand.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.Step1_UpdateCommand.call.
  • Source: resource.dsl.do.Step1_UpdateCommand.call
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.Step1_UpdateCommand.with.bodyParams.command
  • Description: JumpCloud extension data on the managed entity: dsl.do.Step1_UpdateCommand.with.bodyParams.command.
  • Source: resource.dsl.do.Step1_UpdateCommand.with.bodyParams.command
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.Step1_UpdateCommand.with.bodyParams.commandType
  • Description: JumpCloud extension data on the managed entity: dsl.do.Step1_UpdateCommand.with.bodyParams.commandType.
  • Source: resource.dsl.do.Step1_UpdateCommand.with.bodyParams.commandType
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.Step1_UpdateCommand.with.bodyParams.name
  • Description: JumpCloud extension data on the managed entity: dsl.do.Step1_UpdateCommand.with.bodyParams.name.
  • Source: resource.dsl.do.Step1_UpdateCommand.with.bodyParams.name
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.Step1_UpdateCommand.with.bodyParams.user
  • Description: JumpCloud extension data on the managed entity: dsl.do.Step1_UpdateCommand.with.bodyParams.user.
  • Source: resource.dsl.do.Step1_UpdateCommand.with.bodyParams.user
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.Step1_UpdateCommand.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.Step1_UpdateCommand.with.operationId.
  • Source: resource.dsl.do.Step1_UpdateCommand.with.operationId
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.Step1_UpdateCommand.with.pathParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.Step1_UpdateCommand.with.pathParams.id.
  • Source: resource.dsl.do.Step1_UpdateCommand.with.pathParams.id
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.Step1_UpdateCommand.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.Step1_UpdateCommand.with.version.
  • Source: resource.dsl.do.Step1_UpdateCommand.with.version
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.Step2_RunCommand.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.Step2_RunCommand.call.
  • Source: resource.dsl.do.Step2_RunCommand.call
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.Step2_RunCommand.with.bodyParams._id
  • Description: JumpCloud extension data on the managed entity: dsl.do.Step2_RunCommand.with.bodyParams._id.
  • Source: resource.dsl.do.Step2_RunCommand.with.bodyParams._id
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.Step2_RunCommand.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.Step2_RunCommand.with.operationId.
  • Source: resource.dsl.do.Step2_RunCommand.with.operationId
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.Step2_RunCommand.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.Step2_RunCommand.with.version.
  • Source: resource.dsl.do.Step2_RunCommand.with.version
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.accessWorkflowApiGetAccessWorkflow.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.accessWorkflowApiGetAccessWorkflow.call.
  • Source: resource.dsl.do.accessWorkflowApiGetAccessWorkflow.call
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.accessWorkflowApiGetAccessWorkflow.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.accessWorkflowApiGetAccessWorkflow.with.operationId.
  • Source: resource.dsl.do.accessWorkflowApiGetAccessWorkflow.with.operationId
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.accessWorkflowApiGetAccessWorkflow.with.pathParams.approvalFlowId
  • Description: JumpCloud extension data on the managed entity: dsl.do.accessWorkflowApiGetAccessWorkflow.with.pathParams.approvalFlowId.
  • Source: resource.dsl.do.accessWorkflowApiGetAccessWorkflow.with.pathParams.approvalFlowId
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.accessWorkflowApiGetAccessWorkflow.with.queryParams.organizationObjectId
  • Description: JumpCloud extension data on the managed entity: dsl.do.accessWorkflowApiGetAccessWorkflow.with.queryParams.organizationObjectId.
  • Source: resource.dsl.do.accessWorkflowApiGetAccessWorkflow.with.queryParams.organizationObjectId
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.accessWorkflowApiGetAccessWorkflow.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.accessWorkflowApiGetAccessWorkflow.with.version.
  • Source: resource.dsl.do.accessWorkflowApiGetAccessWorkflow.with.version
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.actionActivateUser.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionActivateUser.call.
  • Source: resource.dsl.do.actionActivateUser.call
  • Usage: workflow_delete
entity.data.dsl.do.actionActivateUser.metadata.displayLabels.user
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionActivateUser.metadata.displayLabels.user.
  • Source: resource.dsl.do.actionActivateUser.metadata.displayLabels.user
  • Usage: workflow_delete
entity.data.dsl.do.actionActivateUser.metadata.inputModes.user
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionActivateUser.metadata.inputModes.user.
  • Source: resource.dsl.do.actionActivateUser.metadata.inputModes.user
  • Usage: workflow_delete
entity.data.dsl.do.actionActivateUser.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionActivateUser.with.operationId.
  • Source: resource.dsl.do.actionActivateUser.with.operationId
  • Usage: workflow_delete
entity.data.dsl.do.actionActivateUser.with.pathParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionActivateUser.with.pathParams.id.
  • Source: resource.dsl.do.actionActivateUser.with.pathParams.id
  • Usage: workflow_delete
entity.data.dsl.do.actionActivateUser.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionActivateUser.with.version.
  • Source: resource.dsl.do.actionActivateUser.with.version
  • Usage: workflow_delete
entity.data.dsl.do.actionAddUserToUserGroup.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionAddUserToUserGroup.call.
  • Source: resource.dsl.do.actionAddUserToUserGroup.call
  • Usage: workflow_delete
entity.data.dsl.do.actionAddUserToUserGroup.metadata.displayLabels.user
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionAddUserToUserGroup.metadata.displayLabels.user.
  • Source: resource.dsl.do.actionAddUserToUserGroup.metadata.displayLabels.user
  • Usage: workflow_delete
entity.data.dsl.do.actionAddUserToUserGroup.metadata.displayLabels.userGroup
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionAddUserToUserGroup.metadata.displayLabels.userGroup.
  • Source: resource.dsl.do.actionAddUserToUserGroup.metadata.displayLabels.userGroup
  • Usage: workflow_delete
entity.data.dsl.do.actionAddUserToUserGroup.metadata.inputModes.user
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionAddUserToUserGroup.metadata.inputModes.user.
  • Source: resource.dsl.do.actionAddUserToUserGroup.metadata.inputModes.user
  • Usage: workflow_delete
entity.data.dsl.do.actionAddUserToUserGroup.metadata.inputModes.userGroup
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionAddUserToUserGroup.metadata.inputModes.userGroup.
  • Source: resource.dsl.do.actionAddUserToUserGroup.metadata.inputModes.userGroup
  • Usage: workflow_delete
entity.data.dsl.do.actionAddUserToUserGroup.with.bodyParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionAddUserToUserGroup.with.bodyParams.id.
  • Source: resource.dsl.do.actionAddUserToUserGroup.with.bodyParams.id
  • Usage: workflow_delete
entity.data.dsl.do.actionAddUserToUserGroup.with.bodyParams.op
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionAddUserToUserGroup.with.bodyParams.op.
  • Source: resource.dsl.do.actionAddUserToUserGroup.with.bodyParams.op
  • Usage: workflow_delete
entity.data.dsl.do.actionAddUserToUserGroup.with.bodyParams.type
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionAddUserToUserGroup.with.bodyParams.type.
  • Source: resource.dsl.do.actionAddUserToUserGroup.with.bodyParams.type
  • Usage: workflow_delete
entity.data.dsl.do.actionAddUserToUserGroup.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionAddUserToUserGroup.with.operationId.
  • Source: resource.dsl.do.actionAddUserToUserGroup.with.operationId
  • Usage: workflow_delete
entity.data.dsl.do.actionAddUserToUserGroup.with.pathParams.group_id
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionAddUserToUserGroup.with.pathParams.group_id.
  • Source: resource.dsl.do.actionAddUserToUserGroup.with.pathParams.group_id
  • Usage: workflow_delete
entity.data.dsl.do.actionAddUserToUserGroup.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionAddUserToUserGroup.with.version.
  • Source: resource.dsl.do.actionAddUserToUserGroup.with.version
  • Usage: workflow_delete
entity.data.dsl.do.actionAddUserToUserGroup_v2.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionAddUserToUserGroup_v2.call.
  • Source: resource.dsl.do.actionAddUserToUserGroup_v2.call
  • Usage: workflow_delete
entity.data.dsl.do.actionAddUserToUserGroup_v2.metadata.displayLabels.user
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionAddUserToUserGroup_v2.metadata.displayLabels.user.
  • Source: resource.dsl.do.actionAddUserToUserGroup_v2.metadata.displayLabels.user
  • Usage: workflow_delete
entity.data.dsl.do.actionAddUserToUserGroup_v2.metadata.displayLabels.userGroup
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionAddUserToUserGroup_v2.metadata.displayLabels.userGroup.
  • Source: resource.dsl.do.actionAddUserToUserGroup_v2.metadata.displayLabels.userGroup
  • Usage: workflow_delete
entity.data.dsl.do.actionAddUserToUserGroup_v2.metadata.inputModes.user
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionAddUserToUserGroup_v2.metadata.inputModes.user.
  • Source: resource.dsl.do.actionAddUserToUserGroup_v2.metadata.inputModes.user
  • Usage: workflow_delete
entity.data.dsl.do.actionAddUserToUserGroup_v2.metadata.inputModes.userGroup
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionAddUserToUserGroup_v2.metadata.inputModes.userGroup.
  • Source: resource.dsl.do.actionAddUserToUserGroup_v2.metadata.inputModes.userGroup
  • Usage: workflow_delete
entity.data.dsl.do.actionAddUserToUserGroup_v2.with.bodyParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionAddUserToUserGroup_v2.with.bodyParams.id.
  • Source: resource.dsl.do.actionAddUserToUserGroup_v2.with.bodyParams.id
  • Usage: workflow_delete
entity.data.dsl.do.actionAddUserToUserGroup_v2.with.bodyParams.op
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionAddUserToUserGroup_v2.with.bodyParams.op.
  • Source: resource.dsl.do.actionAddUserToUserGroup_v2.with.bodyParams.op
  • Usage: workflow_delete
entity.data.dsl.do.actionAddUserToUserGroup_v2.with.bodyParams.type
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionAddUserToUserGroup_v2.with.bodyParams.type.
  • Source: resource.dsl.do.actionAddUserToUserGroup_v2.with.bodyParams.type
  • Usage: workflow_delete
entity.data.dsl.do.actionAddUserToUserGroup_v2.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionAddUserToUserGroup_v2.with.operationId.
  • Source: resource.dsl.do.actionAddUserToUserGroup_v2.with.operationId
  • Usage: workflow_delete
entity.data.dsl.do.actionAddUserToUserGroup_v2.with.pathParams.group_id
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionAddUserToUserGroup_v2.with.pathParams.group_id.
  • Source: resource.dsl.do.actionAddUserToUserGroup_v2.with.pathParams.group_id
  • Usage: workflow_delete
entity.data.dsl.do.actionAddUserToUserGroup_v2.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionAddUserToUserGroup_v2.with.version.
  • Source: resource.dsl.do.actionAddUserToUserGroup_v2.with.version
  • Usage: workflow_delete
entity.data.dsl.do.actionEraseDevice.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionEraseDevice.call.
  • Source: resource.dsl.do.actionEraseDevice.call
  • Usage: workflow_delete
entity.data.dsl.do.actionEraseDevice.metadata.displayLabels.device
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionEraseDevice.metadata.displayLabels.device.
  • Source: resource.dsl.do.actionEraseDevice.metadata.displayLabels.device
  • Usage: workflow_delete
entity.data.dsl.do.actionEraseDevice.metadata.inputModes.device
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionEraseDevice.metadata.inputModes.device.
  • Source: resource.dsl.do.actionEraseDevice.metadata.inputModes.device
  • Usage: workflow_delete
entity.data.dsl.do.actionEraseDevice.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionEraseDevice.with.operationId.
  • Source: resource.dsl.do.actionEraseDevice.with.operationId
  • Usage: workflow_delete
entity.data.dsl.do.actionEraseDevice.with.pathParams.system_id
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionEraseDevice.with.pathParams.system_id.
  • Source: resource.dsl.do.actionEraseDevice.with.pathParams.system_id
  • Usage: workflow_delete
entity.data.dsl.do.actionEraseDevice.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionEraseDevice.with.version.
  • Source: resource.dsl.do.actionEraseDevice.with.version
  • Usage: workflow_delete
entity.data.dsl.do.actionReactivateUser.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionReactivateUser.call.
  • Source: resource.dsl.do.actionReactivateUser.call
  • Usage: workflow_delete
entity.data.dsl.do.actionReactivateUser.metadata.displayLabels.user
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionReactivateUser.metadata.displayLabels.user.
  • Source: resource.dsl.do.actionReactivateUser.metadata.displayLabels.user
  • Usage: workflow_delete
entity.data.dsl.do.actionReactivateUser.metadata.inputModes.user
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionReactivateUser.metadata.inputModes.user.
  • Source: resource.dsl.do.actionReactivateUser.metadata.inputModes.user
  • Usage: workflow_delete
entity.data.dsl.do.actionReactivateUser.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionReactivateUser.with.operationId.
  • Source: resource.dsl.do.actionReactivateUser.with.operationId
  • Usage: workflow_delete
entity.data.dsl.do.actionReactivateUser.with.pathParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionReactivateUser.with.pathParams.id.
  • Source: resource.dsl.do.actionReactivateUser.with.pathParams.id
  • Usage: workflow_delete
entity.data.dsl.do.actionReactivateUser.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionReactivateUser.with.version.
  • Source: resource.dsl.do.actionReactivateUser.with.version
  • Usage: workflow_delete
entity.data.dsl.do.actionRemoveUserFromUserGroup.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionRemoveUserFromUserGroup.call.
  • Source: resource.dsl.do.actionRemoveUserFromUserGroup.call
  • Usage: workflow_delete
entity.data.dsl.do.actionRemoveUserFromUserGroup.metadata.displayLabels.user
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionRemoveUserFromUserGroup.metadata.displayLabels.user.
  • Source: resource.dsl.do.actionRemoveUserFromUserGroup.metadata.displayLabels.user
  • Usage: workflow_delete
entity.data.dsl.do.actionRemoveUserFromUserGroup.metadata.displayLabels.userGroup
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionRemoveUserFromUserGroup.metadata.displayLabels.userGroup.
  • Source: resource.dsl.do.actionRemoveUserFromUserGroup.metadata.displayLabels.userGroup
  • Usage: workflow_delete
entity.data.dsl.do.actionRemoveUserFromUserGroup.metadata.inputModes.user
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionRemoveUserFromUserGroup.metadata.inputModes.user.
  • Source: resource.dsl.do.actionRemoveUserFromUserGroup.metadata.inputModes.user
  • Usage: workflow_delete
entity.data.dsl.do.actionRemoveUserFromUserGroup.metadata.inputModes.userGroup
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionRemoveUserFromUserGroup.metadata.inputModes.userGroup.
  • Source: resource.dsl.do.actionRemoveUserFromUserGroup.metadata.inputModes.userGroup
  • Usage: workflow_delete
entity.data.dsl.do.actionRemoveUserFromUserGroup.with.bodyParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionRemoveUserFromUserGroup.with.bodyParams.id.
  • Source: resource.dsl.do.actionRemoveUserFromUserGroup.with.bodyParams.id
  • Usage: workflow_delete
entity.data.dsl.do.actionRemoveUserFromUserGroup.with.bodyParams.op
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionRemoveUserFromUserGroup.with.bodyParams.op.
  • Source: resource.dsl.do.actionRemoveUserFromUserGroup.with.bodyParams.op
  • Usage: workflow_delete
entity.data.dsl.do.actionRemoveUserFromUserGroup.with.bodyParams.type
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionRemoveUserFromUserGroup.with.bodyParams.type.
  • Source: resource.dsl.do.actionRemoveUserFromUserGroup.with.bodyParams.type
  • Usage: workflow_delete
entity.data.dsl.do.actionRemoveUserFromUserGroup.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionRemoveUserFromUserGroup.with.operationId.
  • Source: resource.dsl.do.actionRemoveUserFromUserGroup.with.operationId
  • Usage: workflow_delete
entity.data.dsl.do.actionRemoveUserFromUserGroup.with.pathParams.group_id
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionRemoveUserFromUserGroup.with.pathParams.group_id.
  • Source: resource.dsl.do.actionRemoveUserFromUserGroup.with.pathParams.group_id
  • Usage: workflow_delete
entity.data.dsl.do.actionRemoveUserFromUserGroup.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionRemoveUserFromUserGroup.with.version.
  • Source: resource.dsl.do.actionRemoveUserFromUserGroup.with.version
  • Usage: workflow_delete
entity.data.dsl.do.actionRunCommandOnDevice.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionRunCommandOnDevice.call.
  • Source: resource.dsl.do.actionRunCommandOnDevice.call
  • Usage: workflow_delete
entity.data.dsl.do.actionRunCommandOnDevice.metadata.displayLabels.command
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionRunCommandOnDevice.metadata.displayLabels.command.
  • Source: resource.dsl.do.actionRunCommandOnDevice.metadata.displayLabels.command
  • Usage: workflow_delete
entity.data.dsl.do.actionRunCommandOnDevice.metadata.displayLabels.devices
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionRunCommandOnDevice.metadata.displayLabels.devices.
  • Source: resource.dsl.do.actionRunCommandOnDevice.metadata.displayLabels.devices
  • Usage: workflow_delete
entity.data.dsl.do.actionRunCommandOnDevice.metadata.inputModes.command
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionRunCommandOnDevice.metadata.inputModes.command.
  • Source: resource.dsl.do.actionRunCommandOnDevice.metadata.inputModes.command
  • Usage: workflow_delete
entity.data.dsl.do.actionRunCommandOnDevice.metadata.inputModes.devices
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionRunCommandOnDevice.metadata.inputModes.devices.
  • Source: resource.dsl.do.actionRunCommandOnDevice.metadata.inputModes.devices
  • Usage: workflow_delete
entity.data.dsl.do.actionRunCommandOnDevice.with.bodyParams._id
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionRunCommandOnDevice.with.bodyParams._id.
  • Source: resource.dsl.do.actionRunCommandOnDevice.with.bodyParams._id
  • Usage: workflow_delete
entity.data.dsl.do.actionRunCommandOnDevice.with.bodyParams.systemIds
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionRunCommandOnDevice.with.bodyParams.systemIds.
  • Source: resource.dsl.do.actionRunCommandOnDevice.with.bodyParams.systemIds
  • Usage: workflow_delete
entity.data.dsl.do.actionRunCommandOnDevice.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionRunCommandOnDevice.with.operationId.
  • Source: resource.dsl.do.actionRunCommandOnDevice.with.operationId
  • Usage: workflow_delete
entity.data.dsl.do.actionRunCommandOnDevice.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.actionRunCommandOnDevice.with.version.
  • Source: resource.dsl.do.actionRunCommandOnDevice.with.version
  • Usage: workflow_delete
entity.data.dsl.do.activateUser.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser.call.
  • Source: resource.dsl.do.activateUser.call
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.activateUser.metadata.displayLabels.email
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser.metadata.displayLabels.email.
  • Source: resource.dsl.do.activateUser.metadata.displayLabels.email
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.activateUser.metadata.displayLabels.user
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser.metadata.displayLabels.user.
  • Source: resource.dsl.do.activateUser.metadata.displayLabels.user
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.activateUser.metadata.inputModes.email
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser.metadata.inputModes.email.
  • Source: resource.dsl.do.activateUser.metadata.inputModes.email
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.activateUser.metadata.inputModes.user
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser.metadata.inputModes.user.
  • Source: resource.dsl.do.activateUser.metadata.inputModes.user
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.activateUser.with.bodyParams.email
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser.with.bodyParams.email.
  • Source: resource.dsl.do.activateUser.with.bodyParams.email
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.activateUser.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser.with.operationId.
  • Source: resource.dsl.do.activateUser.with.operationId
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.activateUser.with.pathParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser.with.pathParams.id.
  • Source: resource.dsl.do.activateUser.with.pathParams.id
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.activateUser.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser.with.version.
  • Source: resource.dsl.do.activateUser.with.version
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.activateUser2.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser2.call.
  • Source: resource.dsl.do.activateUser2.call
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.activateUser2.metadata.displayLabels.email
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser2.metadata.displayLabels.email.
  • Source: resource.dsl.do.activateUser2.metadata.displayLabels.email
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.activateUser2.metadata.displayLabels.user
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser2.metadata.displayLabels.user.
  • Source: resource.dsl.do.activateUser2.metadata.displayLabels.user
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.activateUser2.metadata.inputModes.email
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser2.metadata.inputModes.email.
  • Source: resource.dsl.do.activateUser2.metadata.inputModes.email
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.activateUser2.metadata.inputModes.user
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser2.metadata.inputModes.user.
  • Source: resource.dsl.do.activateUser2.metadata.inputModes.user
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.activateUser2.with.bodyParams.email
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser2.with.bodyParams.email.
  • Source: resource.dsl.do.activateUser2.with.bodyParams.email
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.activateUser2.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser2.with.operationId.
  • Source: resource.dsl.do.activateUser2.with.operationId
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.activateUser2.with.pathParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser2.with.pathParams.id.
  • Source: resource.dsl.do.activateUser2.with.pathParams.id
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.activateUser2.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser2.with.version.
  • Source: resource.dsl.do.activateUser2.with.version
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.activateUser3.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser3.call.
  • Source: resource.dsl.do.activateUser3.call
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser3.metadata.displayLabels.email
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser3.metadata.displayLabels.email.
  • Source: resource.dsl.do.activateUser3.metadata.displayLabels.email
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser3.metadata.displayLabels.user
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser3.metadata.displayLabels.user.
  • Source: resource.dsl.do.activateUser3.metadata.displayLabels.user
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser3.metadata.inputModes.email
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser3.metadata.inputModes.email.
  • Source: resource.dsl.do.activateUser3.metadata.inputModes.email
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser3.metadata.inputModes.user
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser3.metadata.inputModes.user.
  • Source: resource.dsl.do.activateUser3.metadata.inputModes.user
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser3.with.bodyParams.email
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser3.with.bodyParams.email.
  • Source: resource.dsl.do.activateUser3.with.bodyParams.email
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser3.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser3.with.operationId.
  • Source: resource.dsl.do.activateUser3.with.operationId
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser3.with.pathParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser3.with.pathParams.id.
  • Source: resource.dsl.do.activateUser3.with.pathParams.id
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser3.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser3.with.version.
  • Source: resource.dsl.do.activateUser3.with.version
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser4.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser4.call.
  • Source: resource.dsl.do.activateUser4.call
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser4.metadata.displayLabels.email
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser4.metadata.displayLabels.email.
  • Source: resource.dsl.do.activateUser4.metadata.displayLabels.email
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser4.metadata.displayLabels.user
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser4.metadata.displayLabels.user.
  • Source: resource.dsl.do.activateUser4.metadata.displayLabels.user
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser4.metadata.inputModes.email
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser4.metadata.inputModes.email.
  • Source: resource.dsl.do.activateUser4.metadata.inputModes.email
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser4.metadata.inputModes.user
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser4.metadata.inputModes.user.
  • Source: resource.dsl.do.activateUser4.metadata.inputModes.user
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser4.with.bodyParams.email
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser4.with.bodyParams.email.
  • Source: resource.dsl.do.activateUser4.with.bodyParams.email
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser4.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser4.with.operationId.
  • Source: resource.dsl.do.activateUser4.with.operationId
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser4.with.pathParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser4.with.pathParams.id.
  • Source: resource.dsl.do.activateUser4.with.pathParams.id
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser4.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser4.with.version.
  • Source: resource.dsl.do.activateUser4.with.version
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser5.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser5.call.
  • Source: resource.dsl.do.activateUser5.call
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser5.metadata.displayLabels.email
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser5.metadata.displayLabels.email.
  • Source: resource.dsl.do.activateUser5.metadata.displayLabels.email
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser5.metadata.displayLabels.user
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser5.metadata.displayLabels.user.
  • Source: resource.dsl.do.activateUser5.metadata.displayLabels.user
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser5.metadata.inputModes.email
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser5.metadata.inputModes.email.
  • Source: resource.dsl.do.activateUser5.metadata.inputModes.email
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser5.metadata.inputModes.user
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser5.metadata.inputModes.user.
  • Source: resource.dsl.do.activateUser5.metadata.inputModes.user
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser5.with.bodyParams.email
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser5.with.bodyParams.email.
  • Source: resource.dsl.do.activateUser5.with.bodyParams.email
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser5.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser5.with.operationId.
  • Source: resource.dsl.do.activateUser5.with.operationId
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser5.with.pathParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser5.with.pathParams.id.
  • Source: resource.dsl.do.activateUser5.with.pathParams.id
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser5.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser5.with.version.
  • Source: resource.dsl.do.activateUser5.with.version
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser6.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser6.call.
  • Source: resource.dsl.do.activateUser6.call
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser6.metadata.displayLabels.email
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser6.metadata.displayLabels.email.
  • Source: resource.dsl.do.activateUser6.metadata.displayLabels.email
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser6.metadata.displayLabels.user
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser6.metadata.displayLabels.user.
  • Source: resource.dsl.do.activateUser6.metadata.displayLabels.user
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser6.metadata.inputModes.email
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser6.metadata.inputModes.email.
  • Source: resource.dsl.do.activateUser6.metadata.inputModes.email
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser6.metadata.inputModes.user
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser6.metadata.inputModes.user.
  • Source: resource.dsl.do.activateUser6.metadata.inputModes.user
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser6.with.bodyParams.email
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser6.with.bodyParams.email.
  • Source: resource.dsl.do.activateUser6.with.bodyParams.email
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser6.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser6.with.operationId.
  • Source: resource.dsl.do.activateUser6.with.operationId
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser6.with.pathParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser6.with.pathParams.id.
  • Source: resource.dsl.do.activateUser6.with.pathParams.id
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser6.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser6.with.version.
  • Source: resource.dsl.do.activateUser6.with.version
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser7.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser7.call.
  • Source: resource.dsl.do.activateUser7.call
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser7.metadata.displayLabels.email
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser7.metadata.displayLabels.email.
  • Source: resource.dsl.do.activateUser7.metadata.displayLabels.email
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser7.metadata.displayLabels.user
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser7.metadata.displayLabels.user.
  • Source: resource.dsl.do.activateUser7.metadata.displayLabels.user
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser7.metadata.inputModes.email
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser7.metadata.inputModes.email.
  • Source: resource.dsl.do.activateUser7.metadata.inputModes.email
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser7.metadata.inputModes.user
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser7.metadata.inputModes.user.
  • Source: resource.dsl.do.activateUser7.metadata.inputModes.user
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser7.with.bodyParams.email
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser7.with.bodyParams.email.
  • Source: resource.dsl.do.activateUser7.with.bodyParams.email
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser7.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser7.with.operationId.
  • Source: resource.dsl.do.activateUser7.with.operationId
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser7.with.pathParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser7.with.pathParams.id.
  • Source: resource.dsl.do.activateUser7.with.pathParams.id
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser7.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser7.with.version.
  • Source: resource.dsl.do.activateUser7.with.version
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser8.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser8.call.
  • Source: resource.dsl.do.activateUser8.call
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser8.metadata.displayLabels.email
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser8.metadata.displayLabels.email.
  • Source: resource.dsl.do.activateUser8.metadata.displayLabels.email
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser8.metadata.displayLabels.user
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser8.metadata.displayLabels.user.
  • Source: resource.dsl.do.activateUser8.metadata.displayLabels.user
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser8.metadata.inputModes.email
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser8.metadata.inputModes.email.
  • Source: resource.dsl.do.activateUser8.metadata.inputModes.email
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser8.metadata.inputModes.user
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser8.metadata.inputModes.user.
  • Source: resource.dsl.do.activateUser8.metadata.inputModes.user
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser8.with.bodyParams.email
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser8.with.bodyParams.email.
  • Source: resource.dsl.do.activateUser8.with.bodyParams.email
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser8.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser8.with.operationId.
  • Source: resource.dsl.do.activateUser8.with.operationId
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser8.with.pathParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser8.with.pathParams.id.
  • Source: resource.dsl.do.activateUser8.with.pathParams.id
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser8.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.activateUser8.with.version.
  • Source: resource.dsl.do.activateUser8.with.version
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.activedirectoriesTranslationRules_recommendations.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.activedirectoriesTranslationRules_recommendations.call.
  • Source: resource.dsl.do.activedirectoriesTranslationRules_recommendations.call
  • Usage: workflow_delete
entity.data.dsl.do.activedirectoriesTranslationRules_recommendations.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.activedirectoriesTranslationRules_recommendations.with.operationId.
  • Source: resource.dsl.do.activedirectoriesTranslationRules_recommendations.with.operationId
  • Usage: workflow_delete
entity.data.dsl.do.activedirectoriesTranslationRules_recommendations.with.pathParams.provider_name
  • Description: JumpCloud extension data on the managed entity: dsl.do.activedirectoriesTranslationRules_recommendations.with.pathParams.provider_name.
  • Source: resource.dsl.do.activedirectoriesTranslationRules_recommendations.with.pathParams.provider_name
  • Usage: workflow_delete
entity.data.dsl.do.activedirectoriesTranslationRules_recommendations.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.activedirectoriesTranslationRules_recommendations.with.version.
  • Source: resource.dsl.do.activedirectoriesTranslationRules_recommendations.with.version
  • Usage: workflow_delete
entity.data.dsl.do.addDepartmentGroup1.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDepartmentGroup1.call.
  • Source: resource.dsl.do.addDepartmentGroup1.call
  • Usage: workflow_create, workflow_update
entity.data.dsl.do.addDepartmentGroup1.with.bodyParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDepartmentGroup1.with.bodyParams.id.
  • Source: resource.dsl.do.addDepartmentGroup1.with.bodyParams.id
  • Usage: workflow_create, workflow_update
entity.data.dsl.do.addDepartmentGroup1.with.bodyParams.op
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDepartmentGroup1.with.bodyParams.op.
  • Source: resource.dsl.do.addDepartmentGroup1.with.bodyParams.op
  • Usage: workflow_create, workflow_update
entity.data.dsl.do.addDepartmentGroup1.with.bodyParams.type
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDepartmentGroup1.with.bodyParams.type.
  • Source: resource.dsl.do.addDepartmentGroup1.with.bodyParams.type
  • Usage: workflow_create, workflow_update
entity.data.dsl.do.addDepartmentGroup1.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDepartmentGroup1.with.operationId.
  • Source: resource.dsl.do.addDepartmentGroup1.with.operationId
  • Usage: workflow_create, workflow_update
entity.data.dsl.do.addDepartmentGroup1.with.pathParams.group_id
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDepartmentGroup1.with.pathParams.group_id.
  • Source: resource.dsl.do.addDepartmentGroup1.with.pathParams.group_id
  • Usage: workflow_create, workflow_update
entity.data.dsl.do.addDepartmentGroup1.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDepartmentGroup1.with.version.
  • Source: resource.dsl.do.addDepartmentGroup1.with.version
  • Usage: workflow_create, workflow_update
entity.data.dsl.do.addDepartmentGroup2.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDepartmentGroup2.call.
  • Source: resource.dsl.do.addDepartmentGroup2.call
  • Usage: workflow_create, workflow_update
entity.data.dsl.do.addDepartmentGroup2.with.bodyParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDepartmentGroup2.with.bodyParams.id.
  • Source: resource.dsl.do.addDepartmentGroup2.with.bodyParams.id
  • Usage: workflow_create, workflow_update
entity.data.dsl.do.addDepartmentGroup2.with.bodyParams.op
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDepartmentGroup2.with.bodyParams.op.
  • Source: resource.dsl.do.addDepartmentGroup2.with.bodyParams.op
  • Usage: workflow_create, workflow_update
entity.data.dsl.do.addDepartmentGroup2.with.bodyParams.type
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDepartmentGroup2.with.bodyParams.type.
  • Source: resource.dsl.do.addDepartmentGroup2.with.bodyParams.type
  • Usage: workflow_create, workflow_update
entity.data.dsl.do.addDepartmentGroup2.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDepartmentGroup2.with.operationId.
  • Source: resource.dsl.do.addDepartmentGroup2.with.operationId
  • Usage: workflow_create, workflow_update
entity.data.dsl.do.addDepartmentGroup2.with.pathParams.group_id
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDepartmentGroup2.with.pathParams.group_id.
  • Source: resource.dsl.do.addDepartmentGroup2.with.pathParams.group_id
  • Usage: workflow_create, workflow_update
entity.data.dsl.do.addDepartmentGroup2.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDepartmentGroup2.with.version.
  • Source: resource.dsl.do.addDepartmentGroup2.with.version
  • Usage: workflow_create, workflow_update
entity.data.dsl.do.addDepartmentGroup3.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDepartmentGroup3.call.
  • Source: resource.dsl.do.addDepartmentGroup3.call
  • Usage: workflow_create, workflow_update
entity.data.dsl.do.addDepartmentGroup3.with.bodyParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDepartmentGroup3.with.bodyParams.id.
  • Source: resource.dsl.do.addDepartmentGroup3.with.bodyParams.id
  • Usage: workflow_create, workflow_update
entity.data.dsl.do.addDepartmentGroup3.with.bodyParams.op
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDepartmentGroup3.with.bodyParams.op.
  • Source: resource.dsl.do.addDepartmentGroup3.with.bodyParams.op
  • Usage: workflow_create, workflow_update
entity.data.dsl.do.addDepartmentGroup3.with.bodyParams.type
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDepartmentGroup3.with.bodyParams.type.
  • Source: resource.dsl.do.addDepartmentGroup3.with.bodyParams.type
  • Usage: workflow_create, workflow_update
entity.data.dsl.do.addDepartmentGroup3.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDepartmentGroup3.with.operationId.
  • Source: resource.dsl.do.addDepartmentGroup3.with.operationId
  • Usage: workflow_create, workflow_update
entity.data.dsl.do.addDepartmentGroup3.with.pathParams.group_id
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDepartmentGroup3.with.pathParams.group_id.
  • Source: resource.dsl.do.addDepartmentGroup3.with.pathParams.group_id
  • Usage: workflow_create, workflow_update
entity.data.dsl.do.addDepartmentGroup3.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDepartmentGroup3.with.version.
  • Source: resource.dsl.do.addDepartmentGroup3.with.version
  • Usage: workflow_create, workflow_update
entity.data.dsl.do.addDeviceToDeviceGroup.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDeviceToDeviceGroup.call.
  • Source: resource.dsl.do.addDeviceToDeviceGroup.call
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup.metadata.displayLabels.device
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDeviceToDeviceGroup.metadata.displayLabels.device.
  • Source: resource.dsl.do.addDeviceToDeviceGroup.metadata.displayLabels.device
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup.metadata.displayLabels.deviceGroup
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDeviceToDeviceGroup.metadata.displayLabels.deviceGroup.
  • Source: resource.dsl.do.addDeviceToDeviceGroup.metadata.displayLabels.deviceGroup
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup.metadata.inputModes.device
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDeviceToDeviceGroup.metadata.inputModes.device.
  • Source: resource.dsl.do.addDeviceToDeviceGroup.metadata.inputModes.device
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup.metadata.inputModes.deviceGroup
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDeviceToDeviceGroup.metadata.inputModes.deviceGroup.
  • Source: resource.dsl.do.addDeviceToDeviceGroup.metadata.inputModes.deviceGroup
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDeviceToDeviceGroup.then.
  • Source: resource.dsl.do.addDeviceToDeviceGroup.then
  • Usage: workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup.with.bodyParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDeviceToDeviceGroup.with.bodyParams.id.
  • Source: resource.dsl.do.addDeviceToDeviceGroup.with.bodyParams.id
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup.with.bodyParams.op
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDeviceToDeviceGroup.with.bodyParams.op.
  • Source: resource.dsl.do.addDeviceToDeviceGroup.with.bodyParams.op
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup.with.bodyParams.type
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDeviceToDeviceGroup.with.bodyParams.type.
  • Source: resource.dsl.do.addDeviceToDeviceGroup.with.bodyParams.type
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDeviceToDeviceGroup.with.operationId.
  • Source: resource.dsl.do.addDeviceToDeviceGroup.with.operationId
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup.with.pathParams.group_id
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDeviceToDeviceGroup.with.pathParams.group_id.
  • Source: resource.dsl.do.addDeviceToDeviceGroup.with.pathParams.group_id
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDeviceToDeviceGroup.with.version.
  • Source: resource.dsl.do.addDeviceToDeviceGroup.with.version
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup2.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDeviceToDeviceGroup2.call.
  • Source: resource.dsl.do.addDeviceToDeviceGroup2.call
  • Usage: workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup2.metadata.displayLabels.device
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDeviceToDeviceGroup2.metadata.displayLabels.device.
  • Source: resource.dsl.do.addDeviceToDeviceGroup2.metadata.displayLabels.device
  • Usage: workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup2.metadata.displayLabels.deviceGroup
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDeviceToDeviceGroup2.metadata.displayLabels.deviceGroup.
  • Source: resource.dsl.do.addDeviceToDeviceGroup2.metadata.displayLabels.deviceGroup
  • Usage: workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup2.metadata.inputModes.device
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDeviceToDeviceGroup2.metadata.inputModes.device.
  • Source: resource.dsl.do.addDeviceToDeviceGroup2.metadata.inputModes.device
  • Usage: workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup2.metadata.inputModes.deviceGroup
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDeviceToDeviceGroup2.metadata.inputModes.deviceGroup.
  • Source: resource.dsl.do.addDeviceToDeviceGroup2.metadata.inputModes.deviceGroup
  • Usage: workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup2.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDeviceToDeviceGroup2.then.
  • Source: resource.dsl.do.addDeviceToDeviceGroup2.then
  • Usage: workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup2.with.bodyParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDeviceToDeviceGroup2.with.bodyParams.id.
  • Source: resource.dsl.do.addDeviceToDeviceGroup2.with.bodyParams.id
  • Usage: workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup2.with.bodyParams.op
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDeviceToDeviceGroup2.with.bodyParams.op.
  • Source: resource.dsl.do.addDeviceToDeviceGroup2.with.bodyParams.op
  • Usage: workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup2.with.bodyParams.type
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDeviceToDeviceGroup2.with.bodyParams.type.
  • Source: resource.dsl.do.addDeviceToDeviceGroup2.with.bodyParams.type
  • Usage: workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup2.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDeviceToDeviceGroup2.with.operationId.
  • Source: resource.dsl.do.addDeviceToDeviceGroup2.with.operationId
  • Usage: workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup2.with.pathParams.group_id
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDeviceToDeviceGroup2.with.pathParams.group_id.
  • Source: resource.dsl.do.addDeviceToDeviceGroup2.with.pathParams.group_id
  • Usage: workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup2.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDeviceToDeviceGroup2.with.version.
  • Source: resource.dsl.do.addDeviceToDeviceGroup2.with.version
  • Usage: workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup3.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDeviceToDeviceGroup3.call.
  • Source: resource.dsl.do.addDeviceToDeviceGroup3.call
  • Usage: workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup3.metadata.displayLabels.device
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDeviceToDeviceGroup3.metadata.displayLabels.device.
  • Source: resource.dsl.do.addDeviceToDeviceGroup3.metadata.displayLabels.device
  • Usage: workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup3.metadata.displayLabels.deviceGroup
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDeviceToDeviceGroup3.metadata.displayLabels.deviceGroup.
  • Source: resource.dsl.do.addDeviceToDeviceGroup3.metadata.displayLabels.deviceGroup
  • Usage: workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup3.metadata.inputModes.device
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDeviceToDeviceGroup3.metadata.inputModes.device.
  • Source: resource.dsl.do.addDeviceToDeviceGroup3.metadata.inputModes.device
  • Usage: workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup3.metadata.inputModes.deviceGroup
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDeviceToDeviceGroup3.metadata.inputModes.deviceGroup.
  • Source: resource.dsl.do.addDeviceToDeviceGroup3.metadata.inputModes.deviceGroup
  • Usage: workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup3.with.bodyParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDeviceToDeviceGroup3.with.bodyParams.id.
  • Source: resource.dsl.do.addDeviceToDeviceGroup3.with.bodyParams.id
  • Usage: workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup3.with.bodyParams.op
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDeviceToDeviceGroup3.with.bodyParams.op.
  • Source: resource.dsl.do.addDeviceToDeviceGroup3.with.bodyParams.op
  • Usage: workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup3.with.bodyParams.type
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDeviceToDeviceGroup3.with.bodyParams.type.
  • Source: resource.dsl.do.addDeviceToDeviceGroup3.with.bodyParams.type
  • Usage: workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup3.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDeviceToDeviceGroup3.with.operationId.
  • Source: resource.dsl.do.addDeviceToDeviceGroup3.with.operationId
  • Usage: workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup3.with.pathParams.group_id
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDeviceToDeviceGroup3.with.pathParams.group_id.
  • Source: resource.dsl.do.addDeviceToDeviceGroup3.with.pathParams.group_id
  • Usage: workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup3.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.addDeviceToDeviceGroup3.with.version.
  • Source: resource.dsl.do.addDeviceToDeviceGroup3.with.version
  • Usage: workflow_delete
entity.data.dsl.do.addToElevatedGroup.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.addToElevatedGroup.call.
  • Source: resource.dsl.do.addToElevatedGroup.call
  • Usage: workflow_delete
entity.data.dsl.do.addToElevatedGroup.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.addToElevatedGroup.then.
  • Source: resource.dsl.do.addToElevatedGroup.then
  • Usage: workflow_delete
entity.data.dsl.do.addToElevatedGroup.with.bodyParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.addToElevatedGroup.with.bodyParams.id.
  • Source: resource.dsl.do.addToElevatedGroup.with.bodyParams.id
  • Usage: workflow_delete
entity.data.dsl.do.addToElevatedGroup.with.bodyParams.op
  • Description: JumpCloud extension data on the managed entity: dsl.do.addToElevatedGroup.with.bodyParams.op.
  • Source: resource.dsl.do.addToElevatedGroup.with.bodyParams.op
  • Usage: workflow_delete
entity.data.dsl.do.addToElevatedGroup.with.bodyParams.type
  • Description: JumpCloud extension data on the managed entity: dsl.do.addToElevatedGroup.with.bodyParams.type.
  • Source: resource.dsl.do.addToElevatedGroup.with.bodyParams.type
  • Usage: workflow_delete
entity.data.dsl.do.addToElevatedGroup.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.addToElevatedGroup.with.operationId.
  • Source: resource.dsl.do.addToElevatedGroup.with.operationId
  • Usage: workflow_delete
entity.data.dsl.do.addToElevatedGroup.with.pathParams.group_id
  • Description: JumpCloud extension data on the managed entity: dsl.do.addToElevatedGroup.with.pathParams.group_id.
  • Source: resource.dsl.do.addToElevatedGroup.with.pathParams.group_id
  • Usage: workflow_delete
entity.data.dsl.do.addToElevatedGroup.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.addToElevatedGroup.with.version.
  • Source: resource.dsl.do.addToElevatedGroup.with.version
  • Usage: workflow_delete
entity.data.dsl.do.addUserToGroup.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.addUserToGroup.call.
  • Source: resource.dsl.do.addUserToGroup.call
  • Usage: workflow_create
entity.data.dsl.do.addUserToGroup.if
  • Description: JumpCloud extension data on the managed entity: dsl.do.addUserToGroup.if.
  • Source: resource.dsl.do.addUserToGroup.if
  • Usage: workflow_create
entity.data.dsl.do.addUserToGroup.with.bodyParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.addUserToGroup.with.bodyParams.id.
  • Source: resource.dsl.do.addUserToGroup.with.bodyParams.id
  • Usage: workflow_create
entity.data.dsl.do.addUserToGroup.with.bodyParams.op
  • Description: JumpCloud extension data on the managed entity: dsl.do.addUserToGroup.with.bodyParams.op.
  • Source: resource.dsl.do.addUserToGroup.with.bodyParams.op
  • Usage: workflow_create
entity.data.dsl.do.addUserToGroup.with.bodyParams.type
  • Description: JumpCloud extension data on the managed entity: dsl.do.addUserToGroup.with.bodyParams.type.
  • Source: resource.dsl.do.addUserToGroup.with.bodyParams.type
  • Usage: workflow_create
entity.data.dsl.do.addUserToGroup.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.addUserToGroup.with.operationId.
  • Source: resource.dsl.do.addUserToGroup.with.operationId
  • Usage: workflow_create
entity.data.dsl.do.addUserToGroup.with.pathParams.group_id
  • Description: JumpCloud extension data on the managed entity: dsl.do.addUserToGroup.with.pathParams.group_id.
  • Source: resource.dsl.do.addUserToGroup.with.pathParams.group_id
  • Usage: workflow_create
entity.data.dsl.do.addUserToGroup.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.addUserToGroup.with.version.
  • Source: resource.dsl.do.addUserToGroup.with.version
  • Usage: workflow_create
entity.data.dsl.do.addUserToUserGroup.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.addUserToUserGroup.call.
  • Source: resource.dsl.do.addUserToUserGroup.call
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.addUserToUserGroup.metadata.displayLabels.user
  • Description: JumpCloud extension data on the managed entity: dsl.do.addUserToUserGroup.metadata.displayLabels.user.
  • Source: resource.dsl.do.addUserToUserGroup.metadata.displayLabels.user
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.addUserToUserGroup.metadata.displayLabels.userGroup
  • Description: JumpCloud extension data on the managed entity: dsl.do.addUserToUserGroup.metadata.displayLabels.userGroup.
  • Source: resource.dsl.do.addUserToUserGroup.metadata.displayLabels.userGroup
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.addUserToUserGroup.metadata.inputModes.user
  • Description: JumpCloud extension data on the managed entity: dsl.do.addUserToUserGroup.metadata.inputModes.user.
  • Source: resource.dsl.do.addUserToUserGroup.metadata.inputModes.user
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.addUserToUserGroup.metadata.inputModes.userGroup
  • Description: JumpCloud extension data on the managed entity: dsl.do.addUserToUserGroup.metadata.inputModes.userGroup.
  • Source: resource.dsl.do.addUserToUserGroup.metadata.inputModes.userGroup
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.addUserToUserGroup.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.addUserToUserGroup.then.
  • Source: resource.dsl.do.addUserToUserGroup.then
  • Usage: workflow_delete
entity.data.dsl.do.addUserToUserGroup.with.bodyParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.addUserToUserGroup.with.bodyParams.id.
  • Source: resource.dsl.do.addUserToUserGroup.with.bodyParams.id
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.addUserToUserGroup.with.bodyParams.op
  • Description: JumpCloud extension data on the managed entity: dsl.do.addUserToUserGroup.with.bodyParams.op.
  • Source: resource.dsl.do.addUserToUserGroup.with.bodyParams.op
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.addUserToUserGroup.with.bodyParams.type
  • Description: JumpCloud extension data on the managed entity: dsl.do.addUserToUserGroup.with.bodyParams.type.
  • Source: resource.dsl.do.addUserToUserGroup.with.bodyParams.type
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.addUserToUserGroup.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.addUserToUserGroup.with.operationId.
  • Source: resource.dsl.do.addUserToUserGroup.with.operationId
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.addUserToUserGroup.with.pathParams.group_id
  • Description: JumpCloud extension data on the managed entity: dsl.do.addUserToUserGroup.with.pathParams.group_id.
  • Source: resource.dsl.do.addUserToUserGroup.with.pathParams.group_id
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.addUserToUserGroup.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.addUserToUserGroup.with.version.
  • Source: resource.dsl.do.addUserToUserGroup.with.version
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.addUserToUserGroup2.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.addUserToUserGroup2.call.
  • Source: resource.dsl.do.addUserToUserGroup2.call
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.addUserToUserGroup2.metadata.displayLabels.user
  • Description: JumpCloud extension data on the managed entity: dsl.do.addUserToUserGroup2.metadata.displayLabels.user.
  • Source: resource.dsl.do.addUserToUserGroup2.metadata.displayLabels.user
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.addUserToUserGroup2.metadata.displayLabels.userGroup
  • Description: JumpCloud extension data on the managed entity: dsl.do.addUserToUserGroup2.metadata.displayLabels.userGroup.
  • Source: resource.dsl.do.addUserToUserGroup2.metadata.displayLabels.userGroup
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.addUserToUserGroup2.metadata.inputModes.user
  • Description: JumpCloud extension data on the managed entity: dsl.do.addUserToUserGroup2.metadata.inputModes.user.
  • Source: resource.dsl.do.addUserToUserGroup2.metadata.inputModes.user
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.addUserToUserGroup2.metadata.inputModes.userGroup
  • Description: JumpCloud extension data on the managed entity: dsl.do.addUserToUserGroup2.metadata.inputModes.userGroup.
  • Source: resource.dsl.do.addUserToUserGroup2.metadata.inputModes.userGroup
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.addUserToUserGroup2.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.addUserToUserGroup2.then.
  • Source: resource.dsl.do.addUserToUserGroup2.then
  • Usage: workflow_delete
entity.data.dsl.do.addUserToUserGroup2.with.bodyParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.addUserToUserGroup2.with.bodyParams.id.
  • Source: resource.dsl.do.addUserToUserGroup2.with.bodyParams.id
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.addUserToUserGroup2.with.bodyParams.op
  • Description: JumpCloud extension data on the managed entity: dsl.do.addUserToUserGroup2.with.bodyParams.op.
  • Source: resource.dsl.do.addUserToUserGroup2.with.bodyParams.op
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.addUserToUserGroup2.with.bodyParams.type
  • Description: JumpCloud extension data on the managed entity: dsl.do.addUserToUserGroup2.with.bodyParams.type.
  • Source: resource.dsl.do.addUserToUserGroup2.with.bodyParams.type
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.addUserToUserGroup2.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.addUserToUserGroup2.with.operationId.
  • Source: resource.dsl.do.addUserToUserGroup2.with.operationId
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.addUserToUserGroup2.with.pathParams.group_id
  • Description: JumpCloud extension data on the managed entity: dsl.do.addUserToUserGroup2.with.pathParams.group_id.
  • Source: resource.dsl.do.addUserToUserGroup2.with.pathParams.group_id
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.addUserToUserGroup2.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.addUserToUserGroup2.with.version.
  • Source: resource.dsl.do.addUserToUserGroup2.with.version
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.allUsers.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.allUsers.call.
  • Source: resource.dsl.do.allUsers.call
  • Usage: workflow_create
entity.data.dsl.do.allUsers.with.extract
  • Description: JumpCloud extension data on the managed entity: dsl.do.allUsers.with.extract.
  • Source: resource.dsl.do.allUsers.with.extract
  • Usage: workflow_create
entity.data.dsl.do.allUsers.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.allUsers.with.operationId.
  • Source: resource.dsl.do.allUsers.with.operationId
  • Usage: workflow_create
entity.data.dsl.do.allUsers.with.pagination.until
  • Description: JumpCloud extension data on the managed entity: dsl.do.allUsers.with.pagination.until.
  • Source: resource.dsl.do.allUsers.with.pagination.until
  • Usage: workflow_create
entity.data.dsl.do.allUsers.with.pagination.update.in
  • Description: JumpCloud extension data on the managed entity: dsl.do.allUsers.with.pagination.update.in.
  • Source: resource.dsl.do.allUsers.with.pagination.update.in
  • Usage: workflow_create
entity.data.dsl.do.allUsers.with.pagination.update.key
  • Description: JumpCloud extension data on the managed entity: dsl.do.allUsers.with.pagination.update.key.
  • Source: resource.dsl.do.allUsers.with.pagination.update.key
  • Usage: workflow_create
entity.data.dsl.do.allUsers.with.pagination.update.value
  • Description: JumpCloud extension data on the managed entity: dsl.do.allUsers.with.pagination.update.value.
  • Source: resource.dsl.do.allUsers.with.pagination.update.value
  • Usage: workflow_create
entity.data.dsl.do.allUsers.with.queryParams.limit
  • Description: JumpCloud extension data on the managed entity: dsl.do.allUsers.with.queryParams.limit.
  • Source: resource.dsl.do.allUsers.with.queryParams.limit
  • Usage: workflow_create
entity.data.dsl.do.allUsers.with.queryParams.skip
  • Description: JumpCloud extension data on the managed entity: dsl.do.allUsers.with.queryParams.skip.
  • Source: resource.dsl.do.allUsers.with.queryParams.skip
  • Usage: workflow_create
entity.data.dsl.do.allUsers.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.allUsers.with.version.
  • Source: resource.dsl.do.allUsers.with.version
  • Usage: workflow_create
entity.data.dsl.do.appleMdmEraseDevice.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.appleMdmEraseDevice.call.
  • Source: resource.dsl.do.appleMdmEraseDevice.call
  • Usage: workflow_delete
entity.data.dsl.do.appleMdmEraseDevice.metadata.displayLabels.device
  • Description: JumpCloud extension data on the managed entity: dsl.do.appleMdmEraseDevice.metadata.displayLabels.device.
  • Source: resource.dsl.do.appleMdmEraseDevice.metadata.displayLabels.device
  • Usage: workflow_delete
entity.data.dsl.do.appleMdmEraseDevice.metadata.displayLabels.pin
  • Description: JumpCloud extension data on the managed entity: dsl.do.appleMdmEraseDevice.metadata.displayLabels.pin.
  • Source: resource.dsl.do.appleMdmEraseDevice.metadata.displayLabels.pin
  • Usage: workflow_delete
entity.data.dsl.do.appleMdmEraseDevice.metadata.inputModes.device
  • Description: JumpCloud extension data on the managed entity: dsl.do.appleMdmEraseDevice.metadata.inputModes.device.
  • Source: resource.dsl.do.appleMdmEraseDevice.metadata.inputModes.device
  • Usage: workflow_delete
entity.data.dsl.do.appleMdmEraseDevice.metadata.inputModes.pin
  • Description: JumpCloud extension data on the managed entity: dsl.do.appleMdmEraseDevice.metadata.inputModes.pin.
  • Source: resource.dsl.do.appleMdmEraseDevice.metadata.inputModes.pin
  • Usage: workflow_delete
entity.data.dsl.do.appleMdmEraseDevice.with.bodyParams.pin
  • Description: JumpCloud extension data on the managed entity: dsl.do.appleMdmEraseDevice.with.bodyParams.pin.
  • Source: resource.dsl.do.appleMdmEraseDevice.with.bodyParams.pin
  • Usage: workflow_delete
entity.data.dsl.do.appleMdmEraseDevice.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.appleMdmEraseDevice.with.operationId.
  • Source: resource.dsl.do.appleMdmEraseDevice.with.operationId
  • Usage: workflow_delete
entity.data.dsl.do.appleMdmEraseDevice.with.pathParams.apple_mdm_id
  • Description: JumpCloud extension data on the managed entity: dsl.do.appleMdmEraseDevice.with.pathParams.apple_mdm_id.
  • Source: resource.dsl.do.appleMdmEraseDevice.with.pathParams.apple_mdm_id
  • Usage: workflow_delete
entity.data.dsl.do.appleMdmEraseDevice.with.pathParams.device_id
  • Description: JumpCloud extension data on the managed entity: dsl.do.appleMdmEraseDevice.with.pathParams.device_id.
  • Source: resource.dsl.do.appleMdmEraseDevice.with.pathParams.device_id
  • Usage: workflow_delete
entity.data.dsl.do.appleMdmEraseDevice.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.appleMdmEraseDevice.with.version.
  • Source: resource.dsl.do.appleMdmEraseDevice.with.version
  • Usage: workflow_delete
entity.data.dsl.do.bindApplicationToUserGroup.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.bindApplicationToUserGroup.call.
  • Source: resource.dsl.do.bindApplicationToUserGroup.call
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.bindApplicationToUserGroup.metadata.displayLabels.application
  • Description: JumpCloud extension data on the managed entity: dsl.do.bindApplicationToUserGroup.metadata.displayLabels.application.
  • Source: resource.dsl.do.bindApplicationToUserGroup.metadata.displayLabels.application
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.bindApplicationToUserGroup.metadata.displayLabels.userGroup
  • Description: JumpCloud extension data on the managed entity: dsl.do.bindApplicationToUserGroup.metadata.displayLabels.userGroup.
  • Source: resource.dsl.do.bindApplicationToUserGroup.metadata.displayLabels.userGroup
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.bindApplicationToUserGroup.metadata.inputModes.application
  • Description: JumpCloud extension data on the managed entity: dsl.do.bindApplicationToUserGroup.metadata.inputModes.application.
  • Source: resource.dsl.do.bindApplicationToUserGroup.metadata.inputModes.application
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.bindApplicationToUserGroup.metadata.inputModes.userGroup
  • Description: JumpCloud extension data on the managed entity: dsl.do.bindApplicationToUserGroup.metadata.inputModes.userGroup.
  • Source: resource.dsl.do.bindApplicationToUserGroup.metadata.inputModes.userGroup
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.bindApplicationToUserGroup.with.bodyParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.bindApplicationToUserGroup.with.bodyParams.id.
  • Source: resource.dsl.do.bindApplicationToUserGroup.with.bodyParams.id
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.bindApplicationToUserGroup.with.bodyParams.op
  • Description: JumpCloud extension data on the managed entity: dsl.do.bindApplicationToUserGroup.with.bodyParams.op.
  • Source: resource.dsl.do.bindApplicationToUserGroup.with.bodyParams.op
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.bindApplicationToUserGroup.with.bodyParams.type
  • Description: JumpCloud extension data on the managed entity: dsl.do.bindApplicationToUserGroup.with.bodyParams.type.
  • Source: resource.dsl.do.bindApplicationToUserGroup.with.bodyParams.type
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.bindApplicationToUserGroup.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.bindApplicationToUserGroup.with.operationId.
  • Source: resource.dsl.do.bindApplicationToUserGroup.with.operationId
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.bindApplicationToUserGroup.with.pathParams.application_id
  • Description: JumpCloud extension data on the managed entity: dsl.do.bindApplicationToUserGroup.with.pathParams.application_id.
  • Source: resource.dsl.do.bindApplicationToUserGroup.with.pathParams.application_id
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.bindApplicationToUserGroup.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.bindApplicationToUserGroup.with.version.
  • Source: resource.dsl.do.bindApplicationToUserGroup.with.version
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.bindPolicyToDevice.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.bindPolicyToDevice.call.
  • Source: resource.dsl.do.bindPolicyToDevice.call
  • Usage: workflow_delete
entity.data.dsl.do.bindPolicyToDevice.metadata.displayLabels.device
  • Description: JumpCloud extension data on the managed entity: dsl.do.bindPolicyToDevice.metadata.displayLabels.device.
  • Source: resource.dsl.do.bindPolicyToDevice.metadata.displayLabels.device
  • Usage: workflow_delete
entity.data.dsl.do.bindPolicyToDevice.metadata.displayLabels.policy
  • Description: JumpCloud extension data on the managed entity: dsl.do.bindPolicyToDevice.metadata.displayLabels.policy.
  • Source: resource.dsl.do.bindPolicyToDevice.metadata.displayLabels.policy
  • Usage: workflow_delete
entity.data.dsl.do.bindPolicyToDevice.metadata.inputModes.device
  • Description: JumpCloud extension data on the managed entity: dsl.do.bindPolicyToDevice.metadata.inputModes.device.
  • Source: resource.dsl.do.bindPolicyToDevice.metadata.inputModes.device
  • Usage: workflow_delete
entity.data.dsl.do.bindPolicyToDevice.metadata.inputModes.policy
  • Description: JumpCloud extension data on the managed entity: dsl.do.bindPolicyToDevice.metadata.inputModes.policy.
  • Source: resource.dsl.do.bindPolicyToDevice.metadata.inputModes.policy
  • Usage: workflow_delete
entity.data.dsl.do.bindPolicyToDevice.with.bodyParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.bindPolicyToDevice.with.bodyParams.id.
  • Source: resource.dsl.do.bindPolicyToDevice.with.bodyParams.id
  • Usage: workflow_delete
entity.data.dsl.do.bindPolicyToDevice.with.bodyParams.op
  • Description: JumpCloud extension data on the managed entity: dsl.do.bindPolicyToDevice.with.bodyParams.op.
  • Source: resource.dsl.do.bindPolicyToDevice.with.bodyParams.op
  • Usage: workflow_delete
entity.data.dsl.do.bindPolicyToDevice.with.bodyParams.type
  • Description: JumpCloud extension data on the managed entity: dsl.do.bindPolicyToDevice.with.bodyParams.type.
  • Source: resource.dsl.do.bindPolicyToDevice.with.bodyParams.type
  • Usage: workflow_delete
entity.data.dsl.do.bindPolicyToDevice.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.bindPolicyToDevice.with.operationId.
  • Source: resource.dsl.do.bindPolicyToDevice.with.operationId
  • Usage: workflow_delete
entity.data.dsl.do.bindPolicyToDevice.with.pathParams.policy_id
  • Description: JumpCloud extension data on the managed entity: dsl.do.bindPolicyToDevice.with.pathParams.policy_id.
  • Source: resource.dsl.do.bindPolicyToDevice.with.pathParams.policy_id
  • Usage: workflow_delete
entity.data.dsl.do.bindPolicyToDevice.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.bindPolicyToDevice.with.version.
  • Source: resource.dsl.do.bindPolicyToDevice.with.version
  • Usage: workflow_delete
entity.data.dsl.do.bindPolicyToDeviceGroup.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.bindPolicyToDeviceGroup.call.
  • Source: resource.dsl.do.bindPolicyToDeviceGroup.call
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.bindPolicyToDeviceGroup.metadata.displayLabels.deviceGroup
  • Description: JumpCloud extension data on the managed entity: dsl.do.bindPolicyToDeviceGroup.metadata.displayLabels.deviceGroup.
  • Source: resource.dsl.do.bindPolicyToDeviceGroup.metadata.displayLabels.deviceGroup
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.bindPolicyToDeviceGroup.metadata.displayLabels.policy
  • Description: JumpCloud extension data on the managed entity: dsl.do.bindPolicyToDeviceGroup.metadata.displayLabels.policy.
  • Source: resource.dsl.do.bindPolicyToDeviceGroup.metadata.displayLabels.policy
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.bindPolicyToDeviceGroup.metadata.inputModes.deviceGroup
  • Description: JumpCloud extension data on the managed entity: dsl.do.bindPolicyToDeviceGroup.metadata.inputModes.deviceGroup.
  • Source: resource.dsl.do.bindPolicyToDeviceGroup.metadata.inputModes.deviceGroup
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.bindPolicyToDeviceGroup.metadata.inputModes.policy
  • Description: JumpCloud extension data on the managed entity: dsl.do.bindPolicyToDeviceGroup.metadata.inputModes.policy.
  • Source: resource.dsl.do.bindPolicyToDeviceGroup.metadata.inputModes.policy
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.bindPolicyToDeviceGroup.with.bodyParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.bindPolicyToDeviceGroup.with.bodyParams.id.
  • Source: resource.dsl.do.bindPolicyToDeviceGroup.with.bodyParams.id
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.bindPolicyToDeviceGroup.with.bodyParams.op
  • Description: JumpCloud extension data on the managed entity: dsl.do.bindPolicyToDeviceGroup.with.bodyParams.op.
  • Source: resource.dsl.do.bindPolicyToDeviceGroup.with.bodyParams.op
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.bindPolicyToDeviceGroup.with.bodyParams.type
  • Description: JumpCloud extension data on the managed entity: dsl.do.bindPolicyToDeviceGroup.with.bodyParams.type.
  • Source: resource.dsl.do.bindPolicyToDeviceGroup.with.bodyParams.type
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.bindPolicyToDeviceGroup.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.bindPolicyToDeviceGroup.with.operationId.
  • Source: resource.dsl.do.bindPolicyToDeviceGroup.with.operationId
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.bindPolicyToDeviceGroup.with.pathParams.policy_id
  • Description: JumpCloud extension data on the managed entity: dsl.do.bindPolicyToDeviceGroup.with.pathParams.policy_id.
  • Source: resource.dsl.do.bindPolicyToDeviceGroup.with.pathParams.policy_id
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.bindPolicyToDeviceGroup.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.bindPolicyToDeviceGroup.with.version.
  • Source: resource.dsl.do.bindPolicyToDeviceGroup.with.version
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.bind_policy_to_device_group.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.bind_policy_to_device_group.call.
  • Source: resource.dsl.do.bind_policy_to_device_group.call
  • Usage: workflow_delete
entity.data.dsl.do.bind_policy_to_device_group.metadata.displayLabels.deviceGroup
  • Description: JumpCloud extension data on the managed entity: dsl.do.bind_policy_to_device_group.metadata.displayLabels.deviceGroup.
  • Source: resource.dsl.do.bind_policy_to_device_group.metadata.displayLabels.deviceGroup
  • Usage: workflow_delete
entity.data.dsl.do.bind_policy_to_device_group.metadata.displayLabels.policy
  • Description: JumpCloud extension data on the managed entity: dsl.do.bind_policy_to_device_group.metadata.displayLabels.policy.
  • Source: resource.dsl.do.bind_policy_to_device_group.metadata.displayLabels.policy
  • Usage: workflow_delete
entity.data.dsl.do.bind_policy_to_device_group.metadata.inputModes.deviceGroup
  • Description: JumpCloud extension data on the managed entity: dsl.do.bind_policy_to_device_group.metadata.inputModes.deviceGroup.
  • Source: resource.dsl.do.bind_policy_to_device_group.metadata.inputModes.deviceGroup
  • Usage: workflow_delete
entity.data.dsl.do.bind_policy_to_device_group.metadata.inputModes.policy
  • Description: JumpCloud extension data on the managed entity: dsl.do.bind_policy_to_device_group.metadata.inputModes.policy.
  • Source: resource.dsl.do.bind_policy_to_device_group.metadata.inputModes.policy
  • Usage: workflow_delete
entity.data.dsl.do.bind_policy_to_device_group.with.bodyParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.bind_policy_to_device_group.with.bodyParams.id.
  • Source: resource.dsl.do.bind_policy_to_device_group.with.bodyParams.id
  • Usage: workflow_delete
entity.data.dsl.do.bind_policy_to_device_group.with.bodyParams.op
  • Description: JumpCloud extension data on the managed entity: dsl.do.bind_policy_to_device_group.with.bodyParams.op.
  • Source: resource.dsl.do.bind_policy_to_device_group.with.bodyParams.op
  • Usage: workflow_delete
entity.data.dsl.do.bind_policy_to_device_group.with.bodyParams.type
  • Description: JumpCloud extension data on the managed entity: dsl.do.bind_policy_to_device_group.with.bodyParams.type.
  • Source: resource.dsl.do.bind_policy_to_device_group.with.bodyParams.type
  • Usage: workflow_delete
entity.data.dsl.do.bind_policy_to_device_group.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.bind_policy_to_device_group.with.operationId.
  • Source: resource.dsl.do.bind_policy_to_device_group.with.operationId
  • Usage: workflow_delete
entity.data.dsl.do.bind_policy_to_device_group.with.pathParams.policy_id
  • Description: JumpCloud extension data on the managed entity: dsl.do.bind_policy_to_device_group.with.pathParams.policy_id.
  • Source: resource.dsl.do.bind_policy_to_device_group.with.pathParams.policy_id
  • Usage: workflow_delete
entity.data.dsl.do.bind_policy_to_device_group.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.bind_policy_to_device_group.with.version.
  • Source: resource.dsl.do.bind_policy_to_device_group.with.version
  • Usage: workflow_delete
entity.data.dsl.do.bind_user_to_system.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.bind_user_to_system.call.
  • Source: resource.dsl.do.bind_user_to_system.call
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.bind_user_to_system.if
  • Description: JumpCloud extension data on the managed entity: dsl.do.bind_user_to_system.if.
  • Source: resource.dsl.do.bind_user_to_system.if
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.bind_user_to_system.with.bodyParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.bind_user_to_system.with.bodyParams.id.
  • Source: resource.dsl.do.bind_user_to_system.with.bodyParams.id
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.bind_user_to_system.with.bodyParams.op
  • Description: JumpCloud extension data on the managed entity: dsl.do.bind_user_to_system.with.bodyParams.op.
  • Source: resource.dsl.do.bind_user_to_system.with.bodyParams.op
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.bind_user_to_system.with.bodyParams.type
  • Description: JumpCloud extension data on the managed entity: dsl.do.bind_user_to_system.with.bodyParams.type.
  • Source: resource.dsl.do.bind_user_to_system.with.bodyParams.type
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.bind_user_to_system.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.bind_user_to_system.with.operationId.
  • Source: resource.dsl.do.bind_user_to_system.with.operationId
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.bind_user_to_system.with.pathParams.system_id
  • Description: JumpCloud extension data on the managed entity: dsl.do.bind_user_to_system.with.pathParams.system_id.
  • Source: resource.dsl.do.bind_user_to_system.with.pathParams.system_id
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.bind_user_to_system.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.bind_user_to_system.with.version.
  • Source: resource.dsl.do.bind_user_to_system.with.version
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.callConnector.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.callConnector.call.
  • Source: resource.dsl.do.callConnector.call
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.callConnector.with.body.data
  • Description: JumpCloud extension data on the managed entity: dsl.do.callConnector.with.body.data.
  • Source: resource.dsl.do.callConnector.with.body.data
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.callConnector.with.body.fields.description.content.content.text
  • Description: JumpCloud extension data on the managed entity: dsl.do.callConnector.with.body.fields.description.content.content.text.
  • Source: resource.dsl.do.callConnector.with.body.fields.description.content.content.text
  • Usage: workflow_create
entity.data.dsl.do.callConnector.with.body.fields.description.content.content.type
  • Description: JumpCloud extension data on the managed entity: dsl.do.callConnector.with.body.fields.description.content.content.type.
  • Source: resource.dsl.do.callConnector.with.body.fields.description.content.content.type
  • Usage: workflow_create
entity.data.dsl.do.callConnector.with.body.fields.description.content.type
  • Description: JumpCloud extension data on the managed entity: dsl.do.callConnector.with.body.fields.description.content.type.
  • Source: resource.dsl.do.callConnector.with.body.fields.description.content.type
  • Usage: workflow_create
entity.data.dsl.do.callConnector.with.body.fields.description.type
  • Description: JumpCloud extension data on the managed entity: dsl.do.callConnector.with.body.fields.description.type.
  • Source: resource.dsl.do.callConnector.with.body.fields.description.type
  • Usage: workflow_create
entity.data.dsl.do.callConnector.with.body.fields.description.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.callConnector.with.body.fields.description.version.
  • Source: resource.dsl.do.callConnector.with.body.fields.description.version
  • Usage: workflow_create
entity.data.dsl.do.callConnector.with.body.fields.issuetype.name
  • Description: JumpCloud extension data on the managed entity: dsl.do.callConnector.with.body.fields.issuetype.name.
  • Source: resource.dsl.do.callConnector.with.body.fields.issuetype.name
  • Usage: workflow_create
entity.data.dsl.do.callConnector.with.body.fields.project.key
  • Description: JumpCloud extension data on the managed entity: dsl.do.callConnector.with.body.fields.project.key.
  • Source: resource.dsl.do.callConnector.with.body.fields.project.key
  • Usage: workflow_create
entity.data.dsl.do.callConnector.with.body.fields.summary
  • Description: JumpCloud extension data on the managed entity: dsl.do.callConnector.with.body.fields.summary.
  • Source: resource.dsl.do.callConnector.with.body.fields.summary
  • Usage: workflow_create
entity.data.dsl.do.callConnector.with.body.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.callConnector.with.body.id.
  • Source: resource.dsl.do.callConnector.with.body.id
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.callConnector.with.body.timestamp
  • Description: JumpCloud extension data on the managed entity: dsl.do.callConnector.with.body.timestamp.
  • Source: resource.dsl.do.callConnector.with.body.timestamp
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.callConnector.with.endpointPath
  • Description: JumpCloud extension data on the managed entity: dsl.do.callConnector.with.endpointPath.
  • Source: resource.dsl.do.callConnector.with.endpointPath
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.callConnector.with.headers.Accept
  • Description: JumpCloud extension data on the managed entity: dsl.do.callConnector.with.headers.Accept.
  • Source: resource.dsl.do.callConnector.with.headers.Accept
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.callConnector.with.headers.EWrwer
  • Description: JumpCloud extension data on the managed entity: dsl.do.callConnector.with.headers.EWrwer.
  • Source: resource.dsl.do.callConnector.with.headers.EWrwer
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.callConnector.with.headers.ew
  • Description: JumpCloud extension data on the managed entity: dsl.do.callConnector.with.headers.ew.
  • Source: resource.dsl.do.callConnector.with.headers.ew
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.callConnector.with.headers.ewd
  • Description: JumpCloud extension data on the managed entity: dsl.do.callConnector.with.headers.ewd.
  • Source: resource.dsl.do.callConnector.with.headers.ewd
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.callConnector.with.headers.ewe
  • Description: JumpCloud extension data on the managed entity: dsl.do.callConnector.with.headers.ewe.
  • Source: resource.dsl.do.callConnector.with.headers.ewe
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.callConnector.with.httpMethod
  • Description: JumpCloud extension data on the managed entity: dsl.do.callConnector.with.httpMethod.
  • Source: resource.dsl.do.callConnector.with.httpMethod
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.callConnector.with.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.callConnector.with.id.
  • Source: resource.dsl.do.callConnector.with.id
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.callConnector2.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.callConnector2.call.
  • Source: resource.dsl.do.callConnector2.call
  • Usage: workflow_delete
entity.data.dsl.do.callConnector2.with.endpointPath
  • Description: JumpCloud extension data on the managed entity: dsl.do.callConnector2.with.endpointPath.
  • Source: resource.dsl.do.callConnector2.with.endpointPath
  • Usage: workflow_delete
entity.data.dsl.do.callConnector2.with.httpMethod
  • Description: JumpCloud extension data on the managed entity: dsl.do.callConnector2.with.httpMethod.
  • Source: resource.dsl.do.callConnector2.with.httpMethod
  • Usage: workflow_delete
entity.data.dsl.do.callConnector2.with.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.callConnector2.with.id.
  • Source: resource.dsl.do.callConnector2.with.id
  • Usage: workflow_delete
entity.data.dsl.do.callConnector3.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.callConnector3.call.
  • Source: resource.dsl.do.callConnector3.call
  • Usage: workflow_delete
entity.data.dsl.do.callConnector3.with.endpointPath
  • Description: JumpCloud extension data on the managed entity: dsl.do.callConnector3.with.endpointPath.
  • Source: resource.dsl.do.callConnector3.with.endpointPath
  • Usage: workflow_delete
entity.data.dsl.do.callConnector3.with.httpMethod
  • Description: JumpCloud extension data on the managed entity: dsl.do.callConnector3.with.httpMethod.
  • Source: resource.dsl.do.callConnector3.with.httpMethod
  • Usage: workflow_delete
entity.data.dsl.do.callConnector3.with.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.callConnector3.with.id.
  • Source: resource.dsl.do.callConnector3.with.id
  • Usage: workflow_delete
entity.data.dsl.do.checkActivated.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.checkActivated.call.
  • Source: resource.dsl.do.checkActivated.call
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.checkActivated.if
  • Description: JumpCloud extension data on the managed entity: dsl.do.checkActivated.if.
  • Source: resource.dsl.do.checkActivated.if
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.checkActivated.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.checkActivated.with.operationId.
  • Source: resource.dsl.do.checkActivated.with.operationId
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.checkActivated.with.pathParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.checkActivated.with.pathParams.id.
  • Source: resource.dsl.do.checkActivated.with.pathParams.id
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.checkActivated.with.queryParams.fields
  • Description: JumpCloud extension data on the managed entity: dsl.do.checkActivated.with.queryParams.fields.
  • Source: resource.dsl.do.checkActivated.with.queryParams.fields
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.checkActivated.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.checkActivated.with.version.
  • Source: resource.dsl.do.checkActivated.with.version
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.checkDelegatedAuthorityExists.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.checkDelegatedAuthorityExists.call.
  • Source: resource.dsl.do.checkDelegatedAuthorityExists.call
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.checkDelegatedAuthorityExists.if
  • Description: JumpCloud extension data on the managed entity: dsl.do.checkDelegatedAuthorityExists.if.
  • Source: resource.dsl.do.checkDelegatedAuthorityExists.if
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.checkDelegatedAuthorityExists.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.checkDelegatedAuthorityExists.with.operationId.
  • Source: resource.dsl.do.checkDelegatedAuthorityExists.with.operationId
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.checkDelegatedAuthorityExists.with.pathParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.checkDelegatedAuthorityExists.with.pathParams.id.
  • Source: resource.dsl.do.checkDelegatedAuthorityExists.with.pathParams.id
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.checkDelegatedAuthorityExists.with.queryParams.fields
  • Description: JumpCloud extension data on the managed entity: dsl.do.checkDelegatedAuthorityExists.with.queryParams.fields.
  • Source: resource.dsl.do.checkDelegatedAuthorityExists.with.queryParams.fields
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.checkDelegatedAuthorityExists.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.checkDelegatedAuthorityExists.with.version.
  • Source: resource.dsl.do.checkDelegatedAuthorityExists.with.version
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.checkPasswordDate.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.checkPasswordDate.call.
  • Source: resource.dsl.do.checkPasswordDate.call
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.checkPasswordDate.if
  • Description: JumpCloud extension data on the managed entity: dsl.do.checkPasswordDate.if.
  • Source: resource.dsl.do.checkPasswordDate.if
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.checkPasswordDate.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.checkPasswordDate.with.operationId.
  • Source: resource.dsl.do.checkPasswordDate.with.operationId
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.checkPasswordDate.with.pathParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.checkPasswordDate.with.pathParams.id.
  • Source: resource.dsl.do.checkPasswordDate.with.pathParams.id
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.checkPasswordDate.with.queryParams.fields
  • Description: JumpCloud extension data on the managed entity: dsl.do.checkPasswordDate.with.queryParams.fields.
  • Source: resource.dsl.do.checkPasswordDate.with.queryParams.fields
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.checkPasswordDate.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.checkPasswordDate.with.version.
  • Source: resource.dsl.do.checkPasswordDate.with.version
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.checkUserInUserGroupListMembership.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.checkUserInUserGroupListMembership.call.
  • Source: resource.dsl.do.checkUserInUserGroupListMembership.call
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.checkUserInUserGroupListMembership.metadata.compositeGroupId
  • Description: JumpCloud extension data on the managed entity: dsl.do.checkUserInUserGroupListMembership.metadata.compositeGroupId.
  • Source: resource.dsl.do.checkUserInUserGroupListMembership.metadata.compositeGroupId
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.checkUserInUserGroupListMembership.metadata.compositeNodeId
  • Description: JumpCloud extension data on the managed entity: dsl.do.checkUserInUserGroupListMembership.metadata.compositeNodeId.
  • Source: resource.dsl.do.checkUserInUserGroupListMembership.metadata.compositeNodeId
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.checkUserInUserGroupListMembership.metadata.compositeStepId
  • Description: JumpCloud extension data on the managed entity: dsl.do.checkUserInUserGroupListMembership.metadata.compositeStepId.
  • Source: resource.dsl.do.checkUserInUserGroupListMembership.metadata.compositeStepId
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.checkUserInUserGroupListMembership.metadata.compositeStepIndex
  • Description: JumpCloud extension data on the managed entity: dsl.do.checkUserInUserGroupListMembership.metadata.compositeStepIndex.
  • Source: resource.dsl.do.checkUserInUserGroupListMembership.metadata.compositeStepIndex
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.checkUserInUserGroupListMembership.metadata.compositeTemplateId
  • Description: JumpCloud extension data on the managed entity: dsl.do.checkUserInUserGroupListMembership.metadata.compositeTemplateId.
  • Source: resource.dsl.do.checkUserInUserGroupListMembership.metadata.compositeTemplateId
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.checkUserInUserGroupListMembership.metadata.displayLabels.user
  • Description: JumpCloud extension data on the managed entity: dsl.do.checkUserInUserGroupListMembership.metadata.displayLabels.user.
  • Source: resource.dsl.do.checkUserInUserGroupListMembership.metadata.displayLabels.user
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.checkUserInUserGroupListMembership.metadata.displayLabels.userGroup
  • Description: JumpCloud extension data on the managed entity: dsl.do.checkUserInUserGroupListMembership.metadata.displayLabels.userGroup.
  • Source: resource.dsl.do.checkUserInUserGroupListMembership.metadata.displayLabels.userGroup
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.checkUserInUserGroupListMembership.metadata.inputModes.user
  • Description: JumpCloud extension data on the managed entity: dsl.do.checkUserInUserGroupListMembership.metadata.inputModes.user.
  • Source: resource.dsl.do.checkUserInUserGroupListMembership.metadata.inputModes.user
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.checkUserInUserGroupListMembership.metadata.inputModes.userGroup
  • Description: JumpCloud extension data on the managed entity: dsl.do.checkUserInUserGroupListMembership.metadata.inputModes.userGroup.
  • Source: resource.dsl.do.checkUserInUserGroupListMembership.metadata.inputModes.userGroup
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.checkUserInUserGroupListMembership.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.checkUserInUserGroupListMembership.with.operationId.
  • Source: resource.dsl.do.checkUserInUserGroupListMembership.with.operationId
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.checkUserInUserGroupListMembership.with.pathParams.group_id
  • Description: JumpCloud extension data on the managed entity: dsl.do.checkUserInUserGroupListMembership.with.pathParams.group_id.
  • Source: resource.dsl.do.checkUserInUserGroupListMembership.with.pathParams.group_id
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.checkUserInUserGroupListMembership.with.queryParams.filter
  • Description: JumpCloud extension data on the managed entity: dsl.do.checkUserInUserGroupListMembership.with.queryParams.filter.
  • Source: resource.dsl.do.checkUserInUserGroupListMembership.with.queryParams.filter
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.checkUserInUserGroupListMembership.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.checkUserInUserGroupListMembership.with.version.
  • Source: resource.dsl.do.checkUserInUserGroupListMembership.with.version
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.checkUserInUserGroupRouteMembership.metadata.compositeGroupId
  • Description: JumpCloud extension data on the managed entity: dsl.do.checkUserInUserGroupRouteMembership.metadata.compositeGroupId.
  • Source: resource.dsl.do.checkUserInUserGroupRouteMembership.metadata.compositeGroupId
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.checkUserInUserGroupRouteMembership.metadata.compositeNodeId
  • Description: JumpCloud extension data on the managed entity: dsl.do.checkUserInUserGroupRouteMembership.metadata.compositeNodeId.
  • Source: resource.dsl.do.checkUserInUserGroupRouteMembership.metadata.compositeNodeId
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.checkUserInUserGroupRouteMembership.metadata.compositeStepId
  • Description: JumpCloud extension data on the managed entity: dsl.do.checkUserInUserGroupRouteMembership.metadata.compositeStepId.
  • Source: resource.dsl.do.checkUserInUserGroupRouteMembership.metadata.compositeStepId
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.checkUserInUserGroupRouteMembership.metadata.compositeStepIndex
  • Description: JumpCloud extension data on the managed entity: dsl.do.checkUserInUserGroupRouteMembership.metadata.compositeStepIndex.
  • Source: resource.dsl.do.checkUserInUserGroupRouteMembership.metadata.compositeStepIndex
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.checkUserInUserGroupRouteMembership.metadata.compositeTemplateId
  • Description: JumpCloud extension data on the managed entity: dsl.do.checkUserInUserGroupRouteMembership.metadata.compositeTemplateId.
  • Source: resource.dsl.do.checkUserInUserGroupRouteMembership.metadata.compositeTemplateId
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.checkUserInUserGroupRouteMembership.switch.default.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.checkUserInUserGroupRouteMembership.switch.default.then.
  • Source: resource.dsl.do.checkUserInUserGroupRouteMembership.switch.default.then
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.checkUserInUserGroupRouteMembership.switch.isMember.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.checkUserInUserGroupRouteMembership.switch.isMember.then.
  • Source: resource.dsl.do.checkUserInUserGroupRouteMembership.switch.isMember.then
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.checkUserInUserGroupRouteMembership.switch.isMember.when
  • Description: JumpCloud extension data on the managed entity: dsl.do.checkUserInUserGroupRouteMembership.switch.isMember.when.
  • Source: resource.dsl.do.checkUserInUserGroupRouteMembership.switch.isMember.when
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.commands_get.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.commands_get.call.
  • Source: resource.dsl.do.commands_get.call
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.commands_get.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.commands_get.with.operationId.
  • Source: resource.dsl.do.commands_get.with.operationId
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.commands_get.with.pathParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.commands_get.with.pathParams.id.
  • Source: resource.dsl.do.commands_get.with.pathParams.id
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.commands_get.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.commands_get.with.version.
  • Source: resource.dsl.do.commands_get.with.version
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.commands_put.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.commands_put.call.
  • Source: resource.dsl.do.commands_put.call
  • Usage: workflow_delete
entity.data.dsl.do.commands_put.with.bodyParams.aiGenerated
  • Description: JumpCloud extension data on the managed entity: dsl.do.commands_put.with.bodyParams.aiGenerated.
  • Source: resource.dsl.do.commands_put.with.bodyParams.aiGenerated
  • Usage: workflow_delete
entity.data.dsl.do.commands_put.with.bodyParams.command
  • Description: JumpCloud extension data on the managed entity: dsl.do.commands_put.with.bodyParams.command.
  • Source: resource.dsl.do.commands_put.with.bodyParams.command
  • Usage: workflow_delete
entity.data.dsl.do.commands_put.with.bodyParams.commandRunners
  • Description: JumpCloud extension data on the managed entity: dsl.do.commands_put.with.bodyParams.commandRunners.
  • Source: resource.dsl.do.commands_put.with.bodyParams.commandRunners
  • Usage: workflow_delete
entity.data.dsl.do.commands_put.with.bodyParams.commandType
  • Description: JumpCloud extension data on the managed entity: dsl.do.commands_put.with.bodyParams.commandType.
  • Source: resource.dsl.do.commands_put.with.bodyParams.commandType
  • Usage: workflow_delete
entity.data.dsl.do.commands_put.with.bodyParams.description
  • Description: JumpCloud extension data on the managed entity: dsl.do.commands_put.with.bodyParams.description.
  • Source: resource.dsl.do.commands_put.with.bodyParams.description
  • Usage: workflow_delete
entity.data.dsl.do.commands_put.with.bodyParams.files
  • Description: JumpCloud extension data on the managed entity: dsl.do.commands_put.with.bodyParams.files.
  • Source: resource.dsl.do.commands_put.with.bodyParams.files
  • Usage: workflow_delete
entity.data.dsl.do.commands_put.with.bodyParams.filesS3
  • Description: JumpCloud extension data on the managed entity: dsl.do.commands_put.with.bodyParams.filesS3.
  • Source: resource.dsl.do.commands_put.with.bodyParams.filesS3
  • Usage: workflow_delete
entity.data.dsl.do.commands_put.with.bodyParams.launchType
  • Description: JumpCloud extension data on the managed entity: dsl.do.commands_put.with.bodyParams.launchType.
  • Source: resource.dsl.do.commands_put.with.bodyParams.launchType
  • Usage: workflow_delete
entity.data.dsl.do.commands_put.with.bodyParams.listensTo
  • Description: JumpCloud extension data on the managed entity: dsl.do.commands_put.with.bodyParams.listensTo.
  • Source: resource.dsl.do.commands_put.with.bodyParams.listensTo
  • Usage: workflow_delete
entity.data.dsl.do.commands_put.with.bodyParams.name
  • Description: JumpCloud extension data on the managed entity: dsl.do.commands_put.with.bodyParams.name.
  • Source: resource.dsl.do.commands_put.with.bodyParams.name
  • Usage: workflow_delete
entity.data.dsl.do.commands_put.with.bodyParams.organization
  • Description: JumpCloud extension data on the managed entity: dsl.do.commands_put.with.bodyParams.organization.
  • Source: resource.dsl.do.commands_put.with.bodyParams.organization
  • Usage: workflow_delete
entity.data.dsl.do.commands_put.with.bodyParams.schedule
  • Description: JumpCloud extension data on the managed entity: dsl.do.commands_put.with.bodyParams.schedule.
  • Source: resource.dsl.do.commands_put.with.bodyParams.schedule
  • Usage: workflow_delete
entity.data.dsl.do.commands_put.with.bodyParams.scheduleRepeatType
  • Description: JumpCloud extension data on the managed entity: dsl.do.commands_put.with.bodyParams.scheduleRepeatType.
  • Source: resource.dsl.do.commands_put.with.bodyParams.scheduleRepeatType
  • Usage: workflow_delete
entity.data.dsl.do.commands_put.with.bodyParams.scheduleYear
  • Description: JumpCloud extension data on the managed entity: dsl.do.commands_put.with.bodyParams.scheduleYear.
  • Source: resource.dsl.do.commands_put.with.bodyParams.scheduleYear
  • Usage: workflow_delete
entity.data.dsl.do.commands_put.with.bodyParams.shell
  • Description: JumpCloud extension data on the managed entity: dsl.do.commands_put.with.bodyParams.shell.
  • Source: resource.dsl.do.commands_put.with.bodyParams.shell
  • Usage: workflow_delete
entity.data.dsl.do.commands_put.with.bodyParams.sudo
  • Description: JumpCloud extension data on the managed entity: dsl.do.commands_put.with.bodyParams.sudo.
  • Source: resource.dsl.do.commands_put.with.bodyParams.sudo
  • Usage: workflow_delete
entity.data.dsl.do.commands_put.with.bodyParams.systems
  • Description: JumpCloud extension data on the managed entity: dsl.do.commands_put.with.bodyParams.systems.
  • Source: resource.dsl.do.commands_put.with.bodyParams.systems
  • Usage: workflow_delete
entity.data.dsl.do.commands_put.with.bodyParams.template
  • Description: JumpCloud extension data on the managed entity: dsl.do.commands_put.with.bodyParams.template.
  • Source: resource.dsl.do.commands_put.with.bodyParams.template
  • Usage: workflow_delete
entity.data.dsl.do.commands_put.with.bodyParams.timeToLiveSeconds
  • Description: JumpCloud extension data on the managed entity: dsl.do.commands_put.with.bodyParams.timeToLiveSeconds.
  • Source: resource.dsl.do.commands_put.with.bodyParams.timeToLiveSeconds
  • Usage: workflow_delete
entity.data.dsl.do.commands_put.with.bodyParams.timeout
  • Description: JumpCloud extension data on the managed entity: dsl.do.commands_put.with.bodyParams.timeout.
  • Source: resource.dsl.do.commands_put.with.bodyParams.timeout
  • Usage: workflow_delete
entity.data.dsl.do.commands_put.with.bodyParams.trigger
  • Description: JumpCloud extension data on the managed entity: dsl.do.commands_put.with.bodyParams.trigger.
  • Source: resource.dsl.do.commands_put.with.bodyParams.trigger
  • Usage: workflow_delete
entity.data.dsl.do.commands_put.with.bodyParams.user
  • Description: JumpCloud extension data on the managed entity: dsl.do.commands_put.with.bodyParams.user.
  • Source: resource.dsl.do.commands_put.with.bodyParams.user
  • Usage: workflow_delete
entity.data.dsl.do.commands_put.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.commands_put.with.operationId.
  • Source: resource.dsl.do.commands_put.with.operationId
  • Usage: workflow_delete
entity.data.dsl.do.commands_put.with.pathParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.commands_put.with.pathParams.id.
  • Source: resource.dsl.do.commands_put.with.pathParams.id
  • Usage: workflow_delete
entity.data.dsl.do.commands_put.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.commands_put.with.version.
  • Source: resource.dsl.do.commands_put.with.version
  • Usage: workflow_delete
entity.data.dsl.do.createAccessRequestWorkflow.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.createAccessRequestWorkflow.call.
  • Source: resource.dsl.do.createAccessRequestWorkflow.call
  • Usage: workflow_create
entity.data.dsl.do.createAccessRequestWorkflow.if
  • Description: JumpCloud extension data on the managed entity: dsl.do.createAccessRequestWorkflow.if.
  • Source: resource.dsl.do.createAccessRequestWorkflow.if
  • Usage: workflow_create
entity.data.dsl.do.createAccessRequestWorkflow.with.bodyParams.approvalType
  • Description: JumpCloud extension data on the managed entity: dsl.do.createAccessRequestWorkflow.with.bodyParams.approvalType.
  • Source: resource.dsl.do.createAccessRequestWorkflow.with.bodyParams.approvalType
  • Usage: workflow_create
entity.data.dsl.do.createAccessRequestWorkflow.with.bodyParams.approverRequirement
  • Description: JumpCloud extension data on the managed entity: dsl.do.createAccessRequestWorkflow.with.bodyParams.approverRequirement.
  • Source: resource.dsl.do.createAccessRequestWorkflow.with.bodyParams.approverRequirement
  • Usage: workflow_create
entity.data.dsl.do.createAccessRequestWorkflow.with.bodyParams.approverResources
  • Description: JumpCloud extension data on the managed entity: dsl.do.createAccessRequestWorkflow.with.bodyParams.approverResources.
  • Source: resource.dsl.do.createAccessRequestWorkflow.with.bodyParams.approverResources
  • Usage: workflow_create
entity.data.dsl.do.createAccessRequestWorkflow.with.bodyParams.description
  • Description: JumpCloud extension data on the managed entity: dsl.do.createAccessRequestWorkflow.with.bodyParams.description.
  • Source: resource.dsl.do.createAccessRequestWorkflow.with.bodyParams.description
  • Usage: workflow_create
entity.data.dsl.do.createAccessRequestWorkflow.with.bodyParams.name
  • Description: JumpCloud extension data on the managed entity: dsl.do.createAccessRequestWorkflow.with.bodyParams.name.
  • Source: resource.dsl.do.createAccessRequestWorkflow.with.bodyParams.name
  • Usage: workflow_create
entity.data.dsl.do.createAccessRequestWorkflow.with.bodyParams.nonAdminApproval
  • Description: JumpCloud extension data on the managed entity: dsl.do.createAccessRequestWorkflow.with.bodyParams.nonAdminApproval.
  • Source: resource.dsl.do.createAccessRequestWorkflow.with.bodyParams.nonAdminApproval
  • Usage: workflow_create
entity.data.dsl.do.createAccessRequestWorkflow.with.bodyParams.resourceId
  • Description: JumpCloud extension data on the managed entity: dsl.do.createAccessRequestWorkflow.with.bodyParams.resourceId.
  • Source: resource.dsl.do.createAccessRequestWorkflow.with.bodyParams.resourceId
  • Usage: workflow_create
entity.data.dsl.do.createAccessRequestWorkflow.with.bodyParams.resourceType
  • Description: JumpCloud extension data on the managed entity: dsl.do.createAccessRequestWorkflow.with.bodyParams.resourceType.
  • Source: resource.dsl.do.createAccessRequestWorkflow.with.bodyParams.resourceType
  • Usage: workflow_create
entity.data.dsl.do.createAccessRequestWorkflow.with.bodyParams.status
  • Description: JumpCloud extension data on the managed entity: dsl.do.createAccessRequestWorkflow.with.bodyParams.status.
  • Source: resource.dsl.do.createAccessRequestWorkflow.with.bodyParams.status
  • Usage: workflow_create
entity.data.dsl.do.createAccessRequestWorkflow.with.bodyParams.timeBasedAccess
  • Description: JumpCloud extension data on the managed entity: dsl.do.createAccessRequestWorkflow.with.bodyParams.timeBasedAccess.
  • Source: resource.dsl.do.createAccessRequestWorkflow.with.bodyParams.timeBasedAccess
  • Usage: workflow_create
entity.data.dsl.do.createAccessRequestWorkflow.with.bodyParams.ttlConfig
  • Description: JumpCloud extension data on the managed entity: dsl.do.createAccessRequestWorkflow.with.bodyParams.ttlConfig.
  • Source: resource.dsl.do.createAccessRequestWorkflow.with.bodyParams.ttlConfig
  • Usage: workflow_create
entity.data.dsl.do.createAccessRequestWorkflow.with.bodyParams.visibleTo
  • Description: JumpCloud extension data on the managed entity: dsl.do.createAccessRequestWorkflow.with.bodyParams.visibleTo.
  • Source: resource.dsl.do.createAccessRequestWorkflow.with.bodyParams.visibleTo
  • Usage: workflow_create
entity.data.dsl.do.createAccessRequestWorkflow.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.createAccessRequestWorkflow.with.operationId.
  • Source: resource.dsl.do.createAccessRequestWorkflow.with.operationId
  • Usage: workflow_create
entity.data.dsl.do.createAccessRequestWorkflow.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.createAccessRequestWorkflow.with.version.
  • Source: resource.dsl.do.createAccessRequestWorkflow.with.version
  • Usage: workflow_create
entity.data.dsl.do.createGroup.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.createGroup.call.
  • Source: resource.dsl.do.createGroup.call
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.createGroup.with.bodyParams.name
  • Description: JumpCloud extension data on the managed entity: dsl.do.createGroup.with.bodyParams.name.
  • Source: resource.dsl.do.createGroup.with.bodyParams.name
  • Usage: workflow_create
entity.data.dsl.do.createGroup.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.createGroup.with.operationId.
  • Source: resource.dsl.do.createGroup.with.operationId
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.createGroup.with.pathParams.objectId
  • Description: JumpCloud extension data on the managed entity: dsl.do.createGroup.with.pathParams.objectId.
  • Source: resource.dsl.do.createGroup.with.pathParams.objectId
  • Usage: workflow_delete
entity.data.dsl.do.createGroup.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.createGroup.with.version.
  • Source: resource.dsl.do.createGroup.with.version
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.deviceLockBranch.if
  • Description: JumpCloud extension data on the managed entity: dsl.do.deviceLockBranch.if.
  • Source: resource.dsl.do.deviceLockBranch.if
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.deviceLockBranch.switch.default.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.deviceLockBranch.switch.default.then.
  • Source: resource.dsl.do.deviceLockBranch.switch.default.then
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.deviceLockBranch.switch.isMac.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.deviceLockBranch.switch.isMac.then.
  • Source: resource.dsl.do.deviceLockBranch.switch.isMac.then
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.deviceLockBranch.switch.isMac.when
  • Description: JumpCloud extension data on the managed entity: dsl.do.deviceLockBranch.switch.isMac.when.
  • Source: resource.dsl.do.deviceLockBranch.switch.isMac.when
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.deviceLockBranch.switch.otherDevice.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.deviceLockBranch.switch.otherDevice.then.
  • Source: resource.dsl.do.deviceLockBranch.switch.otherDevice.then
  • Usage: workflow_create
entity.data.dsl.do.deviceLockBranch.switch.otherDevice.when
  • Description: JumpCloud extension data on the managed entity: dsl.do.deviceLockBranch.switch.otherDevice.when.
  • Source: resource.dsl.do.deviceLockBranch.switch.otherDevice.when
  • Usage: workflow_create
entity.data.dsl.do.duo_accountPost.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.duo_accountPost.call.
  • Source: resource.dsl.do.duo_accountPost.call
  • Usage: workflow_delete
entity.data.dsl.do.duo_accountPost.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.duo_accountPost.with.operationId.
  • Source: resource.dsl.do.duo_accountPost.with.operationId
  • Usage: workflow_delete
entity.data.dsl.do.duo_accountPost.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.duo_accountPost.with.version.
  • Source: resource.dsl.do.duo_accountPost.with.version
  • Usage: workflow_delete
entity.data.dsl.do.emailITOps.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.emailITOps.call.
  • Source: resource.dsl.do.emailITOps.call
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.emailITOps.with.message.body
  • Description: JumpCloud extension data on the managed entity: dsl.do.emailITOps.with.message.body.
  • Source: resource.dsl.do.emailITOps.with.message.body
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.emailITOps.with.message.subject
  • Description: JumpCloud extension data on the managed entity: dsl.do.emailITOps.with.message.subject.
  • Source: resource.dsl.do.emailITOps.with.message.subject
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.emailITOps.with.recipients.to_addresses
  • Description: JumpCloud extension data on the managed entity: dsl.do.emailITOps.with.recipients.to_addresses.
  • Source: resource.dsl.do.emailITOps.with.recipients.to_addresses
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.emailManager.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.emailManager.call.
  • Source: resource.dsl.do.emailManager.call
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.emailManager.if
  • Description: JumpCloud extension data on the managed entity: dsl.do.emailManager.if.
  • Source: resource.dsl.do.emailManager.if
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.emailManager.with.message.body
  • Description: JumpCloud extension data on the managed entity: dsl.do.emailManager.with.message.body.
  • Source: resource.dsl.do.emailManager.with.message.body
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.emailManager.with.message.subject
  • Description: JumpCloud extension data on the managed entity: dsl.do.emailManager.with.message.subject.
  • Source: resource.dsl.do.emailManager.with.message.subject
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.emailManager.with.recipients.to_addresses
  • Description: JumpCloud extension data on the managed entity: dsl.do.emailManager.with.recipients.to_addresses.
  • Source: resource.dsl.do.emailManager.with.recipients.to_addresses
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.eraseDevice.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.eraseDevice.call.
  • Source: resource.dsl.do.eraseDevice.call
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.eraseDevice.metadata.displayLabels.device
  • Description: JumpCloud extension data on the managed entity: dsl.do.eraseDevice.metadata.displayLabels.device.
  • Source: resource.dsl.do.eraseDevice.metadata.displayLabels.device
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.eraseDevice.metadata.inputModes.device
  • Description: JumpCloud extension data on the managed entity: dsl.do.eraseDevice.metadata.inputModes.device.
  • Source: resource.dsl.do.eraseDevice.metadata.inputModes.device
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.eraseDevice.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.eraseDevice.with.operationId.
  • Source: resource.dsl.do.eraseDevice.with.operationId
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.eraseDevice.with.pathParams.system_id
  • Description: JumpCloud extension data on the managed entity: dsl.do.eraseDevice.with.pathParams.system_id.
  • Source: resource.dsl.do.eraseDevice.with.pathParams.system_id
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.eraseDevice.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.eraseDevice.with.version.
  • Source: resource.dsl.do.eraseDevice.with.version
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.eraseMacDevice.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.eraseMacDevice.call.
  • Source: resource.dsl.do.eraseMacDevice.call
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.eraseMacDevice.if
  • Description: JumpCloud extension data on the managed entity: dsl.do.eraseMacDevice.if.
  • Source: resource.dsl.do.eraseMacDevice.if
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.eraseMacDevice.metadata.displayLabels.device
  • Description: JumpCloud extension data on the managed entity: dsl.do.eraseMacDevice.metadata.displayLabels.device.
  • Source: resource.dsl.do.eraseMacDevice.metadata.displayLabels.device
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.eraseMacDevice.metadata.displayLabels.mdmId
  • Description: JumpCloud extension data on the managed entity: dsl.do.eraseMacDevice.metadata.displayLabels.mdmId.
  • Source: resource.dsl.do.eraseMacDevice.metadata.displayLabels.mdmId
  • Usage: workflow_delete
entity.data.dsl.do.eraseMacDevice.metadata.displayLabels.pin
  • Description: JumpCloud extension data on the managed entity: dsl.do.eraseMacDevice.metadata.displayLabels.pin.
  • Source: resource.dsl.do.eraseMacDevice.metadata.displayLabels.pin
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.eraseMacDevice.metadata.inputModes.device
  • Description: JumpCloud extension data on the managed entity: dsl.do.eraseMacDevice.metadata.inputModes.device.
  • Source: resource.dsl.do.eraseMacDevice.metadata.inputModes.device
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.eraseMacDevice.metadata.inputModes.mdmId
  • Description: JumpCloud extension data on the managed entity: dsl.do.eraseMacDevice.metadata.inputModes.mdmId.
  • Source: resource.dsl.do.eraseMacDevice.metadata.inputModes.mdmId
  • Usage: workflow_delete
entity.data.dsl.do.eraseMacDevice.metadata.inputModes.pin
  • Description: JumpCloud extension data on the managed entity: dsl.do.eraseMacDevice.metadata.inputModes.pin.
  • Source: resource.dsl.do.eraseMacDevice.metadata.inputModes.pin
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.eraseMacDevice.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.eraseMacDevice.then.
  • Source: resource.dsl.do.eraseMacDevice.then
  • Usage: workflow_create
entity.data.dsl.do.eraseMacDevice.with.bodyParams.pin
  • Description: JumpCloud extension data on the managed entity: dsl.do.eraseMacDevice.with.bodyParams.pin.
  • Source: resource.dsl.do.eraseMacDevice.with.bodyParams.pin
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.eraseMacDevice.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.eraseMacDevice.with.operationId.
  • Source: resource.dsl.do.eraseMacDevice.with.operationId
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.eraseMacDevice.with.pathParams.apple_mdm_id
  • Description: JumpCloud extension data on the managed entity: dsl.do.eraseMacDevice.with.pathParams.apple_mdm_id.
  • Source: resource.dsl.do.eraseMacDevice.with.pathParams.apple_mdm_id
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.eraseMacDevice.with.pathParams.device_id
  • Description: JumpCloud extension data on the managed entity: dsl.do.eraseMacDevice.with.pathParams.device_id.
  • Source: resource.dsl.do.eraseMacDevice.with.pathParams.device_id
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.eraseMacDevice.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.eraseMacDevice.with.version.
  • Source: resource.dsl.do.eraseMacDevice.with.version
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.eraseOtherDevice.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.eraseOtherDevice.call.
  • Source: resource.dsl.do.eraseOtherDevice.call
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.eraseOtherDevice.if
  • Description: JumpCloud extension data on the managed entity: dsl.do.eraseOtherDevice.if.
  • Source: resource.dsl.do.eraseOtherDevice.if
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.eraseOtherDevice.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.eraseOtherDevice.then.
  • Source: resource.dsl.do.eraseOtherDevice.then
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.eraseOtherDevice.with.bodyParams
  • Description: JumpCloud extension data on the managed entity: dsl.do.eraseOtherDevice.with.bodyParams.
  • Source: resource.dsl.do.eraseOtherDevice.with.bodyParams
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.eraseOtherDevice.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.eraseOtherDevice.with.operationId.
  • Source: resource.dsl.do.eraseOtherDevice.with.operationId
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.eraseOtherDevice.with.pathParams.system_id
  • Description: JumpCloud extension data on the managed entity: dsl.do.eraseOtherDevice.with.pathParams.system_id.
  • Source: resource.dsl.do.eraseOtherDevice.with.pathParams.system_id
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.eraseOtherDevice.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.eraseOtherDevice.with.version.
  • Source: resource.dsl.do.eraseOtherDevice.with.version
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.evaluateGates.switch.default.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.evaluateGates.switch.default.then.
  • Source: resource.dsl.do.evaluateGates.switch.default.then
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.evaluateGates.switch.shouldStrip.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.evaluateGates.switch.shouldStrip.then.
  • Source: resource.dsl.do.evaluateGates.switch.shouldStrip.then
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.evaluateGates.switch.shouldStrip.when
  • Description: JumpCloud extension data on the managed entity: dsl.do.evaluateGates.switch.shouldStrip.when.
  • Source: resource.dsl.do.evaluateGates.switch.shouldStrip.when
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.externalAppConnectorAction.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.externalAppConnectorAction.call.
  • Source: resource.dsl.do.externalAppConnectorAction.call
  • Usage: workflow_create
entity.data.dsl.do.externalAppConnectorAction.with.body.userId
  • Description: JumpCloud extension data on the managed entity: dsl.do.externalAppConnectorAction.with.body.userId.
  • Source: resource.dsl.do.externalAppConnectorAction.with.body.userId
  • Usage: workflow_create
entity.data.dsl.do.externalAppConnectorAction.with.endpointPath
  • Description: JumpCloud extension data on the managed entity: dsl.do.externalAppConnectorAction.with.endpointPath.
  • Source: resource.dsl.do.externalAppConnectorAction.with.endpointPath
  • Usage: workflow_create
entity.data.dsl.do.externalAppConnectorAction.with.headers.Custom-Header
  • Description: JumpCloud extension data on the managed entity: dsl.do.externalAppConnectorAction.with.headers.Custom-Header.
  • Source: resource.dsl.do.externalAppConnectorAction.with.headers.Custom-Header
  • Usage: workflow_create
entity.data.dsl.do.externalAppConnectorAction.with.httpMethod
  • Description: JumpCloud extension data on the managed entity: dsl.do.externalAppConnectorAction.with.httpMethod.
  • Source: resource.dsl.do.externalAppConnectorAction.with.httpMethod
  • Usage: workflow_create
entity.data.dsl.do.externalAppConnectorAction.with.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.externalAppConnectorAction.with.id.
  • Source: resource.dsl.do.externalAppConnectorAction.with.id
  • Usage: workflow_create
entity.data.dsl.do.findScheduledActivations.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.findScheduledActivations.call.
  • Source: resource.dsl.do.findScheduledActivations.call
  • Usage: workflow_create
entity.data.dsl.do.findScheduledActivations.with.extract
  • Description: JumpCloud extension data on the managed entity: dsl.do.findScheduledActivations.with.extract.
  • Source: resource.dsl.do.findScheduledActivations.with.extract
  • Usage: workflow_create
entity.data.dsl.do.findScheduledActivations.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.findScheduledActivations.with.operationId.
  • Source: resource.dsl.do.findScheduledActivations.with.operationId
  • Usage: workflow_create
entity.data.dsl.do.findScheduledActivations.with.pagination.until
  • Description: JumpCloud extension data on the managed entity: dsl.do.findScheduledActivations.with.pagination.until.
  • Source: resource.dsl.do.findScheduledActivations.with.pagination.until
  • Usage: workflow_create
entity.data.dsl.do.findScheduledActivations.with.pagination.update.in
  • Description: JumpCloud extension data on the managed entity: dsl.do.findScheduledActivations.with.pagination.update.in.
  • Source: resource.dsl.do.findScheduledActivations.with.pagination.update.in
  • Usage: workflow_create
entity.data.dsl.do.findScheduledActivations.with.pagination.update.key
  • Description: JumpCloud extension data on the managed entity: dsl.do.findScheduledActivations.with.pagination.update.key.
  • Source: resource.dsl.do.findScheduledActivations.with.pagination.update.key
  • Usage: workflow_create
entity.data.dsl.do.findScheduledActivations.with.pagination.update.value
  • Description: JumpCloud extension data on the managed entity: dsl.do.findScheduledActivations.with.pagination.update.value.
  • Source: resource.dsl.do.findScheduledActivations.with.pagination.update.value
  • Usage: workflow_create
entity.data.dsl.do.findScheduledActivations.with.queryParams.filter
  • Description: JumpCloud extension data on the managed entity: dsl.do.findScheduledActivations.with.queryParams.filter.
  • Source: resource.dsl.do.findScheduledActivations.with.queryParams.filter
  • Usage: workflow_create
entity.data.dsl.do.findScheduledActivations.with.queryParams.limit
  • Description: JumpCloud extension data on the managed entity: dsl.do.findScheduledActivations.with.queryParams.limit.
  • Source: resource.dsl.do.findScheduledActivations.with.queryParams.limit
  • Usage: workflow_create
entity.data.dsl.do.findScheduledActivations.with.queryParams.skip
  • Description: JumpCloud extension data on the managed entity: dsl.do.findScheduledActivations.with.queryParams.skip.
  • Source: resource.dsl.do.findScheduledActivations.with.queryParams.skip
  • Usage: workflow_create
entity.data.dsl.do.findScheduledActivations.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.findScheduledActivations.with.version.
  • Source: resource.dsl.do.findScheduledActivations.with.version
  • Usage: workflow_create
entity.data.dsl.do.getAllUsersGroup.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.getAllUsersGroup.call.
  • Source: resource.dsl.do.getAllUsersGroup.call
  • Usage: workflow_create
entity.data.dsl.do.getAllUsersGroup.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.getAllUsersGroup.with.operationId.
  • Source: resource.dsl.do.getAllUsersGroup.with.operationId
  • Usage: workflow_create
entity.data.dsl.do.getAllUsersGroup.with.queryParams.fields
  • Description: JumpCloud extension data on the managed entity: dsl.do.getAllUsersGroup.with.queryParams.fields.
  • Source: resource.dsl.do.getAllUsersGroup.with.queryParams.fields
  • Usage: workflow_create
entity.data.dsl.do.getAllUsersGroup.with.queryParams.filter
  • Description: JumpCloud extension data on the managed entity: dsl.do.getAllUsersGroup.with.queryParams.filter.
  • Source: resource.dsl.do.getAllUsersGroup.with.queryParams.filter
  • Usage: workflow_create
entity.data.dsl.do.getAllUsersGroup.with.queryParams.limit
  • Description: JumpCloud extension data on the managed entity: dsl.do.getAllUsersGroup.with.queryParams.limit.
  • Source: resource.dsl.do.getAllUsersGroup.with.queryParams.limit
  • Usage: workflow_create
entity.data.dsl.do.getAllUsersGroup.with.queryParams.skip
  • Description: JumpCloud extension data on the managed entity: dsl.do.getAllUsersGroup.with.queryParams.skip.
  • Source: resource.dsl.do.getAllUsersGroup.with.queryParams.skip
  • Usage: workflow_create
entity.data.dsl.do.getAllUsersGroup.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.getAllUsersGroup.with.version.
  • Source: resource.dsl.do.getAllUsersGroup.with.version
  • Usage: workflow_create
entity.data.dsl.do.getAppAssociations.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.getAppAssociations.call.
  • Source: resource.dsl.do.getAppAssociations.call
  • Usage: workflow_create
entity.data.dsl.do.getAppAssociations.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.getAppAssociations.with.operationId.
  • Source: resource.dsl.do.getAppAssociations.with.operationId
  • Usage: workflow_create
entity.data.dsl.do.getAppAssociations.with.pathParams.application_id
  • Description: JumpCloud extension data on the managed entity: dsl.do.getAppAssociations.with.pathParams.application_id.
  • Source: resource.dsl.do.getAppAssociations.with.pathParams.application_id
  • Usage: workflow_create
entity.data.dsl.do.getAppAssociations.with.queryParams.limit
  • Description: JumpCloud extension data on the managed entity: dsl.do.getAppAssociations.with.queryParams.limit.
  • Source: resource.dsl.do.getAppAssociations.with.queryParams.limit
  • Usage: workflow_create
entity.data.dsl.do.getAppAssociations.with.queryParams.skip
  • Description: JumpCloud extension data on the managed entity: dsl.do.getAppAssociations.with.queryParams.skip.
  • Source: resource.dsl.do.getAppAssociations.with.queryParams.skip
  • Usage: workflow_create
entity.data.dsl.do.getAppAssociations.with.queryParams.targets
  • Description: JumpCloud extension data on the managed entity: dsl.do.getAppAssociations.with.queryParams.targets.
  • Source: resource.dsl.do.getAppAssociations.with.queryParams.targets
  • Usage: workflow_create
entity.data.dsl.do.getAppAssociations.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.getAppAssociations.with.version.
  • Source: resource.dsl.do.getAppAssociations.with.version
  • Usage: workflow_create
entity.data.dsl.do.getDeviceAsset.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.getDeviceAsset.call.
  • Source: resource.dsl.do.getDeviceAsset.call
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.getDeviceAsset.if
  • Description: JumpCloud extension data on the managed entity: dsl.do.getDeviceAsset.if.
  • Source: resource.dsl.do.getDeviceAsset.if
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.getDeviceAsset.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.getDeviceAsset.then.
  • Source: resource.dsl.do.getDeviceAsset.then
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.getDeviceAsset.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.getDeviceAsset.with.operationId.
  • Source: resource.dsl.do.getDeviceAsset.with.operationId
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.getDeviceAsset.with.pathParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.getDeviceAsset.with.pathParams.id.
  • Source: resource.dsl.do.getDeviceAsset.with.pathParams.id
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.getDeviceAsset.with.pathParams.jcSystemId
  • Description: JumpCloud extension data on the managed entity: dsl.do.getDeviceAsset.with.pathParams.jcSystemId.
  • Source: resource.dsl.do.getDeviceAsset.with.pathParams.jcSystemId
  • Usage: workflow_create
entity.data.dsl.do.getDeviceAsset.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.getDeviceAsset.with.version.
  • Source: resource.dsl.do.getDeviceAsset.with.version
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.getDeviceAssetByJCSystemID.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.getDeviceAssetByJCSystemID.call.
  • Source: resource.dsl.do.getDeviceAssetByJCSystemID.call
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.getDeviceAssetByJCSystemID.if
  • Description: JumpCloud extension data on the managed entity: dsl.do.getDeviceAssetByJCSystemID.if.
  • Source: resource.dsl.do.getDeviceAssetByJCSystemID.if
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.getDeviceAssetByJCSystemID.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.getDeviceAssetByJCSystemID.then.
  • Source: resource.dsl.do.getDeviceAssetByJCSystemID.then
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.getDeviceAssetByJCSystemID.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.getDeviceAssetByJCSystemID.with.operationId.
  • Source: resource.dsl.do.getDeviceAssetByJCSystemID.with.operationId
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.getDeviceAssetByJCSystemID.with.pathParams.jcSystemId
  • Description: JumpCloud extension data on the managed entity: dsl.do.getDeviceAssetByJCSystemID.with.pathParams.jcSystemId.
  • Source: resource.dsl.do.getDeviceAssetByJCSystemID.with.pathParams.jcSystemId
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.getDeviceAssetByJCSystemID.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.getDeviceAssetByJCSystemID.with.version.
  • Source: resource.dsl.do.getDeviceAssetByJCSystemID.with.version
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.getDeviceAssetFull.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.getDeviceAssetFull.call.
  • Source: resource.dsl.do.getDeviceAssetFull.call
  • Usage: workflow_create
entity.data.dsl.do.getDeviceAssetFull.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.getDeviceAssetFull.with.operationId.
  • Source: resource.dsl.do.getDeviceAssetFull.with.operationId
  • Usage: workflow_create
entity.data.dsl.do.getDeviceAssetFull.with.pathParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.getDeviceAssetFull.with.pathParams.id.
  • Source: resource.dsl.do.getDeviceAssetFull.with.pathParams.id
  • Usage: workflow_create
entity.data.dsl.do.getDeviceAssetFull.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.getDeviceAssetFull.with.version.
  • Source: resource.dsl.do.getDeviceAssetFull.with.version
  • Usage: workflow_create
entity.data.dsl.do.getManagerDetails.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.getManagerDetails.call.
  • Source: resource.dsl.do.getManagerDetails.call
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.getManagerDetails.if
  • Description: JumpCloud extension data on the managed entity: dsl.do.getManagerDetails.if.
  • Source: resource.dsl.do.getManagerDetails.if
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.getManagerDetails.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.getManagerDetails.with.operationId.
  • Source: resource.dsl.do.getManagerDetails.with.operationId
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.getManagerDetails.with.pathParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.getManagerDetails.with.pathParams.id.
  • Source: resource.dsl.do.getManagerDetails.with.pathParams.id
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.getManagerDetails.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.getManagerDetails.with.version.
  • Source: resource.dsl.do.getManagerDetails.with.version
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.getPolicyResults.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.getPolicyResults.call.
  • Source: resource.dsl.do.getPolicyResults.call
  • Usage: workflow_create
entity.data.dsl.do.getPolicyResults.with.extract
  • Description: JumpCloud extension data on the managed entity: dsl.do.getPolicyResults.with.extract.
  • Source: resource.dsl.do.getPolicyResults.with.extract
  • Usage: workflow_create
entity.data.dsl.do.getPolicyResults.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.getPolicyResults.with.operationId.
  • Source: resource.dsl.do.getPolicyResults.with.operationId
  • Usage: workflow_create
entity.data.dsl.do.getPolicyResults.with.pagination.until
  • Description: JumpCloud extension data on the managed entity: dsl.do.getPolicyResults.with.pagination.until.
  • Source: resource.dsl.do.getPolicyResults.with.pagination.until
  • Usage: workflow_create
entity.data.dsl.do.getPolicyResults.with.pagination.update.in
  • Description: JumpCloud extension data on the managed entity: dsl.do.getPolicyResults.with.pagination.update.in.
  • Source: resource.dsl.do.getPolicyResults.with.pagination.update.in
  • Usage: workflow_create
entity.data.dsl.do.getPolicyResults.with.pagination.update.key
  • Description: JumpCloud extension data on the managed entity: dsl.do.getPolicyResults.with.pagination.update.key.
  • Source: resource.dsl.do.getPolicyResults.with.pagination.update.key
  • Usage: workflow_create
entity.data.dsl.do.getPolicyResults.with.pagination.update.value
  • Description: JumpCloud extension data on the managed entity: dsl.do.getPolicyResults.with.pagination.update.value.
  • Source: resource.dsl.do.getPolicyResults.with.pagination.update.value
  • Usage: workflow_create
entity.data.dsl.do.getPolicyResults.with.pathParams.policy_id
  • Description: JumpCloud extension data on the managed entity: dsl.do.getPolicyResults.with.pathParams.policy_id.
  • Source: resource.dsl.do.getPolicyResults.with.pathParams.policy_id
  • Usage: workflow_create
entity.data.dsl.do.getPolicyResults.with.queryParams.filter
  • Description: JumpCloud extension data on the managed entity: dsl.do.getPolicyResults.with.queryParams.filter.
  • Source: resource.dsl.do.getPolicyResults.with.queryParams.filter
  • Usage: workflow_create
entity.data.dsl.do.getPolicyResults.with.queryParams.limit
  • Description: JumpCloud extension data on the managed entity: dsl.do.getPolicyResults.with.queryParams.limit.
  • Source: resource.dsl.do.getPolicyResults.with.queryParams.limit
  • Usage: workflow_create
entity.data.dsl.do.getPolicyResults.with.queryParams.skip
  • Description: JumpCloud extension data on the managed entity: dsl.do.getPolicyResults.with.queryParams.skip.
  • Source: resource.dsl.do.getPolicyResults.with.queryParams.skip
  • Usage: workflow_create
entity.data.dsl.do.getPolicyResults.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.getPolicyResults.with.version.
  • Source: resource.dsl.do.getPolicyResults.with.version
  • Usage: workflow_create
entity.data.dsl.do.getPrimaryDevice.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.getPrimaryDevice.call.
  • Source: resource.dsl.do.getPrimaryDevice.call
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.getPrimaryDevice.if
  • Description: JumpCloud extension data on the managed entity: dsl.do.getPrimaryDevice.if.
  • Source: resource.dsl.do.getPrimaryDevice.if
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.getPrimaryDevice.metadata.displayLabels.filter
  • Description: JumpCloud extension data on the managed entity: dsl.do.getPrimaryDevice.metadata.displayLabels.filter.
  • Source: resource.dsl.do.getPrimaryDevice.metadata.displayLabels.filter
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.getPrimaryDevice.metadata.displayLabels.limit
  • Description: JumpCloud extension data on the managed entity: dsl.do.getPrimaryDevice.metadata.displayLabels.limit.
  • Source: resource.dsl.do.getPrimaryDevice.metadata.displayLabels.limit
  • Usage: workflow_create
entity.data.dsl.do.getPrimaryDevice.metadata.displayLabels.skip
  • Description: JumpCloud extension data on the managed entity: dsl.do.getPrimaryDevice.metadata.displayLabels.skip.
  • Source: resource.dsl.do.getPrimaryDevice.metadata.displayLabels.skip
  • Usage: workflow_create
entity.data.dsl.do.getPrimaryDevice.metadata.inputModes.fields
  • Description: JumpCloud extension data on the managed entity: dsl.do.getPrimaryDevice.metadata.inputModes.fields.
  • Source: resource.dsl.do.getPrimaryDevice.metadata.inputModes.fields
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.getPrimaryDevice.metadata.inputModes.filter
  • Description: JumpCloud extension data on the managed entity: dsl.do.getPrimaryDevice.metadata.inputModes.filter.
  • Source: resource.dsl.do.getPrimaryDevice.metadata.inputModes.filter
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.getPrimaryDevice.metadata.inputModes.limit
  • Description: JumpCloud extension data on the managed entity: dsl.do.getPrimaryDevice.metadata.inputModes.limit.
  • Source: resource.dsl.do.getPrimaryDevice.metadata.inputModes.limit
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.getPrimaryDevice.metadata.inputModes.skip
  • Description: JumpCloud extension data on the managed entity: dsl.do.getPrimaryDevice.metadata.inputModes.skip.
  • Source: resource.dsl.do.getPrimaryDevice.metadata.inputModes.skip
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.getPrimaryDevice.with.bodyParams.fields
  • Description: JumpCloud extension data on the managed entity: dsl.do.getPrimaryDevice.with.bodyParams.fields.
  • Source: resource.dsl.do.getPrimaryDevice.with.bodyParams.fields
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.getPrimaryDevice.with.bodyParams.filter.and.primarySystemUser._id
  • Description: JumpCloud extension data on the managed entity: dsl.do.getPrimaryDevice.with.bodyParams.filter.and.primarySystemUser._id.
  • Source: resource.dsl.do.getPrimaryDevice.with.bodyParams.filter.and.primarySystemUser._id
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.getPrimaryDevice.with.bodyParams.filter.and.primarySystemUser.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.getPrimaryDevice.with.bodyParams.filter.and.primarySystemUser.id.
  • Source: resource.dsl.do.getPrimaryDevice.with.bodyParams.filter.and.primarySystemUser.id
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.getPrimaryDevice.with.extract
  • Description: JumpCloud extension data on the managed entity: dsl.do.getPrimaryDevice.with.extract.
  • Source: resource.dsl.do.getPrimaryDevice.with.extract
  • Usage: workflow_create
entity.data.dsl.do.getPrimaryDevice.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.getPrimaryDevice.with.operationId.
  • Source: resource.dsl.do.getPrimaryDevice.with.operationId
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.getPrimaryDevice.with.pagination.until
  • Description: JumpCloud extension data on the managed entity: dsl.do.getPrimaryDevice.with.pagination.until.
  • Source: resource.dsl.do.getPrimaryDevice.with.pagination.until
  • Usage: workflow_create
entity.data.dsl.do.getPrimaryDevice.with.pagination.update.in
  • Description: JumpCloud extension data on the managed entity: dsl.do.getPrimaryDevice.with.pagination.update.in.
  • Source: resource.dsl.do.getPrimaryDevice.with.pagination.update.in
  • Usage: workflow_create
entity.data.dsl.do.getPrimaryDevice.with.pagination.update.key
  • Description: JumpCloud extension data on the managed entity: dsl.do.getPrimaryDevice.with.pagination.update.key.
  • Source: resource.dsl.do.getPrimaryDevice.with.pagination.update.key
  • Usage: workflow_create
entity.data.dsl.do.getPrimaryDevice.with.pagination.update.value
  • Description: JumpCloud extension data on the managed entity: dsl.do.getPrimaryDevice.with.pagination.update.value.
  • Source: resource.dsl.do.getPrimaryDevice.with.pagination.update.value
  • Usage: workflow_create
entity.data.dsl.do.getPrimaryDevice.with.queryParams.limit
  • Description: JumpCloud extension data on the managed entity: dsl.do.getPrimaryDevice.with.queryParams.limit.
  • Source: resource.dsl.do.getPrimaryDevice.with.queryParams.limit
  • Usage: workflow_create
entity.data.dsl.do.getPrimaryDevice.with.queryParams.skip
  • Description: JumpCloud extension data on the managed entity: dsl.do.getPrimaryDevice.with.queryParams.skip.
  • Source: resource.dsl.do.getPrimaryDevice.with.queryParams.skip
  • Usage: workflow_create
entity.data.dsl.do.getPrimaryDevice.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.getPrimaryDevice.with.version.
  • Source: resource.dsl.do.getPrimaryDevice.with.version
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.getPrimaryDeviceForUser.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.getPrimaryDeviceForUser.call.
  • Source: resource.dsl.do.getPrimaryDeviceForUser.call
  • Usage: workflow_create
entity.data.dsl.do.getPrimaryDeviceForUser.metadata.displayLabels.user
  • Description: JumpCloud extension data on the managed entity: dsl.do.getPrimaryDeviceForUser.metadata.displayLabels.user.
  • Source: resource.dsl.do.getPrimaryDeviceForUser.metadata.displayLabels.user
  • Usage: workflow_create
entity.data.dsl.do.getPrimaryDeviceForUser.metadata.inputModes.user
  • Description: JumpCloud extension data on the managed entity: dsl.do.getPrimaryDeviceForUser.metadata.inputModes.user.
  • Source: resource.dsl.do.getPrimaryDeviceForUser.metadata.inputModes.user
  • Usage: workflow_create
entity.data.dsl.do.getPrimaryDeviceForUser.with.bodyParams.fields
  • Description: JumpCloud extension data on the managed entity: dsl.do.getPrimaryDeviceForUser.with.bodyParams.fields.
  • Source: resource.dsl.do.getPrimaryDeviceForUser.with.bodyParams.fields
  • Usage: workflow_create
entity.data.dsl.do.getPrimaryDeviceForUser.with.bodyParams.filter.and.primarySystemUser.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.getPrimaryDeviceForUser.with.bodyParams.filter.and.primarySystemUser.id.
  • Source: resource.dsl.do.getPrimaryDeviceForUser.with.bodyParams.filter.and.primarySystemUser.id
  • Usage: workflow_create
entity.data.dsl.do.getPrimaryDeviceForUser.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.getPrimaryDeviceForUser.with.operationId.
  • Source: resource.dsl.do.getPrimaryDeviceForUser.with.operationId
  • Usage: workflow_create
entity.data.dsl.do.getPrimaryDeviceForUser.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.getPrimaryDeviceForUser.with.version.
  • Source: resource.dsl.do.getPrimaryDeviceForUser.with.version
  • Usage: workflow_create
entity.data.dsl.do.getPrimaryUserFromDevice.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.getPrimaryUserFromDevice.call.
  • Source: resource.dsl.do.getPrimaryUserFromDevice.call
  • Usage: workflow_create
entity.data.dsl.do.getPrimaryUserFromDevice.metadata.displayLabels.device
  • Description: JumpCloud extension data on the managed entity: dsl.do.getPrimaryUserFromDevice.metadata.displayLabels.device.
  • Source: resource.dsl.do.getPrimaryUserFromDevice.metadata.displayLabels.device
  • Usage: workflow_create
entity.data.dsl.do.getPrimaryUserFromDevice.metadata.inputModes.device
  • Description: JumpCloud extension data on the managed entity: dsl.do.getPrimaryUserFromDevice.metadata.inputModes.device.
  • Source: resource.dsl.do.getPrimaryUserFromDevice.metadata.inputModes.device
  • Usage: workflow_create
entity.data.dsl.do.getPrimaryUserFromDevice.metadata.inputModes.fields
  • Description: JumpCloud extension data on the managed entity: dsl.do.getPrimaryUserFromDevice.metadata.inputModes.fields.
  • Source: resource.dsl.do.getPrimaryUserFromDevice.metadata.inputModes.fields
  • Usage: workflow_create
entity.data.dsl.do.getPrimaryUserFromDevice.metadata.inputModes.filter
  • Description: JumpCloud extension data on the managed entity: dsl.do.getPrimaryUserFromDevice.metadata.inputModes.filter.
  • Source: resource.dsl.do.getPrimaryUserFromDevice.metadata.inputModes.filter
  • Usage: workflow_create
entity.data.dsl.do.getPrimaryUserFromDevice.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.getPrimaryUserFromDevice.with.operationId.
  • Source: resource.dsl.do.getPrimaryUserFromDevice.with.operationId
  • Usage: workflow_create
entity.data.dsl.do.getPrimaryUserFromDevice.with.pathParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.getPrimaryUserFromDevice.with.pathParams.id.
  • Source: resource.dsl.do.getPrimaryUserFromDevice.with.pathParams.id
  • Usage: workflow_create
entity.data.dsl.do.getPrimaryUserFromDevice.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.getPrimaryUserFromDevice.with.version.
  • Source: resource.dsl.do.getPrimaryUserFromDevice.with.version
  • Usage: workflow_create
entity.data.dsl.do.getReportTemplate.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.getReportTemplate.call.
  • Source: resource.dsl.do.getReportTemplate.call
  • Usage: workflow_delete
entity.data.dsl.do.getReportTemplate.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.getReportTemplate.with.operationId.
  • Source: resource.dsl.do.getReportTemplate.with.operationId
  • Usage: workflow_delete
entity.data.dsl.do.getReportTemplate.with.pathParams.objectId
  • Description: JumpCloud extension data on the managed entity: dsl.do.getReportTemplate.with.pathParams.objectId.
  • Source: resource.dsl.do.getReportTemplate.with.pathParams.objectId
  • Usage: workflow_delete
entity.data.dsl.do.getReportTemplate.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.getReportTemplate.with.version.
  • Source: resource.dsl.do.getReportTemplate.with.version
  • Usage: workflow_delete
entity.data.dsl.do.getSystemDetails.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.getSystemDetails.call.
  • Source: resource.dsl.do.getSystemDetails.call
  • Usage: workflow_create
entity.data.dsl.do.getSystemDetails.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.getSystemDetails.with.operationId.
  • Source: resource.dsl.do.getSystemDetails.with.operationId
  • Usage: workflow_create
entity.data.dsl.do.getSystemDetails.with.pathParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.getSystemDetails.with.pathParams.id.
  • Source: resource.dsl.do.getSystemDetails.with.pathParams.id
  • Usage: workflow_create
entity.data.dsl.do.getSystemDetails.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.getSystemDetails.with.version.
  • Source: resource.dsl.do.getSystemDetails.with.version
  • Usage: workflow_create
entity.data.dsl.do.getSystemUsers.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.getSystemUsers.call.
  • Source: resource.dsl.do.getSystemUsers.call
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.getSystemUsers.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.getSystemUsers.with.operationId.
  • Source: resource.dsl.do.getSystemUsers.with.operationId
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.getSystemUsers.with.queryParams.limit
  • Description: JumpCloud extension data on the managed entity: dsl.do.getSystemUsers.with.queryParams.limit.
  • Source: resource.dsl.do.getSystemUsers.with.queryParams.limit
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.getSystemUsers.with.queryParams.skip
  • Description: JumpCloud extension data on the managed entity: dsl.do.getSystemUsers.with.queryParams.skip.
  • Source: resource.dsl.do.getSystemUsers.with.queryParams.skip
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.getSystemUsers.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.getSystemUsers.with.version.
  • Source: resource.dsl.do.getSystemUsers.with.version
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.getUser.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.getUser.call.
  • Source: resource.dsl.do.getUser.call
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.getUser.if
  • Description: JumpCloud extension data on the managed entity: dsl.do.getUser.if.
  • Source: resource.dsl.do.getUser.if
  • Usage: workflow_create
entity.data.dsl.do.getUser.metadata.compositePocUpdateUserAttrs.attributePairs
  • Description: JumpCloud extension data on the managed entity: dsl.do.getUser.metadata.compositePocUpdateUserAttrs.attributePairs.
  • Source: resource.dsl.do.getUser.metadata.compositePocUpdateUserAttrs.attributePairs
  • Usage: workflow_delete
entity.data.dsl.do.getUser.metadata.compositePocUpdateUserAttrs.getTaskName
  • Description: JumpCloud extension data on the managed entity: dsl.do.getUser.metadata.compositePocUpdateUserAttrs.getTaskName.
  • Source: resource.dsl.do.getUser.metadata.compositePocUpdateUserAttrs.getTaskName
  • Usage: workflow_delete
entity.data.dsl.do.getUser.metadata.compositePocUpdateUserAttrs.putTaskName
  • Description: JumpCloud extension data on the managed entity: dsl.do.getUser.metadata.compositePocUpdateUserAttrs.putTaskName.
  • Source: resource.dsl.do.getUser.metadata.compositePocUpdateUserAttrs.putTaskName
  • Usage: workflow_delete
entity.data.dsl.do.getUser.metadata.compositePocUpdateUserAttrs.role
  • Description: JumpCloud extension data on the managed entity: dsl.do.getUser.metadata.compositePocUpdateUserAttrs.role.
  • Source: resource.dsl.do.getUser.metadata.compositePocUpdateUserAttrs.role
  • Usage: workflow_delete
entity.data.dsl.do.getUser.metadata.compositePocUpdateUserAttrs.templateId
  • Description: JumpCloud extension data on the managed entity: dsl.do.getUser.metadata.compositePocUpdateUserAttrs.templateId.
  • Source: resource.dsl.do.getUser.metadata.compositePocUpdateUserAttrs.templateId
  • Usage: workflow_delete
entity.data.dsl.do.getUser.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.getUser.with.operationId.
  • Source: resource.dsl.do.getUser.with.operationId
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.getUser.with.pathParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.getUser.with.pathParams.id.
  • Source: resource.dsl.do.getUser.with.pathParams.id
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.getUser.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.getUser.with.version.
  • Source: resource.dsl.do.getUser.with.version
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.getUserDetails.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.getUserDetails.call.
  • Source: resource.dsl.do.getUserDetails.call
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.getUserDetails.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.getUserDetails.with.operationId.
  • Source: resource.dsl.do.getUserDetails.with.operationId
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.getUserDetails.with.pathParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.getUserDetails.with.pathParams.id.
  • Source: resource.dsl.do.getUserDetails.with.pathParams.id
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.getUserDetails.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.getUserDetails.with.version.
  • Source: resource.dsl.do.getUserDetails.with.version
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.get_system_details.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.get_system_details.call.
  • Source: resource.dsl.do.get_system_details.call
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.get_system_details.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.get_system_details.with.operationId.
  • Source: resource.dsl.do.get_system_details.with.operationId
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.get_system_details.with.pathParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.get_system_details.with.pathParams.id.
  • Source: resource.dsl.do.get_system_details.with.pathParams.id
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.get_system_details.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.get_system_details.with.version.
  • Source: resource.dsl.do.get_system_details.with.version
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.graphUserTraverseSystem.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.graphUserTraverseSystem.call.
  • Source: resource.dsl.do.graphUserTraverseSystem.call
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.graphUserTraverseSystem.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.graphUserTraverseSystem.with.operationId.
  • Source: resource.dsl.do.graphUserTraverseSystem.with.operationId
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.graphUserTraverseSystem.with.pathParams.user_id
  • Description: JumpCloud extension data on the managed entity: dsl.do.graphUserTraverseSystem.with.pathParams.user_id.
  • Source: resource.dsl.do.graphUserTraverseSystem.with.pathParams.user_id
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.graphUserTraverseSystem.with.queryParams.filter
  • Description: JumpCloud extension data on the managed entity: dsl.do.graphUserTraverseSystem.with.queryParams.filter.
  • Source: resource.dsl.do.graphUserTraverseSystem.with.queryParams.filter
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.graphUserTraverseSystem.with.queryParams.limit
  • Description: JumpCloud extension data on the managed entity: dsl.do.graphUserTraverseSystem.with.queryParams.limit.
  • Source: resource.dsl.do.graphUserTraverseSystem.with.queryParams.limit
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.graphUserTraverseSystem.with.queryParams.skip
  • Description: JumpCloud extension data on the managed entity: dsl.do.graphUserTraverseSystem.with.queryParams.skip.
  • Source: resource.dsl.do.graphUserTraverseSystem.with.queryParams.skip
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.graphUserTraverseSystem.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.graphUserTraverseSystem.with.version.
  • Source: resource.dsl.do.graphUserTraverseSystem.with.version
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.graph_userAssociationsPost.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.graph_userAssociationsPost.call.
  • Source: resource.dsl.do.graph_userAssociationsPost.call
  • Usage: workflow_delete
entity.data.dsl.do.graph_userAssociationsPost.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.graph_userAssociationsPost.with.operationId.
  • Source: resource.dsl.do.graph_userAssociationsPost.with.operationId
  • Usage: workflow_delete
entity.data.dsl.do.graph_userAssociationsPost.with.pathParams.user_id
  • Description: JumpCloud extension data on the managed entity: dsl.do.graph_userAssociationsPost.with.pathParams.user_id.
  • Source: resource.dsl.do.graph_userAssociationsPost.with.pathParams.user_id
  • Usage: workflow_delete
entity.data.dsl.do.graph_userAssociationsPost.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.graph_userAssociationsPost.with.version.
  • Source: resource.dsl.do.graph_userAssociationsPost.with.version
  • Usage: workflow_delete
entity.data.dsl.do.groups_policy_post.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.groups_policy_post.call.
  • Source: resource.dsl.do.groups_policy_post.call
  • Usage: workflow_delete
entity.data.dsl.do.groups_policy_post.with.bodyParams.name
  • Description: JumpCloud extension data on the managed entity: dsl.do.groups_policy_post.with.bodyParams.name.
  • Source: resource.dsl.do.groups_policy_post.with.bodyParams.name
  • Usage: workflow_delete
entity.data.dsl.do.groups_policy_post.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.groups_policy_post.with.operationId.
  • Source: resource.dsl.do.groups_policy_post.with.operationId
  • Usage: workflow_delete
entity.data.dsl.do.groups_policy_post.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.groups_policy_post.with.version.
  • Source: resource.dsl.do.groups_policy_post.with.version
  • Usage: workflow_delete
entity.data.dsl.do.idsourcesGet.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.idsourcesGet.call.
  • Source: resource.dsl.do.idsourcesGet.call
  • Usage: workflow_create
entity.data.dsl.do.idsourcesGet.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.idsourcesGet.with.operationId.
  • Source: resource.dsl.do.idsourcesGet.with.operationId
  • Usage: workflow_create
entity.data.dsl.do.idsourcesGet.with.pathParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.idsourcesGet.with.pathParams.id.
  • Source: resource.dsl.do.idsourcesGet.with.pathParams.id
  • Usage: workflow_create
entity.data.dsl.do.idsourcesGet.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.idsourcesGet.with.version.
  • Source: resource.dsl.do.idsourcesGet.with.version
  • Usage: workflow_create
entity.data.dsl.do.ifElse.switch.condition1.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.ifElse.switch.condition1.then.
  • Source: resource.dsl.do.ifElse.switch.condition1.then
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.ifElse.switch.condition1.when
  • Description: JumpCloud extension data on the managed entity: dsl.do.ifElse.switch.condition1.when.
  • Source: resource.dsl.do.ifElse.switch.condition1.when
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.ifElse.switch.condition2.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.ifElse.switch.condition2.then.
  • Source: resource.dsl.do.ifElse.switch.condition2.then
  • Usage: workflow_delete
entity.data.dsl.do.ifElse.switch.condition2.when
  • Description: JumpCloud extension data on the managed entity: dsl.do.ifElse.switch.condition2.when.
  • Source: resource.dsl.do.ifElse.switch.condition2.when
  • Usage: workflow_delete
entity.data.dsl.do.ifElse.switch.condition3.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.ifElse.switch.condition3.then.
  • Source: resource.dsl.do.ifElse.switch.condition3.then
  • Usage: workflow_delete
entity.data.dsl.do.ifElse.switch.condition3.when
  • Description: JumpCloud extension data on the managed entity: dsl.do.ifElse.switch.condition3.when.
  • Source: resource.dsl.do.ifElse.switch.condition3.when
  • Usage: workflow_delete
entity.data.dsl.do.ifElse.switch.default.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.ifElse.switch.default.then.
  • Source: resource.dsl.do.ifElse.switch.default.then
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.ifElse2.switch.condition1.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.ifElse2.switch.condition1.then.
  • Source: resource.dsl.do.ifElse2.switch.condition1.then
  • Usage: workflow_delete
entity.data.dsl.do.ifElse2.switch.condition1.when
  • Description: JumpCloud extension data on the managed entity: dsl.do.ifElse2.switch.condition1.when.
  • Source: resource.dsl.do.ifElse2.switch.condition1.when
  • Usage: workflow_delete
entity.data.dsl.do.ifElse2.switch.default.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.ifElse2.switch.default.then.
  • Source: resource.dsl.do.ifElse2.switch.default.then
  • Usage: workflow_delete
entity.data.dsl.do.installSlack.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.installSlack.call.
  • Source: resource.dsl.do.installSlack.call
  • Usage: workflow_update
entity.data.dsl.do.installSlack.with.bodyParams.displayName
  • Description: JumpCloud extension data on the managed entity: dsl.do.installSlack.with.bodyParams.displayName.
  • Source: resource.dsl.do.installSlack.with.bodyParams.displayName
  • Usage: workflow_update
entity.data.dsl.do.installSlack.with.bodyParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.installSlack.with.bodyParams.id.
  • Source: resource.dsl.do.installSlack.with.bodyParams.id
  • Usage: workflow_update
entity.data.dsl.do.installSlack.with.bodyParams.settings.allowUpdateDelay
  • Description: JumpCloud extension data on the managed entity: dsl.do.installSlack.with.bodyParams.settings.allowUpdateDelay.
  • Source: resource.dsl.do.installSlack.with.bodyParams.settings.allowUpdateDelay
  • Usage: workflow_update
entity.data.dsl.do.installSlack.with.bodyParams.settings.appleVpp
  • Description: JumpCloud extension data on the managed entity: dsl.do.installSlack.with.bodyParams.settings.appleVpp.
  • Source: resource.dsl.do.installSlack.with.bodyParams.settings.appleVpp
  • Usage: workflow_update
entity.data.dsl.do.installSlack.with.bodyParams.settings.assetKind
  • Description: JumpCloud extension data on the managed entity: dsl.do.installSlack.with.bodyParams.settings.assetKind.
  • Source: resource.dsl.do.installSlack.with.bodyParams.settings.assetKind
  • Usage: workflow_update
entity.data.dsl.do.installSlack.with.bodyParams.settings.assetSha256Size
  • Description: JumpCloud extension data on the managed entity: dsl.do.installSlack.with.bodyParams.settings.assetSha256Size.
  • Source: resource.dsl.do.installSlack.with.bodyParams.settings.assetSha256Size
  • Usage: workflow_update
entity.data.dsl.do.installSlack.with.bodyParams.settings.assetSha256Strings
  • Description: JumpCloud extension data on the managed entity: dsl.do.installSlack.with.bodyParams.settings.assetSha256Strings.
  • Source: resource.dsl.do.installSlack.with.bodyParams.settings.assetSha256Strings
  • Usage: workflow_update
entity.data.dsl.do.installSlack.with.bodyParams.settings.autoUpdate
  • Description: JumpCloud extension data on the managed entity: dsl.do.installSlack.with.bodyParams.settings.autoUpdate.
  • Source: resource.dsl.do.installSlack.with.bodyParams.settings.autoUpdate
  • Usage: workflow_update
entity.data.dsl.do.installSlack.with.bodyParams.settings.commandLineArguments
  • Description: JumpCloud extension data on the managed entity: dsl.do.installSlack.with.bodyParams.settings.commandLineArguments.
  • Source: resource.dsl.do.installSlack.with.bodyParams.settings.commandLineArguments
  • Usage: workflow_update
entity.data.dsl.do.installSlack.with.bodyParams.settings.description
  • Description: JumpCloud extension data on the managed entity: dsl.do.installSlack.with.bodyParams.settings.description.
  • Source: resource.dsl.do.installSlack.with.bodyParams.settings.description
  • Usage: workflow_update
entity.data.dsl.do.installSlack.with.bodyParams.settings.desiredState
  • Description: JumpCloud extension data on the managed entity: dsl.do.installSlack.with.bodyParams.settings.desiredState.
  • Source: resource.dsl.do.installSlack.with.bodyParams.settings.desiredState
  • Usage: workflow_update
entity.data.dsl.do.installSlack.with.bodyParams.settings.location
  • Description: JumpCloud extension data on the managed entity: dsl.do.installSlack.with.bodyParams.settings.location.
  • Source: resource.dsl.do.installSlack.with.bodyParams.settings.location
  • Usage: workflow_update
entity.data.dsl.do.installSlack.with.bodyParams.settings.locationObjectId
  • Description: JumpCloud extension data on the managed entity: dsl.do.installSlack.with.bodyParams.settings.locationObjectId.
  • Source: resource.dsl.do.installSlack.with.bodyParams.settings.locationObjectId
  • Usage: workflow_update
entity.data.dsl.do.installSlack.with.bodyParams.settings.microsoftStore.doNotUpdate
  • Description: JumpCloud extension data on the managed entity: dsl.do.installSlack.with.bodyParams.settings.microsoftStore.doNotUpdate.
  • Source: resource.dsl.do.installSlack.with.bodyParams.settings.microsoftStore.doNotUpdate
  • Usage: workflow_update
entity.data.dsl.do.installSlack.with.bodyParams.settings.microsoftStore.nonRemovable
  • Description: JumpCloud extension data on the managed entity: dsl.do.installSlack.with.bodyParams.settings.microsoftStore.nonRemovable.
  • Source: resource.dsl.do.installSlack.with.bodyParams.settings.microsoftStore.nonRemovable
  • Usage: workflow_update
entity.data.dsl.do.installSlack.with.bodyParams.settings.microsoftStore.packageFamilyName
  • Description: JumpCloud extension data on the managed entity: dsl.do.installSlack.with.bodyParams.settings.microsoftStore.packageFamilyName.
  • Source: resource.dsl.do.installSlack.with.bodyParams.settings.microsoftStore.packageFamilyName
  • Usage: workflow_update
entity.data.dsl.do.installSlack.with.bodyParams.settings.packageId
  • Description: JumpCloud extension data on the managed entity: dsl.do.installSlack.with.bodyParams.settings.packageId.
  • Source: resource.dsl.do.installSlack.with.bodyParams.settings.packageId
  • Usage: workflow_update
entity.data.dsl.do.installSlack.with.bodyParams.settings.packageKind
  • Description: JumpCloud extension data on the managed entity: dsl.do.installSlack.with.bodyParams.settings.packageKind.
  • Source: resource.dsl.do.installSlack.with.bodyParams.settings.packageKind
  • Usage: workflow_update
entity.data.dsl.do.installSlack.with.bodyParams.settings.packageManager
  • Description: JumpCloud extension data on the managed entity: dsl.do.installSlack.with.bodyParams.settings.packageManager.
  • Source: resource.dsl.do.installSlack.with.bodyParams.settings.packageManager
  • Usage: workflow_update
entity.data.dsl.do.installSlack.with.bodyParams.settings.packageVersion
  • Description: JumpCloud extension data on the managed entity: dsl.do.installSlack.with.bodyParams.settings.packageVersion.
  • Source: resource.dsl.do.installSlack.with.bodyParams.settings.packageVersion
  • Usage: workflow_update
entity.data.dsl.do.installSlack.with.bodyParams.softwareAppId
  • Description: JumpCloud extension data on the managed entity: dsl.do.installSlack.with.bodyParams.softwareAppId.
  • Source: resource.dsl.do.installSlack.with.bodyParams.softwareAppId
  • Usage: workflow_update
entity.data.dsl.do.installSlack.with.bodyParams.uploadUrl
  • Description: JumpCloud extension data on the managed entity: dsl.do.installSlack.with.bodyParams.uploadUrl.
  • Source: resource.dsl.do.installSlack.with.bodyParams.uploadUrl
  • Usage: workflow_update
entity.data.dsl.do.installSlack.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.installSlack.with.operationId.
  • Source: resource.dsl.do.installSlack.with.operationId
  • Usage: workflow_update
entity.data.dsl.do.installSlack.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.installSlack.with.version.
  • Source: resource.dsl.do.installSlack.with.version
  • Usage: workflow_update
entity.data.dsl.do.listFailedPolicyResults.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.listFailedPolicyResults.call.
  • Source: resource.dsl.do.listFailedPolicyResults.call
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.listFailedPolicyResults.with.extract
  • Description: JumpCloud extension data on the managed entity: dsl.do.listFailedPolicyResults.with.extract.
  • Source: resource.dsl.do.listFailedPolicyResults.with.extract
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.listFailedPolicyResults.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.listFailedPolicyResults.with.operationId.
  • Source: resource.dsl.do.listFailedPolicyResults.with.operationId
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.listFailedPolicyResults.with.pagination.until
  • Description: JumpCloud extension data on the managed entity: dsl.do.listFailedPolicyResults.with.pagination.until.
  • Source: resource.dsl.do.listFailedPolicyResults.with.pagination.until
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.listFailedPolicyResults.with.pagination.update.in
  • Description: JumpCloud extension data on the managed entity: dsl.do.listFailedPolicyResults.with.pagination.update.in.
  • Source: resource.dsl.do.listFailedPolicyResults.with.pagination.update.in
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.listFailedPolicyResults.with.pagination.update.key
  • Description: JumpCloud extension data on the managed entity: dsl.do.listFailedPolicyResults.with.pagination.update.key.
  • Source: resource.dsl.do.listFailedPolicyResults.with.pagination.update.key
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.listFailedPolicyResults.with.pagination.update.value
  • Description: JumpCloud extension data on the managed entity: dsl.do.listFailedPolicyResults.with.pagination.update.value.
  • Source: resource.dsl.do.listFailedPolicyResults.with.pagination.update.value
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.listFailedPolicyResults.with.queryParams.filter
  • Description: JumpCloud extension data on the managed entity: dsl.do.listFailedPolicyResults.with.queryParams.filter.
  • Source: resource.dsl.do.listFailedPolicyResults.with.queryParams.filter
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.listFailedPolicyResults.with.queryParams.limit
  • Description: JumpCloud extension data on the managed entity: dsl.do.listFailedPolicyResults.with.queryParams.limit.
  • Source: resource.dsl.do.listFailedPolicyResults.with.queryParams.limit
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.listFailedPolicyResults.with.queryParams.skip
  • Description: JumpCloud extension data on the managed entity: dsl.do.listFailedPolicyResults.with.queryParams.skip.
  • Source: resource.dsl.do.listFailedPolicyResults.with.queryParams.skip
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.listFailedPolicyResults.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.listFailedPolicyResults.with.version.
  • Source: resource.dsl.do.listFailedPolicyResults.with.version
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.listInactiveUsers.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.listInactiveUsers.call.
  • Source: resource.dsl.do.listInactiveUsers.call
  • Usage: workflow_delete
entity.data.dsl.do.listInactiveUsers.with.extract
  • Description: JumpCloud extension data on the managed entity: dsl.do.listInactiveUsers.with.extract.
  • Source: resource.dsl.do.listInactiveUsers.with.extract
  • Usage: workflow_delete
entity.data.dsl.do.listInactiveUsers.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.listInactiveUsers.with.operationId.
  • Source: resource.dsl.do.listInactiveUsers.with.operationId
  • Usage: workflow_delete
entity.data.dsl.do.listInactiveUsers.with.pagination.until
  • Description: JumpCloud extension data on the managed entity: dsl.do.listInactiveUsers.with.pagination.until.
  • Source: resource.dsl.do.listInactiveUsers.with.pagination.until
  • Usage: workflow_delete
entity.data.dsl.do.listInactiveUsers.with.pagination.update.in
  • Description: JumpCloud extension data on the managed entity: dsl.do.listInactiveUsers.with.pagination.update.in.
  • Source: resource.dsl.do.listInactiveUsers.with.pagination.update.in
  • Usage: workflow_delete
entity.data.dsl.do.listInactiveUsers.with.pagination.update.key
  • Description: JumpCloud extension data on the managed entity: dsl.do.listInactiveUsers.with.pagination.update.key.
  • Source: resource.dsl.do.listInactiveUsers.with.pagination.update.key
  • Usage: workflow_delete
entity.data.dsl.do.listInactiveUsers.with.pagination.update.value
  • Description: JumpCloud extension data on the managed entity: dsl.do.listInactiveUsers.with.pagination.update.value.
  • Source: resource.dsl.do.listInactiveUsers.with.pagination.update.value
  • Usage: workflow_delete
entity.data.dsl.do.listInactiveUsers.with.queryParams.filter
  • Description: JumpCloud extension data on the managed entity: dsl.do.listInactiveUsers.with.queryParams.filter.
  • Source: resource.dsl.do.listInactiveUsers.with.queryParams.filter
  • Usage: workflow_delete
entity.data.dsl.do.listInactiveUsers.with.queryParams.limit
  • Description: JumpCloud extension data on the managed entity: dsl.do.listInactiveUsers.with.queryParams.limit.
  • Source: resource.dsl.do.listInactiveUsers.with.queryParams.limit
  • Usage: workflow_delete
entity.data.dsl.do.listInactiveUsers.with.queryParams.skip
  • Description: JumpCloud extension data on the managed entity: dsl.do.listInactiveUsers.with.queryParams.skip.
  • Source: resource.dsl.do.listInactiveUsers.with.queryParams.skip
  • Usage: workflow_delete
entity.data.dsl.do.listInactiveUsers.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.listInactiveUsers.with.version.
  • Source: resource.dsl.do.listInactiveUsers.with.version
  • Usage: workflow_delete
entity.data.dsl.do.listUserGroups.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.listUserGroups.call.
  • Source: resource.dsl.do.listUserGroups.call
  • Usage: workflow_delete
entity.data.dsl.do.listUserGroups.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.listUserGroups.then.
  • Source: resource.dsl.do.listUserGroups.then
  • Usage: workflow_delete
entity.data.dsl.do.listUserGroups.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.listUserGroups.with.operationId.
  • Source: resource.dsl.do.listUserGroups.with.operationId
  • Usage: workflow_delete
entity.data.dsl.do.listUserGroups.with.pathParams.user_id
  • Description: JumpCloud extension data on the managed entity: dsl.do.listUserGroups.with.pathParams.user_id.
  • Source: resource.dsl.do.listUserGroups.with.pathParams.user_id
  • Usage: workflow_delete
entity.data.dsl.do.listUserGroups.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.listUserGroups.with.version.
  • Source: resource.dsl.do.listUserGroups.with.version
  • Usage: workflow_delete
entity.data.dsl.do.listUserSystems.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.listUserSystems.call.
  • Source: resource.dsl.do.listUserSystems.call
  • Usage: workflow_delete
entity.data.dsl.do.listUserSystems.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.listUserSystems.with.operationId.
  • Source: resource.dsl.do.listUserSystems.with.operationId
  • Usage: workflow_delete
entity.data.dsl.do.listUserSystems.with.pathParams.user_id
  • Description: JumpCloud extension data on the managed entity: dsl.do.listUserSystems.with.pathParams.user_id.
  • Source: resource.dsl.do.listUserSystems.with.pathParams.user_id
  • Usage: workflow_delete
entity.data.dsl.do.listUserSystems.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.listUserSystems.with.version.
  • Source: resource.dsl.do.listUserSystems.with.version
  • Usage: workflow_delete
entity.data.dsl.do.listUsersWithoutMFA.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.listUsersWithoutMFA.call.
  • Source: resource.dsl.do.listUsersWithoutMFA.call
  • Usage: workflow_create
entity.data.dsl.do.listUsersWithoutMFA.with.extract
  • Description: JumpCloud extension data on the managed entity: dsl.do.listUsersWithoutMFA.with.extract.
  • Source: resource.dsl.do.listUsersWithoutMFA.with.extract
  • Usage: workflow_create
entity.data.dsl.do.listUsersWithoutMFA.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.listUsersWithoutMFA.with.operationId.
  • Source: resource.dsl.do.listUsersWithoutMFA.with.operationId
  • Usage: workflow_create
entity.data.dsl.do.listUsersWithoutMFA.with.pagination.until
  • Description: JumpCloud extension data on the managed entity: dsl.do.listUsersWithoutMFA.with.pagination.until.
  • Source: resource.dsl.do.listUsersWithoutMFA.with.pagination.until
  • Usage: workflow_create
entity.data.dsl.do.listUsersWithoutMFA.with.pagination.update.in
  • Description: JumpCloud extension data on the managed entity: dsl.do.listUsersWithoutMFA.with.pagination.update.in.
  • Source: resource.dsl.do.listUsersWithoutMFA.with.pagination.update.in
  • Usage: workflow_create
entity.data.dsl.do.listUsersWithoutMFA.with.pagination.update.key
  • Description: JumpCloud extension data on the managed entity: dsl.do.listUsersWithoutMFA.with.pagination.update.key.
  • Source: resource.dsl.do.listUsersWithoutMFA.with.pagination.update.key
  • Usage: workflow_create
entity.data.dsl.do.listUsersWithoutMFA.with.pagination.update.value
  • Description: JumpCloud extension data on the managed entity: dsl.do.listUsersWithoutMFA.with.pagination.update.value.
  • Source: resource.dsl.do.listUsersWithoutMFA.with.pagination.update.value
  • Usage: workflow_create
entity.data.dsl.do.listUsersWithoutMFA.with.queryParams.filter
  • Description: JumpCloud extension data on the managed entity: dsl.do.listUsersWithoutMFA.with.queryParams.filter.
  • Source: resource.dsl.do.listUsersWithoutMFA.with.queryParams.filter
  • Usage: workflow_create
entity.data.dsl.do.listUsersWithoutMFA.with.queryParams.limit
  • Description: JumpCloud extension data on the managed entity: dsl.do.listUsersWithoutMFA.with.queryParams.limit.
  • Source: resource.dsl.do.listUsersWithoutMFA.with.queryParams.limit
  • Usage: workflow_create
entity.data.dsl.do.listUsersWithoutMFA.with.queryParams.skip
  • Description: JumpCloud extension data on the managed entity: dsl.do.listUsersWithoutMFA.with.queryParams.skip.
  • Source: resource.dsl.do.listUsersWithoutMFA.with.queryParams.skip
  • Usage: workflow_create
entity.data.dsl.do.listUsersWithoutMFA.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.listUsersWithoutMFA.with.version.
  • Source: resource.dsl.do.listUsersWithoutMFA.with.version
  • Usage: workflow_create
entity.data.dsl.do.lockMacDevice.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.lockMacDevice.call.
  • Source: resource.dsl.do.lockMacDevice.call
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.lockMacDevice.metadata.displayLabels.device
  • Description: JumpCloud extension data on the managed entity: dsl.do.lockMacDevice.metadata.displayLabels.device.
  • Source: resource.dsl.do.lockMacDevice.metadata.displayLabels.device
  • Usage: workflow_create
entity.data.dsl.do.lockMacDevice.metadata.displayLabels.pin
  • Description: JumpCloud extension data on the managed entity: dsl.do.lockMacDevice.metadata.displayLabels.pin.
  • Source: resource.dsl.do.lockMacDevice.metadata.displayLabels.pin
  • Usage: workflow_create
entity.data.dsl.do.lockMacDevice.metadata.inputModes.device
  • Description: JumpCloud extension data on the managed entity: dsl.do.lockMacDevice.metadata.inputModes.device.
  • Source: resource.dsl.do.lockMacDevice.metadata.inputModes.device
  • Usage: workflow_create
entity.data.dsl.do.lockMacDevice.metadata.inputModes.pin
  • Description: JumpCloud extension data on the managed entity: dsl.do.lockMacDevice.metadata.inputModes.pin.
  • Source: resource.dsl.do.lockMacDevice.metadata.inputModes.pin
  • Usage: workflow_create
entity.data.dsl.do.lockMacDevice.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.lockMacDevice.then.
  • Source: resource.dsl.do.lockMacDevice.then
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.lockMacDevice.with.bodyParams.pin
  • Description: JumpCloud extension data on the managed entity: dsl.do.lockMacDevice.with.bodyParams.pin.
  • Source: resource.dsl.do.lockMacDevice.with.bodyParams.pin
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.lockMacDevice.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.lockMacDevice.with.operationId.
  • Source: resource.dsl.do.lockMacDevice.with.operationId
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.lockMacDevice.with.pathParams.apple_mdm_id
  • Description: JumpCloud extension data on the managed entity: dsl.do.lockMacDevice.with.pathParams.apple_mdm_id.
  • Source: resource.dsl.do.lockMacDevice.with.pathParams.apple_mdm_id
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.lockMacDevice.with.pathParams.device_id
  • Description: JumpCloud extension data on the managed entity: dsl.do.lockMacDevice.with.pathParams.device_id.
  • Source: resource.dsl.do.lockMacDevice.with.pathParams.device_id
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.lockMacDevice.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.lockMacDevice.with.version.
  • Source: resource.dsl.do.lockMacDevice.with.version
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.lockOtherDevice.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.lockOtherDevice.call.
  • Source: resource.dsl.do.lockOtherDevice.call
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.lockOtherDevice.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.lockOtherDevice.then.
  • Source: resource.dsl.do.lockOtherDevice.then
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.lockOtherDevice.with.bodyParams
  • Description: JumpCloud extension data on the managed entity: dsl.do.lockOtherDevice.with.bodyParams.
  • Source: resource.dsl.do.lockOtherDevice.with.bodyParams
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.lockOtherDevice.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.lockOtherDevice.with.operationId.
  • Source: resource.dsl.do.lockOtherDevice.with.operationId
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.lockOtherDevice.with.pathParams.system_id
  • Description: JumpCloud extension data on the managed entity: dsl.do.lockOtherDevice.with.pathParams.system_id.
  • Source: resource.dsl.do.lockOtherDevice.with.pathParams.system_id
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.lockOtherDevice.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.lockOtherDevice.with.version.
  • Source: resource.dsl.do.lockOtherDevice.with.version
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.lockUserDevices.do.lockDevice.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.lockUserDevices.do.lockDevice.call.
  • Source: resource.dsl.do.lockUserDevices.do.lockDevice.call
  • Usage: workflow_delete
entity.data.dsl.do.lockUserDevices.do.lockDevice.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.lockUserDevices.do.lockDevice.with.operationId.
  • Source: resource.dsl.do.lockUserDevices.do.lockDevice.with.operationId
  • Usage: workflow_delete
entity.data.dsl.do.lockUserDevices.do.lockDevice.with.pathParams.system_id
  • Description: JumpCloud extension data on the managed entity: dsl.do.lockUserDevices.do.lockDevice.with.pathParams.system_id.
  • Source: resource.dsl.do.lockUserDevices.do.lockDevice.with.pathParams.system_id
  • Usage: workflow_delete
entity.data.dsl.do.lockUserDevices.do.lockDevice.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.lockUserDevices.do.lockDevice.with.version.
  • Source: resource.dsl.do.lockUserDevices.do.lockDevice.with.version
  • Usage: workflow_delete
entity.data.dsl.do.lockUserDevices.for.each
  • Description: JumpCloud extension data on the managed entity: dsl.do.lockUserDevices.for.each.
  • Source: resource.dsl.do.lockUserDevices.for.each
  • Usage: workflow_delete
entity.data.dsl.do.lockUserDevices.for.in
  • Description: JumpCloud extension data on the managed entity: dsl.do.lockUserDevices.for.in.
  • Source: resource.dsl.do.lockUserDevices.for.in
  • Usage: workflow_delete
entity.data.dsl.do.loops.do.addUserToUserGroup.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.loops.do.addUserToUserGroup.call.
  • Source: resource.dsl.do.loops.do.addUserToUserGroup.call
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.loops.do.addUserToUserGroup.metadata.displayLabels.user
  • Description: JumpCloud extension data on the managed entity: dsl.do.loops.do.addUserToUserGroup.metadata.displayLabels.user.
  • Source: resource.dsl.do.loops.do.addUserToUserGroup.metadata.displayLabels.user
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.loops.do.addUserToUserGroup.metadata.displayLabels.userGroup
  • Description: JumpCloud extension data on the managed entity: dsl.do.loops.do.addUserToUserGroup.metadata.displayLabels.userGroup.
  • Source: resource.dsl.do.loops.do.addUserToUserGroup.metadata.displayLabels.userGroup
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.loops.do.addUserToUserGroup.metadata.inputModes.user
  • Description: JumpCloud extension data on the managed entity: dsl.do.loops.do.addUserToUserGroup.metadata.inputModes.user.
  • Source: resource.dsl.do.loops.do.addUserToUserGroup.metadata.inputModes.user
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.loops.do.addUserToUserGroup.metadata.inputModes.userGroup
  • Description: JumpCloud extension data on the managed entity: dsl.do.loops.do.addUserToUserGroup.metadata.inputModes.userGroup.
  • Source: resource.dsl.do.loops.do.addUserToUserGroup.metadata.inputModes.userGroup
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.loops.do.addUserToUserGroup.with.bodyParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.loops.do.addUserToUserGroup.with.bodyParams.id.
  • Source: resource.dsl.do.loops.do.addUserToUserGroup.with.bodyParams.id
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.loops.do.addUserToUserGroup.with.bodyParams.op
  • Description: JumpCloud extension data on the managed entity: dsl.do.loops.do.addUserToUserGroup.with.bodyParams.op.
  • Source: resource.dsl.do.loops.do.addUserToUserGroup.with.bodyParams.op
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.loops.do.addUserToUserGroup.with.bodyParams.type
  • Description: JumpCloud extension data on the managed entity: dsl.do.loops.do.addUserToUserGroup.with.bodyParams.type.
  • Source: resource.dsl.do.loops.do.addUserToUserGroup.with.bodyParams.type
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.loops.do.addUserToUserGroup.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.loops.do.addUserToUserGroup.with.operationId.
  • Source: resource.dsl.do.loops.do.addUserToUserGroup.with.operationId
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.loops.do.addUserToUserGroup.with.pathParams.group_id
  • Description: JumpCloud extension data on the managed entity: dsl.do.loops.do.addUserToUserGroup.with.pathParams.group_id.
  • Source: resource.dsl.do.loops.do.addUserToUserGroup.with.pathParams.group_id
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.loops.do.addUserToUserGroup.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.loops.do.addUserToUserGroup.with.version.
  • Source: resource.dsl.do.loops.do.addUserToUserGroup.with.version
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.loops.do.bindUserToDevice.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.loops.do.bindUserToDevice.call.
  • Source: resource.dsl.do.loops.do.bindUserToDevice.call
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.loops.do.bindUserToDevice.metadata.displayLabels.device
  • Description: JumpCloud extension data on the managed entity: dsl.do.loops.do.bindUserToDevice.metadata.displayLabels.device.
  • Source: resource.dsl.do.loops.do.bindUserToDevice.metadata.displayLabels.device
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.loops.do.bindUserToDevice.metadata.displayLabels.user
  • Description: JumpCloud extension data on the managed entity: dsl.do.loops.do.bindUserToDevice.metadata.displayLabels.user.
  • Source: resource.dsl.do.loops.do.bindUserToDevice.metadata.displayLabels.user
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.loops.do.bindUserToDevice.metadata.inputModes.device
  • Description: JumpCloud extension data on the managed entity: dsl.do.loops.do.bindUserToDevice.metadata.inputModes.device.
  • Source: resource.dsl.do.loops.do.bindUserToDevice.metadata.inputModes.device
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.loops.do.bindUserToDevice.metadata.inputModes.user
  • Description: JumpCloud extension data on the managed entity: dsl.do.loops.do.bindUserToDevice.metadata.inputModes.user.
  • Source: resource.dsl.do.loops.do.bindUserToDevice.metadata.inputModes.user
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.loops.do.bindUserToDevice.with.bodyParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.loops.do.bindUserToDevice.with.bodyParams.id.
  • Source: resource.dsl.do.loops.do.bindUserToDevice.with.bodyParams.id
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.loops.do.bindUserToDevice.with.bodyParams.op
  • Description: JumpCloud extension data on the managed entity: dsl.do.loops.do.bindUserToDevice.with.bodyParams.op.
  • Source: resource.dsl.do.loops.do.bindUserToDevice.with.bodyParams.op
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.loops.do.bindUserToDevice.with.bodyParams.type
  • Description: JumpCloud extension data on the managed entity: dsl.do.loops.do.bindUserToDevice.with.bodyParams.type.
  • Source: resource.dsl.do.loops.do.bindUserToDevice.with.bodyParams.type
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.loops.do.bindUserToDevice.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.loops.do.bindUserToDevice.with.operationId.
  • Source: resource.dsl.do.loops.do.bindUserToDevice.with.operationId
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.loops.do.bindUserToDevice.with.pathParams.system_id
  • Description: JumpCloud extension data on the managed entity: dsl.do.loops.do.bindUserToDevice.with.pathParams.system_id.
  • Source: resource.dsl.do.loops.do.bindUserToDevice.with.pathParams.system_id
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.loops.do.bindUserToDevice.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.loops.do.bindUserToDevice.with.version.
  • Source: resource.dsl.do.loops.do.bindUserToDevice.with.version
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.loops.do.ifElse.switch.condition1.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.loops.do.ifElse.switch.condition1.then.
  • Source: resource.dsl.do.loops.do.ifElse.switch.condition1.then
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.loops.do.ifElse.switch.condition1.when
  • Description: JumpCloud extension data on the managed entity: dsl.do.loops.do.ifElse.switch.condition1.when.
  • Source: resource.dsl.do.loops.do.ifElse.switch.condition1.when
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.loops.do.ifElse.switch.condition2.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.loops.do.ifElse.switch.condition2.then.
  • Source: resource.dsl.do.loops.do.ifElse.switch.condition2.then
  • Usage: workflow_update
entity.data.dsl.do.loops.do.ifElse.switch.condition2.when
  • Description: JumpCloud extension data on the managed entity: dsl.do.loops.do.ifElse.switch.condition2.when.
  • Source: resource.dsl.do.loops.do.ifElse.switch.condition2.when
  • Usage: workflow_update
entity.data.dsl.do.loops.do.ifElse.switch.default.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.loops.do.ifElse.switch.default.then.
  • Source: resource.dsl.do.loops.do.ifElse.switch.default.then
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.loops.do.runCommandOnDevice.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.loops.do.runCommandOnDevice.call.
  • Source: resource.dsl.do.loops.do.runCommandOnDevice.call
  • Usage: workflow_update
entity.data.dsl.do.loops.do.runCommandOnDevice.metadata.displayLabels.command
  • Description: JumpCloud extension data on the managed entity: dsl.do.loops.do.runCommandOnDevice.metadata.displayLabels.command.
  • Source: resource.dsl.do.loops.do.runCommandOnDevice.metadata.displayLabels.command
  • Usage: workflow_update
entity.data.dsl.do.loops.do.runCommandOnDevice.metadata.displayLabels.devices
  • Description: JumpCloud extension data on the managed entity: dsl.do.loops.do.runCommandOnDevice.metadata.displayLabels.devices.
  • Source: resource.dsl.do.loops.do.runCommandOnDevice.metadata.displayLabels.devices
  • Usage: workflow_update
entity.data.dsl.do.loops.do.runCommandOnDevice.metadata.inputModes.command
  • Description: JumpCloud extension data on the managed entity: dsl.do.loops.do.runCommandOnDevice.metadata.inputModes.command.
  • Source: resource.dsl.do.loops.do.runCommandOnDevice.metadata.inputModes.command
  • Usage: workflow_update
entity.data.dsl.do.loops.do.runCommandOnDevice.metadata.inputModes.devices
  • Description: JumpCloud extension data on the managed entity: dsl.do.loops.do.runCommandOnDevice.metadata.inputModes.devices.
  • Source: resource.dsl.do.loops.do.runCommandOnDevice.metadata.inputModes.devices
  • Usage: workflow_update
entity.data.dsl.do.loops.do.runCommandOnDevice.with.bodyParams._id
  • Description: JumpCloud extension data on the managed entity: dsl.do.loops.do.runCommandOnDevice.with.bodyParams._id.
  • Source: resource.dsl.do.loops.do.runCommandOnDevice.with.bodyParams._id
  • Usage: workflow_update
entity.data.dsl.do.loops.do.runCommandOnDevice.with.bodyParams.systemIds
  • Description: JumpCloud extension data on the managed entity: dsl.do.loops.do.runCommandOnDevice.with.bodyParams.systemIds.
  • Source: resource.dsl.do.loops.do.runCommandOnDevice.with.bodyParams.systemIds
  • Usage: workflow_update
entity.data.dsl.do.loops.do.runCommandOnDevice.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.loops.do.runCommandOnDevice.with.operationId.
  • Source: resource.dsl.do.loops.do.runCommandOnDevice.with.operationId
  • Usage: workflow_update
entity.data.dsl.do.loops.do.runCommandOnDevice.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.loops.do.runCommandOnDevice.with.version.
  • Source: resource.dsl.do.loops.do.runCommandOnDevice.with.version
  • Usage: workflow_update
entity.data.dsl.do.loops.do.runCommandOnDevice2.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.loops.do.runCommandOnDevice2.call.
  • Source: resource.dsl.do.loops.do.runCommandOnDevice2.call
  • Usage: workflow_update
entity.data.dsl.do.loops.do.runCommandOnDevice2.metadata.displayLabels.command
  • Description: JumpCloud extension data on the managed entity: dsl.do.loops.do.runCommandOnDevice2.metadata.displayLabels.command.
  • Source: resource.dsl.do.loops.do.runCommandOnDevice2.metadata.displayLabels.command
  • Usage: workflow_update
entity.data.dsl.do.loops.do.runCommandOnDevice2.metadata.displayLabels.devices
  • Description: JumpCloud extension data on the managed entity: dsl.do.loops.do.runCommandOnDevice2.metadata.displayLabels.devices.
  • Source: resource.dsl.do.loops.do.runCommandOnDevice2.metadata.displayLabels.devices
  • Usage: workflow_update
entity.data.dsl.do.loops.do.runCommandOnDevice2.metadata.inputModes.command
  • Description: JumpCloud extension data on the managed entity: dsl.do.loops.do.runCommandOnDevice2.metadata.inputModes.command.
  • Source: resource.dsl.do.loops.do.runCommandOnDevice2.metadata.inputModes.command
  • Usage: workflow_update
entity.data.dsl.do.loops.do.runCommandOnDevice2.metadata.inputModes.devices
  • Description: JumpCloud extension data on the managed entity: dsl.do.loops.do.runCommandOnDevice2.metadata.inputModes.devices.
  • Source: resource.dsl.do.loops.do.runCommandOnDevice2.metadata.inputModes.devices
  • Usage: workflow_update
entity.data.dsl.do.loops.do.runCommandOnDevice2.with.bodyParams._id
  • Description: JumpCloud extension data on the managed entity: dsl.do.loops.do.runCommandOnDevice2.with.bodyParams._id.
  • Source: resource.dsl.do.loops.do.runCommandOnDevice2.with.bodyParams._id
  • Usage: workflow_update
entity.data.dsl.do.loops.do.runCommandOnDevice2.with.bodyParams.systemIds
  • Description: JumpCloud extension data on the managed entity: dsl.do.loops.do.runCommandOnDevice2.with.bodyParams.systemIds.
  • Source: resource.dsl.do.loops.do.runCommandOnDevice2.with.bodyParams.systemIds
  • Usage: workflow_update
entity.data.dsl.do.loops.do.runCommandOnDevice2.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.loops.do.runCommandOnDevice2.with.operationId.
  • Source: resource.dsl.do.loops.do.runCommandOnDevice2.with.operationId
  • Usage: workflow_update
entity.data.dsl.do.loops.do.runCommandOnDevice2.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.loops.do.runCommandOnDevice2.with.version.
  • Source: resource.dsl.do.loops.do.runCommandOnDevice2.with.version
  • Usage: workflow_update
entity.data.dsl.do.loops.do.systemsGet.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.loops.do.systemsGet.call.
  • Source: resource.dsl.do.loops.do.systemsGet.call
  • Usage: workflow_update
entity.data.dsl.do.loops.do.systemsGet.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.loops.do.systemsGet.with.operationId.
  • Source: resource.dsl.do.loops.do.systemsGet.with.operationId
  • Usage: workflow_update
entity.data.dsl.do.loops.do.systemsGet.with.pathParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.loops.do.systemsGet.with.pathParams.id.
  • Source: resource.dsl.do.loops.do.systemsGet.with.pathParams.id
  • Usage: workflow_update
entity.data.dsl.do.loops.do.systemsGet.with.queryParams
  • Description: JumpCloud extension data on the managed entity: dsl.do.loops.do.systemsGet.with.queryParams.
  • Source: resource.dsl.do.loops.do.systemsGet.with.queryParams
  • Usage: workflow_update
entity.data.dsl.do.loops.do.systemsGet.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.loops.do.systemsGet.with.version.
  • Source: resource.dsl.do.loops.do.systemsGet.with.version
  • Usage: workflow_update
entity.data.dsl.do.loops.for.each
  • Description: JumpCloud extension data on the managed entity: dsl.do.loops.for.each.
  • Source: resource.dsl.do.loops.for.each
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.loops.for.in
  • Description: JumpCloud extension data on the managed entity: dsl.do.loops.for.in.
  • Source: resource.dsl.do.loops.for.in
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.merge.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.merge.call.
  • Source: resource.dsl.do.merge.call
  • Usage: workflow_delete
entity.data.dsl.do.merge.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.merge.then.
  • Source: resource.dsl.do.merge.then
  • Usage: workflow_delete
entity.data.dsl.do.merge.with.message.body
  • Description: JumpCloud extension data on the managed entity: dsl.do.merge.with.message.body.
  • Source: resource.dsl.do.merge.with.message.body
  • Usage: workflow_delete
entity.data.dsl.do.merge.with.message.subject
  • Description: JumpCloud extension data on the managed entity: dsl.do.merge.with.message.subject.
  • Source: resource.dsl.do.merge.with.message.subject
  • Usage: workflow_delete
entity.data.dsl.do.merge.with.recipients.channel_object_ids
  • Description: JumpCloud extension data on the managed entity: dsl.do.merge.with.recipients.channel_object_ids.
  • Source: resource.dsl.do.merge.with.recipients.channel_object_ids
  • Usage: workflow_delete
entity.data.dsl.do.nliQuestion.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.nliQuestion.call.
  • Source: resource.dsl.do.nliQuestion.call
  • Usage: workflow_delete
entity.data.dsl.do.nliQuestion.with.bodyParams.data
  • Description: JumpCloud extension data on the managed entity: dsl.do.nliQuestion.with.bodyParams.data.
  • Source: resource.dsl.do.nliQuestion.with.bodyParams.data
  • Usage: workflow_delete
entity.data.dsl.do.nliQuestion.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.nliQuestion.with.operationId.
  • Source: resource.dsl.do.nliQuestion.with.operationId
  • Usage: workflow_delete
entity.data.dsl.do.nliQuestion.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.nliQuestion.with.version.
  • Source: resource.dsl.do.nliQuestion.with.version
  • Usage: workflow_delete
entity.data.dsl.do.notifyITReview.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.notifyITReview.call.
  • Source: resource.dsl.do.notifyITReview.call
  • Usage: workflow_delete
entity.data.dsl.do.notifyITReview.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.notifyITReview.then.
  • Source: resource.dsl.do.notifyITReview.then
  • Usage: workflow_delete
entity.data.dsl.do.notifyITReview.with.message.body
  • Description: JumpCloud extension data on the managed entity: dsl.do.notifyITReview.with.message.body.
  • Source: resource.dsl.do.notifyITReview.with.message.body
  • Usage: workflow_delete
entity.data.dsl.do.notifyITReview.with.message.subject
  • Description: JumpCloud extension data on the managed entity: dsl.do.notifyITReview.with.message.subject.
  • Source: resource.dsl.do.notifyITReview.with.message.subject
  • Usage: workflow_delete
entity.data.dsl.do.notifyITReview.with.recipients.channel_object_ids
  • Description: JumpCloud extension data on the managed entity: dsl.do.notifyITReview.with.recipients.channel_object_ids.
  • Source: resource.dsl.do.notifyITReview.with.recipients.channel_object_ids
  • Usage: workflow_delete
entity.data.dsl.do.notifyManagerEmail.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.notifyManagerEmail.call.
  • Source: resource.dsl.do.notifyManagerEmail.call
  • Usage: workflow_delete
entity.data.dsl.do.notifyManagerEmail.if
  • Description: JumpCloud extension data on the managed entity: dsl.do.notifyManagerEmail.if.
  • Source: resource.dsl.do.notifyManagerEmail.if
  • Usage: workflow_delete
entity.data.dsl.do.notifyManagerEmail.with.message.body
  • Description: JumpCloud extension data on the managed entity: dsl.do.notifyManagerEmail.with.message.body.
  • Source: resource.dsl.do.notifyManagerEmail.with.message.body
  • Usage: workflow_delete
entity.data.dsl.do.notifyManagerEmail.with.message.subject
  • Description: JumpCloud extension data on the managed entity: dsl.do.notifyManagerEmail.with.message.subject.
  • Source: resource.dsl.do.notifyManagerEmail.with.message.subject
  • Usage: workflow_delete
entity.data.dsl.do.notifyManagerEmail.with.recipients.to_addresses
  • Description: JumpCloud extension data on the managed entity: dsl.do.notifyManagerEmail.with.recipients.to_addresses.
  • Source: resource.dsl.do.notifyManagerEmail.with.recipients.to_addresses
  • Usage: workflow_delete
entity.data.dsl.do.notifyNoResults.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.notifyNoResults.call.
  • Source: resource.dsl.do.notifyNoResults.call
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.notifyNoResults.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.notifyNoResults.then.
  • Source: resource.dsl.do.notifyNoResults.then
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.notifyNoResults.with.message.body
  • Description: JumpCloud extension data on the managed entity: dsl.do.notifyNoResults.with.message.body.
  • Source: resource.dsl.do.notifyNoResults.with.message.body
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.notifyNoResults.with.message.subject
  • Description: JumpCloud extension data on the managed entity: dsl.do.notifyNoResults.with.message.subject.
  • Source: resource.dsl.do.notifyNoResults.with.message.subject
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.notifyNoResults.with.recipients.channel_object_ids
  • Description: JumpCloud extension data on the managed entity: dsl.do.notifyNoResults.with.recipients.channel_object_ids.
  • Source: resource.dsl.do.notifyNoResults.with.recipients.channel_object_ids
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.notifyOps.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.notifyOps.call.
  • Source: resource.dsl.do.notifyOps.call
  • Usage: workflow_delete
entity.data.dsl.do.notifyOps.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.notifyOps.then.
  • Source: resource.dsl.do.notifyOps.then
  • Usage: workflow_delete
entity.data.dsl.do.notifyOps.with.message.body
  • Description: JumpCloud extension data on the managed entity: dsl.do.notifyOps.with.message.body.
  • Source: resource.dsl.do.notifyOps.with.message.body
  • Usage: workflow_delete
entity.data.dsl.do.notifyOps.with.message.subject
  • Description: JumpCloud extension data on the managed entity: dsl.do.notifyOps.with.message.subject.
  • Source: resource.dsl.do.notifyOps.with.message.subject
  • Usage: workflow_delete
entity.data.dsl.do.notifyOps.with.recipients.channel_object_ids
  • Description: JumpCloud extension data on the managed entity: dsl.do.notifyOps.with.recipients.channel_object_ids.
  • Source: resource.dsl.do.notifyOps.with.recipients.channel_object_ids
  • Usage: workflow_delete
entity.data.dsl.do.notifyOpsChannel.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.notifyOpsChannel.call.
  • Source: resource.dsl.do.notifyOpsChannel.call
  • Usage: workflow_delete
entity.data.dsl.do.notifyOpsChannel.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.notifyOpsChannel.then.
  • Source: resource.dsl.do.notifyOpsChannel.then
  • Usage: workflow_delete
entity.data.dsl.do.notifyOpsChannel.with.message.body
  • Description: JumpCloud extension data on the managed entity: dsl.do.notifyOpsChannel.with.message.body.
  • Source: resource.dsl.do.notifyOpsChannel.with.message.body
  • Usage: workflow_delete
entity.data.dsl.do.notifyOpsChannel.with.message.subject
  • Description: JumpCloud extension data on the managed entity: dsl.do.notifyOpsChannel.with.message.subject.
  • Source: resource.dsl.do.notifyOpsChannel.with.message.subject
  • Usage: workflow_delete
entity.data.dsl.do.notifyOpsChannel.with.recipients.channel_object_ids
  • Description: JumpCloud extension data on the managed entity: dsl.do.notifyOpsChannel.with.recipients.channel_object_ids.
  • Source: resource.dsl.do.notifyOpsChannel.with.recipients.channel_object_ids
  • Usage: workflow_delete
entity.data.dsl.do.postLoopAuditVerification.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.postLoopAuditVerification.call.
  • Source: resource.dsl.do.postLoopAuditVerification.call
  • Usage: workflow_create
entity.data.dsl.do.postLoopAuditVerification.if
  • Description: JumpCloud extension data on the managed entity: dsl.do.postLoopAuditVerification.if.
  • Source: resource.dsl.do.postLoopAuditVerification.if
  • Usage: workflow_create
entity.data.dsl.do.postLoopAuditVerification.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.postLoopAuditVerification.with.operationId.
  • Source: resource.dsl.do.postLoopAuditVerification.with.operationId
  • Usage: workflow_create
entity.data.dsl.do.postLoopAuditVerification.with.queryParams.limit
  • Description: JumpCloud extension data on the managed entity: dsl.do.postLoopAuditVerification.with.queryParams.limit.
  • Source: resource.dsl.do.postLoopAuditVerification.with.queryParams.limit
  • Usage: workflow_create
entity.data.dsl.do.postLoopAuditVerification.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.postLoopAuditVerification.with.version.
  • Source: resource.dsl.do.postLoopAuditVerification.with.version
  • Usage: workflow_create
entity.data.dsl.do.postSwitchCheck.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.postSwitchCheck.call.
  • Source: resource.dsl.do.postSwitchCheck.call
  • Usage: workflow_create
entity.data.dsl.do.postSwitchCheck.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.postSwitchCheck.with.operationId.
  • Source: resource.dsl.do.postSwitchCheck.with.operationId
  • Usage: workflow_create
entity.data.dsl.do.postSwitchCheck.with.queryParams.limit
  • Description: JumpCloud extension data on the managed entity: dsl.do.postSwitchCheck.with.queryParams.limit.
  • Source: resource.dsl.do.postSwitchCheck.with.queryParams.limit
  • Usage: workflow_create
entity.data.dsl.do.postSwitchCheck.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.postSwitchCheck.with.version.
  • Source: resource.dsl.do.postSwitchCheck.with.version
  • Usage: workflow_create
entity.data.dsl.do.processEachUser.do.auditActiveUser.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.processEachUser.do.auditActiveUser.call.
  • Source: resource.dsl.do.processEachUser.do.auditActiveUser.call
  • Usage: workflow_create
entity.data.dsl.do.processEachUser.do.auditActiveUser.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.processEachUser.do.auditActiveUser.then.
  • Source: resource.dsl.do.processEachUser.do.auditActiveUser.then
  • Usage: workflow_create
entity.data.dsl.do.processEachUser.do.auditActiveUser.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.processEachUser.do.auditActiveUser.with.operationId.
  • Source: resource.dsl.do.processEachUser.do.auditActiveUser.with.operationId
  • Usage: workflow_create
entity.data.dsl.do.processEachUser.do.auditActiveUser.with.pathParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.processEachUser.do.auditActiveUser.with.pathParams.id.
  • Source: resource.dsl.do.processEachUser.do.auditActiveUser.with.pathParams.id
  • Usage: workflow_create
entity.data.dsl.do.processEachUser.do.auditActiveUser.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.processEachUser.do.auditActiveUser.with.version.
  • Source: resource.dsl.do.processEachUser.do.auditActiveUser.with.version
  • Usage: workflow_create
entity.data.dsl.do.processEachUser.do.auditSuspendedUser.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.processEachUser.do.auditSuspendedUser.call.
  • Source: resource.dsl.do.processEachUser.do.auditSuspendedUser.call
  • Usage: workflow_create
entity.data.dsl.do.processEachUser.do.auditSuspendedUser.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.processEachUser.do.auditSuspendedUser.then.
  • Source: resource.dsl.do.processEachUser.do.auditSuspendedUser.then
  • Usage: workflow_create
entity.data.dsl.do.processEachUser.do.auditSuspendedUser.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.processEachUser.do.auditSuspendedUser.with.operationId.
  • Source: resource.dsl.do.processEachUser.do.auditSuspendedUser.with.operationId
  • Usage: workflow_create
entity.data.dsl.do.processEachUser.do.auditSuspendedUser.with.pathParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.processEachUser.do.auditSuspendedUser.with.pathParams.id.
  • Source: resource.dsl.do.processEachUser.do.auditSuspendedUser.with.pathParams.id
  • Usage: workflow_create
entity.data.dsl.do.processEachUser.do.auditSuspendedUser.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.processEachUser.do.auditSuspendedUser.with.version.
  • Source: resource.dsl.do.processEachUser.do.auditSuspendedUser.with.version
  • Usage: workflow_create
entity.data.dsl.do.processEachUser.do.routeByState.switch.default.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.processEachUser.do.routeByState.switch.default.then.
  • Source: resource.dsl.do.processEachUser.do.routeByState.switch.default.then
  • Usage: workflow_create
entity.data.dsl.do.processEachUser.do.routeByState.switch.suspendedCase.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.processEachUser.do.routeByState.switch.suspendedCase.then.
  • Source: resource.dsl.do.processEachUser.do.routeByState.switch.suspendedCase.then
  • Usage: workflow_create
entity.data.dsl.do.processEachUser.do.routeByState.switch.suspendedCase.when
  • Description: JumpCloud extension data on the managed entity: dsl.do.processEachUser.do.routeByState.switch.suspendedCase.when.
  • Source: resource.dsl.do.processEachUser.do.routeByState.switch.suspendedCase.when
  • Usage: workflow_create
entity.data.dsl.do.processEachUser.for.each
  • Description: JumpCloud extension data on the managed entity: dsl.do.processEachUser.for.each.
  • Source: resource.dsl.do.processEachUser.for.each
  • Usage: workflow_create
entity.data.dsl.do.processEachUser.for.in
  • Description: JumpCloud extension data on the managed entity: dsl.do.processEachUser.for.in.
  • Source: resource.dsl.do.processEachUser.for.in
  • Usage: workflow_create
entity.data.dsl.do.processFailedPolicies.do.addDeviceToFailedGroup.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.processFailedPolicies.do.addDeviceToFailedGroup.call.
  • Source: resource.dsl.do.processFailedPolicies.do.addDeviceToFailedGroup.call
  • Usage: workflow_create
entity.data.dsl.do.processFailedPolicies.do.addDeviceToFailedGroup.with.bodyParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.processFailedPolicies.do.addDeviceToFailedGroup.with.bodyParams.id.
  • Source: resource.dsl.do.processFailedPolicies.do.addDeviceToFailedGroup.with.bodyParams.id
  • Usage: workflow_create
entity.data.dsl.do.processFailedPolicies.do.addDeviceToFailedGroup.with.bodyParams.op
  • Description: JumpCloud extension data on the managed entity: dsl.do.processFailedPolicies.do.addDeviceToFailedGroup.with.bodyParams.op.
  • Source: resource.dsl.do.processFailedPolicies.do.addDeviceToFailedGroup.with.bodyParams.op
  • Usage: workflow_create
entity.data.dsl.do.processFailedPolicies.do.addDeviceToFailedGroup.with.bodyParams.type
  • Description: JumpCloud extension data on the managed entity: dsl.do.processFailedPolicies.do.addDeviceToFailedGroup.with.bodyParams.type.
  • Source: resource.dsl.do.processFailedPolicies.do.addDeviceToFailedGroup.with.bodyParams.type
  • Usage: workflow_create
entity.data.dsl.do.processFailedPolicies.do.addDeviceToFailedGroup.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.processFailedPolicies.do.addDeviceToFailedGroup.with.operationId.
  • Source: resource.dsl.do.processFailedPolicies.do.addDeviceToFailedGroup.with.operationId
  • Usage: workflow_create
entity.data.dsl.do.processFailedPolicies.do.addDeviceToFailedGroup.with.pathParams.group_id
  • Description: JumpCloud extension data on the managed entity: dsl.do.processFailedPolicies.do.addDeviceToFailedGroup.with.pathParams.group_id.
  • Source: resource.dsl.do.processFailedPolicies.do.addDeviceToFailedGroup.with.pathParams.group_id
  • Usage: workflow_create
entity.data.dsl.do.processFailedPolicies.do.addDeviceToFailedGroup.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.processFailedPolicies.do.addDeviceToFailedGroup.with.version.
  • Source: resource.dsl.do.processFailedPolicies.do.addDeviceToFailedGroup.with.version
  • Usage: workflow_create
entity.data.dsl.do.processFailedPolicies.do.getSystemDetails.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.processFailedPolicies.do.getSystemDetails.call.
  • Source: resource.dsl.do.processFailedPolicies.do.getSystemDetails.call
  • Usage: workflow_create
entity.data.dsl.do.processFailedPolicies.do.getSystemDetails.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.processFailedPolicies.do.getSystemDetails.with.operationId.
  • Source: resource.dsl.do.processFailedPolicies.do.getSystemDetails.with.operationId
  • Usage: workflow_create
entity.data.dsl.do.processFailedPolicies.do.getSystemDetails.with.pathParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.processFailedPolicies.do.getSystemDetails.with.pathParams.id.
  • Source: resource.dsl.do.processFailedPolicies.do.getSystemDetails.with.pathParams.id
  • Usage: workflow_create
entity.data.dsl.do.processFailedPolicies.do.getSystemDetails.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.processFailedPolicies.do.getSystemDetails.with.version.
  • Source: resource.dsl.do.processFailedPolicies.do.getSystemDetails.with.version
  • Usage: workflow_create
entity.data.dsl.do.processFailedPolicies.do.getUserDetails.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.processFailedPolicies.do.getUserDetails.call.
  • Source: resource.dsl.do.processFailedPolicies.do.getUserDetails.call
  • Usage: workflow_create
entity.data.dsl.do.processFailedPolicies.do.getUserDetails.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.processFailedPolicies.do.getUserDetails.with.operationId.
  • Source: resource.dsl.do.processFailedPolicies.do.getUserDetails.with.operationId
  • Usage: workflow_create
entity.data.dsl.do.processFailedPolicies.do.getUserDetails.with.pathParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.processFailedPolicies.do.getUserDetails.with.pathParams.id.
  • Source: resource.dsl.do.processFailedPolicies.do.getUserDetails.with.pathParams.id
  • Usage: workflow_create
entity.data.dsl.do.processFailedPolicies.do.getUserDetails.with.queryParams.fields
  • Description: JumpCloud extension data on the managed entity: dsl.do.processFailedPolicies.do.getUserDetails.with.queryParams.fields.
  • Source: resource.dsl.do.processFailedPolicies.do.getUserDetails.with.queryParams.fields
  • Usage: workflow_create
entity.data.dsl.do.processFailedPolicies.do.getUserDetails.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.processFailedPolicies.do.getUserDetails.with.version.
  • Source: resource.dsl.do.processFailedPolicies.do.getUserDetails.with.version
  • Usage: workflow_create
entity.data.dsl.do.processFailedPolicies.do.sendRemediationEmail.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.processFailedPolicies.do.sendRemediationEmail.call.
  • Source: resource.dsl.do.processFailedPolicies.do.sendRemediationEmail.call
  • Usage: workflow_create
entity.data.dsl.do.processFailedPolicies.do.sendRemediationEmail.if
  • Description: JumpCloud extension data on the managed entity: dsl.do.processFailedPolicies.do.sendRemediationEmail.if.
  • Source: resource.dsl.do.processFailedPolicies.do.sendRemediationEmail.if
  • Usage: workflow_create
entity.data.dsl.do.processFailedPolicies.do.sendRemediationEmail.with.message.body
  • Description: JumpCloud extension data on the managed entity: dsl.do.processFailedPolicies.do.sendRemediationEmail.with.message.body.
  • Source: resource.dsl.do.processFailedPolicies.do.sendRemediationEmail.with.message.body
  • Usage: workflow_create
entity.data.dsl.do.processFailedPolicies.do.sendRemediationEmail.with.message.subject
  • Description: JumpCloud extension data on the managed entity: dsl.do.processFailedPolicies.do.sendRemediationEmail.with.message.subject.
  • Source: resource.dsl.do.processFailedPolicies.do.sendRemediationEmail.with.message.subject
  • Usage: workflow_create
entity.data.dsl.do.processFailedPolicies.do.sendRemediationEmail.with.recipients.to_addresses
  • Description: JumpCloud extension data on the managed entity: dsl.do.processFailedPolicies.do.sendRemediationEmail.with.recipients.to_addresses.
  • Source: resource.dsl.do.processFailedPolicies.do.sendRemediationEmail.with.recipients.to_addresses
  • Usage: workflow_create
entity.data.dsl.do.processFailedPolicies.for.each
  • Description: JumpCloud extension data on the managed entity: dsl.do.processFailedPolicies.for.each.
  • Source: resource.dsl.do.processFailedPolicies.for.each
  • Usage: workflow_create
entity.data.dsl.do.processFailedPolicies.for.in
  • Description: JumpCloud extension data on the managed entity: dsl.do.processFailedPolicies.for.in.
  • Source: resource.dsl.do.processFailedPolicies.for.in
  • Usage: workflow_create
entity.data.dsl.do.processNonCompliantDevices.do.getSystemDetails.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.processNonCompliantDevices.do.getSystemDetails.call.
  • Source: resource.dsl.do.processNonCompliantDevices.do.getSystemDetails.call
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.processNonCompliantDevices.do.getSystemDetails.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.processNonCompliantDevices.do.getSystemDetails.with.operationId.
  • Source: resource.dsl.do.processNonCompliantDevices.do.getSystemDetails.with.operationId
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.processNonCompliantDevices.do.getSystemDetails.with.pathParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.processNonCompliantDevices.do.getSystemDetails.with.pathParams.id.
  • Source: resource.dsl.do.processNonCompliantDevices.do.getSystemDetails.with.pathParams.id
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.processNonCompliantDevices.do.getSystemDetails.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.processNonCompliantDevices.do.getSystemDetails.with.version.
  • Source: resource.dsl.do.processNonCompliantDevices.do.getSystemDetails.with.version
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.processNonCompliantDevices.do.lockDevice.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.processNonCompliantDevices.do.lockDevice.call.
  • Source: resource.dsl.do.processNonCompliantDevices.do.lockDevice.call
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.processNonCompliantDevices.do.lockDevice.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.processNonCompliantDevices.do.lockDevice.with.operationId.
  • Source: resource.dsl.do.processNonCompliantDevices.do.lockDevice.with.operationId
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.processNonCompliantDevices.do.lockDevice.with.pathParams.system_id
  • Description: JumpCloud extension data on the managed entity: dsl.do.processNonCompliantDevices.do.lockDevice.with.pathParams.system_id.
  • Source: resource.dsl.do.processNonCompliantDevices.do.lockDevice.with.pathParams.system_id
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.processNonCompliantDevices.do.lockDevice.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.processNonCompliantDevices.do.lockDevice.with.version.
  • Source: resource.dsl.do.processNonCompliantDevices.do.lockDevice.with.version
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.processNonCompliantDevices.do.notifyToChannel.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.processNonCompliantDevices.do.notifyToChannel.call.
  • Source: resource.dsl.do.processNonCompliantDevices.do.notifyToChannel.call
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.processNonCompliantDevices.do.notifyToChannel.with.message.body
  • Description: JumpCloud extension data on the managed entity: dsl.do.processNonCompliantDevices.do.notifyToChannel.with.message.body.
  • Source: resource.dsl.do.processNonCompliantDevices.do.notifyToChannel.with.message.body
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.processNonCompliantDevices.do.notifyToChannel.with.message.subject
  • Description: JumpCloud extension data on the managed entity: dsl.do.processNonCompliantDevices.do.notifyToChannel.with.message.subject.
  • Source: resource.dsl.do.processNonCompliantDevices.do.notifyToChannel.with.message.subject
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.processNonCompliantDevices.do.notifyToChannel.with.recipients.channel_object_ids
  • Description: JumpCloud extension data on the managed entity: dsl.do.processNonCompliantDevices.do.notifyToChannel.with.recipients.channel_object_ids.
  • Source: resource.dsl.do.processNonCompliantDevices.do.notifyToChannel.with.recipients.channel_object_ids
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.processNonCompliantDevices.for.each
  • Description: JumpCloud extension data on the managed entity: dsl.do.processNonCompliantDevices.for.each.
  • Source: resource.dsl.do.processNonCompliantDevices.for.each
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.processNonCompliantDevices.for.in
  • Description: JumpCloud extension data on the managed entity: dsl.do.processNonCompliantDevices.for.in.
  • Source: resource.dsl.do.processNonCompliantDevices.for.in
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.processNonCompliantDevices.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.processNonCompliantDevices.then.
  • Source: resource.dsl.do.processNonCompliantDevices.then
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.processNonMFAUsers.do.addUserToNonMFAGroup.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.processNonMFAUsers.do.addUserToNonMFAGroup.call.
  • Source: resource.dsl.do.processNonMFAUsers.do.addUserToNonMFAGroup.call
  • Usage: workflow_create
entity.data.dsl.do.processNonMFAUsers.do.addUserToNonMFAGroup.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.processNonMFAUsers.do.addUserToNonMFAGroup.then.
  • Source: resource.dsl.do.processNonMFAUsers.do.addUserToNonMFAGroup.then
  • Usage: workflow_create
entity.data.dsl.do.processNonMFAUsers.do.addUserToNonMFAGroup.with.bodyParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.processNonMFAUsers.do.addUserToNonMFAGroup.with.bodyParams.id.
  • Source: resource.dsl.do.processNonMFAUsers.do.addUserToNonMFAGroup.with.bodyParams.id
  • Usage: workflow_create
entity.data.dsl.do.processNonMFAUsers.do.addUserToNonMFAGroup.with.bodyParams.op
  • Description: JumpCloud extension data on the managed entity: dsl.do.processNonMFAUsers.do.addUserToNonMFAGroup.with.bodyParams.op.
  • Source: resource.dsl.do.processNonMFAUsers.do.addUserToNonMFAGroup.with.bodyParams.op
  • Usage: workflow_create
entity.data.dsl.do.processNonMFAUsers.do.addUserToNonMFAGroup.with.bodyParams.type
  • Description: JumpCloud extension data on the managed entity: dsl.do.processNonMFAUsers.do.addUserToNonMFAGroup.with.bodyParams.type.
  • Source: resource.dsl.do.processNonMFAUsers.do.addUserToNonMFAGroup.with.bodyParams.type
  • Usage: workflow_create
entity.data.dsl.do.processNonMFAUsers.do.addUserToNonMFAGroup.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.processNonMFAUsers.do.addUserToNonMFAGroup.with.operationId.
  • Source: resource.dsl.do.processNonMFAUsers.do.addUserToNonMFAGroup.with.operationId
  • Usage: workflow_create
entity.data.dsl.do.processNonMFAUsers.do.addUserToNonMFAGroup.with.pathParams.group_id
  • Description: JumpCloud extension data on the managed entity: dsl.do.processNonMFAUsers.do.addUserToNonMFAGroup.with.pathParams.group_id.
  • Source: resource.dsl.do.processNonMFAUsers.do.addUserToNonMFAGroup.with.pathParams.group_id
  • Usage: workflow_create
entity.data.dsl.do.processNonMFAUsers.do.addUserToNonMFAGroup.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.processNonMFAUsers.do.addUserToNonMFAGroup.with.version.
  • Source: resource.dsl.do.processNonMFAUsers.do.addUserToNonMFAGroup.with.version
  • Usage: workflow_create
entity.data.dsl.do.processNonMFAUsers.do.routeActiveUsers.switch.default.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.processNonMFAUsers.do.routeActiveUsers.switch.default.then.
  • Source: resource.dsl.do.processNonMFAUsers.do.routeActiveUsers.switch.default.then
  • Usage: workflow_create
entity.data.dsl.do.processNonMFAUsers.do.routeActiveUsers.switch.isActive.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.processNonMFAUsers.do.routeActiveUsers.switch.isActive.then.
  • Source: resource.dsl.do.processNonMFAUsers.do.routeActiveUsers.switch.isActive.then
  • Usage: workflow_create
entity.data.dsl.do.processNonMFAUsers.do.routeActiveUsers.switch.isActive.when
  • Description: JumpCloud extension data on the managed entity: dsl.do.processNonMFAUsers.do.routeActiveUsers.switch.isActive.when.
  • Source: resource.dsl.do.processNonMFAUsers.do.routeActiveUsers.switch.isActive.when
  • Usage: workflow_create
entity.data.dsl.do.processNonMFAUsers.do.sendMFAReminderEmail.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.processNonMFAUsers.do.sendMFAReminderEmail.call.
  • Source: resource.dsl.do.processNonMFAUsers.do.sendMFAReminderEmail.call
  • Usage: workflow_create
entity.data.dsl.do.processNonMFAUsers.do.sendMFAReminderEmail.if
  • Description: JumpCloud extension data on the managed entity: dsl.do.processNonMFAUsers.do.sendMFAReminderEmail.if.
  • Source: resource.dsl.do.processNonMFAUsers.do.sendMFAReminderEmail.if
  • Usage: workflow_create
entity.data.dsl.do.processNonMFAUsers.do.sendMFAReminderEmail.with.message.body
  • Description: JumpCloud extension data on the managed entity: dsl.do.processNonMFAUsers.do.sendMFAReminderEmail.with.message.body.
  • Source: resource.dsl.do.processNonMFAUsers.do.sendMFAReminderEmail.with.message.body
  • Usage: workflow_create
entity.data.dsl.do.processNonMFAUsers.do.sendMFAReminderEmail.with.message.subject
  • Description: JumpCloud extension data on the managed entity: dsl.do.processNonMFAUsers.do.sendMFAReminderEmail.with.message.subject.
  • Source: resource.dsl.do.processNonMFAUsers.do.sendMFAReminderEmail.with.message.subject
  • Usage: workflow_create
entity.data.dsl.do.processNonMFAUsers.do.sendMFAReminderEmail.with.recipients.to_addresses
  • Description: JumpCloud extension data on the managed entity: dsl.do.processNonMFAUsers.do.sendMFAReminderEmail.with.recipients.to_addresses.
  • Source: resource.dsl.do.processNonMFAUsers.do.sendMFAReminderEmail.with.recipients.to_addresses
  • Usage: workflow_create
entity.data.dsl.do.processNonMFAUsers.for.each
  • Description: JumpCloud extension data on the managed entity: dsl.do.processNonMFAUsers.for.each.
  • Source: resource.dsl.do.processNonMFAUsers.for.each
  • Usage: workflow_create
entity.data.dsl.do.processNonMFAUsers.for.in
  • Description: JumpCloud extension data on the managed entity: dsl.do.processNonMFAUsers.for.in.
  • Source: resource.dsl.do.processNonMFAUsers.for.in
  • Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.addUserToPreHireGroup.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.processScheduledUsers.do.addUserToPreHireGroup.call.
  • Source: resource.dsl.do.processScheduledUsers.do.addUserToPreHireGroup.call
  • Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.addUserToPreHireGroup.metadata.displayLabels.user
  • Description: JumpCloud extension data on the managed entity: dsl.do.processScheduledUsers.do.addUserToPreHireGroup.metadata.displayLabels.user.
  • Source: resource.dsl.do.processScheduledUsers.do.addUserToPreHireGroup.metadata.displayLabels.user
  • Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.addUserToPreHireGroup.metadata.displayLabels.userGroup
  • Description: JumpCloud extension data on the managed entity: dsl.do.processScheduledUsers.do.addUserToPreHireGroup.metadata.displayLabels.userGroup.
  • Source: resource.dsl.do.processScheduledUsers.do.addUserToPreHireGroup.metadata.displayLabels.userGroup
  • Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.addUserToPreHireGroup.metadata.inputModes.user
  • Description: JumpCloud extension data on the managed entity: dsl.do.processScheduledUsers.do.addUserToPreHireGroup.metadata.inputModes.user.
  • Source: resource.dsl.do.processScheduledUsers.do.addUserToPreHireGroup.metadata.inputModes.user
  • Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.addUserToPreHireGroup.metadata.inputModes.userGroup
  • Description: JumpCloud extension data on the managed entity: dsl.do.processScheduledUsers.do.addUserToPreHireGroup.metadata.inputModes.userGroup.
  • Source: resource.dsl.do.processScheduledUsers.do.addUserToPreHireGroup.metadata.inputModes.userGroup
  • Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.addUserToPreHireGroup.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.processScheduledUsers.do.addUserToPreHireGroup.then.
  • Source: resource.dsl.do.processScheduledUsers.do.addUserToPreHireGroup.then
  • Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.addUserToPreHireGroup.with.bodyParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.processScheduledUsers.do.addUserToPreHireGroup.with.bodyParams.id.
  • Source: resource.dsl.do.processScheduledUsers.do.addUserToPreHireGroup.with.bodyParams.id
  • Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.addUserToPreHireGroup.with.bodyParams.op
  • Description: JumpCloud extension data on the managed entity: dsl.do.processScheduledUsers.do.addUserToPreHireGroup.with.bodyParams.op.
  • Source: resource.dsl.do.processScheduledUsers.do.addUserToPreHireGroup.with.bodyParams.op
  • Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.addUserToPreHireGroup.with.bodyParams.type
  • Description: JumpCloud extension data on the managed entity: dsl.do.processScheduledUsers.do.addUserToPreHireGroup.with.bodyParams.type.
  • Source: resource.dsl.do.processScheduledUsers.do.addUserToPreHireGroup.with.bodyParams.type
  • Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.addUserToPreHireGroup.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.processScheduledUsers.do.addUserToPreHireGroup.with.operationId.
  • Source: resource.dsl.do.processScheduledUsers.do.addUserToPreHireGroup.with.operationId
  • Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.addUserToPreHireGroup.with.pathParams.group_id
  • Description: JumpCloud extension data on the managed entity: dsl.do.processScheduledUsers.do.addUserToPreHireGroup.with.pathParams.group_id.
  • Source: resource.dsl.do.processScheduledUsers.do.addUserToPreHireGroup.with.pathParams.group_id
  • Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.addUserToPreHireGroup.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.processScheduledUsers.do.addUserToPreHireGroup.with.version.
  • Source: resource.dsl.do.processScheduledUsers.do.addUserToPreHireGroup.with.version
  • Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.emailITOps.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.processScheduledUsers.do.emailITOps.call.
  • Source: resource.dsl.do.processScheduledUsers.do.emailITOps.call
  • Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.emailITOps.with.message.body
  • Description: JumpCloud extension data on the managed entity: dsl.do.processScheduledUsers.do.emailITOps.with.message.body.
  • Source: resource.dsl.do.processScheduledUsers.do.emailITOps.with.message.body
  • Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.emailITOps.with.message.subject
  • Description: JumpCloud extension data on the managed entity: dsl.do.processScheduledUsers.do.emailITOps.with.message.subject.
  • Source: resource.dsl.do.processScheduledUsers.do.emailITOps.with.message.subject
  • Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.emailITOps.with.recipients.to_addresses
  • Description: JumpCloud extension data on the managed entity: dsl.do.processScheduledUsers.do.emailITOps.with.recipients.to_addresses.
  • Source: resource.dsl.do.processScheduledUsers.do.emailITOps.with.recipients.to_addresses
  • Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.emailManager.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.processScheduledUsers.do.emailManager.call.
  • Source: resource.dsl.do.processScheduledUsers.do.emailManager.call
  • Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.emailManager.if
  • Description: JumpCloud extension data on the managed entity: dsl.do.processScheduledUsers.do.emailManager.if.
  • Source: resource.dsl.do.processScheduledUsers.do.emailManager.if
  • Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.emailManager.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.processScheduledUsers.do.emailManager.then.
  • Source: resource.dsl.do.processScheduledUsers.do.emailManager.then
  • Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.emailManager.with.message.body
  • Description: JumpCloud extension data on the managed entity: dsl.do.processScheduledUsers.do.emailManager.with.message.body.
  • Source: resource.dsl.do.processScheduledUsers.do.emailManager.with.message.body
  • Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.emailManager.with.message.subject
  • Description: JumpCloud extension data on the managed entity: dsl.do.processScheduledUsers.do.emailManager.with.message.subject.
  • Source: resource.dsl.do.processScheduledUsers.do.emailManager.with.message.subject
  • Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.emailManager.with.recipients.to_addresses
  • Description: JumpCloud extension data on the managed entity: dsl.do.processScheduledUsers.do.emailManager.with.recipients.to_addresses.
  • Source: resource.dsl.do.processScheduledUsers.do.emailManager.with.recipients.to_addresses
  • Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.getManagerDetails.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.processScheduledUsers.do.getManagerDetails.call.
  • Source: resource.dsl.do.processScheduledUsers.do.getManagerDetails.call
  • Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.getManagerDetails.if
  • Description: JumpCloud extension data on the managed entity: dsl.do.processScheduledUsers.do.getManagerDetails.if.
  • Source: resource.dsl.do.processScheduledUsers.do.getManagerDetails.if
  • Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.getManagerDetails.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.processScheduledUsers.do.getManagerDetails.with.operationId.
  • Source: resource.dsl.do.processScheduledUsers.do.getManagerDetails.with.operationId
  • Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.getManagerDetails.with.pathParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.processScheduledUsers.do.getManagerDetails.with.pathParams.id.
  • Source: resource.dsl.do.processScheduledUsers.do.getManagerDetails.with.pathParams.id
  • Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.getManagerDetails.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.processScheduledUsers.do.getManagerDetails.with.version.
  • Source: resource.dsl.do.processScheduledUsers.do.getManagerDetails.with.version
  • Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.getUserDetails.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.processScheduledUsers.do.getUserDetails.call.
  • Source: resource.dsl.do.processScheduledUsers.do.getUserDetails.call
  • Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.getUserDetails.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.processScheduledUsers.do.getUserDetails.then.
  • Source: resource.dsl.do.processScheduledUsers.do.getUserDetails.then
  • Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.getUserDetails.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.processScheduledUsers.do.getUserDetails.with.operationId.
  • Source: resource.dsl.do.processScheduledUsers.do.getUserDetails.with.operationId
  • Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.getUserDetails.with.pathParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.processScheduledUsers.do.getUserDetails.with.pathParams.id.
  • Source: resource.dsl.do.processScheduledUsers.do.getUserDetails.with.pathParams.id
  • Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.getUserDetails.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.processScheduledUsers.do.getUserDetails.with.version.
  • Source: resource.dsl.do.processScheduledUsers.do.getUserDetails.with.version
  • Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.routeByScheduledDateWindow.switch.default.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.processScheduledUsers.do.routeByScheduledDateWindow.switch.default.then.
  • Source: resource.dsl.do.processScheduledUsers.do.routeByScheduledDateWindow.switch.default.then
  • Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.routeByScheduledDateWindow.switch.scheduledSoon.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.processScheduledUsers.do.routeByScheduledDateWindow.switch.scheduledSoon.then.
  • Source: resource.dsl.do.processScheduledUsers.do.routeByScheduledDateWindow.switch.scheduledSoon.then
  • Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.routeByScheduledDateWindow.switch.scheduledSoon.when
  • Description: JumpCloud extension data on the managed entity: dsl.do.processScheduledUsers.do.routeByScheduledDateWindow.switch.scheduledSoon.when.
  • Source: resource.dsl.do.processScheduledUsers.do.routeByScheduledDateWindow.switch.scheduledSoon.when
  • Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.for.each
  • Description: JumpCloud extension data on the managed entity: dsl.do.processScheduledUsers.for.each.
  • Source: resource.dsl.do.processScheduledUsers.for.each
  • Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.for.in
  • Description: JumpCloud extension data on the managed entity: dsl.do.processScheduledUsers.for.in.
  • Source: resource.dsl.do.processScheduledUsers.for.in
  • Usage: workflow_create
entity.data.dsl.do.putCommandFullSync.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.putCommandFullSync.call.
  • Source: resource.dsl.do.putCommandFullSync.call
  • Usage: workflow_create
entity.data.dsl.do.putCommandFullSync.if
  • Description: JumpCloud extension data on the managed entity: dsl.do.putCommandFullSync.if.
  • Source: resource.dsl.do.putCommandFullSync.if
  • Usage: workflow_create
entity.data.dsl.do.putCommandFullSync.with.bodyParams.command
  • Description: JumpCloud extension data on the managed entity: dsl.do.putCommandFullSync.with.bodyParams.command.
  • Source: resource.dsl.do.putCommandFullSync.with.bodyParams.command
  • Usage: workflow_create
entity.data.dsl.do.putCommandFullSync.with.bodyParams.commandRunners
  • Description: JumpCloud extension data on the managed entity: dsl.do.putCommandFullSync.with.bodyParams.commandRunners.
  • Source: resource.dsl.do.putCommandFullSync.with.bodyParams.commandRunners
  • Usage: workflow_create
entity.data.dsl.do.putCommandFullSync.with.bodyParams.commandType
  • Description: JumpCloud extension data on the managed entity: dsl.do.putCommandFullSync.with.bodyParams.commandType.
  • Source: resource.dsl.do.putCommandFullSync.with.bodyParams.commandType
  • Usage: workflow_create
entity.data.dsl.do.putCommandFullSync.with.bodyParams.description
  • Description: JumpCloud extension data on the managed entity: dsl.do.putCommandFullSync.with.bodyParams.description.
  • Source: resource.dsl.do.putCommandFullSync.with.bodyParams.description
  • Usage: workflow_create
entity.data.dsl.do.putCommandFullSync.with.bodyParams.files
  • Description: JumpCloud extension data on the managed entity: dsl.do.putCommandFullSync.with.bodyParams.files.
  • Source: resource.dsl.do.putCommandFullSync.with.bodyParams.files
  • Usage: workflow_create
entity.data.dsl.do.putCommandFullSync.with.bodyParams.launchType
  • Description: JumpCloud extension data on the managed entity: dsl.do.putCommandFullSync.with.bodyParams.launchType.
  • Source: resource.dsl.do.putCommandFullSync.with.bodyParams.launchType
  • Usage: workflow_create
entity.data.dsl.do.putCommandFullSync.with.bodyParams.listensTo
  • Description: JumpCloud extension data on the managed entity: dsl.do.putCommandFullSync.with.bodyParams.listensTo.
  • Source: resource.dsl.do.putCommandFullSync.with.bodyParams.listensTo
  • Usage: workflow_create
entity.data.dsl.do.putCommandFullSync.with.bodyParams.name
  • Description: JumpCloud extension data on the managed entity: dsl.do.putCommandFullSync.with.bodyParams.name.
  • Source: resource.dsl.do.putCommandFullSync.with.bodyParams.name
  • Usage: workflow_create
entity.data.dsl.do.putCommandFullSync.with.bodyParams.organization
  • Description: JumpCloud extension data on the managed entity: dsl.do.putCommandFullSync.with.bodyParams.organization.
  • Source: resource.dsl.do.putCommandFullSync.with.bodyParams.organization
  • Usage: workflow_create
entity.data.dsl.do.putCommandFullSync.with.bodyParams.schedule
  • Description: JumpCloud extension data on the managed entity: dsl.do.putCommandFullSync.with.bodyParams.schedule.
  • Source: resource.dsl.do.putCommandFullSync.with.bodyParams.schedule
  • Usage: workflow_create
entity.data.dsl.do.putCommandFullSync.with.bodyParams.scheduleRepeatType
  • Description: JumpCloud extension data on the managed entity: dsl.do.putCommandFullSync.with.bodyParams.scheduleRepeatType.
  • Source: resource.dsl.do.putCommandFullSync.with.bodyParams.scheduleRepeatType
  • Usage: workflow_create
entity.data.dsl.do.putCommandFullSync.with.bodyParams.scheduleYear
  • Description: JumpCloud extension data on the managed entity: dsl.do.putCommandFullSync.with.bodyParams.scheduleYear.
  • Source: resource.dsl.do.putCommandFullSync.with.bodyParams.scheduleYear
  • Usage: workflow_create
entity.data.dsl.do.putCommandFullSync.with.bodyParams.shell
  • Description: JumpCloud extension data on the managed entity: dsl.do.putCommandFullSync.with.bodyParams.shell.
  • Source: resource.dsl.do.putCommandFullSync.with.bodyParams.shell
  • Usage: workflow_create
entity.data.dsl.do.putCommandFullSync.with.bodyParams.sudo
  • Description: JumpCloud extension data on the managed entity: dsl.do.putCommandFullSync.with.bodyParams.sudo.
  • Source: resource.dsl.do.putCommandFullSync.with.bodyParams.sudo
  • Usage: workflow_create
entity.data.dsl.do.putCommandFullSync.with.bodyParams.systems
  • Description: JumpCloud extension data on the managed entity: dsl.do.putCommandFullSync.with.bodyParams.systems.
  • Source: resource.dsl.do.putCommandFullSync.with.bodyParams.systems
  • Usage: workflow_create
entity.data.dsl.do.putCommandFullSync.with.bodyParams.template
  • Description: JumpCloud extension data on the managed entity: dsl.do.putCommandFullSync.with.bodyParams.template.
  • Source: resource.dsl.do.putCommandFullSync.with.bodyParams.template
  • Usage: workflow_create
entity.data.dsl.do.putCommandFullSync.with.bodyParams.timeToLiveSeconds
  • Description: JumpCloud extension data on the managed entity: dsl.do.putCommandFullSync.with.bodyParams.timeToLiveSeconds.
  • Source: resource.dsl.do.putCommandFullSync.with.bodyParams.timeToLiveSeconds
  • Usage: workflow_create
entity.data.dsl.do.putCommandFullSync.with.bodyParams.timeout
  • Description: JumpCloud extension data on the managed entity: dsl.do.putCommandFullSync.with.bodyParams.timeout.
  • Source: resource.dsl.do.putCommandFullSync.with.bodyParams.timeout
  • Usage: workflow_create
entity.data.dsl.do.putCommandFullSync.with.bodyParams.trigger
  • Description: JumpCloud extension data on the managed entity: dsl.do.putCommandFullSync.with.bodyParams.trigger.
  • Source: resource.dsl.do.putCommandFullSync.with.bodyParams.trigger
  • Usage: workflow_create
entity.data.dsl.do.putCommandFullSync.with.bodyParams.user
  • Description: JumpCloud extension data on the managed entity: dsl.do.putCommandFullSync.with.bodyParams.user.
  • Source: resource.dsl.do.putCommandFullSync.with.bodyParams.user
  • Usage: workflow_create
entity.data.dsl.do.putCommandFullSync.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.putCommandFullSync.with.operationId.
  • Source: resource.dsl.do.putCommandFullSync.with.operationId
  • Usage: workflow_create
entity.data.dsl.do.putCommandFullSync.with.pathParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.putCommandFullSync.with.pathParams.id.
  • Source: resource.dsl.do.putCommandFullSync.with.pathParams.id
  • Usage: workflow_create
entity.data.dsl.do.putCommandFullSync.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.putCommandFullSync.with.version.
  • Source: resource.dsl.do.putCommandFullSync.with.version
  • Usage: workflow_create
entity.data.dsl.do.putUserFullSync.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserFullSync.call.
  • Source: resource.dsl.do.putUserFullSync.call
  • Usage: workflow_create
entity.data.dsl.do.putUserFullSync.if
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserFullSync.if.
  • Source: resource.dsl.do.putUserFullSync.if
  • Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.account_locked
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserFullSync.with.bodyParams.account_locked.
  • Source: resource.dsl.do.putUserFullSync.with.bodyParams.account_locked
  • Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.addresses
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserFullSync.with.bodyParams.addresses.
  • Source: resource.dsl.do.putUserFullSync.with.bodyParams.addresses
  • Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.allow_public_key
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserFullSync.with.bodyParams.allow_public_key.
  • Source: resource.dsl.do.putUserFullSync.with.bodyParams.allow_public_key
  • Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.alternateEmail
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserFullSync.with.bodyParams.alternateEmail.
  • Source: resource.dsl.do.putUserFullSync.with.bodyParams.alternateEmail
  • Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.attributes
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserFullSync.with.bodyParams.attributes.
  • Source: resource.dsl.do.putUserFullSync.with.bodyParams.attributes
  • Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.company
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserFullSync.with.bodyParams.company.
  • Source: resource.dsl.do.putUserFullSync.with.bodyParams.company
  • Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.costCenter
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserFullSync.with.bodyParams.costCenter.
  • Source: resource.dsl.do.putUserFullSync.with.bodyParams.costCenter
  • Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.department
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserFullSync.with.bodyParams.department.
  • Source: resource.dsl.do.putUserFullSync.with.bodyParams.department
  • Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.description
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserFullSync.with.bodyParams.description.
  • Source: resource.dsl.do.putUserFullSync.with.bodyParams.description
  • Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.disableDeviceMaxLoginAttempts
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserFullSync.with.bodyParams.disableDeviceMaxLoginAttempts.
  • Source: resource.dsl.do.putUserFullSync.with.bodyParams.disableDeviceMaxLoginAttempts
  • Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.displayname
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserFullSync.with.bodyParams.displayname.
  • Source: resource.dsl.do.putUserFullSync.with.bodyParams.displayname
  • Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.email
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserFullSync.with.bodyParams.email.
  • Source: resource.dsl.do.putUserFullSync.with.bodyParams.email
  • Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.employeeIdentifier
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserFullSync.with.bodyParams.employeeIdentifier.
  • Source: resource.dsl.do.putUserFullSync.with.bodyParams.employeeIdentifier
  • Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.employeeType
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserFullSync.with.bodyParams.employeeType.
  • Source: resource.dsl.do.putUserFullSync.with.bodyParams.employeeType
  • Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.enable_managed_uid
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserFullSync.with.bodyParams.enable_managed_uid.
  • Source: resource.dsl.do.putUserFullSync.with.bodyParams.enable_managed_uid
  • Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.enable_user_portal_multifactor
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserFullSync.with.bodyParams.enable_user_portal_multifactor.
  • Source: resource.dsl.do.putUserFullSync.with.bodyParams.enable_user_portal_multifactor
  • Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.external_dn
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserFullSync.with.bodyParams.external_dn.
  • Source: resource.dsl.do.putUserFullSync.with.bodyParams.external_dn
  • Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.external_password_expiration_date
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserFullSync.with.bodyParams.external_password_expiration_date.
  • Source: resource.dsl.do.putUserFullSync.with.bodyParams.external_password_expiration_date
  • Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.external_source_type
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserFullSync.with.bodyParams.external_source_type.
  • Source: resource.dsl.do.putUserFullSync.with.bodyParams.external_source_type
  • Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.externally_managed
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserFullSync.with.bodyParams.externally_managed.
  • Source: resource.dsl.do.putUserFullSync.with.bodyParams.externally_managed
  • Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.firstname
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserFullSync.with.bodyParams.firstname.
  • Source: resource.dsl.do.putUserFullSync.with.bodyParams.firstname
  • Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.jobTitle
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserFullSync.with.bodyParams.jobTitle.
  • Source: resource.dsl.do.putUserFullSync.with.bodyParams.jobTitle
  • Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.lastname
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserFullSync.with.bodyParams.lastname.
  • Source: resource.dsl.do.putUserFullSync.with.bodyParams.lastname
  • Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.ldap_binding_user
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserFullSync.with.bodyParams.ldap_binding_user.
  • Source: resource.dsl.do.putUserFullSync.with.bodyParams.ldap_binding_user
  • Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.location
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserFullSync.with.bodyParams.location.
  • Source: resource.dsl.do.putUserFullSync.with.bodyParams.location
  • Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.managedAppleId
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserFullSync.with.bodyParams.managedAppleId.
  • Source: resource.dsl.do.putUserFullSync.with.bodyParams.managedAppleId
  • Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.manager
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserFullSync.with.bodyParams.manager.
  • Source: resource.dsl.do.putUserFullSync.with.bodyParams.manager
  • Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.mfa
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserFullSync.with.bodyParams.mfa.
  • Source: resource.dsl.do.putUserFullSync.with.bodyParams.mfa
  • Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.middlename
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserFullSync.with.bodyParams.middlename.
  • Source: resource.dsl.do.putUserFullSync.with.bodyParams.middlename
  • Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.password_never_expires
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserFullSync.with.bodyParams.password_never_expires.
  • Source: resource.dsl.do.putUserFullSync.with.bodyParams.password_never_expires
  • Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.phoneNumbers
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserFullSync.with.bodyParams.phoneNumbers.
  • Source: resource.dsl.do.putUserFullSync.with.bodyParams.phoneNumbers
  • Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.public_key
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserFullSync.with.bodyParams.public_key.
  • Source: resource.dsl.do.putUserFullSync.with.bodyParams.public_key
  • Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.relationships
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserFullSync.with.bodyParams.relationships.
  • Source: resource.dsl.do.putUserFullSync.with.bodyParams.relationships
  • Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.restrictedFields
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserFullSync.with.bodyParams.restrictedFields.
  • Source: resource.dsl.do.putUserFullSync.with.bodyParams.restrictedFields
  • Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.samba_service_user
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserFullSync.with.bodyParams.samba_service_user.
  • Source: resource.dsl.do.putUserFullSync.with.bodyParams.samba_service_user
  • Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.ssh_keys
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserFullSync.with.bodyParams.ssh_keys.
  • Source: resource.dsl.do.putUserFullSync.with.bodyParams.ssh_keys
  • Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.state
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserFullSync.with.bodyParams.state.
  • Source: resource.dsl.do.putUserFullSync.with.bodyParams.state
  • Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.sudo
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserFullSync.with.bodyParams.sudo.
  • Source: resource.dsl.do.putUserFullSync.with.bodyParams.sudo
  • Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.suspended
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserFullSync.with.bodyParams.suspended.
  • Source: resource.dsl.do.putUserFullSync.with.bodyParams.suspended
  • Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.tags
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserFullSync.with.bodyParams.tags.
  • Source: resource.dsl.do.putUserFullSync.with.bodyParams.tags
  • Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.username
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserFullSync.with.bodyParams.username.
  • Source: resource.dsl.do.putUserFullSync.with.bodyParams.username
  • Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserFullSync.with.operationId.
  • Source: resource.dsl.do.putUserFullSync.with.operationId
  • Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.pathParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserFullSync.with.pathParams.id.
  • Source: resource.dsl.do.putUserFullSync.with.pathParams.id
  • Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserFullSync.with.version.
  • Source: resource.dsl.do.putUserFullSync.with.version
  • Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserWithApproval.call.
  • Source: resource.dsl.do.putUserWithApproval.call
  • Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.if
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserWithApproval.if.
  • Source: resource.dsl.do.putUserWithApproval.if
  • Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.account_locked
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserWithApproval.with.bodyParams.account_locked.
  • Source: resource.dsl.do.putUserWithApproval.with.bodyParams.account_locked
  • Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.addresses
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserWithApproval.with.bodyParams.addresses.
  • Source: resource.dsl.do.putUserWithApproval.with.bodyParams.addresses
  • Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.allow_public_key
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserWithApproval.with.bodyParams.allow_public_key.
  • Source: resource.dsl.do.putUserWithApproval.with.bodyParams.allow_public_key
  • Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.alternateEmail
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserWithApproval.with.bodyParams.alternateEmail.
  • Source: resource.dsl.do.putUserWithApproval.with.bodyParams.alternateEmail
  • Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.attributes
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserWithApproval.with.bodyParams.attributes.
  • Source: resource.dsl.do.putUserWithApproval.with.bodyParams.attributes
  • Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.company
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserWithApproval.with.bodyParams.company.
  • Source: resource.dsl.do.putUserWithApproval.with.bodyParams.company
  • Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.costCenter
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserWithApproval.with.bodyParams.costCenter.
  • Source: resource.dsl.do.putUserWithApproval.with.bodyParams.costCenter
  • Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.department
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserWithApproval.with.bodyParams.department.
  • Source: resource.dsl.do.putUserWithApproval.with.bodyParams.department
  • Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.description
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserWithApproval.with.bodyParams.description.
  • Source: resource.dsl.do.putUserWithApproval.with.bodyParams.description
  • Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.disableDeviceMaxLoginAttempts
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserWithApproval.with.bodyParams.disableDeviceMaxLoginAttempts.
  • Source: resource.dsl.do.putUserWithApproval.with.bodyParams.disableDeviceMaxLoginAttempts
  • Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.displayname
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserWithApproval.with.bodyParams.displayname.
  • Source: resource.dsl.do.putUserWithApproval.with.bodyParams.displayname
  • Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.email
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserWithApproval.with.bodyParams.email.
  • Source: resource.dsl.do.putUserWithApproval.with.bodyParams.email
  • Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.employeeIdentifier
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserWithApproval.with.bodyParams.employeeIdentifier.
  • Source: resource.dsl.do.putUserWithApproval.with.bodyParams.employeeIdentifier
  • Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.employeeType
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserWithApproval.with.bodyParams.employeeType.
  • Source: resource.dsl.do.putUserWithApproval.with.bodyParams.employeeType
  • Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.enable_managed_uid
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserWithApproval.with.bodyParams.enable_managed_uid.
  • Source: resource.dsl.do.putUserWithApproval.with.bodyParams.enable_managed_uid
  • Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.enable_user_portal_multifactor
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserWithApproval.with.bodyParams.enable_user_portal_multifactor.
  • Source: resource.dsl.do.putUserWithApproval.with.bodyParams.enable_user_portal_multifactor
  • Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.external_dn
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserWithApproval.with.bodyParams.external_dn.
  • Source: resource.dsl.do.putUserWithApproval.with.bodyParams.external_dn
  • Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.external_password_expiration_date
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserWithApproval.with.bodyParams.external_password_expiration_date.
  • Source: resource.dsl.do.putUserWithApproval.with.bodyParams.external_password_expiration_date
  • Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.external_source_type
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserWithApproval.with.bodyParams.external_source_type.
  • Source: resource.dsl.do.putUserWithApproval.with.bodyParams.external_source_type
  • Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.externally_managed
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserWithApproval.with.bodyParams.externally_managed.
  • Source: resource.dsl.do.putUserWithApproval.with.bodyParams.externally_managed
  • Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.firstname
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserWithApproval.with.bodyParams.firstname.
  • Source: resource.dsl.do.putUserWithApproval.with.bodyParams.firstname
  • Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.jobTitle
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserWithApproval.with.bodyParams.jobTitle.
  • Source: resource.dsl.do.putUserWithApproval.with.bodyParams.jobTitle
  • Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.lastname
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserWithApproval.with.bodyParams.lastname.
  • Source: resource.dsl.do.putUserWithApproval.with.bodyParams.lastname
  • Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.ldap_binding_user
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserWithApproval.with.bodyParams.ldap_binding_user.
  • Source: resource.dsl.do.putUserWithApproval.with.bodyParams.ldap_binding_user
  • Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.location
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserWithApproval.with.bodyParams.location.
  • Source: resource.dsl.do.putUserWithApproval.with.bodyParams.location
  • Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.managedAppleId
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserWithApproval.with.bodyParams.managedAppleId.
  • Source: resource.dsl.do.putUserWithApproval.with.bodyParams.managedAppleId
  • Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.manager
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserWithApproval.with.bodyParams.manager.
  • Source: resource.dsl.do.putUserWithApproval.with.bodyParams.manager
  • Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.mfa
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserWithApproval.with.bodyParams.mfa.
  • Source: resource.dsl.do.putUserWithApproval.with.bodyParams.mfa
  • Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.middlename
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserWithApproval.with.bodyParams.middlename.
  • Source: resource.dsl.do.putUserWithApproval.with.bodyParams.middlename
  • Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.password_never_expires
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserWithApproval.with.bodyParams.password_never_expires.
  • Source: resource.dsl.do.putUserWithApproval.with.bodyParams.password_never_expires
  • Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.phoneNumbers
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserWithApproval.with.bodyParams.phoneNumbers.
  • Source: resource.dsl.do.putUserWithApproval.with.bodyParams.phoneNumbers
  • Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.public_key
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserWithApproval.with.bodyParams.public_key.
  • Source: resource.dsl.do.putUserWithApproval.with.bodyParams.public_key
  • Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.relationships
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserWithApproval.with.bodyParams.relationships.
  • Source: resource.dsl.do.putUserWithApproval.with.bodyParams.relationships
  • Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.restrictedFields
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserWithApproval.with.bodyParams.restrictedFields.
  • Source: resource.dsl.do.putUserWithApproval.with.bodyParams.restrictedFields
  • Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.samba_service_user
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserWithApproval.with.bodyParams.samba_service_user.
  • Source: resource.dsl.do.putUserWithApproval.with.bodyParams.samba_service_user
  • Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.ssh_keys
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserWithApproval.with.bodyParams.ssh_keys.
  • Source: resource.dsl.do.putUserWithApproval.with.bodyParams.ssh_keys
  • Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.state
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserWithApproval.with.bodyParams.state.
  • Source: resource.dsl.do.putUserWithApproval.with.bodyParams.state
  • Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.sudo
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserWithApproval.with.bodyParams.sudo.
  • Source: resource.dsl.do.putUserWithApproval.with.bodyParams.sudo
  • Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.suspended
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserWithApproval.with.bodyParams.suspended.
  • Source: resource.dsl.do.putUserWithApproval.with.bodyParams.suspended
  • Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.tags
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserWithApproval.with.bodyParams.tags.
  • Source: resource.dsl.do.putUserWithApproval.with.bodyParams.tags
  • Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.username
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserWithApproval.with.bodyParams.username.
  • Source: resource.dsl.do.putUserWithApproval.with.bodyParams.username
  • Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserWithApproval.with.operationId.
  • Source: resource.dsl.do.putUserWithApproval.with.operationId
  • Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.pathParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserWithApproval.with.pathParams.id.
  • Source: resource.dsl.do.putUserWithApproval.with.pathParams.id
  • Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.putUserWithApproval.with.version.
  • Source: resource.dsl.do.putUserWithApproval.with.version
  • Usage: workflow_create
entity.data.dsl.do.reactivateUser.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.reactivateUser.call.
  • Source: resource.dsl.do.reactivateUser.call
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.reactivateUser.metadata.displayLabels.user
  • Description: JumpCloud extension data on the managed entity: dsl.do.reactivateUser.metadata.displayLabels.user.
  • Source: resource.dsl.do.reactivateUser.metadata.displayLabels.user
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.reactivateUser.metadata.inputModes.email
  • Description: JumpCloud extension data on the managed entity: dsl.do.reactivateUser.metadata.inputModes.email.
  • Source: resource.dsl.do.reactivateUser.metadata.inputModes.email
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.reactivateUser.metadata.inputModes.user
  • Description: JumpCloud extension data on the managed entity: dsl.do.reactivateUser.metadata.inputModes.user.
  • Source: resource.dsl.do.reactivateUser.metadata.inputModes.user
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.reactivateUser.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.reactivateUser.with.operationId.
  • Source: resource.dsl.do.reactivateUser.with.operationId
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.reactivateUser.with.pathParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.reactivateUser.with.pathParams.id.
  • Source: resource.dsl.do.reactivateUser.with.pathParams.id
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.reactivateUser.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.reactivateUser.with.version.
  • Source: resource.dsl.do.reactivateUser.with.version
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.removeDelegatedAuthority.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.removeDelegatedAuthority.call.
  • Source: resource.dsl.do.removeDelegatedAuthority.call
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.removeDelegatedAuthority.if
  • Description: JumpCloud extension data on the managed entity: dsl.do.removeDelegatedAuthority.if.
  • Source: resource.dsl.do.removeDelegatedAuthority.if
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.removeDelegatedAuthority.with.bodyParams.delegatedAuthority
  • Description: JumpCloud extension data on the managed entity: dsl.do.removeDelegatedAuthority.with.bodyParams.delegatedAuthority.
  • Source: resource.dsl.do.removeDelegatedAuthority.with.bodyParams.delegatedAuthority
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.removeDelegatedAuthority.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.removeDelegatedAuthority.with.operationId.
  • Source: resource.dsl.do.removeDelegatedAuthority.with.operationId
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.removeDelegatedAuthority.with.pathParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.removeDelegatedAuthority.with.pathParams.id.
  • Source: resource.dsl.do.removeDelegatedAuthority.with.pathParams.id
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.removeDelegatedAuthority.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.removeDelegatedAuthority.with.version.
  • Source: resource.dsl.do.removeDelegatedAuthority.with.version
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.removeFromAllGroups.do.removeFromGroup.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.removeFromAllGroups.do.removeFromGroup.call.
  • Source: resource.dsl.do.removeFromAllGroups.do.removeFromGroup.call
  • Usage: workflow_delete
entity.data.dsl.do.removeFromAllGroups.do.removeFromGroup.with.bodyParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.removeFromAllGroups.do.removeFromGroup.with.bodyParams.id.
  • Source: resource.dsl.do.removeFromAllGroups.do.removeFromGroup.with.bodyParams.id
  • Usage: workflow_delete
entity.data.dsl.do.removeFromAllGroups.do.removeFromGroup.with.bodyParams.op
  • Description: JumpCloud extension data on the managed entity: dsl.do.removeFromAllGroups.do.removeFromGroup.with.bodyParams.op.
  • Source: resource.dsl.do.removeFromAllGroups.do.removeFromGroup.with.bodyParams.op
  • Usage: workflow_delete
entity.data.dsl.do.removeFromAllGroups.do.removeFromGroup.with.bodyParams.type
  • Description: JumpCloud extension data on the managed entity: dsl.do.removeFromAllGroups.do.removeFromGroup.with.bodyParams.type.
  • Source: resource.dsl.do.removeFromAllGroups.do.removeFromGroup.with.bodyParams.type
  • Usage: workflow_delete
entity.data.dsl.do.removeFromAllGroups.do.removeFromGroup.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.removeFromAllGroups.do.removeFromGroup.with.operationId.
  • Source: resource.dsl.do.removeFromAllGroups.do.removeFromGroup.with.operationId
  • Usage: workflow_delete
entity.data.dsl.do.removeFromAllGroups.do.removeFromGroup.with.pathParams.group_id
  • Description: JumpCloud extension data on the managed entity: dsl.do.removeFromAllGroups.do.removeFromGroup.with.pathParams.group_id.
  • Source: resource.dsl.do.removeFromAllGroups.do.removeFromGroup.with.pathParams.group_id
  • Usage: workflow_delete
entity.data.dsl.do.removeFromAllGroups.do.removeFromGroup.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.removeFromAllGroups.do.removeFromGroup.with.version.
  • Source: resource.dsl.do.removeFromAllGroups.do.removeFromGroup.with.version
  • Usage: workflow_delete
entity.data.dsl.do.removeFromAllGroups.do.removeUserFromGroup.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.removeFromAllGroups.do.removeUserFromGroup.call.
  • Source: resource.dsl.do.removeFromAllGroups.do.removeUserFromGroup.call
  • Usage: workflow_delete
entity.data.dsl.do.removeFromAllGroups.do.removeUserFromGroup.with.bodyParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.removeFromAllGroups.do.removeUserFromGroup.with.bodyParams.id.
  • Source: resource.dsl.do.removeFromAllGroups.do.removeUserFromGroup.with.bodyParams.id
  • Usage: workflow_delete
entity.data.dsl.do.removeFromAllGroups.do.removeUserFromGroup.with.bodyParams.op
  • Description: JumpCloud extension data on the managed entity: dsl.do.removeFromAllGroups.do.removeUserFromGroup.with.bodyParams.op.
  • Source: resource.dsl.do.removeFromAllGroups.do.removeUserFromGroup.with.bodyParams.op
  • Usage: workflow_delete
entity.data.dsl.do.removeFromAllGroups.do.removeUserFromGroup.with.bodyParams.type
  • Description: JumpCloud extension data on the managed entity: dsl.do.removeFromAllGroups.do.removeUserFromGroup.with.bodyParams.type.
  • Source: resource.dsl.do.removeFromAllGroups.do.removeUserFromGroup.with.bodyParams.type
  • Usage: workflow_delete
entity.data.dsl.do.removeFromAllGroups.do.removeUserFromGroup.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.removeFromAllGroups.do.removeUserFromGroup.with.operationId.
  • Source: resource.dsl.do.removeFromAllGroups.do.removeUserFromGroup.with.operationId
  • Usage: workflow_delete
entity.data.dsl.do.removeFromAllGroups.do.removeUserFromGroup.with.pathParams.group_id
  • Description: JumpCloud extension data on the managed entity: dsl.do.removeFromAllGroups.do.removeUserFromGroup.with.pathParams.group_id.
  • Source: resource.dsl.do.removeFromAllGroups.do.removeUserFromGroup.with.pathParams.group_id
  • Usage: workflow_delete
entity.data.dsl.do.removeFromAllGroups.do.removeUserFromGroup.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.removeFromAllGroups.do.removeUserFromGroup.with.version.
  • Source: resource.dsl.do.removeFromAllGroups.do.removeUserFromGroup.with.version
  • Usage: workflow_delete
entity.data.dsl.do.removeFromAllGroups.for.each
  • Description: JumpCloud extension data on the managed entity: dsl.do.removeFromAllGroups.for.each.
  • Source: resource.dsl.do.removeFromAllGroups.for.each
  • Usage: workflow_delete
entity.data.dsl.do.removeFromAllGroups.for.in
  • Description: JumpCloud extension data on the managed entity: dsl.do.removeFromAllGroups.for.in.
  • Source: resource.dsl.do.removeFromAllGroups.for.in
  • Usage: workflow_delete
entity.data.dsl.do.removeFromElevatedGroup.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.removeFromElevatedGroup.call.
  • Source: resource.dsl.do.removeFromElevatedGroup.call
  • Usage: workflow_delete
entity.data.dsl.do.removeFromElevatedGroup.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.removeFromElevatedGroup.then.
  • Source: resource.dsl.do.removeFromElevatedGroup.then
  • Usage: workflow_delete
entity.data.dsl.do.removeFromElevatedGroup.with.bodyParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.removeFromElevatedGroup.with.bodyParams.id.
  • Source: resource.dsl.do.removeFromElevatedGroup.with.bodyParams.id
  • Usage: workflow_delete
entity.data.dsl.do.removeFromElevatedGroup.with.bodyParams.op
  • Description: JumpCloud extension data on the managed entity: dsl.do.removeFromElevatedGroup.with.bodyParams.op.
  • Source: resource.dsl.do.removeFromElevatedGroup.with.bodyParams.op
  • Usage: workflow_delete
entity.data.dsl.do.removeFromElevatedGroup.with.bodyParams.type
  • Description: JumpCloud extension data on the managed entity: dsl.do.removeFromElevatedGroup.with.bodyParams.type.
  • Source: resource.dsl.do.removeFromElevatedGroup.with.bodyParams.type
  • Usage: workflow_delete
entity.data.dsl.do.removeFromElevatedGroup.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.removeFromElevatedGroup.with.operationId.
  • Source: resource.dsl.do.removeFromElevatedGroup.with.operationId
  • Usage: workflow_delete
entity.data.dsl.do.removeFromElevatedGroup.with.pathParams.group_id
  • Description: JumpCloud extension data on the managed entity: dsl.do.removeFromElevatedGroup.with.pathParams.group_id.
  • Source: resource.dsl.do.removeFromElevatedGroup.with.pathParams.group_id
  • Usage: workflow_delete
entity.data.dsl.do.removeFromElevatedGroup.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.removeFromElevatedGroup.with.version.
  • Source: resource.dsl.do.removeFromElevatedGroup.with.version
  • Usage: workflow_delete
entity.data.dsl.do.removeUserFromUserGroup.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.removeUserFromUserGroup.call.
  • Source: resource.dsl.do.removeUserFromUserGroup.call
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.removeUserFromUserGroup.metadata.displayLabels.user
  • Description: JumpCloud extension data on the managed entity: dsl.do.removeUserFromUserGroup.metadata.displayLabels.user.
  • Source: resource.dsl.do.removeUserFromUserGroup.metadata.displayLabels.user
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.removeUserFromUserGroup.metadata.displayLabels.userGroup
  • Description: JumpCloud extension data on the managed entity: dsl.do.removeUserFromUserGroup.metadata.displayLabels.userGroup.
  • Source: resource.dsl.do.removeUserFromUserGroup.metadata.displayLabels.userGroup
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.removeUserFromUserGroup.metadata.inputModes.user
  • Description: JumpCloud extension data on the managed entity: dsl.do.removeUserFromUserGroup.metadata.inputModes.user.
  • Source: resource.dsl.do.removeUserFromUserGroup.metadata.inputModes.user
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.removeUserFromUserGroup.metadata.inputModes.userGroup
  • Description: JumpCloud extension data on the managed entity: dsl.do.removeUserFromUserGroup.metadata.inputModes.userGroup.
  • Source: resource.dsl.do.removeUserFromUserGroup.metadata.inputModes.userGroup
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.removeUserFromUserGroup.with.bodyParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.removeUserFromUserGroup.with.bodyParams.id.
  • Source: resource.dsl.do.removeUserFromUserGroup.with.bodyParams.id
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.removeUserFromUserGroup.with.bodyParams.op
  • Description: JumpCloud extension data on the managed entity: dsl.do.removeUserFromUserGroup.with.bodyParams.op.
  • Source: resource.dsl.do.removeUserFromUserGroup.with.bodyParams.op
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.removeUserFromUserGroup.with.bodyParams.type
  • Description: JumpCloud extension data on the managed entity: dsl.do.removeUserFromUserGroup.with.bodyParams.type.
  • Source: resource.dsl.do.removeUserFromUserGroup.with.bodyParams.type
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.removeUserFromUserGroup.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.removeUserFromUserGroup.with.operationId.
  • Source: resource.dsl.do.removeUserFromUserGroup.with.operationId
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.removeUserFromUserGroup.with.pathParams.group_id
  • Description: JumpCloud extension data on the managed entity: dsl.do.removeUserFromUserGroup.with.pathParams.group_id.
  • Source: resource.dsl.do.removeUserFromUserGroup.with.pathParams.group_id
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.removeUserFromUserGroup.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.removeUserFromUserGroup.with.version.
  • Source: resource.dsl.do.removeUserFromUserGroup.with.version
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.reportsExportReport.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.reportsExportReport.call.
  • Source: resource.dsl.do.reportsExportReport.call
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.reportsExportReport.with.bodyParams.dsds
  • Description: JumpCloud extension data on the managed entity: dsl.do.reportsExportReport.with.bodyParams.dsds.
  • Source: resource.dsl.do.reportsExportReport.with.bodyParams.dsds
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.reportsExportReport.with.bodyParams.euyfe
  • Description: JumpCloud extension data on the managed entity: dsl.do.reportsExportReport.with.bodyParams.euyfe.
  • Source: resource.dsl.do.reportsExportReport.with.bodyParams.euyfe
  • Usage: workflow_create
entity.data.dsl.do.reportsExportReport.with.bodyParams.exportType
  • Description: JumpCloud extension data on the managed entity: dsl.do.reportsExportReport.with.bodyParams.exportType.
  • Source: resource.dsl.do.reportsExportReport.with.bodyParams.exportType
  • Usage: workflow_delete
entity.data.dsl.do.reportsExportReport.with.bodyParams.ff
  • Description: JumpCloud extension data on the managed entity: dsl.do.reportsExportReport.with.bodyParams.ff.
  • Source: resource.dsl.do.reportsExportReport.with.bodyParams.ff
  • Usage: workflow_create
entity.data.dsl.do.reportsExportReport.with.bodyParams.notifyByEmail
  • Description: JumpCloud extension data on the managed entity: dsl.do.reportsExportReport.with.bodyParams.notifyByEmail.
  • Source: resource.dsl.do.reportsExportReport.with.bodyParams.notifyByEmail
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.reportsExportReport.with.bodyParams.reportName
  • Description: JumpCloud extension data on the managed entity: dsl.do.reportsExportReport.with.bodyParams.reportName.
  • Source: resource.dsl.do.reportsExportReport.with.bodyParams.reportName
  • Usage: workflow_delete
entity.data.dsl.do.reportsExportReport.with.bodyParams.searchRequest.fields.include
  • Description: JumpCloud extension data on the managed entity: dsl.do.reportsExportReport.with.bodyParams.searchRequest.fields.include.
  • Source: resource.dsl.do.reportsExportReport.with.bodyParams.searchRequest.fields.include
  • Usage: workflow_delete
entity.data.dsl.do.reportsExportReport.with.bodyParams.searchRequest.filters
  • Description: JumpCloud extension data on the managed entity: dsl.do.reportsExportReport.with.bodyParams.searchRequest.filters.
  • Source: resource.dsl.do.reportsExportReport.with.bodyParams.searchRequest.filters
  • Usage: workflow_delete
entity.data.dsl.do.reportsExportReport.with.bodyParams.searchRequest.gh
  • Description: JumpCloud extension data on the managed entity: dsl.do.reportsExportReport.with.bodyParams.searchRequest.gh.
  • Source: resource.dsl.do.reportsExportReport.with.bodyParams.searchRequest.gh
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.reportsExportReport.with.bodyParams.searchRequest.sort.field
  • Description: JumpCloud extension data on the managed entity: dsl.do.reportsExportReport.with.bodyParams.searchRequest.sort.field.
  • Source: resource.dsl.do.reportsExportReport.with.bodyParams.searchRequest.sort.field
  • Usage: workflow_delete
entity.data.dsl.do.reportsExportReport.with.bodyParams.searchRequest.sort.order
  • Description: JumpCloud extension data on the managed entity: dsl.do.reportsExportReport.with.bodyParams.searchRequest.sort.order.
  • Source: resource.dsl.do.reportsExportReport.with.bodyParams.searchRequest.sort.order
  • Usage: workflow_delete
entity.data.dsl.do.reportsExportReport.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.reportsExportReport.with.operationId.
  • Source: resource.dsl.do.reportsExportReport.with.operationId
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.reportsExportReport.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.reportsExportReport.with.version.
  • Source: resource.dsl.do.reportsExportReport.with.version
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.reportsGetReportTemplate.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.reportsGetReportTemplate.call.
  • Source: resource.dsl.do.reportsGetReportTemplate.call
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.reportsGetReportTemplate.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.reportsGetReportTemplate.with.operationId.
  • Source: resource.dsl.do.reportsGetReportTemplate.with.operationId
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.reportsGetReportTemplate.with.pathParams.objectId
  • Description: JumpCloud extension data on the managed entity: dsl.do.reportsGetReportTemplate.with.pathParams.objectId.
  • Source: resource.dsl.do.reportsGetReportTemplate.with.pathParams.objectId
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.reportsGetReportTemplate.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.reportsGetReportTemplate.with.version.
  • Source: resource.dsl.do.reportsGetReportTemplate.with.version
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.restartDevice.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.restartDevice.call.
  • Source: resource.dsl.do.restartDevice.call
  • Usage: workflow_create, workflow_update
entity.data.dsl.do.restartDevice.metadata.displayLabels.device
  • Description: JumpCloud extension data on the managed entity: dsl.do.restartDevice.metadata.displayLabels.device.
  • Source: resource.dsl.do.restartDevice.metadata.displayLabels.device
  • Usage: workflow_create, workflow_update
entity.data.dsl.do.restartDevice.metadata.inputModes.device
  • Description: JumpCloud extension data on the managed entity: dsl.do.restartDevice.metadata.inputModes.device.
  • Source: resource.dsl.do.restartDevice.metadata.inputModes.device
  • Usage: workflow_create, workflow_update
entity.data.dsl.do.restartDevice.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.restartDevice.with.operationId.
  • Source: resource.dsl.do.restartDevice.with.operationId
  • Usage: workflow_create, workflow_update
entity.data.dsl.do.restartDevice.with.pathParams.system_id
  • Description: JumpCloud extension data on the managed entity: dsl.do.restartDevice.with.pathParams.system_id.
  • Source: resource.dsl.do.restartDevice.with.pathParams.system_id
  • Usage: workflow_create, workflow_update
entity.data.dsl.do.restartDevice.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.restartDevice.with.version.
  • Source: resource.dsl.do.restartDevice.with.version
  • Usage: workflow_create, workflow_update
entity.data.dsl.do.routeAssetUpdate.switch.default.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.routeAssetUpdate.switch.default.then.
  • Source: resource.dsl.do.routeAssetUpdate.switch.default.then
  • Usage: workflow_create
entity.data.dsl.do.routeAssetUpdate.switch.preserveTypeIfPresent.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.routeAssetUpdate.switch.preserveTypeIfPresent.then.
  • Source: resource.dsl.do.routeAssetUpdate.switch.preserveTypeIfPresent.then
  • Usage: workflow_create
entity.data.dsl.do.routeAssetUpdate.switch.preserveTypeIfPresent.when
  • Description: JumpCloud extension data on the managed entity: dsl.do.routeAssetUpdate.switch.preserveTypeIfPresent.when.
  • Source: resource.dsl.do.routeAssetUpdate.switch.preserveTypeIfPresent.when
  • Usage: workflow_create
entity.data.dsl.do.routeByOsFamily.if
  • Description: JumpCloud extension data on the managed entity: dsl.do.routeByOsFamily.if.
  • Source: resource.dsl.do.routeByOsFamily.if
  • Usage: workflow_create
entity.data.dsl.do.routeByOsFamily.switch.default.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.routeByOsFamily.switch.default.then.
  • Source: resource.dsl.do.routeByOsFamily.switch.default.then
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.routeByOsFamily.switch.isMac.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.routeByOsFamily.switch.isMac.then.
  • Source: resource.dsl.do.routeByOsFamily.switch.isMac.then
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.routeByOsFamily.switch.isMac.when
  • Description: JumpCloud extension data on the managed entity: dsl.do.routeByOsFamily.switch.isMac.when.
  • Source: resource.dsl.do.routeByOsFamily.switch.isMac.when
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.routeByOsFamily.switch.isOtherOs.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.routeByOsFamily.switch.isOtherOs.then.
  • Source: resource.dsl.do.routeByOsFamily.switch.isOtherOs.then
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.routeByOsFamily.switch.isOtherOs.when
  • Description: JumpCloud extension data on the managed entity: dsl.do.routeByOsFamily.switch.isOtherOs.when.
  • Source: resource.dsl.do.routeByOsFamily.switch.isOtherOs.when
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.routeByTitle.switch.default.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.routeByTitle.switch.default.then.
  • Source: resource.dsl.do.routeByTitle.switch.default.then
  • Usage: workflow_delete
entity.data.dsl.do.routeByTitle.switch.demotionTitle.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.routeByTitle.switch.demotionTitle.then.
  • Source: resource.dsl.do.routeByTitle.switch.demotionTitle.then
  • Usage: workflow_delete
entity.data.dsl.do.routeByTitle.switch.demotionTitle.when
  • Description: JumpCloud extension data on the managed entity: dsl.do.routeByTitle.switch.demotionTitle.when.
  • Source: resource.dsl.do.routeByTitle.switch.demotionTitle.when
  • Usage: workflow_delete
entity.data.dsl.do.routeByTitle.switch.elevatedTitle.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.routeByTitle.switch.elevatedTitle.then.
  • Source: resource.dsl.do.routeByTitle.switch.elevatedTitle.then
  • Usage: workflow_delete
entity.data.dsl.do.routeByTitle.switch.elevatedTitle.when
  • Description: JumpCloud extension data on the managed entity: dsl.do.routeByTitle.switch.elevatedTitle.when.
  • Source: resource.dsl.do.routeByTitle.switch.elevatedTitle.when
  • Usage: workflow_delete
entity.data.dsl.do.routeByUserState.switch.activatedCase.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.routeByUserState.switch.activatedCase.then.
  • Source: resource.dsl.do.routeByUserState.switch.activatedCase.then
  • Usage: workflow_create
entity.data.dsl.do.routeByUserState.switch.activatedCase.when
  • Description: JumpCloud extension data on the managed entity: dsl.do.routeByUserState.switch.activatedCase.when.
  • Source: resource.dsl.do.routeByUserState.switch.activatedCase.when
  • Usage: workflow_create
entity.data.dsl.do.routeByUserState.switch.default.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.routeByUserState.switch.default.then.
  • Source: resource.dsl.do.routeByUserState.switch.default.then
  • Usage: workflow_create
entity.data.dsl.do.routeByUserState.switch.suspendedCase.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.routeByUserState.switch.suspendedCase.then.
  • Source: resource.dsl.do.routeByUserState.switch.suspendedCase.then
  • Usage: workflow_create
entity.data.dsl.do.routeByUserState.switch.suspendedCase.when
  • Description: JumpCloud extension data on the managed entity: dsl.do.routeByUserState.switch.suspendedCase.when.
  • Source: resource.dsl.do.routeByUserState.switch.suspendedCase.when
  • Usage: workflow_create
entity.data.dsl.do.routeHasAnyResults.switch.default.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.routeHasAnyResults.switch.default.then.
  • Source: resource.dsl.do.routeHasAnyResults.switch.default.then
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.routeHasAnyResults.switch.hasResults.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.routeHasAnyResults.switch.hasResults.then.
  • Source: resource.dsl.do.routeHasAnyResults.switch.hasResults.then
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.routeHasAnyResults.switch.hasResults.when
  • Description: JumpCloud extension data on the managed entity: dsl.do.routeHasAnyResults.switch.hasResults.when.
  • Source: resource.dsl.do.routeHasAnyResults.switch.hasResults.when
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.runCommandOnDevice.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.runCommandOnDevice.call.
  • Source: resource.dsl.do.runCommandOnDevice.call
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.runCommandOnDevice.metadata.displayLabels.command
  • Description: JumpCloud extension data on the managed entity: dsl.do.runCommandOnDevice.metadata.displayLabels.command.
  • Source: resource.dsl.do.runCommandOnDevice.metadata.displayLabels.command
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.runCommandOnDevice.metadata.displayLabels.devices
  • Description: JumpCloud extension data on the managed entity: dsl.do.runCommandOnDevice.metadata.displayLabels.devices.
  • Source: resource.dsl.do.runCommandOnDevice.metadata.displayLabels.devices
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.runCommandOnDevice.metadata.inputModes.command
  • Description: JumpCloud extension data on the managed entity: dsl.do.runCommandOnDevice.metadata.inputModes.command.
  • Source: resource.dsl.do.runCommandOnDevice.metadata.inputModes.command
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.runCommandOnDevice.metadata.inputModes.devices
  • Description: JumpCloud extension data on the managed entity: dsl.do.runCommandOnDevice.metadata.inputModes.devices.
  • Source: resource.dsl.do.runCommandOnDevice.metadata.inputModes.devices
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.runCommandOnDevice.with.bodyParams._id
  • Description: JumpCloud extension data on the managed entity: dsl.do.runCommandOnDevice.with.bodyParams._id.
  • Source: resource.dsl.do.runCommandOnDevice.with.bodyParams._id
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.runCommandOnDevice.with.bodyParams.systemIds
  • Description: JumpCloud extension data on the managed entity: dsl.do.runCommandOnDevice.with.bodyParams.systemIds.
  • Source: resource.dsl.do.runCommandOnDevice.with.bodyParams.systemIds
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.runCommandOnDevice.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.runCommandOnDevice.with.operationId.
  • Source: resource.dsl.do.runCommandOnDevice.with.operationId
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.runCommandOnDevice.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.runCommandOnDevice.with.version.
  • Source: resource.dsl.do.runCommandOnDevice.with.version
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.runCommandOnDevice2.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.runCommandOnDevice2.call.
  • Source: resource.dsl.do.runCommandOnDevice2.call
  • Usage: workflow_delete
entity.data.dsl.do.runCommandOnDevice2.metadata.displayLabels.command
  • Description: JumpCloud extension data on the managed entity: dsl.do.runCommandOnDevice2.metadata.displayLabels.command.
  • Source: resource.dsl.do.runCommandOnDevice2.metadata.displayLabels.command
  • Usage: workflow_delete
entity.data.dsl.do.runCommandOnDevice2.metadata.displayLabels.devices
  • Description: JumpCloud extension data on the managed entity: dsl.do.runCommandOnDevice2.metadata.displayLabels.devices.
  • Source: resource.dsl.do.runCommandOnDevice2.metadata.displayLabels.devices
  • Usage: workflow_delete
entity.data.dsl.do.runCommandOnDevice2.metadata.inputModes.command
  • Description: JumpCloud extension data on the managed entity: dsl.do.runCommandOnDevice2.metadata.inputModes.command.
  • Source: resource.dsl.do.runCommandOnDevice2.metadata.inputModes.command
  • Usage: workflow_delete
entity.data.dsl.do.runCommandOnDevice2.metadata.inputModes.devices
  • Description: JumpCloud extension data on the managed entity: dsl.do.runCommandOnDevice2.metadata.inputModes.devices.
  • Source: resource.dsl.do.runCommandOnDevice2.metadata.inputModes.devices
  • Usage: workflow_delete
entity.data.dsl.do.runCommandOnDevice2.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.runCommandOnDevice2.then.
  • Source: resource.dsl.do.runCommandOnDevice2.then
  • Usage: workflow_delete
entity.data.dsl.do.runCommandOnDevice2.with.bodyParams._id
  • Description: JumpCloud extension data on the managed entity: dsl.do.runCommandOnDevice2.with.bodyParams._id.
  • Source: resource.dsl.do.runCommandOnDevice2.with.bodyParams._id
  • Usage: workflow_delete
entity.data.dsl.do.runCommandOnDevice2.with.bodyParams.systemIds
  • Description: JumpCloud extension data on the managed entity: dsl.do.runCommandOnDevice2.with.bodyParams.systemIds.
  • Source: resource.dsl.do.runCommandOnDevice2.with.bodyParams.systemIds
  • Usage: workflow_delete
entity.data.dsl.do.runCommandOnDevice2.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.runCommandOnDevice2.with.operationId.
  • Source: resource.dsl.do.runCommandOnDevice2.with.operationId
  • Usage: workflow_delete
entity.data.dsl.do.runCommandOnDevice2.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.runCommandOnDevice2.with.version.
  • Source: resource.dsl.do.runCommandOnDevice2.with.version
  • Usage: workflow_delete
entity.data.dsl.do.runCommandOnPrimaryDevice.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.runCommandOnPrimaryDevice.call.
  • Source: resource.dsl.do.runCommandOnPrimaryDevice.call
  • Usage: workflow_create, workflow_update
entity.data.dsl.do.runCommandOnPrimaryDevice.if
  • Description: JumpCloud extension data on the managed entity: dsl.do.runCommandOnPrimaryDevice.if.
  • Source: resource.dsl.do.runCommandOnPrimaryDevice.if
  • Usage: workflow_create, workflow_update
entity.data.dsl.do.runCommandOnPrimaryDevice.with.bodyParams._id
  • Description: JumpCloud extension data on the managed entity: dsl.do.runCommandOnPrimaryDevice.with.bodyParams._id.
  • Source: resource.dsl.do.runCommandOnPrimaryDevice.with.bodyParams._id
  • Usage: workflow_create, workflow_update
entity.data.dsl.do.runCommandOnPrimaryDevice.with.bodyParams.systemIds
  • Description: JumpCloud extension data on the managed entity: dsl.do.runCommandOnPrimaryDevice.with.bodyParams.systemIds.
  • Source: resource.dsl.do.runCommandOnPrimaryDevice.with.bodyParams.systemIds
  • Usage: workflow_create, workflow_update
entity.data.dsl.do.runCommandOnPrimaryDevice.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.runCommandOnPrimaryDevice.with.operationId.
  • Source: resource.dsl.do.runCommandOnPrimaryDevice.with.operationId
  • Usage: workflow_create, workflow_update
entity.data.dsl.do.runCommandOnPrimaryDevice.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.runCommandOnPrimaryDevice.with.version.
  • Source: resource.dsl.do.runCommandOnPrimaryDevice.with.version
  • Usage: workflow_create, workflow_update
entity.data.dsl.do.searchSystems.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.searchSystems.call.
  • Source: resource.dsl.do.searchSystems.call
  • Usage: workflow_update
entity.data.dsl.do.searchSystems.with.bodyParams.filter.and.primarySystemUser._id
  • Description: JumpCloud extension data on the managed entity: dsl.do.searchSystems.with.bodyParams.filter.and.primarySystemUser._id.
  • Source: resource.dsl.do.searchSystems.with.bodyParams.filter.and.primarySystemUser._id
  • Usage: workflow_update
entity.data.dsl.do.searchSystems.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.searchSystems.with.operationId.
  • Source: resource.dsl.do.searchSystems.with.operationId
  • Usage: workflow_update
entity.data.dsl.do.searchSystems.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.searchSystems.with.version.
  • Source: resource.dsl.do.searchSystems.with.version
  • Usage: workflow_update
entity.data.dsl.do.searchSystemsPost.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.searchSystemsPost.call.
  • Source: resource.dsl.do.searchSystemsPost.call
  • Usage: workflow_delete
entity.data.dsl.do.searchSystemsPost.with.bodyParams.filter
  • Description: JumpCloud extension data on the managed entity: dsl.do.searchSystemsPost.with.bodyParams.filter.
  • Source: resource.dsl.do.searchSystemsPost.with.bodyParams.filter
  • Usage: workflow_delete
entity.data.dsl.do.searchSystemsPost.with.bodyParams.searchFilter
  • Description: JumpCloud extension data on the managed entity: dsl.do.searchSystemsPost.with.bodyParams.searchFilter.
  • Source: resource.dsl.do.searchSystemsPost.with.bodyParams.searchFilter
  • Usage: workflow_delete
entity.data.dsl.do.searchSystemsPost.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.searchSystemsPost.with.operationId.
  • Source: resource.dsl.do.searchSystemsPost.with.operationId
  • Usage: workflow_delete
entity.data.dsl.do.searchSystemsPost.with.queryParams.limit
  • Description: JumpCloud extension data on the managed entity: dsl.do.searchSystemsPost.with.queryParams.limit.
  • Source: resource.dsl.do.searchSystemsPost.with.queryParams.limit
  • Usage: workflow_delete
entity.data.dsl.do.searchSystemsPost.with.queryParams.skip
  • Description: JumpCloud extension data on the managed entity: dsl.do.searchSystemsPost.with.queryParams.skip.
  • Source: resource.dsl.do.searchSystemsPost.with.queryParams.skip
  • Usage: workflow_delete
entity.data.dsl.do.searchSystemsPost.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.searchSystemsPost.with.version.
  • Source: resource.dsl.do.searchSystemsPost.with.version
  • Usage: workflow_delete
entity.data.dsl.do.search_matching_user.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.search_matching_user.call.
  • Source: resource.dsl.do.search_matching_user.call
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.search_matching_user.with.bodyParams.filter.and.username
  • Description: JumpCloud extension data on the managed entity: dsl.do.search_matching_user.with.bodyParams.filter.and.username.
  • Source: resource.dsl.do.search_matching_user.with.bodyParams.filter.and.username
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.search_matching_user.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.search_matching_user.with.operationId.
  • Source: resource.dsl.do.search_matching_user.with.operationId
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.search_matching_user.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.search_matching_user.with.version.
  • Source: resource.dsl.do.search_matching_user.with.version
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.sendEmailAddresses.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.sendEmailAddresses.call.
  • Source: resource.dsl.do.sendEmailAddresses.call
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.sendEmailAddresses.with.message.body
  • Description: JumpCloud extension data on the managed entity: dsl.do.sendEmailAddresses.with.message.body.
  • Source: resource.dsl.do.sendEmailAddresses.with.message.body
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.sendEmailAddresses.with.message.subject
  • Description: JumpCloud extension data on the managed entity: dsl.do.sendEmailAddresses.with.message.subject.
  • Source: resource.dsl.do.sendEmailAddresses.with.message.subject
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.sendEmailAddresses.with.recipients.to_addresses
  • Description: JumpCloud extension data on the managed entity: dsl.do.sendEmailAddresses.with.recipients.to_addresses.
  • Source: resource.dsl.do.sendEmailAddresses.with.recipients.to_addresses
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.sendEmailChannels.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.sendEmailChannels.call.
  • Source: resource.dsl.do.sendEmailChannels.call
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.sendEmailChannels.with.message.body
  • Description: JumpCloud extension data on the managed entity: dsl.do.sendEmailChannels.with.message.body.
  • Source: resource.dsl.do.sendEmailChannels.with.message.body
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.sendEmailChannels.with.message.subject
  • Description: JumpCloud extension data on the managed entity: dsl.do.sendEmailChannels.with.message.subject.
  • Source: resource.dsl.do.sendEmailChannels.with.message.subject
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.sendEmailChannels.with.recipients.channel_object_ids
  • Description: JumpCloud extension data on the managed entity: dsl.do.sendEmailChannels.with.recipients.channel_object_ids.
  • Source: resource.dsl.do.sendEmailChannels.with.recipients.channel_object_ids
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.sendSummaryEmail.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.sendSummaryEmail.call.
  • Source: resource.dsl.do.sendSummaryEmail.call
  • Usage: workflow_create
entity.data.dsl.do.sendSummaryEmail.with.message.body
  • Description: JumpCloud extension data on the managed entity: dsl.do.sendSummaryEmail.with.message.body.
  • Source: resource.dsl.do.sendSummaryEmail.with.message.body
  • Usage: workflow_create
entity.data.dsl.do.sendSummaryEmail.with.message.subject
  • Description: JumpCloud extension data on the managed entity: dsl.do.sendSummaryEmail.with.message.subject.
  • Source: resource.dsl.do.sendSummaryEmail.with.message.subject
  • Usage: workflow_create
entity.data.dsl.do.sendSummaryEmail.with.recipients.to_addresses
  • Description: JumpCloud extension data on the managed entity: dsl.do.sendSummaryEmail.with.recipients.to_addresses.
  • Source: resource.dsl.do.sendSummaryEmail.with.recipients.to_addresses
  • Usage: workflow_create
entity.data.dsl.do.stageUsers.do.addToStagingGroup.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.stageUsers.do.addToStagingGroup.call.
  • Source: resource.dsl.do.stageUsers.do.addToStagingGroup.call
  • Usage: workflow_delete
entity.data.dsl.do.stageUsers.do.addToStagingGroup.with.bodyParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.stageUsers.do.addToStagingGroup.with.bodyParams.id.
  • Source: resource.dsl.do.stageUsers.do.addToStagingGroup.with.bodyParams.id
  • Usage: workflow_delete
entity.data.dsl.do.stageUsers.do.addToStagingGroup.with.bodyParams.op
  • Description: JumpCloud extension data on the managed entity: dsl.do.stageUsers.do.addToStagingGroup.with.bodyParams.op.
  • Source: resource.dsl.do.stageUsers.do.addToStagingGroup.with.bodyParams.op
  • Usage: workflow_delete
entity.data.dsl.do.stageUsers.do.addToStagingGroup.with.bodyParams.type
  • Description: JumpCloud extension data on the managed entity: dsl.do.stageUsers.do.addToStagingGroup.with.bodyParams.type.
  • Source: resource.dsl.do.stageUsers.do.addToStagingGroup.with.bodyParams.type
  • Usage: workflow_delete
entity.data.dsl.do.stageUsers.do.addToStagingGroup.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.stageUsers.do.addToStagingGroup.with.operationId.
  • Source: resource.dsl.do.stageUsers.do.addToStagingGroup.with.operationId
  • Usage: workflow_delete
entity.data.dsl.do.stageUsers.do.addToStagingGroup.with.pathParams.group_id
  • Description: JumpCloud extension data on the managed entity: dsl.do.stageUsers.do.addToStagingGroup.with.pathParams.group_id.
  • Source: resource.dsl.do.stageUsers.do.addToStagingGroup.with.pathParams.group_id
  • Usage: workflow_delete
entity.data.dsl.do.stageUsers.do.addToStagingGroup.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.stageUsers.do.addToStagingGroup.with.version.
  • Source: resource.dsl.do.stageUsers.do.addToStagingGroup.with.version
  • Usage: workflow_delete
entity.data.dsl.do.stageUsers.do.getManagerDetails.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.stageUsers.do.getManagerDetails.call.
  • Source: resource.dsl.do.stageUsers.do.getManagerDetails.call
  • Usage: workflow_delete
entity.data.dsl.do.stageUsers.do.getManagerDetails.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.stageUsers.do.getManagerDetails.with.operationId.
  • Source: resource.dsl.do.stageUsers.do.getManagerDetails.with.operationId
  • Usage: workflow_delete
entity.data.dsl.do.stageUsers.do.getManagerDetails.with.pathParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.stageUsers.do.getManagerDetails.with.pathParams.id.
  • Source: resource.dsl.do.stageUsers.do.getManagerDetails.with.pathParams.id
  • Usage: workflow_delete
entity.data.dsl.do.stageUsers.do.getManagerDetails.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.stageUsers.do.getManagerDetails.with.version.
  • Source: resource.dsl.do.stageUsers.do.getManagerDetails.with.version
  • Usage: workflow_delete
entity.data.dsl.do.stageUsers.do.getUserFullDetails.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.stageUsers.do.getUserFullDetails.call.
  • Source: resource.dsl.do.stageUsers.do.getUserFullDetails.call
  • Usage: workflow_delete
entity.data.dsl.do.stageUsers.do.getUserFullDetails.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.stageUsers.do.getUserFullDetails.with.operationId.
  • Source: resource.dsl.do.stageUsers.do.getUserFullDetails.with.operationId
  • Usage: workflow_delete
entity.data.dsl.do.stageUsers.do.getUserFullDetails.with.pathParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.stageUsers.do.getUserFullDetails.with.pathParams.id.
  • Source: resource.dsl.do.stageUsers.do.getUserFullDetails.with.pathParams.id
  • Usage: workflow_delete
entity.data.dsl.do.stageUsers.do.getUserFullDetails.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.stageUsers.do.getUserFullDetails.with.version.
  • Source: resource.dsl.do.stageUsers.do.getUserFullDetails.with.version
  • Usage: workflow_delete
entity.data.dsl.do.stageUsers.do.notifyManager.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.stageUsers.do.notifyManager.call.
  • Source: resource.dsl.do.stageUsers.do.notifyManager.call
  • Usage: workflow_delete
entity.data.dsl.do.stageUsers.do.notifyManager.with.message.body
  • Description: JumpCloud extension data on the managed entity: dsl.do.stageUsers.do.notifyManager.with.message.body.
  • Source: resource.dsl.do.stageUsers.do.notifyManager.with.message.body
  • Usage: workflow_delete
entity.data.dsl.do.stageUsers.do.notifyManager.with.message.subject
  • Description: JumpCloud extension data on the managed entity: dsl.do.stageUsers.do.notifyManager.with.message.subject.
  • Source: resource.dsl.do.stageUsers.do.notifyManager.with.message.subject
  • Usage: workflow_delete
entity.data.dsl.do.stageUsers.do.notifyManager.with.recipients.to_addresses
  • Description: JumpCloud extension data on the managed entity: dsl.do.stageUsers.do.notifyManager.with.recipients.to_addresses.
  • Source: resource.dsl.do.stageUsers.do.notifyManager.with.recipients.to_addresses
  • Usage: workflow_delete
entity.data.dsl.do.stageUsers.for.each
  • Description: JumpCloud extension data on the managed entity: dsl.do.stageUsers.for.each.
  • Source: resource.dsl.do.stageUsers.for.each
  • Usage: workflow_delete
entity.data.dsl.do.stageUsers.for.in
  • Description: JumpCloud extension data on the managed entity: dsl.do.stageUsers.for.in.
  • Source: resource.dsl.do.stageUsers.for.in
  • Usage: workflow_delete
entity.data.dsl.do.stageUsers.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.stageUsers.then.
  • Source: resource.dsl.do.stageUsers.then
  • Usage: workflow_delete
entity.data.dsl.do.stripDelegation.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.stripDelegation.call.
  • Source: resource.dsl.do.stripDelegation.call
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.stripDelegation.with.bodyParams.externally_managed
  • Description: JumpCloud extension data on the managed entity: dsl.do.stripDelegation.with.bodyParams.externally_managed.
  • Source: resource.dsl.do.stripDelegation.with.bodyParams.externally_managed
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.stripDelegation.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.stripDelegation.with.operationId.
  • Source: resource.dsl.do.stripDelegation.with.operationId
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.stripDelegation.with.pathParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.stripDelegation.with.pathParams.id.
  • Source: resource.dsl.do.stripDelegation.with.pathParams.id
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.stripDelegation.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.stripDelegation.with.version.
  • Source: resource.dsl.do.stripDelegation.with.version
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.summary.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.summary.call.
  • Source: resource.dsl.do.summary.call
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.summary.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.summary.then.
  • Source: resource.dsl.do.summary.then
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.summary.with.message.body
  • Description: JumpCloud extension data on the managed entity: dsl.do.summary.with.message.body.
  • Source: resource.dsl.do.summary.with.message.body
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.summary.with.message.subject
  • Description: JumpCloud extension data on the managed entity: dsl.do.summary.with.message.subject.
  • Source: resource.dsl.do.summary.with.message.subject
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.summary.with.recipients.channel_object_ids
  • Description: JumpCloud extension data on the managed entity: dsl.do.summary.with.recipients.channel_object_ids.
  • Source: resource.dsl.do.summary.with.recipients.channel_object_ids
  • Usage: workflow_delete, workflow_update
entity.data.dsl.do.suspendAccount.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.suspendAccount.call.
  • Source: resource.dsl.do.suspendAccount.call
  • Usage: workflow_delete
entity.data.dsl.do.suspendAccount.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.suspendAccount.with.operationId.
  • Source: resource.dsl.do.suspendAccount.with.operationId
  • Usage: workflow_delete
entity.data.dsl.do.suspendAccount.with.pathParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.suspendAccount.with.pathParams.id.
  • Source: resource.dsl.do.suspendAccount.with.pathParams.id
  • Usage: workflow_delete
entity.data.dsl.do.suspendAccount.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.suspendAccount.with.version.
  • Source: resource.dsl.do.suspendAccount.with.version
  • Usage: workflow_delete
entity.data.dsl.do.suspendUser.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.suspendUser.call.
  • Source: resource.dsl.do.suspendUser.call
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.suspendUser.metadata.displayLabels.user
  • Description: JumpCloud extension data on the managed entity: dsl.do.suspendUser.metadata.displayLabels.user.
  • Source: resource.dsl.do.suspendUser.metadata.displayLabels.user
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.suspendUser.metadata.inputModes.user
  • Description: JumpCloud extension data on the managed entity: dsl.do.suspendUser.metadata.inputModes.user.
  • Source: resource.dsl.do.suspendUser.metadata.inputModes.user
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.suspendUser.with.bodyParams.suspended
  • Description: JumpCloud extension data on the managed entity: dsl.do.suspendUser.with.bodyParams.suspended.
  • Source: resource.dsl.do.suspendUser.with.bodyParams.suspended
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.suspendUser.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.suspendUser.with.operationId.
  • Source: resource.dsl.do.suspendUser.with.operationId
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.suspendUser.with.pathParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.suspendUser.with.pathParams.id.
  • Source: resource.dsl.do.suspendUser.with.pathParams.id
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.suspendUser.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.suspendUser.with.version.
  • Source: resource.dsl.do.suspendUser.with.version
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.systemsGet.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.systemsGet.call.
  • Source: resource.dsl.do.systemsGet.call
  • Usage: workflow_delete
entity.data.dsl.do.systemsGet.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.systemsGet.with.operationId.
  • Source: resource.dsl.do.systemsGet.with.operationId
  • Usage: workflow_delete
entity.data.dsl.do.systemsGet.with.pathParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.systemsGet.with.pathParams.id.
  • Source: resource.dsl.do.systemsGet.with.pathParams.id
  • Usage: workflow_delete
entity.data.dsl.do.systemsGet.with.queryParams.fields
  • Description: JumpCloud extension data on the managed entity: dsl.do.systemsGet.with.queryParams.fields.
  • Source: resource.dsl.do.systemsGet.with.queryParams.fields
  • Usage: workflow_delete
entity.data.dsl.do.systemsGet.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.systemsGet.with.version.
  • Source: resource.dsl.do.systemsGet.with.version
  • Usage: workflow_delete
entity.data.dsl.do.systemusersGet.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.systemusersGet.call.
  • Source: resource.dsl.do.systemusersGet.call
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.systemusersGet.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.systemusersGet.with.operationId.
  • Source: resource.dsl.do.systemusersGet.with.operationId
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.systemusersGet.with.pathParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.systemusersGet.with.pathParams.id.
  • Source: resource.dsl.do.systemusersGet.with.pathParams.id
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.systemusersGet.with.queryParams.fields
  • Description: JumpCloud extension data on the managed entity: dsl.do.systemusersGet.with.queryParams.fields.
  • Source: resource.dsl.do.systemusersGet.with.queryParams.fields
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.systemusersGet.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.systemusersGet.with.version.
  • Source: resource.dsl.do.systemusersGet.with.version
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.systemusersList.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.systemusersList.call.
  • Source: resource.dsl.do.systemusersList.call
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.systemusersList.with.extract
  • Description: JumpCloud extension data on the managed entity: dsl.do.systemusersList.with.extract.
  • Source: resource.dsl.do.systemusersList.with.extract
  • Usage: workflow_delete
entity.data.dsl.do.systemusersList.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.systemusersList.with.operationId.
  • Source: resource.dsl.do.systemusersList.with.operationId
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.systemusersList.with.pagination.until
  • Description: JumpCloud extension data on the managed entity: dsl.do.systemusersList.with.pagination.until.
  • Source: resource.dsl.do.systemusersList.with.pagination.until
  • Usage: workflow_delete
entity.data.dsl.do.systemusersList.with.pagination.update.in
  • Description: JumpCloud extension data on the managed entity: dsl.do.systemusersList.with.pagination.update.in.
  • Source: resource.dsl.do.systemusersList.with.pagination.update.in
  • Usage: workflow_delete
entity.data.dsl.do.systemusersList.with.pagination.update.key
  • Description: JumpCloud extension data on the managed entity: dsl.do.systemusersList.with.pagination.update.key.
  • Source: resource.dsl.do.systemusersList.with.pagination.update.key
  • Usage: workflow_delete
entity.data.dsl.do.systemusersList.with.pagination.update.value
  • Description: JumpCloud extension data on the managed entity: dsl.do.systemusersList.with.pagination.update.value.
  • Source: resource.dsl.do.systemusersList.with.pagination.update.value
  • Usage: workflow_delete
entity.data.dsl.do.systemusersList.with.queryParams.limit
  • Description: JumpCloud extension data on the managed entity: dsl.do.systemusersList.with.queryParams.limit.
  • Source: resource.dsl.do.systemusersList.with.queryParams.limit
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.systemusersList.with.queryParams.skip
  • Description: JumpCloud extension data on the managed entity: dsl.do.systemusersList.with.queryParams.skip.
  • Source: resource.dsl.do.systemusersList.with.queryParams.skip
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.systemusersList.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.systemusersList.with.version.
  • Source: resource.dsl.do.systemusersList.with.version
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.systemusersPut.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.systemusersPut.call.
  • Source: resource.dsl.do.systemusersPut.call
  • Usage: workflow_update
entity.data.dsl.do.systemusersPut.with.bodyParams.attributes
  • Description: JumpCloud extension data on the managed entity: dsl.do.systemusersPut.with.bodyParams.attributes.
  • Source: resource.dsl.do.systemusersPut.with.bodyParams.attributes
  • Usage: workflow_update
entity.data.dsl.do.systemusersPut.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.systemusersPut.with.operationId.
  • Source: resource.dsl.do.systemusersPut.with.operationId
  • Usage: workflow_update
entity.data.dsl.do.systemusersPut.with.pathParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.systemusersPut.with.pathParams.id.
  • Source: resource.dsl.do.systemusersPut.with.pathParams.id
  • Usage: workflow_update
entity.data.dsl.do.systemusersPut.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.systemusersPut.with.version.
  • Source: resource.dsl.do.systemusersPut.with.version
  • Usage: workflow_update
entity.data.dsl.do.systemusers_get.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.systemusers_get.call.
  • Source: resource.dsl.do.systemusers_get.call
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.systemusers_get.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.systemusers_get.with.operationId.
  • Source: resource.dsl.do.systemusers_get.with.operationId
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.systemusers_get.with.pathParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.systemusers_get.with.pathParams.id.
  • Source: resource.dsl.do.systemusers_get.with.pathParams.id
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.systemusers_get.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.systemusers_get.with.version.
  • Source: resource.dsl.do.systemusers_get.with.version
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.updateAssetStatus.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.updateAssetStatus.call.
  • Source: resource.dsl.do.updateAssetStatus.call
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.updateAssetStatus.if
  • Description: JumpCloud extension data on the managed entity: dsl.do.updateAssetStatus.if.
  • Source: resource.dsl.do.updateAssetStatus.if
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.updateAssetStatus.metadata.displayLabels.assetFields
  • Description: JumpCloud extension data on the managed entity: dsl.do.updateAssetStatus.metadata.displayLabels.assetFields.
  • Source: resource.dsl.do.updateAssetStatus.metadata.displayLabels.assetFields
  • Usage: workflow_create
entity.data.dsl.do.updateAssetStatus.metadata.displayLabels.assetId
  • Description: JumpCloud extension data on the managed entity: dsl.do.updateAssetStatus.metadata.displayLabels.assetId.
  • Source: resource.dsl.do.updateAssetStatus.metadata.displayLabels.assetId
  • Usage: workflow_create
entity.data.dsl.do.updateAssetStatus.metadata.inputModes.assetFields
  • Description: JumpCloud extension data on the managed entity: dsl.do.updateAssetStatus.metadata.inputModes.assetFields.
  • Source: resource.dsl.do.updateAssetStatus.metadata.inputModes.assetFields
  • Usage: workflow_create
entity.data.dsl.do.updateAssetStatus.metadata.inputModes.assetId
  • Description: JumpCloud extension data on the managed entity: dsl.do.updateAssetStatus.metadata.inputModes.assetId.
  • Source: resource.dsl.do.updateAssetStatus.metadata.inputModes.assetId
  • Usage: workflow_create
entity.data.dsl.do.updateAssetStatus.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.updateAssetStatus.then.
  • Source: resource.dsl.do.updateAssetStatus.then
  • Usage: workflow_delete
entity.data.dsl.do.updateAssetStatus.with.bodyParams.fields.Name
  • Description: JumpCloud extension data on the managed entity: dsl.do.updateAssetStatus.with.bodyParams.fields.Name.
  • Source: resource.dsl.do.updateAssetStatus.with.bodyParams.fields.Name
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.updateAssetStatus.with.bodyParams.fields.Status.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.updateAssetStatus.with.bodyParams.fields.Status.id.
  • Source: resource.dsl.do.updateAssetStatus.with.bodyParams.fields.Status.id
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.updateAssetStatus.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.updateAssetStatus.with.operationId.
  • Source: resource.dsl.do.updateAssetStatus.with.operationId
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.updateAssetStatus.with.pathParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.updateAssetStatus.with.pathParams.id.
  • Source: resource.dsl.do.updateAssetStatus.with.pathParams.id
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.updateAssetStatus.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.updateAssetStatus.with.version.
  • Source: resource.dsl.do.updateAssetStatus.with.version
  • Usage: workflow_create, workflow_delete
entity.data.dsl.do.updateAssetStatusWithType.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.updateAssetStatusWithType.call.
  • Source: resource.dsl.do.updateAssetStatusWithType.call
  • Usage: workflow_create
entity.data.dsl.do.updateAssetStatusWithType.with.bodyParams.fields.Name
  • Description: JumpCloud extension data on the managed entity: dsl.do.updateAssetStatusWithType.with.bodyParams.fields.Name.
  • Source: resource.dsl.do.updateAssetStatusWithType.with.bodyParams.fields.Name
  • Usage: workflow_create
entity.data.dsl.do.updateAssetStatusWithType.with.bodyParams.fields.Status.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.updateAssetStatusWithType.with.bodyParams.fields.Status.id.
  • Source: resource.dsl.do.updateAssetStatusWithType.with.bodyParams.fields.Status.id
  • Usage: workflow_create
entity.data.dsl.do.updateAssetStatusWithType.with.bodyParams.fields.Type.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.updateAssetStatusWithType.with.bodyParams.fields.Type.id.
  • Source: resource.dsl.do.updateAssetStatusWithType.with.bodyParams.fields.Type.id
  • Usage: workflow_create
entity.data.dsl.do.updateAssetStatusWithType.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.updateAssetStatusWithType.with.operationId.
  • Source: resource.dsl.do.updateAssetStatusWithType.with.operationId
  • Usage: workflow_create
entity.data.dsl.do.updateAssetStatusWithType.with.pathParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.updateAssetStatusWithType.with.pathParams.id.
  • Source: resource.dsl.do.updateAssetStatusWithType.with.pathParams.id
  • Usage: workflow_create
entity.data.dsl.do.updateAssetStatusWithType.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.updateAssetStatusWithType.with.version.
  • Source: resource.dsl.do.updateAssetStatusWithType.with.version
  • Usage: workflow_create
entity.data.dsl.do.updateCustomAttribute.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.updateCustomAttribute.call.
  • Source: resource.dsl.do.updateCustomAttribute.call
  • Usage: workflow_update
entity.data.dsl.do.updateCustomAttribute.with.bodyParams.attributes.name
  • Description: JumpCloud extension data on the managed entity: dsl.do.updateCustomAttribute.with.bodyParams.attributes.name.
  • Source: resource.dsl.do.updateCustomAttribute.with.bodyParams.attributes.name
  • Usage: workflow_update
entity.data.dsl.do.updateCustomAttribute.with.bodyParams.attributes.value
  • Description: JumpCloud extension data on the managed entity: dsl.do.updateCustomAttribute.with.bodyParams.attributes.value.
  • Source: resource.dsl.do.updateCustomAttribute.with.bodyParams.attributes.value
  • Usage: workflow_update
entity.data.dsl.do.updateCustomAttribute.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.updateCustomAttribute.with.operationId.
  • Source: resource.dsl.do.updateCustomAttribute.with.operationId
  • Usage: workflow_update
entity.data.dsl.do.updateCustomAttribute.with.pathParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.updateCustomAttribute.with.pathParams.id.
  • Source: resource.dsl.do.updateCustomAttribute.with.pathParams.id
  • Usage: workflow_update
entity.data.dsl.do.updateCustomAttribute.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.updateCustomAttribute.with.version.
  • Source: resource.dsl.do.updateCustomAttribute.with.version
  • Usage: workflow_update
entity.data.dsl.do.updateCustomAttributes.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.updateCustomAttributes.call.
  • Source: resource.dsl.do.updateCustomAttributes.call
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.updateCustomAttributes.with.bodyParams.attributes
  • Description: JumpCloud extension data on the managed entity: dsl.do.updateCustomAttributes.with.bodyParams.attributes.
  • Source: resource.dsl.do.updateCustomAttributes.with.bodyParams.attributes
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.updateCustomAttributes.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.updateCustomAttributes.with.operationId.
  • Source: resource.dsl.do.updateCustomAttributes.with.operationId
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.updateCustomAttributes.with.pathParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.updateCustomAttributes.with.pathParams.id.
  • Source: resource.dsl.do.updateCustomAttributes.with.pathParams.id
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.updateCustomAttributes.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.updateCustomAttributes.with.version.
  • Source: resource.dsl.do.updateCustomAttributes.with.version
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.updateIsApproved.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.updateIsApproved.call.
  • Source: resource.dsl.do.updateIsApproved.call
  • Usage: workflow_update
entity.data.dsl.do.updateIsApproved.if
  • Description: JumpCloud extension data on the managed entity: dsl.do.updateIsApproved.if.
  • Source: resource.dsl.do.updateIsApproved.if
  • Usage: workflow_update
entity.data.dsl.do.updateIsApproved.with.bodyParams.attributes
  • Description: JumpCloud extension data on the managed entity: dsl.do.updateIsApproved.with.bodyParams.attributes.
  • Source: resource.dsl.do.updateIsApproved.with.bodyParams.attributes
  • Usage: workflow_update
entity.data.dsl.do.updateIsApproved.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.updateIsApproved.with.operationId.
  • Source: resource.dsl.do.updateIsApproved.with.operationId
  • Usage: workflow_update
entity.data.dsl.do.updateIsApproved.with.pathParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.updateIsApproved.with.pathParams.id.
  • Source: resource.dsl.do.updateIsApproved.with.pathParams.id
  • Usage: workflow_update
entity.data.dsl.do.updateIsApproved.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.updateIsApproved.with.version.
  • Source: resource.dsl.do.updateIsApproved.with.version
  • Usage: workflow_update
entity.data.dsl.do.updateUserAttributes.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.updateUserAttributes.call.
  • Source: resource.dsl.do.updateUserAttributes.call
  • Usage: workflow_delete
entity.data.dsl.do.updateUserAttributes.if
  • Description: JumpCloud extension data on the managed entity: dsl.do.updateUserAttributes.if.
  • Source: resource.dsl.do.updateUserAttributes.if
  • Usage: workflow_delete
entity.data.dsl.do.updateUserAttributes.metadata.compositePocUpdateUserAttrs.attributePairs.name
  • Description: JumpCloud extension data on the managed entity: dsl.do.updateUserAttributes.metadata.compositePocUpdateUserAttrs.attributePairs.name.
  • Source: resource.dsl.do.updateUserAttributes.metadata.compositePocUpdateUserAttrs.attributePairs.name
  • Usage: workflow_delete
entity.data.dsl.do.updateUserAttributes.metadata.compositePocUpdateUserAttrs.attributePairs.value
  • Description: JumpCloud extension data on the managed entity: dsl.do.updateUserAttributes.metadata.compositePocUpdateUserAttrs.attributePairs.value.
  • Source: resource.dsl.do.updateUserAttributes.metadata.compositePocUpdateUserAttrs.attributePairs.value
  • Usage: workflow_delete
entity.data.dsl.do.updateUserAttributes.metadata.compositePocUpdateUserAttrs.getTaskName
  • Description: JumpCloud extension data on the managed entity: dsl.do.updateUserAttributes.metadata.compositePocUpdateUserAttrs.getTaskName.
  • Source: resource.dsl.do.updateUserAttributes.metadata.compositePocUpdateUserAttrs.getTaskName
  • Usage: workflow_delete
entity.data.dsl.do.updateUserAttributes.metadata.compositePocUpdateUserAttrs.role
  • Description: JumpCloud extension data on the managed entity: dsl.do.updateUserAttributes.metadata.compositePocUpdateUserAttrs.role.
  • Source: resource.dsl.do.updateUserAttributes.metadata.compositePocUpdateUserAttrs.role
  • Usage: workflow_delete
entity.data.dsl.do.updateUserAttributes.metadata.compositePocUpdateUserAttrs.templateId
  • Description: JumpCloud extension data on the managed entity: dsl.do.updateUserAttributes.metadata.compositePocUpdateUserAttrs.templateId.
  • Source: resource.dsl.do.updateUserAttributes.metadata.compositePocUpdateUserAttrs.templateId
  • Usage: workflow_delete
entity.data.dsl.do.updateUserAttributes.metadata.displayLabels.__pocAttributes
  • Description: JumpCloud extension data on the managed entity: dsl.do.updateUserAttributes.metadata.displayLabels.__pocAttributes.
  • Source: resource.dsl.do.updateUserAttributes.metadata.displayLabels.__pocAttributes
  • Usage: workflow_delete
entity.data.dsl.do.updateUserAttributes.with.bodyParams.attributes
  • Description: JumpCloud extension data on the managed entity: dsl.do.updateUserAttributes.with.bodyParams.attributes.
  • Source: resource.dsl.do.updateUserAttributes.with.bodyParams.attributes
  • Usage: workflow_delete
entity.data.dsl.do.updateUserAttributes.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.updateUserAttributes.with.operationId.
  • Source: resource.dsl.do.updateUserAttributes.with.operationId
  • Usage: workflow_delete
entity.data.dsl.do.updateUserAttributes.with.pathParams.id
  • Description: JumpCloud extension data on the managed entity: dsl.do.updateUserAttributes.with.pathParams.id.
  • Source: resource.dsl.do.updateUserAttributes.with.pathParams.id
  • Usage: workflow_delete
entity.data.dsl.do.updateUserAttributes.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.updateUserAttributes.with.version.
  • Source: resource.dsl.do.updateUserAttributes.with.version
  • Usage: workflow_delete
entity.data.dsl.do.userServiceGetAllUsers.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.userServiceGetAllUsers.call.
  • Source: resource.dsl.do.userServiceGetAllUsers.call
  • Usage: workflow_delete
entity.data.dsl.do.userServiceGetAllUsers.with.extract
  • Description: JumpCloud extension data on the managed entity: dsl.do.userServiceGetAllUsers.with.extract.
  • Source: resource.dsl.do.userServiceGetAllUsers.with.extract
  • Usage: workflow_delete
entity.data.dsl.do.userServiceGetAllUsers.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.userServiceGetAllUsers.with.operationId.
  • Source: resource.dsl.do.userServiceGetAllUsers.with.operationId
  • Usage: workflow_delete
entity.data.dsl.do.userServiceGetAllUsers.with.pagination.until
  • Description: JumpCloud extension data on the managed entity: dsl.do.userServiceGetAllUsers.with.pagination.until.
  • Source: resource.dsl.do.userServiceGetAllUsers.with.pagination.until
  • Usage: workflow_delete
entity.data.dsl.do.userServiceGetAllUsers.with.pagination.update.in
  • Description: JumpCloud extension data on the managed entity: dsl.do.userServiceGetAllUsers.with.pagination.update.in.
  • Source: resource.dsl.do.userServiceGetAllUsers.with.pagination.update.in
  • Usage: workflow_delete
entity.data.dsl.do.userServiceGetAllUsers.with.pagination.update.key
  • Description: JumpCloud extension data on the managed entity: dsl.do.userServiceGetAllUsers.with.pagination.update.key.
  • Source: resource.dsl.do.userServiceGetAllUsers.with.pagination.update.key
  • Usage: workflow_delete
entity.data.dsl.do.userServiceGetAllUsers.with.pagination.update.value
  • Description: JumpCloud extension data on the managed entity: dsl.do.userServiceGetAllUsers.with.pagination.update.value.
  • Source: resource.dsl.do.userServiceGetAllUsers.with.pagination.update.value
  • Usage: workflow_delete
entity.data.dsl.do.userServiceGetAllUsers.with.queryParams.filter
  • Description: JumpCloud extension data on the managed entity: dsl.do.userServiceGetAllUsers.with.queryParams.filter.
  • Source: resource.dsl.do.userServiceGetAllUsers.with.queryParams.filter
  • Usage: workflow_delete
entity.data.dsl.do.userServiceGetAllUsers.with.queryParams.limit
  • Description: JumpCloud extension data on the managed entity: dsl.do.userServiceGetAllUsers.with.queryParams.limit.
  • Source: resource.dsl.do.userServiceGetAllUsers.with.queryParams.limit
  • Usage: workflow_delete
entity.data.dsl.do.userServiceGetAllUsers.with.queryParams.search
  • Description: JumpCloud extension data on the managed entity: dsl.do.userServiceGetAllUsers.with.queryParams.search.
  • Source: resource.dsl.do.userServiceGetAllUsers.with.queryParams.search
  • Usage: workflow_delete
entity.data.dsl.do.userServiceGetAllUsers.with.queryParams.skip
  • Description: JumpCloud extension data on the managed entity: dsl.do.userServiceGetAllUsers.with.queryParams.skip.
  • Source: resource.dsl.do.userServiceGetAllUsers.with.queryParams.skip
  • Usage: workflow_delete
entity.data.dsl.do.userServiceGetAllUsers.with.queryParams.sort
  • Description: JumpCloud extension data on the managed entity: dsl.do.userServiceGetAllUsers.with.queryParams.sort.
  • Source: resource.dsl.do.userServiceGetAllUsers.with.queryParams.sort
  • Usage: workflow_delete
entity.data.dsl.do.userServiceGetAllUsers.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.userServiceGetAllUsers.with.version.
  • Source: resource.dsl.do.userServiceGetAllUsers.with.version
  • Usage: workflow_delete
entity.data.dsl.do.verifyActiveStatus.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.verifyActiveStatus.call.
  • Source: resource.dsl.do.verifyActiveStatus.call
  • Usage: workflow_create
entity.data.dsl.do.verifyActiveStatus.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.verifyActiveStatus.then.
  • Source: resource.dsl.do.verifyActiveStatus.then
  • Usage: workflow_create
entity.data.dsl.do.verifyActiveStatus.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.verifyActiveStatus.with.operationId.
  • Source: resource.dsl.do.verifyActiveStatus.with.operationId
  • Usage: workflow_create
entity.data.dsl.do.verifyActiveStatus.with.queryParams.limit
  • Description: JumpCloud extension data on the managed entity: dsl.do.verifyActiveStatus.with.queryParams.limit.
  • Source: resource.dsl.do.verifyActiveStatus.with.queryParams.limit
  • Usage: workflow_create
entity.data.dsl.do.verifyActiveStatus.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.verifyActiveStatus.with.version.
  • Source: resource.dsl.do.verifyActiveStatus.with.version
  • Usage: workflow_create
entity.data.dsl.do.verifyDefaultStatus.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.verifyDefaultStatus.call.
  • Source: resource.dsl.do.verifyDefaultStatus.call
  • Usage: workflow_create
entity.data.dsl.do.verifyDefaultStatus.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.verifyDefaultStatus.then.
  • Source: resource.dsl.do.verifyDefaultStatus.then
  • Usage: workflow_create
entity.data.dsl.do.verifyDefaultStatus.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.verifyDefaultStatus.with.operationId.
  • Source: resource.dsl.do.verifyDefaultStatus.with.operationId
  • Usage: workflow_create
entity.data.dsl.do.verifyDefaultStatus.with.queryParams.limit
  • Description: JumpCloud extension data on the managed entity: dsl.do.verifyDefaultStatus.with.queryParams.limit.
  • Source: resource.dsl.do.verifyDefaultStatus.with.queryParams.limit
  • Usage: workflow_create
entity.data.dsl.do.verifyDefaultStatus.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.verifyDefaultStatus.with.version.
  • Source: resource.dsl.do.verifyDefaultStatus.with.version
  • Usage: workflow_create
entity.data.dsl.do.verifySuspendedStatus.call
  • Description: JumpCloud extension data on the managed entity: dsl.do.verifySuspendedStatus.call.
  • Source: resource.dsl.do.verifySuspendedStatus.call
  • Usage: workflow_create
entity.data.dsl.do.verifySuspendedStatus.then
  • Description: JumpCloud extension data on the managed entity: dsl.do.verifySuspendedStatus.then.
  • Source: resource.dsl.do.verifySuspendedStatus.then
  • Usage: workflow_create
entity.data.dsl.do.verifySuspendedStatus.with.operationId
  • Description: JumpCloud extension data on the managed entity: dsl.do.verifySuspendedStatus.with.operationId.
  • Source: resource.dsl.do.verifySuspendedStatus.with.operationId
  • Usage: workflow_create
entity.data.dsl.do.verifySuspendedStatus.with.queryParams.limit
  • Description: JumpCloud extension data on the managed entity: dsl.do.verifySuspendedStatus.with.queryParams.limit.
  • Source: resource.dsl.do.verifySuspendedStatus.with.queryParams.limit
  • Usage: workflow_create
entity.data.dsl.do.verifySuspendedStatus.with.version
  • Description: JumpCloud extension data on the managed entity: dsl.do.verifySuspendedStatus.with.version.
  • Source: resource.dsl.do.verifySuspendedStatus.with.version
  • Usage: workflow_create
entity.data.dsl.input.schema.document.filters
  • Description: JumpCloud extension data on the managed entity: dsl.input.schema.document.filters.
  • Source: resource.dsl.input.schema.document.filters
  • Usage: workflow_delete
entity.data.dsl.input.schema.document.properties.channelId.type
  • Description: JumpCloud extension data on the managed entity: dsl.input.schema.document.properties.channelId.type.
  • Source: resource.dsl.input.schema.document.properties.channelId.type
  • Usage: workflow_delete, workflow_update
entity.data.dsl.input.schema.document.properties.commandId.type
  • Description: JumpCloud extension data on the managed entity: dsl.input.schema.document.properties.commandId.type.
  • Source: resource.dsl.input.schema.document.properties.commandId.type
  • Usage: workflow_delete
entity.data.dsl.input.schema.document.properties.defenderExclusionPath.type
  • Description: JumpCloud extension data on the managed entity: dsl.input.schema.document.properties.defenderExclusionPath.type.
  • Source: resource.dsl.input.schema.document.properties.defenderExclusionPath.type
  • Usage: workflow_delete
entity.data.dsl.input.schema.document.properties.elevatedGroupId.type
  • Description: JumpCloud extension data on the managed entity: dsl.input.schema.document.properties.elevatedGroupId.type.
  • Source: resource.dsl.input.schema.document.properties.elevatedGroupId.type
  • Usage: workflow_delete
entity.data.dsl.input.schema.document.properties.id.description
  • Description: JumpCloud extension data on the managed entity: dsl.input.schema.document.properties.id.description.
  • Source: resource.dsl.input.schema.document.properties.id.description
  • Usage: workflow_create
entity.data.dsl.input.schema.document.properties.id.type
  • Description: JumpCloud extension data on the managed entity: dsl.input.schema.document.properties.id.type.
  • Source: resource.dsl.input.schema.document.properties.id.type
  • Usage: workflow_create
entity.data.dsl.input.schema.document.properties.itReviewChannelId.type
  • Description: JumpCloud extension data on the managed entity: dsl.input.schema.document.properties.itReviewChannelId.type.
  • Source: resource.dsl.input.schema.document.properties.itReviewChannelId.type
  • Usage: workflow_delete
entity.data.dsl.input.schema.document.properties.jobTitle.type
  • Description: JumpCloud extension data on the managed entity: dsl.input.schema.document.properties.jobTitle.type.
  • Source: resource.dsl.input.schema.document.properties.jobTitle.type
  • Usage: workflow_delete
entity.data.dsl.input.schema.document.properties.name.type
  • Description: JumpCloud extension data on the managed entity: dsl.input.schema.document.properties.name.type.
  • Source: resource.dsl.input.schema.document.properties.name.type
  • Usage: workflow_delete
entity.data.dsl.input.schema.document.properties.opsChannelId.type
  • Description: JumpCloud extension data on the managed entity: dsl.input.schema.document.properties.opsChannelId.type.
  • Source: resource.dsl.input.schema.document.properties.opsChannelId.type
  • Usage: workflow_delete
entity.data.dsl.input.schema.document.properties.previousJobTitle.type
  • Description: JumpCloud extension data on the managed entity: dsl.input.schema.document.properties.previousJobTitle.type.
  • Source: resource.dsl.input.schema.document.properties.previousJobTitle.type
  • Usage: workflow_delete
entity.data.dsl.input.schema.document.properties.stagingGroupId.type
  • Description: JumpCloud extension data on the managed entity: dsl.input.schema.document.properties.stagingGroupId.type.
  • Source: resource.dsl.input.schema.document.properties.stagingGroupId.type
  • Usage: workflow_delete
entity.data.dsl.input.schema.document.properties.userId.description
  • Description: JumpCloud extension data on the managed entity: dsl.input.schema.document.properties.userId.description.
  • Source: resource.dsl.input.schema.document.properties.userId.description
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.input.schema.document.properties.userId.type
  • Description: JumpCloud extension data on the managed entity: dsl.input.schema.document.properties.userId.type.
  • Source: resource.dsl.input.schema.document.properties.userId.type
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.input.schema.document.required
  • Description: JumpCloud extension data on the managed entity: dsl.input.schema.document.required.
  • Source: resource.dsl.input.schema.document.required
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.input.schema.document.type
  • Description: JumpCloud extension data on the managed entity: dsl.input.schema.document.type.
  • Source: resource.dsl.input.schema.document.type
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.input.schema.format
  • Description: JumpCloud extension data on the managed entity: dsl.input.schema.format.
  • Source: resource.dsl.input.schema.format
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.schedule.day_of_week
  • Description: JumpCloud extension data on the managed entity: dsl.schedule.day_of_week.
  • Source: resource.dsl.schedule.day_of_week
  • Usage: workflow_create
entity.data.dsl.schedule.frequency
  • Description: JumpCloud extension data on the managed entity: dsl.schedule.frequency.
  • Source: resource.dsl.schedule.frequency
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.schedule.interval
  • Description: JumpCloud extension data on the managed entity: dsl.schedule.interval.
  • Source: resource.dsl.schedule.interval
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.schedule.on.one.with.condition
  • Description: JumpCloud extension data on the managed entity: dsl.schedule.on.one.with.condition.
  • Source: resource.dsl.schedule.on.one.with.condition
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.schedule.on.one.with.source
  • Description: JumpCloud extension data on the managed entity: dsl.schedule.on.one.with.source.
  • Source: resource.dsl.schedule.on.one.with.source
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.schedule.on.one.with.type
  • Description: JumpCloud extension data on the managed entity: dsl.schedule.on.one.with.type.
  • Source: resource.dsl.schedule.on.one.with.type
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.schedule.start_date
  • Description: JumpCloud extension data on the managed entity: dsl.schedule.start_date.
  • Source: resource.dsl.schedule.start_date
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.schedule.start_time
  • Description: JumpCloud extension data on the managed entity: dsl.schedule.start_time.
  • Source: resource.dsl.schedule.start_time
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.schedule.time
  • Description: JumpCloud extension data on the managed entity: dsl.schedule.time.
  • Source: resource.dsl.schedule.time
  • Usage: workflow_create, workflow_delete
entity.data.dsl.schedule.timezone
  • Description: JumpCloud extension data on the managed entity: dsl.schedule.timezone.
  • Source: resource.dsl.schedule.timezone
  • Usage: workflow_create, workflow_delete, workflow_update
entity.data.status
  • Description: JumpCloud extension data on the managed entity: status.
  • Source: resource.status
  • Usage: workflow_create, workflow_delete, workflow_update
entity.name
  • Description: The name of the managed entity. It should match the name of the specific entity object's name if populated, or the name of the managed entity if the type_id is 'Other'.
  • Source: resource.name
  • Usage: workflow_create, workflow_delete, workflow_update
entity.type
  • Description: The managed entity type. For example: Policy, User, Organization, Device.
  • Source: resource.type
  • Usage: workflow_create, workflow_delete, workflow_update
entity.uid
  • Description: The identifier of the managed entity. It should match the uid of the specific entity's object UID if populated, or the source specific ID if the type_id is 'Other'.
  • Source: resource.id
  • Usage: workflow_create, workflow_delete, workflow_update
entity_result.data.changes_to_do_activateUser2_call
  • Description: JumpCloud extension data on the managed entity: changes_to_do_activateUser2_call.
  • Source: changes.to.do.activateUser2.call
  • Usage: workflow_update
entity_result.data.changes_to_do_activateUser2_metadata_displayLabels_email
  • Description: JumpCloud extension data on the managed entity: changes_to_do_activateUser2_metadata_displayLabels_email.
  • Source: changes.to.do.activateUser2.metadata.displayLabels.email
  • Usage: workflow_update
entity_result.data.changes_to_do_activateUser2_metadata_displayLabels_user
  • Description: JumpCloud extension data on the managed entity: changes_to_do_activateUser2_metadata_displayLabels_user.
  • Source: changes.to.do.activateUser2.metadata.displayLabels.user
  • Usage: workflow_update
entity_result.data.changes_to_do_activateUser2_metadata_inputModes_email
  • Description: JumpCloud extension data on the managed entity: changes_to_do_activateUser2_metadata_inputModes_email.
  • Source: changes.to.do.activateUser2.metadata.inputModes.email
  • Usage: workflow_update
entity_result.data.changes_to_do_activateUser2_metadata_inputModes_user
  • Description: JumpCloud extension data on the managed entity: changes_to_do_activateUser2_metadata_inputModes_user.
  • Source: changes.to.do.activateUser2.metadata.inputModes.user
  • Usage: workflow_update
entity_result.data.changes_to_do_activateUser2_with_bodyParams_email
  • Description: JumpCloud extension data on the managed entity: changes_to_do_activateUser2_with_bodyParams_email.
  • Source: changes.to.do.activateUser2.with.bodyParams.email
  • Usage: workflow_update
entity_result.data.changes_to_do_activateUser2_with_operationId
  • Description: JumpCloud extension data on the managed entity: changes_to_do_activateUser2_with_operationId.
  • Source: changes.to.do.activateUser2.with.operationId
  • Usage: workflow_update
entity_result.data.changes_to_do_activateUser2_with_pathParams_id
  • Description: JumpCloud extension data on the managed entity: changes_to_do_activateUser2_with_pathParams_id.
  • Source: changes.to.do.activateUser2.with.pathParams.id
  • Usage: workflow_update
entity_result.data.changes_to_do_activateUser2_with_version
  • Description: JumpCloud extension data on the managed entity: changes_to_do_activateUser2_with_version.
  • Source: changes.to.do.activateUser2.with.version
  • Usage: workflow_update
entity_result.data.changes_to_do_activateUser_call
  • Description: JumpCloud extension data on the managed entity: changes_to_do_activateUser_call.
  • Source: changes.to.do.activateUser.call
  • Usage: workflow_update
entity_result.data.changes_to_do_activateUser_metadata_displayLabels_email
  • Description: JumpCloud extension data on the managed entity: changes_to_do_activateUser_metadata_displayLabels_email.
  • Source: changes.to.do.activateUser.metadata.displayLabels.email
  • Usage: workflow_update
entity_result.data.changes_to_do_activateUser_metadata_displayLabels_user
  • Description: JumpCloud extension data on the managed entity: changes_to_do_activateUser_metadata_displayLabels_user.
  • Source: changes.to.do.activateUser.metadata.displayLabels.user
  • Usage: workflow_update
entity_result.data.changes_to_do_activateUser_metadata_inputModes_email
  • Description: JumpCloud extension data on the managed entity: changes_to_do_activateUser_metadata_inputModes_email.
  • Source: changes.to.do.activateUser.metadata.inputModes.email
  • Usage: workflow_update
entity_result.data.changes_to_do_activateUser_metadata_inputModes_user
  • Description: JumpCloud extension data on the managed entity: changes_to_do_activateUser_metadata_inputModes_user.
  • Source: changes.to.do.activateUser.metadata.inputModes.user
  • Usage: workflow_update
entity_result.data.changes_to_do_activateUser_with_bodyParams_email
  • Description: JumpCloud extension data on the managed entity: changes_to_do_activateUser_with_bodyParams_email.
  • Source: changes.to.do.activateUser.with.bodyParams.email
  • Usage: workflow_update
entity_result.data.changes_to_do_activateUser_with_operationId
  • Description: JumpCloud extension data on the managed entity: changes_to_do_activateUser_with_operationId.
  • Source: changes.to.do.activateUser.with.operationId
  • Usage: workflow_update
entity_result.data.changes_to_do_activateUser_with_pathParams_id
  • Description: JumpCloud extension data on the managed entity: changes_to_do_activateUser_with_pathParams_id.
  • Source: changes.to.do.activateUser.with.pathParams.id
  • Usage: workflow_update
entity_result.data.changes_to_do_activateUser_with_version
  • Description: JumpCloud extension data on the managed entity: changes_to_do_activateUser_with_version.
  • Source: changes.to.do.activateUser.with.version
  • Usage: workflow_update
entity_result.data.changes_to_do_callConnector_call
  • Description: JumpCloud extension data on the managed entity: changes_to_do_callConnector_call.
  • Source: changes.to.do.callConnector.call
  • Usage: workflow_update
entity_result.data.changes_to_do_callConnector_with_body_data
  • Description: JumpCloud extension data on the managed entity: changes_to_do_callConnector_with_body_data.
  • Source: changes.to.do.callConnector.with.body.data
  • Usage: workflow_update
entity_result.data.changes_to_do_callConnector_with_body_id
  • Description: JumpCloud extension data on the managed entity: changes_to_do_callConnector_with_body_id.
  • Source: changes.to.do.callConnector.with.body.id
  • Usage: workflow_update
entity_result.data.changes_to_do_callConnector_with_body_timestamp
  • Description: JumpCloud extension data on the managed entity: changes_to_do_callConnector_with_body_timestamp.
  • Source: changes.to.do.callConnector.with.body.timestamp
  • Usage: workflow_update
entity_result.data.changes_to_do_callConnector_with_endpointPath
  • Description: JumpCloud extension data on the managed entity: changes_to_do_callConnector_with_endpointPath.
  • Source: changes.to.do.callConnector.with.endpointPath
  • Usage: workflow_update
entity_result.data.changes_to_do_callConnector_with_headers_Accept
  • Description: JumpCloud extension data on the managed entity: changes_to_do_callConnector_with_headers_Accept.
  • Source: changes.to.do.callConnector.with.headers.Accept
  • Usage: workflow_update
entity_result.data.changes_to_do_callConnector_with_headers_EWrwer
  • Description: JumpCloud extension data on the managed entity: changes_to_do_callConnector_with_headers_EWrwer.
  • Source: changes.to.do.callConnector.with.headers.EWrwer
  • Usage: workflow_update
entity_result.data.changes_to_do_callConnector_with_headers_ew
  • Description: JumpCloud extension data on the managed entity: changes_to_do_callConnector_with_headers_ew.
  • Source: changes.to.do.callConnector.with.headers.ew
  • Usage: workflow_update
entity_result.data.changes_to_do_callConnector_with_headers_ewd
  • Description: JumpCloud extension data on the managed entity: changes_to_do_callConnector_with_headers_ewd.
  • Source: changes.to.do.callConnector.with.headers.ewd
  • Usage: workflow_update
entity_result.data.changes_to_do_callConnector_with_headers_ewe
  • Description: JumpCloud extension data on the managed entity: changes_to_do_callConnector_with_headers_ewe.
  • Source: changes.to.do.callConnector.with.headers.ewe
  • Usage: workflow_update
entity_result.data.changes_to_do_callConnector_with_httpMethod
  • Description: JumpCloud extension data on the managed entity: changes_to_do_callConnector_with_httpMethod.
  • Source: changes.to.do.callConnector.with.httpMethod
  • Usage: workflow_update
entity_result.data.changes_to_do_callConnector_with_id
  • Description: JumpCloud extension data on the managed entity: changes_to_do_callConnector_with_id.
  • Source: changes.to.do.callConnector.with.id
  • Usage: workflow_update
entity_result.data.changes_to_do_checkActivated_call
  • Description: JumpCloud extension data on the managed entity: changes_to_do_checkActivated_call.
  • Source: changes.to.do.checkActivated.call
  • Usage: workflow_update
entity_result.data.changes_to_do_checkActivated_if
  • Description: JumpCloud extension data on the managed entity: changes_to_do_checkActivated_if.
  • Source: changes.to.do.checkActivated.if
  • Usage: workflow_update
entity_result.data.changes_to_do_checkActivated_with_operationId
  • Description: JumpCloud extension data on the managed entity: changes_to_do_checkActivated_with_operationId.
  • Source: changes.to.do.checkActivated.with.operationId
  • Usage: workflow_update
entity_result.data.changes_to_do_checkActivated_with_pathParams_id
  • Description: JumpCloud extension data on the managed entity: changes_to_do_checkActivated_with_pathParams_id.
  • Source: changes.to.do.checkActivated.with.pathParams.id
  • Usage: workflow_update
entity_result.data.changes_to_do_checkActivated_with_queryParams_fields
  • Description: JumpCloud extension data on the managed entity: changes_to_do_checkActivated_with_queryParams_fields.
  • Source: changes.to.do.checkActivated.with.queryParams.fields
  • Usage: workflow_update
entity_result.data.changes_to_do_checkActivated_with_version
  • Description: JumpCloud extension data on the managed entity: changes_to_do_checkActivated_with_version.
  • Source: changes.to.do.checkActivated.with.version
  • Usage: workflow_update
entity_result.data.changes_to_do_checkDelegatedAuthorityExists_call
  • Description: JumpCloud extension data on the managed entity: changes_to_do_checkDelegatedAuthorityExists_call.
  • Source: changes.to.do.checkDelegatedAuthorityExists.call
  • Usage: workflow_update
entity_result.data.changes_to_do_checkDelegatedAuthorityExists_if
  • Description: JumpCloud extension data on the managed entity: changes_to_do_checkDelegatedAuthorityExists_if.
  • Source: changes.to.do.checkDelegatedAuthorityExists.if
  • Usage: workflow_update
entity_result.data.changes_to_do_checkDelegatedAuthorityExists_with_operationId
  • Description: JumpCloud extension data on the managed entity: changes_to_do_checkDelegatedAuthorityExists_with_operationId.
  • Source: changes.to.do.checkDelegatedAuthorityExists.with.operationId
  • Usage: workflow_update
entity_result.data.changes_to_do_checkDelegatedAuthorityExists_with_pathParams_id
  • Description: JumpCloud extension data on the managed entity: changes_to_do_checkDelegatedAuthorityExists_with_pathParams_id.
  • Source: changes.to.do.checkDelegatedAuthorityExists.with.pathParams.id
  • Usage: workflow_update
entity_result.data.changes_to_do_checkDelegatedAuthorityExists_with_queryParams_fields
  • Description: JumpCloud extension data on the managed entity: changes_to_do_checkDelegatedAuthorityExists_with_queryParams_fields.
  • Source: changes.to.do.checkDelegatedAuthorityExists.with.queryParams.fields
  • Usage: workflow_update
entity_result.data.changes_to_do_checkDelegatedAuthorityExists_with_version
  • Description: JumpCloud extension data on the managed entity: changes_to_do_checkDelegatedAuthorityExists_with_version.
  • Source: changes.to.do.checkDelegatedAuthorityExists.with.version
  • Usage: workflow_update
entity_result.data.changes_to_do_checkPasswordDate_call
  • Description: JumpCloud extension data on the managed entity: changes_to_do_checkPasswordDate_call.
  • Source: changes.to.do.checkPasswordDate.call
  • Usage: workflow_update
entity_result.data.changes_to_do_checkPasswordDate_if
  • Description: JumpCloud extension data on the managed entity: changes_to_do_checkPasswordDate_if.
  • Source: changes.to.do.checkPasswordDate.if
  • Usage: workflow_update
entity_result.data.changes_to_do_checkPasswordDate_with_operationId
  • Description: JumpCloud extension data on the managed entity: changes_to_do_checkPasswordDate_with_operationId.
  • Source: changes.to.do.checkPasswordDate.with.operationId
  • Usage: workflow_update
entity_result.data.changes_to_do_checkPasswordDate_with_pathParams_id
  • Description: JumpCloud extension data on the managed entity: changes_to_do_checkPasswordDate_with_pathParams_id.
  • Source: changes.to.do.checkPasswordDate.with.pathParams.id
  • Usage: workflow_update
entity_result.data.changes_to_do_checkPasswordDate_with_queryParams_fields
  • Description: JumpCloud extension data on the managed entity: changes_to_do_checkPasswordDate_with_queryParams_fields.
  • Source: changes.to.do.checkPasswordDate.with.queryParams.fields
  • Usage: workflow_update
entity_result.data.changes_to_do_checkPasswordDate_with_version
  • Description: JumpCloud extension data on the managed entity: changes_to_do_checkPasswordDate_with_version.
  • Source: changes.to.do.checkPasswordDate.with.version
  • Usage: workflow_update
entity_result.data.changes_to_do_getUser_call
  • Description: JumpCloud extension data on the managed entity: changes_to_do_getUser_call.
  • Source: changes.to.do.getUser.call
  • Usage: workflow_update
entity_result.data.changes_to_do_getUser_with_operationId
  • Description: JumpCloud extension data on the managed entity: changes_to_do_getUser_with_operationId.
  • Source: changes.to.do.getUser.with.operationId
  • Usage: workflow_update
entity_result.data.changes_to_do_getUser_with_pathParams_id
  • Description: JumpCloud extension data on the managed entity: changes_to_do_getUser_with_pathParams_id.
  • Source: changes.to.do.getUser.with.pathParams.id
  • Usage: workflow_update
entity_result.data.changes_to_do_getUser_with_version
  • Description: JumpCloud extension data on the managed entity: changes_to_do_getUser_with_version.
  • Source: changes.to.do.getUser.with.version
  • Usage: workflow_update
entity_result.data.changes_to_do_removeDelegatedAuthority_call
  • Description: JumpCloud extension data on the managed entity: changes_to_do_removeDelegatedAuthority_call.
  • Source: changes.to.do.removeDelegatedAuthority.call
  • Usage: workflow_update
entity_result.data.changes_to_do_removeDelegatedAuthority_if
  • Description: JumpCloud extension data on the managed entity: changes_to_do_removeDelegatedAuthority_if.
  • Source: changes.to.do.removeDelegatedAuthority.if
  • Usage: workflow_update
entity_result.data.changes_to_do_removeDelegatedAuthority_with_bodyParams_delegatedAuthority
  • Description: JumpCloud extension data on the managed entity: changes_to_do_removeDelegatedAuthority_with_bodyParams_delegatedAuthority.
  • Source: changes.to.do.removeDelegatedAuthority.with.bodyParams.delegatedAuthority
  • Usage: workflow_update
entity_result.data.changes_to_do_removeDelegatedAuthority_with_operationId
  • Description: JumpCloud extension data on the managed entity: changes_to_do_removeDelegatedAuthority_with_operationId.
  • Source: changes.to.do.removeDelegatedAuthority.with.operationId
  • Usage: workflow_update
entity_result.data.changes_to_do_removeDelegatedAuthority_with_pathParams_id
  • Description: JumpCloud extension data on the managed entity: changes_to_do_removeDelegatedAuthority_with_pathParams_id.
  • Source: changes.to.do.removeDelegatedAuthority.with.pathParams.id
  • Usage: workflow_update
entity_result.data.changes_to_do_removeDelegatedAuthority_with_version
  • Description: JumpCloud extension data on the managed entity: changes_to_do_removeDelegatedAuthority_with_version.
  • Source: changes.to.do.removeDelegatedAuthority.with.version
  • Usage: workflow_update
entity_result.data.changes_to_do_sendEmailAddresses_call
  • Description: JumpCloud extension data on the managed entity: changes_to_do_sendEmailAddresses_call.
  • Source: changes.to.do.sendEmailAddresses.call
  • Usage: workflow_update
entity_result.data.changes_to_do_sendEmailAddresses_with_message_body
  • Description: JumpCloud extension data on the managed entity: changes_to_do_sendEmailAddresses_with_message_body.
  • Source: changes.to.do.sendEmailAddresses.with.message.body
  • Usage: workflow_update
entity_result.data.changes_to_do_sendEmailAddresses_with_message_subject
  • Description: JumpCloud extension data on the managed entity: changes_to_do_sendEmailAddresses_with_message_subject.
  • Source: changes.to.do.sendEmailAddresses.with.message.subject
  • Usage: workflow_update
entity_result.data.changes_to_do_sendEmailAddresses_with_recipients_to_addresses
  • Description: JumpCloud extension data on the managed entity: changes_to_do_sendEmailAddresses_with_recipients_to_addresses.
  • Source: changes.to.do.sendEmailAddresses.with.recipients.to_addresses
  • Usage: workflow_update
entity_result.data.changes_to_do_systemusersGet_call
  • Description: JumpCloud extension data on the managed entity: changes_to_do_systemusersGet_call.
  • Source: changes.to.do.systemusersGet.call
  • Usage: workflow_update
entity_result.data.changes_to_do_systemusersGet_with_operationId
  • Description: JumpCloud extension data on the managed entity: changes_to_do_systemusersGet_with_operationId.
  • Source: changes.to.do.systemusersGet.with.operationId
  • Usage: workflow_update
entity_result.data.changes_to_do_systemusersGet_with_pathParams_id
  • Description: JumpCloud extension data on the managed entity: changes_to_do_systemusersGet_with_pathParams_id.
  • Source: changes.to.do.systemusersGet.with.pathParams.id
  • Usage: workflow_update
entity_result.data.changes_to_do_systemusersGet_with_queryParams_fields
  • Description: JumpCloud extension data on the managed entity: changes_to_do_systemusersGet_with_queryParams_fields.
  • Source: changes.to.do.systemusersGet.with.queryParams.fields
  • Usage: workflow_update
entity_result.data.changes_to_do_systemusersGet_with_version
  • Description: JumpCloud extension data on the managed entity: changes_to_do_systemusersGet_with_version.
  • Source: changes.to.do.systemusersGet.with.version
  • Usage: workflow_update
entity_result.data.changes_to_do_updateIsApproved_call
  • Description: JumpCloud extension data on the managed entity: changes_to_do_updateIsApproved_call.
  • Source: changes.to.do.updateIsApproved.call
  • Usage: workflow_update
entity_result.data.changes_to_do_updateIsApproved_if
  • Description: JumpCloud extension data on the managed entity: changes_to_do_updateIsApproved_if.
  • Source: changes.to.do.updateIsApproved.if
  • Usage: workflow_update
entity_result.data.changes_to_do_updateIsApproved_with_bodyParams_attributes
  • Description: JumpCloud extension data on the managed entity: changes_to_do_updateIsApproved_with_bodyParams_attributes.
  • Source: changes.to.do.updateIsApproved.with.bodyParams.attributes
  • Usage: workflow_update
entity_result.data.changes_to_do_updateIsApproved_with_operationId
  • Description: JumpCloud extension data on the managed entity: changes_to_do_updateIsApproved_with_operationId.
  • Source: changes.to.do.updateIsApproved.with.operationId
  • Usage: workflow_update
entity_result.data.changes_to_do_updateIsApproved_with_pathParams_id
  • Description: JumpCloud extension data on the managed entity: changes_to_do_updateIsApproved_with_pathParams_id.
  • Source: changes.to.do.updateIsApproved.with.pathParams.id
  • Usage: workflow_update
entity_result.data.changes_to_do_updateIsApproved_with_version
  • Description: JumpCloud extension data on the managed entity: changes_to_do_updateIsApproved_with_version.
  • Source: changes.to.do.updateIsApproved.with.version
  • Usage: workflow_update
entity_result.data.changes_to_schedule_frequency
  • Description: JumpCloud extension data on the managed entity: changes_to_schedule_frequency.
  • Source: changes.to.schedule.frequency
  • Usage: workflow_update
entity_result.data.changes_to_schedule_interval
  • Description: JumpCloud extension data on the managed entity: changes_to_schedule_interval.
  • Source: changes.to.schedule.interval
  • Usage: workflow_update
entity_result.data.changes_to_schedule_on_one_with_condition
  • Description: JumpCloud extension data on the managed entity: changes_to_schedule_on_one_with_condition.
  • Source: changes.to.schedule.on.one.with.condition
  • Usage: workflow_update
entity_result.data.changes_to_schedule_on_one_with_source
  • Description: JumpCloud extension data on the managed entity: changes_to_schedule_on_one_with_source.
  • Source: changes.to.schedule.on.one.with.source
  • Usage: workflow_update
entity_result.data.changes_to_schedule_on_one_with_type
  • Description: JumpCloud extension data on the managed entity: changes_to_schedule_on_one_with_type.
  • Source: changes.to.schedule.on.one.with.type
  • Usage: workflow_update
entity_result.data.changes_to_schedule_start_date
  • Description: JumpCloud extension data on the managed entity: changes_to_schedule_start_date.
  • Source: changes.to.schedule.start_date
  • Usage: workflow_update
entity_result.data.changes_to_schedule_start_time
  • Description: JumpCloud extension data on the managed entity: changes_to_schedule_start_time.
  • Source: changes.to.schedule.start_time
  • Usage: workflow_update
entity_result.data.changes_to_schedule_timezone
  • Description: JumpCloud extension data on the managed entity: changes_to_schedule_timezone.
  • Source: changes.to.schedule.timezone
  • Usage: workflow_update

Src Endpoint

src_endpoint.autonomous_system.name
  • Description: Organization name for the Autonomous System.
  • Source: asn.organization
  • Usage: workflow_create, workflow_delete
src_endpoint.autonomous_system.number
  • Description: Unique number that the AS is identified by.
  • Source: asn.number
  • Transform:
  • asn.number → int (workflow_create, workflow_delete)
  • Usage: workflow_create, workflow_delete
src_endpoint.ip
  • Description: Source IP address the request originated from.
  • Source: client_ip
  • Usage: workflow_create, workflow_delete, workflow_update
src_endpoint.location.city
  • Description: The name of the city.
  • Source: geoip.city
  • Usage: workflow_create, workflow_delete, workflow_update
src_endpoint.location.continent
  • Description: The name of the continent.
  • Source: geoip.continent_code
  • Usage: workflow_create, workflow_delete, workflow_update
src_endpoint.location.country
  • Description: The ISO 3166-1 Alpha-2 country code.

    Note: The two letter country code should be capitalized. For example: US or CA.

  • Source: geoip.country_code
  • Usage: workflow_create, workflow_delete, workflow_update
src_endpoint.location.lat
  • Description: The geographical Latitude coordinate represented in Decimal Degrees (DD). For example: 42.361145.
  • Source: geoip.latitude
  • Transform:
  • geoip.latitude → double (workflow_create, workflow_delete, workflow_update)
  • Usage: workflow_create, workflow_delete, workflow_update
src_endpoint.location.long
  • Description: The geographical Longitude coordinate represented in Decimal Degrees (DD). For example: -71.057083.
  • Source: geoip.longitude
  • Transform:
  • geoip.longitude → double (workflow_create, workflow_delete, workflow_update)
  • Usage: workflow_create, workflow_delete, workflow_update
src_endpoint.location.region
  • Description: The alphanumeric code that identifies the principal subdivision (e.g. province or state) of the country. For example, 'CH-VD' for the Canton of Vaud, Switzerland
  • Source: geoip.region_code
  • Usage: workflow_create, workflow_delete, workflow_update

Http Request

http_request.user_agent
  • Description: The request header that identifies the operating system and web browser.
  • Source: user_agent
  • Usage: workflow_create, workflow_delete, workflow_update

Observables

observables[].name
  • Description: The full name of the observable attribute. The name is a pointer/reference to an attribute within the OCSF event data. For example: file.name. Array attributes may be represented in one of three ways. For example: resources.uid, resources[].uid, resources[0].uid.
  • Literal: actor.user.uid, http_request.user_agent, src_endpoint.ip, src_endpoint.location.country
  • Usage: all events in this service
observables[].type_id
  • Description: The observable value type identifier.
  • Literal: 14, 16, 2, 31
  • Usage: all events in this service
observables[].value
  • Description: The value associated with the observable attribute. The meaning of the value depends on the observable type.
    If the name refers to a scalar attribute, then the value is the value of the attribute.
    If the name refers to an object attribute, then the value is not populated.
  • Source: client_ip, geoip.country_code, initiated_by.id, user_agent
  • Usage: all events in this service

Other

job.run_state
  • Description: The run state of the job.
  • Source: resource.status
  • Usage: workflow_run, workflow_run_rate_limited

Unmapped

unmapped.@version
  • Description: JumpCloud Directory Insights field @version preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: @version
  • Usage: all events in this service
unmapped.asn.network
  • Description: JumpCloud Directory Insights field asn.network preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: asn.network
  • Usage: workflow_create, workflow_delete
unmapped.client_ip
  • Description: JumpCloud Directory Insights field client_ip preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: client_ip
  • Usage: workflow_run, workflow_run_rate_limited
unmapped.geoip.region_name
  • Description: JumpCloud Directory Insights field geoip.region_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.region_name
  • Usage: workflow_create, workflow_delete, workflow_update
unmapped.geoip.timezone
  • Description: JumpCloud Directory Insights field geoip.timezone preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: geoip.timezone
  • Usage: workflow_create, workflow_delete, workflow_update
unmapped.initiated_by_id_hash
  • Description: JumpCloud Directory Insights field initiated_by_id_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: initiated_by_id_hash
  • Usage: all events in this service
unmapped.is_out_of_bound
  • Description: JumpCloud Directory Insights field is_out_of_bound preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: is_out_of_bound
  • Usage: all events in this service
unmapped.jc_application_name
  • Description: JumpCloud Directory Insights field jc_application_name preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_application_name
  • Usage: all events in this service
unmapped.jc_transformation_ts
  • Description: JumpCloud Directory Insights field jc_transformation_ts preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: jc_transformation_ts
  • Usage: all events in this service
unmapped.resource.id
  • Description: JumpCloud Directory Insights field resource.id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.id
  • Usage: workflow_run, workflow_run_rate_limited
unmapped.resource.meta_data.event_id
  • Description: JumpCloud Directory Insights field resource.meta_data.event_id preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.meta_data.event_id
  • Usage: workflow_run
unmapped.resource.meta_data.event_type
  • Description: JumpCloud Directory Insights field resource.meta_data.event_type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.meta_data.event_type
  • Usage: workflow_run
unmapped.resource.meta_data.trigger_source
  • Description: JumpCloud Directory Insights field resource.meta_data.trigger_source preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.meta_data.trigger_source
  • Usage: workflow_run, workflow_run_rate_limited
unmapped.resource.type
  • Description: JumpCloud Directory Insights field resource.type preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource.type
  • Usage: workflow_run, workflow_run_rate_limited
unmapped.resource_id_hash
  • Description: JumpCloud Directory Insights field resource_id_hash preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: resource_id_hash
  • Usage: all events in this service
unmapped.timestamp_source
  • Description: JumpCloud Directory Insights field timestamp_source preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: timestamp_source
  • Usage: all events in this service
unmapped.user_agent
  • Description: JumpCloud Directory Insights field user_agent preserved in the OCSF unmapped object (no dedicated OCSF mapping).
  • Source: user_agent
  • Usage: workflow_run, workflow_run_rate_limited