All 551 events with OCSF mappings, grouped by Directory Insights service — same layout as the Directory Insights API event-type lists.
Services#
- Access Management — 7 events
- AI Admin — 6 events
- AI Gateway — 3 events
- Alerts — 8 events
- Asset Management — 9 events
- Directory — Command and Policy Events — 35 events
- Directory — Integrations — 56 events
- Directory — MTP/MSP Events — 29 events
- Directory — Object Events — 46 events
- Directory — User and Admin Events — 98 events
- GenAI — 12 events
- Generic Directory Insights — 2 events
- LDAP — 2 events
- MDM — 11 events
- Notifications — 8 events
- Object Storage — 4 events
- Password Manager — 72 events
- Password Vault — 47 events
- RADIUS — 1 event
- Reports — 13 events
- SaaS Management — 16 events
- Slack Integration — 2 events
- Software — 7 events
- SSO — 1 event
- Systems — 51 events
- Workflow — 5 events
Access Management#
access_management · 7 events
| Event | Category | Class | Activity | Type UID | Fields |
|---|---|---|---|---|---|
access_management_access_request |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 73 |
access_management_access_request_approval |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 80 |
access_management_access_request_settings_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 74 |
access_management_approval_flow_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 83 |
access_management_approval_flow_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 74 |
access_management_approval_flow_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 74 |
access_management_association_change |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 82 |
OCSF field mappings#
Legend
- Description: what the OCSF field represents (from OCSF schema v1.8.0)
- Source: raw JumpCloud event field(s) mapped via
${{placeholder}}template - Transform:
fieldMappingsentry applied at runtime (cast, enum, etc.) - Literal: static value set in the mapping template
- Usage: event types in this service that include this field
Core
activity_id
- Description: The normalized identifier of the activity that triggered the event.
- Literal:
1,3,4 - Usage: all events in this service
activity_name
- Description: The event activity name, as defined by the activity_id.
- Literal:
Create,Delete,Update - Usage: all events in this service
category_name
- Description: The event category name, as defined by category_uid value:
Discovery. - Literal:
Identity & Access Management - Usage: all events in this service
category_uid
- Description: The category unique identifier of the event.
- Literal:
3 - Usage: all events in this service
class_name
- Description: The event class name, as defined by class_uid value:
User Inventory Info. - Literal:
Entity Management - Usage: all events in this service
class_uid
- Description: The unique identifier of a class. A class describes the attributes available in an event.
- Literal:
3004 - Usage: all events in this service
severity_id
- Description: OCSF severity identifier for the event.
- Literal:
1 - Usage: all events in this service
status_detail
- Description: The status detail contains additional information about the event/finding outcome.
- Source:
error_message - Usage: all events in this service
status_id
- Description: Normalized status of the activity (1=Success, 2=Failure).
- Source:
success - Transform:
success→boolean_to_status_id; true→1, false→2 (all events in this service)- Usage: all events in this service
time
- Description: Event time, in epoch milliseconds (OCSF
time). - Source:
timestamp - Transform:
timestamp→iso8601_to_epoch_millis(all events in this service)- Usage: all events in this service
type_uid
- Description: The event/finding type ID. It identifies the event's semantics and structure. The value is calculated by the logging system as:
class_uid * 100 + activity_id. - Literal:
300401,300403,300404 - Usage: all events in this service
Metadata
metadata.event_code
- Description: JumpCloud event type code.
- Source:
event_type - Usage: all events in this service
metadata.original_time
- Description: The original event time as reported by the event source. For example, the time in the original format from system event log such as Syslog on Unix/Linux and the System event file on Windows. Omit if event is generated instead of collected via logs.
- Source:
server_timestamp - Usage: all events in this service
metadata.product.name
- Description: Originating JumpCloud service that produced the event.
- Source:
service - Usage: all events in this service
metadata.tenant_uid
- Description: JumpCloud organization (tenant) identifier.
- Source:
organization - Usage: all events in this service
metadata.uid
- Description: Unique event identifier assigned by JumpCloud.
- Source:
id - Usage: all events in this service
metadata.version
- Description: OCSF schema version used for this event.
- Literal:
1.8.0 - Usage: all events in this service
Actor
actor.user.email_addr
- Description: Email address of the actor who initiated the event.
- Source:
initiated_by.email - Usage: access_management_access_request_approval, access_management_access_request_settings_update, access_management_approval_flow_create, access_management_approval_flow_delete, access_management_approval_flow_update, access_management_association_change
actor.user.name
- Description: Display name of the actor who initiated the event.
- Source:
initiated_by.name,initiated_by.username - Usage: access_management_access_request, access_management_access_request_approval, access_management_approval_flow_create
actor.user.type_id
- Description: OCSF user type of the actor (1=User, 2=Admin, 3=System, 4=Service).
- Source:
initiated_by.type - Transform:
initiated_by.type→enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (all events in this service)- Usage: all events in this service
actor.user.uid
- Description: Unique identifier of the actor who initiated the event.
- Source:
initiated_by.id - Usage: all events in this service
Entity
entity.data.access_request_id
- Description: JumpCloud extension data on the managed entity:
access_request_id. - Source:
access_request_id - Usage: access_management_access_request_approval, access_management_association_change
entity.data.association_attributes
- Description: JumpCloud extension data on the managed entity:
association_attributes. - Source:
association.attributes - Usage: access_management_association_change
entity.data.association_from_name
- Description: JumpCloud extension data on the managed entity:
association_from_name. - Source:
association.connection.from.name - Usage: access_management_association_change
entity.data.association_from_object_id
- Description: JumpCloud extension data on the managed entity:
association_from_object_id. - Source:
association.connection.from.object_id - Usage: access_management_association_change
entity.data.association_from_type
- Description: JumpCloud extension data on the managed entity:
association_from_type. - Source:
association.connection.from.type - Usage: access_management_association_change
entity.data.association_op
- Description: JumpCloud extension data on the managed entity:
association_op. - Source:
association.op - Usage: access_management_association_change
entity.data.association_to_name
- Description: JumpCloud extension data on the managed entity:
association_to_name. - Source:
association.connection.to.name - Usage: access_management_association_change
entity.data.association_to_object_id
- Description: JumpCloud extension data on the managed entity:
association_to_object_id. - Source:
association.connection.to.object_id - Usage: access_management_association_change
entity.data.association_to_type
- Description: JumpCloud extension data on the managed entity:
association_to_type. - Source:
association.connection.to.type - Usage: access_management_association_change
entity.data.changed_field
- Description: JumpCloud extension data on the managed entity:
changed_field. - Source:
changes.field - Usage: all events in this service
entity.data.changes_from
- Description: JumpCloud extension data on the managed entity:
changes_from. - Source:
changes.from - Usage: access_management_access_request, access_management_access_request_approval, access_management_access_request_settings_update, access_management_approval_flow_create, access_management_approval_flow_delete, access_management_association_change
entity.data.changes_from_LdapGroups_name
- Description: JumpCloud extension data on the managed entity:
changes_from_LdapGroups_name. - Source:
changes.from.LdapGroups.name - Usage: access_management_approval_flow_update
entity.data.initiated_from_slack_app_id
- Description: JumpCloud extension data on the managed entity:
initiated_from_slack_app_id. - Source:
initiated_from.slack.app_id - Usage: access_management_access_request_approval
entity.data.initiated_from_slack_source
- Description: JumpCloud extension data on the managed entity:
initiated_from_slack_source. - Source:
initiated_from.slack.source - Usage: access_management_access_request_approval
entity.data.initiated_from_slack_team_id
- Description: JumpCloud extension data on the managed entity:
initiated_from_slack_team_id. - Source:
initiated_from.slack.team_id - Usage: access_management_access_request_approval
entity.data.initiated_from_slack_user_id
- Description: JumpCloud extension data on the managed entity:
initiated_from_slack_user_id. - Source:
initiated_from.slack.user_id - Usage: access_management_access_request_approval
entity.data.resource_id
- Description: JumpCloud extension data on the managed entity:
resource_id. - Source:
resource.id - Usage: access_management_access_request
entity.data.resource_type
- Description: JumpCloud extension data on the managed entity:
resource_type. - Source:
resource.type - Usage: access_management_access_request
entity.data.workflow.description
- Description: JumpCloud extension data on the managed entity:
workflow.description. - Source:
workflow.description - Usage: access_management_access_request, access_management_access_request_approval, access_management_approval_flow_create, access_management_approval_flow_delete, access_management_approval_flow_update, access_management_association_change
entity.data.workflow.id
- Description: JumpCloud extension data on the managed entity:
workflow.id. - Source:
workflow.id - Usage: access_management_access_request, access_management_access_request_approval, access_management_approval_flow_create, access_management_approval_flow_delete, access_management_approval_flow_update, access_management_association_change
entity.data.workflow.name
- Description: JumpCloud extension data on the managed entity:
workflow.name. - Source:
workflow.name - Usage: access_management_access_request, access_management_access_request_approval, access_management_approval_flow_create, access_management_approval_flow_delete, access_management_approval_flow_update, access_management_association_change
entity.data.workflow.type
- Description: JumpCloud extension data on the managed entity:
workflow.type. - Source:
workflow.type - Usage: access_management_access_request, access_management_access_request_approval, access_management_approval_flow_create, access_management_approval_flow_delete, access_management_approval_flow_update, access_management_association_change
entity.name
- Description: The name of the managed entity. It should match the name of the specific entity object's name if populated, or the name of the managed entity if the
type_idis 'Other'. - Source:
resource.name - Usage: access_management_access_request_settings_update, access_management_approval_flow_create, access_management_approval_flow_delete, access_management_approval_flow_update
entity.type
- Description: The managed entity type. For example:
Policy,User,Organization,Device. - Source:
resource.type - Usage: access_management_access_request_approval, access_management_access_request_settings_update, access_management_approval_flow_create, access_management_approval_flow_delete, access_management_approval_flow_update, access_management_association_change
entity.uid
- Description: The identifier of the managed entity. It should match the
uidof the specific entity's object UID if populated, or the source specific ID if thetype_idis 'Other'. - Source:
access_request_id,resource.id - Usage: all events in this service
entity_result.data.changes_to
- Description: JumpCloud extension data on the managed entity:
changes_to. - Source:
changes.to - Usage: access_management_access_request, access_management_access_request_approval, access_management_access_request_settings_update, access_management_association_change
entity_result.data.changes_to_LdapGroups_name
- Description: JumpCloud extension data on the managed entity:
changes_to_LdapGroups_name. - Source:
changes.to.LdapGroups.name - Usage: access_management_approval_flow_create, access_management_approval_flow_delete, access_management_approval_flow_update
Src Endpoint
src_endpoint.autonomous_system.name
- Description: Organization name for the Autonomous System.
- Source:
asn.organization - Usage: all events in this service
src_endpoint.autonomous_system.number
- Description: Unique number that the AS is identified by.
- Source:
asn.number - Transform:
asn.number→int(all events in this service)- Usage: all events in this service
src_endpoint.ip
- Description: Source IP address the request originated from.
- Source:
client_ip - Usage: all events in this service
src_endpoint.location.city
- Description: The name of the city.
- Source:
location.City.Name - Usage: all events in this service
src_endpoint.location.continent
- Description: The name of the continent.
- Source:
geoip.continent_code - Usage: all events in this service
src_endpoint.location.country
- Description: The ISO 3166-1 Alpha-2 country code.
Note: The two letter country code should be capitalized. For example:
USorCA. - Source:
location.Country.IsoCode - Usage: all events in this service
src_endpoint.location.lat
- Description: The geographical Latitude coordinate represented in Decimal Degrees (DD). For example:
42.361145. - Source:
geoip.latitude - Transform:
geoip.latitude→double(all events in this service)- Usage: all events in this service
src_endpoint.location.long
- Description: The geographical Longitude coordinate represented in Decimal Degrees (DD). For example:
-71.057083. - Source:
geoip.longitude - Transform:
geoip.longitude→double(all events in this service)- Usage: all events in this service
src_endpoint.location.region
- Description: The alphanumeric code that identifies the principal subdivision (e.g. province or state) of the country. For example, 'CH-VD' for the Canton of Vaud, Switzerland
- Source:
location.Subdivisions.IsoCode - Usage: all events in this service
Http Request
http_request.user_agent
- Description: The request header that identifies the operating system and web browser.
- Source:
user_agent - Usage: all events in this service
Observables
observables[].name
- Description: The full name of the observable attribute. The
nameis a pointer/reference to an attribute within the OCSF event data. For example:file.name. Array attributes may be represented in one of three ways. For example:resources.uid,resources[].uid,resources[0].uid. - Literal:
actor.user.email_addr,actor.user.name,actor.user.uid,http_request.user_agent,src_endpoint.ip,src_endpoint.location.country - Usage: all events in this service
observables[].type_id
- Description: The observable value type identifier.
- Literal:
14,16,2,31,4,5 - Usage: all events in this service
observables[].value
- Description: The value associated with the observable attribute. The meaning of the value depends on the observable type.
If thenamerefers to a scalar attribute, then thevalueis the value of the attribute.
If thenamerefers to an object attribute, then thevalueis not populated. - Source:
client_ip,geoip.country_code,initiated_by.email,initiated_by.id,initiated_by.name,initiated_by.username,location.Country.IsoCode,user_agent - Usage: all events in this service
Unmapped
unmapped.@timestamp
- Description: JumpCloud Directory Insights field
@timestamppreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
@timestamp - Usage: access_management_access_request, access_management_access_request_approval, access_management_access_request_settings_update, access_management_approval_flow_create, access_management_association_change
unmapped.@version
- Description: JumpCloud Directory Insights field
@versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
@version - Usage: all events in this service
unmapped.asn.network
- Description: JumpCloud Directory Insights field
asn.networkpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
asn.network - Usage: all events in this service
unmapped.file_input_timestamp
- Description: JumpCloud Directory Insights field
file_input_timestamppreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
file_input_timestamp - Usage: access_management_access_request, access_management_access_request_approval, access_management_access_request_settings_update, access_management_approval_flow_create, access_management_association_change
unmapped.geoip.region_name
- Description: JumpCloud Directory Insights field
geoip.region_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.region_name - Usage: all events in this service
unmapped.geoip.timezone
- Description: JumpCloud Directory Insights field
geoip.timezonepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.timezone - Usage: all events in this service
unmapped.initiated_by.source_metadata.workflow.id
- Description: JumpCloud Directory Insights field
initiated_by.source_metadata.workflow.idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by.source_metadata.workflow.id - Usage: access_management_approval_flow_create
unmapped.initiated_by.source_metadata.workflow.run_id
- Description: JumpCloud Directory Insights field
initiated_by.source_metadata.workflow.run_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by.source_metadata.workflow.run_id - Usage: access_management_approval_flow_create
unmapped.initiated_by.source_metadata.workflow.type
- Description: JumpCloud Directory Insights field
initiated_by.source_metadata.workflow.typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by.source_metadata.workflow.type - Usage: access_management_approval_flow_create
unmapped.initiated_by_email_hash
- Description: JumpCloud Directory Insights field
initiated_by_email_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_email_hash - Usage: access_management_access_request_approval, access_management_access_request_settings_update, access_management_approval_flow_create, access_management_approval_flow_delete, access_management_approval_flow_update, access_management_association_change
unmapped.initiated_by_id_hash
- Description: JumpCloud Directory Insights field
initiated_by_id_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_id_hash - Usage: all events in this service
unmapped.initiated_by_name_hash
- Description: JumpCloud Directory Insights field
initiated_by_name_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_name_hash - Usage: access_management_approval_flow_create
unmapped.initiated_by_username_hash
- Description: JumpCloud Directory Insights field
initiated_by_username_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_username_hash - Usage: access_management_access_request, access_management_access_request_approval
unmapped.is_out_of_bound
- Description: JumpCloud Directory Insights field
is_out_of_boundpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
is_out_of_bound - Usage: all events in this service
unmapped.jc_application_name
- Description: JumpCloud Directory Insights field
jc_application_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_application_name - Usage: all events in this service
unmapped.jc_index_name
- Description: JumpCloud Directory Insights field
jc_index_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_index_name - Usage: access_management_access_request_approval, access_management_association_change
unmapped.jc_initiated_by_email
- Description: JumpCloud Directory Insights field
jc_initiated_by_emailpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_initiated_by_email - Usage: access_management_access_request_settings_update, access_management_approval_flow_create, access_management_approval_flow_delete, access_management_approval_flow_update
unmapped.jc_initiated_by_username
- Description: JumpCloud Directory Insights field
jc_initiated_by_usernamepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_initiated_by_username - Usage: access_management_access_request_settings_update, access_management_approval_flow_create, access_management_approval_flow_delete, access_management_approval_flow_update
unmapped.jc_organization_name
- Description: JumpCloud Directory Insights field
jc_organization_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_organization_name - Usage: access_management_access_request_settings_update, access_management_approval_flow_create, access_management_approval_flow_delete, access_management_approval_flow_update
unmapped.jc_provider_id
- Description: JumpCloud Directory Insights field
jc_provider_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_provider_id - Usage: access_management_access_request_settings_update, access_management_approval_flow_create, access_management_approval_flow_delete, access_management_approval_flow_update
unmapped.jc_transformation_ts
- Description: JumpCloud Directory Insights field
jc_transformation_tspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_transformation_ts - Usage: all events in this service
unmapped.location.Country.Name
- Description: JumpCloud Directory Insights field
location.Country.Namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
location.Country.Name - Usage: all events in this service
unmapped.location.Subdivisions.Name
- Description: JumpCloud Directory Insights field
location.Subdivisions.Namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
location.Subdivisions.Name - Usage: all events in this service
unmapped.pid
- Description: JumpCloud Directory Insights field
pidpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
pid - Usage: all events in this service
unmapped.provider
- Description: JumpCloud Directory Insights field
providerpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
provider - Usage: access_management_access_request_settings_update, access_management_approval_flow_create
unmapped.resource_id_hash
- Description: JumpCloud Directory Insights field
resource_id_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource_id_hash - Usage: access_management_access_request, access_management_access_request_approval, access_management_approval_flow_create, access_management_approval_flow_delete, access_management_approval_flow_update, access_management_association_change
unmapped.tags
- Description: JumpCloud Directory Insights field
tagspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
tags - Usage: access_management_access_request, access_management_access_request_approval, access_management_access_request_settings_update, access_management_approval_flow_create, access_management_association_change
unmapped.timestamp_source
- Description: JumpCloud Directory Insights field
timestamp_sourcepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
timestamp_source - Usage: all events in this service
unmapped.useragent.device
- Description: JumpCloud Directory Insights field
useragent.devicepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.device - Usage: all events in this service
unmapped.useragent.major
- Description: JumpCloud Directory Insights field
useragent.majorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.major - Usage: all events in this service
unmapped.useragent.minor
- Description: JumpCloud Directory Insights field
useragent.minorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.minor - Usage: all events in this service
unmapped.useragent.name
- Description: JumpCloud Directory Insights field
useragent.namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.name - Usage: all events in this service
unmapped.useragent.os
- Description: JumpCloud Directory Insights field
useragent.ospreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os - Usage: all events in this service
unmapped.useragent.os_full
- Description: JumpCloud Directory Insights field
useragent.os_fullpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_full - Usage: all events in this service
unmapped.useragent.os_major
- Description: JumpCloud Directory Insights field
useragent.os_majorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_major - Usage: all events in this service
unmapped.useragent.os_minor
- Description: JumpCloud Directory Insights field
useragent.os_minorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_minor - Usage: all events in this service
unmapped.useragent.os_name
- Description: JumpCloud Directory Insights field
useragent.os_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_name - Usage: all events in this service
unmapped.useragent.os_patch
- Description: JumpCloud Directory Insights field
useragent.os_patchpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_patch - Usage: all events in this service
unmapped.useragent.os_version
- Description: JumpCloud Directory Insights field
useragent.os_versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_version - Usage: all events in this service
unmapped.useragent.patch
- Description: JumpCloud Directory Insights field
useragent.patchpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.patch - Usage: all events in this service
unmapped.useragent.version
- Description: JumpCloud Directory Insights field
useragent.versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.version - Usage: all events in this service
unmapped.workflow
- Description: JumpCloud Directory Insights field
workflowpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
workflow - Usage: access_management_access_request_settings_update
AI Admin#
ai_admin · 6 events
| Event | Category | Class | Activity | Type UID | Fields |
|---|---|---|---|---|---|
redirect_uri_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 54 |
redirect_uri_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 56 |
redirect_uri_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 60 |
server_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 63 |
server_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 58 |
server_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 68 |
OCSF field mappings#
Legend
- Description: what the OCSF field represents (from OCSF schema v1.8.0)
- Source: raw JumpCloud event field(s) mapped via
${{placeholder}}template - Transform:
fieldMappingsentry applied at runtime (cast, enum, etc.) - Literal: static value set in the mapping template
- Usage: event types in this service that include this field
Core
activity_id
- Description: The normalized identifier of the activity that triggered the event.
- Literal:
1,3,4 - Usage: all events in this service
activity_name
- Description: The event activity name, as defined by the activity_id.
- Literal:
Create,Delete,Update - Usage: all events in this service
category_name
- Description: The event category name, as defined by category_uid value:
Discovery. - Literal:
Identity & Access Management - Usage: all events in this service
category_uid
- Description: The category unique identifier of the event.
- Literal:
3 - Usage: all events in this service
class_name
- Description: The event class name, as defined by class_uid value:
User Inventory Info. - Literal:
Entity Management - Usage: all events in this service
class_uid
- Description: The unique identifier of a class. A class describes the attributes available in an event.
- Literal:
3004 - Usage: all events in this service
severity_id
- Description: OCSF severity identifier for the event.
- Literal:
1 - Usage: all events in this service
status_id
- Description: Normalized status of the activity (1=Success, 2=Failure).
- Source:
success - Transform:
success→boolean_to_status_id; true→1, false→2 (all events in this service)- Usage: all events in this service
time
- Description: Event time, in epoch milliseconds (OCSF
time). - Source:
timestamp - Transform:
timestamp→iso8601_to_epoch_millis(all events in this service)- Usage: all events in this service
type_uid
- Description: The event/finding type ID. It identifies the event's semantics and structure. The value is calculated by the logging system as:
class_uid * 100 + activity_id. - Literal:
300401,300403,300404 - Usage: all events in this service
Metadata
metadata.event_code
- Description: JumpCloud event type code.
- Source:
event_type - Usage: all events in this service
metadata.product.name
- Description: Originating JumpCloud service that produced the event.
- Source:
service - Usage: all events in this service
metadata.tenant_uid
- Description: JumpCloud organization (tenant) identifier.
- Source:
organization - Usage: all events in this service
metadata.uid
- Description: Unique event identifier assigned by JumpCloud.
- Source:
id - Usage: all events in this service
metadata.version
- Description: OCSF schema version used for this event.
- Literal:
1.8.0 - Usage: all events in this service
Actor
actor.user.email_addr
- Description: Email address of the actor who initiated the event.
- Source:
initiated_by.email - Usage: all events in this service
actor.user.type_id
- Description: OCSF user type of the actor (1=User, 2=Admin, 3=System, 4=Service).
- Source:
initiated_by.type - Transform:
initiated_by.type→enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (all events in this service)- Usage: all events in this service
actor.user.uid
- Description: Unique identifier of the actor who initiated the event.
- Source:
initiated_by.id - Usage: all events in this service
Entity
entity.data.application_id
- Description: JumpCloud extension data on the managed entity:
application_id. - Source:
resource.application_id - Usage: server_create, server_update
entity.data.auth_config.api_token
- Description: JumpCloud extension data on the managed entity:
auth_config.api_token. - Source:
resource.auth_config.api_token - Usage: server_create, server_update
entity.data.auth_config.oauth.client_id
- Description: JumpCloud extension data on the managed entity:
auth_config.oauth.client_id. - Source:
resource.auth_config.oauth.client_id - Usage: server_create, server_update
entity.data.auth_config.oauth.client_secret
- Description: JumpCloud extension data on the managed entity:
auth_config.oauth.client_secret. - Source:
resource.auth_config.oauth.client_secret - Usage: server_update
entity.data.auth_config.oauth.client_secret_hint
- Description: JumpCloud extension data on the managed entity:
auth_config.oauth.client_secret_hint. - Source:
resource.auth_config.oauth.client_secret_hint - Usage: server_create, server_update
entity.data.auth_config.oauth.scope
- Description: JumpCloud extension data on the managed entity:
auth_config.oauth.scope. - Source:
resource.auth_config.oauth.scope - Usage: server_create, server_update
entity.data.auth_method
- Description: JumpCloud extension data on the managed entity:
auth_method. - Source:
auth_method - Usage: all events in this service
entity.data.changed_field
- Description: JumpCloud extension data on the managed entity:
changed_field. - Source:
changes.field - Usage: redirect_uri_delete, redirect_uri_update, server_delete, server_update
entity.data.changes_from
- Description: JumpCloud extension data on the managed entity:
changes_from. - Source:
changes.from - Usage: redirect_uri_delete, redirect_uri_update, server_update
entity.data.changes_from_api_token
- Description: JumpCloud extension data on the managed entity:
changes_from_api_token. - Source:
changes.from.api_token - Usage: server_delete
entity.data.changes_from_oauth
- Description: JumpCloud extension data on the managed entity:
changes_from_oauth. - Source:
changes.from.oauth - Usage: server_delete
entity.data.description
- Description: JumpCloud extension data on the managed entity:
description. - Source:
resource.description - Usage: redirect_uri_update
entity.data.prefix
- Description: JumpCloud extension data on the managed entity:
prefix. - Source:
resource.prefix - Usage: server_create, server_update
entity.data.target_url
- Description: JumpCloud extension data on the managed entity:
target_url. - Source:
resource.target_url - Usage: server_create, server_update
entity.data.uri
- Description: JumpCloud extension data on the managed entity:
uri. - Source:
resource.uri - Usage: redirect_uri_create, redirect_uri_update
entity.name
- Description: The name of the managed entity. It should match the name of the specific entity object's name if populated, or the name of the managed entity if the
type_idis 'Other'. - Source:
resource.name - Usage: redirect_uri_update, server_create, server_update
entity.org.uid
- Description: The unique identifier of the organization, Oracle Cloud Tenancy, Google Cloud Organization, or AWS Organization. For example, an
AWS Org IDorOracle Cloud Domain ID. - Source:
resource.organization_id - Usage: all events in this service
entity.uid
- Description: The identifier of the managed entity. It should match the
uidof the specific entity's object UID if populated, or the source specific ID if thetype_idis 'Other'. - Source:
resource.id - Usage: all events in this service
entity_result.data.changes_to
- Description: JumpCloud extension data on the managed entity:
changes_to. - Source:
changes.to - Usage: redirect_uri_delete, redirect_uri_update, server_delete
entity_result.data.changes_to_client_id
- Description: JumpCloud extension data on the managed entity:
changes_to_client_id. - Source:
changes.to.client_id - Usage: server_update
entity_result.data.changes_to_client_secret_hint
- Description: JumpCloud extension data on the managed entity:
changes_to_client_secret_hint. - Source:
changes.to.client_secret_hint - Usage: server_update
entity_result.data.changes_to_scope
- Description: JumpCloud extension data on the managed entity:
changes_to_scope. - Source:
changes.to.scope - Usage: server_update
Src Endpoint
src_endpoint.ip
- Description: Source IP address the request originated from.
- Source:
client_ip - Usage: all events in this service
src_endpoint.location.city
- Description: The name of the city.
- Source:
geoip.city - Usage: all events in this service
src_endpoint.location.continent
- Description: The name of the continent.
- Source:
geoip.continent_code - Usage: all events in this service
src_endpoint.location.country
- Description: The ISO 3166-1 Alpha-2 country code.
Note: The two letter country code should be capitalized. For example:
USorCA. - Source:
geoip.country_code - Usage: all events in this service
src_endpoint.location.lat
- Description: The geographical Latitude coordinate represented in Decimal Degrees (DD). For example:
42.361145. - Source:
geoip.latitude - Transform:
geoip.latitude→double(all events in this service)- Usage: all events in this service
src_endpoint.location.long
- Description: The geographical Longitude coordinate represented in Decimal Degrees (DD). For example:
-71.057083. - Source:
geoip.longitude - Transform:
geoip.longitude→double(all events in this service)- Usage: all events in this service
src_endpoint.location.region
- Description: The alphanumeric code that identifies the principal subdivision (e.g. province or state) of the country. For example, 'CH-VD' for the Canton of Vaud, Switzerland
- Source:
geoip.region_code - Usage: all events in this service
Http Request
http_request.user_agent
- Description: The request header that identifies the operating system and web browser.
- Source:
useragent.raw - Usage: all events in this service
Observables
observables[].name
- Description: The full name of the observable attribute. The
nameis a pointer/reference to an attribute within the OCSF event data. For example:file.name. Array attributes may be represented in one of three ways. For example:resources.uid,resources[].uid,resources[0].uid. - Literal:
actor.user.email_addr,actor.user.uid,http_request.user_agent,src_endpoint.ip,src_endpoint.location.country - Usage: all events in this service
observables[].type_id
- Description: The observable value type identifier.
- Literal:
14,16,2,31,5 - Usage: all events in this service
observables[].value
- Description: The value associated with the observable attribute. The meaning of the value depends on the observable type.
If thenamerefers to a scalar attribute, then thevalueis the value of the attribute.
If thenamerefers to an object attribute, then thevalueis not populated. - Source:
client_ip,geoip.country_code,initiated_by.email,initiated_by.id,useragent.raw - Usage: all events in this service
Unmapped
unmapped.changes
- Description: JumpCloud Directory Insights field
changespreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes - Usage: redirect_uri_create, server_create
unmapped.geoip.region_name
- Description: JumpCloud Directory Insights field
geoip.region_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.region_name - Usage: all events in this service
unmapped.geoip.timezone
- Description: JumpCloud Directory Insights field
geoip.timezonepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.timezone - Usage: all events in this service
unmapped.initiated_by.source
- Description: JumpCloud Directory Insights field
initiated_by.sourcepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by.source - Usage: all events in this service
unmapped.initiated_by.source_metadata
- Description: JumpCloud Directory Insights field
initiated_by.source_metadatapreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by.source_metadata - Usage: all events in this service
unmapped.is_out_of_bound
- Description: JumpCloud Directory Insights field
is_out_of_boundpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
is_out_of_bound - Usage: all events in this service
unmapped.jc_organization_name
- Description: JumpCloud Directory Insights field
jc_organization_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_organization_name - Usage: redirect_uri_update, server_create, server_delete, server_update
unmapped.jc_provider_id
- Description: JumpCloud Directory Insights field
jc_provider_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_provider_id - Usage: server_create, server_delete, server_update
unmapped.jc_transformation_ts
- Description: JumpCloud Directory Insights field
jc_transformation_tspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_transformation_ts - Usage: all events in this service
unmapped.jcdataprevious
- Description: JumpCloud Directory Insights field
jcdatapreviouspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jcdataprevious - Usage: redirect_uri_delete, redirect_uri_update
unmapped.provider
- Description: JumpCloud Directory Insights field
providerpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
provider - Usage: all events in this service
unmapped.useragent.device
- Description: JumpCloud Directory Insights field
useragent.devicepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.device - Usage: all events in this service
unmapped.useragent.major
- Description: JumpCloud Directory Insights field
useragent.majorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.major - Usage: all events in this service
unmapped.useragent.minor
- Description: JumpCloud Directory Insights field
useragent.minorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.minor - Usage: all events in this service
unmapped.useragent.name
- Description: JumpCloud Directory Insights field
useragent.namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.name - Usage: all events in this service
unmapped.useragent.os
- Description: JumpCloud Directory Insights field
useragent.ospreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os - Usage: all events in this service
unmapped.useragent.os_full
- Description: JumpCloud Directory Insights field
useragent.os_fullpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_full - Usage: all events in this service
unmapped.useragent.os_major
- Description: JumpCloud Directory Insights field
useragent.os_majorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_major - Usage: all events in this service
unmapped.useragent.os_minor
- Description: JumpCloud Directory Insights field
useragent.os_minorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_minor - Usage: all events in this service
unmapped.useragent.os_name
- Description: JumpCloud Directory Insights field
useragent.os_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_name - Usage: all events in this service
unmapped.useragent.os_patch
- Description: JumpCloud Directory Insights field
useragent.os_patchpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_patch - Usage: all events in this service
unmapped.useragent.os_version
- Description: JumpCloud Directory Insights field
useragent.os_versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_version - Usage: all events in this service
unmapped.useragent.patch
- Description: JumpCloud Directory Insights field
useragent.patchpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.patch - Usage: all events in this service
unmapped.useragent.version
- Description: JumpCloud Directory Insights field
useragent.versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.version - Usage: all events in this service
AI Gateway#
aigw · 3 events
| Event | Category | Class | Activity | Type UID | Fields |
|---|---|---|---|---|---|
aigw_session_activity |
Application Activity (6) | API Activity (6003) | Read (2) | 600302 | 54 |
aigw_session_closed |
Identity & Access Management (3) | Authentication (3002) | Logoff (2) | 300202 | 55 |
aigw_session_opened |
Identity & Access Management (3) | Authentication (3002) | Logon (1) | 300201 | 57 |
OCSF field mappings#
Legend
- Description: what the OCSF field represents (from OCSF schema v1.8.0)
- Source: raw JumpCloud event field(s) mapped via
${{placeholder}}template - Transform:
fieldMappingsentry applied at runtime (cast, enum, etc.) - Literal: static value set in the mapping template
- Usage: event types in this service that include this field
Core
activity_id
- Description: The normalized identifier of the activity that triggered the event.
- Literal:
1,2 - Usage: all events in this service
activity_name
- Description: The event activity name, as defined by the activity_id.
- Literal:
Logoff,Logon,Read - Usage: all events in this service
category_name
- Description: The event category name, as defined by category_uid value:
Discovery. - Literal:
Application Activity,Identity & Access Management - Usage: all events in this service
category_uid
- Description: The category unique identifier of the event.
- Literal:
3,6 - Usage: all events in this service
class_name
- Description: The event class name, as defined by class_uid value:
User Inventory Info. - Literal:
API Activity,Authentication - Usage: all events in this service
class_uid
- Description: The unique identifier of a class. A class describes the attributes available in an event.
- Literal:
3002,6003 - Usage: all events in this service
severity_id
- Description: OCSF severity identifier for the event.
- Literal:
1 - Usage: all events in this service
status_detail
- Description: The status detail contains additional information about the event/finding outcome.
- Source:
aigw_detail.outcome - Usage: aigw_session_activity
status_id
- Description: Normalized status of the activity (1=Success, 2=Failure).
- Source:
success - Transform:
success→boolean_to_status_id; true→1, false→2 (all events in this service)- Usage: all events in this service
time
- Description: Event time, in epoch milliseconds (OCSF
time). - Source:
timestamp - Usage: all events in this service
type_uid
- Description: The event/finding type ID. It identifies the event's semantics and structure. The value is calculated by the logging system as:
class_uid * 100 + activity_id. - Literal:
300201,300202,600302 - Usage: all events in this service
Metadata
metadata.event_code
- Description: JumpCloud event type code.
- Source:
event_type - Usage: all events in this service
metadata.processed_time
- Description: The event processed time, such as an ETL operation.
- Source:
jc_transformation_ts - Usage: all events in this service
metadata.product.name
- Description: Originating JumpCloud service that produced the event.
- Source:
service - Usage: all events in this service
metadata.tenant_uid
- Description: JumpCloud organization (tenant) identifier.
- Source:
organization - Usage: all events in this service
metadata.uid
- Description: Unique event identifier assigned by JumpCloud.
- Source:
id - Usage: all events in this service
metadata.version
- Description: OCSF schema version used for this event.
- Literal:
1.8.0 - Usage: all events in this service
Actor
actor.user.email_addr
- Description: Email address of the actor who initiated the event.
- Source:
initiated_by.email - Usage: aigw_session_activity
actor.user.type_id
- Description: OCSF user type of the actor (1=User, 2=Admin, 3=System, 4=Service).
- Source:
initiated_by.type - Usage: aigw_session_activity
actor.user.uid
- Description: Unique identifier of the actor who initiated the event.
- Source:
initiated_by.id - Usage: aigw_session_activity
User
user.email_addr
- Description: Email address of the user associated with the event.
- Source:
initiated_by.email - Usage: aigw_session_closed, aigw_session_opened
user.type_id
- Description: OCSF user type (1=User, 2=Admin, 3=System, 4=Service).
- Source:
initiated_by.type - Usage: aigw_session_closed, aigw_session_opened
user.uid
- Description: Unique identifier of the user associated with the event.
- Source:
initiated_by.id - Usage: aigw_session_closed, aigw_session_opened
Src Endpoint
src_endpoint.autonomous_system.name
- Description: Organization name for the Autonomous System.
- Source:
asn.organization - Usage: aigw_session_closed, aigw_session_opened
src_endpoint.autonomous_system.number
- Description: Unique number that the AS is identified by.
- Source:
asn.number - Transform:
asn.number→int(aigw_session_closed, aigw_session_opened)- Usage: aigw_session_closed, aigw_session_opened
src_endpoint.ip
- Description: Source IP address the request originated from.
- Source:
client_ip - Usage: all events in this service
src_endpoint.location.city
- Description: The name of the city.
- Source:
geoip.city - Usage: all events in this service
src_endpoint.location.continent
- Description: The name of the continent.
- Source:
geoip.continent_code - Usage: all events in this service
src_endpoint.location.country
- Description: The ISO 3166-1 Alpha-2 country code.
Note: The two letter country code should be capitalized. For example:
USorCA. - Source:
geoip.country_code - Usage: all events in this service
src_endpoint.location.lat
- Description: The geographical Latitude coordinate represented in Decimal Degrees (DD). For example:
42.361145. - Source:
geoip.latitude - Transform:
geoip.latitude→double(all events in this service)- Usage: all events in this service
src_endpoint.location.long
- Description: The geographical Longitude coordinate represented in Decimal Degrees (DD). For example:
-71.057083. - Source:
geoip.longitude - Transform:
geoip.longitude→double(all events in this service)- Usage: all events in this service
src_endpoint.location.region
- Description: The alphanumeric code that identifies the principal subdivision (e.g. province or state) of the country. For example, 'CH-VD' for the Canton of Vaud, Switzerland
- Source:
geoip.region_code - Usage: all events in this service
Http Request
http_request.user_agent
- Description: The request header that identifies the operating system and web browser.
- Source:
useragent.raw - Usage: all events in this service
Observables
observables[].name
- Description: The full name of the observable attribute. The
nameis a pointer/reference to an attribute within the OCSF event data. For example:file.name. Array attributes may be represented in one of three ways. For example:resources.uid,resources[].uid,resources[0].uid. - Literal:
actor.user.email_addr,actor.user.uid,http_request.user_agent,src_endpoint.ip,src_endpoint.location.country,user.email_addr,user.uid - Usage: all events in this service
observables[].type_id
- Description: The observable value type identifier.
- Literal:
14,16,2,31,5 - Usage: all events in this service
observables[].value
- Description: The value associated with the observable attribute. The meaning of the value depends on the observable type.
If thenamerefers to a scalar attribute, then thevalueis the value of the attribute.
If thenamerefers to an object attribute, then thevalueis not populated. - Source:
client_ip,geoip.country_code,initiated_by.email,initiated_by.id,useragent.raw - Usage: all events in this service
Other
api.operation
- Description: Verb/Operation associated with the request
- Source:
aigw_detail.activity_kind - Usage: aigw_session_activity
api.request.uid
- Description: The unique request identifier.
- Source:
aigw_detail.mcp_session_id - Usage: aigw_session_activity
auth_protocol
- Description: The authentication protocol as defined by the caption of
auth_protocol_id. In the case ofOther, it is defined by the event source. - Source:
auth_method - Usage: aigw_session_closed, aigw_session_opened
duration
- Description: The event duration or aggregate time, the amount of time the event covers from
start_timetoend_timein milliseconds. - Source:
aigw_detail.duration_ms - Usage: aigw_session_activity, aigw_session_opened
session.expiration_reason
- Description: The reason which triggered the session expiration.
- Source:
aigw_detail.close_reason - Usage: aigw_session_closed
session.uid
- Description: The unique identifier of the session.
- Source:
aigw_detail.mcp_session_id - Usage: aigw_session_closed, aigw_session_opened
Unmapped
unmapped.@version
- Description: JumpCloud Directory Insights field
@versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
@version - Usage: all events in this service
unmapped.aigw_detail.backend_tool_name
- Description: JumpCloud Directory Insights field
aigw_detail.backend_tool_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
aigw_detail.backend_tool_name - Usage: aigw_session_activity
unmapped.aigw_detail.backends.name
- Description: JumpCloud Directory Insights field
aigw_detail.backends.namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
aigw_detail.backends.name - Usage: aigw_session_opened
unmapped.aigw_detail.backends.server_object_id
- Description: JumpCloud Directory Insights field
aigw_detail.backends.server_object_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
aigw_detail.backends.server_object_id - Usage: aigw_session_opened
unmapped.aigw_detail.server_object_id
- Description: JumpCloud Directory Insights field
aigw_detail.server_object_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
aigw_detail.server_object_id - Usage: aigw_session_activity
unmapped.aigw_detail.tool_name
- Description: JumpCloud Directory Insights field
aigw_detail.tool_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
aigw_detail.tool_name - Usage: aigw_session_activity
unmapped.aigw_detail.transport
- Description: JumpCloud Directory Insights field
aigw_detail.transportpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
aigw_detail.transport - Usage: aigw_session_opened
unmapped.asn.error
- Description: JumpCloud Directory Insights field
asn.errorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
asn.error - Usage: aigw_session_opened
unmapped.asn.ip_address
- Description: JumpCloud Directory Insights field
asn.ip_addresspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
asn.ip_address - Usage: aigw_session_opened
unmapped.asn.network
- Description: JumpCloud Directory Insights field
asn.networkpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
asn.network - Usage: aigw_session_closed, aigw_session_opened
unmapped.auth_method
- Description: JumpCloud Directory Insights field
auth_methodpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
auth_method - Usage: aigw_session_activity
unmapped.geoip.region_name
- Description: JumpCloud Directory Insights field
geoip.region_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.region_name - Usage: all events in this service
unmapped.geoip.timezone
- Description: JumpCloud Directory Insights field
geoip.timezonepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.timezone - Usage: all events in this service
unmapped.initiated_by.source
- Description: JumpCloud Directory Insights field
initiated_by.sourcepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by.source - Usage: all events in this service
unmapped.initiated_by.source_metadata
- Description: JumpCloud Directory Insights field
initiated_by.source_metadatapreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by.source_metadata - Usage: all events in this service
unmapped.initiated_by_id_hash
- Description: JumpCloud Directory Insights field
initiated_by_id_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_id_hash - Usage: all events in this service
unmapped.is_out_of_bound
- Description: JumpCloud Directory Insights field
is_out_of_boundpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
is_out_of_bound - Usage: all events in this service
unmapped.provider
- Description: JumpCloud Directory Insights field
providerpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
provider - Usage: all events in this service
unmapped.resource.id
- Description: JumpCloud Directory Insights field
resource.idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.id - Usage: all events in this service
unmapped.resource.name
- Description: JumpCloud Directory Insights field
resource.namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.name - Usage: all events in this service
unmapped.resource.type
- Description: JumpCloud Directory Insights field
resource.typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.type - Usage: all events in this service
unmapped.useragent.device
- Description: JumpCloud Directory Insights field
useragent.devicepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.device - Usage: all events in this service
unmapped.useragent.major
- Description: JumpCloud Directory Insights field
useragent.majorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.major - Usage: aigw_session_closed
unmapped.useragent.minor
- Description: JumpCloud Directory Insights field
useragent.minorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.minor - Usage: aigw_session_closed
unmapped.useragent.name
- Description: JumpCloud Directory Insights field
useragent.namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.name - Usage: all events in this service
unmapped.useragent.os
- Description: JumpCloud Directory Insights field
useragent.ospreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os - Usage: all events in this service
unmapped.useragent.os_full
- Description: JumpCloud Directory Insights field
useragent.os_fullpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_full - Usage: all events in this service
unmapped.useragent.os_name
- Description: JumpCloud Directory Insights field
useragent.os_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_name - Usage: all events in this service
unmapped.useragent.version
- Description: JumpCloud Directory Insights field
useragent.versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.version - Usage: aigw_session_closed
Alerts#
alert · 8 events
| Event | Category | Class | Activity | Type UID | Fields |
|---|---|---|---|---|---|
alert_created |
Findings (2) | Detection Finding (2004) | Create (1) | 200401 | 75 |
alert_status_updated |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 106 |
alert_updated |
Findings (2) | Detection Finding (2004) | Update (2) | 200402 | 67 |
bulk_delete_alerts |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 45 |
bulk_update_alerts |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 47 |
rule_config_created |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 62 |
rule_config_deleted |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 54 |
rule_config_updated |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 82 |
OCSF field mappings#
Legend
- Description: what the OCSF field represents (from OCSF schema v1.8.0)
- Source: raw JumpCloud event field(s) mapped via
${{placeholder}}template - Transform:
fieldMappingsentry applied at runtime (cast, enum, etc.) - Literal: static value set in the mapping template
- Usage: event types in this service that include this field
Core
activity_id
- Description: The normalized identifier of the activity that triggered the event.
- Literal:
1,2,3,4 - Usage: all events in this service
activity_name
- Description: The event activity name, as defined by the activity_id.
- Literal:
Create,Delete,Update - Usage: all events in this service
category_name
- Description: The event category name, as defined by category_uid value:
Discovery. - Literal:
Findings,Identity & Access Management - Usage: all events in this service
category_uid
- Description: The category unique identifier of the event.
- Literal:
2,3 - Usage: all events in this service
class_name
- Description: The event class name, as defined by class_uid value:
User Inventory Info. - Literal:
Detection Finding,Entity Management - Usage: all events in this service
class_uid
- Description: The unique identifier of a class. A class describes the attributes available in an event.
- Literal:
2004,3004 - Usage: all events in this service
message
- Description: The description of the event/finding, as defined by the source.
- Source:
bulk_ops_remark - Usage: bulk_delete_alerts, bulk_update_alerts
severity_id
- Description: OCSF severity identifier for the event.
- Literal:
1 - Usage: all events in this service
status_detail
- Description: The status detail contains additional information about the event/finding outcome.
- Source:
error_message - Usage: all events in this service
status_id
- Description: Normalized status of the activity (1=Success, 2=Failure).
- Source:
success - Transform:
success→boolean_to_status_id; true→1, false→2 (all events in this service)- Usage: all events in this service
time
- Description: Event time, in epoch milliseconds (OCSF
time). - Source:
timestamp - Transform:
timestamp→iso8601_to_epoch_millis(all events in this service)- Usage: all events in this service
type_uid
- Description: The event/finding type ID. It identifies the event's semantics and structure. The value is calculated by the logging system as:
class_uid * 100 + activity_id. - Literal:
200401,200402,300401,300403,300404 - Usage: all events in this service
Metadata
metadata.event_code
- Description: JumpCloud event type code.
- Source:
event_type - Usage: all events in this service
metadata.original_time
- Description: The original event time as reported by the event source. For example, the time in the original format from system event log such as Syslog on Unix/Linux and the System event file on Windows. Omit if event is generated instead of collected via logs.
- Source:
server_timestamp - Usage: all events in this service
metadata.processed_time
- Description: The event processed time, such as an ETL operation.
- Source:
jc_transformation_ts - Usage: all events in this service
metadata.product.name
- Description: Originating JumpCloud service that produced the event.
- Source:
service - Usage: all events in this service
metadata.tenant_uid
- Description: JumpCloud organization (tenant) identifier.
- Source:
organization - Usage: all events in this service
metadata.uid
- Description: Unique event identifier assigned by JumpCloud.
- Source:
id - Usage: all events in this service
metadata.version
- Description: OCSF schema version used for this event.
- Literal:
1.8.0 - Usage: all events in this service
Actor
actor.user.email_addr
- Description: Email address of the actor who initiated the event.
- Source:
initiated_by.email - Usage: alert_status_updated, bulk_delete_alerts, bulk_update_alerts, rule_config_created, rule_config_deleted, rule_config_updated
actor.user.type_id
- Description: OCSF user type of the actor (1=User, 2=Admin, 3=System, 4=Service).
- Source:
initiated_by.type - Transform:
initiated_by.type→enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (alert_status_updated, bulk_delete_alerts, bulk_update_alerts, rule_config_created, rule_config_deleted, rule_config_updated)- Usage: alert_status_updated, bulk_delete_alerts, bulk_update_alerts, rule_config_created, rule_config_deleted, rule_config_updated
actor.user.uid
- Description: Unique identifier of the actor who initiated the event.
- Source:
initiated_by.id - Usage: alert_status_updated, bulk_delete_alerts, bulk_update_alerts, rule_config_created, rule_config_deleted, rule_config_updated
Entity
entity.data.alerts_enabled
- Description: JumpCloud extension data on the managed entity:
alerts_enabled. - Source:
alerts_enabled - Usage: rule_config_created, rule_config_deleted, rule_config_updated
entity.data.category
- Description: JumpCloud extension data on the managed entity:
category. - Source:
category - Usage: alert_status_updated
entity.data.changed_field
- Description: JumpCloud extension data on the managed entity:
changed_field. - Source:
changes.field - Usage: alert_status_updated, bulk_update_alerts, rule_config_updated
entity.data.changes_from
- Description: JumpCloud extension data on the managed entity:
changes_from. - Source:
changes.from - Usage: alert_status_updated, rule_config_updated
entity.data.changes_removed.condition_object_id
- Description: JumpCloud extension data on the managed entity:
changes_removed.condition_object_id. - Source:
changes.removed.condition_object_id - Usage: rule_config_updated
entity.data.changes_removed.filter_name
- Description: JumpCloud extension data on the managed entity:
changes_removed.filter_name. - Source:
changes.removed.filter_name - Usage: rule_config_updated
entity.data.changes_removed.match_type
- Description: JumpCloud extension data on the managed entity:
changes_removed.match_type. - Source:
changes.removed.match_type - Usage: rule_config_updated
entity.data.changes_removed.value
- Description: JumpCloud extension data on the managed entity:
changes_removed.value. - Source:
changes.removed.value - Usage: rule_config_updated
entity.data.condition_object_id
- Description: JumpCloud extension data on the managed entity:
condition_object_id. - Source:
rule_conditions.condition_object_id - Usage: rule_config_created, rule_config_updated
entity.data.context.already_expired
- Description: JumpCloud extension data on the managed entity:
context.already_expired. - Source:
resource.context.already_expired - Usage: alert_status_updated
entity.data.context.app_id
- Description: JumpCloud extension data on the managed entity:
context.app_id. - Source:
resource.context.app_id - Usage: alert_status_updated
entity.data.context.app_name
- Description: JumpCloud extension data on the managed entity:
context.app_name. - Source:
resource.context.app_name - Usage: alert_status_updated
entity.data.context.certificates.certificate_name
- Description: JumpCloud extension data on the managed entity:
context.certificates.certificate_name. - Source:
resource.context.certificates.certificate_name - Usage: alert_status_updated
entity.data.context.certificates.certificate_type
- Description: JumpCloud extension data on the managed entity:
context.certificates.certificate_type. - Source:
resource.context.certificates.certificate_type - Usage: alert_status_updated
entity.data.context.certificates.expiry_date
- Description: JumpCloud extension data on the managed entity:
context.certificates.expiry_date. - Source:
resource.context.certificates.expiry_date - Usage: alert_status_updated
entity.data.context.certificates.id
- Description: JumpCloud extension data on the managed entity:
context.certificates.id. - Source:
resource.context.certificates.id - Usage: alert_status_updated
entity.data.context.command_id
- Description: JumpCloud extension data on the managed entity:
context.command_id. - Source:
resource.context.command_id - Usage: alert_status_updated
entity.data.context.command_name
- Description: JumpCloud extension data on the managed entity:
context.command_name. - Source:
resource.context.command_name - Usage: alert_status_updated
entity.data.context.condition_id
- Description: JumpCloud extension data on the managed entity:
context.condition_id. - Source:
resource.context.condition_id - Usage: alert_status_updated
entity.data.context.days_until_expiry
- Description: JumpCloud extension data on the managed entity:
context.days_until_expiry. - Source:
resource.context.days_until_expiry - Usage: alert_status_updated
entity.data.context.device.display_name
- Description: JumpCloud extension data on the managed entity:
context.device.display_name. - Source:
resource.context.device.display_name - Usage: alert_status_updated
entity.data.context.device.id
- Description: JumpCloud extension data on the managed entity:
context.device.id. - Source:
resource.context.device.id - Usage: alert_status_updated
entity.data.context.device_group.name
- Description: JumpCloud extension data on the managed entity:
context.device_group.name. - Source:
resource.context.device_group.name - Usage: alert_status_updated
entity.data.context.device_id
- Description: JumpCloud extension data on the managed entity:
context.device_id. - Source:
resource.context.device_id - Usage: alert_status_updated
entity.data.context.di_event
- Description: JumpCloud extension data on the managed entity:
context.di_event. - Source:
resource.context.di_event - Usage: alert_status_updated
entity.data.context.event_description
- Description: JumpCloud extension data on the managed entity:
context.event_description. - Source:
resource.context.event_description - Usage: alert_status_updated
entity.data.context.existing_condition
- Description: JumpCloud extension data on the managed entity:
context.existing_condition. - Source:
resource.context.existing_condition - Usage: alert_status_updated
entity.data.context.expires_at
- Description: JumpCloud extension data on the managed entity:
context.expires_at. - Source:
resource.context.expires_at - Usage: alert_status_updated
entity.data.context.href_enabled
- Description: JumpCloud extension data on the managed entity:
context.href_enabled. - Source:
resource.context.href_enabled - Usage: alert_status_updated
entity.data.context.label
- Description: JumpCloud extension data on the managed entity:
context.label. - Source:
resource.context.label - Usage: alert_status_updated
entity.data.context.last_contact_time
- Description: JumpCloud extension data on the managed entity:
context.last_contact_time. - Source:
resource.context.last_contact_time - Usage: alert_status_updated
entity.data.context.name
- Description: JumpCloud extension data on the managed entity:
context.name. - Source:
resource.context.name - Usage: alert_status_updated
entity.data.context.notify_config.channel_object_ids
- Description: JumpCloud extension data on the managed entity:
context.notify_config.channel_object_ids. - Source:
resource.context.notify_config.channel_object_ids - Usage: alert_status_updated
entity.data.context.notify_config.notify_on_acknowledgment
- Description: JumpCloud extension data on the managed entity:
context.notify_config.notify_on_acknowledgment. - Source:
resource.context.notify_config.notify_on_acknowledgment - Usage: alert_status_updated
entity.data.context.notify_config.notify_on_resolution
- Description: JumpCloud extension data on the managed entity:
context.notify_config.notify_on_resolution. - Source:
resource.context.notify_config.notify_on_resolution - Usage: alert_status_updated
entity.data.context.notify_config.notify_on_violation
- Description: JumpCloud extension data on the managed entity:
context.notify_config.notify_on_violation. - Source:
resource.context.notify_config.notify_on_violation - Usage: alert_status_updated
entity.data.context.notify_config.notify_primary_user_of_device
- Description: JumpCloud extension data on the managed entity:
context.notify_config.notify_primary_user_of_device. - Source:
resource.context.notify_config.notify_primary_user_of_device - Usage: alert_status_updated
entity.data.context.notify_config.primary_user_email
- Description: JumpCloud extension data on the managed entity:
context.notify_config.primary_user_email. - Source:
resource.context.notify_config.primary_user_email - Usage: alert_status_updated
entity.data.context.notify_config.primary_user_id
- Description: JumpCloud extension data on the managed entity:
context.notify_config.primary_user_id. - Source:
resource.context.notify_config.primary_user_id - Usage: alert_status_updated
entity.data.context.notify_config.primary_user_resolved
- Description: JumpCloud extension data on the managed entity:
context.notify_config.primary_user_resolved. - Source:
resource.context.notify_config.primary_user_resolved - Usage: alert_status_updated
entity.data.context.policy_id
- Description: JumpCloud extension data on the managed entity:
context.policy_id. - Source:
resource.context.policy_id - Usage: alert_status_updated
entity.data.context.policy_name
- Description: JumpCloud extension data on the managed entity:
context.policy_name. - Source:
resource.context.policy_name - Usage: alert_status_updated
entity.data.context.poll_event_type
- Description: JumpCloud extension data on the managed entity:
context.poll_event_type. - Source:
resource.context.poll_event_type - Usage: alert_status_updated
entity.data.context.raw_event_key
- Description: JumpCloud extension data on the managed entity:
context.raw_event_key. - Source:
resource.context.raw_event_key - Usage: alert_status_updated
entity.data.context.resolution_condition
- Description: JumpCloud extension data on the managed entity:
context.resolution_condition. - Source:
resource.context.resolution_condition - Usage: alert_status_updated
entity.data.context.resource_id
- Description: JumpCloud extension data on the managed entity:
context.resource_id. - Source:
resource.context.resource_id - Usage: alert_status_updated
entity.data.context.resource_type
- Description: JumpCloud extension data on the managed entity:
context.resource_type. - Source:
resource.context.resource_type - Usage: alert_status_updated
entity.data.context.rule_name
- Description: JumpCloud extension data on the managed entity:
context.rule_name. - Source:
resource.context.rule_name - Usage: alert_status_updated
entity.data.context.rule_object_id
- Description: JumpCloud extension data on the managed entity:
context.rule_object_id. - Source:
resource.context.rule_object_id - Usage: alert_status_updated
entity.data.context.rule_template_name
- Description: JumpCloud extension data on the managed entity:
context.rule_template_name. - Source:
resource.context.rule_template_name - Usage: alert_status_updated
entity.data.context.source_name
- Description: JumpCloud extension data on the managed entity:
context.source_name. - Source:
resource.context.source_name - Usage: alert_status_updated
entity.data.context.source_url
- Description: JumpCloud extension data on the managed entity:
context.source_url. - Source:
resource.context.source_url - Usage: alert_status_updated
entity.data.context.template_type
- Description: JumpCloud extension data on the managed entity:
context.template_type. - Source:
resource.context.template_type - Usage: alert_status_updated
entity.data.context.threshold_value
- Description: JumpCloud extension data on the managed entity:
context.threshold_value. - Source:
resource.context.threshold_value - Usage: alert_status_updated
entity.data.context.type
- Description: JumpCloud extension data on the managed entity:
context.type. - Source:
resource.context.type - Usage: alert_status_updated
entity.data.context.uptime_total_seconds
- Description: JumpCloud extension data on the managed entity:
context.uptime_total_seconds. - Source:
resource.context.uptime_total_seconds - Usage: alert_status_updated
entity.data.context.user_id
- Description: JumpCloud extension data on the managed entity:
context.user_id. - Source:
resource.context.user_id - Usage: alert_status_updated
entity.data.context.violation_condition
- Description: JumpCloud extension data on the managed entity:
context.violation_condition. - Source:
resource.context.violation_condition - Usage: alert_status_updated
entity.data.correlation.id
- Description: JumpCloud extension data on the managed entity:
correlation.id. - Source:
correlation.id - Usage: rule_config_created, rule_config_deleted, rule_config_updated
entity.data.created_by_object_id
- Description: JumpCloud extension data on the managed entity:
created_by_object_id. - Source:
created_by_object_id - Usage: rule_config_created, rule_config_deleted, rule_config_updated
entity.data.enable_bootstrap
- Description: JumpCloud extension data on the managed entity:
enable_bootstrap. - Source:
enable_bootstrap - Usage: rule_config_created, rule_config_deleted, rule_config_updated
entity.data.event_types
- Description: JumpCloud extension data on the managed entity:
event_types. - Source:
event_filters.event_types - Usage: rule_config_created, rule_config_updated
entity.data.filter_name
- Description: JumpCloud extension data on the managed entity:
filter_name. - Source:
rule_conditions.filter_name - Usage: rule_config_created, rule_config_updated
entity.data.filter_source
- Description: JumpCloud extension data on the managed entity:
filter_source. - Source:
event_filters.filter_source - Usage: rule_config_created, rule_config_updated
entity.data.initiated_from_slack_app_id
- Description: JumpCloud extension data on the managed entity:
initiated_from_slack_app_id. - Source:
initiated_from.slack.app_id - Usage: alert_status_updated
entity.data.initiated_from_slack_channel_id
- Description: JumpCloud extension data on the managed entity:
initiated_from_slack_channel_id. - Source:
initiated_from.slack.channel_id - Usage: alert_status_updated
entity.data.initiated_from_slack_channel_name
- Description: JumpCloud extension data on the managed entity:
initiated_from_slack_channel_name. - Source:
initiated_from.slack.channel_name - Usage: alert_status_updated
entity.data.initiated_from_slack_source
- Description: JumpCloud extension data on the managed entity:
initiated_from_slack_source. - Source:
initiated_from.slack.source - Usage: alert_status_updated
entity.data.initiated_from_slack_team_id
- Description: JumpCloud extension data on the managed entity:
initiated_from_slack_team_id. - Source:
initiated_from.slack.team_id - Usage: alert_status_updated
entity.data.initiated_from_slack_user_id
- Description: JumpCloud extension data on the managed entity:
initiated_from_slack_user_id. - Source:
initiated_from.slack.user_id - Usage: alert_status_updated
entity.data.match_type
- Description: JumpCloud extension data on the managed entity:
match_type. - Source:
rule_conditions.match_type - Usage: rule_config_created, rule_config_updated
entity.data.notification_channel_object_ids
- Description: JumpCloud extension data on the managed entity:
notification_channel_object_ids. - Source:
notification_channel_object_ids - Usage: rule_config_created, rule_config_deleted, rule_config_updated
entity.data.notify_on_acknowledgment
- Description: JumpCloud extension data on the managed entity:
notify_on_acknowledgment. - Source:
notify_on_acknowledgment - Usage: rule_config_created, rule_config_deleted, rule_config_updated
entity.data.notify_on_resolution
- Description: JumpCloud extension data on the managed entity:
notify_on_resolution. - Source:
notify_on_resolution - Usage: rule_config_created, rule_config_deleted, rule_config_updated
entity.data.notify_on_violation
- Description: JumpCloud extension data on the managed entity:
notify_on_violation. - Source:
notify_on_violation - Usage: rule_config_created, rule_config_deleted, rule_config_updated
entity.data.reference_fields
- Description: JumpCloud extension data on the managed entity:
reference_fields. - Source:
event_filters.reference_fields - Usage: rule_config_created, rule_config_updated
entity.data.reference_id
- Description: JumpCloud extension data on the managed entity:
reference_id. - Source:
resource.reference_id - Usage: alert_status_updated
entity.data.removed_event_filters_event_types
- Description: JumpCloud extension data on the managed entity:
removed_event_filters_event_types. - Source:
changes.removed_event_filters.event_types - Usage: rule_config_updated
entity.data.removed_event_filters_filter_source
- Description: JumpCloud extension data on the managed entity:
removed_event_filters_filter_source. - Source:
changes.removed_event_filters.filter_source - Usage: rule_config_updated
entity.data.removed_event_filters_reference_fields
- Description: JumpCloud extension data on the managed entity:
removed_event_filters_reference_fields. - Source:
changes.removed_event_filters.reference_fields - Usage: rule_config_updated
entity.data.removed_event_filters_violation_condition
- Description: JumpCloud extension data on the managed entity:
removed_event_filters_violation_condition. - Source:
changes.removed_event_filters.violation_condition - Usage: rule_config_updated
entity.data.rule_event_type
- Description: JumpCloud extension data on the managed entity:
rule_event_type. - Source:
rule_event_type - Usage: rule_config_created, rule_config_deleted, rule_config_updated
entity.data.rule_severity
- Description: JumpCloud extension data on the managed entity:
rule_severity. - Source:
rule_severity - Usage: rule_config_created, rule_config_deleted, rule_config_updated
entity.data.rule_status
- Description: JumpCloud extension data on the managed entity:
rule_status. - Source:
rule_status - Usage: rule_config_created, rule_config_deleted, rule_config_updated
entity.data.rule_type
- Description: JumpCloud extension data on the managed entity:
rule_type. - Source:
rule_type - Usage: rule_config_created, rule_config_deleted, rule_config_updated
entity.data.source_id
- Description: JumpCloud extension data on the managed entity:
source_id. - Source:
resource.source_id - Usage: alert_status_updated
entity.data.value
- Description: JumpCloud extension data on the managed entity:
value. - Source:
rule_conditions.value - Usage: rule_config_created, rule_config_updated
entity.data.violation_condition
- Description: JumpCloud extension data on the managed entity:
violation_condition. - Source:
event_filters.violation_condition - Usage: rule_config_created, rule_config_updated
entity.name
- Description: The name of the managed entity. It should match the name of the specific entity object's name if populated, or the name of the managed entity if the
type_idis 'Other'. - Source:
resource.source_name - Usage: alert_status_updated
entity.type
- Description: The managed entity type. For example:
Policy,User,Organization,Device. - Source:
resource.source_type,rule_category - Usage: alert_status_updated, rule_config_created, rule_config_deleted, rule_config_updated
entity.uid
- Description: The identifier of the managed entity. It should match the
uidof the specific entity's object UID if populated, or the source specific ID if thetype_idis 'Other'. - Source:
resource.alert_object_id,rule_object_id - Usage: alert_status_updated, rule_config_created, rule_config_deleted, rule_config_updated
entity_result.data.added_event_filters_event_types
- Description: JumpCloud extension data on the managed entity:
added_event_filters_event_types. - Source:
changes.added_event_filters.event_types - Usage: rule_config_updated
entity_result.data.added_event_filters_filter_source
- Description: JumpCloud extension data on the managed entity:
added_event_filters_filter_source. - Source:
changes.added_event_filters.filter_source - Usage: rule_config_updated
entity_result.data.added_event_filters_reference_fields
- Description: JumpCloud extension data on the managed entity:
added_event_filters_reference_fields. - Source:
changes.added_event_filters.reference_fields - Usage: rule_config_updated
entity_result.data.added_event_filters_violation_condition
- Description: JumpCloud extension data on the managed entity:
added_event_filters_violation_condition. - Source:
changes.added_event_filters.violation_condition - Usage: rule_config_updated
entity_result.data.added_notification_channels
- Description: JumpCloud extension data on the managed entity:
added_notification_channels. - Source:
changes.added_notification_channels - Usage: rule_config_updated
entity_result.data.changes_added.condition_object_id
- Description: JumpCloud extension data on the managed entity:
changes_added.condition_object_id. - Source:
changes.added.condition_object_id - Usage: rule_config_updated
entity_result.data.changes_added.filter_name
- Description: JumpCloud extension data on the managed entity:
changes_added.filter_name. - Source:
changes.added.filter_name - Usage: rule_config_updated
entity_result.data.changes_added.match_type
- Description: JumpCloud extension data on the managed entity:
changes_added.match_type. - Source:
changes.added.match_type - Usage: rule_config_updated
entity_result.data.changes_added.value
- Description: JumpCloud extension data on the managed entity:
changes_added.value. - Source:
changes.added.value - Usage: rule_config_updated
entity_result.data.changes_to
- Description: JumpCloud extension data on the managed entity:
changes_to. - Source:
changes.to - Usage: alert_status_updated, bulk_update_alerts, rule_config_updated
Src Endpoint
src_endpoint.autonomous_system.name
- Description: Organization name for the Autonomous System.
- Source:
asn.organization - Usage: bulk_delete_alerts, bulk_update_alerts
src_endpoint.autonomous_system.number
- Description: Unique number that the AS is identified by.
- Source:
asn.number - Transform:
asn.number→int(bulk_delete_alerts, bulk_update_alerts)- Usage: bulk_delete_alerts, bulk_update_alerts
src_endpoint.ip
- Description: Source IP address the request originated from.
- Source:
client_ip - Usage: alert_status_updated, bulk_delete_alerts, bulk_update_alerts, rule_config_created, rule_config_deleted, rule_config_updated
src_endpoint.location.city
- Description: The name of the city.
- Source:
geoip.city - Usage: alert_status_updated, bulk_delete_alerts, bulk_update_alerts, rule_config_created, rule_config_deleted, rule_config_updated
src_endpoint.location.continent
- Description: The name of the continent.
- Source:
geoip.continent_code - Usage: alert_status_updated, bulk_delete_alerts, bulk_update_alerts, rule_config_created, rule_config_deleted, rule_config_updated
src_endpoint.location.country
- Description: The ISO 3166-1 Alpha-2 country code.
Note: The two letter country code should be capitalized. For example:
USorCA. - Source:
geoip.country_code - Usage: alert_status_updated, bulk_delete_alerts, bulk_update_alerts, rule_config_created, rule_config_deleted, rule_config_updated
src_endpoint.location.lat
- Description: The geographical Latitude coordinate represented in Decimal Degrees (DD). For example:
42.361145. - Source:
geoip.latitude - Transform:
geoip.latitude→double(alert_status_updated, bulk_delete_alerts, bulk_update_alerts, rule_config_created, rule_config_deleted, rule_config_updated)- Usage: alert_status_updated, bulk_delete_alerts, bulk_update_alerts, rule_config_created, rule_config_deleted, rule_config_updated
src_endpoint.location.long
- Description: The geographical Longitude coordinate represented in Decimal Degrees (DD). For example:
-71.057083. - Source:
geoip.longitude - Transform:
geoip.longitude→double(alert_status_updated, bulk_delete_alerts, bulk_update_alerts, rule_config_created, rule_config_deleted, rule_config_updated)- Usage: alert_status_updated, bulk_delete_alerts, bulk_update_alerts, rule_config_created, rule_config_deleted, rule_config_updated
src_endpoint.location.region
- Description: The alphanumeric code that identifies the principal subdivision (e.g. province or state) of the country. For example, 'CH-VD' for the Canton of Vaud, Switzerland
- Source:
geoip.region_code - Usage: alert_status_updated, bulk_delete_alerts, bulk_update_alerts, rule_config_created, rule_config_deleted, rule_config_updated
Http Request
http_request.user_agent
- Description: The request header that identifies the operating system and web browser.
- Source:
user_agent - Usage: alert_status_updated, bulk_delete_alerts, bulk_update_alerts, rule_config_created, rule_config_deleted, rule_config_updated
Observables
observables[].name
- Description: The full name of the observable attribute. The
nameis a pointer/reference to an attribute within the OCSF event data. For example:file.name. Array attributes may be represented in one of three ways. For example:resources.uid,resources[].uid,resources[0].uid. - Literal:
actor.user.email_addr,actor.user.uid,http_request.user_agent,src_endpoint.ip,src_endpoint.location.country,src_url - Usage: all events in this service
observables[].type_id
- Description: The observable value type identifier.
- Literal:
14,16,2,31,5,6 - Usage: all events in this service
observables[].value
- Description: The value associated with the observable attribute. The meaning of the value depends on the observable type.
If thenamerefers to a scalar attribute, then thevalueis the value of the attribute.
If thenamerefers to an object attribute, then thevalueis not populated. - Source:
client_ip,geoip.country_code,initiated_by.email,initiated_by.id,resource.context.source_url,user_agent - Usage: all events in this service
Other
finding_info.analytic.name
- Description: The name of the analytic that generated the finding.
- Source:
resource.context.rule_name - Usage: alert_created, alert_updated
finding_info.desc
- Description: The description of the reported finding.
- Source:
resource.context.event_description - Usage: alert_created, alert_updated
finding_info.title
- Description: A title or a brief phrase summarizing the reported finding.
- Source:
resource.source_name - Usage: alert_created, alert_updated
finding_info.uid
- Description: The unique identifier of the reported finding.
- Source:
resource.alert_object_id - Usage: alert_created, alert_updated
policy.uid
- Description: A unique identifier of the policy instance.
- Source:
resource.context.rule_object_id - Usage: alert_created, alert_updated
severity
- Description: The event/finding severity, normalized to the caption of the
severity_idvalue. In the case of 'Other', it is defined by the source. - Source:
severity - Usage: alert_created, alert_status_updated, alert_updated
src_url
- Description: A Url link used to access the original incident.
- Source:
resource.context.source_url - Usage: alert_created, alert_updated
status
- Description: The event status, normalized to the caption of the status_id value. In the case of 'Other', it is defined by the event source.
- Source:
status - Usage: alert_created, alert_status_updated, alert_updated
Unmapped
unmapped.@version
- Description: JumpCloud Directory Insights field
@versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
@version - Usage: all events in this service
unmapped.asn.network
- Description: JumpCloud Directory Insights field
asn.networkpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
asn.network - Usage: bulk_delete_alerts, bulk_update_alerts
unmapped.category
- Description: JumpCloud Directory Insights field
categorypreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
category - Usage: alert_created, alert_updated
unmapped.client_ip
- Description: JumpCloud Directory Insights field
client_ippreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
client_ip - Usage: alert_created, alert_updated
unmapped.file_input_timestamp
- Description: JumpCloud Directory Insights field
file_input_timestamppreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
file_input_timestamp - Usage: bulk_delete_alerts, bulk_update_alerts
unmapped.geoip.city
- Description: JumpCloud Directory Insights field
geoip.citypreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.city - Usage: alert_created
unmapped.geoip.continent_code
- Description: JumpCloud Directory Insights field
geoip.continent_codepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.continent_code - Usage: alert_created
unmapped.geoip.country_code
- Description: JumpCloud Directory Insights field
geoip.country_codepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.country_code - Usage: alert_created
unmapped.geoip.latitude
- Description: JumpCloud Directory Insights field
geoip.latitudepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.latitude - Usage: alert_created
unmapped.geoip.longitude
- Description: JumpCloud Directory Insights field
geoip.longitudepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.longitude - Usage: alert_created
unmapped.geoip.region_code
- Description: JumpCloud Directory Insights field
geoip.region_codepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.region_code - Usage: alert_created
unmapped.geoip.region_name
- Description: JumpCloud Directory Insights field
geoip.region_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.region_name - Usage: alert_created, alert_status_updated, bulk_delete_alerts, bulk_update_alerts, rule_config_created, rule_config_deleted, rule_config_updated
unmapped.geoip.timezone
- Description: JumpCloud Directory Insights field
geoip.timezonepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.timezone - Usage: alert_created, alert_status_updated, bulk_delete_alerts, bulk_update_alerts, rule_config_created, rule_config_deleted, rule_config_updated
unmapped.initiated_by
- Description: JumpCloud Directory Insights field
initiated_bypreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by - Usage: alert_created, alert_updated
unmapped.initiated_by_email_hash
- Description: JumpCloud Directory Insights field
initiated_by_email_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_email_hash - Usage: alert_status_updated, bulk_delete_alerts, bulk_update_alerts, rule_config_created, rule_config_deleted, rule_config_updated
unmapped.initiated_by_id_hash
- Description: JumpCloud Directory Insights field
initiated_by_id_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_id_hash - Usage: alert_status_updated, bulk_delete_alerts, bulk_update_alerts, rule_config_created, rule_config_deleted, rule_config_updated
unmapped.is_out_of_bound
- Description: JumpCloud Directory Insights field
is_out_of_boundpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
is_out_of_bound - Usage: all events in this service
unmapped.jc_application_name
- Description: JumpCloud Directory Insights field
jc_application_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_application_name - Usage: all events in this service
unmapped.resource.context.already_expired
- Description: JumpCloud Directory Insights field
resource.context.already_expiredpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.already_expired - Usage: alert_created, alert_updated
unmapped.resource.context.certificates.certificate_name
- Description: JumpCloud Directory Insights field
resource.context.certificates.certificate_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.certificates.certificate_name - Usage: alert_created, alert_updated
unmapped.resource.context.certificates.certificate_type
- Description: JumpCloud Directory Insights field
resource.context.certificates.certificate_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.certificates.certificate_type - Usage: alert_created, alert_updated
unmapped.resource.context.certificates.expiry_date
- Description: JumpCloud Directory Insights field
resource.context.certificates.expiry_datepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.certificates.expiry_date - Usage: alert_created, alert_updated
unmapped.resource.context.certificates.id
- Description: JumpCloud Directory Insights field
resource.context.certificates.idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.certificates.id - Usage: alert_created, alert_updated
unmapped.resource.context.condition_id
- Description: JumpCloud Directory Insights field
resource.context.condition_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.condition_id - Usage: alert_created, alert_updated
unmapped.resource.context.days_until_expiry
- Description: JumpCloud Directory Insights field
resource.context.days_until_expirypreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.days_until_expiry - Usage: alert_created, alert_updated
unmapped.resource.context.di_event
- Description: JumpCloud Directory Insights field
resource.context.di_eventpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.di_event - Usage: alert_created, alert_updated
unmapped.resource.context.existing_condition
- Description: JumpCloud Directory Insights field
resource.context.existing_conditionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.existing_condition - Usage: alert_created, alert_updated
unmapped.resource.context.expires_at
- Description: JumpCloud Directory Insights field
resource.context.expires_atpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.expires_at - Usage: alert_created, alert_updated
unmapped.resource.context.key1
- Description: JumpCloud Directory Insights field
resource.context.key1preserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.key1 - Usage: alert_created
unmapped.resource.context.key2
- Description: JumpCloud Directory Insights field
resource.context.key2preserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.key2 - Usage: alert_created
unmapped.resource.context.label
- Description: JumpCloud Directory Insights field
resource.context.labelpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.label - Usage: alert_created, alert_updated
unmapped.resource.context.notify_config.channel_object_ids
- Description: JumpCloud Directory Insights field
resource.context.notify_config.channel_object_idspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.notify_config.channel_object_ids - Usage: alert_created, alert_updated
unmapped.resource.context.notify_config.notify_on_acknowledgment
- Description: JumpCloud Directory Insights field
resource.context.notify_config.notify_on_acknowledgmentpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.notify_config.notify_on_acknowledgment - Usage: alert_created, alert_updated
unmapped.resource.context.notify_config.notify_on_resolution
- Description: JumpCloud Directory Insights field
resource.context.notify_config.notify_on_resolutionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.notify_config.notify_on_resolution - Usage: alert_created, alert_updated
unmapped.resource.context.notify_config.notify_on_violation
- Description: JumpCloud Directory Insights field
resource.context.notify_config.notify_on_violationpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.notify_config.notify_on_violation - Usage: alert_created, alert_updated
unmapped.resource.context.poll_event_type
- Description: JumpCloud Directory Insights field
resource.context.poll_event_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.poll_event_type - Usage: alert_created, alert_updated
unmapped.resource.context.raw_event_key
- Description: JumpCloud Directory Insights field
resource.context.raw_event_keypreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.raw_event_key - Usage: alert_created, alert_updated
unmapped.resource.context.resolution_condition
- Description: JumpCloud Directory Insights field
resource.context.resolution_conditionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.resolution_condition - Usage: alert_created, alert_updated
unmapped.resource.context.resource_id
- Description: JumpCloud Directory Insights field
resource.context.resource_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.resource_id - Usage: alert_created, alert_updated
unmapped.resource.context.resource_type
- Description: JumpCloud Directory Insights field
resource.context.resource_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.resource_type - Usage: alert_created, alert_updated
unmapped.resource.context.rule_template_name
- Description: JumpCloud Directory Insights field
resource.context.rule_template_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.rule_template_name - Usage: alert_created, alert_updated
unmapped.resource.context.source_name
- Description: JumpCloud Directory Insights field
resource.context.source_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.source_name - Usage: alert_created, alert_updated
unmapped.resource.context.template_type
- Description: JumpCloud Directory Insights field
resource.context.template_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.template_type - Usage: alert_created, alert_updated
unmapped.resource.context.threshold_value
- Description: JumpCloud Directory Insights field
resource.context.threshold_valuepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.threshold_value - Usage: alert_created, alert_updated
unmapped.resource.context.type
- Description: JumpCloud Directory Insights field
resource.context.typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.type - Usage: alert_updated
unmapped.resource.context.uptime_total_seconds
- Description: JumpCloud Directory Insights field
resource.context.uptime_total_secondspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.uptime_total_seconds - Usage: alert_updated
unmapped.resource.context.violation_condition
- Description: JumpCloud Directory Insights field
resource.context.violation_conditionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.violation_condition - Usage: alert_created, alert_updated
unmapped.resource.reference_id
- Description: JumpCloud Directory Insights field
resource.reference_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.reference_id - Usage: alert_created, alert_updated
unmapped.resource.source_id
- Description: JumpCloud Directory Insights field
resource.source_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.source_id - Usage: alert_created, alert_updated
unmapped.resource.source_type
- Description: JumpCloud Directory Insights field
resource.source_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.source_type - Usage: alert_created, alert_updated
unmapped.timestamp_source
- Description: JumpCloud Directory Insights field
timestamp_sourcepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
timestamp_source - Usage: all events in this service
unmapped.user_agent
- Description: JumpCloud Directory Insights field
user_agentpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
user_agent - Usage: alert_created, alert_updated
Asset Management#
asset_management · 9 events
| Event | Category | Class | Activity | Type UID | Fields |
|---|---|---|---|---|---|
asset_management_asset_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 84 |
asset_management_asset_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 57 |
asset_management_asset_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 47 |
asset_management_disable |
Identity & Access Management (3) | Entity Management (3004) | Disable (9) | 300409 | 51 |
asset_management_enable |
Identity & Access Management (3) | Entity Management (3004) | Enable (8) | 300408 | 52 |
asset_management_field_setting_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 56 |
asset_management_field_setting_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 49 |
asset_management_field_setting_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 52 |
asset_management_general_settings_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 54 |
OCSF field mappings#
Legend
- Description: what the OCSF field represents (from OCSF schema v1.8.0)
- Source: raw JumpCloud event field(s) mapped via
${{placeholder}}template - Transform:
fieldMappingsentry applied at runtime (cast, enum, etc.) - Literal: static value set in the mapping template
- Usage: event types in this service that include this field
Core
activity_id
- Description: The normalized identifier of the activity that triggered the event.
- Literal:
1,3,4,8,9 - Usage: all events in this service
activity_name
- Description: The event activity name, as defined by the activity_id.
- Literal:
Create,Delete,Disable,Enable,Update - Usage: all events in this service
category_name
- Description: The event category name, as defined by category_uid value:
Discovery. - Literal:
Identity & Access Management - Usage: all events in this service
category_uid
- Description: The category unique identifier of the event.
- Literal:
3 - Usage: all events in this service
class_name
- Description: The event class name, as defined by class_uid value:
User Inventory Info. - Literal:
Entity Management - Usage: all events in this service
class_uid
- Description: The unique identifier of a class. A class describes the attributes available in an event.
- Literal:
3004 - Usage: all events in this service
message
- Description: The description of the event/finding, as defined by the source.
- Source:
detail - Usage: all events in this service
severity_id
- Description: OCSF severity identifier for the event.
- Literal:
1 - Usage: all events in this service
status_detail
- Description: The status detail contains additional information about the event/finding outcome.
- Source:
error_message - Usage: all events in this service
status_id
- Description: Normalized status of the activity (1=Success, 2=Failure).
- Source:
success - Transform:
success→boolean_to_status_id; true→1, false→2 (all events in this service)- Usage: all events in this service
time
- Description: Event time, in epoch milliseconds (OCSF
time). - Source:
timestamp - Transform:
timestamp→iso8601_to_epoch_millis(all events in this service)- Usage: all events in this service
type_uid
- Description: The event/finding type ID. It identifies the event's semantics and structure. The value is calculated by the logging system as:
class_uid * 100 + activity_id. - Literal:
300401,300403,300404,300408,300409 - Usage: all events in this service
Metadata
metadata.event_code
- Description: JumpCloud event type code.
- Source:
event_type - Usage: all events in this service
metadata.original_time
- Description: The original event time as reported by the event source. For example, the time in the original format from system event log such as Syslog on Unix/Linux and the System event file on Windows. Omit if event is generated instead of collected via logs.
- Source:
server_timestamp - Usage: all events in this service
metadata.processed_time
- Description: The event processed time, such as an ETL operation.
- Source:
jc_transformation_ts - Usage: all events in this service
metadata.product.name
- Description: Originating JumpCloud service that produced the event.
- Source:
service - Usage: all events in this service
metadata.tenant_uid
- Description: JumpCloud organization (tenant) identifier.
- Source:
organization - Usage: all events in this service
metadata.uid
- Description: Unique event identifier assigned by JumpCloud.
- Source:
id - Usage: all events in this service
metadata.version
- Description: OCSF schema version used for this event.
- Literal:
1.8.0 - Usage: all events in this service
Actor
actor.user.email_addr
- Description: Email address of the actor who initiated the event.
- Source:
initiated_by.email - Usage: all events in this service
actor.user.type_id
- Description: OCSF user type of the actor (1=User, 2=Admin, 3=System, 4=Service).
- Source:
initiated_by.type - Transform:
initiated_by.type→enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (all events in this service)- Usage: all events in this service
actor.user.uid
- Description: Unique identifier of the actor who initiated the event.
- Source:
initiated_by.id - Usage: all events in this service
Entity
entity.data.agent_status
- Description: JumpCloud extension data on the managed entity:
agent_status. - Source:
resource.agent_status - Usage: asset_management_asset_create
entity.data.agent_version
- Description: JumpCloud extension data on the managed entity:
agent_version. - Source:
resource.agent_version - Usage: asset_management_asset_create
entity.data.battery_current_capacity
- Description: JumpCloud extension data on the managed entity:
battery_current_capacity. - Source:
resource.battery_current_capacity - Usage: asset_management_asset_create
entity.data.battery_max_capacity
- Description: JumpCloud extension data on the managed entity:
battery_max_capacity. - Source:
resource.battery_max_capacity - Usage: asset_management_asset_create
entity.data.changed_field
- Description: JumpCloud extension data on the managed entity:
changed_field. - Source:
changes.field - Usage: asset_management_asset_update, asset_management_field_setting_update, asset_management_general_settings_update
entity.data.changes_from
- Description: JumpCloud extension data on the managed entity:
changes_from. - Source:
changes.from - Usage: asset_management_asset_update, asset_management_field_setting_update, asset_management_general_settings_update
entity.data.country
- Description: JumpCloud extension data on the managed entity:
country. - Source:
resource.country - Usage: asset_management_asset_create
entity.data.currency_code
- Description: JumpCloud extension data on the managed entity:
currency_code. - Source:
resource.currency_code - Usage: asset_management_asset_create
entity.data.data_source
- Description: JumpCloud extension data on the managed entity:
data_source. - Source:
resource.data_source - Usage: asset_management_asset_create, asset_management_asset_delete
entity.data.deployed_at
- Description: JumpCloud extension data on the managed entity:
deployed_at. - Source:
resource.deployed_at - Usage: asset_management_asset_create
entity.data.device_groups
- Description: JumpCloud extension data on the managed entity:
device_groups. - Source:
resource.device_groups - Usage: asset_management_asset_create
entity.data.disk_encrypted
- Description: JumpCloud extension data on the managed entity:
disk_encrypted. - Source:
resource.disk_encrypted - Usage: asset_management_asset_create
entity.data.field_type
- Description: JumpCloud extension data on the managed entity:
field_type. - Source:
resource.type - Usage: asset_management_field_setting_create, asset_management_field_setting_delete, asset_management_field_setting_update
entity.data.mandatory
- Description: JumpCloud extension data on the managed entity:
mandatory. - Source:
resource.mandatory - Usage: asset_management_field_setting_create
entity.data.mdm_provider
- Description: JumpCloud extension data on the managed entity:
mdm_provider. - Source:
resource.mdm_provider - Usage: asset_management_asset_create
entity.data.mfa_status
- Description: JumpCloud extension data on the managed entity:
mfa_status. - Source:
resource.mfa_status - Usage: asset_management_asset_create
entity.data.multiple
- Description: JumpCloud extension data on the managed entity:
multiple. - Source:
resource.multiple - Usage: asset_management_field_setting_create
entity.data.options_id
- Description: JumpCloud extension data on the managed entity:
options_id. - Source:
resource.options.id - Usage: asset_management_field_setting_create
entity.data.options_value
- Description: JumpCloud extension data on the managed entity:
options_value. - Source:
resource.options.value - Usage: asset_management_field_setting_create
entity.data.ownership_type
- Description: JumpCloud extension data on the managed entity:
ownership_type. - Source:
resource.ownership_type - Usage: asset_management_asset_create
entity.data.po_number
- Description: JumpCloud extension data on the managed entity:
po_number. - Source:
resource.po_number - Usage: asset_management_asset_create
entity.data.purchase_cost
- Description: JumpCloud extension data on the managed entity:
purchase_cost. - Source:
resource.purchase_cost - Usage: asset_management_asset_create
entity.data.purchased_at
- Description: JumpCloud extension data on the managed entity:
purchased_at. - Source:
resource.purchased_at - Usage: asset_management_asset_create
entity.data.section
- Description: JumpCloud extension data on the managed entity:
section. - Source:
resource.section - Usage: asset_management_field_setting_create
entity.data.status
- Description: JumpCloud extension data on the managed entity:
status. - Source:
resource.status - Usage: asset_management_asset_create
entity.data.supplier
- Description: JumpCloud extension data on the managed entity:
supplier. - Source:
resource.supplier - Usage: asset_management_asset_create
entity.data.system_insights_enabled
- Description: JumpCloud extension data on the managed entity:
system_insights_enabled. - Source:
resource.system_insights_enabled - Usage: asset_management_asset_create
entity.data.tag
- Description: JumpCloud extension data on the managed entity:
tag. - Source:
resource.tag - Usage: asset_management_asset_create
entity.data.tooltip
- Description: JumpCloud extension data on the managed entity:
tooltip. - Source:
resource.tooltip - Usage: asset_management_field_setting_create
entity.data.unique
- Description: JumpCloud extension data on the managed entity:
unique. - Source:
resource.unique - Usage: asset_management_field_setting_create
entity.data.users
- Description: JumpCloud extension data on the managed entity:
users. - Source:
resource.users - Usage: asset_management_asset_create
entity.data.warranty_expired_at
- Description: JumpCloud extension data on the managed entity:
warranty_expired_at. - Source:
resource.warranty_expired_at - Usage: asset_management_asset_create
entity.data.warranty_period_months
- Description: JumpCloud extension data on the managed entity:
warranty_period_months. - Source:
resource.warranty_period_months - Usage: asset_management_asset_create
entity.device.hw_info.cpu_type
- Description: The processor type. For example:
x86 Family 6 Model 37 Stepping 5. - Source:
resource.cpu - Usage: asset_management_asset_create
entity.device.hw_info.ram_size
- Description: The total amount of installed RAM, in Megabytes. For example:
2048. - Source:
resource.rammb - Usage: asset_management_asset_create
entity.device.hw_info.serial_number
- Description: The device manufacturer serial number.
- Source:
resource.serial - Usage: asset_management_asset_create
entity.device.is_managed
- Description: The event occurred on a managed device.
- Source:
resource.mdm_status - Usage: asset_management_asset_create
entity.device.last_seen_time
- Description: The most recent discovery time of the device.
- Source:
resource.last_contact - Usage: asset_management_asset_create
entity.device.model
- Description: The model of the device. For example
ThinkPad X1 Carbon. - Source:
resource.model - Usage: asset_management_asset_create
entity.device.os.name
- Description: The operating system name.
- Source:
resource.os - Usage: asset_management_asset_create
entity.device.os.type
- Description: The type of the operating system.
- Source:
resource.os_family - Usage: asset_management_asset_create
entity.device.os.version
- Description: The version of the OS running on the device that originated the event. For example: "Windows 10", "OS X 10.7", or "iOS 9".
- Source:
resource.os_version - Usage: asset_management_asset_create
entity.device.owner.name
- Description: The username. For example,
janedoe1. - Source:
resource.owner_user - Usage: asset_management_asset_create
entity.device.type
- Description: The device type. For example:
unknown,server,desktop,laptop,tablet,mobile,virtual,browser, orother. - Source:
resource.type - Usage: asset_management_asset_create, asset_management_asset_delete
entity.device.uid
- Description: The unique identifier of the device. For example the Windows TargetSID or AWS EC2 ARN.
- Source:
resource.system_id - Usage: asset_management_asset_create
entity.device.vendor_name
- Description: The vendor for the device. For example
DellorLenovo. - Source:
resource.vendor - Usage: asset_management_asset_create
entity.name
- Description: The name of the managed entity. It should match the name of the specific entity object's name if populated, or the name of the managed entity if the
type_idis 'Other'. - Source:
resource.label,resource.name - Usage: asset_management_asset_create, asset_management_asset_delete, asset_management_field_setting_create, asset_management_field_setting_delete, asset_management_field_setting_update
entity.type
- Description: The managed entity type. For example:
Policy,User,Organization,Device. - Source:
resource.asset_type,resource.scope,resource.type - Usage: asset_management_asset_create, asset_management_asset_delete, asset_management_asset_update, asset_management_field_setting_create, asset_management_field_setting_delete, asset_management_field_setting_update
entity.uid
- Description: The identifier of the managed entity. It should match the
uidof the specific entity's object UID if populated, or the source specific ID if thetype_idis 'Other'. - Source:
resource.id,service - Usage: all events in this service
entity_result.data.changes_to
- Description: JumpCloud extension data on the managed entity:
changes_to. - Source:
changes.to - Usage: asset_management_asset_update, asset_management_field_setting_update, asset_management_general_settings_update
Src Endpoint
src_endpoint.autonomous_system.name
- Description: Organization name for the Autonomous System.
- Source:
asn.organization - Usage: asset_management_asset_create, asset_management_asset_delete, asset_management_disable, asset_management_enable, asset_management_field_setting_create, asset_management_field_setting_delete, asset_management_field_setting_update, asset_management_general_settings_update
src_endpoint.autonomous_system.number
- Description: Unique number that the AS is identified by.
- Source:
asn.number - Transform:
asn.number→int(asset_management_asset_create, asset_management_asset_delete, asset_management_disable, asset_management_enable, asset_management_field_setting_create, asset_management_field_setting_delete, asset_management_field_setting_update, asset_management_general_settings_update)- Usage: asset_management_asset_create, asset_management_asset_delete, asset_management_disable, asset_management_enable, asset_management_field_setting_create, asset_management_field_setting_delete, asset_management_field_setting_update, asset_management_general_settings_update
src_endpoint.ip
- Description: Source IP address the request originated from.
- Source:
client_ip - Usage: all events in this service
src_endpoint.location.city
- Description: The name of the city.
- Source:
geoip.city - Usage: all events in this service
src_endpoint.location.continent
- Description: The name of the continent.
- Source:
geoip.continent_code - Usage: all events in this service
src_endpoint.location.country
- Description: The ISO 3166-1 Alpha-2 country code.
Note: The two letter country code should be capitalized. For example:
USorCA. - Source:
geoip.country_code - Usage: all events in this service
src_endpoint.location.lat
- Description: The geographical Latitude coordinate represented in Decimal Degrees (DD). For example:
42.361145. - Source:
geoip.latitude - Transform:
geoip.latitude→double(all events in this service)- Usage: all events in this service
src_endpoint.location.long
- Description: The geographical Longitude coordinate represented in Decimal Degrees (DD). For example:
-71.057083. - Source:
geoip.longitude - Transform:
geoip.longitude→double(all events in this service)- Usage: all events in this service
src_endpoint.location.region
- Description: The alphanumeric code that identifies the principal subdivision (e.g. province or state) of the country. For example, 'CH-VD' for the Canton of Vaud, Switzerland
- Source:
geoip.region_code - Usage: all events in this service
Http Request
http_request.user_agent
- Description: The request header that identifies the operating system and web browser.
- Source:
user_agent - Usage: all events in this service
Observables
observables[].name
- Description: The full name of the observable attribute. The
nameis a pointer/reference to an attribute within the OCSF event data. For example:file.name. Array attributes may be represented in one of three ways. For example:resources.uid,resources[].uid,resources[0].uid. - Literal:
actor.user.email_addr,actor.user.uid,entity.device.hw_info.serial_number,entity.device.owner.name,entity.device.uid,http_request.user_agent,src_endpoint.ip,src_endpoint.location.country - Usage: all events in this service
observables[].type_id
- Description: The observable value type identifier.
- Literal:
14,16,2,31,37,4,47,5 - Usage: all events in this service
observables[].value
- Description: The value associated with the observable attribute. The meaning of the value depends on the observable type.
If thenamerefers to a scalar attribute, then thevalueis the value of the attribute.
If thenamerefers to an object attribute, then thevalueis not populated. - Source:
client_ip,geoip.country_code,initiated_by.email,initiated_by.id,resource.owner_user,resource.serial,resource.system_id,user_agent - Usage: all events in this service
Unmapped
unmapped.@version
- Description: JumpCloud Directory Insights field
@versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
@version - Usage: all events in this service
unmapped.asn.network
- Description: JumpCloud Directory Insights field
asn.networkpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
asn.network - Usage: asset_management_asset_create, asset_management_asset_delete, asset_management_disable, asset_management_enable, asset_management_field_setting_create, asset_management_field_setting_delete, asset_management_field_setting_update, asset_management_general_settings_update
unmapped.geoip.region_name
- Description: JumpCloud Directory Insights field
geoip.region_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.region_name - Usage: all events in this service
unmapped.geoip.timezone
- Description: JumpCloud Directory Insights field
geoip.timezonepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.timezone - Usage: all events in this service
unmapped.initiated_by_email_hash
- Description: JumpCloud Directory Insights field
initiated_by_email_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_email_hash - Usage: all events in this service
unmapped.initiated_by_id_hash
- Description: JumpCloud Directory Insights field
initiated_by_id_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_id_hash - Usage: all events in this service
unmapped.is_out_of_bound
- Description: JumpCloud Directory Insights field
is_out_of_boundpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
is_out_of_bound - Usage: all events in this service
unmapped.jc_application_name
- Description: JumpCloud Directory Insights field
jc_application_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_application_name - Usage: all events in this service
unmapped.jc_initiated_by_email
- Description: JumpCloud Directory Insights field
jc_initiated_by_emailpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_initiated_by_email - Usage: asset_management_asset_delete, asset_management_disable, asset_management_enable, asset_management_general_settings_update
unmapped.jc_initiated_by_id
- Description: JumpCloud Directory Insights field
jc_initiated_by_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_initiated_by_id - Usage: asset_management_asset_delete, asset_management_disable, asset_management_enable, asset_management_general_settings_update
unmapped.jc_initiated_by_username
- Description: JumpCloud Directory Insights field
jc_initiated_by_usernamepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_initiated_by_username - Usage: asset_management_asset_delete, asset_management_disable, asset_management_enable, asset_management_general_settings_update
unmapped.jc_organization_name
- Description: JumpCloud Directory Insights field
jc_organization_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_organization_name - Usage: asset_management_asset_delete, asset_management_disable, asset_management_enable, asset_management_general_settings_update
unmapped.jc_provider_id
- Description: JumpCloud Directory Insights field
jc_provider_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_provider_id - Usage: asset_management_enable
unmapped.jc_system_display_name
- Description: JumpCloud Directory Insights field
jc_system_display_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_system_display_name - Usage: asset_management_asset_delete, asset_management_disable, asset_management_enable, asset_management_general_settings_update
unmapped.jc_system_hostname
- Description: JumpCloud Directory Insights field
jc_system_hostnamepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_system_hostname - Usage: asset_management_asset_delete, asset_management_disable, asset_management_enable, asset_management_general_settings_update
unmapped.resource_id_hash
- Description: JumpCloud Directory Insights field
resource_id_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource_id_hash - Usage: asset_management_asset_create, asset_management_asset_delete, asset_management_asset_update, asset_management_field_setting_create, asset_management_field_setting_delete, asset_management_field_setting_update
unmapped.resource_name_hash
- Description: JumpCloud Directory Insights field
resource_name_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource_name_hash - Usage: asset_management_asset_delete
unmapped.timestamp_source
- Description: JumpCloud Directory Insights field
timestamp_sourcepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
timestamp_source - Usage: all events in this service
Directory — Command and Policy Events#
directory_command_policy · 35 events
| Event | Category | Class | Activity | Type UID | Fields |
|---|---|---|---|---|---|
authnfallbackpolicy_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 45 |
authnfallbackpolicy_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 69 |
authnfallbackpolicy_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 53 |
authnpolicy_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 73 |
authnpolicy_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 66 |
authnpolicy_mfa_factor_selection_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 64 |
authnpolicy_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 56 |
background_access_file |
System Activity (1) | Process Activity (1007) | Open (3) | 100703 | 66 |
background_access_shell |
System Activity (1) | Process Activity (1007) | Launch (1) | 100701 | 51 |
command_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 43 |
command_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 71 |
command_result |
System Activity (1) | Scheduled Job Activity (1006) | Start (6) | 100606 | 38 |
command_run |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 67 |
command_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 63 |
commandresult_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 63 |
commandtemplate_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 55 |
commandtemplate_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 59 |
commandtemplate_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 59 |
configuredpolicytemplate_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 66 |
configuredpolicytemplate_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 62 |
file_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 61 |
file_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 64 |
file_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 68 |
iplist_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 43 |
iplist_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 60 |
iplist_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 66 |
passwordpolicy_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 54 |
passwordpolicy_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 53 |
passwordpolicy_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 53 |
policy_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 48 |
policy_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 48 |
policy_result |
Discovery (5) | Device Config State Change (5019) | Log (1) | 501901 | 37 |
policy_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 49 |
policygrouptemplate_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 63 |
policygrouptemplate_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 60 |
OCSF field mappings#
Legend
- Description: what the OCSF field represents (from OCSF schema v1.8.0)
- Source: raw JumpCloud event field(s) mapped via
${{placeholder}}template - Transform:
fieldMappingsentry applied at runtime (cast, enum, etc.) - Literal: static value set in the mapping template
- Usage: event types in this service that include this field
Core
activity_id
- Description: The normalized identifier of the activity that triggered the event.
- Literal:
1,3,4,6 - Usage: all events in this service
activity_name
- Description: The event activity name, as defined by the activity_id.
- Literal:
Create,Delete,Launch,Log,Open,Start,Update - Usage: all events in this service
category_name
- Description: The event category name, as defined by category_uid value:
Discovery. - Literal:
Discovery,Identity & Access Management,System Activity - Usage: all events in this service
category_uid
- Description: The category unique identifier of the event.
- Literal:
1,3,5 - Usage: all events in this service
class_name
- Description: The event class name, as defined by class_uid value:
User Inventory Info. - Literal:
Device Config State Change,Entity Management,Process Activity,Scheduled Job Activity - Usage: all events in this service
class_uid
- Description: The unique identifier of a class. A class describes the attributes available in an event.
- Literal:
1006,1007,3004,5019 - Usage: all events in this service
message
- Description: The description of the event/finding, as defined by the source.
- Source:
message - Usage: background_access_file, background_access_shell
severity_id
- Description: OCSF severity identifier for the event.
- Literal:
1 - Usage: all events in this service
status_detail
- Description: The status detail contains additional information about the event/finding outcome.
- Source:
error_message - Usage: 29 events: authnfallbackpolicy_delete, authnfallbackpolicy_update, authnpolicy_create, authnpolicy_delete, authnpolicy_mfa_factor_selection_update, authnpolicy_update, background_access_file, background_access_shell, ... (+21 more)
status_id
- Description: Normalized status of the activity (1=Success, 2=Failure).
- Source:
success - Transform:
success→boolean_to_status_id; true→1, false→2 (26 events: authnfallbackpolicy_delete, authnfallbackpolicy_update, authnpolicy_mfa_factor_selection_update, background_access_file, background_access_shell, command_delete, command_result, command_run, ... (+18 more))- Usage: 26 events: authnfallbackpolicy_delete, authnfallbackpolicy_update, authnpolicy_mfa_factor_selection_update, background_access_file, background_access_shell, command_delete, command_result, command_run, ... (+18 more)
time
- Description: Event time, in epoch milliseconds (OCSF
time). - Source:
timestamp - Transform:
timestamp→iso8601_to_epoch_millis(all events in this service)- Usage: all events in this service
type_uid
- Description: The event/finding type ID. It identifies the event's semantics and structure. The value is calculated by the logging system as:
class_uid * 100 + activity_id. - Literal:
100606,100701,100703,300401,300403,300404,501901 - Usage: all events in this service
Metadata
metadata.event_code
- Description: JumpCloud event type code.
- Source:
event_type - Usage: all events in this service
metadata.original_time
- Description: The original event time as reported by the event source. For example, the time in the original format from system event log such as Syslog on Unix/Linux and the System event file on Windows. Omit if event is generated instead of collected via logs.
- Source:
server_timestamp - Usage: background_access_file, background_access_shell, command_result, passwordpolicy_create, passwordpolicy_delete, passwordpolicy_update, policy_result
metadata.processed_time
- Description: The event processed time, such as an ETL operation.
- Source:
jc_transformation_ts - Usage: 26 events: authnfallbackpolicy_delete, authnfallbackpolicy_update, authnpolicy_mfa_factor_selection_update, background_access_file, background_access_shell, command_delete, command_result, command_run, ... (+18 more)
metadata.product.name
- Description: Originating JumpCloud service that produced the event.
- Source:
service - Usage: all events in this service
metadata.tenant_uid
- Description: JumpCloud organization (tenant) identifier.
- Source:
organization - Usage: all events in this service
metadata.uid
- Description: Unique event identifier assigned by JumpCloud.
- Source:
id - Usage: all events in this service
metadata.version
- Description: OCSF schema version used for this event.
- Literal:
1.8.0 - Usage: all events in this service
Actor
actor.user.email_addr
- Description: Email address of the actor who initiated the event.
- Source:
initiated_by.email - Usage: 33 events (missing: command_result, policy_result)
actor.user.name
- Description: Display name of the actor who initiated the event.
- Source:
initiated_by.name - Usage: background_access_file, background_access_shell, command_run
actor.user.type_id
- Description: OCSF user type of the actor (1=User, 2=Admin, 3=System, 4=Service).
- Source:
initiated_by.type - Transform:
initiated_by.type→enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (33 events (missing: command_result, policy_result))- Usage: 33 events (missing: command_result, policy_result)
actor.user.uid
- Description: Unique identifier of the actor who initiated the event.
- Source:
initiated_by.id - Usage: 33 events (missing: command_result, policy_result)
Device
device.hostname
- Description: The device hostname.
- Source:
system.hostname - Usage: background_access_file, background_access_shell
device.hw_info.serial_number
- Description: The device manufacturer serial number.
- Source:
system.serialno - Usage: background_access_file, background_access_shell
device.name
- Description: The alternate device name, ordinarily as assigned by an administrator.
Note: The Name could be any other string that helps to identify the device, such as a phone number; for example
310-555-1234. - Source:
system.displayName - Usage: background_access_file, background_access_shell
device.uid
- Description: The unique identifier of the device. For example the Windows TargetSID or AWS EC2 ARN.
- Source:
resource.id,system.id - Usage: background_access_file, background_access_shell, command_result, policy_result
Entity
entity.data.auth_method
- Description: JumpCloud extension data on the managed entity:
auth_method. - Source:
auth_method - Usage: 28 events: authnfallbackpolicy_create, authnfallbackpolicy_delete, authnfallbackpolicy_update, authnpolicy_create, authnpolicy_delete, authnpolicy_mfa_factor_selection_update, authnpolicy_update, command_create, ... (+20 more)
entity.data.changed_field
- Description: JumpCloud extension data on the managed entity:
changed_field. - Source:
changes.field - Usage: 27 events: authnfallbackpolicy_create, authnfallbackpolicy_delete, authnfallbackpolicy_update, authnpolicy_create, authnpolicy_delete, authnpolicy_mfa_factor_selection_update, authnpolicy_update, command_create, ... (+19 more)
entity.data.changes_from
- Description: JumpCloud extension data on the managed entity:
changes_from. - Source:
changes.from - Usage: authnpolicy_mfa_factor_selection_update, command_delete, command_update, commandtemplate_delete, file_delete, file_update, iplist_delete, iplist_update, policy_delete, policy_update
entity.data.changes_from_all_deviceEncrypted
- Description: JumpCloud extension data on the managed entity:
changes_from_all_deviceEncrypted. - Source:
changes.from.all.deviceEncrypted - Usage: authnpolicy_delete
entity.data.changes_from_all_deviceManaged
- Description: JumpCloud extension data on the managed entity:
changes_from_all_deviceManaged. - Source:
changes.from.all.deviceManaged - Usage: authnpolicy_delete, authnpolicy_update
entity.data.changes_from_all_ipAddressIn
- Description: JumpCloud extension data on the managed entity:
changes_from_all_ipAddressIn. - Source:
changes.from.all.ipAddressIn - Usage: authnpolicy_delete, authnpolicy_update
entity.data.changes_from_all_locationIn_countries
- Description: JumpCloud extension data on the managed entity:
changes_from_all_locationIn_countries. - Source:
changes.from.all.locationIn.countries - Usage: authnpolicy_delete, authnpolicy_update
entity.data.changes_from_any_deviceEncrypted
- Description: JumpCloud extension data on the managed entity:
changes_from_any_deviceEncrypted. - Source:
changes.from.any.deviceEncrypted - Usage: authnpolicy_delete
entity.data.changes_from_any_deviceManaged
- Description: JumpCloud extension data on the managed entity:
changes_from_any_deviceManaged. - Source:
changes.from.any.deviceManaged - Usage: authnpolicy_delete
entity.data.changes_from_any_not_ipAddressIn
- Description: JumpCloud extension data on the managed entity:
changes_from_any_not_ipAddressIn. - Source:
changes.from.any.not.ipAddressIn - Usage: authnpolicy_delete
entity.data.changes_from_any_not_locationIn_countries
- Description: JumpCloud extension data on the managed entity:
changes_from_any_not_locationIn_countries. - Source:
changes.from.any.not.locationIn.countries - Usage: authnpolicy_delete
entity.data.changes_from_exclusions
- Description: JumpCloud extension data on the managed entity:
changes_from_exclusions. - Source:
changes.from.exclusions - Usage: authnpolicy_delete
entity.data.changes_from_id
- Description: JumpCloud extension data on the managed entity:
changes_from_id. - Source:
changes.from.id - Usage: authnpolicy_delete
entity.data.changes_from_inclusions
- Description: JumpCloud extension data on the managed entity:
changes_from_inclusions. - Source:
changes.from.inclusions - Usage: authnpolicy_delete
entity.data.changes_from_locationIn_countries
- Description: JumpCloud extension data on the managed entity:
changes_from_locationIn_countries. - Source:
changes.from.locationIn.countries - Usage: authnpolicy_delete
entity.data.changes_from_mfaFactors
- Description: JumpCloud extension data on the managed entity:
changes_from_mfaFactors. - Source:
changes.from.mfaFactors - Usage: authnfallbackpolicy_update
entity.data.changes_from_mfaFactors_id_data
- Description: JumpCloud extension data on the managed entity:
changes_from_mfaFactors_id_data. - Source:
changes.from.mfaFactors.id.data - Usage: authnfallbackpolicy_delete
entity.data.changes_from_mfaFactors_id_type
- Description: JumpCloud extension data on the managed entity:
changes_from_mfaFactors_id_type. - Source:
changes.from.mfaFactors.id.type - Usage: authnfallbackpolicy_delete
entity.data.changes_from_mfaFactors_type
- Description: JumpCloud extension data on the managed entity:
changes_from_mfaFactors_type. - Source:
changes.from.mfaFactors.type - Usage: authnfallbackpolicy_delete
entity.data.changes_from_mfa_required
- Description: JumpCloud extension data on the managed entity:
changes_from_mfa_required. - Source:
changes.from.mfa.required - Usage: authnfallbackpolicy_delete, authnfallbackpolicy_update, authnpolicy_delete
entity.data.changes_from_type
- Description: JumpCloud extension data on the managed entity:
changes_from_type. - Source:
changes.from.type - Usage: authnpolicy_delete
entity.data.changes_from_userVerification_requirement
- Description: JumpCloud extension data on the managed entity:
changes_from_userVerification_requirement. - Source:
changes.from.userVerification.requirement - Usage: authnfallbackpolicy_delete, authnfallbackpolicy_update
entity.data.changes_to
- Description: JumpCloud extension data on the managed entity:
changes_to. - Source:
changes.to - Usage: policygrouptemplate_delete
entity.data.command
- Description: JumpCloud extension data on the managed entity:
command. - Source:
resource.command - Usage: commandresult_delete
entity.data.initiated_by_provider
- Description: JumpCloud extension data on the managed entity:
initiated_by_provider. - Source:
initiated_by.provider - Usage: 14 events: authnfallbackpolicy_delete, authnpolicy_mfa_factor_selection_update, command_run, command_update, commandtemplate_create, commandtemplate_delete, commandtemplate_update, configuredpolicytemplate_create, ... (+6 more)
entity.data.initiated_by_user_id
- Description: JumpCloud extension data on the managed entity:
initiated_by_user_id. - Source:
initiated_by.user_id - Usage: command_run, file_delete, file_update
entity.data.metadata.action
- Description: JumpCloud extension data on the managed entity:
metadata.action. - Source:
resource.metadata.action - Usage: authnpolicy_create, authnpolicy_delete, authnpolicy_update
entity.data.metadata.conditions
- Description: JumpCloud extension data on the managed entity:
metadata.conditions. - Source:
resource.metadata.conditions - Usage: authnpolicy_create, authnpolicy_delete, authnpolicy_update
entity.data.metadata.resource_type
- Description: JumpCloud extension data on the managed entity:
metadata.resource_type. - Source:
resource.metadata.resource_type - Usage: authnpolicy_create, authnpolicy_delete, authnpolicy_update
entity.data.metadata.targets
- Description: JumpCloud extension data on the managed entity:
metadata.targets. - Source:
resource.metadata.targets - Usage: authnpolicy_create, authnpolicy_delete, authnpolicy_update
entity.data.os_meta_family
- Description: JumpCloud extension data on the managed entity:
os_meta_family. - Source:
os_meta_family - Usage: policy_create, policy_delete, policy_update
entity.data.provider
- Description: JumpCloud extension data on the managed entity:
provider. - Source:
provider - Usage: 27 events: authnfallbackpolicy_create, authnfallbackpolicy_delete, authnfallbackpolicy_update, authnpolicy_create, authnpolicy_delete, authnpolicy_mfa_factor_selection_update, authnpolicy_update, command_create, ... (+19 more)
entity.data.resourceType
- Description: JumpCloud extension data on the managed entity:
resourceType. - Source:
resource.resourceType - Usage: authnfallbackpolicy_create, authnfallbackpolicy_delete, authnfallbackpolicy_update
entity.data.workflow_id
- Description: JumpCloud extension data on the managed entity:
workflow_id. - Source:
initiated_by.source_metadata.workflow.id - Usage: command_run
entity.data.workflow_run_id
- Description: JumpCloud extension data on the managed entity:
workflow_run_id. - Source:
initiated_by.source_metadata.workflow.run_id - Usage: command_run
entity.data.workflow_type
- Description: JumpCloud extension data on the managed entity:
workflow_type. - Source:
initiated_by.source_metadata.workflow.type - Usage: command_run
entity.name
- Description: The name of the managed entity. It should match the name of the specific entity object's name if populated, or the name of the managed entity if the
type_idis 'Other'. - Source:
resource.name - Usage: 23 events: authnpolicy_create, authnpolicy_delete, authnpolicy_mfa_factor_selection_update, authnpolicy_update, command_create, command_delete, command_run, command_update, ... (+15 more)
entity.type
- Description: The managed entity type. For example:
Policy,User,Organization,Device. - Source:
resource.type - Usage: 31 events: authnfallbackpolicy_create, authnfallbackpolicy_delete, authnfallbackpolicy_update, authnpolicy_create, authnpolicy_delete, authnpolicy_mfa_factor_selection_update, authnpolicy_update, command_create, ... (+23 more)
entity.uid
- Description: The identifier of the managed entity. It should match the
uidof the specific entity's object UID if populated, or the source specific ID if thetype_idis 'Other'. - Source:
resource.id - Usage: 27 events: authnpolicy_create, authnpolicy_delete, authnpolicy_mfa_factor_selection_update, authnpolicy_update, command_delete, command_run, command_update, commandresult_delete, ... (+19 more)
entity_result.data.changes_to
- Description: JumpCloud extension data on the managed entity:
changes_to. - Source:
changes.to - Usage: 14 events: authnpolicy_mfa_factor_selection_update, authnpolicy_update, command_create, command_update, commandtemplate_create, commandtemplate_update, configuredpolicytemplate_delete, file_create, ... (+6 more)
entity_result.data.changes_to_all_deviceManaged
- Description: JumpCloud extension data on the managed entity:
changes_to_all_deviceManaged. - Source:
changes.to.all.deviceManaged - Usage: authnpolicy_create
entity_result.data.changes_to_all_ipAddressIn
- Description: JumpCloud extension data on the managed entity:
changes_to_all_ipAddressIn. - Source:
changes.to.all.ipAddressIn - Usage: authnpolicy_create
entity_result.data.changes_to_all_locationIn_countries
- Description: JumpCloud extension data on the managed entity:
changes_to_all_locationIn_countries. - Source:
changes.to.all.locationIn.countries - Usage: authnpolicy_create
entity_result.data.changes_to_all_operatingSystemIn
- Description: JumpCloud extension data on the managed entity:
changes_to_all_operatingSystemIn. - Source:
changes.to.all.operatingSystemIn - Usage: authnpolicy_create
entity_result.data.changes_to_any_deviceEncrypted
- Description: JumpCloud extension data on the managed entity:
changes_to_any_deviceEncrypted. - Source:
changes.to.any.deviceEncrypted - Usage: authnpolicy_create
entity_result.data.changes_to_any_deviceManaged
- Description: JumpCloud extension data on the managed entity:
changes_to_any_deviceManaged. - Source:
changes.to.any.deviceManaged - Usage: authnpolicy_create
entity_result.data.changes_to_any_ipAddressIn
- Description: JumpCloud extension data on the managed entity:
changes_to_any_ipAddressIn. - Source:
changes.to.any.ipAddressIn - Usage: authnpolicy_create
entity_result.data.changes_to_any_locationIn_countries
- Description: JumpCloud extension data on the managed entity:
changes_to_any_locationIn_countries. - Source:
changes.to.any.locationIn.countries - Usage: authnpolicy_create
entity_result.data.changes_to_any_not_ipAddressIn
- Description: JumpCloud extension data on the managed entity:
changes_to_any_not_ipAddressIn. - Source:
changes.to.any.not.ipAddressIn - Usage: authnpolicy_create
entity_result.data.changes_to_any_not_locationIn_countries
- Description: JumpCloud extension data on the managed entity:
changes_to_any_not_locationIn_countries. - Source:
changes.to.any.not.locationIn.countries - Usage: authnpolicy_create
entity_result.data.changes_to_any_operatingSystemIn
- Description: JumpCloud extension data on the managed entity:
changes_to_any_operatingSystemIn. - Source:
changes.to.any.operatingSystemIn - Usage: authnpolicy_create
entity_result.data.changes_to_configFieldID
- Description: JumpCloud extension data on the managed entity:
changes_to_configFieldID. - Source:
changes.to.configFieldID - Usage: configuredpolicytemplate_create
entity_result.data.changes_to_configFieldName
- Description: JumpCloud extension data on the managed entity:
changes_to_configFieldName. - Source:
changes.to.configFieldName - Usage: configuredpolicytemplate_create
entity_result.data.changes_to_deviceManaged
- Description: JumpCloud extension data on the managed entity:
changes_to_deviceManaged. - Source:
changes.to.deviceManaged - Usage: authnpolicy_create
entity_result.data.changes_to_exclusions
- Description: JumpCloud extension data on the managed entity:
changes_to_exclusions. - Source:
changes.to.exclusions - Usage: authnpolicy_create
entity_result.data.changes_to_id
- Description: JumpCloud extension data on the managed entity:
changes_to_id. - Source:
changes.to.id - Usage: authnpolicy_create
entity_result.data.changes_to_inclusions
- Description: JumpCloud extension data on the managed entity:
changes_to_inclusions. - Source:
changes.to.inclusions - Usage: authnpolicy_create
entity_result.data.changes_to_ipAddressIn
- Description: JumpCloud extension data on the managed entity:
changes_to_ipAddressIn. - Source:
changes.to.ipAddressIn - Usage: authnpolicy_create
entity_result.data.changes_to_locationIn_countries
- Description: JumpCloud extension data on the managed entity:
changes_to_locationIn_countries. - Source:
changes.to.locationIn.countries - Usage: authnpolicy_create
entity_result.data.changes_to_mfaFactors
- Description: JumpCloud extension data on the managed entity:
changes_to_mfaFactors. - Source:
changes.to.mfaFactors - Usage: authnfallbackpolicy_create, authnfallbackpolicy_update
entity_result.data.changes_to_mfa_required
- Description: JumpCloud extension data on the managed entity:
changes_to_mfa_required. - Source:
changes.to.mfa.required - Usage: authnfallbackpolicy_create, authnfallbackpolicy_update, authnpolicy_create
entity_result.data.changes_to_nanos
- Description: JumpCloud extension data on the managed entity:
changes_to_nanos. - Source:
changes.to.nanos - Usage: commandresult_delete
entity_result.data.changes_to_not_ipAddressIn
- Description: JumpCloud extension data on the managed entity:
changes_to_not_ipAddressIn. - Source:
changes.to.not.ipAddressIn - Usage: authnpolicy_create
entity_result.data.changes_to_operatingSystemIn
- Description: JumpCloud extension data on the managed entity:
changes_to_operatingSystemIn. - Source:
changes.to.operatingSystemIn - Usage: authnpolicy_create
entity_result.data.changes_to_seconds
- Description: JumpCloud extension data on the managed entity:
changes_to_seconds. - Source:
changes.to.seconds - Usage: commandresult_delete
entity_result.data.changes_to_sensitive
- Description: JumpCloud extension data on the managed entity:
changes_to_sensitive. - Source:
changes.to.sensitive - Usage: configuredpolicytemplate_create
entity_result.data.changes_to_type
- Description: JumpCloud extension data on the managed entity:
changes_to_type. - Source:
changes.to.type - Usage: authnpolicy_create
entity_result.data.changes_to_userVerification_requirement
- Description: JumpCloud extension data on the managed entity:
changes_to_userVerification_requirement. - Source:
changes.to.userVerification.requirement - Usage: authnfallbackpolicy_create, authnfallbackpolicy_update
entity_result.data.changes_to_value
- Description: JumpCloud extension data on the managed entity:
changes_to_value. - Source:
changes.to.value - Usage: configuredpolicytemplate_create
Src Endpoint
src_endpoint.autonomous_system.name
- Description: Organization name for the Autonomous System.
- Source:
asn.organization - Usage: 16 events: authnfallbackpolicy_delete, authnpolicy_mfa_factor_selection_update, command_delete, command_run, commandresult_delete, commandtemplate_create, commandtemplate_delete, commandtemplate_update, ... (+8 more)
src_endpoint.autonomous_system.number
- Description: Unique number that the AS is identified by.
- Source:
asn.number - Transform:
asn.number→int(16 events: authnfallbackpolicy_delete, authnpolicy_mfa_factor_selection_update, command_delete, command_run, commandresult_delete, commandtemplate_create, commandtemplate_delete, commandtemplate_update, ... (+8 more))- Usage: 16 events: authnfallbackpolicy_delete, authnpolicy_mfa_factor_selection_update, command_delete, command_run, commandresult_delete, commandtemplate_create, commandtemplate_delete, commandtemplate_update, ... (+8 more)
src_endpoint.ip
- Description: Source IP address the request originated from.
- Source:
client_ip - Usage: 31 events: authnfallbackpolicy_create, authnfallbackpolicy_delete, authnfallbackpolicy_update, authnpolicy_create, authnpolicy_delete, authnpolicy_mfa_factor_selection_update, authnpolicy_update, command_create, ... (+23 more)
src_endpoint.location.city
- Description: The name of the city.
- Source:
geoip.city - Usage: 18 events: authnfallbackpolicy_delete, authnpolicy_mfa_factor_selection_update, command_delete, command_run, command_update, commandresult_delete, commandtemplate_create, commandtemplate_delete, ... (+10 more)
src_endpoint.location.continent
- Description: The name of the continent.
- Source:
geoip.continent_code - Usage: 28 events: authnfallbackpolicy_create, authnfallbackpolicy_delete, authnfallbackpolicy_update, authnpolicy_create, authnpolicy_delete, authnpolicy_mfa_factor_selection_update, authnpolicy_update, command_create, ... (+20 more)
src_endpoint.location.country
- Description: The ISO 3166-1 Alpha-2 country code.
Note: The two letter country code should be capitalized. For example:
USorCA. - Source:
geoip.country_code - Usage: 28 events: authnfallbackpolicy_create, authnfallbackpolicy_delete, authnfallbackpolicy_update, authnpolicy_create, authnpolicy_delete, authnpolicy_mfa_factor_selection_update, authnpolicy_update, command_create, ... (+20 more)
src_endpoint.location.lat
- Description: The geographical Latitude coordinate represented in Decimal Degrees (DD). For example:
42.361145. - Source:
geoip.latitude - Transform:
geoip.latitude→double(28 events: authnfallbackpolicy_create, authnfallbackpolicy_delete, authnfallbackpolicy_update, authnpolicy_create, authnpolicy_delete, authnpolicy_mfa_factor_selection_update, authnpolicy_update, command_create, ... (+20 more))- Usage: 28 events: authnfallbackpolicy_create, authnfallbackpolicy_delete, authnfallbackpolicy_update, authnpolicy_create, authnpolicy_delete, authnpolicy_mfa_factor_selection_update, authnpolicy_update, command_create, ... (+20 more)
src_endpoint.location.long
- Description: The geographical Longitude coordinate represented in Decimal Degrees (DD). For example:
-71.057083. - Source:
geoip.longitude - Transform:
geoip.longitude→double(28 events: authnfallbackpolicy_create, authnfallbackpolicy_delete, authnfallbackpolicy_update, authnpolicy_create, authnpolicy_delete, authnpolicy_mfa_factor_selection_update, authnpolicy_update, command_create, ... (+20 more))- Usage: 28 events: authnfallbackpolicy_create, authnfallbackpolicy_delete, authnfallbackpolicy_update, authnpolicy_create, authnpolicy_delete, authnpolicy_mfa_factor_selection_update, authnpolicy_update, command_create, ... (+20 more)
src_endpoint.location.region
- Description: The alphanumeric code that identifies the principal subdivision (e.g. province or state) of the country. For example, 'CH-VD' for the Canton of Vaud, Switzerland
- Source:
geoip.region_code - Usage: 28 events: authnfallbackpolicy_create, authnfallbackpolicy_delete, authnfallbackpolicy_update, authnpolicy_create, authnpolicy_delete, authnpolicy_mfa_factor_selection_update, authnpolicy_update, command_create, ... (+20 more)
Http Request
http_request.user_agent
- Description: The request header that identifies the operating system and web browser.
- Source:
user_agent - Usage: 21 events: authnfallbackpolicy_delete, authnpolicy_mfa_factor_selection_update, command_delete, command_run, command_update, commandresult_delete, commandtemplate_create, commandtemplate_delete, ... (+13 more)
Observables
observables[].name
- Description: The full name of the observable attribute. The
nameis a pointer/reference to an attribute within the OCSF event data. For example:file.name. Array attributes may be represented in one of three ways. For example:resources.uid,resources[].uid,resources[0].uid. - Literal:
actor.user.email_addr,actor.user.name,actor.user.uid,device.hostname,device.hw_info.serial_number,device.uid,http_request.user_agent,process.cmd_line,src_endpoint.ip,src_endpoint.location.country - Usage: all events in this service
observables[].type_id
- Description: The observable value type identifier.
- Literal:
1,13,14,16,2,31,37,4,47,5 - Usage: all events in this service
observables[].value
- Description: The value associated with the observable attribute. The meaning of the value depends on the observable type.
If thenamerefers to a scalar attribute, then thevalueis the value of the attribute.
If thenamerefers to an object attribute, then thevalueis not populated. - Source:
admin_info.email,admin_info.id,admin_info.name,client_ip,commands.command,geoip.country_code,initiated_by.email,initiated_by.id,initiated_by.name,resource.id,system.hostname,system.id,system.serialno,user_agent - Usage: all events in this service
Other
job.desc
- Description: The description of the job.
- Source:
resource.command_id - Usage: command_result
job.name
- Description: The name of the job.
- Source:
resource.command_name - Usage: command_result
policy.name
- Description: The policy name. For example:
AdministratorAccess Policy. - Source:
resource.policy_name - Usage: policy_result
policy.uid
- Description: A unique identifier of the policy instance.
- Source:
resource.policy_id - Usage: policy_result
process.cmd_line
- Description: The full command line used to launch an application, service, process, or job. For example:
ssh user@10.0.0.10. If the command line is unavailable or missing, the empty string''is to be used. - Source:
commands.command - Usage: background_access_shell
process.created_time
- Description: The time when the process was created/started.
- Source:
commands.timestamp - Usage: background_access_file, background_access_shell
state
- Description: The normalized state of a security finding.
- Source:
state - Usage: policy_result
Unmapped
unmapped.@timestamp
- Description: JumpCloud Directory Insights field
@timestamppreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
@timestamp - Usage: 15 events: authnfallbackpolicy_create, authnfallbackpolicy_update, authnpolicy_create, authnpolicy_delete, authnpolicy_update, command_create, command_delete, command_result, ... (+7 more)
unmapped.@version
- Description: JumpCloud Directory Insights field
@versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
@version - Usage: all events in this service
unmapped.asn.error
- Description: JumpCloud Directory Insights field
asn.errorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
asn.error - Usage: background_access_file, background_access_shell
unmapped.asn.ip_address
- Description: JumpCloud Directory Insights field
asn.ip_addresspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
asn.ip_address - Usage: background_access_file, background_access_shell
unmapped.asn.network
- Description: JumpCloud Directory Insights field
asn.networkpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
asn.network - Usage: 17 events: authnfallbackpolicy_delete, authnpolicy_mfa_factor_selection_update, background_access_file, command_delete, command_run, commandresult_delete, commandtemplate_create, commandtemplate_delete, ... (+9 more)
unmapped.asn.number
- Description: JumpCloud Directory Insights field
asn.numberpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
asn.number - Usage: background_access_file
unmapped.asn.organization
- Description: JumpCloud Directory Insights field
asn.organizationpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
asn.organization - Usage: background_access_file
unmapped.client_ip
- Description: JumpCloud Directory Insights field
client_ippreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
client_ip - Usage: background_access_file, background_access_shell, command_result, policy_result
unmapped.commands.type
- Description: JumpCloud Directory Insights field
commands.typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
commands.type - Usage: background_access_file
unmapped.correlation
- Description: JumpCloud Directory Insights field
correlationpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
correlation - Usage: command_delete, command_update
unmapped.correlation.id
- Description: JumpCloud Directory Insights field
correlation.idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
correlation.id - Usage: background_access_file, background_access_shell
unmapped.correlation.session_duration
- Description: JumpCloud Directory Insights field
correlation.session_durationpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
correlation.session_duration - Usage: background_access_file, background_access_shell
unmapped.correlation.type
- Description: JumpCloud Directory Insights field
correlation.typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
correlation.type - Usage: background_access_file, background_access_shell
unmapped.exit_code
- Description: JumpCloud Directory Insights field
exit_codepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
exit_code - Usage: command_result
unmapped.file_input_timestamp
- Description: JumpCloud Directory Insights field
file_input_timestamppreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
file_input_timestamp - Usage: 16 events: authnfallbackpolicy_create, authnfallbackpolicy_update, authnpolicy_create, authnpolicy_delete, authnpolicy_update, background_access_file, command_create, command_delete, ... (+8 more)
unmapped.geoip.city
- Description: JumpCloud Directory Insights field
geoip.citypreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.city - Usage: background_access_file
unmapped.geoip.continent_code
- Description: JumpCloud Directory Insights field
geoip.continent_codepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.continent_code - Usage: background_access_file
unmapped.geoip.country_code
- Description: JumpCloud Directory Insights field
geoip.country_codepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.country_code - Usage: background_access_file
unmapped.geoip.error
- Description: JumpCloud Directory Insights field
geoip.errorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.error - Usage: background_access_file, background_access_shell
unmapped.geoip.ip_address
- Description: JumpCloud Directory Insights field
geoip.ip_addresspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.ip_address - Usage: background_access_file, background_access_shell
unmapped.geoip.latitude
- Description: JumpCloud Directory Insights field
geoip.latitudepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.latitude - Usage: background_access_file
unmapped.geoip.longitude
- Description: JumpCloud Directory Insights field
geoip.longitudepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.longitude - Usage: background_access_file
unmapped.geoip.region_code
- Description: JumpCloud Directory Insights field
geoip.region_codepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.region_code - Usage: background_access_file
unmapped.geoip.region_name
- Description: JumpCloud Directory Insights field
geoip.region_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.region_name - Usage: 29 events: authnfallbackpolicy_create, authnfallbackpolicy_delete, authnfallbackpolicy_update, authnpolicy_create, authnpolicy_delete, authnpolicy_mfa_factor_selection_update, authnpolicy_update, background_access_file, ... (+21 more)
unmapped.geoip.timezone
- Description: JumpCloud Directory Insights field
geoip.timezonepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.timezone - Usage: 29 events: authnfallbackpolicy_create, authnfallbackpolicy_delete, authnfallbackpolicy_update, authnpolicy_create, authnpolicy_delete, authnpolicy_mfa_factor_selection_update, authnpolicy_update, background_access_file, ... (+21 more)
unmapped.initiated_by
- Description: JumpCloud Directory Insights field
initiated_bypreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by - Usage: command_result, policy_result
unmapped.initiated_by.hostname
- Description: JumpCloud Directory Insights field
initiated_by.hostnamepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by.hostname - Usage: background_access_file, background_access_shell
unmapped.initiated_by.uid
- Description: JumpCloud Directory Insights field
initiated_by.uidpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by.uid - Usage: background_access_file, background_access_shell
unmapped.initiated_by.username
- Description: JumpCloud Directory Insights field
initiated_by.usernamepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by.username - Usage: background_access_file, background_access_shell
unmapped.initiated_by_email_hash
- Description: JumpCloud Directory Insights field
initiated_by_email_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_email_hash - Usage: 24 events: authnfallbackpolicy_delete, authnfallbackpolicy_update, authnpolicy_mfa_factor_selection_update, background_access_file, background_access_shell, command_delete, command_run, command_update, ... (+16 more)
unmapped.initiated_by_id_hash
- Description: JumpCloud Directory Insights field
initiated_by_id_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_id_hash - Usage: 24 events: authnfallbackpolicy_delete, authnfallbackpolicy_update, authnpolicy_mfa_factor_selection_update, background_access_file, background_access_shell, command_delete, command_run, command_update, ... (+16 more)
unmapped.initiated_by_name_hash
- Description: JumpCloud Directory Insights field
initiated_by_name_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_name_hash - Usage: command_run
unmapped.is_out_of_bound
- Description: JumpCloud Directory Insights field
is_out_of_boundpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
is_out_of_bound - Usage: 25 events: authnfallbackpolicy_delete, authnpolicy_mfa_factor_selection_update, background_access_file, background_access_shell, command_delete, command_result, command_run, command_update, ... (+17 more)
unmapped.jc_application_name
- Description: JumpCloud Directory Insights field
jc_application_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_application_name - Usage: 25 events: authnfallbackpolicy_delete, authnpolicy_mfa_factor_selection_update, background_access_file, background_access_shell, command_delete, command_result, command_run, command_update, ... (+17 more)
unmapped.jc_initiated_by_email
- Description: JumpCloud Directory Insights field
jc_initiated_by_emailpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_initiated_by_email - Usage: authnfallbackpolicy_delete, command_delete, commandtemplate_delete, commandtemplate_update, iplist_update, passwordpolicy_create, passwordpolicy_delete
unmapped.jc_initiated_by_username
- Description: JumpCloud Directory Insights field
jc_initiated_by_usernamepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_initiated_by_username - Usage: authnfallbackpolicy_delete, command_delete, commandtemplate_delete, commandtemplate_update, iplist_update, passwordpolicy_create, passwordpolicy_delete
unmapped.jc_organization_name
- Description: JumpCloud Directory Insights field
jc_organization_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_organization_name - Usage: authnfallbackpolicy_delete, command_delete, commandtemplate_delete, commandtemplate_update, iplist_update, passwordpolicy_create, passwordpolicy_delete
unmapped.jc_provider_id
- Description: JumpCloud Directory Insights field
jc_provider_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_provider_id - Usage: authnfallbackpolicy_delete, command_delete, commandtemplate_delete, commandtemplate_update, passwordpolicy_create, passwordpolicy_delete
unmapped.message_chain
- Description: JumpCloud Directory Insights field
message_chainpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
message_chain - Usage: background_access_file, command_delete, command_result, command_update
unmapped.previous_state
- Description: JumpCloud Directory Insights field
previous_statepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
previous_state - Usage: policy_result
unmapped.resource.policy_template_id
- Description: JumpCloud Directory Insights field
resource.policy_template_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.policy_template_id - Usage: policy_result
unmapped.resource.policy_template_name
- Description: JumpCloud Directory Insights field
resource.policy_template_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.policy_template_name - Usage: policy_result
unmapped.resource.type
- Description: JumpCloud Directory Insights field
resource.typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.type - Usage: command_result, policy_result
unmapped.resource_id_hash
- Description: JumpCloud Directory Insights field
resource_id_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource_id_hash - Usage: 22 events: authnpolicy_mfa_factor_selection_update, command_delete, command_result, command_run, command_update, commandresult_delete, commandtemplate_create, commandtemplate_delete, ... (+14 more)
unmapped.system_id_hash
- Description: JumpCloud Directory Insights field
system_id_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
system_id_hash - Usage: background_access_file
unmapped.tags
- Description: JumpCloud Directory Insights field
tagspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
tags - Usage: 16 events: authnfallbackpolicy_create, authnfallbackpolicy_update, authnpolicy_create, authnpolicy_delete, authnpolicy_update, background_access_file, command_create, command_delete, ... (+8 more)
unmapped.timestamp_source
- Description: JumpCloud Directory Insights field
timestamp_sourcepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
timestamp_source - Usage: background_access_file, background_access_shell, command_result, passwordpolicy_create, passwordpolicy_delete, passwordpolicy_update, policy_result
unmapped.user_agent
- Description: JumpCloud Directory Insights field
user_agentpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
user_agent - Usage: background_access_file, background_access_shell, command_result, policy_result
unmapped.useragent.device
- Description: JumpCloud Directory Insights field
useragent.devicepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.device - Usage: 31 events: authnfallbackpolicy_create, authnfallbackpolicy_delete, authnfallbackpolicy_update, authnpolicy_create, authnpolicy_delete, authnpolicy_mfa_factor_selection_update, authnpolicy_update, command_create, ... (+23 more)
unmapped.useragent.major
- Description: JumpCloud Directory Insights field
useragent.majorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.major - Usage: 24 events: authnfallbackpolicy_delete, authnpolicy_create, authnpolicy_delete, authnpolicy_mfa_factor_selection_update, authnpolicy_update, command_delete, command_run, command_update, ... (+16 more)
unmapped.useragent.minor
- Description: JumpCloud Directory Insights field
useragent.minorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.minor - Usage: 24 events: authnfallbackpolicy_delete, authnpolicy_create, authnpolicy_delete, authnpolicy_mfa_factor_selection_update, authnpolicy_update, command_delete, command_run, command_update, ... (+16 more)
unmapped.useragent.name
- Description: JumpCloud Directory Insights field
useragent.namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.name - Usage: 31 events: authnfallbackpolicy_create, authnfallbackpolicy_delete, authnfallbackpolicy_update, authnpolicy_create, authnpolicy_delete, authnpolicy_mfa_factor_selection_update, authnpolicy_update, command_create, ... (+23 more)
unmapped.useragent.os
- Description: JumpCloud Directory Insights field
useragent.ospreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os - Usage: 31 events: authnfallbackpolicy_create, authnfallbackpolicy_delete, authnfallbackpolicy_update, authnpolicy_create, authnpolicy_delete, authnpolicy_mfa_factor_selection_update, authnpolicy_update, command_create, ... (+23 more)
unmapped.useragent.os_full
- Description: JumpCloud Directory Insights field
useragent.os_fullpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_full - Usage: 31 events: authnfallbackpolicy_create, authnfallbackpolicy_delete, authnfallbackpolicy_update, authnpolicy_create, authnpolicy_delete, authnpolicy_mfa_factor_selection_update, authnpolicy_update, command_create, ... (+23 more)
unmapped.useragent.os_major
- Description: JumpCloud Directory Insights field
useragent.os_majorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_major - Usage: 18 events: authnfallbackpolicy_delete, authnpolicy_mfa_factor_selection_update, command_delete, command_run, command_update, commandresult_delete, configuredpolicytemplate_create, configuredpolicytemplate_delete, ... (+10 more)
unmapped.useragent.os_minor
- Description: JumpCloud Directory Insights field
useragent.os_minorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_minor - Usage: 17 events: authnfallbackpolicy_delete, authnpolicy_mfa_factor_selection_update, command_delete, command_run, command_update, commandresult_delete, configuredpolicytemplate_create, configuredpolicytemplate_delete, ... (+9 more)
unmapped.useragent.os_name
- Description: JumpCloud Directory Insights field
useragent.os_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_name - Usage: 31 events: authnfallbackpolicy_create, authnfallbackpolicy_delete, authnfallbackpolicy_update, authnpolicy_create, authnpolicy_delete, authnpolicy_mfa_factor_selection_update, authnpolicy_update, command_create, ... (+23 more)
unmapped.useragent.os_patch
- Description: JumpCloud Directory Insights field
useragent.os_patchpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_patch - Usage: 17 events: authnfallbackpolicy_delete, authnpolicy_mfa_factor_selection_update, command_delete, command_run, command_update, commandresult_delete, configuredpolicytemplate_create, configuredpolicytemplate_delete, ... (+9 more)
unmapped.useragent.os_version
- Description: JumpCloud Directory Insights field
useragent.os_versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_version - Usage: 18 events: authnfallbackpolicy_delete, authnpolicy_mfa_factor_selection_update, command_delete, command_run, command_update, commandresult_delete, configuredpolicytemplate_create, configuredpolicytemplate_delete, ... (+10 more)
unmapped.useragent.patch
- Description: JumpCloud Directory Insights field
useragent.patchpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.patch - Usage: 21 events: authnfallbackpolicy_delete, authnpolicy_create, authnpolicy_delete, authnpolicy_mfa_factor_selection_update, authnpolicy_update, command_delete, command_run, command_update, ... (+13 more)
unmapped.useragent.version
- Description: JumpCloud Directory Insights field
useragent.versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.version - Usage: 24 events: authnfallbackpolicy_delete, authnpolicy_create, authnpolicy_delete, authnpolicy_mfa_factor_selection_update, authnpolicy_update, command_delete, command_run, command_update, ... (+16 more)
unmapped.username
- Description: JumpCloud Directory Insights field
usernamepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
username - Usage: background_access_file, background_access_shell
Directory — Integrations#
directory_integrations · 56 events
| Event | Category | Class | Activity | Type UID | Fields |
|---|---|---|---|---|---|
account_resync_failure |
Application Activity (6) | API Activity (6003) | Update (3) | 600303 | 70 |
account_resync_initiated |
Application Activity (6) | API Activity (6003) | Update (3) | 600303 | 71 |
activedirectory_agent_activate |
Identity & Access Management (3) | Entity Management (3004) | Enable (8) | 300408 | 56 |
activedirectory_agent_active |
Identity & Access Management (3) | Entity Management (3004) | Enable (8) | 300408 | 57 |
activedirectory_agent_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 66 |
activedirectory_agent_deleted |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 60 |
activedirectory_agent_inactive |
Identity & Access Management (3) | Entity Management (3004) | Disable (9) | 300409 | 56 |
activedirectory_config_selection_updated |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 61 |
activedirectory_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 47 |
activedirectory_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 70 |
activedirectory_domain_delegated_password_change |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 62 |
activedirectory_primary_agent_switch |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 54 |
attributemappings_add |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 82 |
attributemappings_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 93 |
attributemappings_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 87 |
connector_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 72 |
connector_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 73 |
connector_execute |
Application Activity (6) | API Activity (6003) | Read (2) | 600302 | 54 |
connector_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 70 |
duo_configuration_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 65 |
duoaccount_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 62 |
duoapplication_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 64 |
duoapplication_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 62 |
duoapplication_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 62 |
gsuite_directory_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 65 |
gsuite_directory_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 65 |
gsuite_directory_reactivate |
Identity & Access Management (3) | Entity Management (3004) | Enable (8) | 300408 | 61 |
gsuite_directory_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 62 |
idm_integration_activate |
Identity & Access Management (3) | Entity Management (3004) | Activate (10) | 300410 | 111 |
idm_integration_auth |
Identity & Access Management (3) | Authentication (3002) | Logon (1) | 300201 | 68 |
idm_integration_deactivate |
Identity & Access Management (3) | Entity Management (3004) | Deactivate (11) | 300411 | 73 |
idm_integration_reauth |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 82 |
idm_integration_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 107 |
idp_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 54 |
idp_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 63 |
idp_routing_policy_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 70 |
idp_routing_policy_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 66 |
idp_routing_policy_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 64 |
idp_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 64 |
idsource_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 53 |
idsource_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 72 |
idsource_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 72 |
integration_default_domain_add |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 56 |
integration_default_domain_delete |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 56 |
integration_default_domain_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 56 |
integration_domain_add |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 65 |
integration_domain_delete |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 63 |
ldap_server_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 60 |
o365_directory_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 65 |
o365_directory_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 65 |
o365_directory_reactivate |
Identity & Access Management (3) | Entity Management (3004) | Activate (10) | 300410 | 65 |
o365_directory_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 66 |
sambadomain_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 55 |
sambadomain_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 65 |
sambadomain_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 68 |
workday_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 60 |
OCSF field mappings#
Legend
- Description: what the OCSF field represents (from OCSF schema v1.8.0)
- Source: raw JumpCloud event field(s) mapped via
${{placeholder}}template - Transform:
fieldMappingsentry applied at runtime (cast, enum, etc.) - Literal: static value set in the mapping template
- Usage: event types in this service that include this field
Core
activity_id
- Description: The normalized identifier of the activity that triggered the event.
- Literal:
1,10,11,2,3,4,8,9 - Usage: all events in this service
activity_name
- Description: The event activity name, as defined by the activity_id.
- Literal:
Activate,Create,Deactivate,Delete,Disable,Enable,Logon,Read,Update - Usage: all events in this service
category_name
- Description: The event category name, as defined by category_uid value:
Discovery. - Literal:
Application Activity,Identity & Access Management - Usage: all events in this service
category_uid
- Description: The category unique identifier of the event.
- Literal:
3,6 - Usage: all events in this service
class_name
- Description: The event class name, as defined by class_uid value:
User Inventory Info. - Literal:
API Activity,Authentication,Entity Management - Usage: all events in this service
class_uid
- Description: The unique identifier of a class. A class describes the attributes available in an event.
- Literal:
3002,3004,6003 - Usage: all events in this service
severity_id
- Description: OCSF severity identifier for the event.
- Literal:
1 - Usage: all events in this service
status_detail
- Description: The status detail contains additional information about the event/finding outcome.
- Source:
error,error_message,message_chain.response_message - Usage: 54 events (missing: activedirectory_create, idp_create)
status_id
- Description: Normalized status of the activity (1=Success, 2=Failure).
- Source:
success - Transform:
success→boolean_to_status_id; true→1, false→2 (54 events (missing: activedirectory_create, idp_create))- Usage: 54 events (missing: activedirectory_create, idp_create)
time
- Description: Event time, in epoch milliseconds (OCSF
time). - Source:
timestamp - Transform:
timestamp→iso8601_to_epoch_millis(all events in this service)- Usage: all events in this service
type_uid
- Description: The event/finding type ID. It identifies the event's semantics and structure. The value is calculated by the logging system as:
class_uid * 100 + activity_id. - Literal:
300201,300401,300403,300404,300408,300409,300410,300411,600302,600303 - Usage: all events in this service
Metadata
metadata.event_code
- Description: JumpCloud event type code.
- Source:
event_type - Usage: all events in this service
metadata.original_time
- Description: The original event time as reported by the event source. For example, the time in the original format from system event log such as Syslog on Unix/Linux and the System event file on Windows. Omit if event is generated instead of collected via logs.
- Source:
server_timestamp - Usage: 26 events: account_resync_failure, account_resync_initiated, activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_deleted, activedirectory_agent_inactive, activedirectory_config_selection_updated, activedirectory_domain_delegated_password_change, ... (+18 more)
metadata.processed_time
- Description: The event processed time, such as an ETL operation.
- Source:
jc_transformation_ts - Usage: 54 events (missing: activedirectory_create, idp_create)
metadata.product.name
- Description: Originating JumpCloud service that produced the event.
- Source:
service - Usage: all events in this service
metadata.tenant_uid
- Description: JumpCloud organization (tenant) identifier.
- Source:
organization - Usage: all events in this service
metadata.uid
- Description: Unique event identifier assigned by JumpCloud.
- Source:
id - Usage: all events in this service
metadata.version
- Description: OCSF schema version used for this event.
- Literal:
1.8.0 - Usage: all events in this service
Actor
actor.user.email_addr
- Description: Email address of the actor who initiated the event.
- Source:
initiated_by.email - Usage: 48 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_agent_deleted, activedirectory_config_selection_updated, activedirectory_create, activedirectory_delete, activedirectory_domain_delegated_password_change, ... (+40 more)
actor.user.type_id
- Description: OCSF user type of the actor (1=User, 2=Admin, 3=System, 4=Service).
- Source:
initiated_by.type - Transform:
initiated_by.type→enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (54 events (missing: activedirectory_primary_agent_switch, connector_execute))- Usage: 55 events (missing: connector_execute)
actor.user.uid
- Description: Unique identifier of the actor who initiated the event.
- Source:
initiated_by.id - Usage: 54 events (missing: activedirectory_primary_agent_switch, connector_execute)
Entity
entity.data.account_object_id
- Description: JumpCloud extension data on the managed entity:
account_object_id. - Source:
resource.account_object_id - Usage: integration_domain_add
entity.data.add.account_object_id
- Description: JumpCloud extension data on the managed entity:
add.account_object_id. - Source:
changes.add.account_object_id - Usage: integration_domain_add
entity.data.add.default
- Description: JumpCloud extension data on the managed entity:
add.default. - Source:
changes.add.default - Usage: integration_domain_add
entity.data.add.domain
- Description: JumpCloud extension data on the managed entity:
add.domain. - Source:
changes.add.domain - Usage: integration_domain_add
entity.data.add.object_id
- Description: JumpCloud extension data on the managed entity:
add.object_id. - Source:
changes.add.object_id - Usage: integration_domain_add
entity.data.add.resource_object_id
- Description: JumpCloud extension data on the managed entity:
add.resource_object_id. - Source:
changes.add.resource_object_id - Usage: integration_domain_add
entity.data.agent_version
- Description: JumpCloud extension data on the managed entity:
agent_version. - Source:
resource.version - Usage: activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_deleted, activedirectory_agent_inactive, activedirectory_domain_delegated_password_change, activedirectory_primary_agent_switch, idsource_create, idsource_delete, idsource_update
entity.data.application_display_name
- Description: JumpCloud extension data on the managed entity:
application_display_name. - Source:
application.displayName - Usage: attributemappings_add, attributemappings_delete, attributemappings_update
entity.data.application_id
- Description: JumpCloud extension data on the managed entity:
application_id. - Source:
application.id - Usage: attributemappings_add, attributemappings_delete, attributemappings_update
entity.data.application_name
- Description: JumpCloud extension data on the managed entity:
application_name. - Source:
application.name - Usage: attributemappings_add, attributemappings_delete, attributemappings_update
entity.data.application_protocol
- Description: JumpCloud extension data on the managed entity:
application_protocol. - Source:
application.name - Usage: idm_integration_activate, idm_integration_deactivate, idm_integration_reauth, idm_integration_update
entity.data.association_action_source
- Description: JumpCloud extension data on the managed entity:
association_action_source. - Source:
association.action_source - Usage: activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_deleted, activedirectory_agent_inactive, activedirectory_config_selection_updated, activedirectory_domain_delegated_password_change, activedirectory_primary_agent_switch
entity.data.association_attributes
- Description: JumpCloud extension data on the managed entity:
association_attributes. - Source:
association.attributes - Usage: activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_deleted, activedirectory_agent_inactive, activedirectory_config_selection_updated, activedirectory_domain_delegated_password_change, activedirectory_primary_agent_switch
entity.data.association_from_name
- Description: JumpCloud extension data on the managed entity:
association_from_name. - Source:
association.connection.from.name - Usage: activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_deleted, activedirectory_agent_inactive, activedirectory_config_selection_updated, activedirectory_domain_delegated_password_change, activedirectory_primary_agent_switch
entity.data.association_from_object_id
- Description: JumpCloud extension data on the managed entity:
association_from_object_id. - Source:
association.connection.from.object_id - Usage: activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_deleted, activedirectory_agent_inactive, activedirectory_config_selection_updated, activedirectory_domain_delegated_password_change, activedirectory_primary_agent_switch
entity.data.association_from_type
- Description: JumpCloud extension data on the managed entity:
association_from_type. - Source:
association.connection.from.type - Usage: activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_deleted, activedirectory_agent_inactive, activedirectory_config_selection_updated, activedirectory_domain_delegated_password_change, activedirectory_primary_agent_switch
entity.data.association_op
- Description: JumpCloud extension data on the managed entity:
association_op. - Source:
association.op - Usage: activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_deleted, activedirectory_agent_inactive, activedirectory_config_selection_updated, activedirectory_domain_delegated_password_change, activedirectory_primary_agent_switch
entity.data.association_to_name
- Description: JumpCloud extension data on the managed entity:
association_to_name. - Source:
association.connection.to.name - Usage: activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_deleted, activedirectory_agent_inactive, activedirectory_config_selection_updated, activedirectory_domain_delegated_password_change, activedirectory_primary_agent_switch
entity.data.association_to_object_id
- Description: JumpCloud extension data on the managed entity:
association_to_object_id. - Source:
association.connection.to.object_id - Usage: activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_deleted, activedirectory_agent_inactive, activedirectory_config_selection_updated, activedirectory_domain_delegated_password_change, activedirectory_primary_agent_switch
entity.data.association_to_type
- Description: JumpCloud extension data on the managed entity:
association_to_type. - Source:
association.connection.to.type - Usage: activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_deleted, activedirectory_agent_inactive, activedirectory_config_selection_updated, activedirectory_domain_delegated_password_change, activedirectory_primary_agent_switch
entity.data.auth_method
- Description: JumpCloud extension data on the managed entity:
auth_method. - Source:
auth_method - Usage: 48 events: activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_create, activedirectory_agent_deleted, activedirectory_agent_inactive, activedirectory_config_selection_updated, activedirectory_create, activedirectory_delete, ... (+40 more)
entity.data.authentication_header_key
- Description: JumpCloud extension data on the managed entity:
authentication_header_key. - Source:
resource.authentication.header_key - Usage: connector_create, connector_delete, connector_update
entity.data.authentication_type
- Description: JumpCloud extension data on the managed entity:
authentication_type. - Source:
resource.authentication.type - Usage: connector_create, connector_delete, connector_update
entity.data.authentication_username
- Description: JumpCloud extension data on the managed entity:
authentication_username. - Source:
resource.authentication.username - Usage: connector_create, connector_delete, connector_update
entity.data.authentication_value_prefix
- Description: JumpCloud extension data on the managed entity:
authentication_value_prefix. - Source:
resource.authentication.value_prefix - Usage: connector_create, connector_delete, connector_update
entity.data.base_url
- Description: JumpCloud extension data on the managed entity:
base_url. - Source:
resource.base_url - Usage: connector_create, connector_delete, connector_update
entity.data.changed_field
- Description: JumpCloud extension data on the managed entity:
changed_field. - Source:
changes.field - Usage: 43 events: activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_create, activedirectory_agent_inactive, activedirectory_config_selection_updated, activedirectory_create, activedirectory_delete, activedirectory_domain_delegated_password_change, ... (+35 more)
entity.data.changes_from
- Description: JumpCloud extension data on the managed entity:
changes_from. - Source:
changes.from - Usage: 24 events: activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_inactive, activedirectory_config_selection_updated, activedirectory_delete, activedirectory_domain_delegated_password_change, activedirectory_primary_agent_switch, attributemappings_add, ... (+16 more)
entity.data.changes_from_destination
- Description: JumpCloud extension data on the managed entity:
changes_from_destination. - Source:
changes.from.destination - Usage: attributemappings_delete, attributemappings_update
entity.data.changes_from_direction
- Description: JumpCloud extension data on the managed entity:
changes_from_direction. - Source:
changes.from.direction - Usage: attributemappings_delete, attributemappings_update
entity.data.changes_from_required
- Description: JumpCloud extension data on the managed entity:
changes_from_required. - Source:
changes.from.required - Usage: attributemappings_delete, attributemappings_update
entity.data.changes_from_source
- Description: JumpCloud extension data on the managed entity:
changes_from_source. - Source:
changes.from.source - Usage: attributemappings_delete, attributemappings_update
entity.data.client_id
- Description: JumpCloud extension data on the managed entity:
client_id. - Source:
client_id - Usage: attributemappings_add, attributemappings_delete, attributemappings_update, idm_integration_activate, idm_integration_deactivate, idm_integration_reauth, idm_integration_update
entity.data.connector_id
- Description: JumpCloud extension data on the managed entity:
connector_id. - Source:
resource.connector_id - Usage: connector_create, connector_delete, connector_update
entity.data.correlation_id
- Description: JumpCloud extension data on the managed entity:
correlation_id. - Source:
correlation.id - Usage: idm_integration_activate, idm_integration_deactivate, idm_integration_reauth, idm_integration_update
entity.data.correlation_type
- Description: JumpCloud extension data on the managed entity:
correlation_type. - Source:
correlation.type - Usage: idm_integration_activate, idm_integration_deactivate, idm_integration_reauth, idm_integration_update
entity.data.custom_headers.X-API-KEY
- Description: JumpCloud extension data on the managed entity:
custom_headers.X-API-KEY. - Source:
resource.custom_headers.X-API-KEY - Usage: connector_create
entity.data.custom_headers.custom
- Description: JumpCloud extension data on the managed entity:
custom_headers.custom. - Source:
resource.custom_headers.custom - Usage: connector_create
entity.data.custom_headers.dsadsad
- Description: JumpCloud extension data on the managed entity:
custom_headers.dsadsad. - Source:
resource.custom_headers.dsadsad - Usage: connector_create
entity.data.custom_headers.header
- Description: JumpCloud extension data on the managed entity:
custom_headers.header. - Source:
resource.custom_headers.header - Usage: connector_create
entity.data.custom_headers.headerkey
- Description: JumpCloud extension data on the managed entity:
custom_headers.headerkey. - Source:
resource.custom_headers.headerkey - Usage: connector_update
entity.data.custom_headers.headers
- Description: JumpCloud extension data on the managed entity:
custom_headers.headers. - Source:
resource.custom_headers.headers - Usage: connector_create, connector_delete
entity.data.custom_headers.new
- Description: JumpCloud extension data on the managed entity:
custom_headers.new. - Source:
resource.custom_headers.new - Usage: connector_create, connector_delete
entity.data.custom_headers.sdadasdads
- Description: JumpCloud extension data on the managed entity:
custom_headers.sdadasdads. - Source:
resource.custom_headers.sdadasdads - Usage: connector_create, connector_delete, connector_update
entity.data.custom_headers.test
- Description: JumpCloud extension data on the managed entity:
custom_headers.test. - Source:
resource.custom_headers.test - Usage: connector_delete
entity.data.custom_headers.x-amzn-custom
- Description: JumpCloud extension data on the managed entity:
custom_headers.x-amzn-custom. - Source:
resource.custom_headers.x-amzn-custom - Usage: connector_create, connector_delete, connector_update
entity.data.custom_headers.x-amzn-key
- Description: JumpCloud extension data on the managed entity:
custom_headers.x-amzn-key. - Source:
resource.custom_headers.x-amzn-key - Usage: connector_delete, connector_update
entity.data.custom_headers.x-amzn-test
- Description: JumpCloud extension data on the managed entity:
custom_headers.x-amzn-test. - Source:
resource.custom_headers.x-amzn-test - Usage: connector_update
entity.data.custom_headers.x-gi-id
- Description: JumpCloud extension data on the managed entity:
custom_headers.x-gi-id. - Source:
resource.custom_headers.x-gi-id - Usage: connector_create, connector_delete, connector_update
entity.data.custom_headers.x-header-2
- Description: JumpCloud extension data on the managed entity:
custom_headers.x-header-2. - Source:
resource.custom_headers.x-header-2 - Usage: connector_delete, connector_update
entity.data.custom_headers.x-jc-id
- Description: JumpCloud extension data on the managed entity:
custom_headers.x-jc-id. - Source:
resource.custom_headers.x-jc-id - Usage: connector_create, connector_delete, connector_update
entity.data.custom_headers.x-team-id
- Description: JumpCloud extension data on the managed entity:
custom_headers.x-team-id. - Source:
resource.custom_headers.x-team-id - Usage: connector_delete
entity.data.custom_headers.x-test
- Description: JumpCloud extension data on the managed entity:
custom_headers.x-test. - Source:
resource.custom_headers.x-test - Usage: connector_create
entity.data.custom_headers.x-test-1
- Description: JumpCloud extension data on the managed entity:
custom_headers.x-test-1. - Source:
resource.custom_headers.x-test-1 - Usage: connector_delete, connector_update
entity.data.custom_headers.yes
- Description: JumpCloud extension data on the managed entity:
custom_headers.yes. - Source:
resource.custom_headers.yes - Usage: connector_delete
entity.data.delegation_state
- Description: JumpCloud extension data on the managed entity:
delegation_state. - Source:
resource.delegation_state - Usage: activedirectory_domain_delegated_password_change
entity.data.delete.account_object_id
- Description: JumpCloud extension data on the managed entity:
delete.account_object_id. - Source:
changes.delete.account_object_id - Usage: integration_domain_delete
entity.data.delete.default
- Description: JumpCloud extension data on the managed entity:
delete.default. - Source:
changes.delete.default - Usage: integration_domain_delete
entity.data.delete.domain
- Description: JumpCloud extension data on the managed entity:
delete.domain. - Source:
changes.delete.domain - Usage: integration_domain_delete
entity.data.delete.object_id
- Description: JumpCloud extension data on the managed entity:
delete.object_id. - Source:
changes.delete.object_id - Usage: integration_domain_delete
entity.data.delete.resource_object_id
- Description: JumpCloud extension data on the managed entity:
delete.resource_object_id. - Source:
changes.delete.resource_object_id - Usage: integration_domain_delete
entity.data.destination
- Description: JumpCloud extension data on the managed entity:
destination. - Source:
changes.destination - Usage: attributemappings_add, attributemappings_delete, attributemappings_update
entity.data.direction
- Description: JumpCloud extension data on the managed entity:
direction. - Source:
changes.direction - Usage: attributemappings_add, attributemappings_delete, attributemappings_update
entity.data.dn
- Description: JumpCloud extension data on the managed entity:
dn. - Source:
resource.dn - Usage: idsource_create, idsource_delete, idsource_update
entity.data.domain
- Description: JumpCloud extension data on the managed entity:
domain. - Source:
resource.domain - Usage: activedirectory_agent_deleted, activedirectory_domain_delegated_password_change, activedirectory_primary_agent_switch
entity.data.idm_client_id
- Description: JumpCloud extension data on the managed entity:
idm_client_id. - Source:
resource.idm_client_id - Usage: idm_integration_activate, idm_integration_deactivate, idm_integration_reauth, idm_integration_update
entity.data.ids
- Description: JumpCloud extension data on the managed entity:
ids. - Source:
resource.ids - Usage: attributemappings_add, attributemappings_delete, attributemappings_update
entity.data.initiated_by_provider
- Description: JumpCloud extension data on the managed entity:
initiated_by_provider. - Source:
initiated_by.provider - Usage: 26 events: duo_configuration_update, duoaccount_create, duoapplication_create, duoapplication_delete, gsuite_directory_create, gsuite_directory_delete, gsuite_directory_reactivate, gsuite_directory_update, ... (+18 more)
entity.data.initiated_by_source
- Description: JumpCloud extension data on the managed entity:
initiated_by_source. - Source:
initiated_by.source - Usage: idp_create, idp_delete, idp_routing_policy_create, idp_routing_policy_delete, idp_routing_policy_update, idp_update
entity.data.initiated_by_source_name
- Description: JumpCloud extension data on the managed entity:
initiated_by_source_name. - Source:
initiated_by.source_metadata.sourceName - Usage: attributemappings_add, attributemappings_delete, attributemappings_update
entity.data.initiated_by_user_id
- Description: JumpCloud extension data on the managed entity:
initiated_by_user_id. - Source:
initiated_by.user_id - Usage: idm_integration_activate, idm_integration_reauth, idm_integration_update
entity.data.message_chain_message_details
- Description: JumpCloud extension data on the managed entity:
message_chain_message_details. - Source:
message_chain.message_details - Usage: idm_integration_activate, idm_integration_deactivate, idm_integration_reauth, idm_integration_update
entity.data.message_chain_response_code
- Description: JumpCloud extension data on the managed entity:
message_chain_response_code. - Source:
message_chain.response_code - Usage: idm_integration_activate, idm_integration_deactivate, idm_integration_reauth, idm_integration_update
entity.data.names
- Description: JumpCloud extension data on the managed entity:
names. - Source:
resource.names - Usage: attributemappings_add, attributemappings_delete, attributemappings_update
entity.data.object_id
- Description: JumpCloud extension data on the managed entity:
object_id. - Source:
resource.object_id - Usage: connector_create, connector_delete, connector_update
entity.data.primary_agent
- Description: JumpCloud extension data on the managed entity:
primary_agent. - Source:
resource.primary_agent - Usage: activedirectory_agent_active
entity.data.provider
- Description: JumpCloud extension data on the managed entity:
provider. - Source:
provider - Usage: 37 events: attributemappings_add, attributemappings_delete, attributemappings_update, duo_configuration_update, duoaccount_create, duoapplication_create, duoapplication_delete, gsuite_directory_create, ... (+29 more)
entity.data.required
- Description: JumpCloud extension data on the managed entity:
required. - Source:
changes.required - Usage: attributemappings_add
entity.data.source
- Description: JumpCloud extension data on the managed entity:
source. - Source:
changes.source - Usage: attributemappings_add, attributemappings_delete, attributemappings_update
entity.data.status
- Description: JumpCloud extension data on the managed entity:
status. - Source:
resource.status - Usage: activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_inactive, activedirectory_primary_agent_switch, connector_create, connector_delete, connector_update
entity.device.hostname
- Description: The device hostname.
- Source:
resource.hostname - Usage: activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_deleted, activedirectory_agent_inactive, activedirectory_domain_delegated_password_change, activedirectory_primary_agent_switch
entity.device.ip
- Description: The device IP address, in either IPv4 or IPv6 format.
- Source:
resource.ipAddress,resource.source_ip - Usage: activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_deleted, activedirectory_agent_inactive, activedirectory_domain_delegated_password_change, activedirectory_primary_agent_switch, idsource_create, idsource_delete, idsource_update
entity.device.os.name
- Description: The operating system name.
- Source:
resource.hostOSVersion,resource.host_os_version - Usage: activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_deleted, activedirectory_agent_inactive, activedirectory_domain_delegated_password_change, activedirectory_primary_agent_switch, idsource_delete, idsource_update
entity.device.type
- Description: The device type. For example:
unknown,server,desktop,laptop,tablet,mobile,virtual,browser, orother. - Source:
resource.hostType,resource.host_type - Usage: activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_deleted, activedirectory_agent_inactive, activedirectory_domain_delegated_password_change, activedirectory_primary_agent_switch, idsource_delete, idsource_update
entity.name
- Description: The name of the managed entity. It should match the name of the specific entity object's name if populated, or the name of the managed entity if the
type_idis 'Other'. - Source:
application.displayName,resource.domain,resource.name - Usage: 34 events: activedirectory_config_selection_updated, activedirectory_create, activedirectory_delete, attributemappings_add, attributemappings_delete, attributemappings_update, connector_create, connector_delete, ... (+26 more)
entity.type
- Description: The managed entity type. For example:
Policy,User,Organization,Device. - Source:
resource.type - Usage: 52 events (missing: account_resync_failure, account_resync_initiated, connector_execute, idm_integration_auth)
entity.uid
- Description: The identifier of the managed entity. It should match the
uidof the specific entity's object UID if populated, or the source specific ID if thetype_idis 'Other'. - Source:
application.id,resource.id - Usage: 43 events: activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_create, activedirectory_agent_deleted, activedirectory_agent_inactive, activedirectory_config_selection_updated, activedirectory_create, activedirectory_delete, ... (+35 more)
entity_result.data.changes_to
- Description: JumpCloud extension data on the managed entity:
changes_to. - Source:
changes.to - Usage: 34 events: activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_create, activedirectory_agent_inactive, activedirectory_config_selection_updated, activedirectory_create, activedirectory_domain_delegated_password_change, activedirectory_primary_agent_switch, ... (+26 more)
entity_result.data.changes_to_account_object_id
- Description: JumpCloud extension data on the managed entity:
changes_to_account_object_id. - Source:
changes.to.account_object_id - Usage: integration_domain_add, integration_domain_delete
entity_result.data.changes_to_api_users_get_additionalHeaders
- Description: JumpCloud extension data on the managed entity:
changes_to_api_users_get_additionalHeaders. - Source:
changes.to.api.users.get.additionalHeaders - Usage: idm_integration_activate
entity_result.data.changes_to_api_users_get_additionalHeaders_key
- Description: JumpCloud extension data on the managed entity:
changes_to_api_users_get_additionalHeaders_key. - Source:
changes.to.api.users.get.additionalHeaders.key - Usage: idm_integration_update
entity_result.data.changes_to_api_users_get_additionalHeaders_sensitive
- Description: JumpCloud extension data on the managed entity:
changes_to_api_users_get_additionalHeaders_sensitive. - Source:
changes.to.api.users.get.additionalHeaders.sensitive - Usage: idm_integration_update
entity_result.data.changes_to_api_users_get_additionalHeaders_value
- Description: JumpCloud extension data on the managed entity:
changes_to_api_users_get_additionalHeaders_value. - Source:
changes.to.api.users.get.additionalHeaders.value - Usage: idm_integration_update
entity_result.data.changes_to_api_users_get_method
- Description: JumpCloud extension data on the managed entity:
changes_to_api_users_get_method. - Source:
changes.to.api.users.get.method - Usage: idm_integration_activate, idm_integration_update
entity_result.data.changes_to_api_users_get_path
- Description: JumpCloud extension data on the managed entity:
changes_to_api_users_get_path. - Source:
changes.to.api.users.get.path - Usage: idm_integration_activate, idm_integration_update
entity_result.data.changes_to_api_users_list_countField
- Description: JumpCloud extension data on the managed entity:
changes_to_api_users_list_countField. - Source:
changes.to.api.users.list.countField - Usage: idm_integration_activate, idm_integration_update
entity_result.data.changes_to_api_users_list_cursorBased_count
- Description: JumpCloud extension data on the managed entity:
changes_to_api_users_list_cursorBased_count. - Source:
changes.to.api.users.list.cursorBased.count - Usage: idm_integration_activate, idm_integration_update
entity_result.data.changes_to_api_users_list_cursorBased_cursor
- Description: JumpCloud extension data on the managed entity:
changes_to_api_users_list_cursorBased_cursor. - Source:
changes.to.api.users.list.cursorBased.cursor - Usage: idm_integration_activate, idm_integration_update
entity_result.data.changes_to_api_users_list_cursorBased_cursorField
- Description: JumpCloud extension data on the managed entity:
changes_to_api_users_list_cursorBased_cursorField. - Source:
changes.to.api.users.list.cursorBased.cursorField - Usage: idm_integration_activate, idm_integration_update
entity_result.data.changes_to_api_users_list_cursorBased_isLink
- Description: JumpCloud extension data on the managed entity:
changes_to_api_users_list_cursorBased_isLink. - Source:
changes.to.api.users.list.cursorBased.isLink - Usage: idm_integration_activate, idm_integration_update
entity_result.data.changes_to_api_users_list_endpoint_additionalHeaders
- Description: JumpCloud extension data on the managed entity:
changes_to_api_users_list_endpoint_additionalHeaders. - Source:
changes.to.api.users.list.endpoint.additionalHeaders - Usage: idm_integration_activate
entity_result.data.changes_to_api_users_list_endpoint_additionalHeaders_key
- Description: JumpCloud extension data on the managed entity:
changes_to_api_users_list_endpoint_additionalHeaders_key. - Source:
changes.to.api.users.list.endpoint.additionalHeaders.key - Usage: idm_integration_update
entity_result.data.changes_to_api_users_list_endpoint_additionalHeaders_sensitive
- Description: JumpCloud extension data on the managed entity:
changes_to_api_users_list_endpoint_additionalHeaders_sensitive. - Source:
changes.to.api.users.list.endpoint.additionalHeaders.sensitive - Usage: idm_integration_update
entity_result.data.changes_to_api_users_list_endpoint_additionalHeaders_value
- Description: JumpCloud extension data on the managed entity:
changes_to_api_users_list_endpoint_additionalHeaders_value. - Source:
changes.to.api.users.list.endpoint.additionalHeaders.value - Usage: idm_integration_update
entity_result.data.changes_to_api_users_list_endpoint_method
- Description: JumpCloud extension data on the managed entity:
changes_to_api_users_list_endpoint_method. - Source:
changes.to.api.users.list.endpoint.method - Usage: idm_integration_activate, idm_integration_update
entity_result.data.changes_to_api_users_list_endpoint_path
- Description: JumpCloud extension data on the managed entity:
changes_to_api_users_list_endpoint_path. - Source:
changes.to.api.users.list.endpoint.path - Usage: idm_integration_activate, idm_integration_update
entity_result.data.changes_to_api_users_list_limit
- Description: JumpCloud extension data on the managed entity:
changes_to_api_users_list_limit. - Source:
changes.to.api.users.list.limit - Usage: idm_integration_activate, idm_integration_update
entity_result.data.changes_to_api_users_list_noPagination
- Description: JumpCloud extension data on the managed entity:
changes_to_api_users_list_noPagination. - Source:
changes.to.api.users.list.noPagination - Usage: idm_integration_activate, idm_integration_update
entity_result.data.changes_to_api_users_list_offset_count
- Description: JumpCloud extension data on the managed entity:
changes_to_api_users_list_offset_count. - Source:
changes.to.api.users.list.offset.count - Usage: idm_integration_activate, idm_integration_update
entity_result.data.changes_to_api_users_list_offset_skip
- Description: JumpCloud extension data on the managed entity:
changes_to_api_users_list_offset_skip. - Source:
changes.to.api.users.list.offset.skip - Usage: idm_integration_activate, idm_integration_update
entity_result.data.changes_to_api_users_list_offset_startIndex
- Description: JumpCloud extension data on the managed entity:
changes_to_api_users_list_offset_startIndex. - Source:
changes.to.api.users.list.offset.startIndex - Usage: idm_integration_activate, idm_integration_update
entity_result.data.changes_to_api_users_list_pageBased_count
- Description: JumpCloud extension data on the managed entity:
changes_to_api_users_list_pageBased_count. - Source:
changes.to.api.users.list.pageBased.count - Usage: idm_integration_activate, idm_integration_update
entity_result.data.changes_to_api_users_list_pageBased_index
- Description: JumpCloud extension data on the managed entity:
changes_to_api_users_list_pageBased_index. - Source:
changes.to.api.users.list.pageBased.index - Usage: idm_integration_activate, idm_integration_update
entity_result.data.changes_to_api_users_list_resources
- Description: JumpCloud extension data on the managed entity:
changes_to_api_users_list_resources. - Source:
changes.to.api.users.list.resources - Usage: idm_integration_activate, idm_integration_update
entity_result.data.changes_to_appliedOn
- Description: JumpCloud extension data on the managed entity:
changes_to_appliedOn. - Source:
changes.to.appliedOn - Usage: idm_integration_activate
entity_result.data.changes_to_builtIn
- Description: JumpCloud extension data on the managed entity:
changes_to_builtIn. - Source:
changes.to.builtIn - Usage: idm_integration_activate
entity_result.data.changes_to_data
- Description: JumpCloud extension data on the managed entity:
changes_to_data. - Source:
changes.to.data - Usage: idm_integration_activate
entity_result.data.changes_to_default
- Description: JumpCloud extension data on the managed entity:
changes_to_default. - Source:
changes.to.default - Usage: idm_integration_activate, integration_domain_add, integration_domain_delete
entity_result.data.changes_to_deleteUser
- Description: JumpCloud extension data on the managed entity:
changes_to_deleteUser. - Source:
changes.to.deleteUser - Usage: idm_integration_activate
entity_result.data.changes_to_destination
- Description: JumpCloud extension data on the managed entity:
changes_to_destination. - Source:
changes.to.destination - Usage: attributemappings_add, attributemappings_update, idm_integration_activate
entity_result.data.changes_to_direction
- Description: JumpCloud extension data on the managed entity:
changes_to_direction. - Source:
changes.to.direction - Usage: attributemappings_add, attributemappings_update, idm_integration_activate
entity_result.data.changes_to_domain
- Description: JumpCloud extension data on the managed entity:
changes_to_domain. - Source:
changes.to.domain - Usage: integration_domain_add, integration_domain_delete
entity_result.data.changes_to_editable
- Description: JumpCloud extension data on the managed entity:
changes_to_editable. - Source:
changes.to.editable - Usage: idm_integration_activate
entity_result.data.changes_to_id
- Description: JumpCloud extension data on the managed entity:
changes_to_id. - Source:
changes.to.id - Usage: idm_integration_activate
entity_result.data.changes_to_object_id
- Description: JumpCloud extension data on the managed entity:
changes_to_object_id. - Source:
changes.to.object_id - Usage: integration_domain_add, integration_domain_delete
entity_result.data.changes_to_required
- Description: JumpCloud extension data on the managed entity:
changes_to_required. - Source:
changes.to.required - Usage: attributemappings_add, attributemappings_update, idm_integration_activate
entity_result.data.changes_to_resource_object_id
- Description: JumpCloud extension data on the managed entity:
changes_to_resource_object_id. - Source:
changes.to.resource_object_id - Usage: integration_domain_add
entity_result.data.changes_to_source
- Description: JumpCloud extension data on the managed entity:
changes_to_source. - Source:
changes.to.source - Usage: attributemappings_add, attributemappings_update, idm_integration_activate
entity_result.data.changes_to_sourceType
- Description: JumpCloud extension data on the managed entity:
changes_to_sourceType. - Source:
changes.to.sourceType - Usage: idm_integration_activate
entity_result.data.changes_to_target
- Description: JumpCloud extension data on the managed entity:
changes_to_target. - Source:
changes.to.target - Usage: idm_integration_activate
entity_result.data.changes_to_template
- Description: JumpCloud extension data on the managed entity:
changes_to_template. - Source:
changes.to.template - Usage: idm_integration_activate
entity_result.data.changes_to_type
- Description: JumpCloud extension data on the managed entity:
changes_to_type. - Source:
changes.to.type - Usage: idm_integration_activate
entity_result.data.changes_to_userSchema_inactiveStatus_path
- Description: JumpCloud extension data on the managed entity:
changes_to_userSchema_inactiveStatus_path. - Source:
changes.to.userSchema.inactiveStatus.path - Usage: idm_integration_activate, idm_integration_update
entity_result.data.changes_to_userSchema_inactiveStatus_values
- Description: JumpCloud extension data on the managed entity:
changes_to_userSchema_inactiveStatus_values. - Source:
changes.to.userSchema.inactiveStatus.values - Usage: idm_integration_activate, idm_integration_update
entity_result.data.changes_to_userSchema_mappings_direction
- Description: JumpCloud extension data on the managed entity:
changes_to_userSchema_mappings_direction. - Source:
changes.to.userSchema.mappings.direction - Usage: idm_integration_activate, idm_integration_update
entity_result.data.changes_to_userSchema_mappings_external_type
- Description: JumpCloud extension data on the managed entity:
changes_to_userSchema_mappings_external_type. - Source:
changes.to.userSchema.mappings.external.type - Usage: idm_integration_activate, idm_integration_update
entity_result.data.changes_to_userSchema_mappings_external_value
- Description: JumpCloud extension data on the managed entity:
changes_to_userSchema_mappings_external_value. - Source:
changes.to.userSchema.mappings.external.value - Usage: idm_integration_activate, idm_integration_update
entity_result.data.changes_to_userSchema_mappings_internal_type
- Description: JumpCloud extension data on the managed entity:
changes_to_userSchema_mappings_internal_type. - Source:
changes.to.userSchema.mappings.internal.type - Usage: idm_integration_activate, idm_integration_update
entity_result.data.changes_to_userSchema_mappings_internal_value
- Description: JumpCloud extension data on the managed entity:
changes_to_userSchema_mappings_internal_value. - Source:
changes.to.userSchema.mappings.internal.value - Usage: idm_integration_activate, idm_integration_update
entity_result.data.changes_to_userSchema_uniqueIdentifier
- Description: JumpCloud extension data on the managed entity:
changes_to_userSchema_uniqueIdentifier. - Source:
changes.to.userSchema.uniqueIdentifier - Usage: idm_integration_activate, idm_integration_update
Src Endpoint
src_endpoint.autonomous_system.name
- Description: Organization name for the Autonomous System.
- Source:
asn.organization - Usage: 35 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_delete, attributemappings_delete, attributemappings_update, connector_create, connector_delete, ... (+27 more)
src_endpoint.autonomous_system.number
- Description: Unique number that the AS is identified by.
- Source:
asn.number - Transform:
asn.number→int(35 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_delete, attributemappings_delete, attributemappings_update, connector_create, connector_delete, ... (+27 more))- Usage: 35 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_delete, attributemappings_delete, attributemappings_update, connector_create, connector_delete, ... (+27 more)
src_endpoint.ip
- Description: Source IP address the request originated from.
- Source:
client_ip - Usage: all events in this service
src_endpoint.location.city
- Description: The name of the city.
- Source:
geoip.city - Usage: 42 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_config_selection_updated, activedirectory_delete, attributemappings_add, attributemappings_delete, attributemappings_update, ... (+34 more)
src_endpoint.location.continent
- Description: The name of the continent.
- Source:
geoip.continent_code - Usage: 44 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_config_selection_updated, activedirectory_create, activedirectory_delete, attributemappings_add, attributemappings_delete, ... (+36 more)
src_endpoint.location.country
- Description: The ISO 3166-1 Alpha-2 country code.
Note: The two letter country code should be capitalized. For example:
USorCA. - Source:
geoip.country_code - Usage: 44 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_config_selection_updated, activedirectory_create, activedirectory_delete, attributemappings_add, attributemappings_delete, ... (+36 more)
src_endpoint.location.lat
- Description: The geographical Latitude coordinate represented in Decimal Degrees (DD). For example:
42.361145. - Source:
geoip.latitude - Transform:
geoip.latitude→double(44 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_config_selection_updated, activedirectory_create, activedirectory_delete, attributemappings_add, attributemappings_delete, ... (+36 more))- Usage: 44 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_config_selection_updated, activedirectory_create, activedirectory_delete, attributemappings_add, attributemappings_delete, ... (+36 more)
src_endpoint.location.long
- Description: The geographical Longitude coordinate represented in Decimal Degrees (DD). For example:
-71.057083. - Source:
geoip.longitude - Transform:
geoip.longitude→double(44 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_config_selection_updated, activedirectory_create, activedirectory_delete, attributemappings_add, attributemappings_delete, ... (+36 more))- Usage: 44 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_config_selection_updated, activedirectory_create, activedirectory_delete, attributemappings_add, attributemappings_delete, ... (+36 more)
src_endpoint.location.region
- Description: The alphanumeric code that identifies the principal subdivision (e.g. province or state) of the country. For example, 'CH-VD' for the Canton of Vaud, Switzerland
- Source:
geoip.region_code - Usage: 44 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_config_selection_updated, activedirectory_create, activedirectory_delete, attributemappings_add, attributemappings_delete, ... (+36 more)
Http Request
http_request.user_agent
- Description: The request header that identifies the operating system and web browser.
- Source:
user_agent - Usage: 50 events: account_resync_failure, account_resync_initiated, activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_create, activedirectory_agent_deleted, activedirectory_agent_inactive, activedirectory_delete, ... (+42 more)
Observables
observables[].name
- Description: The full name of the observable attribute. The
nameis a pointer/reference to an attribute within the OCSF event data. For example:file.name. Array attributes may be represented in one of three ways. For example:resources.uid,resources[].uid,resources[0].uid. - Literal:
actor.user.email_addr,actor.user.uid,entity.device.hostname,entity.device.ip,http_request.user_agent,src_endpoint.ip,src_endpoint.location.country - Usage: all events in this service
observables[].type_id
- Description: The observable value type identifier.
- Literal:
1,14,16,2,31,5 - Usage: all events in this service
observables[].value
- Description: The value associated with the observable attribute. The meaning of the value depends on the observable type.
If thenamerefers to a scalar attribute, then thevalueis the value of the attribute.
If thenamerefers to an object attribute, then thevalueis not populated. - Source:
client_ip,geoip.country_code,initiated_by.email,initiated_by.id,resource.hostname,resource.ipAddress,resource.source_ip,user_agent - Usage: all events in this service
Resources
resources.type
- Description: The resource type as defined by the event source.
- Source:
resource.type - Usage: account_resync_failure, account_resync_initiated
Other
api.request.uid
- Description: The unique request identifier.
- Source:
correlation.id - Usage: account_resync_failure, account_resync_initiated
http_response.code
- Description: The Hypertext Transfer Protocol (HTTP) status code returned from the web server to the client. For example, 200.
- Source:
status_code - Usage: connector_execute
service.name
- Description: The name of the service.
- Source:
application.displayName - Usage: idm_integration_auth
service.uid
- Description: The unique identifier of the service.
- Source:
application.id - Usage: idm_integration_auth
Unmapped
unmapped.@timestamp
- Description: JumpCloud Directory Insights field
@timestamppreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
@timestamp - Usage: 12 events: activedirectory_config_selection_updated, activedirectory_create, activedirectory_delete, activedirectory_domain_delegated_password_change, attributemappings_add, attributemappings_delete, attributemappings_update, idp_create, ... (+4 more)
unmapped.@version
- Description: JumpCloud Directory Insights field
@versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
@version - Usage: all events in this service
unmapped._datadog.ot-baggage-jc-request-start
- Description: JumpCloud Directory Insights field
_datadog.ot-baggage-jc-request-startpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
_datadog.ot-baggage-jc-request-start - Usage: idm_integration_reauth
unmapped._datadog.traceparent
- Description: JumpCloud Directory Insights field
_datadog.traceparentpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
_datadog.traceparent - Usage: idm_integration_reauth
unmapped._datadog.tracestate
- Description: JumpCloud Directory Insights field
_datadog.tracestatepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
_datadog.tracestate - Usage: idm_integration_reauth
unmapped._datadog.x-datadog-parent-id
- Description: JumpCloud Directory Insights field
_datadog.x-datadog-parent-idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
_datadog.x-datadog-parent-id - Usage: idm_integration_reauth
unmapped._datadog.x-datadog-sampling-priority
- Description: JumpCloud Directory Insights field
_datadog.x-datadog-sampling-prioritypreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
_datadog.x-datadog-sampling-priority - Usage: idm_integration_reauth
unmapped._datadog.x-datadog-tags
- Description: JumpCloud Directory Insights field
_datadog.x-datadog-tagspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
_datadog.x-datadog-tags - Usage: idm_integration_reauth
unmapped._datadog.x-datadog-trace-id
- Description: JumpCloud Directory Insights field
_datadog.x-datadog-trace-idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
_datadog.x-datadog-trace-id - Usage: idm_integration_reauth
unmapped.application.name
- Description: JumpCloud Directory Insights field
application.namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
application.name - Usage: idm_integration_auth
unmapped.application_id_hash
- Description: JumpCloud Directory Insights field
application_id_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
application_id_hash - Usage: attributemappings_delete, idm_integration_auth, idm_integration_deactivate, idm_integration_reauth, idm_integration_update
unmapped.application_name
- Description: JumpCloud Directory Insights field
application_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
application.name - Usage: account_resync_failure, account_resync_initiated
unmapped.asn.error
- Description: JumpCloud Directory Insights field
asn.errorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
asn.error - Usage: duo_configuration_update, duoapplication_create, idm_integration_update
unmapped.asn.ip_address
- Description: JumpCloud Directory Insights field
asn.ip_addresspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
asn.ip_address - Usage: duo_configuration_update, duoapplication_create, idm_integration_update
unmapped.asn.network
- Description: JumpCloud Directory Insights field
asn.networkpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
asn.network - Usage: 35 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_delete, attributemappings_delete, attributemappings_update, connector_create, connector_delete, ... (+27 more)
unmapped.auth_method
- Description: JumpCloud Directory Insights field
auth_methodpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
auth_method - Usage: account_resync_failure, account_resync_initiated, idm_integration_auth
unmapped.caller_service
- Description: JumpCloud Directory Insights field
caller_servicepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
caller_service - Usage: connector_execute
unmapped.changes
- Description: JumpCloud Directory Insights field
changespreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes - Usage: idm_integration_auth, idm_integration_deactivate
unmapped.client_id
- Description: JumpCloud Directory Insights field
client_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
client_id - Usage: account_resync_failure, account_resync_initiated, idm_integration_auth
unmapped.correlation
- Description: JumpCloud Directory Insights field
correlationpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
correlation - Usage: activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_deleted, activedirectory_agent_inactive, activedirectory_config_selection_updated, activedirectory_domain_delegated_password_change, activedirectory_primary_agent_switch, attributemappings_add, attributemappings_delete, attributemappings_update
unmapped.correlation.id
- Description: JumpCloud Directory Insights field
correlation.idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
correlation.id - Usage: idm_integration_auth
unmapped.correlation.type
- Description: JumpCloud Directory Insights field
correlation.typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
correlation.type - Usage: idm_integration_auth
unmapped.correlation_type
- Description: JumpCloud Directory Insights field
correlation_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
correlation.type - Usage: account_resync_failure, account_resync_initiated
unmapped.error_message
- Description: JumpCloud Directory Insights field
error_messagepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
error_message - Usage: connector_execute
unmapped.file_input_timestamp
- Description: JumpCloud Directory Insights field
file_input_timestamppreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
file_input_timestamp - Usage: 12 events: activedirectory_config_selection_updated, activedirectory_create, activedirectory_delete, activedirectory_domain_delegated_password_change, attributemappings_add, attributemappings_delete, attributemappings_update, idp_create, ... (+4 more)
unmapped.geoip.region_name
- Description: JumpCloud Directory Insights field
geoip.region_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.region_name - Usage: 44 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_config_selection_updated, activedirectory_create, activedirectory_delete, attributemappings_add, attributemappings_delete, ... (+36 more)
unmapped.geoip.timezone
- Description: JumpCloud Directory Insights field
geoip.timezonepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.timezone - Usage: 44 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_config_selection_updated, activedirectory_create, activedirectory_delete, attributemappings_add, attributemappings_delete, ... (+36 more)
unmapped.initiated_by.source_metadata.sourceName
- Description: JumpCloud Directory Insights field
initiated_by.source_metadata.sourceNamepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by.source_metadata.sourceName - Usage: account_resync_failure, account_resync_initiated
unmapped.initiated_by.type
- Description: JumpCloud Directory Insights field
initiated_by.typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by.type - Usage: connector_execute
unmapped.initiated_by_email_hash
- Description: JumpCloud Directory Insights field
initiated_by_email_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_email_hash - Usage: 46 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_agent_deleted, activedirectory_config_selection_updated, activedirectory_delete, activedirectory_domain_delegated_password_change, attributemappings_add, ... (+38 more)
unmapped.initiated_by_id_hash
- Description: JumpCloud Directory Insights field
initiated_by_id_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_id_hash - Usage: 52 events (missing: activedirectory_create, activedirectory_primary_agent_switch, connector_execute, idp_create)
unmapped.initiated_by_provider
- Description: JumpCloud Directory Insights field
initiated_by_providerpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by.provider - Usage: activedirectory_agent_create, activedirectory_delete
unmapped.is_out_of_bound
- Description: JumpCloud Directory Insights field
is_out_of_boundpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
is_out_of_bound - Usage: 50 events: account_resync_failure, account_resync_initiated, activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_create, activedirectory_agent_deleted, activedirectory_agent_inactive, activedirectory_delete, ... (+42 more)
unmapped.jc_application_name
- Description: JumpCloud Directory Insights field
jc_application_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_application_name - Usage: 50 events: account_resync_failure, account_resync_initiated, activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_create, activedirectory_agent_deleted, activedirectory_agent_inactive, activedirectory_delete, ... (+42 more)
unmapped.jc_initiated_by_email
- Description: JumpCloud Directory Insights field
jc_initiated_by_emailpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_initiated_by_email - Usage: 23 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_agent_deleted, activedirectory_delete, attributemappings_delete, connector_create, connector_delete, ... (+15 more)
unmapped.jc_initiated_by_id
- Description: JumpCloud Directory Insights field
jc_initiated_by_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_initiated_by_id - Usage: attributemappings_delete, connector_create, connector_delete, connector_update
unmapped.jc_initiated_by_username
- Description: JumpCloud Directory Insights field
jc_initiated_by_usernamepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_initiated_by_username - Usage: 23 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_agent_deleted, activedirectory_delete, attributemappings_delete, connector_create, connector_delete, ... (+15 more)
unmapped.jc_organization_name
- Description: JumpCloud Directory Insights field
jc_organization_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_organization_name - Usage: 23 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_agent_deleted, activedirectory_delete, attributemappings_delete, connector_create, connector_delete, ... (+15 more)
unmapped.jc_provider_id
- Description: JumpCloud Directory Insights field
jc_provider_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_provider_id - Usage: 17 events: account_resync_initiated, activedirectory_agent_create, activedirectory_agent_deleted, activedirectory_delete, attributemappings_delete, gsuite_directory_create, gsuite_directory_delete, idm_integration_deactivate, ... (+9 more)
unmapped.jc_system_display_name
- Description: JumpCloud Directory Insights field
jc_system_display_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_system_display_name - Usage: attributemappings_delete, connector_create, connector_delete, connector_update
unmapped.jc_system_hostname
- Description: JumpCloud Directory Insights field
jc_system_hostnamepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_system_hostname - Usage: attributemappings_delete, connector_create, connector_delete, connector_update
unmapped.message_chain.message_details
- Description: JumpCloud Directory Insights field
message_chain.message_detailspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
message_chain.message_details - Usage: attributemappings_add, attributemappings_delete, attributemappings_update, idm_integration_auth, integration_default_domain_add, integration_default_domain_delete, integration_default_domain_update, integration_domain_add, integration_domain_delete
unmapped.message_chain.response_code
- Description: JumpCloud Directory Insights field
message_chain.response_codepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
message_chain.response_code - Usage: attributemappings_add, attributemappings_delete, attributemappings_update, idm_integration_auth, integration_default_domain_add, integration_default_domain_delete, integration_default_domain_update, integration_domain_add, integration_domain_delete
unmapped.message_chain.response_message
- Description: JumpCloud Directory Insights field
message_chain.response_messagepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
message_chain.response_message - Usage: attributemappings_add, attributemappings_delete, attributemappings_update, integration_default_domain_add, integration_default_domain_delete, integration_default_domain_update, integration_domain_add, integration_domain_delete
unmapped.message_chain_message_details
- Description: JumpCloud Directory Insights field
message_chain_message_detailspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
message_chain.message_details - Usage: account_resync_failure, account_resync_initiated, activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_deleted, activedirectory_agent_inactive, activedirectory_config_selection_updated, activedirectory_domain_delegated_password_change, activedirectory_primary_agent_switch
unmapped.message_chain_response_code
- Description: JumpCloud Directory Insights field
message_chain_response_codepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
message_chain.response_code - Usage: account_resync_failure, account_resync_initiated, activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_deleted, activedirectory_agent_inactive, activedirectory_config_selection_updated, activedirectory_domain_delegated_password_change, activedirectory_primary_agent_switch
unmapped.message_chain_response_message
- Description: JumpCloud Directory Insights field
message_chain_response_messagepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
message_chain.response_message - Usage: account_resync_failure, account_resync_initiated, activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_deleted, activedirectory_agent_inactive, activedirectory_config_selection_updated, activedirectory_domain_delegated_password_change, activedirectory_primary_agent_switch
unmapped.msp_provider_id
- Description: JumpCloud Directory Insights field
msp_provider_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
provider - Usage: activedirectory_agent_create, activedirectory_agent_deleted, activedirectory_create, activedirectory_delete
unmapped.provider
- Description: JumpCloud Directory Insights field
providerpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
provider - Usage: idm_integration_auth
unmapped.resource.authentication.header_key
- Description: JumpCloud Directory Insights field
resource.authentication.header_keypreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.authentication.header_key - Usage: connector_execute
unmapped.resource.authentication.type
- Description: JumpCloud Directory Insights field
resource.authentication.typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.authentication.type - Usage: connector_execute
unmapped.resource.authentication.username
- Description: JumpCloud Directory Insights field
resource.authentication.usernamepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.authentication.username - Usage: connector_execute
unmapped.resource.authentication.value_prefix
- Description: JumpCloud Directory Insights field
resource.authentication.value_prefixpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.authentication.value_prefix - Usage: connector_execute
unmapped.resource.base_url
- Description: JumpCloud Directory Insights field
resource.base_urlpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.base_url - Usage: connector_execute
unmapped.resource.connector_id
- Description: JumpCloud Directory Insights field
resource.connector_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.connector_id - Usage: connector_execute
unmapped.resource.custom_headers.Header
- Description: JumpCloud Directory Insights field
resource.custom_headers.Headerpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.custom_headers.Header - Usage: connector_execute
unmapped.resource.custom_headers.Headers
- Description: JumpCloud Directory Insights field
resource.custom_headers.Headerspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.custom_headers.Headers - Usage: connector_execute
unmapped.resource.custom_headers.New
- Description: JumpCloud Directory Insights field
resource.custom_headers.Newpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.custom_headers.New - Usage: connector_execute
unmapped.resource.custom_headers.X-API-KEY
- Description: JumpCloud Directory Insights field
resource.custom_headers.X-API-KEYpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.custom_headers.X-API-KEY - Usage: connector_execute
unmapped.resource.custom_headers.X-Api-Key
- Description: JumpCloud Directory Insights field
resource.custom_headers.X-Api-Keypreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.custom_headers.X-Api-Key - Usage: connector_execute
unmapped.resource.custom_headers.X-Jc-Id
- Description: JumpCloud Directory Insights field
resource.custom_headers.X-Jc-Idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.custom_headers.X-Jc-Id - Usage: connector_execute
unmapped.resource.custom_headers.header
- Description: JumpCloud Directory Insights field
resource.custom_headers.headerpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.custom_headers.header - Usage: connector_execute
unmapped.resource.custom_headers.headers
- Description: JumpCloud Directory Insights field
resource.custom_headers.headerspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.custom_headers.headers - Usage: connector_execute
unmapped.resource.custom_headers.new
- Description: JumpCloud Directory Insights field
resource.custom_headers.newpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.custom_headers.new - Usage: connector_execute
unmapped.resource.id
- Description: JumpCloud Directory Insights field
resource.idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.id - Usage: connector_execute
unmapped.resource.idm_client_id
- Description: JumpCloud Directory Insights field
resource.idm_client_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.idm_client_id - Usage: idm_integration_auth
unmapped.resource.name
- Description: JumpCloud Directory Insights field
resource.namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.name - Usage: connector_execute
unmapped.resource.object_id
- Description: JumpCloud Directory Insights field
resource.object_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.object_id - Usage: connector_execute
unmapped.resource.status
- Description: JumpCloud Directory Insights field
resource.statuspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.status - Usage: connector_execute
unmapped.resource.type
- Description: JumpCloud Directory Insights field
resource.typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.type - Usage: connector_execute, idm_integration_auth
unmapped.resource_id_hash
- Description: JumpCloud Directory Insights field
resource_id_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource_id_hash - Usage: 38 events: activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_create, activedirectory_agent_deleted, activedirectory_agent_inactive, activedirectory_config_selection_updated, activedirectory_delete, activedirectory_domain_delegated_password_change, ... (+30 more)
unmapped.resource_ids
- Description: JumpCloud Directory Insights field
resource_idspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.ids - Usage: account_resync_failure, account_resync_initiated
unmapped.resource_name_hash
- Description: JumpCloud Directory Insights field
resource_name_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource_name_hash - Usage: attributemappings_delete, connector_create, connector_delete, connector_execute, connector_update
unmapped.tags
- Description: JumpCloud Directory Insights field
tagspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
tags - Usage: 12 events: activedirectory_config_selection_updated, activedirectory_create, activedirectory_delete, activedirectory_domain_delegated_password_change, attributemappings_add, attributemappings_delete, attributemappings_update, idp_create, ... (+4 more)
unmapped.timestamp_source
- Description: JumpCloud Directory Insights field
timestamp_sourcepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
timestamp_source - Usage: 26 events: account_resync_failure, account_resync_initiated, activedirectory_agent_activate, activedirectory_agent_active, activedirectory_agent_deleted, activedirectory_agent_inactive, activedirectory_config_selection_updated, activedirectory_domain_delegated_password_change, ... (+18 more)
unmapped.useragent.device
- Description: JumpCloud Directory Insights field
useragent.devicepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.device - Usage: 45 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_create, activedirectory_delete, attributemappings_add, attributemappings_delete, attributemappings_update, ... (+37 more)
unmapped.useragent.major
- Description: JumpCloud Directory Insights field
useragent.majorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.major - Usage: 44 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_create, activedirectory_delete, attributemappings_add, attributemappings_delete, attributemappings_update, ... (+36 more)
unmapped.useragent.minor
- Description: JumpCloud Directory Insights field
useragent.minorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.minor - Usage: 44 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_create, activedirectory_delete, attributemappings_add, attributemappings_delete, attributemappings_update, ... (+36 more)
unmapped.useragent.name
- Description: JumpCloud Directory Insights field
useragent.namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.name - Usage: 45 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_create, activedirectory_delete, attributemappings_add, attributemappings_delete, attributemappings_update, ... (+37 more)
unmapped.useragent.os
- Description: JumpCloud Directory Insights field
useragent.ospreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os - Usage: 45 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_create, activedirectory_delete, attributemappings_add, attributemappings_delete, attributemappings_update, ... (+37 more)
unmapped.useragent.os_full
- Description: JumpCloud Directory Insights field
useragent.os_fullpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_full - Usage: 45 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_create, activedirectory_delete, attributemappings_add, attributemappings_delete, attributemappings_update, ... (+37 more)
unmapped.useragent.os_major
- Description: JumpCloud Directory Insights field
useragent.os_majorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_major - Usage: 42 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_delete, attributemappings_add, attributemappings_delete, attributemappings_update, duo_configuration_update, ... (+34 more)
unmapped.useragent.os_minor
- Description: JumpCloud Directory Insights field
useragent.os_minorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_minor - Usage: 41 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_delete, attributemappings_add, attributemappings_delete, attributemappings_update, duo_configuration_update, ... (+33 more)
unmapped.useragent.os_name
- Description: JumpCloud Directory Insights field
useragent.os_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_name - Usage: 45 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_create, activedirectory_delete, attributemappings_add, attributemappings_delete, attributemappings_update, ... (+37 more)
unmapped.useragent.os_patch
- Description: JumpCloud Directory Insights field
useragent.os_patchpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_patch - Usage: 41 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_delete, attributemappings_add, attributemappings_delete, attributemappings_update, duo_configuration_update, ... (+33 more)
unmapped.useragent.os_version
- Description: JumpCloud Directory Insights field
useragent.os_versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_version - Usage: 42 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_delete, attributemappings_add, attributemappings_delete, attributemappings_update, duo_configuration_update, ... (+34 more)
unmapped.useragent.patch
- Description: JumpCloud Directory Insights field
useragent.patchpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.patch - Usage: 43 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_delete, attributemappings_add, attributemappings_delete, attributemappings_update, duo_configuration_update, ... (+35 more)
unmapped.useragent.version
- Description: JumpCloud Directory Insights field
useragent.versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.version - Usage: 44 events: account_resync_failure, account_resync_initiated, activedirectory_agent_create, activedirectory_create, activedirectory_delete, attributemappings_add, attributemappings_delete, attributemappings_update, ... (+36 more)
unmapped.version
- Description: JumpCloud Directory Insights field
versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
version - Usage: connector_create, connector_delete, connector_execute, connector_update
Directory — MTP/MSP Events#
directory_mtp · 29 events
| Event | Category | Class | Activity | Type UID | Fields |
|---|---|---|---|---|---|
admin_lockout |
Identity & Access Management (3) | Account Change (3001) | Lock (9) | 300109 | 68 |
admin_suspended |
Identity & Access Management (3) | Account Change (3001) | Disable (5) | 300105 | 68 |
admin_unsuspend |
Identity & Access Management (3) | Account Change (3001) | Enable (2) | 300102 | 64 |
autotask_billing_mapping_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 68 |
autotask_billing_mapping_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 67 |
autotask_billing_mapping_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 70 |
autotask_company_mapping_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 62 |
autotask_company_mapping_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 64 |
autotask_integration_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 60 |
autotask_integration_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 58 |
connectwise_billing_mapping_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 63 |
connectwise_billing_mapping_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 59 |
connectwise_billing_mapping_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 64 |
connectwise_company_mapping_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 62 |
connectwise_company_mapping_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 64 |
connectwise_integration_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 60 |
connectwise_integration_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 60 |
connectwise_integration_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 61 |
connectwise_settings_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 61 |
msp_ticket_create |
Application Activity (6) | API Activity (6003) | Create (1) | 600301 | 34 |
mtp_download_invoice |
Identity & Access Management (3) | Entity Management (3004) | Read (2) | 300402 | 61 |
partner_organization_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 38 |
provider_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 63 |
syncro_billing_mapping_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 67 |
syncro_billing_sync |
System Activity (1) | Scheduled Job Activity (1006) | Start (6) | 100606 | 29 |
syncro_company_mapping_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 62 |
syncro_company_mapping_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 63 |
syncro_company_mapping_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 64 |
syncro_integration_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 60 |
OCSF field mappings#
Legend
- Description: what the OCSF field represents (from OCSF schema v1.8.0)
- Source: raw JumpCloud event field(s) mapped via
${{placeholder}}template - Transform:
fieldMappingsentry applied at runtime (cast, enum, etc.) - Literal: static value set in the mapping template
- Usage: event types in this service that include this field
Core
activity_id
- Description: The normalized identifier of the activity that triggered the event.
- Literal:
1,2,3,4,5,6,9 - Usage: all events in this service
activity_name
- Description: The event activity name, as defined by the activity_id.
- Literal:
Create,Delete,Disable,Enable,Lock,Read,Start,Update - Usage: all events in this service
category_name
- Description: The event category name, as defined by category_uid value:
Discovery. - Literal:
Application Activity,Identity & Access Management,System Activity - Usage: all events in this service
category_uid
- Description: The category unique identifier of the event.
- Literal:
1,3,6 - Usage: all events in this service
class_name
- Description: The event class name, as defined by class_uid value:
User Inventory Info. - Literal:
API Activity,Account Change,Entity Management,Scheduled Job Activity - Usage: all events in this service
class_uid
- Description: The unique identifier of a class. A class describes the attributes available in an event.
- Literal:
1006,3001,3004,6003 - Usage: all events in this service
severity_id
- Description: OCSF severity identifier for the event.
- Literal:
1 - Usage: all events in this service
status_detail
- Description: The status detail contains additional information about the event/finding outcome.
- Source:
error_message - Usage: all events in this service
status_id
- Description: Normalized status of the activity (1=Success, 2=Failure).
- Source:
success - Transform:
success→boolean_to_status_id; true→1, false→2 (all events in this service)- Usage: all events in this service
time
- Description: Event time, in epoch milliseconds (OCSF
time). - Source:
timestamp - Transform:
timestamp→iso8601_to_epoch_millis(all events in this service)- Usage: all events in this service
type_uid
- Description: The event/finding type ID. It identifies the event's semantics and structure. The value is calculated by the logging system as:
class_uid * 100 + activity_id. - Literal:
100606,300102,300105,300109,300401,300402,300403,300404,600301 - Usage: all events in this service
Metadata
metadata.event_code
- Description: JumpCloud event type code.
- Source:
event_type - Usage: all events in this service
metadata.original_time
- Description: The original event time as reported by the event source. For example, the time in the original format from system event log such as Syslog on Unix/Linux and the System event file on Windows. Omit if event is generated instead of collected via logs.
- Source:
server_timestamp - Usage: msp_ticket_create, partner_organization_delete, syncro_billing_sync
metadata.processed_time
- Description: The event processed time, such as an ETL operation.
- Source:
jc_transformation_ts - Usage: all events in this service
metadata.product.name
- Description: Originating JumpCloud service that produced the event.
- Source:
service - Usage: all events in this service
metadata.tenant_uid
- Description: JumpCloud organization (tenant) identifier.
- Source:
organization - Usage: all events in this service
metadata.uid
- Description: Unique event identifier assigned by JumpCloud.
- Source:
id - Usage: all events in this service
metadata.version
- Description: OCSF schema version used for this event.
- Literal:
1.8.0 - Usage: all events in this service
Actor
actor.invoked_by
- Description: The name of the service that invoked the activity as described in the event.
- Source:
initiated_by.source - Usage: partner_organization_delete
actor.user.email_addr
- Description: Email address of the actor who initiated the event.
- Source:
initiated_by.email - Usage: 26 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+18 more)
actor.user.org.uid
- Description: The unique identifier of the organization, Oracle Cloud Tenancy, Google Cloud Organization, or AWS Organization. For example, an
AWS Org IDorOracle Cloud Domain ID. - Source:
initiated_by.provider - Usage: 14 events: connectwise_billing_mapping_create, connectwise_billing_mapping_delete, connectwise_billing_mapping_update, connectwise_company_mapping_create, connectwise_company_mapping_update, connectwise_integration_create, connectwise_integration_delete, connectwise_integration_update, ... (+6 more)
actor.user.type_id
- Description: OCSF user type of the actor (1=User, 2=Admin, 3=System, 4=Service).
- Source:
initiated_by.type - Transform:
initiated_by.type→enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (27 events (missing: msp_ticket_create, syncro_billing_sync))- Usage: 27 events (missing: msp_ticket_create, syncro_billing_sync)
actor.user.uid
- Description: Unique identifier of the actor who initiated the event.
- Source:
initiated_by.id - Usage: 26 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+18 more)
User
user.account.is_disabled
- Description: Indicates if the account is disabled.
- Source:
changes.from - Usage: admin_lockout
user.email_addr
- Description: Email address of the user associated with the event.
- Source:
resource.email - Usage: admin_lockout, admin_suspended, admin_unsuspend
user.type_id
- Description: OCSF user type (1=User, 2=Admin, 3=System, 4=Service).
- Source:
resource.type - Transform:
resource.type→enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (admin_lockout, admin_suspended, admin_unsuspend)- Usage: admin_lockout, admin_suspended, admin_unsuspend
user.uid
- Description: Unique identifier of the user associated with the event.
- Source:
resource.id - Usage: admin_lockout, admin_suspended, admin_unsuspend
Entity
entity.data.auth_method
- Description: JumpCloud extension data on the managed entity:
auth_method. - Source:
auth_method - Usage: 14 events: connectwise_billing_mapping_create, connectwise_billing_mapping_delete, connectwise_billing_mapping_update, connectwise_company_mapping_create, connectwise_company_mapping_update, connectwise_integration_create, connectwise_integration_delete, connectwise_integration_update, ... (+6 more)
entity.data.changed_field
- Description: JumpCloud extension data on the managed entity:
changed_field. - Source:
changes.field - Usage: 22 events: autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, autotask_integration_delete, autotask_integration_update, connectwise_billing_mapping_create, ... (+14 more)
entity.data.changes_from
- Description: JumpCloud extension data on the managed entity:
changes_from. - Source:
changes.from - Usage: autotask_billing_mapping_create, autotask_integration_delete, autotask_integration_update, connectwise_billing_mapping_create, connectwise_integration_delete, connectwise_integration_update, connectwise_settings_update, provider_update
entity.data.changes_from_id
- Description: JumpCloud extension data on the managed entity:
changes_from_id. - Source:
changes.from.id - Usage: autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_delete, connectwise_billing_mapping_delete, connectwise_billing_mapping_update, connectwise_company_mapping_update, syncro_company_mapping_delete, syncro_company_mapping_update
entity.data.changes_from_name
- Description: JumpCloud extension data on the managed entity:
changes_from_name. - Source:
changes.from.name - Usage: autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_delete, connectwise_billing_mapping_delete, connectwise_billing_mapping_update, connectwise_company_mapping_update, syncro_company_mapping_delete, syncro_company_mapping_update
entity.data.changes_from_nonBillableUsers
- Description: JumpCloud extension data on the managed entity:
changes_from_nonBillableUsers. - Source:
changes.from.nonBillableUsers - Usage: autotask_billing_mapping_delete, autotask_billing_mapping_update
entity.data.origin
- Description: JumpCloud extension data on the managed entity:
origin. - Source:
origin - Usage: partner_organization_delete
entity.data.provider
- Description: JumpCloud extension data on the managed entity:
provider. - Source:
provider - Usage: 23 events: autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, autotask_integration_delete, autotask_integration_update, connectwise_billing_mapping_create, ... (+15 more)
entity.data.reason
- Description: JumpCloud extension data on the managed entity:
reason. - Source:
reason - Usage: partner_organization_delete
entity.data.status
- Description: JumpCloud extension data on the managed entity:
status. - Source:
status - Usage: partner_organization_delete
entity.name
- Description: The name of the managed entity. It should match the name of the specific entity object's name if populated, or the name of the managed entity if the
type_idis 'Other'. - Source:
partner_name - Usage: partner_organization_delete
entity.type
- Description: The managed entity type. For example:
Policy,User,Organization,Device. - Source:
resource.type - Usage: 23 events: autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, autotask_integration_delete, autotask_integration_update, connectwise_billing_mapping_create, ... (+15 more)
entity.uid
- Description: The identifier of the managed entity. It should match the
uidof the specific entity's object UID if populated, or the source specific ID if thetype_idis 'Other'. - Source:
resource.id - Usage: mtp_download_invoice, provider_update
entity_result.data.changes_to
- Description: JumpCloud extension data on the managed entity:
changes_to. - Source:
changes.to - Usage: autotask_billing_mapping_delete, autotask_integration_update, connectwise_billing_mapping_delete, connectwise_integration_create, connectwise_integration_update, connectwise_settings_update, provider_update, syncro_integration_create
entity_result.data.changes_to_fields_line_item_id_kind
- Description: JumpCloud extension data on the managed entity:
changes_to_fields_line_item_id_kind. - Source:
changes.to.fields.line_item_id.kind - Usage: syncro_billing_mapping_create
entity_result.data.changes_to_fields_line_item_id_numberValue
- Description: JumpCloud extension data on the managed entity:
changes_to_fields_line_item_id_numberValue. - Source:
changes.to.fields.line_item_id.numberValue - Usage: syncro_billing_mapping_create
entity_result.data.changes_to_fields_line_item_name_kind
- Description: JumpCloud extension data on the managed entity:
changes_to_fields_line_item_name_kind. - Source:
changes.to.fields.line_item_name.kind - Usage: syncro_billing_mapping_create
entity_result.data.changes_to_fields_line_item_name_stringValue
- Description: JumpCloud extension data on the managed entity:
changes_to_fields_line_item_name_stringValue. - Source:
changes.to.fields.line_item_name.stringValue - Usage: syncro_billing_mapping_create
entity_result.data.changes_to_fields_schedule_id_numberValue
- Description: JumpCloud extension data on the managed entity:
changes_to_fields_schedule_id_numberValue. - Source:
changes.to.fields.schedule_id.numberValue - Usage: syncro_billing_mapping_create
entity_result.data.changes_to_fields_schedule_name_stringValue
- Description: JumpCloud extension data on the managed entity:
changes_to_fields_schedule_name_stringValue. - Source:
changes.to.fields.schedule_name.stringValue - Usage: syncro_billing_mapping_create
entity_result.data.changes_to_id
- Description: JumpCloud extension data on the managed entity:
changes_to_id. - Source:
changes.to.id - Usage: autotask_billing_mapping_create, autotask_billing_mapping_update, autotask_company_mapping_create, connectwise_billing_mapping_create, connectwise_billing_mapping_update, connectwise_company_mapping_create, connectwise_company_mapping_update, syncro_billing_mapping_create, syncro_company_mapping_create, syncro_company_mapping_update
entity_result.data.changes_to_name
- Description: JumpCloud extension data on the managed entity:
changes_to_name. - Source:
changes.to.name - Usage: autotask_billing_mapping_create, autotask_billing_mapping_update, autotask_company_mapping_create, connectwise_billing_mapping_create, connectwise_billing_mapping_update, connectwise_company_mapping_create, connectwise_company_mapping_update, syncro_billing_mapping_create, syncro_company_mapping_create, syncro_company_mapping_update
entity_result.data.changes_to_nonBillableUsers
- Description: JumpCloud extension data on the managed entity:
changes_to_nonBillableUsers. - Source:
changes.to.nonBillableUsers - Usage: autotask_billing_mapping_create, autotask_billing_mapping_update
entity_result.data.changes_to_value
- Description: JumpCloud extension data on the managed entity:
changes_to_value. - Source:
changes.to.value - Usage: autotask_billing_mapping_create, autotask_billing_mapping_update, autotask_company_mapping_create, connectwise_billing_mapping_create, connectwise_billing_mapping_update, connectwise_company_mapping_create, connectwise_company_mapping_update, syncro_company_mapping_create, syncro_company_mapping_update
Src Endpoint
src_endpoint.autonomous_system.name
- Description: Organization name for the Autonomous System.
- Source:
asn.organization - Usage: 25 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+17 more)
src_endpoint.autonomous_system.number
- Description: Unique number that the AS is identified by.
- Source:
asn.number - Transform:
asn.number→int(25 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+17 more))- Usage: 25 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+17 more)
src_endpoint.ip
- Description: Source IP address the request originated from.
- Source:
client_ip - Usage: 28 events (missing: syncro_billing_sync)
src_endpoint.location.city
- Description: The name of the city.
- Source:
geoip.city - Usage: 26 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+18 more)
src_endpoint.location.continent
- Description: The name of the continent.
- Source:
geoip.continent_code - Usage: 26 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+18 more)
src_endpoint.location.country
- Description: The ISO 3166-1 Alpha-2 country code.
Note: The two letter country code should be capitalized. For example:
USorCA. - Source:
geoip.country_code - Usage: 26 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+18 more)
src_endpoint.location.lat
- Description: The geographical Latitude coordinate represented in Decimal Degrees (DD). For example:
42.361145. - Source:
geoip.latitude - Transform:
geoip.latitude→double(26 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+18 more))- Usage: 26 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+18 more)
src_endpoint.location.long
- Description: The geographical Longitude coordinate represented in Decimal Degrees (DD). For example:
-71.057083. - Source:
geoip.longitude - Transform:
geoip.longitude→double(26 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+18 more))- Usage: 26 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+18 more)
src_endpoint.location.region
- Description: The alphanumeric code that identifies the principal subdivision (e.g. province or state) of the country. For example, 'CH-VD' for the Canton of Vaud, Switzerland
- Source:
geoip.region_code - Usage: 26 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+18 more)
Http Request
http_request.user_agent
- Description: The request header that identifies the operating system and web browser.
- Source:
user_agent - Usage: 28 events (missing: syncro_billing_sync)
Observables
observables[].name
- Description: The full name of the observable attribute. The
nameis a pointer/reference to an attribute within the OCSF event data. For example:file.name. Array attributes may be represented in one of three ways. For example:resources.uid,resources[].uid,resources[0].uid. - Literal:
actor.user.email_addr,actor.user.uid,http_request.user_agent,src_endpoint.ip,src_endpoint.location.country,user.email_addr,user.uid - Usage: 28 events (missing: syncro_billing_sync)
observables[].type_id
- Description: The observable value type identifier.
- Literal:
14,16,2,31,5 - Usage: 28 events (missing: syncro_billing_sync)
observables[].value
- Description: The value associated with the observable attribute. The meaning of the value depends on the observable type.
If thenamerefers to a scalar attribute, then thevalueis the value of the attribute.
If thenamerefers to an object attribute, then thevalueis not populated. - Source:
client_ip,geoip.country_code,initiated_by.email,initiated_by.id,resource.email,resource.id,user_agent - Usage: 28 events (missing: syncro_billing_sync)
Other
api.request.uid
- Description: The unique request identifier.
- Source:
ticketing_event_id - Usage: msp_ticket_create
api.service.name
- Description: The name of the service.
- Source:
integration_type - Usage: msp_ticket_create
user_result.account.is_disabled
- Description: Indicates if the account is disabled.
- Source:
changes.to - Usage: admin_lockout
Unmapped
unmapped.@timestamp
- Description: JumpCloud Directory Insights field
@timestamppreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
@timestamp - Usage: autotask_company_mapping_delete, msp_ticket_create, partner_organization_delete, syncro_billing_sync
unmapped.@version
- Description: JumpCloud Directory Insights field
@versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
@version - Usage: all events in this service
unmapped.asn.network
- Description: JumpCloud Directory Insights field
asn.networkpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
asn.network - Usage: 23 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+15 more)
unmapped.auth_method
- Description: JumpCloud Directory Insights field
auth_methodpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
auth_method - Usage: 13 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+5 more)
unmapped.changed_field
- Description: JumpCloud Directory Insights field
changed_fieldpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.field - Usage: admin_lockout, admin_suspended, admin_unsuspend
unmapped.changes
- Description: JumpCloud Directory Insights field
changespreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes - Usage: mtp_download_invoice
unmapped.changes_from
- Description: JumpCloud Directory Insights field
changes_frompreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.from - Usage: admin_suspended, admin_unsuspend
unmapped.changes_to
- Description: JumpCloud Directory Insights field
changes_topreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to - Usage: admin_suspended, admin_unsuspend
unmapped.client_ip
- Description: JumpCloud Directory Insights field
client_ippreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
client_ip - Usage: syncro_billing_sync
unmapped.file_input_timestamp
- Description: JumpCloud Directory Insights field
file_input_timestamppreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
file_input_timestamp - Usage: autotask_company_mapping_delete, msp_ticket_create, partner_organization_delete, syncro_billing_sync
unmapped.geoip.region_name
- Description: JumpCloud Directory Insights field
geoip.region_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.region_name - Usage: 26 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+18 more)
unmapped.geoip.timezone
- Description: JumpCloud Directory Insights field
geoip.timezonepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.timezone - Usage: 26 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+18 more)
unmapped.initiated_by
- Description: JumpCloud Directory Insights field
initiated_bypreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by - Usage: msp_ticket_create, syncro_billing_sync
unmapped.initiated_by_email_hash
- Description: JumpCloud Directory Insights field
initiated_by_email_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_email_hash - Usage: 26 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+18 more)
unmapped.initiated_by_id_hash
- Description: JumpCloud Directory Insights field
initiated_by_id_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_id_hash - Usage: 26 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+18 more)
unmapped.initiated_by_provider
- Description: JumpCloud Directory Insights field
initiated_by_providerpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by.provider - Usage: 12 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+4 more)
unmapped.is_out_of_bound
- Description: JumpCloud Directory Insights field
is_out_of_boundpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
is_out_of_bound - Usage: all events in this service
unmapped.jc_application_name
- Description: JumpCloud Directory Insights field
jc_application_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_application_name - Usage: all events in this service
unmapped.jc_initiated_by_email
- Description: JumpCloud Directory Insights field
jc_initiated_by_emailpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_initiated_by_email - Usage: admin_lockout, admin_suspended, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, syncro_company_mapping_delete
unmapped.jc_initiated_by_username
- Description: JumpCloud Directory Insights field
jc_initiated_by_usernamepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_initiated_by_username - Usage: admin_lockout, admin_suspended, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, syncro_company_mapping_delete
unmapped.jc_organization_name
- Description: JumpCloud Directory Insights field
jc_organization_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_organization_name - Usage: admin_lockout, admin_suspended, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, syncro_company_mapping_delete
unmapped.jc_provider_id
- Description: JumpCloud Directory Insights field
jc_provider_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_provider_id - Usage: admin_lockout, admin_suspended, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update
unmapped.msp_provider_id
- Description: JumpCloud Directory Insights field
msp_provider_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
provider - Usage: admin_lockout, admin_suspended, admin_unsuspend, msp_ticket_create
unmapped.provider
- Description: JumpCloud Directory Insights field
providerpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
provider - Usage: syncro_billing_sync
unmapped.resource_id_hash
- Description: JumpCloud Directory Insights field
resource_id_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource_id_hash - Usage: admin_lockout, admin_suspended, admin_unsuspend, mtp_download_invoice, provider_update
unmapped.source_metadata_name
- Description: JumpCloud Directory Insights field
source_metadata_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by.source_metadata.name - Usage: partner_organization_delete
unmapped.tags
- Description: JumpCloud Directory Insights field
tagspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
tags - Usage: autotask_company_mapping_delete, msp_ticket_create, partner_organization_delete, syncro_billing_sync
unmapped.timestamp_source
- Description: JumpCloud Directory Insights field
timestamp_sourcepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
timestamp_source - Usage: msp_ticket_create, partner_organization_delete, syncro_billing_sync
unmapped.user_agent
- Description: JumpCloud Directory Insights field
user_agentpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
user_agent - Usage: syncro_billing_sync
unmapped.useragent.device
- Description: JumpCloud Directory Insights field
useragent.devicepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.device - Usage: 26 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+18 more)
unmapped.useragent.major
- Description: JumpCloud Directory Insights field
useragent.majorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.major - Usage: 26 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+18 more)
unmapped.useragent.minor
- Description: JumpCloud Directory Insights field
useragent.minorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.minor - Usage: 26 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+18 more)
unmapped.useragent.name
- Description: JumpCloud Directory Insights field
useragent.namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.name - Usage: 26 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+18 more)
unmapped.useragent.os
- Description: JumpCloud Directory Insights field
useragent.ospreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os - Usage: 26 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+18 more)
unmapped.useragent.os_full
- Description: JumpCloud Directory Insights field
useragent.os_fullpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_full - Usage: 26 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+18 more)
unmapped.useragent.os_major
- Description: JumpCloud Directory Insights field
useragent.os_majorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_major - Usage: 26 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+18 more)
unmapped.useragent.os_minor
- Description: JumpCloud Directory Insights field
useragent.os_minorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_minor - Usage: 25 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+17 more)
unmapped.useragent.os_name
- Description: JumpCloud Directory Insights field
useragent.os_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_name - Usage: 26 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+18 more)
unmapped.useragent.os_patch
- Description: JumpCloud Directory Insights field
useragent.os_patchpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_patch - Usage: 25 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+17 more)
unmapped.useragent.os_version
- Description: JumpCloud Directory Insights field
useragent.os_versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_version - Usage: 26 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+18 more)
unmapped.useragent.patch
- Description: JumpCloud Directory Insights field
useragent.patchpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.patch - Usage: 26 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+18 more)
unmapped.useragent.version
- Description: JumpCloud Directory Insights field
useragent.versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.version - Usage: 26 events: admin_lockout, admin_suspended, admin_unsuspend, autotask_billing_mapping_create, autotask_billing_mapping_delete, autotask_billing_mapping_update, autotask_company_mapping_create, autotask_company_mapping_delete, ... (+18 more)
Directory — Object Events#
directory_object · 46 events
| Event | Category | Class | Activity | Type UID | Fields |
|---|---|---|---|---|---|
application_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 50 |
application_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 57 |
application_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 50 |
association_change |
Identity & Access Management (3) | Group Management (3006) | Add User (3) | 300603 | 35 |
group_create |
Identity & Access Management (3) | Group Management (3006) | Create (6) | 300606 | 50 |
group_create_provision |
Application Activity (6) | API Activity (6003) | Create (1) | 600301 | 46 |
group_delete |
Identity & Access Management (3) | Group Management (3006) | Delete (5) | 300605 | 66 |
group_delete_provision |
Application Activity (6) | API Activity (6003) | Delete (4) | 600304 | 45 |
group_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 77 |
group_update_provision |
Application Activity (6) | API Activity (6003) | Update (3) | 600303 | 38 |
group_warning |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 35 |
integrationattribute_exclude |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 55 |
integrationattribute_include |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 44 |
invoice_download |
Identity & Access Management (3) | Entity Management (3004) | Read (2) | 300402 | 58 |
jumpcloud_durt_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 68 |
jumpcloud_durt_enablement_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 35 |
jumpcloud_durt_registration |
Identity & Access Management (3) | Entity Management (3004) | Enroll (6) | 300406 | 42 |
membership_create_provision |
Application Activity (6) | API Activity (6003) | Create (1) | 600301 | 45 |
membership_delete_provision |
Application Activity (6) | API Activity (6003) | Delete (4) | 600304 | 46 |
order_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 65 |
organization_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 87 |
organization_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 65 |
organization_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 87 |
provider_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 62 |
radius_radsec_certificate_upload |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 64 |
radiusserver_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 47 |
radiusserver_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 48 |
radiusserver_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 48 |
role_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 38 |
role_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 41 |
role_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 39 |
scheduled_import_job_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 68 |
scheduled_import_job_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 68 |
service_account_access_granted |
Identity & Access Management (3) | User Access Management (3005) | Assign Privileges (1) | 300501 | 66 |
service_account_access_revoked |
Identity & Access Management (3) | User Access Management (3005) | Revoke Privileges (2) | 300502 | 64 |
service_account_auth_config_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 82 |
service_account_auth_config_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 82 |
service_account_auth_config_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 43 |
service_account_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 65 |
service_account_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 83 |
service_account_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 66 |
system_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 60 |
system_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 48 |
system_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 54 |
user_group_admin_grant |
Identity & Access Management (3) | Group Management (3006) | Assign Privileges (1) | 300601 | 70 |
user_group_admin_revoke |
Identity & Access Management (3) | Group Management (3006) | Revoke Privileges (2) | 300602 | 69 |
OCSF field mappings#
Legend
- Description: what the OCSF field represents (from OCSF schema v1.8.0)
- Source: raw JumpCloud event field(s) mapped via
${{placeholder}}template - Transform:
fieldMappingsentry applied at runtime (cast, enum, etc.) - Literal: static value set in the mapping template
- Usage: event types in this service that include this field
Core
activity_id
- Description: The normalized identifier of the activity that triggered the event.
- Literal:
1,2,3,4,5,6 - Usage: all events in this service
activity_name
- Description: The event activity name, as defined by the activity_id.
- Literal:
Add User,Assign Privileges,Create,Delete,Enroll,Read,Revoke Privileges,Update - Usage: all events in this service
category_name
- Description: The event category name, as defined by category_uid value:
Discovery. - Literal:
Application Activity,Identity & Access Management - Usage: all events in this service
category_uid
- Description: The category unique identifier of the event.
- Literal:
3,6 - Usage: all events in this service
class_name
- Description: The event class name, as defined by class_uid value:
User Inventory Info. - Literal:
API Activity,Entity Management,Group Management,User Access Management - Usage: all events in this service
class_uid
- Description: The unique identifier of a class. A class describes the attributes available in an event.
- Literal:
3004,3005,3006,6003 - Usage: all events in this service
message
- Description: The description of the event/finding, as defined by the source.
- Source:
error_message,message_chain.response_message - Usage: jumpcloud_durt_delete, jumpcloud_durt_enablement_update, jumpcloud_durt_registration, scheduled_import_job_create, scheduled_import_job_delete
severity_id
- Description: OCSF severity identifier for the event.
- Literal:
1 - Usage: all events in this service
status_detail
- Description: The status detail contains additional information about the event/finding outcome.
- Source:
error_message - Usage: 32 events: application_delete, group_create_provision, group_delete, group_delete_provision, group_update, group_update_provision, group_warning, integrationattribute_exclude, ... (+24 more)
status_id
- Description: Normalized status of the activity (1=Success, 2=Failure).
- Source:
success - Transform:
success→boolean_to_status_id; true→1, false→2 (35 events: application_delete, association_change, group_create_provision, group_delete, group_delete_provision, group_update, group_update_provision, group_warning, ... (+27 more))- Usage: 35 events: application_delete, association_change, group_create_provision, group_delete, group_delete_provision, group_update, group_update_provision, group_warning, ... (+27 more)
time
- Description: Event time, in epoch milliseconds (OCSF
time). - Source:
timestamp - Transform:
timestamp→iso8601_to_epoch_millis(all events in this service)- Usage: all events in this service
type_uid
- Description: The event/finding type ID. It identifies the event's semantics and structure. The value is calculated by the logging system as:
class_uid * 100 + activity_id. - Literal:
300401,300402,300403,300404,300406,300501,300502,300601,300602,300603,300605,300606,600301,600303,600304 - Usage: all events in this service
Metadata
metadata.event_code
- Description: JumpCloud event type code.
- Source:
event_type - Usage: all events in this service
metadata.original_time
- Description: The original event time as reported by the event source. For example, the time in the original format from system event log such as Syslog on Unix/Linux and the System event file on Windows. Omit if event is generated instead of collected via logs.
- Source:
server_timestamp - Usage: 22 events: association_change, group_create_provision, group_delete_provision, group_update_provision, group_warning, jumpcloud_durt_delete, jumpcloud_durt_registration, membership_create_provision, ... (+14 more)
metadata.processed_time
- Description: The event processed time, such as an ETL operation.
- Source:
jc_transformation_ts - Usage: 34 events: application_delete, group_create_provision, group_delete, group_delete_provision, group_update, group_update_provision, group_warning, integrationattribute_exclude, ... (+26 more)
metadata.product.name
- Description: Originating JumpCloud service that produced the event.
- Source:
service - Usage: all events in this service
metadata.tenant_uid
- Description: JumpCloud organization (tenant) identifier.
- Source:
organization - Usage: all events in this service
metadata.uid
- Description: Unique event identifier assigned by JumpCloud.
- Source:
id - Usage: all events in this service
metadata.version
- Description: OCSF schema version used for this event.
- Literal:
1.8.0 - Usage: all events in this service
Actor
actor.user.email_addr
- Description: Email address of the actor who initiated the event.
- Source:
initiated_by.email - Usage: 35 events: application_create, application_delete, application_update, group_create, group_delete, group_update, integrationattribute_exclude, integrationattribute_include, ... (+27 more)
actor.user.name
- Description: Display name of the actor who initiated the event.
- Source:
initiated_by.name,initiated_by.user_name,initiated_by.username - Usage: group_create_provision, jumpcloud_durt_delete, membership_create_provision, membership_delete_provision, service_account_access_granted, service_account_create, service_account_delete, system_create
actor.user.type_id
- Description: OCSF user type of the actor (1=User, 2=Admin, 3=System, 4=Service).
- Source:
initiated_by.type - Transform:
initiated_by.type→enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (33 events: application_create, application_delete, application_update, group_delete, group_update, integrationattribute_exclude, integrationattribute_include, invoice_download, ... (+25 more))- Usage: 40 events: application_create, application_delete, application_update, association_change, group_create, group_create_provision, group_delete, group_update, ... (+32 more)
actor.user.uid
- Description: Unique identifier of the actor who initiated the event.
- Source:
initiated_by.id - Usage: 35 events: application_create, application_delete, application_update, group_create, group_delete, group_update, integrationattribute_exclude, integrationattribute_include, ... (+27 more)
User
user.name
- Description: The username. For example,
janedoe1. - Source:
association.connection.to.name,resource.name - Usage: association_change, service_account_access_granted, service_account_access_revoked
user.uid
- Description: Unique identifier of the user associated with the event.
- Source:
association.connection.to.object_id,resource.objectId - Usage: association_change, service_account_access_granted, service_account_access_revoked
Entity
entity.data.authConfigList.apiKeyConfig.apiKeyPrefix
- Description: JumpCloud extension data on the managed entity:
authConfigList.apiKeyConfig.apiKeyPrefix. - Source:
resource.authConfigList.apiKeyConfig.apiKeyPrefix - Usage: service_account_auth_config_create, service_account_auth_config_delete, service_account_delete
entity.data.authConfigList.apiKeyConfig.createdAt
- Description: JumpCloud extension data on the managed entity:
authConfigList.apiKeyConfig.createdAt. - Source:
resource.authConfigList.apiKeyConfig.createdAt - Usage: service_account_auth_config_create, service_account_auth_config_delete, service_account_delete
entity.data.authConfigList.apiKeyConfig.expiresAt
- Description: JumpCloud extension data on the managed entity:
authConfigList.apiKeyConfig.expiresAt. - Source:
resource.authConfigList.apiKeyConfig.expiresAt - Usage: service_account_auth_config_create, service_account_auth_config_delete, service_account_delete
entity.data.authConfigList.apiKeyConfig.lifetime
- Description: JumpCloud extension data on the managed entity:
authConfigList.apiKeyConfig.lifetime. - Source:
resource.authConfigList.apiKeyConfig.lifetime - Usage: service_account_auth_config_create, service_account_auth_config_delete, service_account_delete
entity.data.authConfigList.apiKeyConfig.objectId
- Description: JumpCloud extension data on the managed entity:
authConfigList.apiKeyConfig.objectId. - Source:
resource.authConfigList.apiKeyConfig.objectId - Usage: service_account_auth_config_create, service_account_auth_config_delete, service_account_delete
entity.data.authConfigList.apiKeyConfig.status
- Description: JumpCloud extension data on the managed entity:
authConfigList.apiKeyConfig.status. - Source:
resource.authConfigList.apiKeyConfig.status - Usage: service_account_auth_config_create, service_account_auth_config_delete, service_account_delete
entity.data.authConfigList.authType
- Description: JumpCloud extension data on the managed entity:
authConfigList.authType. - Source:
resource.authConfigList.authType - Usage: service_account_auth_config_create, service_account_auth_config_delete, service_account_auth_config_update, service_account_create, service_account_delete
entity.data.authConfigList.clientSecretConfig.clientId
- Description: JumpCloud extension data on the managed entity:
authConfigList.clientSecretConfig.clientId. - Source:
resource.authConfigList.clientSecretConfig.clientId - Usage: service_account_auth_config_create, service_account_auth_config_delete, service_account_auth_config_update, service_account_create, service_account_delete
entity.data.authConfigList.clientSecretConfig.createdAt
- Description: JumpCloud extension data on the managed entity:
authConfigList.clientSecretConfig.createdAt. - Source:
resource.authConfigList.clientSecretConfig.createdAt - Usage: service_account_auth_config_create, service_account_auth_config_delete, service_account_auth_config_update, service_account_create, service_account_delete
entity.data.authConfigList.clientSecretConfig.expiresAt
- Description: JumpCloud extension data on the managed entity:
authConfigList.clientSecretConfig.expiresAt. - Source:
resource.authConfigList.clientSecretConfig.expiresAt - Usage: service_account_auth_config_create, service_account_auth_config_delete, service_account_auth_config_update, service_account_create, service_account_delete
entity.data.authConfigList.clientSecretConfig.lifetime
- Description: JumpCloud extension data on the managed entity:
authConfigList.clientSecretConfig.lifetime. - Source:
resource.authConfigList.clientSecretConfig.lifetime - Usage: service_account_auth_config_create, service_account_auth_config_delete, service_account_auth_config_update, service_account_create, service_account_delete
entity.data.authConfigList.clientSecretConfig.objectId
- Description: JumpCloud extension data on the managed entity:
authConfigList.clientSecretConfig.objectId. - Source:
resource.authConfigList.clientSecretConfig.objectId - Usage: service_account_auth_config_create, service_account_auth_config_delete, service_account_auth_config_update, service_account_create, service_account_delete
entity.data.authConfigList.clientSecretConfig.status
- Description: JumpCloud extension data on the managed entity:
authConfigList.clientSecretConfig.status. - Source:
resource.authConfigList.clientSecretConfig.status - Usage: service_account_auth_config_create, service_account_auth_config_delete, service_account_auth_config_update, service_account_create, service_account_delete
entity.data.auth_method
- Description: JumpCloud extension data on the managed entity:
auth_method. - Source:
auth_method - Usage: 27 events: application_create, application_delete, application_update, group_update, integrationattribute_exclude, integrationattribute_include, jumpcloud_durt_enablement_update, order_create, ... (+19 more)
entity.data.changed_field
- Description: JumpCloud extension data on the managed entity:
changed_field. - Source:
changes.field - Usage: 27 events: application_create, application_delete, application_update, group_update, group_warning, integrationattribute_exclude, integrationattribute_include, jumpcloud_durt_enablement_update, ... (+19 more)
entity.data.changes_from
- Description: JumpCloud extension data on the managed entity:
changes_from. - Source:
changes.from - Usage: 13 events: application_delete, application_update, group_warning, integrationattribute_exclude, jumpcloud_durt_enablement_update, radiusserver_delete, radiusserver_update, role_delete, ... (+5 more)
entity.data.changes_from_allowUnenrolledMFAPasswordReset
- Description: JumpCloud extension data on the managed entity:
changes_from_allowUnenrolledMFAPasswordReset. - Source:
changes.from.allowUnenrolledMFAPasswordReset - Usage: organization_delete
entity.data.changes_from_allowUsernameSubstring
- Description: JumpCloud extension data on the managed entity:
changes_from_allowUsernameSubstring. - Source:
changes.from.allowUsernameSubstring - Usage: organization_delete
entity.data.changes_from_applicationImport
- Description: JumpCloud extension data on the managed entity:
changes_from_applicationImport. - Source:
changes.from.applicationImport - Usage: organization_delete
entity.data.changes_from_cookieExpirationType
- Description: JumpCloud extension data on the managed entity:
changes_from_cookieExpirationType. - Source:
changes.from.cookieExpirationType - Usage: organization_delete
entity.data.changes_from_csvImport
- Description: JumpCloud extension data on the managed entity:
changes_from_csvImport. - Source:
changes.from.csvImport - Usage: organization_delete
entity.data.changes_from_daysAfterExpirationToSelfRecover
- Description: JumpCloud extension data on the managed entity:
changes_from_daysAfterExpirationToSelfRecover. - Source:
changes.from.daysAfterExpirationToSelfRecover - Usage: organization_delete
entity.data.changes_from_daysBeforeExpirationToForceReset
- Description: JumpCloud extension data on the managed entity:
changes_from_daysBeforeExpirationToForceReset. - Source:
changes.from.daysBeforeExpirationToForceReset - Usage: organization_delete
entity.data.changes_from_directoryInsightsPremium_createdAt
- Description: JumpCloud extension data on the managed entity:
changes_from_directoryInsightsPremium_createdAt. - Source:
changes.from.directoryInsightsPremium.createdAt - Usage: organization_delete
entity.data.changes_from_directoryInsightsPremium_enabled
- Description: JumpCloud extension data on the managed entity:
changes_from_directoryInsightsPremium_enabled. - Source:
changes.from.directoryInsightsPremium.enabled - Usage: organization_delete
entity.data.changes_from_directoryInsightsPremium_updatedAt
- Description: JumpCloud extension data on the managed entity:
changes_from_directoryInsightsPremium_updatedAt. - Source:
changes.from.directoryInsightsPremium.updatedAt - Usage: organization_delete
entity.data.changes_from_disallowCommonlyUsedPasswords
- Description: JumpCloud extension data on the managed entity:
changes_from_disallowCommonlyUsedPasswords. - Source:
changes.from.disallowCommonlyUsedPasswords - Usage: organization_delete
entity.data.changes_from_disallowSequentialOrRepetitiveChars
- Description: JumpCloud extension data on the managed entity:
changes_from_disallowSequentialOrRepetitiveChars. - Source:
changes.from.disallowSequentialOrRepetitiveChars - Usage: organization_delete
entity.data.changes_from_effectiveDate
- Description: JumpCloud extension data on the managed entity:
changes_from_effectiveDate. - Source:
changes.from.effectiveDate - Usage: organization_delete
entity.data.changes_from_enableDaysAfterExpirationToSelfRecover
- Description: JumpCloud extension data on the managed entity:
changes_from_enableDaysAfterExpirationToSelfRecover. - Source:
changes.from.enableDaysAfterExpirationToSelfRecover - Usage: organization_delete
entity.data.changes_from_enableDaysBeforeExpirationToForceReset
- Description: JumpCloud extension data on the managed entity:
changes_from_enableDaysBeforeExpirationToForceReset. - Source:
changes.from.enableDaysBeforeExpirationToForceReset - Usage: organization_delete
entity.data.changes_from_enableLockoutTimeInSeconds
- Description: JumpCloud extension data on the managed entity:
changes_from_enableLockoutTimeInSeconds. - Source:
changes.from.enableLockoutTimeInSeconds - Usage: organization_delete
entity.data.changes_from_enableMaxHistory
- Description: JumpCloud extension data on the managed entity:
changes_from_enableMaxHistory. - Source:
changes.from.enableMaxHistory - Usage: organization_delete
entity.data.changes_from_enableMaxLoginAttempts
- Description: JumpCloud extension data on the managed entity:
changes_from_enableMaxLoginAttempts. - Source:
changes.from.enableMaxLoginAttempts - Usage: organization_delete
entity.data.changes_from_enableMinChangePeriodInDays
- Description: JumpCloud extension data on the managed entity:
changes_from_enableMinChangePeriodInDays. - Source:
changes.from.enableMinChangePeriodInDays - Usage: organization_delete
entity.data.changes_from_enableMinLength
- Description: JumpCloud extension data on the managed entity:
changes_from_enableMinLength. - Source:
changes.from.enableMinLength - Usage: organization_delete
entity.data.changes_from_enablePasswordExpirationInDays
- Description: JumpCloud extension data on the managed entity:
changes_from_enablePasswordExpirationInDays. - Source:
changes.from.enablePasswordExpirationInDays - Usage: organization_delete
entity.data.changes_from_enableRecoveryEmail
- Description: JumpCloud extension data on the managed entity:
changes_from_enableRecoveryEmail. - Source:
changes.from.enableRecoveryEmail - Usage: organization_delete
entity.data.changes_from_enableResetLockoutCounter
- Description: JumpCloud extension data on the managed entity:
changes_from_enableResetLockoutCounter. - Source:
changes.from.enableResetLockoutCounter - Usage: organization_delete
entity.data.changes_from_filters_field
- Description: JumpCloud extension data on the managed entity:
changes_from_filters_field. - Source:
changes.from.filters.field - Usage: group_update
entity.data.changes_from_filters_operator
- Description: JumpCloud extension data on the managed entity:
changes_from_filters_operator. - Source:
changes.from.filters.operator - Usage: group_update
entity.data.changes_from_filters_value
- Description: JumpCloud extension data on the managed entity:
changes_from_filters_value. - Source:
changes.from.filters.value - Usage: group_update
entity.data.changes_from_idleSessionDurationMinutes
- Description: JumpCloud extension data on the managed entity:
changes_from_idleSessionDurationMinutes. - Source:
changes.from.idleSessionDurationMinutes - Usage: organization_delete
entity.data.changes_from_ldapGroups_name
- Description: JumpCloud extension data on the managed entity:
changes_from_ldapGroups_name. - Source:
changes.from.ldapGroups.name - Usage: group_update
entity.data.changes_from_lockoutTimeInSeconds
- Description: JumpCloud extension data on the managed entity:
changes_from_lockoutTimeInSeconds. - Source:
changes.from.lockoutTimeInSeconds - Usage: organization_delete
entity.data.changes_from_manualEntry
- Description: JumpCloud extension data on the managed entity:
changes_from_manualEntry. - Source:
changes.from.manualEntry - Usage: organization_delete
entity.data.changes_from_maxHistory
- Description: JumpCloud extension data on the managed entity:
changes_from_maxHistory. - Source:
changes.from.maxHistory - Usage: organization_delete
entity.data.changes_from_maxLoginAttempts
- Description: JumpCloud extension data on the managed entity:
changes_from_maxLoginAttempts. - Source:
changes.from.maxLoginAttempts - Usage: organization_delete
entity.data.changes_from_minChangePeriodInDays
- Description: JumpCloud extension data on the managed entity:
changes_from_minChangePeriodInDays. - Source:
changes.from.minChangePeriodInDays - Usage: organization_delete
entity.data.changes_from_minLength
- Description: JumpCloud extension data on the managed entity:
changes_from_minLength. - Source:
changes.from.minLength - Usage: organization_delete
entity.data.changes_from_needsLowercase
- Description: JumpCloud extension data on the managed entity:
changes_from_needsLowercase. - Source:
changes.from.needsLowercase - Usage: organization_delete
entity.data.changes_from_needsNumeric
- Description: JumpCloud extension data on the managed entity:
changes_from_needsNumeric. - Source:
changes.from.needsNumeric - Usage: organization_delete
entity.data.changes_from_needsSymbolic
- Description: JumpCloud extension data on the managed entity:
changes_from_needsSymbolic. - Source:
changes.from.needsSymbolic - Usage: organization_delete
entity.data.changes_from_needsUppercase
- Description: JumpCloud extension data on the managed entity:
changes_from_needsUppercase. - Source:
changes.from.needsUppercase - Usage: organization_delete
entity.data.changes_from_passwordExpirationInDays
- Description: JumpCloud extension data on the managed entity:
changes_from_passwordExpirationInDays. - Source:
changes.from.passwordExpirationInDays - Usage: organization_delete
entity.data.changes_from_queryType
- Description: JumpCloud extension data on the managed entity:
changes_from_queryType. - Source:
changes.from.queryType - Usage: group_update
entity.data.changes_from_radius_reply_name
- Description: JumpCloud extension data on the managed entity:
changes_from_radius_reply_name. - Source:
changes.from.radius.reply.name - Usage: group_update
entity.data.changes_from_radius_reply_value
- Description: JumpCloud extension data on the managed entity:
changes_from_radius_reply_value. - Source:
changes.from.radius.reply.value - Usage: group_update
entity.data.changes_from_resetLockoutCounterMinutes
- Description: JumpCloud extension data on the managed entity:
changes_from_resetLockoutCounterMinutes. - Source:
changes.from.resetLockoutCounterMinutes - Usage: organization_delete
entity.data.changes_from_searchFilters
- Description: JumpCloud extension data on the managed entity:
changes_from_searchFilters. - Source:
changes.from.searchFilters - Usage: group_update
entity.data.changes_from_systemInsights_createdAt
- Description: JumpCloud extension data on the managed entity:
changes_from_systemInsights_createdAt. - Source:
changes.from.systemInsights.createdAt - Usage: organization_delete
entity.data.changes_from_systemInsights_enableNewDarwin
- Description: JumpCloud extension data on the managed entity:
changes_from_systemInsights_enableNewDarwin. - Source:
changes.from.systemInsights.enableNewDarwin - Usage: organization_delete
entity.data.changes_from_systemInsights_enableNewLinux
- Description: JumpCloud extension data on the managed entity:
changes_from_systemInsights_enableNewLinux. - Source:
changes.from.systemInsights.enableNewLinux - Usage: organization_delete
entity.data.changes_from_systemInsights_enableNewWindows
- Description: JumpCloud extension data on the managed entity:
changes_from_systemInsights_enableNewWindows. - Source:
changes.from.systemInsights.enableNewWindows - Usage: organization_delete
entity.data.changes_from_systemInsights_enabled
- Description: JumpCloud extension data on the managed entity:
changes_from_systemInsights_enabled. - Source:
changes.from.systemInsights.enabled - Usage: organization_delete
entity.data.changes_from_systemInsights_updatedAt
- Description: JumpCloud extension data on the managed entity:
changes_from_systemInsights_updatedAt. - Source:
changes.from.systemInsights.updatedAt - Usage: organization_delete
entity.data.correlation_id
- Description: JumpCloud extension data on the managed entity:
correlation_id. - Source:
correlation.id - Usage: scheduled_import_job_create, scheduled_import_job_delete
entity.data.correlation_type
- Description: JumpCloud extension data on the managed entity:
correlation_type. - Source:
correlation.type - Usage: scheduled_import_job_create, scheduled_import_job_delete
entity.data.createdAt
- Description: JumpCloud extension data on the managed entity:
createdAt. - Source:
resource.createdAt - Usage: service_account_auth_config_create, service_account_auth_config_delete, service_account_auth_config_update, service_account_create, service_account_delete
entity.data.credential_id
- Description: JumpCloud extension data on the managed entity:
credential_id. - Source:
resource.deleted_credentials.credential_id - Usage: jumpcloud_durt_delete
entity.data.credential_os
- Description: JumpCloud extension data on the managed entity:
credential_os. - Source:
resource.deleted_credentials.os - Usage: jumpcloud_durt_delete
entity.data.device_name
- Description: JumpCloud extension data on the managed entity:
device_name. - Source:
resource.name - Usage: system_create
entity.data.direction
- Description: JumpCloud extension data on the managed entity:
direction. - Source:
resource.direction - Usage: integrationattribute_exclude, integrationattribute_include
entity.data.display_label
- Description: JumpCloud extension data on the managed entity:
display_label. - Source:
resource.displayLabel - Usage: application_create, application_delete, application_update
entity.data.enrollment_type
- Description: JumpCloud extension data on the managed entity:
enrollment_type. - Source:
resource.enrollment_type - Usage: jumpcloud_durt_registration, system_create
entity.data.management_mode
- Description: JumpCloud extension data on the managed entity:
management_mode. - Source:
resource.management_mode - Usage: system_create
entity.data.mdm_vendor
- Description: JumpCloud extension data on the managed entity:
mdm_vendor. - Source:
resource.mdm_vendor - Usage: jumpcloud_durt_registration
entity.data.orgId
- Description: JumpCloud extension data on the managed entity:
orgId. - Source:
resource.orgId - Usage: service_account_auth_config_create, service_account_auth_config_delete, service_account_auth_config_update
entity.data.ownership_type
- Description: JumpCloud extension data on the managed entity:
ownership_type. - Source:
resource.ownership_type - Usage: system_create
entity.data.providerId
- Description: JumpCloud extension data on the managed entity:
providerId. - Source:
resource.providerId - Usage: service_account_auth_config_create, service_account_auth_config_delete, service_account_auth_config_update
entity.data.reason
- Description: JumpCloud extension data on the managed entity:
reason. - Source:
resource.reason - Usage: jumpcloud_durt_delete
entity.data.roleId
- Description: JumpCloud extension data on the managed entity:
roleId. - Source:
resource.roleId - Usage: service_account_auth_config_create, service_account_auth_config_delete, service_account_auth_config_update, service_account_create, service_account_delete
entity.data.roleName
- Description: JumpCloud extension data on the managed entity:
roleName. - Source:
resource.roleName - Usage: service_account_auth_config_create, service_account_auth_config_delete, service_account_auth_config_update, service_account_create, service_account_delete
entity.data.scheduled_job_id
- Description: JumpCloud extension data on the managed entity:
scheduled_job_id. - Source:
changes.delete.scheduled_job_id - Usage: scheduled_import_job_delete
entity.data.slug
- Description: JumpCloud extension data on the managed entity:
slug. - Source:
resource.name - Usage: application_create, application_delete, application_update
entity.data.subscription_productCode
- Description: JumpCloud extension data on the managed entity:
subscription_productCode. - Source:
resource.subscription.productCode - Usage: order_create
entity.data.system_user_id
- Description: JumpCloud extension data on the managed entity:
system_user_id. - Source:
resource.deleted_credentials.system_user_id - Usage: jumpcloud_durt_delete
entity.device.hostname
- Description: The device hostname.
- Source:
resource.hostname - Usage: system_create, system_delete, system_update
entity.device.os.type
- Description: The type of the operating system.
- Source:
system.osFamily - Usage: system_create
entity.device.os.version
- Description: The version of the OS running on the device that originated the event. For example: "Windows 10", "OS X 10.7", or "iOS 9".
- Source:
system.osVersion - Usage: system_create
entity.device.uid
- Description: The unique identifier of the device. For example the Windows TargetSID or AWS EC2 ARN.
- Source:
resource.deleted_credentials.system_id,resource.id,system.id - Usage: jumpcloud_durt_delete, jumpcloud_durt_registration, system_create, system_delete, system_update
entity.name
- Description: The name of the managed entity. It should match the name of the specific entity object's name if populated, or the name of the managed entity if the
type_idis 'Other'. - Source:
resource.displayName,resource.name,system.displayName - Usage: 23 events: application_create, application_delete, application_update, group_update, group_warning, organization_create, organization_delete, organization_update, ... (+15 more)
entity.type
- Description: The managed entity type. For example:
Policy,User,Organization,Device. - Source:
resource.type - Usage: 29 events: application_create, application_delete, application_update, group_update, group_warning, integrationattribute_exclude, integrationattribute_include, invoice_download, ... (+21 more)
entity.uid
- Description: The identifier of the managed entity. It should match the
uidof the specific entity's object UID if populated, or the source specific ID if thetype_idis 'Other'. - Source:
resource.account_object_id,resource.id,resource.objectId - Usage: 28 events: application_create, application_delete, application_update, group_update, group_warning, integrationattribute_exclude, integrationattribute_include, invoice_download, ... (+20 more)
entity_result.data.changes_to
- Description: JumpCloud extension data on the managed entity:
changes_to. - Source:
changes.to - Usage: 16 events: application_create, application_update, group_warning, integrationattribute_exclude, integrationattribute_include, jumpcloud_durt_enablement_update, provider_create, radius_radsec_certificate_upload, ... (+8 more)
entity_result.data.changes_to_allowUnenrolledMFAPasswordReset
- Description: JumpCloud extension data on the managed entity:
changes_to_allowUnenrolledMFAPasswordReset. - Source:
changes.to.allowUnenrolledMFAPasswordReset - Usage: organization_create, organization_update
entity_result.data.changes_to_allowUsernameSubstring
- Description: JumpCloud extension data on the managed entity:
changes_to_allowUsernameSubstring. - Source:
changes.to.allowUsernameSubstring - Usage: organization_create, organization_update
entity_result.data.changes_to_annualPrice
- Description: JumpCloud extension data on the managed entity:
changes_to_annualPrice. - Source:
changes.to.annualPrice - Usage: order_create
entity_result.data.changes_to_applicationImport
- Description: JumpCloud extension data on the managed entity:
changes_to_applicationImport. - Source:
changes.to.applicationImport - Usage: organization_create, organization_update
entity_result.data.changes_to_cookieExpirationType
- Description: JumpCloud extension data on the managed entity:
changes_to_cookieExpirationType. - Source:
changes.to.cookieExpirationType - Usage: organization_create, organization_update
entity_result.data.changes_to_csvImport
- Description: JumpCloud extension data on the managed entity:
changes_to_csvImport. - Source:
changes.to.csvImport - Usage: organization_create, organization_update
entity_result.data.changes_to_daysAfterExpirationToSelfRecover
- Description: JumpCloud extension data on the managed entity:
changes_to_daysAfterExpirationToSelfRecover. - Source:
changes.to.daysAfterExpirationToSelfRecover - Usage: organization_create, organization_update
entity_result.data.changes_to_daysBeforeExpirationToForceReset
- Description: JumpCloud extension data on the managed entity:
changes_to_daysBeforeExpirationToForceReset. - Source:
changes.to.daysBeforeExpirationToForceReset - Usage: organization_create, organization_update
entity_result.data.changes_to_directoryInsightsPremium_createdAt
- Description: JumpCloud extension data on the managed entity:
changes_to_directoryInsightsPremium_createdAt. - Source:
changes.to.directoryInsightsPremium.createdAt - Usage: organization_create, organization_update
entity_result.data.changes_to_directoryInsightsPremium_enabled
- Description: JumpCloud extension data on the managed entity:
changes_to_directoryInsightsPremium_enabled. - Source:
changes.to.directoryInsightsPremium.enabled - Usage: organization_create, organization_update
entity_result.data.changes_to_directoryInsightsPremium_updatedAt
- Description: JumpCloud extension data on the managed entity:
changes_to_directoryInsightsPremium_updatedAt. - Source:
changes.to.directoryInsightsPremium.updatedAt - Usage: organization_create, organization_update
entity_result.data.changes_to_disallowCommonlyUsedPasswords
- Description: JumpCloud extension data on the managed entity:
changes_to_disallowCommonlyUsedPasswords. - Source:
changes.to.disallowCommonlyUsedPasswords - Usage: organization_create, organization_update
entity_result.data.changes_to_disallowSequentialOrRepetitiveChars
- Description: JumpCloud extension data on the managed entity:
changes_to_disallowSequentialOrRepetitiveChars. - Source:
changes.to.disallowSequentialOrRepetitiveChars - Usage: organization_create, organization_update
entity_result.data.changes_to_effectiveDate
- Description: JumpCloud extension data on the managed entity:
changes_to_effectiveDate. - Source:
changes.to.effectiveDate - Usage: organization_create, organization_update
entity_result.data.changes_to_enableDaysAfterExpirationToSelfRecover
- Description: JumpCloud extension data on the managed entity:
changes_to_enableDaysAfterExpirationToSelfRecover. - Source:
changes.to.enableDaysAfterExpirationToSelfRecover - Usage: organization_create, organization_update
entity_result.data.changes_to_enableDaysBeforeExpirationToForceReset
- Description: JumpCloud extension data on the managed entity:
changes_to_enableDaysBeforeExpirationToForceReset. - Source:
changes.to.enableDaysBeforeExpirationToForceReset - Usage: organization_create, organization_update
entity_result.data.changes_to_enableLockoutTimeInSeconds
- Description: JumpCloud extension data on the managed entity:
changes_to_enableLockoutTimeInSeconds. - Source:
changes.to.enableLockoutTimeInSeconds - Usage: organization_create, organization_update
entity_result.data.changes_to_enableMaxHistory
- Description: JumpCloud extension data on the managed entity:
changes_to_enableMaxHistory. - Source:
changes.to.enableMaxHistory - Usage: organization_create, organization_update
entity_result.data.changes_to_enableMaxLoginAttempts
- Description: JumpCloud extension data on the managed entity:
changes_to_enableMaxLoginAttempts. - Source:
changes.to.enableMaxLoginAttempts - Usage: organization_create, organization_update
entity_result.data.changes_to_enableMinChangePeriodInDays
- Description: JumpCloud extension data on the managed entity:
changes_to_enableMinChangePeriodInDays. - Source:
changes.to.enableMinChangePeriodInDays - Usage: organization_create, organization_update
entity_result.data.changes_to_enableMinLength
- Description: JumpCloud extension data on the managed entity:
changes_to_enableMinLength. - Source:
changes.to.enableMinLength - Usage: organization_create, organization_update
entity_result.data.changes_to_enablePasswordExpirationInDays
- Description: JumpCloud extension data on the managed entity:
changes_to_enablePasswordExpirationInDays. - Source:
changes.to.enablePasswordExpirationInDays - Usage: organization_create, organization_update
entity_result.data.changes_to_enableRecoveryEmail
- Description: JumpCloud extension data on the managed entity:
changes_to_enableRecoveryEmail. - Source:
changes.to.enableRecoveryEmail - Usage: organization_create, organization_update
entity_result.data.changes_to_enableResetLockoutCounter
- Description: JumpCloud extension data on the managed entity:
changes_to_enableResetLockoutCounter. - Source:
changes.to.enableResetLockoutCounter - Usage: organization_create, organization_update
entity_result.data.changes_to_features
- Description: JumpCloud extension data on the managed entity:
changes_to_features. - Source:
changes.to.features - Usage: order_create
entity_result.data.changes_to_filters
- Description: JumpCloud extension data on the managed entity:
changes_to_filters. - Source:
changes.to.filters - Usage: group_update
entity_result.data.changes_to_idleSessionDurationMinutes
- Description: JumpCloud extension data on the managed entity:
changes_to_idleSessionDurationMinutes. - Source:
changes.to.idleSessionDurationMinutes - Usage: organization_create, organization_update
entity_result.data.changes_to_ldapGroups_name
- Description: JumpCloud extension data on the managed entity:
changes_to_ldapGroups_name. - Source:
changes.to.ldapGroups.name - Usage: group_update
entity_result.data.changes_to_ldap_groups_name
- Description: JumpCloud extension data on the managed entity:
changes_to_ldap_groups_name. - Source:
changes.to.ldap_groups.name - Usage: group_update
entity_result.data.changes_to_listPrice
- Description: JumpCloud extension data on the managed entity:
changes_to_listPrice. - Source:
changes.to.listPrice - Usage: order_create
entity_result.data.changes_to_lockoutTimeInSeconds
- Description: JumpCloud extension data on the managed entity:
changes_to_lockoutTimeInSeconds. - Source:
changes.to.lockoutTimeInSeconds - Usage: organization_create, organization_update
entity_result.data.changes_to_manualEntry
- Description: JumpCloud extension data on the managed entity:
changes_to_manualEntry. - Source:
changes.to.manualEntry - Usage: organization_create, organization_update
entity_result.data.changes_to_maxHistory
- Description: JumpCloud extension data on the managed entity:
changes_to_maxHistory. - Source:
changes.to.maxHistory - Usage: organization_create, organization_update
entity_result.data.changes_to_maxLoginAttempts
- Description: JumpCloud extension data on the managed entity:
changes_to_maxLoginAttempts. - Source:
changes.to.maxLoginAttempts - Usage: organization_create, organization_update
entity_result.data.changes_to_minChangePeriodInDays
- Description: JumpCloud extension data on the managed entity:
changes_to_minChangePeriodInDays. - Source:
changes.to.minChangePeriodInDays - Usage: organization_create, organization_update
entity_result.data.changes_to_minLength
- Description: JumpCloud extension data on the managed entity:
changes_to_minLength. - Source:
changes.to.minLength - Usage: organization_create, organization_update
entity_result.data.changes_to_needsLowercase
- Description: JumpCloud extension data on the managed entity:
changes_to_needsLowercase. - Source:
changes.to.needsLowercase - Usage: organization_create, organization_update
entity_result.data.changes_to_needsNumeric
- Description: JumpCloud extension data on the managed entity:
changes_to_needsNumeric. - Source:
changes.to.needsNumeric - Usage: organization_create, organization_update
entity_result.data.changes_to_needsSymbolic
- Description: JumpCloud extension data on the managed entity:
changes_to_needsSymbolic. - Source:
changes.to.needsSymbolic - Usage: organization_create, organization_update
entity_result.data.changes_to_needsUppercase
- Description: JumpCloud extension data on the managed entity:
changes_to_needsUppercase. - Source:
changes.to.needsUppercase - Usage: organization_create, organization_update
entity_result.data.changes_to_oneTimePrice
- Description: JumpCloud extension data on the managed entity:
changes_to_oneTimePrice. - Source:
changes.to.oneTimePrice - Usage: order_create
entity_result.data.changes_to_passwordExpirationInDays
- Description: JumpCloud extension data on the managed entity:
changes_to_passwordExpirationInDays. - Source:
changes.to.passwordExpirationInDays - Usage: organization_create, organization_update
entity_result.data.changes_to_posix_groups
- Description: JumpCloud extension data on the managed entity:
changes_to_posix_groups. - Source:
changes.to.posix_groups - Usage: group_update
entity_result.data.changes_to_productCode
- Description: JumpCloud extension data on the managed entity:
changes_to_productCode. - Source:
changes.to.productCode - Usage: order_create
entity_result.data.changes_to_queryType
- Description: JumpCloud extension data on the managed entity:
changes_to_queryType. - Source:
changes.to.queryType - Usage: group_update
entity_result.data.changes_to_radius_reply_name
- Description: JumpCloud extension data on the managed entity:
changes_to_radius_reply_name. - Source:
changes.to.radius.reply.name - Usage: group_update
entity_result.data.changes_to_radius_reply_tempId
- Description: JumpCloud extension data on the managed entity:
changes_to_radius_reply_tempId. - Source:
changes.to.radius.reply.tempId - Usage: group_update
entity_result.data.changes_to_radius_reply_value
- Description: JumpCloud extension data on the managed entity:
changes_to_radius_reply_value. - Source:
changes.to.radius.reply.value - Usage: group_update
entity_result.data.changes_to_resetLockoutCounterMinutes
- Description: JumpCloud extension data on the managed entity:
changes_to_resetLockoutCounterMinutes. - Source:
changes.to.resetLockoutCounterMinutes - Usage: organization_create, organization_update
entity_result.data.changes_to_sambaEnabled
- Description: JumpCloud extension data on the managed entity:
changes_to_sambaEnabled. - Source:
changes.to.sambaEnabled - Usage: group_update
entity_result.data.changes_to_samba_enabled
- Description: JumpCloud extension data on the managed entity:
changes_to_samba_enabled. - Source:
changes.to.samba_enabled - Usage: group_update
entity_result.data.changes_to_searchFilters
- Description: JumpCloud extension data on the managed entity:
changes_to_searchFilters. - Source:
changes.to.searchFilters - Usage: group_update
entity_result.data.changes_to_sudo
- Description: JumpCloud extension data on the managed entity:
changes_to_sudo. - Source:
changes.to.sudo - Usage: group_update
entity_result.data.changes_to_systemInsights_createdAt
- Description: JumpCloud extension data on the managed entity:
changes_to_systemInsights_createdAt. - Source:
changes.to.systemInsights.createdAt - Usage: organization_create, organization_update
entity_result.data.changes_to_systemInsights_enableNewDarwin
- Description: JumpCloud extension data on the managed entity:
changes_to_systemInsights_enableNewDarwin. - Source:
changes.to.systemInsights.enableNewDarwin - Usage: organization_create, organization_update
entity_result.data.changes_to_systemInsights_enableNewLinux
- Description: JumpCloud extension data on the managed entity:
changes_to_systemInsights_enableNewLinux. - Source:
changes.to.systemInsights.enableNewLinux - Usage: organization_create, organization_update
entity_result.data.changes_to_systemInsights_enableNewWindows
- Description: JumpCloud extension data on the managed entity:
changes_to_systemInsights_enableNewWindows. - Source:
changes.to.systemInsights.enableNewWindows - Usage: organization_create, organization_update
entity_result.data.changes_to_systemInsights_enabled
- Description: JumpCloud extension data on the managed entity:
changes_to_systemInsights_enabled. - Source:
changes.to.systemInsights.enabled - Usage: organization_create, organization_update
entity_result.data.changes_to_systemInsights_updatedAt
- Description: JumpCloud extension data on the managed entity:
changes_to_systemInsights_updatedAt. - Source:
changes.to.systemInsights.updatedAt - Usage: organization_create, organization_update
entity_result.data.scheduled_job_id
- Description: JumpCloud extension data on the managed entity:
scheduled_job_id. - Source:
changes.add.scheduled_job_id - Usage: scheduled_import_job_create
Src Endpoint
src_endpoint.autonomous_system.name
- Description: Organization name for the Autonomous System.
- Source:
asn.organization - Usage: 15 events: jumpcloud_durt_delete, order_create, provider_create, radius_radsec_certificate_upload, scheduled_import_job_create, scheduled_import_job_delete, service_account_access_granted, service_account_access_revoked, ... (+7 more)
src_endpoint.autonomous_system.number
- Description: Unique number that the AS is identified by.
- Source:
asn.number - Transform:
asn.number→int(15 events: jumpcloud_durt_delete, order_create, provider_create, radius_radsec_certificate_upload, scheduled_import_job_create, scheduled_import_job_delete, service_account_access_granted, service_account_access_revoked, ... (+7 more))- Usage: 15 events: jumpcloud_durt_delete, order_create, provider_create, radius_radsec_certificate_upload, scheduled_import_job_create, scheduled_import_job_delete, service_account_access_granted, service_account_access_revoked, ... (+7 more)
src_endpoint.ip
- Description: Source IP address the request originated from.
- Source:
client_ip - Usage: 42 events (missing: association_change, jumpcloud_durt_enablement_update, jumpcloud_durt_registration, organization_delete)
src_endpoint.location.city
- Description: The name of the city.
- Source:
geoip.city - Usage: 20 events: application_delete, group_delete, integrationattribute_exclude, invoice_download, jumpcloud_durt_delete, order_create, provider_create, radius_radsec_certificate_upload, ... (+12 more)
src_endpoint.location.continent
- Description: The name of the continent.
- Source:
geoip.continent_code - Usage: 32 events: application_create, application_delete, application_update, group_create, group_delete, group_update, integrationattribute_exclude, integrationattribute_include, ... (+24 more)
src_endpoint.location.country
- Description: The ISO 3166-1 Alpha-2 country code.
Note: The two letter country code should be capitalized. For example:
USorCA. - Source:
geoip.country_code - Usage: 32 events: application_create, application_delete, application_update, group_create, group_delete, group_update, integrationattribute_exclude, integrationattribute_include, ... (+24 more)
src_endpoint.location.lat
- Description: The geographical Latitude coordinate represented in Decimal Degrees (DD). For example:
42.361145. - Source:
geoip.latitude - Transform:
geoip.latitude→double(32 events: application_create, application_delete, application_update, group_create, group_delete, group_update, integrationattribute_exclude, integrationattribute_include, ... (+24 more))- Usage: 32 events: application_create, application_delete, application_update, group_create, group_delete, group_update, integrationattribute_exclude, integrationattribute_include, ... (+24 more)
src_endpoint.location.long
- Description: The geographical Longitude coordinate represented in Decimal Degrees (DD). For example:
-71.057083. - Source:
geoip.longitude - Transform:
geoip.longitude→double(32 events: application_create, application_delete, application_update, group_create, group_delete, group_update, integrationattribute_exclude, integrationattribute_include, ... (+24 more))- Usage: 32 events: application_create, application_delete, application_update, group_create, group_delete, group_update, integrationattribute_exclude, integrationattribute_include, ... (+24 more)
src_endpoint.location.region
- Description: The alphanumeric code that identifies the principal subdivision (e.g. province or state) of the country. For example, 'CH-VD' for the Canton of Vaud, Switzerland
- Source:
geoip.region_code - Usage: 30 events: application_create, application_delete, application_update, group_create, group_delete, group_update, integrationattribute_exclude, integrationattribute_include, ... (+22 more)
Http Request
http_request.user_agent
- Description: The request header that identifies the operating system and web browser.
- Source:
user_agent - Usage: 28 events: group_create_provision, group_delete, group_delete_provision, group_update_provision, group_warning, integrationattribute_exclude, jumpcloud_durt_delete, jumpcloud_durt_registration, ... (+20 more)
Observables
observables[].name
- Description: The full name of the observable attribute. The
nameis a pointer/reference to an attribute within the OCSF event data. For example:file.name. Array attributes may be represented in one of three ways. For example:resources.uid,resources[].uid,resources[0].uid. - Literal:
actor.user.email_addr,actor.user.name,actor.user.uid,entity.device.hostname,entity.device.uid,group.name,group.uid,http_request.user_agent,resource.uid,src_endpoint.ip,src_endpoint.location.country,subgroup.name,subgroup.uid,user.name,user.uid - Usage: 45 events (missing: organization_delete)
observables[].type_id
- Description: The observable value type identifier.
- Literal:
1,10,14,16,2,31,32,33,4,47,5 - Usage: 45 events (missing: organization_delete)
observables[].value
- Description: The value associated with the observable attribute. The meaning of the value depends on the observable type.
If thenamerefers to a scalar attribute, then thevalueis the value of the attribute.
If thenamerefers to an object attribute, then thevalueis not populated. - Source:
association.connection.from.name,association.connection.from.object_id,association.connection.to.name,association.connection.to.object_id,changes.organizationId,client_ip,geoip.country_code,initiated_by.email,initiated_by.id,initiated_by.name,initiated_by.user_name,initiated_by.username,resource.deleted_credentials.system_id,resource.hostname,resource.id,resource.name,resource.objectId,system.id,system_group.id,system_group.name,user_agent - Usage: 45 events (missing: organization_delete)
Resources
resources.type
- Description: The resource type as defined by the event source.
- Source:
resource.type - Usage: group_create_provision, group_delete_provision, group_update_provision, membership_create_provision, membership_delete_provision
Other
action
- Description: The normalized caption of
action_id. - Source:
association.op - Usage: association_change
group.name
- Description: The group name.
- Source:
association.connection.from.name,resource.name - Usage: association_change, group_create, group_delete, user_group_admin_grant, user_group_admin_revoke
group.type
- Description: The type of the group.
- Source:
association.connection.from.type,resource.type - Usage: association_change, group_create, group_delete, user_group_admin_grant, user_group_admin_revoke
group.uid
- Description: The unique identifier of the group. For example, for Windows events this is the security identifier (SID) of the group. Another example, pool id or desktop id that the device belongs to.
- Source:
association.connection.from.object_id,resource.id - Usage: association_change, group_create, group_delete, user_group_admin_grant, user_group_admin_revoke
resource.uid
- Description: The unique identifier of the resource.
- Source:
changes.organizationId - Usage: service_account_access_granted, service_account_access_revoked
subgroup.name
- Description: The group name.
- Source:
system_group.name - Usage: user_group_admin_grant, user_group_admin_revoke
subgroup.type
- Description: The type of the group.
- Source:
system_group.type - Usage: user_group_admin_grant, user_group_admin_revoke
subgroup.uid
- Description: The unique identifier of the group. For example, for Windows events this is the security identifier (SID) of the group. Another example, pool id or desktop id that the device belongs to.
- Source:
system_group.id - Usage: user_group_admin_grant, user_group_admin_revoke
Unmapped
unmapped.@timestamp
- Description: JumpCloud Directory Insights field
@timestamppreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
@timestamp - Usage: 18 events: application_create, application_delete, application_update, association_change, group_create, group_delete, group_update, integrationattribute_exclude, ... (+10 more)
unmapped.@version
- Description: JumpCloud Directory Insights field
@versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
@version - Usage: all events in this service
unmapped.application_id
- Description: JumpCloud Directory Insights field
application_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
application.id - Usage: group_create_provision, membership_create_provision, membership_delete_provision
unmapped.application_id_hash
- Description: JumpCloud Directory Insights field
application_id_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
application_id_hash - Usage: membership_delete_provision
unmapped.application_name
- Description: JumpCloud Directory Insights field
application_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
application.name - Usage: group_create_provision, group_delete_provision, group_update_provision, membership_create_provision, membership_delete_provision, scheduled_import_job_create, scheduled_import_job_delete
unmapped.application_type
- Description: JumpCloud Directory Insights field
application_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
application.type - Usage: group_create_provision, membership_create_provision, membership_delete_provision
unmapped.asn.error
- Description: JumpCloud Directory Insights field
asn.errorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
asn.error - Usage: system_create
unmapped.asn.ip_address
- Description: JumpCloud Directory Insights field
asn.ip_addresspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
asn.ip_address - Usage: system_create
unmapped.asn.network
- Description: JumpCloud Directory Insights field
asn.networkpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
asn.network - Usage: 15 events: jumpcloud_durt_delete, order_create, provider_create, radius_radsec_certificate_upload, scheduled_import_job_create, scheduled_import_job_delete, service_account_access_granted, service_account_access_revoked, ... (+7 more)
unmapped.association_action_source
- Description: JumpCloud Directory Insights field
association_action_sourcepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
association.action_source - Usage: association_change
unmapped.association_attributes
- Description: JumpCloud Directory Insights field
association_attributespreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
association.attributes - Usage: association_change
unmapped.association_to_type
- Description: JumpCloud Directory Insights field
association_to_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
association.connection.to.type - Usage: association_change
unmapped.auth_method
- Description: JumpCloud Directory Insights field
auth_methodpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
auth_method - Usage: group_create, group_create_provision, group_delete, invoice_download, membership_create_provision, membership_delete_provision, service_account_access_granted, service_account_access_revoked, user_group_admin_grant, user_group_admin_revoke
unmapped.changes
- Description: JumpCloud Directory Insights field
changespreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes - Usage: invoice_download
unmapped.changes.from.ldapGroups.name
- Description: JumpCloud Directory Insights field
changes.from.ldapGroups.namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.from.ldapGroups.name - Usage: group_delete
unmapped.changes.from.role
- Description: JumpCloud Directory Insights field
changes.from.rolepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.from.role - Usage: group_delete
unmapped.changes.to.filters
- Description: JumpCloud Directory Insights field
changes.to.filterspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to.filters - Usage: group_create
unmapped.changes.to.ldapGroups.name
- Description: JumpCloud Directory Insights field
changes.to.ldapGroups.namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to.ldapGroups.name - Usage: group_create
unmapped.changes.to.queryType
- Description: JumpCloud Directory Insights field
changes.to.queryTypepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to.queryType - Usage: group_create
unmapped.changes_field
- Description: JumpCloud Directory Insights field
changes_fieldpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.field - Usage: group_create, group_delete, user_group_admin_grant, user_group_admin_revoke
unmapped.changes_from
- Description: JumpCloud Directory Insights field
changes_frompreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.from - Usage: group_delete, user_group_admin_revoke
unmapped.changes_to
- Description: JumpCloud Directory Insights field
changes_topreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to - Usage: group_create, user_group_admin_grant, user_group_admin_revoke
unmapped.client_id
- Description: JumpCloud Directory Insights field
client_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
client_id - Usage: group_create_provision, group_delete_provision, group_update_provision, membership_create_provision, membership_delete_provision, scheduled_import_job_create, scheduled_import_job_delete
unmapped.client_ip
- Description: JumpCloud Directory Insights field
client_ippreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
client_ip - Usage: jumpcloud_durt_registration
unmapped.correlation
- Description: JumpCloud Directory Insights field
correlationpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
correlation - Usage: group_create_provision, group_delete_provision, group_update_provision, membership_create_provision, membership_delete_provision
unmapped.file_input_timestamp
- Description: JumpCloud Directory Insights field
file_input_timestamppreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
file_input_timestamp - Usage: 18 events: application_create, application_delete, application_update, association_change, group_create, group_delete, group_update, integrationattribute_exclude, ... (+10 more)
unmapped.geoip.region_name
- Description: JumpCloud Directory Insights field
geoip.region_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.region_name - Usage: 30 events: application_create, application_delete, application_update, group_create, group_delete, group_update, integrationattribute_exclude, integrationattribute_include, ... (+22 more)
unmapped.geoip.timezone
- Description: JumpCloud Directory Insights field
geoip.timezonepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.timezone - Usage: 32 events: application_create, application_delete, application_update, group_create, group_delete, group_update, integrationattribute_exclude, integrationattribute_include, ... (+24 more)
unmapped.initiated_by
- Description: JumpCloud Directory Insights field
initiated_bypreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by - Usage: group_delete_provision, group_update_provision, scheduled_import_job_create, scheduled_import_job_delete, service_account_auth_config_update
unmapped.initiated_by.provider
- Description: JumpCloud Directory Insights field
initiated_by.providerpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by.provider - Usage: group_delete
unmapped.initiated_by.user_id
- Description: JumpCloud Directory Insights field
initiated_by.user_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by.user_id - Usage: group_delete
unmapped.initiated_by_email_hash
- Description: JumpCloud Directory Insights field
initiated_by_email_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_email_hash - Usage: 25 events: application_delete, group_delete, group_update, integrationattribute_exclude, invoice_download, jumpcloud_durt_delete, jumpcloud_durt_registration, order_create, ... (+17 more)
unmapped.initiated_by_id_hash
- Description: JumpCloud Directory Insights field
initiated_by_id_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_id_hash - Usage: 25 events: application_delete, group_delete, group_update, integrationattribute_exclude, invoice_download, jumpcloud_durt_delete, jumpcloud_durt_registration, order_create, ... (+17 more)
unmapped.initiated_by_name_hash
- Description: JumpCloud Directory Insights field
initiated_by_name_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_name_hash - Usage: group_create_provision, membership_create_provision, membership_delete_provision, service_account_access_granted, service_account_create, service_account_delete
unmapped.initiated_by_provider
- Description: JumpCloud Directory Insights field
initiated_by_providerpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by.provider - Usage: provider_create, user_group_admin_grant
unmapped.initiated_by_source
- Description: JumpCloud Directory Insights field
initiated_by_sourcepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by.source - Usage: group_create_provision, membership_create_provision, membership_delete_provision
unmapped.initiated_by_user_id
- Description: JumpCloud Directory Insights field
initiated_by_user_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by.user_id - Usage: invoice_download
unmapped.initiated_by_username_hash
- Description: JumpCloud Directory Insights field
initiated_by_username_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_username_hash - Usage: jumpcloud_durt_delete
unmapped.is_out_of_bound
- Description: JumpCloud Directory Insights field
is_out_of_boundpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
is_out_of_bound - Usage: 28 events: group_create_provision, group_delete, group_delete_provision, group_update_provision, group_warning, integrationattribute_exclude, jumpcloud_durt_delete, jumpcloud_durt_registration, ... (+20 more)
unmapped.jc_application_name
- Description: JumpCloud Directory Insights field
jc_application_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_application_name - Usage: 28 events: group_create_provision, group_delete, group_delete_provision, group_update_provision, group_warning, integrationattribute_exclude, jumpcloud_durt_delete, jumpcloud_durt_registration, ... (+20 more)
unmapped.jc_initiated_by_email
- Description: JumpCloud Directory Insights field
jc_initiated_by_emailpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_initiated_by_email - Usage: 12 events: group_delete_provision, jumpcloud_durt_delete, jumpcloud_durt_registration, role_delete, scheduled_import_job_create, scheduled_import_job_delete, service_account_auth_config_create, service_account_auth_config_delete, ... (+4 more)
unmapped.jc_initiated_by_id
- Description: JumpCloud Directory Insights field
jc_initiated_by_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_initiated_by_id - Usage: group_delete_provision
unmapped.jc_initiated_by_username
- Description: JumpCloud Directory Insights field
jc_initiated_by_usernamepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_initiated_by_username - Usage: 12 events: group_delete_provision, jumpcloud_durt_delete, jumpcloud_durt_registration, role_delete, scheduled_import_job_create, scheduled_import_job_delete, service_account_auth_config_create, service_account_auth_config_delete, ... (+4 more)
unmapped.jc_organization_name
- Description: JumpCloud Directory Insights field
jc_organization_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_organization_name - Usage: 12 events: group_delete_provision, jumpcloud_durt_delete, jumpcloud_durt_registration, role_delete, scheduled_import_job_create, scheduled_import_job_delete, service_account_auth_config_create, service_account_auth_config_delete, ... (+4 more)
unmapped.jc_provider_id
- Description: JumpCloud Directory Insights field
jc_provider_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_provider_id - Usage: group_delete_provision, jumpcloud_durt_delete, jumpcloud_durt_registration, scheduled_import_job_create, scheduled_import_job_delete, service_account_auth_config_create, service_account_auth_config_delete, service_account_delete, user_group_admin_grant, user_group_admin_revoke
unmapped.jc_system_display_name
- Description: JumpCloud Directory Insights field
jc_system_display_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_system_display_name - Usage: group_delete_provision
unmapped.jc_system_hostname
- Description: JumpCloud Directory Insights field
jc_system_hostnamepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_system_hostname - Usage: group_delete_provision
unmapped.message_chain_message_details
- Description: JumpCloud Directory Insights field
message_chain_message_detailspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
message_chain.message_details - Usage: group_create_provision, group_delete_provision, group_update_provision, membership_create_provision, membership_delete_provision, scheduled_import_job_create, scheduled_import_job_delete
unmapped.message_chain_response_code
- Description: JumpCloud Directory Insights field
message_chain_response_codepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
message_chain.response_code - Usage: group_create_provision, group_delete_provision, group_update_provision, membership_create_provision, membership_delete_provision, scheduled_import_job_create, scheduled_import_job_delete
unmapped.message_chain_response_message
- Description: JumpCloud Directory Insights field
message_chain_response_messagepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
message_chain.response_message - Usage: group_create_provision, group_delete_provision, group_update_provision, membership_create_provision, membership_delete_provision
unmapped.msp_provider_id
- Description: JumpCloud Directory Insights field
msp_provider_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
provider - Usage: 18 events: organization_delete, provider_create, radius_radsec_certificate_upload, radiusserver_create, radiusserver_delete, radiusserver_update, role_create, role_delete, ... (+10 more)
unmapped.provider
- Description: JumpCloud Directory Insights field
providerpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
provider - Usage: 14 events: application_create, application_delete, application_update, association_change, group_create, group_delete, group_update, integrationattribute_exclude, ... (+6 more)
unmapped.resource_email
- Description: JumpCloud Directory Insights field
resource_emailpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.email - Usage: group_create_provision
unmapped.resource_group_email
- Description: JumpCloud Directory Insights field
resource_group_emailpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.group_email - Usage: membership_create_provision, membership_delete_provision
unmapped.resource_group_id
- Description: JumpCloud Directory Insights field
resource_group_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.group_id - Usage: membership_create_provision, membership_delete_provision
unmapped.resource_group_name
- Description: JumpCloud Directory Insights field
resource_group_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.group_name - Usage: membership_create_provision, membership_delete_provision
unmapped.resource_id
- Description: JumpCloud Directory Insights field
resource_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.id - Usage: group_create_provision, group_delete_provision, group_update_provision
unmapped.resource_id_hash
- Description: JumpCloud Directory Insights field
resource_id_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource_id_hash - Usage: 21 events: application_delete, group_create_provision, group_delete, group_delete_provision, group_update, group_update_provision, group_warning, integrationattribute_exclude, ... (+13 more)
unmapped.resource_name
- Description: JumpCloud Directory Insights field
resource_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.name - Usage: group_create_provision
unmapped.resource_type
- Description: JumpCloud Directory Insights field
resource_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.type - Usage: service_account_access_granted, service_account_access_revoked
unmapped.resource_user_email
- Description: JumpCloud Directory Insights field
resource_user_emailpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.user_email - Usage: membership_create_provision, membership_delete_provision
unmapped.resource_username
- Description: JumpCloud Directory Insights field
resource_usernamepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.username - Usage: group_create_provision, group_delete_provision, group_update_provision
unmapped.service_account_role_id
- Description: JumpCloud Directory Insights field
service_account_role_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.roleId - Usage: service_account_access_granted, service_account_access_revoked
unmapped.service_account_role_name
- Description: JumpCloud Directory Insights field
service_account_role_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.roleName - Usage: service_account_access_granted, service_account_access_revoked
unmapped.tags
- Description: JumpCloud Directory Insights field
tagspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
tags - Usage: 18 events: application_create, application_delete, application_update, association_change, group_create, group_delete, group_update, integrationattribute_exclude, ... (+10 more)
unmapped.timestamp_source
- Description: JumpCloud Directory Insights field
timestamp_sourcepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
timestamp_source - Usage: 22 events: association_change, group_create_provision, group_delete_provision, group_update_provision, group_warning, jumpcloud_durt_delete, jumpcloud_durt_registration, membership_create_provision, ... (+14 more)
unmapped.useragent.device
- Description: JumpCloud Directory Insights field
useragent.devicepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.device - Usage: 32 events: application_create, application_delete, application_update, group_create, group_delete, group_update, integrationattribute_exclude, integrationattribute_include, ... (+24 more)
unmapped.useragent.major
- Description: JumpCloud Directory Insights field
useragent.majorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.major - Usage: 29 events: application_create, application_delete, application_update, group_create, group_delete, group_update, invoice_download, jumpcloud_durt_delete, ... (+21 more)
unmapped.useragent.minor
- Description: JumpCloud Directory Insights field
useragent.minorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.minor - Usage: 29 events: application_create, application_delete, application_update, group_create, group_delete, group_update, invoice_download, jumpcloud_durt_delete, ... (+21 more)
unmapped.useragent.name
- Description: JumpCloud Directory Insights field
useragent.namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.name - Usage: 32 events: application_create, application_delete, application_update, group_create, group_delete, group_update, integrationattribute_exclude, integrationattribute_include, ... (+24 more)
unmapped.useragent.os
- Description: JumpCloud Directory Insights field
useragent.ospreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os - Usage: 32 events: application_create, application_delete, application_update, group_create, group_delete, group_update, integrationattribute_exclude, integrationattribute_include, ... (+24 more)
unmapped.useragent.os_full
- Description: JumpCloud Directory Insights field
useragent.os_fullpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_full - Usage: 32 events: application_create, application_delete, application_update, group_create, group_delete, group_update, integrationattribute_exclude, integrationattribute_include, ... (+24 more)
unmapped.useragent.os_major
- Description: JumpCloud Directory Insights field
useragent.os_majorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_major - Usage: 17 events: group_delete, group_update, invoice_download, jumpcloud_durt_delete, order_create, provider_create, radius_radsec_certificate_upload, scheduled_import_job_create, ... (+9 more)
unmapped.useragent.os_minor
- Description: JumpCloud Directory Insights field
useragent.os_minorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_minor - Usage: 17 events: group_delete, group_update, invoice_download, jumpcloud_durt_delete, order_create, provider_create, radius_radsec_certificate_upload, scheduled_import_job_create, ... (+9 more)
unmapped.useragent.os_name
- Description: JumpCloud Directory Insights field
useragent.os_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_name - Usage: 32 events: application_create, application_delete, application_update, group_create, group_delete, group_update, integrationattribute_exclude, integrationattribute_include, ... (+24 more)
unmapped.useragent.os_patch
- Description: JumpCloud Directory Insights field
useragent.os_patchpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_patch - Usage: 17 events: group_delete, group_update, invoice_download, jumpcloud_durt_delete, order_create, provider_create, radius_radsec_certificate_upload, scheduled_import_job_create, ... (+9 more)
unmapped.useragent.os_version
- Description: JumpCloud Directory Insights field
useragent.os_versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_version - Usage: 17 events: group_delete, group_update, invoice_download, jumpcloud_durt_delete, order_create, provider_create, radius_radsec_certificate_upload, scheduled_import_job_create, ... (+9 more)
unmapped.useragent.patch
- Description: JumpCloud Directory Insights field
useragent.patchpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.patch - Usage: 20 events: application_create, application_delete, group_delete, group_update, invoice_download, jumpcloud_durt_delete, order_create, provider_create, ... (+12 more)
unmapped.useragent.version
- Description: JumpCloud Directory Insights field
useragent.versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.version - Usage: 29 events: application_create, application_delete, application_update, group_create, group_delete, group_update, invoice_download, jumpcloud_durt_delete, ... (+21 more)
Directory — User and Admin Events#
directory_user_admin · 98 events
| Event | Category | Class | Activity | Type UID | Fields |
|---|---|---|---|---|---|
admin_access_granted |
Identity & Access Management (3) | User Access Management (3005) | Assign Privileges (1) | 300501 | 61 |
admin_access_revoked |
Identity & Access Management (3) | User Access Management (3005) | Revoke Privileges (2) | 300502 | 66 |
admin_apikey_created |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 46 |
admin_apikey_expired |
Identity & Access Management (3) | Entity Management (3004) | Deactivate (11) | 300411 | 36 |
admin_apikey_expiring_soon |
Identity & Access Management (3) | Entity Management (3004) | Read (2) | 300402 | 35 |
admin_apikey_revoked |
Identity & Access Management (3) | Entity Management (3004) | Disable (9) | 300409 | 54 |
admin_create |
Identity & Access Management (3) | Account Change (3001) | Create (1) | 300101 | 47 |
admin_delete |
Identity & Access Management (3) | Account Change (3001) | Delete (6) | 300106 | 63 |
admin_login_attempt |
Identity & Access Management (3) | Authentication (3002) | Logon (1) | 300201 | 49 |
admin_old_api_key_attempt |
Identity & Access Management (3) | Authentication (3002) | Logon (1) | 300201 | 52 |
admin_password_change |
Identity & Access Management (3) | Account Change (3001) | Password Change (3) | 300103 | 58 |
admin_password_reset_request |
Identity & Access Management (3) | Account Change (3001) | Password Reset (4) | 300104 | 58 |
admin_password_set |
Identity & Access Management (3) | Account Change (3001) | Password Change (3) | 300103 | 59 |
admin_role_granted |
Identity & Access Management (3) | User Access Management (3005) | Assign Privileges (1) | 300501 | 64 |
admin_role_revoked |
Identity & Access Management (3) | User Access Management (3005) | Revoke Privileges (2) | 300502 | 64 |
admin_totp_disable |
Identity & Access Management (3) | Account Change (3001) | MFA Factor Disable (11) | 300111 | 62 |
admin_totp_finish_enrollment |
Identity & Access Management (3) | Account Change (3001) | MFA Factor Enable (10) | 300110 | 57 |
admin_totp_start_enrollment |
Identity & Access Management (3) | Account Change (3001) | MFA Factor Enable (10) | 300110 | 57 |
admin_update |
Identity & Access Management (3) | Account Change (3001) | Other (99) | 300199 | 48 |
feature_settings_change |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 61 |
jumpcloud_protect_device_activation |
Identity & Access Management (3) | Entity Management (3004) | Activate (10) | 300410 | 70 |
jumpcloud_protect_device_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 79 |
jumpcloud_protect_device_enrollment |
Identity & Access Management (3) | Entity Management (3004) | Enroll (6) | 300406 | 74 |
jumpcloud_protect_device_push_verification |
Identity & Access Management (3) | Authentication (3002) | Other (99) | 300299 | 67 |
jumpcloud_protect_device_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 70 |
minimum_mfa_compliance_state_changed |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 62 |
minimum_mfa_policy_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 63 |
minimum_mfa_policy_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 66 |
nli_settings_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 47 |
push_configuration_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 65 |
push_mfa_attempt_failed |
Identity & Access Management (3) | Authentication (3002) | Logon (1) | 300201 | 42 |
registered_mobile_secret_generated |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 51 |
registered_mobile_secret_revoked |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 51 |
registered_mobile_secret_rotated |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 52 |
sms_configuration_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 66 |
sms_otp_delete_enrollment |
Identity & Access Management (3) | Entity Management (3004) | Unenroll (7) | 300407 | 66 |
sms_otp_finish_enrollment |
Identity & Access Management (3) | Entity Management (3004) | Enroll (6) | 300406 | 69 |
sms_otp_start_enrollment |
Identity & Access Management (3) | Entity Management (3004) | Enroll (6) | 300406 | 66 |
sms_twilio_configuration_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 67 |
sms_twilio_configuration_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 65 |
sms_twilio_configuration_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 63 |
sms_twilio_excluded_user_groups_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 67 |
totp_configuration_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 61 |
totp_delete_enrollment |
Identity & Access Management (3) | Account Change (3001) | MFA Factor Disable (11) | 300111 | 38 |
totp_finish_enrollment |
Identity & Access Management (3) | Account Change (3001) | MFA Factor Enable (10) | 300110 | 63 |
totp_start_enrollment |
Identity & Access Management (3) | Account Change (3001) | MFA Factor Enable (10) | 300110 | 61 |
trial_resume |
Identity & Access Management (3) | Entity Management (3004) | Resume (13) | 300413 | 60 |
trial_start |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 57 |
trial_stop |
Identity & Access Management (3) | Entity Management (3004) | Disable (9) | 300409 | 60 |
unified_mfa_totp_delete_enrollment |
Identity & Access Management (3) | Account Change (3001) | MFA Factor Disable (11) | 300111 | 69 |
unified_mfa_totp_enrollment |
Identity & Access Management (3) | Account Change (3001) | MFA Factor Enable (10) | 300110 | 60 |
unified_mfa_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 54 |
unified_mfa_user_update |
Identity & Access Management (3) | Account Change (3001) | MFA Factor Enable (10) | 300110 | 60 |
user_activated |
Identity & Access Management (3) | Account Change (3001) | Enable (2) | 300102 | 53 |
user_activation_email |
Network Activity (4) | Email Activity (4009) | Send (1) | 400901 | 67 |
user_activation_schedule_create |
System Activity (1) | Scheduled Job Activity (1006) | Create (1) | 100601 | 53 |
user_activation_schedule_delete |
System Activity (1) | Scheduled Job Activity (1006) | Delete (3) | 100603 | 49 |
user_admin_grant |
Identity & Access Management (3) | User Access Management (3005) | Assign Privileges (1) | 300501 | 72 |
user_admin_granted |
Identity & Access Management (3) | User Access Management (3005) | Assign Privileges (1) | 300501 | 71 |
user_admin_revoke |
Identity & Access Management (3) | User Access Management (3005) | Revoke Privileges (2) | 300502 | 72 |
user_admin_revoked |
Identity & Access Management (3) | User Access Management (3005) | Revoke Privileges (2) | 300502 | 81 |
user_create |
Identity & Access Management (3) | Account Change (3001) | Create (1) | 300101 | 59 |
user_create_provision |
Application Activity (6) | Application Lifecycle (6002) | Install (1) | 600201 | 59 |
user_deactivated |
Identity & Access Management (3) | Account Change (3001) | Disable (5) | 300105 | 40 |
user_delegated_authority_update |
Identity & Access Management (3) | Account Change (3001) | Other (99) | 300199 | 64 |
user_delete |
Identity & Access Management (3) | Account Change (3001) | Delete (6) | 300106 | 47 |
user_delete_provision |
Application Activity (6) | Application Lifecycle (6002) | Remove (2) | 600202 | 35 |
user_deprovision |
Application Activity (6) | Application Lifecycle (6002) | Remove (2) | 600202 | 56 |
user_import_completed |
System Activity (1) | Scheduled Job Activity (1006) | Other (99) | 100699 | 35 |
user_import_error |
Application Activity (6) | Application Error (6008) | General Error (1) | 600801 | 39 |
user_import_skipped |
System Activity (1) | Scheduled Job Activity (1006) | Other (99) | 100699 | 40 |
user_import_started |
System Activity (1) | Scheduled Job Activity (1006) | Start (6) | 100606 | 35 |
user_import_stopped |
Application Activity (6) | Application Error (6008) | General Error (1) | 600801 | 36 |
user_login_attempt |
Identity & Access Management (3) | Authentication (3002) | Logon (1) | 300201 | 66 |
user_lookup_provision |
Application Activity (6) | API Activity (6003) | Read (2) | 600302 | 37 |
user_mfa_exclusion_expired |
Identity & Access Management (3) | Account Change (3001) | Other (99) | 300199 | 38 |
user_password_expired |
Identity & Access Management (3) | Account Change (3001) | Other (99) | 300199 | 33 |
user_password_reset_email |
Network Activity (4) | Email Activity (4009) | Send (1) | 400901 | 59 |
user_password_reset_request |
Identity & Access Management (3) | Account Change (3001) | Password Reset (4) | 300104 | 64 |
user_password_set |
Identity & Access Management (3) | Account Change (3001) | Password Change (3) | 300103 | 59 |
user_password_update_provision |
Identity & Access Management (3) | Account Change (3001) | Password Change (3) | 300103 | 47 |
user_password_warning_email |
Network Activity (4) | Email Activity (4009) | Send (1) | 400901 | 36 |
user_suspended |
Identity & Access Management (3) | Account Change (3001) | Disable (5) | 300105 | 34 |
user_suspension_schedule_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 46 |
user_suspension_schedule_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 49 |
user_transfer_in |
Identity & Access Management (3) | Account Change (3001) | Other (99) | 300199 | 54 |
user_transfer_out |
Identity & Access Management (3) | Account Change (3001) | Other (99) | 300199 | 54 |
user_unlocked |
Identity & Access Management (3) | Account Change (3001) | Unlock (12) | 300112 | 68 |
user_update |
Identity & Access Management (3) | Account Change (3001) | Other (99) | 300199 | 81 |
user_update_password_provision |
Identity & Access Management (3) | Account Change (3001) | Password Change (3) | 300103 | 50 |
user_update_provision |
Identity & Access Management (3) | Account Change (3001) | Other (99) | 300199 | 73 |
user_update_provision_manager |
Application Activity (6) | API Activity (6003) | Update (3) | 600303 | 38 |
webauthn_configuration_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 57 |
webauthnconfig_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 59 |
webauthncredential_beginregistration |
Identity & Access Management (3) | Account Change (3001) | MFA Factor Enable (10) | 300110 | 73 |
webauthncredential_delete |
Identity & Access Management (3) | Account Change (3001) | MFA Factor Disable (11) | 300111 | 67 |
webauthncredential_finishregistration |
Identity & Access Management (3) | Account Change (3001) | MFA Factor Enable (10) | 300110 | 71 |
webauthncredential_update |
Identity & Access Management (3) | Account Change (3001) | Other (99) | 300199 | 65 |
OCSF field mappings#
Legend
- Description: what the OCSF field represents (from OCSF schema v1.8.0)
- Source: raw JumpCloud event field(s) mapped via
${{placeholder}}template - Transform:
fieldMappingsentry applied at runtime (cast, enum, etc.) - Literal: static value set in the mapping template
- Usage: event types in this service that include this field
Core
activity_id
- Description: The normalized identifier of the activity that triggered the event.
- Literal:
1,10,11,12,13,2,3,4,5,6,7,9,99 - Usage: all events in this service
activity_name
- Description: The event activity name, as defined by the activity_id.
- Literal:
Activate,Assign Privileges,Create,Deactivate,Delete,Disable,Enable,Enroll,General Error,Install,Logon,MFA Factor Disable,MFA Factor Enable,Other,Password Change,Password Reset,Read,Remove,Resume,Revoke Privileges,Send,Start,Unenroll,Unlock,Update - Usage: all events in this service
category_name
- Description: The event category name, as defined by category_uid value:
Discovery. - Literal:
Application Activity,Identity & Access Management,Network Activity,System Activity - Usage: all events in this service
category_uid
- Description: The category unique identifier of the event.
- Literal:
1,3,4,6 - Usage: all events in this service
class_name
- Description: The event class name, as defined by class_uid value:
User Inventory Info. - Literal:
API Activity,Account Change,Application Error,Application Lifecycle,Authentication,Email Activity,Entity Management,Scheduled Job Activity,User Access Management - Usage: all events in this service
class_uid
- Description: The unique identifier of a class. A class describes the attributes available in an event.
- Literal:
1006,3001,3002,3004,3005,4009,6002,6003,6008 - Usage: all events in this service
message
- Description: The description of the event/finding, as defined by the source.
- Source:
message_chain.message_details,message_chain.response_message - Usage: 15 events: user_create_provision, user_delete_provision, user_deprovision, user_import_completed, user_import_error, user_import_skipped, user_import_started, user_import_stopped, ... (+7 more)
severity_id
- Description: OCSF severity identifier for the event.
- Literal:
1 - Usage: all events in this service
status_detail
- Description: The status detail contains additional information about the event/finding outcome.
- Source:
error_message,message_chain.response_message - Usage: 87 events: admin_access_granted, admin_access_revoked, admin_apikey_expired, admin_apikey_expiring_soon, admin_delete, admin_old_api_key_attempt, admin_password_change, admin_password_reset_request, ... (+79 more)
status_id
- Description: Normalized status of the activity (1=Success, 2=Failure).
- Source:
success - Transform:
success→boolean_to_status_id; true→1, false→2 (93 events (missing: admin_apikey_revoked, admin_create, admin_update, user_create, user_delete))- Usage: 93 events (missing: admin_apikey_revoked, admin_create, admin_update, user_create, user_delete)
time
- Description: Event time, in epoch milliseconds (OCSF
time). - Source:
timestamp - Transform:
timestamp→iso8601_to_epoch_millis(all events in this service)- Usage: all events in this service
type_uid
- Description: The event/finding type ID. It identifies the event's semantics and structure. The value is calculated by the logging system as:
class_uid * 100 + activity_id. - Literal:
100601,100603,100606,100699,300101,300102,300103,300104,300105,300106,300110,300111,300112,300199,300201,300299,300401,300402,300403,300404,300406,300407,300409,300410,300411,300413,300501,300502,400901,600201,600202,600302,600303,600801 - Usage: all events in this service
Metadata
metadata.event_code
- Description: JumpCloud event type code.
- Source:
event_type - Usage: all events in this service
metadata.original_time
- Description: The original event time as reported by the event source. For example, the time in the original format from system event log such as Syslog on Unix/Linux and the System event file on Windows. Omit if event is generated instead of collected via logs.
- Source:
server_timestamp - Usage: 44 events: feature_settings_change, jumpcloud_protect_device_activation, jumpcloud_protect_device_delete, jumpcloud_protect_device_enrollment, jumpcloud_protect_device_push_verification, jumpcloud_protect_device_update, minimum_mfa_compliance_state_changed, minimum_mfa_policy_create, ... (+36 more)
metadata.processed_time
- Description: The event processed time, such as an ETL operation.
- Source:
jc_transformation_ts - Usage: 84 events: admin_access_granted, admin_access_revoked, admin_apikey_expired, admin_apikey_expiring_soon, admin_delete, admin_old_api_key_attempt, admin_password_change, admin_password_reset_request, ... (+76 more)
metadata.product.name
- Description: Originating JumpCloud service that produced the event.
- Source:
service - Usage: all events in this service
metadata.tenant_uid
- Description: JumpCloud organization (tenant) identifier.
- Source:
organization - Usage: all events in this service
metadata.uid
- Description: Unique event identifier assigned by JumpCloud.
- Source:
id - Usage: all events in this service
metadata.version
- Description: OCSF schema version used for this event.
- Literal:
1.8.0 - Usage: all events in this service
Actor
actor.user.email_addr
- Description: Email address of the actor who initiated the event.
- Source:
initiated_by.email - Usage: 62 events: admin_access_granted, admin_access_revoked, admin_apikey_created, admin_apikey_revoked, admin_create, admin_delete, admin_password_change, admin_password_reset_request, ... (+54 more)
actor.user.name
- Description: Display name of the actor who initiated the event.
- Source:
initiated_by.name,initiated_by.username - Usage: 20 events: jumpcloud_protect_device_activation, jumpcloud_protect_device_delete, jumpcloud_protect_device_enrollment, jumpcloud_protect_device_update, minimum_mfa_compliance_state_changed, sms_otp_delete_enrollment, sms_otp_finish_enrollment, sms_otp_start_enrollment, ... (+12 more)
actor.user.type_id
- Description: OCSF user type of the actor (1=User, 2=Admin, 3=System, 4=Service).
- Source:
initiated_by.type - Transform:
initiated_by.type→enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (81 events: admin_access_granted, admin_access_revoked, admin_apikey_created, admin_apikey_expired, admin_apikey_expiring_soon, admin_apikey_revoked, admin_create, admin_delete, ... (+73 more))- Usage: 82 events: admin_access_granted, admin_access_revoked, admin_apikey_created, admin_apikey_expired, admin_apikey_expiring_soon, admin_apikey_revoked, admin_create, admin_delete, ... (+74 more)
actor.user.uid
- Description: Unique identifier of the actor who initiated the event.
- Source:
initiated_by.id - Usage: 73 events: admin_access_granted, admin_access_revoked, admin_apikey_created, admin_apikey_revoked, admin_create, admin_delete, admin_password_change, admin_password_reset_request, ... (+65 more)
User
user.email_addr
- Description: Email address of the user associated with the event.
- Source:
changes.to.user.name,initiated_by.email,initiated_by.username,resource.email - Usage: 19 events: admin_access_granted, admin_access_revoked, admin_create, admin_delete, admin_login_attempt, admin_old_api_key_attempt, admin_password_change, admin_password_reset_request, ... (+11 more)
user.name
- Description: The username. For example,
janedoe1. - Source:
auth_mfa_context.jumpcloud_protect_device.username,changes.to.user.display_name,resource.username,verification_context.jumpcloud_protect_device.username - Usage: 30 events: jumpcloud_protect_device_push_verification, push_mfa_attempt_failed, totp_delete_enrollment, totp_finish_enrollment, totp_start_enrollment, unified_mfa_totp_delete_enrollment, unified_mfa_totp_enrollment, unified_mfa_user_update, ... (+22 more)
user.type
- Description: The type of the user. For example, System, AWS IAM User, etc.
- Source:
resource.type - Usage: 12 events: user_mfa_exclusion_expired, user_password_expired, user_password_reset_request, user_password_set, user_password_update_provision, user_suspended, user_transfer_in, user_transfer_out, ... (+4 more)
user.type_id
- Description: OCSF user type (1=User, 2=Admin, 3=System, 4=Service).
- Source:
initiated_by.type,resource.type - Transform:
initiated_by.type→enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (admin_login_attempt, admin_old_api_key_attempt, jumpcloud_protect_device_push_verification, user_login_attempt)resource.type→enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (26 events: admin_access_granted, admin_access_revoked, admin_create, admin_delete, admin_password_change, admin_password_reset_request, admin_password_set, admin_totp_disable, ... (+18 more))- Usage: 30 events: admin_access_granted, admin_access_revoked, admin_create, admin_delete, admin_login_attempt, admin_old_api_key_attempt, admin_password_change, admin_password_reset_request, ... (+22 more)
user.uid
- Description: Unique identifier of the user associated with the event.
- Source:
auth_mfa_context.jumpcloud_protect_device.user_id,changes.to.user.id,initiated_by.id,resource.id,resource.userId,resource.user_id,verification_context.jumpcloud_protect_device.user_id - Usage: 49 events: admin_access_granted, admin_access_revoked, admin_create, admin_delete, admin_login_attempt, admin_old_api_key_attempt, admin_password_change, admin_password_reset_request, ... (+41 more)
Device
device.model
- Description: The model of the device. For example
ThinkPad X1 Carbon. - Source:
auth_mfa_context.jumpcloud_protect_device.model,verification_context.jumpcloud_protect_device.model - Usage: jumpcloud_protect_device_push_verification, push_mfa_attempt_failed
device.os.type
- Description: The type of the operating system.
- Source:
auth_mfa_context.jumpcloud_protect_device.os,verification_context.jumpcloud_protect_device.os - Usage: jumpcloud_protect_device_push_verification, push_mfa_attempt_failed
device.os.version
- Description: The version of the OS running on the device that originated the event. For example: "Windows 10", "OS X 10.7", or "iOS 9".
- Source:
auth_mfa_context.jumpcloud_protect_device.os_version,verification_context.jumpcloud_protect_device.os_version - Usage: jumpcloud_protect_device_push_verification, push_mfa_attempt_failed
device.uid
- Description: The unique identifier of the device. For example the Windows TargetSID or AWS EC2 ARN.
- Source:
auth_mfa_context.jumpcloud_protect_device.id,verification_context.jumpcloud_protect_device.id - Usage: jumpcloud_protect_device_push_verification, push_mfa_attempt_failed
device.vendor_name
- Description: The vendor for the device. For example
DellorLenovo. - Source:
auth_mfa_context.jumpcloud_protect_device.make,verification_context.jumpcloud_protect_device.make - Usage: jumpcloud_protect_device_push_verification, push_mfa_attempt_failed
Entity
entity.data.active_secret_id
- Description: JumpCloud extension data on the managed entity:
active_secret_id. - Source:
resource.active_secret_id - Usage: registered_mobile_secret_rotated
entity.data.app_version
- Description: JumpCloud extension data on the managed entity:
app_version. - Source:
resource.metadata.jumpcloud_protect_device.app_version - Usage: jumpcloud_protect_device_activation, jumpcloud_protect_device_delete, jumpcloud_protect_device_enrollment, jumpcloud_protect_device_update
entity.data.auth_method
- Description: JumpCloud extension data on the managed entity:
auth_method. - Source:
auth_method - Usage: 30 events: admin_apikey_created, admin_apikey_expired, admin_apikey_expiring_soon, admin_apikey_revoked, feature_settings_change, jumpcloud_protect_device_activation, jumpcloud_protect_device_delete, jumpcloud_protect_device_enrollment, ... (+22 more)
entity.data.changed_field
- Description: JumpCloud extension data on the managed entity:
changed_field. - Source:
changes.field - Usage: 23 events: admin_apikey_revoked, feature_settings_change, jumpcloud_protect_device_activation, jumpcloud_protect_device_delete, jumpcloud_protect_device_enrollment, jumpcloud_protect_device_update, minimum_mfa_policy_create, minimum_mfa_policy_update, ... (+15 more)
entity.data.changes_from
- Description: JumpCloud extension data on the managed entity:
changes_from. - Source:
changes.from - Usage: 18 events: admin_apikey_revoked, feature_settings_change, jumpcloud_protect_device_activation, jumpcloud_protect_device_delete, jumpcloud_protect_device_update, minimum_mfa_policy_update, nli_settings_update, push_configuration_update, ... (+10 more)
entity.data.createdAt
- Description: JumpCloud extension data on the managed entity:
createdAt. - Source:
resource.createdAt - Usage: admin_apikey_revoked
entity.data.enrollment_type
- Description: JumpCloud extension data on the managed entity:
enrollment_type. - Source:
resource.enrollment_type - Usage: registered_mobile_secret_generated, registered_mobile_secret_revoked, registered_mobile_secret_rotated
entity.data.expireAt
- Description: JumpCloud extension data on the managed entity:
expireAt. - Source:
resource.expireAt - Usage: admin_apikey_expired, admin_apikey_expiring_soon, admin_apikey_revoked
entity.data.initiated_by_source
- Description: JumpCloud extension data on the managed entity:
initiated_by_source. - Source:
initiated_by.source - Usage: jumpcloud_protect_device_activation, jumpcloud_protect_device_delete, jumpcloud_protect_device_enrollment
entity.data.label
- Description: JumpCloud extension data on the managed entity:
label. - Source:
resource.label - Usage: registered_mobile_secret_generated, registered_mobile_secret_revoked, registered_mobile_secret_rotated
entity.data.masked_phone_number
- Description: JumpCloud extension data on the managed entity:
masked_phone_number. - Source:
resource.masked_phone_number - Usage: sms_otp_delete_enrollment, sms_otp_finish_enrollment, sms_otp_start_enrollment
entity.data.prefix
- Description: JumpCloud extension data on the managed entity:
prefix. - Source:
resource.prefix - Usage: admin_apikey_expired, admin_apikey_expiring_soon, admin_apikey_revoked
entity.data.previous_compliance_state
- Description: JumpCloud extension data on the managed entity:
previous_compliance_state. - Source:
previous_compliance_state - Usage: minimum_mfa_compliance_state_changed
entity.data.provider
- Description: JumpCloud extension data on the managed entity:
provider. - Source:
provider - Usage: webauthn_configuration_update, webauthnconfig_update
entity.data.revokedAt
- Description: JumpCloud extension data on the managed entity:
revokedAt. - Source:
resource.revokedAt - Usage: admin_apikey_revoked
entity.data.settings_name
- Description: JumpCloud extension data on the managed entity:
settings_name. - Source:
resource.settings.name - Usage: feature_settings_change
entity.data.settings_value
- Description: JumpCloud extension data on the managed entity:
settings_value. - Source:
resource.settings.value - Usage: feature_settings_change
entity.data.trigger
- Description: JumpCloud extension data on the managed entity:
trigger. - Source:
trigger - Usage: minimum_mfa_compliance_state_changed
entity.data.userEmail
- Description: JumpCloud extension data on the managed entity:
userEmail. - Source:
resource.userEmail - Usage: admin_apikey_revoked
entity.data.userId
- Description: JumpCloud extension data on the managed entity:
userId. - Source:
resource.userId - Usage: admin_apikey_revoked
entity.data.user_id
- Description: JumpCloud extension data on the managed entity:
user_id. - Source:
resource.user_id - Usage: jumpcloud_protect_device_activation, jumpcloud_protect_device_delete, jumpcloud_protect_device_enrollment, jumpcloud_protect_device_update, sms_otp_delete_enrollment, sms_otp_finish_enrollment, sms_otp_start_enrollment
entity.device.model
- Description: The model of the device. For example
ThinkPad X1 Carbon. - Source:
resource.metadata.jumpcloud_protect_device.model - Usage: jumpcloud_protect_device_activation, jumpcloud_protect_device_delete, jumpcloud_protect_device_enrollment, jumpcloud_protect_device_update
entity.device.os.type
- Description: The type of the operating system.
- Source:
resource.metadata.jumpcloud_protect_device.os - Usage: jumpcloud_protect_device_activation, jumpcloud_protect_device_delete, jumpcloud_protect_device_enrollment, jumpcloud_protect_device_update
entity.device.os.version
- Description: The version of the OS running on the device that originated the event. For example: "Windows 10", "OS X 10.7", or "iOS 9".
- Source:
resource.metadata.jumpcloud_protect_device.os_version - Usage: jumpcloud_protect_device_activation, jumpcloud_protect_device_delete, jumpcloud_protect_device_enrollment, jumpcloud_protect_device_update
entity.device.vendor_name
- Description: The vendor for the device. For example
DellorLenovo. - Source:
resource.metadata.jumpcloud_protect_device.make - Usage: jumpcloud_protect_device_activation, jumpcloud_protect_device_delete, jumpcloud_protect_device_enrollment, jumpcloud_protect_device_update
entity.name
- Description: The name of the managed entity. It should match the name of the specific entity object's name if populated, or the name of the managed entity if the
type_idis 'Other'. - Source:
resource.name - Usage: feature_settings_change, trial_resume, trial_start, trial_stop
entity.org.uid
- Description: The unique identifier of the organization, Oracle Cloud Tenancy, Google Cloud Organization, or AWS Organization. For example, an
AWS Org IDorOracle Cloud Domain ID. - Source:
organization_object_id - Usage: minimum_mfa_compliance_state_changed
entity.type
- Description: The managed entity type. For example:
Policy,User,Organization,Device. - Source:
resource.category,resource.type - Usage: 29 events: admin_apikey_created, admin_apikey_expired, admin_apikey_expiring_soon, admin_apikey_revoked, feature_settings_change, jumpcloud_protect_device_activation, jumpcloud_protect_device_delete, jumpcloud_protect_device_enrollment, ... (+21 more)
entity.uid
- Description: The identifier of the managed entity. It should match the
uidof the specific entity's object UID if populated, or the source specific ID if thetype_idis 'Other'. - Source:
resource.id,user_object_id - Usage: 19 events: jumpcloud_protect_device_activation, jumpcloud_protect_device_delete, jumpcloud_protect_device_enrollment, jumpcloud_protect_device_update, minimum_mfa_compliance_state_changed, minimum_mfa_policy_create, minimum_mfa_policy_update, registered_mobile_secret_generated, ... (+11 more)
entity_result.data.changes_to
- Description: JumpCloud extension data on the managed entity:
changes_to. - Source:
changes.to - Usage: 21 events: admin_apikey_revoked, feature_settings_change, jumpcloud_protect_device_activation, jumpcloud_protect_device_enrollment, jumpcloud_protect_device_update, minimum_mfa_policy_create, minimum_mfa_policy_update, nli_settings_update, ... (+13 more)
entity_result.data.new_compliance_state
- Description: JumpCloud extension data on the managed entity:
new_compliance_state. - Source:
new_compliance_state - Usage: minimum_mfa_compliance_state_changed
Src Endpoint
src_endpoint.autonomous_system.name
- Description: Organization name for the Autonomous System.
- Source:
asn.organization - Usage: 36 events: admin_access_revoked, admin_password_set, admin_role_granted, admin_role_revoked, admin_totp_disable, jumpcloud_protect_device_activation, jumpcloud_protect_device_delete, jumpcloud_protect_device_enrollment, ... (+28 more)
src_endpoint.autonomous_system.number
- Description: Unique number that the AS is identified by.
- Source:
asn.number - Transform:
asn.number→int(36 events: admin_access_revoked, admin_password_set, admin_role_granted, admin_role_revoked, admin_totp_disable, jumpcloud_protect_device_activation, jumpcloud_protect_device_delete, jumpcloud_protect_device_enrollment, ... (+28 more))- Usage: 36 events: admin_access_revoked, admin_password_set, admin_role_granted, admin_role_revoked, admin_totp_disable, jumpcloud_protect_device_activation, jumpcloud_protect_device_delete, jumpcloud_protect_device_enrollment, ... (+28 more)
src_endpoint.ip
- Description: Source IP address the request originated from.
- Source:
client_ip - Usage: 87 events: admin_access_granted, admin_access_revoked, admin_apikey_created, admin_apikey_expired, admin_apikey_expiring_soon, admin_apikey_revoked, admin_create, admin_delete, ... (+79 more)
src_endpoint.location.city
- Description: The name of the city.
- Source:
geoip.city,location.City.Name - Usage: 60 events: admin_access_granted, admin_access_revoked, admin_delete, admin_old_api_key_attempt, admin_password_change, admin_password_reset_request, admin_password_set, admin_role_granted, ... (+52 more)
src_endpoint.location.continent
- Description: The name of the continent.
- Source:
geoip.continent_code - Usage: 71 events: admin_access_granted, admin_access_revoked, admin_apikey_created, admin_apikey_revoked, admin_create, admin_delete, admin_login_attempt, admin_old_api_key_attempt, ... (+63 more)
src_endpoint.location.country
- Description: The ISO 3166-1 Alpha-2 country code.
Note: The two letter country code should be capitalized. For example:
USorCA. - Source:
geoip.country_code,location.Country.IsoCode - Usage: 71 events: admin_access_granted, admin_access_revoked, admin_apikey_created, admin_apikey_revoked, admin_create, admin_delete, admin_login_attempt, admin_old_api_key_attempt, ... (+63 more)
src_endpoint.location.lat
- Description: The geographical Latitude coordinate represented in Decimal Degrees (DD). For example:
42.361145. - Source:
geoip.latitude - Transform:
geoip.latitude→double(71 events: admin_access_granted, admin_access_revoked, admin_apikey_created, admin_apikey_revoked, admin_create, admin_delete, admin_login_attempt, admin_old_api_key_attempt, ... (+63 more))- Usage: 71 events: admin_access_granted, admin_access_revoked, admin_apikey_created, admin_apikey_revoked, admin_create, admin_delete, admin_login_attempt, admin_old_api_key_attempt, ... (+63 more)
src_endpoint.location.long
- Description: The geographical Longitude coordinate represented in Decimal Degrees (DD). For example:
-71.057083. - Source:
geoip.longitude - Transform:
geoip.longitude→double(71 events: admin_access_granted, admin_access_revoked, admin_apikey_created, admin_apikey_revoked, admin_create, admin_delete, admin_login_attempt, admin_old_api_key_attempt, ... (+63 more))- Usage: 71 events: admin_access_granted, admin_access_revoked, admin_apikey_created, admin_apikey_revoked, admin_create, admin_delete, admin_login_attempt, admin_old_api_key_attempt, ... (+63 more)
src_endpoint.location.region
- Description: The alphanumeric code that identifies the principal subdivision (e.g. province or state) of the country. For example, 'CH-VD' for the Canton of Vaud, Switzerland
- Source:
geoip.region_code,location.Subdivisions.IsoCode - Usage: 70 events: admin_access_granted, admin_access_revoked, admin_apikey_created, admin_apikey_revoked, admin_create, admin_delete, admin_login_attempt, admin_old_api_key_attempt, ... (+62 more)
Http Request
http_request.user_agent
- Description: The request header that identifies the operating system and web browser.
- Source:
user_agent,useragent.device - Usage: 62 events: admin_access_granted, admin_access_revoked, admin_apikey_expired, admin_apikey_expiring_soon, admin_delete, admin_password_set, admin_role_granted, admin_role_revoked, ... (+54 more)
Observables
observables[].name
- Description: The full name of the observable attribute. The
nameis a pointer/reference to an attribute within the OCSF event data. For example:file.name. Array attributes may be represented in one of three ways. For example:resources.uid,resources[].uid,resources[0].uid. - Literal:
actor.user.email_addr,actor.user.name,actor.user.uid,device.uid,email.to,email.uid,http_request.user_agent,resources.uid,src_endpoint.ip,src_endpoint.location.country,user.email_addr,user.name,user.uid - Usage: 90 events (missing: user_create_provision, user_delete_provision, user_deprovision, user_import_completed, user_import_error...)
observables[].type_id
- Description: The observable value type identifier.
- Literal:
10,14,16,2,31,4,41,47,5 - Usage: 90 events (missing: user_create_provision, user_delete_provision, user_deprovision, user_import_completed, user_import_error...)
observables[].value
- Description: The value associated with the observable attribute. The meaning of the value depends on the observable type.
If thenamerefers to a scalar attribute, then thevalueis the value of the attribute.
If thenamerefers to an object attribute, then thevalueis not populated. - Source:
auth_mfa_context.jumpcloud_protect_device.id,auth_mfa_context.jumpcloud_protect_device.user_id,auth_mfa_context.jumpcloud_protect_device.username,changes.to.user.display_name,changes.to.user.id,changes.to.user.name,client_ip,geoip.country_code,initiated_by.email,initiated_by.id,initiated_by.name,initiated_by.username,location.Country.IsoCode,resource.email,resource.id,resource.recipient_email,resource.userId,resource.user_id,resource.username,user_agent,useragent.device,verification_context.jumpcloud_protect_device.id,verification_context.jumpcloud_protect_device.user_id,verification_context.jumpcloud_protect_device.username - Usage: 90 events (missing: user_create_provision, user_delete_provision, user_deprovision, user_import_completed, user_import_error...)
Resources
resources.uid
- Description: The unique identifier of the resource.
- Source:
resource.id - Usage: user_update_provision_manager
Other
api.request.uid
- Description: The unique request identifier.
- Source:
client_id - Usage: user_update_provision_manager
api.response.code
- Description: The numeric response sent to a request.
- Source:
message_chain.response_code - Transform:
message_chain.response_code→int(user_lookup_provision)- Usage: user_lookup_provision
api.service.name
- Description: The name of the service.
- Source:
application.name - Usage: user_lookup_provision, user_update_provision_manager
app.name
- Description: The name of the product.
- Source:
application.name - Usage: user_create_provision, user_delete_provision, user_deprovision
app.uid
- Description: The unique identifier of the product.
- Source:
application.id - Usage: user_create_provision, user_deprovision
auth_factors.factor_type
- Description: The type of authentication factor used in an authentication attempt.
- Source:
resource.metadata.credentialType - Usage: webauthncredential_delete, webauthncredential_finishregistration, webauthncredential_update
direction_id
- Description:
The direction of the email relative to the scanning host or organization.
Email scanned at an internet gateway might be characterized as inbound to the organization from the Internet, outbound from the organization to the Internet, or internal within the organization. Email scanned at a workstation might be characterized as inbound to, or outbound from the workstation. - Usage: user_activation_email, user_password_reset_email, user_password_warning_email
email.to
- Description: The machine-readable email header To values, as defined by RFC 5322. For example
example.user@usersdomain.com - Source:
resource.recipient_email - Usage: user_password_reset_email
email.uid
- Description: The unique identifier of the email thread.
- Source:
resource.id - Usage: user_password_reset_email, user_password_warning_email
is_mfa
- Description: Indicates whether Multi Factor Authentication was used during authentication.
- Source:
mfa - Usage: admin_login_attempt, user_login_attempt
job.desc
- Description: The description of the job.
- Source:
resource.type - Usage: user_activation_schedule_create, user_activation_schedule_delete, user_import_completed, user_import_skipped, user_import_started
job.name
- Description: The name of the job.
- Source:
application.name - Usage: user_import_completed, user_import_skipped, user_import_started
status_code
- Description: The event status code, as reported by the event source.
For example, in a Windows Failed Authentication event, this would be the value of 'Failure Code', e.g. 0x18. - Source:
message_chain.response_code - Usage: user_update_password_provision, user_update_provision, user_update_provision_manager
Unmapped
unmapped.@timestamp
- Description: JumpCloud Directory Insights field
@timestamppreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
@timestamp - Usage: 40 events: admin_apikey_created, admin_apikey_expiring_soon, admin_apikey_revoked, admin_create, admin_delete, admin_login_attempt, admin_old_api_key_attempt, admin_password_change, ... (+32 more)
unmapped.@version
- Description: JumpCloud Directory Insights field
@versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
@version - Usage: all events in this service
unmapped.access_request_id
- Description: JumpCloud Directory Insights field
access_request_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
access_request_id - Usage: user_admin_revoked
unmapped.access_type
- Description: JumpCloud Directory Insights field
access_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
access_type - Usage: user_admin_granted, user_admin_revoked
unmapped.api_endpoint
- Description: JumpCloud Directory Insights field
api_endpointpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.name - Usage: admin_old_api_key_attempt
unmapped.app_version
- Description: JumpCloud Directory Insights field
app_versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
auth_mfa_context.jumpcloud_protect_device.app_version,verification_context.jumpcloud_protect_device.app_version - Usage: jumpcloud_protect_device_push_verification, push_mfa_attempt_failed
unmapped.application_id
- Description: JumpCloud Directory Insights field
application_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
application.id - Usage: user_activated, user_import_completed, user_import_error, user_import_skipped, user_import_started, user_import_stopped, user_password_update_provision, user_suspended, user_update, user_update_provision
unmapped.application_name
- Description: JumpCloud Directory Insights field
application_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
application.name - Usage: user_activated, user_import_error, user_import_stopped, user_password_update_provision, user_suspended, user_update, user_update_provision
unmapped.application_type
- Description: JumpCloud Directory Insights field
application_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
application.type - Usage: user_create_provision, user_deprovision, user_password_update_provision
unmapped.asn.error
- Description: JumpCloud Directory Insights field
asn.errorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
asn.error - Usage: admin_access_revoked, minimum_mfa_policy_update
unmapped.asn.ip_address
- Description: JumpCloud Directory Insights field
asn.ip_addresspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
asn.ip_address - Usage: admin_access_revoked, minimum_mfa_policy_update
unmapped.asn.network
- Description: JumpCloud Directory Insights field
asn.networkpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
asn.network - Usage: 36 events: admin_access_revoked, admin_password_set, admin_role_granted, admin_role_revoked, admin_totp_disable, jumpcloud_protect_device_activation, jumpcloud_protect_device_delete, jumpcloud_protect_device_enrollment, ... (+28 more)
unmapped.association_action_source
- Description: JumpCloud Directory Insights field
association_action_sourcepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
association.action_source - Usage: user_update_password_provision
unmapped.association_attributes
- Description: JumpCloud Directory Insights field
association_attributespreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
association.attributes - Usage: user_update_password_provision
unmapped.association_connection_from_name
- Description: JumpCloud Directory Insights field
association_connection_from_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
association.connection.from.name - Usage: user_update_password_provision
unmapped.association_connection_from_object_id
- Description: JumpCloud Directory Insights field
association_connection_from_object_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
association.connection.from.object_id - Usage: user_update_password_provision
unmapped.association_connection_from_type
- Description: JumpCloud Directory Insights field
association_connection_from_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
association.connection.from.type - Usage: user_update_password_provision
unmapped.association_connection_to_name
- Description: JumpCloud Directory Insights field
association_connection_to_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
association.connection.to.name - Usage: user_update_password_provision
unmapped.association_connection_to_object_id
- Description: JumpCloud Directory Insights field
association_connection_to_object_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
association.connection.to.object_id - Usage: user_update_password_provision
unmapped.association_connection_to_type
- Description: JumpCloud Directory Insights field
association_connection_to_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
association.connection.to.type - Usage: user_update_password_provision
unmapped.association_op
- Description: JumpCloud Directory Insights field
association_oppreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
association.op - Usage: user_update_password_provision
unmapped.auth_context_amr
- Description: JumpCloud Directory Insights field
auth_context_amrpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
auth_context.identity_provider.authentication_method_reference - Usage: user_login_attempt
unmapped.auth_context_idp_id
- Description: JumpCloud Directory Insights field
auth_context_idp_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
auth_context.identity_provider.id - Usage: user_login_attempt
unmapped.auth_context_idp_name
- Description: JumpCloud Directory Insights field
auth_context_idp_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
auth_context.identity_provider.name - Usage: user_login_attempt
unmapped.auth_context_idp_success
- Description: JumpCloud Directory Insights field
auth_context_idp_successpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
auth_context.auth_methods.identity_provider.success - Usage: user_login_attempt
unmapped.auth_context_idp_type
- Description: JumpCloud Directory Insights field
auth_context_idp_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
auth_context.identity_provider.type - Usage: user_login_attempt
unmapped.auth_context_idp_user_id
- Description: JumpCloud Directory Insights field
auth_context_idp_user_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
auth_context.identity_provider.user_id - Usage: user_login_attempt
unmapped.auth_context_password_success
- Description: JumpCloud Directory Insights field
auth_context_password_successpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
auth_context.auth_methods.password.success - Usage: user_login_attempt
unmapped.auth_context_policy_action
- Description: JumpCloud Directory Insights field
auth_context_policy_actionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
auth_context.policies_applied.metadata.action - Usage: user_login_attempt
unmapped.auth_context_policy_conditions
- Description: JumpCloud Directory Insights field
auth_context_policy_conditionspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
auth_context.policies_applied.metadata.conditions - Usage: user_login_attempt
unmapped.auth_context_policy_id
- Description: JumpCloud Directory Insights field
auth_context_policy_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
auth_context.policies_applied.id - Usage: user_login_attempt
unmapped.auth_context_policy_name
- Description: JumpCloud Directory Insights field
auth_context_policy_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
auth_context.policies_applied.name - Usage: user_login_attempt
unmapped.auth_context_policy_resource_type
- Description: JumpCloud Directory Insights field
auth_context_policy_resource_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
auth_context.policies_applied.metadata.resource_type - Usage: user_login_attempt
unmapped.auth_context_policy_targets
- Description: JumpCloud Directory Insights field
auth_context_policy_targetspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
auth_context.policies_applied.metadata.targets - Usage: user_login_attempt
unmapped.auth_method
- Description: JumpCloud Directory Insights field
auth_methodpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
auth_method - Usage: 45 events: admin_access_granted, admin_access_revoked, admin_create, admin_delete, admin_old_api_key_attempt, admin_password_change, admin_password_reset_request, admin_role_granted, ... (+37 more)
unmapped.auth_mfa_resource
- Description: JumpCloud Directory Insights field
auth_mfa_resourcepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
auth_mfa_context.resource - Usage: push_mfa_attempt_failed
unmapped.changed_field
- Description: JumpCloud Directory Insights field
changed_fieldpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.field - Usage: 40 events: admin_access_granted, admin_access_revoked, admin_create, admin_delete, admin_password_change, admin_role_granted, admin_role_revoked, admin_update, ... (+32 more)
unmapped.changes
- Description: JumpCloud Directory Insights field
changespreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes - Usage: admin_old_api_key_attempt, admin_password_reset_request, sms_twilio_configuration_delete, user_activation_email, user_password_warning_email, user_transfer_in, user_transfer_out
unmapped.changes.from
- Description: JumpCloud Directory Insights field
changes.frompreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.from - Usage: user_deprovision
unmapped.changes.to.costCenter
- Description: JumpCloud Directory Insights field
changes.to.costCenterpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to.costCenter - Usage: user_create_provision, user_deprovision
unmapped.changes.to.department
- Description: JumpCloud Directory Insights field
changes.to.departmentpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to.department - Usage: user_create_provision, user_deprovision
unmapped.changes.to.description
- Description: JumpCloud Directory Insights field
changes.to.descriptionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to.description - Usage: user_create_provision
unmapped.changes.to.display
- Description: JumpCloud Directory Insights field
changes.to.displaypreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to.display - Usage: user_create_provision
unmapped.changes.to.displayName
- Description: JumpCloud Directory Insights field
changes.to.displayNamepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to.displayName - Usage: user_create_provision
unmapped.changes.to.familyName
- Description: JumpCloud Directory Insights field
changes.to.familyNamepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to.familyName - Usage: user_create_provision
unmapped.changes.to.givenName
- Description: JumpCloud Directory Insights field
changes.to.givenNamepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to.givenName - Usage: user_create_provision
unmapped.changes.to.locality
- Description: JumpCloud Directory Insights field
changes.to.localitypreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to.locality - Usage: user_deprovision
unmapped.changes.to.organization
- Description: JumpCloud Directory Insights field
changes.to.organizationpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to.organization - Usage: user_create_provision, user_deprovision
unmapped.changes.to.region
- Description: JumpCloud Directory Insights field
changes.to.regionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to.region - Usage: user_deprovision
unmapped.changes.to.streetAddress
- Description: JumpCloud Directory Insights field
changes.to.streetAddresspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to.streetAddress - Usage: user_deprovision
unmapped.changes.to.title
- Description: JumpCloud Directory Insights field
changes.to.titlepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to.title - Usage: user_create_provision
unmapped.changes.to.value
- Description: JumpCloud Directory Insights field
changes.to.valuepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to.value - Usage: user_create_provision, user_deprovision
unmapped.changes_from
- Description: JumpCloud Directory Insights field
changes_frompreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.from - Usage: 24 events: admin_access_granted, admin_access_revoked, admin_delete, admin_role_revoked, admin_update, totp_delete_enrollment, totp_finish_enrollment, unified_mfa_totp_delete_enrollment, ... (+16 more)
unmapped.changes_from_from__id
- Description: JumpCloud Directory Insights field
changes_from_from__idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.from._id - Usage: user_update
unmapped.changes_from_from_country
- Description: JumpCloud Directory Insights field
changes_from_from_countrypreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.from.country - Usage: user_update
unmapped.changes_from_from_extendedAddress
- Description: JumpCloud Directory Insights field
changes_from_from_extendedAddresspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.from.extendedAddress - Usage: user_update
unmapped.changes_from_from_field
- Description: JumpCloud Directory Insights field
changes_from_from_fieldpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.from.field - Usage: user_update
unmapped.changes_from_from_id
- Description: JumpCloud Directory Insights field
changes_from_from_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.from.id - Usage: user_update
unmapped.changes_from_from_locality
- Description: JumpCloud Directory Insights field
changes_from_from_localitypreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.from.locality - Usage: user_update
unmapped.changes_from_from_nanos
- Description: JumpCloud Directory Insights field
changes_from_from_nanospreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.from.nanos - Usage: webauthncredential_delete
unmapped.changes_from_from_number
- Description: JumpCloud Directory Insights field
changes_from_from_numberpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.from.number - Usage: user_update
unmapped.changes_from_from_poBox
- Description: JumpCloud Directory Insights field
changes_from_from_poBoxpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.from.poBox - Usage: user_update
unmapped.changes_from_from_postalCode
- Description: JumpCloud Directory Insights field
changes_from_from_postalCodepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.from.postalCode - Usage: user_update
unmapped.changes_from_from_region
- Description: JumpCloud Directory Insights field
changes_from_from_regionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.from.region - Usage: user_update
unmapped.changes_from_from_seconds
- Description: JumpCloud Directory Insights field
changes_from_from_secondspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.from.seconds - Usage: webauthncredential_delete
unmapped.changes_from_from_streetAddress
- Description: JumpCloud Directory Insights field
changes_from_from_streetAddresspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.from.streetAddress - Usage: user_update
unmapped.changes_from_from_type
- Description: JumpCloud Directory Insights field
changes_from_from_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.from.type - Usage: user_update
unmapped.changes_to
- Description: JumpCloud Directory Insights field
changes_topreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to - Usage: 26 events: admin_access_granted, admin_access_revoked, admin_create, admin_role_granted, admin_update, totp_delete_enrollment, totp_finish_enrollment, unified_mfa_totp_delete_enrollment, ... (+18 more)
unmapped.changes_to_country
- Description: JumpCloud Directory Insights field
changes_to_countrypreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to.country - Usage: user_create, user_create_provision, user_deprovision
unmapped.changes_to_employee_number
- Description: JumpCloud Directory Insights field
changes_to_employee_numberpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to.employeeNumber - Usage: user_create_provision, user_deprovision
unmapped.changes_to_extended_address
- Description: JumpCloud Directory Insights field
changes_to_extended_addresspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to.extendedAddress - Usage: user_create
unmapped.changes_to_field
- Description: JumpCloud Directory Insights field
changes_to_fieldpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to.field - Usage: user_create
unmapped.changes_to_id
- Description: JumpCloud Directory Insights field
changes_to_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to.id - Usage: user_create
unmapped.changes_to_locality
- Description: JumpCloud Directory Insights field
changes_to_localitypreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to.locality - Usage: user_create
unmapped.changes_to_manager_id
- Description: JumpCloud Directory Insights field
changes_to_manager_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to.manager.managerId - Usage: user_create_provision
unmapped.changes_to_name
- Description: JumpCloud Directory Insights field
changes_to_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to.name - Usage: user_create
unmapped.changes_to_number
- Description: JumpCloud Directory Insights field
changes_to_numberpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to.number - Usage: user_create
unmapped.changes_to_po_box
- Description: JumpCloud Directory Insights field
changes_to_po_boxpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to.poBox - Usage: user_create
unmapped.changes_to_postal_code
- Description: JumpCloud Directory Insights field
changes_to_postal_codepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to.postalCode - Usage: user_create
unmapped.changes_to_primary
- Description: JumpCloud Directory Insights field
changes_to_primarypreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to.primary - Usage: user_create_provision, user_deprovision
unmapped.changes_to_region
- Description: JumpCloud Directory Insights field
changes_to_regionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to.region - Usage: user_create
unmapped.changes_to_street_address
- Description: JumpCloud Directory Insights field
changes_to_street_addresspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to.streetAddress - Usage: user_create
unmapped.changes_to_to__id
- Description: JumpCloud Directory Insights field
changes_to_to__idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to._id - Usage: user_update
unmapped.changes_to_to_attestation
- Description: JumpCloud Directory Insights field
changes_to_to_attestationpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to.attestation - Usage: webauthncredential_beginregistration
unmapped.changes_to_to_authenticatorSelection_authenticator_attachment
- Description: JumpCloud Directory Insights field
changes_to_to_authenticatorSelection_authenticator_attachmentpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to.authenticatorSelection.authenticator_attachment - Usage: webauthncredential_beginregistration
unmapped.changes_to_to_authenticatorSelection_user_verification
- Description: JumpCloud Directory Insights field
changes_to_to_authenticatorSelection_user_verificationpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to.authenticatorSelection.user_verification - Usage: webauthncredential_beginregistration
unmapped.changes_to_to_challenge
- Description: JumpCloud Directory Insights field
changes_to_to_challengepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to.challenge - Usage: webauthncredential_beginregistration
unmapped.changes_to_to_country
- Description: JumpCloud Directory Insights field
changes_to_to_countrypreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to.country - Usage: user_update
unmapped.changes_to_to_extendedAddress
- Description: JumpCloud Directory Insights field
changes_to_to_extendedAddresspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to.extendedAddress - Usage: user_update
unmapped.changes_to_to_field
- Description: JumpCloud Directory Insights field
changes_to_to_fieldpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to.field - Usage: user_update
unmapped.changes_to_to_id
- Description: JumpCloud Directory Insights field
changes_to_to_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to.id - Usage: user_update
unmapped.changes_to_to_locality
- Description: JumpCloud Directory Insights field
changes_to_to_localitypreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to.locality - Usage: user_update
unmapped.changes_to_to_nanos
- Description: JumpCloud Directory Insights field
changes_to_to_nanospreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to.nanos - Usage: webauthncredential_finishregistration
unmapped.changes_to_to_number
- Description: JumpCloud Directory Insights field
changes_to_to_numberpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to.number - Usage: user_update
unmapped.changes_to_to_poBox
- Description: JumpCloud Directory Insights field
changes_to_to_poBoxpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to.poBox - Usage: user_update
unmapped.changes_to_to_postalCode
- Description: JumpCloud Directory Insights field
changes_to_to_postalCodepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to.postalCode - Usage: user_update
unmapped.changes_to_to_pubKeyCredParams_alg
- Description: JumpCloud Directory Insights field
changes_to_to_pubKeyCredParams_algpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to.pubKeyCredParams.alg - Usage: webauthncredential_beginregistration
unmapped.changes_to_to_pubKeyCredParams_type
- Description: JumpCloud Directory Insights field
changes_to_to_pubKeyCredParams_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to.pubKeyCredParams.type - Usage: webauthncredential_beginregistration
unmapped.changes_to_to_region
- Description: JumpCloud Directory Insights field
changes_to_to_regionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to.region - Usage: user_update
unmapped.changes_to_to_rp_id
- Description: JumpCloud Directory Insights field
changes_to_to_rp_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to.rp.id - Usage: webauthncredential_beginregistration
unmapped.changes_to_to_rp_name
- Description: JumpCloud Directory Insights field
changes_to_to_rp_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to.rp.name - Usage: webauthncredential_beginregistration
unmapped.changes_to_to_seconds
- Description: JumpCloud Directory Insights field
changes_to_to_secondspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to.seconds - Usage: webauthncredential_finishregistration
unmapped.changes_to_to_streetAddress
- Description: JumpCloud Directory Insights field
changes_to_to_streetAddresspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to.streetAddress - Usage: user_update
unmapped.changes_to_to_timout
- Description: JumpCloud Directory Insights field
changes_to_to_timoutpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to.timout - Usage: webauthncredential_beginregistration
unmapped.changes_to_to_type
- Description: JumpCloud Directory Insights field
changes_to_to_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to.type - Usage: user_update
unmapped.changes_to_type
- Description: JumpCloud Directory Insights field
changes_to_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to.type - Usage: user_create, user_create_provision, user_deprovision
unmapped.changes_to_value
- Description: JumpCloud Directory Insights field
changes_to_valuepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to.value - Usage: user_create
unmapped.client_id
- Description: JumpCloud Directory Insights field
client_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
client_id - Usage: user_create_provision, user_delete_provision, user_deprovision, user_import_completed, user_import_error, user_import_skipped, user_import_started, user_import_stopped, user_lookup_provision, user_password_update_provision
unmapped.client_ip
- Description: JumpCloud Directory Insights field
client_ippreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
client_ip - Usage: user_activation_schedule_create, user_activation_schedule_delete, user_create_provision, user_delete_provision, user_deprovision, user_import_error, user_import_skipped
unmapped.correlation
- Description: JumpCloud Directory Insights field
correlationpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
correlation - Usage: 12 events: user_activated, user_create_provision, user_deactivated, user_delegated_authority_update, user_delete_provision, user_deprovision, user_transfer_in, user_transfer_out, ... (+4 more)
unmapped.correlation_id
- Description: JumpCloud Directory Insights field
correlation_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
correlation.id - Usage: user_import_completed, user_import_error, user_import_skipped, user_import_started, user_import_stopped
unmapped.correlation_type
- Description: JumpCloud Directory Insights field
correlation_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
correlation.type - Usage: user_import_completed, user_import_error, user_import_skipped, user_import_started, user_import_stopped
unmapped.credential_id
- Description: JumpCloud Directory Insights field
credential_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.id - Usage: webauthncredential_delete, webauthncredential_finishregistration, webauthncredential_update
unmapped.email_type
- Description: JumpCloud Directory Insights field
email_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.email_type - Usage: user_activation_email, user_password_reset_email
unmapped.expiry
- Description: JumpCloud Directory Insights field
expirypreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
expiry - Usage: user_admin_granted, user_admin_revoked
unmapped.file_input_timestamp
- Description: JumpCloud Directory Insights field
file_input_timestamppreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
file_input_timestamp - Usage: 40 events: admin_apikey_created, admin_apikey_expiring_soon, admin_apikey_revoked, admin_create, admin_delete, admin_login_attempt, admin_old_api_key_attempt, admin_password_change, ... (+32 more)
unmapped.g_suite_name
- Description: JumpCloud Directory Insights field
g_suite_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
g_suite.name - Usage: user_admin_grant, user_admin_revoke
unmapped.g_suite_type
- Description: JumpCloud Directory Insights field
g_suite_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
g_suite.type - Usage: user_admin_grant, user_admin_revoke
unmapped.geoip.city
- Description: JumpCloud Directory Insights field
geoip.citypreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.city - Usage: user_activation_schedule_create, user_activation_schedule_delete
unmapped.geoip.continent_code
- Description: JumpCloud Directory Insights field
geoip.continent_codepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.continent_code - Usage: user_activation_schedule_create, user_activation_schedule_delete
unmapped.geoip.country_code
- Description: JumpCloud Directory Insights field
geoip.country_codepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.country_code - Usage: user_activation_schedule_create, user_activation_schedule_delete
unmapped.geoip.latitude
- Description: JumpCloud Directory Insights field
geoip.latitudepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.latitude - Usage: user_activation_schedule_create, user_activation_schedule_delete
unmapped.geoip.longitude
- Description: JumpCloud Directory Insights field
geoip.longitudepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.longitude - Usage: user_activation_schedule_create, user_activation_schedule_delete
unmapped.geoip.region_code
- Description: JumpCloud Directory Insights field
geoip.region_codepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.region_code - Usage: user_activation_schedule_create, user_activation_schedule_delete
unmapped.geoip.region_name
- Description: JumpCloud Directory Insights field
geoip.region_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.region_name - Usage: 72 events: admin_access_granted, admin_access_revoked, admin_apikey_created, admin_apikey_revoked, admin_create, admin_delete, admin_login_attempt, admin_old_api_key_attempt, ... (+64 more)
unmapped.geoip.timezone
- Description: JumpCloud Directory Insights field
geoip.timezonepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.timezone - Usage: 73 events: admin_access_granted, admin_access_revoked, admin_apikey_created, admin_apikey_revoked, admin_create, admin_delete, admin_login_attempt, admin_old_api_key_attempt, ... (+65 more)
unmapped.host
- Description: JumpCloud Directory Insights field
hostpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
host - Usage: user_update_provision
unmapped.idm_client_id
- Description: JumpCloud Directory Insights field
idm_client_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
idm_client_id - Usage: user_update_provision
unmapped.idm_client_id_hash
- Description: JumpCloud Directory Insights field
idm_client_id_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
idm_client_id_hash - Usage: user_update_provision
unmapped.initiated_by
- Description: JumpCloud Directory Insights field
initiated_bypreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by - Usage: push_mfa_attempt_failed, totp_delete_enrollment, totp_finish_enrollment, totp_start_enrollment, unified_mfa_totp_delete_enrollment, unified_mfa_totp_enrollment, unified_mfa_user_update, user_delete_provision, user_update_provision_manager
unmapped.initiated_by.provider
- Description: JumpCloud Directory Insights field
initiated_by.providerpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by.provider - Usage: admin_delete, sms_configuration_update, sms_twilio_configuration_create, sms_twilio_configuration_delete, sms_twilio_configuration_update, sms_twilio_excluded_user_groups_update, user_activation_email, user_delegated_authority_update
unmapped.initiated_by.source
- Description: JumpCloud Directory Insights field
initiated_by.sourcepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by.source - Usage: user_activation_email
unmapped.initiated_by.source_metadata.applicationID
- Description: JumpCloud Directory Insights field
initiated_by.source_metadata.applicationIDpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by.source_metadata.applicationID - Usage: user_import_skipped
unmapped.initiated_by.source_metadata.sourceName
- Description: JumpCloud Directory Insights field
initiated_by.source_metadata.sourceNamepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by.source_metadata.sourceName - Usage: user_create_provision, user_deprovision
unmapped.initiated_by.user_id
- Description: JumpCloud Directory Insights field
initiated_by.user_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by.user_id - Usage: sms_configuration_update
unmapped.initiated_by_administrator
- Description: JumpCloud Directory Insights field
initiated_by_administratorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by.administrator - Usage: user_login_attempt
unmapped.initiated_by_application_id
- Description: JumpCloud Directory Insights field
initiated_by_application_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by.source_metadata.applicationID - Usage: user_suspended, user_update, user_update_password_provision
unmapped.initiated_by_email_hash
- Description: JumpCloud Directory Insights field
initiated_by_email_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_email_hash - Usage: 56 events: admin_access_granted, admin_access_revoked, admin_delete, admin_old_api_key_attempt, admin_password_change, admin_password_reset_request, admin_password_set, admin_role_granted, ... (+48 more)
unmapped.initiated_by_id
- Description: JumpCloud Directory Insights field
initiated_by_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by.id - Usage: unified_mfa_user_update
unmapped.initiated_by_id_hash
- Description: JumpCloud Directory Insights field
initiated_by_id_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_id_hash - Usage: 66 events: admin_access_granted, admin_access_revoked, admin_delete, admin_old_api_key_attempt, admin_password_change, admin_password_reset_request, admin_password_set, admin_role_granted, ... (+58 more)
unmapped.initiated_by_name
- Description: JumpCloud Directory Insights field
initiated_by_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by.name - Usage: user_create_provision, user_deprovision
unmapped.initiated_by_name_hash
- Description: JumpCloud Directory Insights field
initiated_by_name_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_name_hash - Usage: user_create_provision, user_deprovision, user_password_update_provision, user_update_provision
unmapped.initiated_by_provider
- Description: JumpCloud Directory Insights field
initiated_by_providerpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by.provider - Usage: 14 events: admin_access_granted, admin_access_revoked, admin_apikey_created, admin_apikey_expired, admin_apikey_expiring_soon, admin_apikey_revoked, admin_old_api_key_attempt, admin_role_granted, ... (+6 more)
unmapped.initiated_by_source
- Description: JumpCloud Directory Insights field
initiated_by_sourcepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by.source - Usage: 14 events: user_activated, user_create_provision, user_deactivated, user_deprovision, user_import_completed, user_import_error, user_import_skipped, user_import_started, ... (+6 more)
unmapped.initiated_by_source_application_id
- Description: JumpCloud Directory Insights field
initiated_by_source_application_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by.source_metadata.applicationID - Usage: user_activated
unmapped.initiated_by_source_metadata_name
- Description: JumpCloud Directory Insights field
initiated_by_source_metadata_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by.source_metadata.name - Usage: user_unlocked
unmapped.initiated_by_source_name
- Description: JumpCloud Directory Insights field
initiated_by_source_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by.source_metadata.name,initiated_by.source_metadata.sourceName - Usage: 12 events: user_activated, user_deactivated, user_import_completed, user_import_error, user_import_skipped, user_import_started, user_import_stopped, user_password_update_provision, ... (+4 more)
unmapped.initiated_by_type
- Description: JumpCloud Directory Insights field
initiated_by_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by.type - Usage: user_create_provision, user_deprovision, user_import_error, user_import_stopped
unmapped.initiated_by_user_id
- Description: JumpCloud Directory Insights field
initiated_by_user_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by.user_id - Usage: admin_password_set, push_configuration_update
unmapped.initiated_by_username_hash
- Description: JumpCloud Directory Insights field
initiated_by_username_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_username_hash - Usage: 18 events: jumpcloud_protect_device_activation, jumpcloud_protect_device_delete, jumpcloud_protect_device_enrollment, jumpcloud_protect_device_update, minimum_mfa_compliance_state_changed, sms_otp_delete_enrollment, sms_otp_finish_enrollment, sms_otp_start_enrollment, ... (+10 more)
unmapped.is_out_of_bound
- Description: JumpCloud Directory Insights field
is_out_of_boundpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
is_out_of_bound - Usage: 62 events: admin_access_granted, admin_access_revoked, admin_apikey_expired, admin_apikey_expiring_soon, admin_delete, admin_password_set, admin_role_granted, admin_role_revoked, ... (+54 more)
unmapped.jc_application_name
- Description: JumpCloud Directory Insights field
jc_application_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_application_name - Usage: 62 events: admin_access_granted, admin_access_revoked, admin_apikey_expired, admin_apikey_expiring_soon, admin_delete, admin_password_set, admin_role_granted, admin_role_revoked, ... (+54 more)
unmapped.jc_index_name
- Description: JumpCloud Directory Insights field
jc_index_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_index_name - Usage: jumpcloud_protect_device_delete, totp_finish_enrollment, totp_start_enrollment
unmapped.jc_initiated_by_email
- Description: JumpCloud Directory Insights field
jc_initiated_by_emailpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_initiated_by_email - Usage: 17 events: admin_apikey_expired, admin_password_set, admin_totp_disable, jumpcloud_protect_device_activation, jumpcloud_protect_device_delete, jumpcloud_protect_device_enrollment, push_mfa_attempt_failed, sms_configuration_update, ... (+9 more)
unmapped.jc_initiated_by_username
- Description: JumpCloud Directory Insights field
jc_initiated_by_usernamepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_initiated_by_username - Usage: 17 events: admin_apikey_expired, admin_password_set, admin_totp_disable, jumpcloud_protect_device_activation, jumpcloud_protect_device_delete, jumpcloud_protect_device_enrollment, push_mfa_attempt_failed, sms_configuration_update, ... (+9 more)
unmapped.jc_organization_id
- Description: JumpCloud Directory Insights field
jc_organization_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_organization_id - Usage: jumpcloud_protect_device_delete, totp_finish_enrollment, totp_start_enrollment
unmapped.jc_organization_name
- Description: JumpCloud Directory Insights field
jc_organization_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_organization_name - Usage: 17 events: admin_apikey_expired, admin_password_set, admin_totp_disable, jumpcloud_protect_device_activation, jumpcloud_protect_device_delete, jumpcloud_protect_device_enrollment, push_mfa_attempt_failed, sms_configuration_update, ... (+9 more)
unmapped.jc_provider_id
- Description: JumpCloud Directory Insights field
jc_provider_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_provider_id - Usage: 14 events: admin_apikey_expired, admin_password_set, jumpcloud_protect_device_delete, jumpcloud_protect_device_enrollment, push_mfa_attempt_failed, sms_configuration_update, sms_otp_finish_enrollment, sms_otp_start_enrollment, ... (+6 more)
unmapped.ldap_server_name
- Description: JumpCloud Directory Insights field
ldap_server_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
ldap_server.name - Usage: user_admin_grant, user_admin_revoke
unmapped.ldap_server_type
- Description: JumpCloud Directory Insights field
ldap_server_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
ldap_server.type - Usage: user_admin_grant, user_admin_revoke
unmapped.location.Country.Name
- Description: JumpCloud Directory Insights field
location.Country.Namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
location.Country.Name - Usage: user_admin_granted, user_admin_revoked
unmapped.location.Subdivisions.Name
- Description: JumpCloud Directory Insights field
location.Subdivisions.Namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
location.Subdivisions.Name - Usage: user_admin_granted, user_admin_revoked
unmapped.message_chain
- Description: JumpCloud Directory Insights field
message_chainpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
message_chain - Usage: user_activated, user_deactivated, user_delegated_authority_update, user_transfer_in, user_unlocked
unmapped.message_chain_message_details
- Description: JumpCloud Directory Insights field
message_chain_message_detailspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
message_chain.message_details - Usage: user_create_provision, user_delete_provision, user_deprovision, user_import_completed, user_import_error, user_import_skipped, user_import_started, user_import_stopped
unmapped.message_chain_response_code
- Description: JumpCloud Directory Insights field
message_chain_response_codepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
message_chain.response_code - Usage: user_create_provision, user_delete_provision, user_deprovision, user_import_completed, user_import_error, user_import_skipped, user_import_started, user_import_stopped
unmapped.message_details
- Description: JumpCloud Directory Insights field
message_detailspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
message_chain.message_details - Usage: user_lookup_provision, user_password_update_provision
unmapped.msp_provider_id
- Description: JumpCloud Directory Insights field
msp_provider_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
provider - Usage: 33 events: admin_access_granted, admin_access_revoked, admin_apikey_created, admin_apikey_expired, admin_apikey_expiring_soon, admin_apikey_revoked, admin_role_granted, admin_role_revoked, ... (+25 more)
unmapped.office_365_name
- Description: JumpCloud Directory Insights field
office_365_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
office_365.name - Usage: user_admin_grant
unmapped.office_365_type
- Description: JumpCloud Directory Insights field
office_365_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
office_365.type - Usage: user_admin_grant, user_admin_revoke
unmapped.pid
- Description: JumpCloud Directory Insights field
pidpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
pid - Usage: user_admin_granted, user_admin_revoked
unmapped.provider
- Description: JumpCloud Directory Insights field
providerpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
provider - Usage: 35 events: admin_create, admin_delete, admin_login_attempt, admin_old_api_key_attempt, admin_password_change, admin_password_reset_request, admin_password_set, admin_totp_finish_enrollment, ... (+27 more)
unmapped.provider_id
- Description: JumpCloud Directory Insights field
provider_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.providerId - Usage: admin_role_granted, admin_role_revoked
unmapped.push_status
- Description: JumpCloud Directory Insights field
push_statuspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
push_status.status - Usage: jumpcloud_protect_device_push_verification
unmapped.recipient_email
- Description: JumpCloud Directory Insights field
recipient_emailpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.recipient_email - Usage: user_activation_email
unmapped.resource_id
- Description: JumpCloud Directory Insights field
resource_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.id - Usage: 13 events: unified_mfa_update, user_activation_email, user_activation_schedule_create, user_activation_schedule_delete, user_create_provision, user_delete_provision, user_deprovision, user_import_completed, ... (+5 more)
unmapped.resource_id_hash
- Description: JumpCloud Directory Insights field
resource_id_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource_id_hash - Usage: 64 events: admin_access_granted, admin_access_revoked, admin_delete, admin_password_change, admin_password_reset_request, admin_password_set, admin_totp_disable, admin_totp_finish_enrollment, ... (+56 more)
unmapped.resource_name
- Description: JumpCloud Directory Insights field
resource_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.name - Usage: user_admin_grant, user_admin_revoke
unmapped.resource_type
- Description: JumpCloud Directory Insights field
resource_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.type - Usage: 17 events: admin_old_api_key_attempt, admin_role_granted, admin_role_revoked, user_activation_email, user_create_provision, user_delete_provision, user_deprovision, user_import_error, ... (+9 more)
unmapped.resource_username
- Description: JumpCloud Directory Insights field
resource_usernamepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.username - Usage: 14 events: unified_mfa_update, user_activation_email, user_create_provision, user_delete_provision, user_deprovision, user_import_completed, user_import_error, user_import_skipped, ... (+6 more)
unmapped.resource_username_hash
- Description: JumpCloud Directory Insights field
resource_username_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource_username_hash - Usage: 29 events: totp_delete_enrollment, totp_finish_enrollment, totp_start_enrollment, unified_mfa_totp_delete_enrollment, unified_mfa_totp_enrollment, unified_mfa_user_update, user_activation_email, user_admin_grant, ... (+21 more)
unmapped.response_code
- Description: JumpCloud Directory Insights field
response_codepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
message_chain.response_code - Usage: user_password_update_provision
unmapped.role_id
- Description: JumpCloud Directory Insights field
role_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.roleId - Usage: admin_role_granted, admin_role_revoked
unmapped.system_display_name
- Description: JumpCloud Directory Insights field
system_display_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
system.displayName - Usage: user_admin_granted, user_admin_revoked
unmapped.system_group_id
- Description: JumpCloud Directory Insights field
system_group_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
system_group.id - Usage: user_admin_grant
unmapped.system_group_name
- Description: JumpCloud Directory Insights field
system_group_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
system_group.name - Usage: user_admin_grant
unmapped.system_group_type
- Description: JumpCloud Directory Insights field
system_group_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
system_group.type - Usage: user_admin_grant
unmapped.system_hostname
- Description: JumpCloud Directory Insights field
system_hostnamepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
system.hostname - Usage: user_admin_granted, user_admin_revoked
unmapped.system_id
- Description: JumpCloud Directory Insights field
system_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
system.id - Usage: user_admin_granted, user_admin_revoked
unmapped.system_type
- Description: JumpCloud Directory Insights field
system_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
system.type - Usage: user_admin_granted, user_admin_revoked
unmapped.tags
- Description: JumpCloud Directory Insights field
tagspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
tags - Usage: 40 events: admin_apikey_created, admin_apikey_expiring_soon, admin_apikey_revoked, admin_create, admin_delete, admin_login_attempt, admin_old_api_key_attempt, admin_password_change, ... (+32 more)
unmapped.target_resource_type
- Description: JumpCloud Directory Insights field
target_resource_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
target_resource.type - Usage: admin_login_attempt, user_login_attempt
unmapped.timestamp_source
- Description: JumpCloud Directory Insights field
timestamp_sourcepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
timestamp_source - Usage: 44 events: feature_settings_change, jumpcloud_protect_device_activation, jumpcloud_protect_device_delete, jumpcloud_protect_device_enrollment, jumpcloud_protect_device_push_verification, jumpcloud_protect_device_update, minimum_mfa_compliance_state_changed, minimum_mfa_policy_create, ... (+36 more)
unmapped.type
- Description: JumpCloud Directory Insights field
typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
type - Usage: user_update_provision
unmapped.user_action
- Description: JumpCloud Directory Insights field
user_actionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
user_action.action - Usage: jumpcloud_protect_device_push_verification
unmapped.user_agent
- Description: JumpCloud Directory Insights field
user_agentpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
user_agent - Usage: user_activation_email, user_create_provision, user_delete_provision, user_deprovision, user_import_error, user_import_skipped, user_password_warning_email
unmapped.useragent.build
- Description: JumpCloud Directory Insights field
useragent.buildpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.build - Usage: jumpcloud_protect_device_delete, totp_finish_enrollment, totp_start_enrollment
unmapped.useragent.device
- Description: JumpCloud Directory Insights field
useragent.devicepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.device - Usage: 64 events: admin_access_granted, admin_access_revoked, admin_apikey_created, admin_apikey_revoked, admin_create, admin_delete, admin_login_attempt, admin_old_api_key_attempt, ... (+56 more)
unmapped.useragent.major
- Description: JumpCloud Directory Insights field
useragent.majorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.major - Usage: 72 events: admin_access_granted, admin_access_revoked, admin_apikey_created, admin_apikey_revoked, admin_create, admin_delete, admin_login_attempt, admin_old_api_key_attempt, ... (+64 more)
unmapped.useragent.minor
- Description: JumpCloud Directory Insights field
useragent.minorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.minor - Usage: 72 events: admin_access_granted, admin_access_revoked, admin_apikey_created, admin_apikey_revoked, admin_create, admin_delete, admin_login_attempt, admin_old_api_key_attempt, ... (+64 more)
unmapped.useragent.name
- Description: JumpCloud Directory Insights field
useragent.namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.name - Usage: 77 events: admin_access_granted, admin_access_revoked, admin_apikey_created, admin_apikey_revoked, admin_create, admin_delete, admin_login_attempt, admin_old_api_key_attempt, ... (+69 more)
unmapped.useragent.os
- Description: JumpCloud Directory Insights field
useragent.ospreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os - Usage: 77 events: admin_access_granted, admin_access_revoked, admin_apikey_created, admin_apikey_revoked, admin_create, admin_delete, admin_login_attempt, admin_old_api_key_attempt, ... (+69 more)
unmapped.useragent.os_full
- Description: JumpCloud Directory Insights field
useragent.os_fullpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_full - Usage: 77 events: admin_access_granted, admin_access_revoked, admin_apikey_created, admin_apikey_revoked, admin_create, admin_delete, admin_login_attempt, admin_old_api_key_attempt, ... (+69 more)
unmapped.useragent.os_major
- Description: JumpCloud Directory Insights field
useragent.os_majorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_major - Usage: 56 events: admin_access_granted, admin_access_revoked, admin_delete, admin_login_attempt, admin_password_change, admin_password_reset_request, admin_role_granted, admin_role_revoked, ... (+48 more)
unmapped.useragent.os_minor
- Description: JumpCloud Directory Insights field
useragent.os_minorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_minor - Usage: 56 events: admin_access_granted, admin_access_revoked, admin_delete, admin_login_attempt, admin_password_change, admin_password_reset_request, admin_role_granted, admin_role_revoked, ... (+48 more)
unmapped.useragent.os_name
- Description: JumpCloud Directory Insights field
useragent.os_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_name - Usage: 77 events: admin_access_granted, admin_access_revoked, admin_apikey_created, admin_apikey_revoked, admin_create, admin_delete, admin_login_attempt, admin_old_api_key_attempt, ... (+69 more)
unmapped.useragent.os_patch
- Description: JumpCloud Directory Insights field
useragent.os_patchpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_patch - Usage: 55 events: admin_access_granted, admin_access_revoked, admin_delete, admin_login_attempt, admin_password_change, admin_password_reset_request, admin_role_granted, admin_role_revoked, ... (+47 more)
unmapped.useragent.os_version
- Description: JumpCloud Directory Insights field
useragent.os_versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_version - Usage: 56 events: admin_access_granted, admin_access_revoked, admin_delete, admin_login_attempt, admin_password_change, admin_password_reset_request, admin_role_granted, admin_role_revoked, ... (+48 more)
unmapped.useragent.patch
- Description: JumpCloud Directory Insights field
useragent.patchpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.patch - Usage: 60 events: admin_access_granted, admin_access_revoked, admin_apikey_created, admin_apikey_revoked, admin_delete, admin_login_attempt, admin_password_change, admin_password_reset_request, ... (+52 more)
unmapped.useragent.version
- Description: JumpCloud Directory Insights field
useragent.versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.version - Usage: 72 events: admin_access_granted, admin_access_revoked, admin_apikey_created, admin_apikey_revoked, admin_create, admin_delete, admin_login_attempt, admin_old_api_key_attempt, ... (+64 more)
unmapped.verification_device_ip
- Description: JumpCloud Directory Insights field
verification_device_ippreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
verification_context.device_ip_address - Usage: jumpcloud_protect_device_push_verification
unmapped.workflow
- Description: JumpCloud Directory Insights field
workflowpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
workflow - Usage: user_admin_revoked
unmapped.workflow_desc
- Description: JumpCloud Directory Insights field
workflow_descpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
workflow.desc - Usage: user_update_provision
unmapped.workflow_id
- Description: JumpCloud Directory Insights field
workflow_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
workflow.id - Usage: user_update_provision
unmapped.workflow_name
- Description: JumpCloud Directory Insights field
workflow_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
workflow.name - Usage: user_update_provision
unmapped.workflow_type
- Description: JumpCloud Directory Insights field
workflow_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
workflow.type - Usage: user_update_provision
GenAI#
genai · 12 events
| Event | Category | Class | Activity | Type UID | Fields |
|---|---|---|---|---|---|
genai_ai_assistant_chat_created |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 64 |
genai_ai_assistant_chat_deleted |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 67 |
genai_ai_assistant_chat_message_sent |
Identity & Access Management (3) | Entity Management (3004) | Read (2) | 300402 | 83 |
genai_ai_assistant_chat_updated |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 71 |
genai_ai_assistant_memory_deleted |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 69 |
genai_ai_assistant_org_rule_created |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 70 |
genai_ai_assistant_org_rule_deleted |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 68 |
genai_ai_assistant_org_rule_updated |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 64 |
genai_ai_assistant_org_settings_updated |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 68 |
genai_ai_search_executed |
Identity & Access Management (3) | Entity Management (3004) | Read (2) | 300402 | 67 |
genai_mcp_manual_revoked |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 74 |
genai_mcp_session_created |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 73 |
OCSF field mappings#
Legend
- Description: what the OCSF field represents (from OCSF schema v1.8.0)
- Source: raw JumpCloud event field(s) mapped via
${{placeholder}}template - Transform:
fieldMappingsentry applied at runtime (cast, enum, etc.) - Literal: static value set in the mapping template
- Usage: event types in this service that include this field
Core
activity_id
- Description: The normalized identifier of the activity that triggered the event.
- Literal:
1,2,3,4 - Usage: all events in this service
activity_name
- Description: The event activity name, as defined by the activity_id.
- Literal:
Create,Delete,Read,Update - Usage: all events in this service
category_name
- Description: The event category name, as defined by category_uid value:
Discovery. - Literal:
Identity & Access Management - Usage: all events in this service
category_uid
- Description: The category unique identifier of the event.
- Literal:
3 - Usage: all events in this service
class_name
- Description: The event class name, as defined by class_uid value:
User Inventory Info. - Literal:
Entity Management - Usage: all events in this service
class_uid
- Description: The unique identifier of a class. A class describes the attributes available in an event.
- Literal:
3004 - Usage: all events in this service
severity_id
- Description: OCSF severity identifier for the event.
- Literal:
1 - Usage: all events in this service
status_detail
- Description: The status detail contains additional information about the event/finding outcome.
- Source:
error_message - Usage: all events in this service
status_id
- Description: Normalized status of the activity (1=Success, 2=Failure).
- Source:
success - Transform:
success→boolean_to_status_id; true→1, false→2 (all events in this service)- Usage: all events in this service
time
- Description: Event time, in epoch milliseconds (OCSF
time). - Source:
timestamp - Transform:
timestamp→iso8601_to_epoch_millis(all events in this service)- Usage: all events in this service
type_uid
- Description: The event/finding type ID. It identifies the event's semantics and structure. The value is calculated by the logging system as:
class_uid * 100 + activity_id. - Literal:
300401,300402,300403,300404 - Usage: all events in this service
Metadata
metadata.event_code
- Description: JumpCloud event type code.
- Source:
event_type - Usage: all events in this service
metadata.processed_time
- Description: The event processed time, such as an ETL operation.
- Source:
jc_transformation_ts - Usage: all events in this service
metadata.product.name
- Description: Originating JumpCloud service that produced the event.
- Source:
service - Usage: all events in this service
metadata.tenant_uid
- Description: JumpCloud organization (tenant) identifier.
- Source:
organization - Usage: all events in this service
metadata.uid
- Description: Unique event identifier assigned by JumpCloud.
- Source:
id - Usage: all events in this service
metadata.version
- Description: OCSF schema version used for this event.
- Literal:
1.8.0 - Usage: all events in this service
Actor
actor.user.email_addr
- Description: Email address of the actor who initiated the event.
- Source:
initiated_by.email - Usage: all events in this service
actor.user.type_id
- Description: OCSF user type of the actor (1=User, 2=Admin, 3=System, 4=Service).
- Source:
initiated_by.type - Transform:
initiated_by.type→enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (all events in this service)- Usage: all events in this service
actor.user.uid
- Description: Unique identifier of the actor who initiated the event.
- Source:
initiated_by.id - Usage: all events in this service
Entity
entity.data.auth_method
- Description: JumpCloud extension data on the managed entity:
auth_method. - Source:
auth_method - Usage: all events in this service
entity.data.categories
- Description: JumpCloud extension data on the managed entity:
categories. - Source:
categories - Usage: genai_ai_assistant_chat_message_sent
entity.data.category
- Description: JumpCloud extension data on the managed entity:
category. - Source:
resource.category - Usage: genai_ai_assistant_memory_deleted
entity.data.changed_field
- Description: JumpCloud extension data on the managed entity:
changed_field. - Source:
changes.field - Usage: genai_ai_assistant_chat_created, genai_ai_assistant_chat_updated, genai_ai_assistant_org_rule_created, genai_ai_assistant_org_rule_updated, genai_ai_assistant_org_settings_updated, genai_ai_search_executed
entity.data.changes_from
- Description: JumpCloud extension data on the managed entity:
changes_from. - Source:
changes.from - Usage: genai_ai_assistant_chat_updated, genai_ai_assistant_org_rule_updated, genai_ai_assistant_org_settings_updated
entity.data.client_id
- Description: JumpCloud extension data on the managed entity:
client_id. - Source:
resource.client_id - Usage: genai_mcp_manual_revoked, genai_mcp_session_created
entity.data.client_name
- Description: JumpCloud extension data on the managed entity:
client_name. - Source:
client_name - Usage: genai_mcp_manual_revoked, genai_mcp_session_created
entity.data.messageId
- Description: JumpCloud extension data on the managed entity:
messageId. - Source:
resource.messageId - Usage: genai_ai_assistant_chat_message_sent
entity.data.org_id
- Description: JumpCloud extension data on the managed entity:
org_id. - Source:
org_id - Usage: genai_mcp_manual_revoked, genai_mcp_session_created
entity.data.ruleText
- Description: JumpCloud extension data on the managed entity:
ruleText. - Source:
resource.ruleText - Usage: genai_ai_assistant_org_rule_created, genai_ai_assistant_org_rule_deleted, genai_ai_assistant_org_rule_updated
entity.data.session_id
- Description: JumpCloud extension data on the managed entity:
session_id. - Source:
session_id - Usage: genai_mcp_manual_revoked, genai_mcp_session_created
entity.data.tools_used.approved
- Description: JumpCloud extension data on the managed entity:
tools_used.approved. - Source:
tools_used.approved - Usage: genai_ai_assistant_chat_message_sent
entity.data.tools_used.parameters.command
- Description: JumpCloud extension data on the managed entity:
tools_used.parameters.command. - Source:
tools_used.parameters.command - Usage: genai_ai_assistant_chat_message_sent
entity.data.tools_used.parameters.commandType
- Description: JumpCloud extension data on the managed entity:
tools_used.parameters.commandType. - Source:
tools_used.parameters.commandType - Usage: genai_ai_assistant_chat_message_sent
entity.data.tools_used.parameters.description
- Description: JumpCloud extension data on the managed entity:
tools_used.parameters.description. - Source:
tools_used.parameters.description - Usage: genai_ai_assistant_chat_message_sent
entity.data.tools_used.parameters.exemptions.id
- Description: JumpCloud extension data on the managed entity:
tools_used.parameters.exemptions.id. - Source:
tools_used.parameters.exemptions.id - Usage: genai_ai_assistant_chat_message_sent
entity.data.tools_used.parameters.exemptions.name
- Description: JumpCloud extension data on the managed entity:
tools_used.parameters.exemptions.name. - Source:
tools_used.parameters.exemptions.name - Usage: genai_ai_assistant_chat_message_sent
entity.data.tools_used.parameters.exemptions.op
- Description: JumpCloud extension data on the managed entity:
tools_used.parameters.exemptions.op. - Source:
tools_used.parameters.exemptions.op - Usage: genai_ai_assistant_chat_message_sent
entity.data.tools_used.parameters.exemptions.type
- Description: JumpCloud extension data on the managed entity:
tools_used.parameters.exemptions.type. - Source:
tools_used.parameters.exemptions.type - Usage: genai_ai_assistant_chat_message_sent
entity.data.tools_used.parameters.filterOperator
- Description: JumpCloud extension data on the managed entity:
tools_used.parameters.filterOperator. - Source:
tools_used.parameters.filterOperator - Usage: genai_ai_assistant_chat_message_sent
entity.data.tools_used.parameters.filters
- Description: JumpCloud extension data on the managed entity:
tools_used.parameters.filters. - Source:
tools_used.parameters.filters - Usage: genai_ai_assistant_chat_message_sent
entity.data.tools_used.parameters.id
- Description: JumpCloud extension data on the managed entity:
tools_used.parameters.id. - Source:
tools_used.parameters.id - Usage: genai_ai_assistant_chat_message_sent
entity.data.tools_used.parameters.intent
- Description: JumpCloud extension data on the managed entity:
tools_used.parameters.intent. - Source:
tools_used.parameters.intent - Usage: genai_ai_assistant_chat_message_sent
entity.data.tools_used.parameters.interactionId
- Description: JumpCloud extension data on the managed entity:
tools_used.parameters.interactionId. - Source:
tools_used.parameters.interactionId - Usage: genai_ai_assistant_chat_message_sent
entity.data.tools_used.parameters.limit
- Description: JumpCloud extension data on the managed entity:
tools_used.parameters.limit. - Source:
tools_used.parameters.limit - Usage: genai_ai_assistant_chat_message_sent
entity.data.tools_used.parameters.name
- Description: JumpCloud extension data on the managed entity:
tools_used.parameters.name. - Source:
tools_used.parameters.name - Usage: genai_ai_assistant_chat_message_sent
entity.data.tools_used.parameters.question
- Description: JumpCloud extension data on the managed entity:
tools_used.parameters.question. - Source:
tools_used.parameters.question - Usage: genai_ai_assistant_chat_message_sent
entity.data.tools_used.parameters.search
- Description: JumpCloud extension data on the managed entity:
tools_used.parameters.search. - Source:
tools_used.parameters.search - Usage: genai_ai_assistant_chat_message_sent
entity.data.tools_used.parameters.shellType
- Description: JumpCloud extension data on the managed entity:
tools_used.parameters.shellType. - Source:
tools_used.parameters.shellType - Usage: genai_ai_assistant_chat_message_sent
entity.data.tools_used.parameters.skip
- Description: JumpCloud extension data on the managed entity:
tools_used.parameters.skip. - Source:
tools_used.parameters.skip - Usage: genai_ai_assistant_chat_message_sent
entity.data.tools_used.parameters.systemIds
- Description: JumpCloud extension data on the managed entity:
tools_used.parameters.systemIds. - Source:
tools_used.parameters.systemIds - Usage: genai_ai_assistant_chat_message_sent
entity.data.tools_used.parameters.title
- Description: JumpCloud extension data on the managed entity:
tools_used.parameters.title. - Source:
tools_used.parameters.title - Usage: genai_ai_assistant_chat_message_sent
entity.data.tools_used.parameters.type
- Description: JumpCloud extension data on the managed entity:
tools_used.parameters.type. - Source:
tools_used.parameters.type - Usage: genai_ai_assistant_chat_message_sent
entity.data.tools_used.tool_name
- Description: JumpCloud extension data on the managed entity:
tools_used.tool_name. - Source:
tools_used.tool_name - Usage: genai_ai_assistant_chat_message_sent
entity.data.trigger
- Description: JumpCloud extension data on the managed entity:
trigger. - Source:
trigger - Usage: genai_mcp_manual_revoked
entity.data.user_id
- Description: JumpCloud extension data on the managed entity:
user_id. - Source:
user_id - Usage: genai_mcp_manual_revoked, genai_mcp_session_created
entity.data.user_prompt
- Description: JumpCloud extension data on the managed entity:
user_prompt. - Source:
user_prompt - Usage: genai_ai_assistant_chat_message_sent
entity.name
- Description: The name of the managed entity. It should match the name of the specific entity object's name if populated, or the name of the managed entity if the
type_idis 'Other'. - Source:
resource.name - Usage: genai_ai_assistant_chat_created, genai_ai_assistant_chat_deleted, genai_ai_assistant_chat_message_sent, genai_ai_assistant_chat_updated, genai_ai_assistant_memory_deleted, genai_ai_assistant_org_rule_created, genai_ai_assistant_org_rule_deleted, genai_ai_assistant_org_rule_updated, genai_mcp_manual_revoked, genai_mcp_session_created
entity.type
- Description: The managed entity type. For example:
Policy,User,Organization,Device. - Source:
resource.type - Usage: all events in this service
entity.uid
- Description: The identifier of the managed entity. It should match the
uidof the specific entity's object UID if populated, or the source specific ID if thetype_idis 'Other'. - Source:
resource.id - Usage: all events in this service
entity_result.data.changes_to
- Description: JumpCloud extension data on the managed entity:
changes_to. - Source:
changes.to - Usage: genai_ai_assistant_chat_created, genai_ai_assistant_chat_updated, genai_ai_assistant_org_rule_created, genai_ai_assistant_org_rule_updated, genai_ai_assistant_org_settings_updated, genai_ai_search_executed
Src Endpoint
src_endpoint.autonomous_system.name
- Description: Organization name for the Autonomous System.
- Source:
asn.organization - Usage: 11 events (missing: genai_ai_assistant_chat_message_sent)
src_endpoint.autonomous_system.number
- Description: Unique number that the AS is identified by.
- Source:
asn.number - Transform:
asn.number→int(11 events (missing: genai_ai_assistant_chat_message_sent))- Usage: 11 events (missing: genai_ai_assistant_chat_message_sent)
src_endpoint.ip
- Description: Source IP address the request originated from.
- Source:
client_ip - Usage: all events in this service
src_endpoint.location.city
- Description: The name of the city.
- Source:
geoip.city - Usage: all events in this service
src_endpoint.location.continent
- Description: The name of the continent.
- Source:
geoip.continent_code - Usage: all events in this service
src_endpoint.location.country
- Description: The ISO 3166-1 Alpha-2 country code.
Note: The two letter country code should be capitalized. For example:
USorCA. - Source:
geoip.country_code - Usage: all events in this service
src_endpoint.location.lat
- Description: The geographical Latitude coordinate represented in Decimal Degrees (DD). For example:
42.361145. - Source:
geoip.latitude - Transform:
geoip.latitude→double(all events in this service)- Usage: all events in this service
src_endpoint.location.long
- Description: The geographical Longitude coordinate represented in Decimal Degrees (DD). For example:
-71.057083. - Source:
geoip.longitude - Transform:
geoip.longitude→double(all events in this service)- Usage: all events in this service
src_endpoint.location.region
- Description: The alphanumeric code that identifies the principal subdivision (e.g. province or state) of the country. For example, 'CH-VD' for the Canton of Vaud, Switzerland
- Source:
geoip.region_code - Usage: all events in this service
Http Request
http_request.user_agent
- Description: The request header that identifies the operating system and web browser.
- Source:
user_agent - Usage: all events in this service
Observables
observables[].name
- Description: The full name of the observable attribute. The
nameis a pointer/reference to an attribute within the OCSF event data. For example:file.name. Array attributes may be represented in one of three ways. For example:resources.uid,resources[].uid,resources[0].uid. - Literal:
actor.user.email_addr,actor.user.uid,http_request.user_agent,src_endpoint.ip,src_endpoint.location.country - Usage: all events in this service
observables[].type_id
- Description: The observable value type identifier.
- Literal:
14,16,2,31,5 - Usage: all events in this service
observables[].value
- Description: The value associated with the observable attribute. The meaning of the value depends on the observable type.
If thenamerefers to a scalar attribute, then thevalueis the value of the attribute.
If thenamerefers to an object attribute, then thevalueis not populated. - Source:
client_ip,geoip.country_code,initiated_by.email,initiated_by.id,user_agent - Usage: all events in this service
Unmapped
unmapped.@version
- Description: JumpCloud Directory Insights field
@versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
@version - Usage: all events in this service
unmapped.asn.error
- Description: JumpCloud Directory Insights field
asn.errorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
asn.error - Usage: genai_ai_assistant_chat_created
unmapped.asn.ip_address
- Description: JumpCloud Directory Insights field
asn.ip_addresspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
asn.ip_address - Usage: genai_ai_assistant_chat_created
unmapped.asn.network
- Description: JumpCloud Directory Insights field
asn.networkpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
asn.network - Usage: 11 events (missing: genai_ai_assistant_chat_message_sent)
unmapped.geoip.region_name
- Description: JumpCloud Directory Insights field
geoip.region_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.region_name - Usage: all events in this service
unmapped.geoip.timezone
- Description: JumpCloud Directory Insights field
geoip.timezonepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.timezone - Usage: all events in this service
unmapped.initiated_by_email_hash
- Description: JumpCloud Directory Insights field
initiated_by_email_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_email_hash - Usage: all events in this service
unmapped.initiated_by_id_hash
- Description: JumpCloud Directory Insights field
initiated_by_id_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_id_hash - Usage: all events in this service
unmapped.is_out_of_bound
- Description: JumpCloud Directory Insights field
is_out_of_boundpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
is_out_of_bound - Usage: all events in this service
unmapped.jc_application_name
- Description: JumpCloud Directory Insights field
jc_application_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_application_name - Usage: all events in this service
unmapped.jc_initiated_by_email
- Description: JumpCloud Directory Insights field
jc_initiated_by_emailpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_initiated_by_email - Usage: genai_ai_assistant_chat_deleted, genai_ai_assistant_chat_updated, genai_ai_assistant_memory_deleted, genai_ai_assistant_org_rule_created, genai_ai_assistant_org_rule_deleted, genai_ai_assistant_org_settings_updated, genai_ai_search_executed, genai_mcp_manual_revoked, genai_mcp_session_created
unmapped.jc_initiated_by_id
- Description: JumpCloud Directory Insights field
jc_initiated_by_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_initiated_by_id - Usage: genai_ai_assistant_chat_deleted, genai_ai_assistant_chat_updated, genai_ai_assistant_memory_deleted, genai_ai_assistant_org_rule_created, genai_ai_assistant_org_rule_deleted, genai_ai_assistant_org_settings_updated, genai_ai_search_executed, genai_mcp_manual_revoked, genai_mcp_session_created
unmapped.jc_initiated_by_username
- Description: JumpCloud Directory Insights field
jc_initiated_by_usernamepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_initiated_by_username - Usage: genai_ai_assistant_chat_deleted, genai_ai_assistant_chat_updated, genai_ai_assistant_memory_deleted, genai_ai_assistant_org_rule_created, genai_ai_assistant_org_rule_deleted, genai_ai_assistant_org_settings_updated, genai_ai_search_executed, genai_mcp_manual_revoked, genai_mcp_session_created
unmapped.jc_organization_name
- Description: JumpCloud Directory Insights field
jc_organization_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_organization_name - Usage: genai_ai_assistant_chat_deleted, genai_ai_assistant_chat_updated, genai_ai_assistant_memory_deleted, genai_ai_assistant_org_rule_created, genai_ai_assistant_org_rule_deleted, genai_ai_assistant_org_settings_updated, genai_ai_search_executed, genai_mcp_manual_revoked, genai_mcp_session_created
unmapped.jc_provider_id
- Description: JumpCloud Directory Insights field
jc_provider_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_provider_id - Usage: genai_ai_assistant_chat_updated, genai_ai_assistant_memory_deleted, genai_mcp_manual_revoked, genai_mcp_session_created
unmapped.jc_system_display_name
- Description: JumpCloud Directory Insights field
jc_system_display_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_system_display_name - Usage: genai_ai_assistant_chat_deleted, genai_ai_assistant_chat_updated, genai_ai_assistant_memory_deleted, genai_ai_assistant_org_rule_created, genai_ai_assistant_org_rule_deleted, genai_ai_assistant_org_settings_updated, genai_ai_search_executed, genai_mcp_manual_revoked, genai_mcp_session_created
unmapped.jc_system_hostname
- Description: JumpCloud Directory Insights field
jc_system_hostnamepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_system_hostname - Usage: genai_ai_assistant_chat_deleted, genai_ai_assistant_chat_updated, genai_ai_assistant_memory_deleted, genai_ai_assistant_org_rule_created, genai_ai_assistant_org_rule_deleted, genai_ai_assistant_org_settings_updated, genai_ai_search_executed, genai_mcp_manual_revoked, genai_mcp_session_created
unmapped.provider
- Description: JumpCloud Directory Insights field
providerpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
provider - Usage: all events in this service
unmapped.resource_id_hash
- Description: JumpCloud Directory Insights field
resource_id_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource_id_hash - Usage: all events in this service
unmapped.resource_name_hash
- Description: JumpCloud Directory Insights field
resource_name_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource_name_hash - Usage: genai_ai_assistant_chat_deleted, genai_ai_assistant_chat_updated, genai_ai_assistant_memory_deleted, genai_ai_assistant_org_rule_created, genai_ai_assistant_org_rule_deleted, genai_mcp_manual_revoked, genai_mcp_session_created
unmapped.useragent.device
- Description: JumpCloud Directory Insights field
useragent.devicepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.device - Usage: all events in this service
unmapped.useragent.major
- Description: JumpCloud Directory Insights field
useragent.majorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.major - Usage: all events in this service
unmapped.useragent.minor
- Description: JumpCloud Directory Insights field
useragent.minorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.minor - Usage: all events in this service
unmapped.useragent.name
- Description: JumpCloud Directory Insights field
useragent.namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.name - Usage: all events in this service
unmapped.useragent.os
- Description: JumpCloud Directory Insights field
useragent.ospreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os - Usage: all events in this service
unmapped.useragent.os_full
- Description: JumpCloud Directory Insights field
useragent.os_fullpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_full - Usage: all events in this service
unmapped.useragent.os_major
- Description: JumpCloud Directory Insights field
useragent.os_majorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_major - Usage: all events in this service
unmapped.useragent.os_minor
- Description: JumpCloud Directory Insights field
useragent.os_minorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_minor - Usage: all events in this service
unmapped.useragent.os_name
- Description: JumpCloud Directory Insights field
useragent.os_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_name - Usage: all events in this service
unmapped.useragent.os_patch
- Description: JumpCloud Directory Insights field
useragent.os_patchpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_patch - Usage: all events in this service
unmapped.useragent.os_version
- Description: JumpCloud Directory Insights field
useragent.os_versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_version - Usage: all events in this service
unmapped.useragent.patch
- Description: JumpCloud Directory Insights field
useragent.patchpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.patch - Usage: all events in this service
unmapped.useragent.version
- Description: JumpCloud Directory Insights field
useragent.versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.version - Usage: all events in this service
Generic Directory Insights#
generic_di · 2 events
| Event | Category | Class | Activity | Type UID | Fields |
|---|---|---|---|---|---|
risk_event_created |
Findings (2) | Detection Finding (2004) | Create (1) | 200401 | 69 |
risk_event_resolved |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 59 |
OCSF field mappings#
Legend
- Description: what the OCSF field represents (from OCSF schema v1.8.0)
- Source: raw JumpCloud event field(s) mapped via
${{placeholder}}template - Transform:
fieldMappingsentry applied at runtime (cast, enum, etc.) - Literal: static value set in the mapping template
- Usage: event types in this service that include this field
Core
activity_id
- Description: The normalized identifier of the activity that triggered the event.
- Literal:
1,3 - Usage: all events in this service
activity_name
- Description: The event activity name, as defined by the activity_id.
- Literal:
Create,Update - Usage: all events in this service
category_name
- Description: The event category name, as defined by category_uid value:
Discovery. - Literal:
Findings,Identity & Access Management - Usage: all events in this service
category_uid
- Description: The category unique identifier of the event.
- Literal:
2,3 - Usage: all events in this service
class_name
- Description: The event class name, as defined by class_uid value:
User Inventory Info. - Literal:
Detection Finding,Entity Management - Usage: all events in this service
class_uid
- Description: The unique identifier of a class. A class describes the attributes available in an event.
- Literal:
2004,3004 - Usage: all events in this service
severity_id
- Description: OCSF severity identifier for the event.
- Literal:
1 - Usage: all events in this service
status_detail
- Description: The status detail contains additional information about the event/finding outcome.
- Source:
error_message - Usage: all events in this service
status_id
- Description: Normalized status of the activity (1=Success, 2=Failure).
- Source:
success - Transform:
success→boolean_to_status_id; true→1, false→2 (all events in this service)- Usage: all events in this service
time
- Description: Event time, in epoch milliseconds (OCSF
time). - Source:
timestamp - Transform:
timestamp→iso8601_to_epoch_millis(all events in this service)- Usage: all events in this service
type_uid
- Description: The event/finding type ID. It identifies the event's semantics and structure. The value is calculated by the logging system as:
class_uid * 100 + activity_id. - Literal:
200401,300403 - Usage: all events in this service
Metadata
metadata.event_code
- Description: JumpCloud event type code.
- Source:
event_type - Usage: all events in this service
metadata.original_time
- Description: The original event time as reported by the event source. For example, the time in the original format from system event log such as Syslog on Unix/Linux and the System event file on Windows. Omit if event is generated instead of collected via logs.
- Source:
server_timestamp - Usage: all events in this service
metadata.processed_time
- Description: The event processed time, such as an ETL operation.
- Source:
jc_transformation_ts - Usage: all events in this service
metadata.product.name
- Description: Originating JumpCloud service that produced the event.
- Source:
service - Usage: all events in this service
metadata.tenant_uid
- Description: JumpCloud organization (tenant) identifier.
- Source:
organization - Usage: all events in this service
metadata.uid
- Description: Unique event identifier assigned by JumpCloud.
- Source:
id - Usage: all events in this service
metadata.version
- Description: OCSF schema version used for this event.
- Literal:
1.8.0 - Usage: all events in this service
Actor
actor.user.email_addr
- Description: Email address of the actor who initiated the event.
- Source:
initiated_by.email - Usage: risk_event_resolved
actor.user.type_id
- Description: OCSF user type of the actor (1=User, 2=Admin, 3=System, 4=Service).
- Source:
initiated_by.type - Transform:
initiated_by.type→enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (all events in this service)- Usage: all events in this service
actor.user.uid
- Description: Unique identifier of the actor who initiated the event.
- Source:
initiated_by.id - Usage: risk_event_resolved
Entity
entity.data.changes_from
- Description: JumpCloud extension data on the managed entity:
changes_from. - Source:
changes.from - Usage: risk_event_resolved
entity.name
- Description: The name of the managed entity. It should match the name of the specific entity object's name if populated, or the name of the managed entity if the
type_idis 'Other'. - Source:
resource.name - Usage: risk_event_resolved
entity.type
- Description: The managed entity type. For example:
Policy,User,Organization,Device. - Source:
resource.type - Usage: risk_event_resolved
entity.uid
- Description: The identifier of the managed entity. It should match the
uidof the specific entity's object UID if populated, or the source specific ID if thetype_idis 'Other'. - Source:
resource.id - Usage: risk_event_resolved
entity_result.data.changes_to
- Description: JumpCloud extension data on the managed entity:
changes_to. - Source:
changes.to - Usage: risk_event_resolved
entity_result.data.resolution_status
- Description: JumpCloud extension data on the managed entity:
resolution_status. - Source:
resource.context.resolution_status - Usage: risk_event_resolved
Src Endpoint
src_endpoint.autonomous_system.name
- Description: Organization name for the Autonomous System.
- Source:
asn.organization - Usage: risk_event_resolved
src_endpoint.autonomous_system.number
- Description: Unique number that the AS is identified by.
- Source:
asn.number - Usage: risk_event_resolved
src_endpoint.ip
- Description: Source IP address the request originated from.
- Source:
client_ip - Usage: risk_event_resolved
src_endpoint.location.city
- Description: The name of the city.
- Source:
geoip.city - Usage: risk_event_resolved
src_endpoint.location.continent
- Description: The name of the continent.
- Source:
geoip.continent_code - Usage: risk_event_resolved
src_endpoint.location.country
- Description: The ISO 3166-1 Alpha-2 country code.
Note: The two letter country code should be capitalized. For example:
USorCA. - Source:
geoip.country_code - Usage: risk_event_resolved
src_endpoint.location.lat
- Description: The geographical Latitude coordinate represented in Decimal Degrees (DD). For example:
42.361145. - Source:
geoip.latitude - Transform:
geoip.latitude→double(risk_event_resolved)- Usage: risk_event_resolved
src_endpoint.location.long
- Description: The geographical Longitude coordinate represented in Decimal Degrees (DD). For example:
-71.057083. - Source:
geoip.longitude - Transform:
geoip.longitude→double(risk_event_resolved)- Usage: risk_event_resolved
src_endpoint.location.region
- Description: The alphanumeric code that identifies the principal subdivision (e.g. province or state) of the country. For example, 'CH-VD' for the Canton of Vaud, Switzerland
- Source:
geoip.region_code - Usage: risk_event_resolved
Http Request
http_request.user_agent
- Description: The request header that identifies the operating system and web browser.
- Source:
user_agent - Usage: risk_event_resolved
Observables
observables[].name
- Description: The full name of the observable attribute. The
nameis a pointer/reference to an attribute within the OCSF event data. For example:file.name. Array attributes may be represented in one of three ways. For example:resources.uid,resources[].uid,resources[0].uid. - Literal:
actor.user.email_addr,actor.user.uid,http_request.user_agent,src_endpoint.ip,src_endpoint.location.country - Usage: risk_event_resolved
observables[].type_id
- Description: The observable value type identifier.
- Literal:
14,16,2,31,5 - Usage: risk_event_resolved
observables[].value
- Description: The value associated with the observable attribute. The meaning of the value depends on the observable type.
If thenamerefers to a scalar attribute, then thevalueis the value of the attribute.
If thenamerefers to an object attribute, then thevalueis not populated. - Source:
client_ip,geoip.country_code,initiated_by.email,initiated_by.id,user_agent - Usage: risk_event_resolved
Other
finding_info.title
- Description: A title or a brief phrase summarizing the reported finding.
- Source:
resource.name - Usage: risk_event_created
finding_info.uid
- Description: The unique identifier of the reported finding.
- Source:
resource.id - Usage: risk_event_created
risk_level
- Description: The risk level, normalized to the caption of the risk_level_id value.
- Source:
resource.context.risk_severity - Usage: risk_event_created
risk_score
- Description: The risk score as reported by the event source.
- Source:
resource.context.risk_score - Usage: risk_event_created
Unmapped
unmapped.@version
- Description: JumpCloud Directory Insights field
@versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
@version - Usage: all events in this service
unmapped.asn.network
- Description: JumpCloud Directory Insights field
asn.networkpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
asn.network - Usage: risk_event_resolved
unmapped.changes.field
- Description: JumpCloud Directory Insights field
changes.fieldpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.field - Usage: risk_event_resolved
unmapped.client_ip
- Description: JumpCloud Directory Insights field
client_ippreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
client_ip - Usage: risk_event_created
unmapped.geoip.region_name
- Description: JumpCloud Directory Insights field
geoip.region_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.region_name - Usage: risk_event_resolved
unmapped.geoip.timezone
- Description: JumpCloud Directory Insights field
geoip.timezonepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.timezone - Usage: risk_event_resolved
unmapped.initiated_by_email_hash
- Description: JumpCloud Directory Insights field
initiated_by_email_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_email_hash - Usage: risk_event_resolved
unmapped.initiated_by_id_hash
- Description: JumpCloud Directory Insights field
initiated_by_id_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_id_hash - Usage: risk_event_resolved
unmapped.is_out_of_bound
- Description: JumpCloud Directory Insights field
is_out_of_boundpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
is_out_of_bound - Usage: all events in this service
unmapped.jc_application_name
- Description: JumpCloud Directory Insights field
jc_application_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_application_name - Usage: all events in this service
unmapped.jc_initiated_by_email
- Description: JumpCloud Directory Insights field
jc_initiated_by_emailpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_initiated_by_email - Usage: risk_event_resolved
unmapped.jc_initiated_by_id
- Description: JumpCloud Directory Insights field
jc_initiated_by_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_initiated_by_id - Usage: risk_event_resolved
unmapped.jc_initiated_by_username
- Description: JumpCloud Directory Insights field
jc_initiated_by_usernamepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_initiated_by_username - Usage: risk_event_resolved
unmapped.jc_organization_name
- Description: JumpCloud Directory Insights field
jc_organization_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_organization_name - Usage: risk_event_resolved
unmapped.jc_system_display_name
- Description: JumpCloud Directory Insights field
jc_system_display_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_system_display_name - Usage: risk_event_resolved
unmapped.jc_system_hostname
- Description: JumpCloud Directory Insights field
jc_system_hostnamepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_system_hostname - Usage: risk_event_resolved
unmapped.resource.context.identity_identifier
- Description: JumpCloud Directory Insights field
resource.context.identity_identifierpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.identity_identifier - Usage: risk_event_created
unmapped.resource.context.identity_object_id
- Description: JumpCloud Directory Insights field
resource.context.identity_object_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.identity_object_id - Usage: risk_event_created
unmapped.resource.context.identity_type
- Description: JumpCloud Directory Insights field
resource.context.identity_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.identity_type - Usage: risk_event_created
unmapped.resource.context.resolution_state
- Description: JumpCloud Directory Insights field
resource.context.resolution_statepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.resolution_state - Usage: risk_event_created
unmapped.resource.context.resolution_status
- Description: JumpCloud Directory Insights field
resource.context.resolution_statuspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.resolution_status - Usage: risk_event_created
unmapped.resource.context.risk_event_factors.description
- Description: JumpCloud Directory Insights field
resource.context.risk_event_factors.descriptionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.risk_event_factors.description - Usage: risk_event_created
unmapped.resource.context.risk_event_factors.metadata.application_id
- Description: JumpCloud Directory Insights field
resource.context.risk_event_factors.metadata.application_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.risk_event_factors.metadata.application_id - Usage: risk_event_created
unmapped.resource.context.risk_event_factors.metadata.application_name
- Description: JumpCloud Directory Insights field
resource.context.risk_event_factors.metadata.application_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.risk_event_factors.metadata.application_name - Usage: risk_event_created
unmapped.resource.context.risk_event_factors.metadata.baseline_mean
- Description: JumpCloud Directory Insights field
resource.context.risk_event_factors.metadata.baseline_meanpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.risk_event_factors.metadata.baseline_mean - Usage: risk_event_created
unmapped.resource.context.risk_event_factors.metadata.browser_name
- Description: JumpCloud Directory Insights field
resource.context.risk_event_factors.metadata.browser_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.risk_event_factors.metadata.browser_name - Usage: risk_event_created
unmapped.resource.context.risk_event_factors.metadata.current_failures
- Description: JumpCloud Directory Insights field
resource.context.risk_event_factors.metadata.current_failurespreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.risk_event_factors.metadata.current_failures - Usage: risk_event_created
unmapped.resource.context.risk_event_factors.metadata.current_total
- Description: JumpCloud Directory Insights field
resource.context.risk_event_factors.metadata.current_totalpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.risk_event_factors.metadata.current_total - Usage: risk_event_created
unmapped.resource.context.risk_event_factors.metadata.days_since_last_login
- Description: JumpCloud Directory Insights field
resource.context.risk_event_factors.metadata.days_since_last_loginpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.risk_event_factors.metadata.days_since_last_login - Usage: risk_event_created
unmapped.resource.context.risk_event_factors.metadata.device_id
- Description: JumpCloud Directory Insights field
resource.context.risk_event_factors.metadata.device_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.risk_event_factors.metadata.device_id - Usage: risk_event_created
unmapped.resource.context.risk_event_factors.metadata.device_type
- Description: JumpCloud Directory Insights field
resource.context.risk_event_factors.metadata.device_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.risk_event_factors.metadata.device_type - Usage: risk_event_created
unmapped.resource.context.risk_event_factors.metadata.dormant_threshold_days
- Description: JumpCloud Directory Insights field
resource.context.risk_event_factors.metadata.dormant_threshold_dayspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.risk_event_factors.metadata.dormant_threshold_days - Usage: risk_event_created
unmapped.resource.context.risk_event_factors.metadata.geoip_timezone_raw
- Description: JumpCloud Directory Insights field
resource.context.risk_event_factors.metadata.geoip_timezone_rawpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.risk_event_factors.metadata.geoip_timezone_raw - Usage: risk_event_created
unmapped.resource.context.risk_event_factors.metadata.hour_via_time_stats
- Description: JumpCloud Directory Insights field
resource.context.risk_event_factors.metadata.hour_via_time_statspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.risk_event_factors.metadata.hour_via_time_stats - Usage: risk_event_created
unmapped.resource.context.risk_event_factors.metadata.last_successful_login
- Description: JumpCloud Directory Insights field
resource.context.risk_event_factors.metadata.last_successful_loginpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.risk_event_factors.metadata.last_successful_login - Usage: risk_event_created
unmapped.resource.context.risk_event_factors.metadata.local_datetime
- Description: JumpCloud Directory Insights field
resource.context.risk_event_factors.metadata.local_datetimepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.risk_event_factors.metadata.local_datetime - Usage: risk_event_created
unmapped.resource.context.risk_event_factors.metadata.local_hour
- Description: JumpCloud Directory Insights field
resource.context.risk_event_factors.metadata.local_hourpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.risk_event_factors.metadata.local_hour - Usage: risk_event_created
unmapped.resource.context.risk_event_factors.metadata.min_required
- Description: JumpCloud Directory Insights field
resource.context.risk_event_factors.metadata.min_requiredpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.risk_event_factors.metadata.min_required - Usage: risk_event_created
unmapped.resource.context.risk_event_factors.metadata.multiplier
- Description: JumpCloud Directory Insights field
resource.context.risk_event_factors.metadata.multiplierpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.risk_event_factors.metadata.multiplier - Usage: risk_event_created
unmapped.resource.context.risk_event_factors.metadata.novel_hour
- Description: JumpCloud Directory Insights field
resource.context.risk_event_factors.metadata.novel_hourpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.risk_event_factors.metadata.novel_hour - Usage: risk_event_created
unmapped.resource.context.risk_event_factors.metadata.novel_weekday
- Description: JumpCloud Directory Insights field
resource.context.risk_event_factors.metadata.novel_weekdaypreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.risk_event_factors.metadata.novel_weekday - Usage: risk_event_created
unmapped.resource.context.risk_event_factors.metadata.os_name
- Description: JumpCloud Directory Insights field
resource.context.risk_event_factors.metadata.os_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.risk_event_factors.metadata.os_name - Usage: risk_event_created
unmapped.resource.context.risk_event_factors.metadata.threshold
- Description: JumpCloud Directory Insights field
resource.context.risk_event_factors.metadata.thresholdpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.risk_event_factors.metadata.threshold - Usage: risk_event_created
unmapped.resource.context.risk_event_factors.metadata.timezone
- Description: JumpCloud Directory Insights field
resource.context.risk_event_factors.metadata.timezonepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.risk_event_factors.metadata.timezone - Usage: risk_event_created
unmapped.resource.context.risk_event_factors.metadata.ua_composite
- Description: JumpCloud Directory Insights field
resource.context.risk_event_factors.metadata.ua_compositepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.risk_event_factors.metadata.ua_composite - Usage: risk_event_created
unmapped.resource.context.risk_event_factors.metadata.utc_datetime
- Description: JumpCloud Directory Insights field
resource.context.risk_event_factors.metadata.utc_datetimepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.risk_event_factors.metadata.utc_datetime - Usage: risk_event_created
unmapped.resource.context.risk_event_factors.metadata.utc_hour
- Description: JumpCloud Directory Insights field
resource.context.risk_event_factors.metadata.utc_hourpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.risk_event_factors.metadata.utc_hour - Usage: risk_event_created
unmapped.resource.context.risk_event_factors.metadata.weekday_key
- Description: JumpCloud Directory Insights field
resource.context.risk_event_factors.metadata.weekday_keypreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.risk_event_factors.metadata.weekday_key - Usage: risk_event_created
unmapped.resource.context.risk_event_factors.metadata.weekday_via_time_stats
- Description: JumpCloud Directory Insights field
resource.context.risk_event_factors.metadata.weekday_via_time_statspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.risk_event_factors.metadata.weekday_via_time_stats - Usage: risk_event_created
unmapped.resource.context.risk_event_factors.severity
- Description: JumpCloud Directory Insights field
resource.context.risk_event_factors.severitypreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.risk_event_factors.severity - Usage: risk_event_created
unmapped.resource.context.risk_event_factors.type
- Description: JumpCloud Directory Insights field
resource.context.risk_event_factors.typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.risk_event_factors.type - Usage: risk_event_created
unmapped.resource.context.risk_event_factors.weight
- Description: JumpCloud Directory Insights field
resource.context.risk_event_factors.weightpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.risk_event_factors.weight - Usage: risk_event_created
unmapped.resource.context.risk_event_object_id
- Description: JumpCloud Directory Insights field
resource.context.risk_event_object_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.risk_event_object_id - Usage: all events in this service
unmapped.resource.context.source_event_object_id
- Description: JumpCloud Directory Insights field
resource.context.source_event_object_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.source_event_object_id - Usage: risk_event_created
unmapped.resource.type
- Description: JumpCloud Directory Insights field
resource.typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.type - Usage: risk_event_created
unmapped.resource_id_hash
- Description: JumpCloud Directory Insights field
resource_id_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource_id_hash - Usage: all events in this service
unmapped.resource_name_hash
- Description: JumpCloud Directory Insights field
resource_name_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource_name_hash - Usage: risk_event_resolved
unmapped.timestamp_source
- Description: JumpCloud Directory Insights field
timestamp_sourcepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
timestamp_source - Usage: all events in this service
unmapped.user_agent
- Description: JumpCloud Directory Insights field
user_agentpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
user_agent - Usage: risk_event_created
LDAP#
ldap · 2 events
| Event | Category | Class | Activity | Type UID | Fields |
|---|---|---|---|---|---|
ldap_bind |
Identity & Access Management (3) | Authentication (3002) | Logon (1) | 300201 | 48 |
ldap_srch |
Application Activity (6) | Datastore Activity (6005) | Query (4) | 600504 | 44 |
OCSF field mappings#
Legend
- Description: what the OCSF field represents (from OCSF schema v1.8.0)
- Source: raw JumpCloud event field(s) mapped via
${{placeholder}}template - Transform:
fieldMappingsentry applied at runtime (cast, enum, etc.) - Literal: static value set in the mapping template
- Usage: event types in this service that include this field
Core
activity_id
- Description: The normalized identifier of the activity that triggered the event.
- Literal:
1,4 - Usage: all events in this service
activity_name
- Description: The event activity name, as defined by the activity_id.
- Literal:
Logon,Query - Usage: all events in this service
category_name
- Description: The event category name, as defined by category_uid value:
Discovery. - Literal:
Application Activity,Identity & Access Management - Usage: all events in this service
category_uid
- Description: The category unique identifier of the event.
- Literal:
3,6 - Usage: all events in this service
class_name
- Description: The event class name, as defined by class_uid value:
User Inventory Info. - Literal:
Authentication,Datastore Activity - Usage: all events in this service
class_uid
- Description: The unique identifier of a class. A class describes the attributes available in an event.
- Literal:
3002,6005 - Usage: all events in this service
severity_id
- Description: OCSF severity identifier for the event.
- Literal:
1 - Usage: all events in this service
status_detail
- Description: The status detail contains additional information about the event/finding outcome.
- Source:
error_message - Usage: all events in this service
status_id
- Description: Normalized status of the activity (1=Success, 2=Failure).
- Source:
success - Transform:
success→boolean_to_status_id; true→1, false→2 (ldap_bind)- Usage: ldap_bind
time
- Description: Event time, in epoch milliseconds (OCSF
time). - Source:
timestamp - Transform:
timestamp→iso8601_to_epoch_millis(all events in this service)- Usage: all events in this service
type_uid
- Description: The event/finding type ID. It identifies the event's semantics and structure. The value is calculated by the logging system as:
class_uid * 100 + activity_id. - Literal:
300201,600504 - Usage: all events in this service
Metadata
metadata.event_code
- Description: JumpCloud event type code.
- Source:
event_type - Usage: all events in this service
metadata.processed_time
- Description: The event processed time, such as an ETL operation.
- Source:
jc_transformation_ts - Usage: all events in this service
metadata.product.name
- Description: Originating JumpCloud service that produced the event.
- Source:
service - Usage: all events in this service
metadata.tenant_uid
- Description: JumpCloud organization (tenant) identifier.
- Source:
organization - Usage: all events in this service
metadata.uid
- Description: Unique event identifier assigned by JumpCloud.
- Source:
id - Usage: all events in this service
metadata.version
- Description: OCSF schema version used for this event.
- Literal:
1.8.0 - Usage: all events in this service
Actor
actor.user.name
- Description: Display name of the actor who initiated the event.
- Source:
initiated_by.username,username - Usage: all events in this service
actor.user.type_id
- Description: OCSF user type of the actor (1=User, 2=Admin, 3=System, 4=Service).
- Source:
initiated_by.type - Transform:
initiated_by.type→enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (all events in this service)- Usage: all events in this service
User
user.name
- Description: The username. For example,
janedoe1. - Source:
username - Usage: ldap_bind
user.uid
- Description: Unique identifier of the user associated with the event.
- Source:
dn - Usage: ldap_bind
Src Endpoint
src_endpoint.ip
- Description: Source IP address the request originated from.
- Source:
client_ip - Usage: all events in this service
src_endpoint.location.city
- Description: The name of the city.
- Source:
geoip.city - Usage: ldap_bind
src_endpoint.location.continent
- Description: The name of the continent.
- Source:
geoip.continent_code - Usage: ldap_bind
src_endpoint.location.country
- Description: The ISO 3166-1 Alpha-2 country code.
Note: The two letter country code should be capitalized. For example:
USorCA. - Source:
geoip.country_code - Usage: ldap_bind
src_endpoint.location.lat
- Description: The geographical Latitude coordinate represented in Decimal Degrees (DD). For example:
42.361145. - Source:
geoip.latitude - Transform:
geoip.latitude→double(ldap_bind)- Usage: ldap_bind
src_endpoint.location.long
- Description: The geographical Longitude coordinate represented in Decimal Degrees (DD). For example:
-71.057083. - Source:
geoip.longitude - Transform:
geoip.longitude→double(ldap_bind)- Usage: ldap_bind
src_endpoint.location.region
- Description: The alphanumeric code that identifies the principal subdivision (e.g. province or state) of the country. For example, 'CH-VD' for the Canton of Vaud, Switzerland
- Source:
geoip.region_code - Usage: ldap_bind
Http Request
http_request.user_agent
- Description: The request header that identifies the operating system and web browser.
- Source:
user_agent - Usage: all events in this service
Observables
observables[].name
- Description: The full name of the observable attribute. The
nameis a pointer/reference to an attribute within the OCSF event data. For example:file.name. Array attributes may be represented in one of three ways. For example:resources.uid,resources[].uid,resources[0].uid. - Literal:
actor.user.name,http_request.user_agent,src_endpoint.ip,src_endpoint.location.country,user.name,user.uid - Usage: all events in this service
observables[].type_id
- Description: The observable value type identifier.
- Literal:
14,16,2,31,4 - Usage: all events in this service
observables[].value
- Description: The value associated with the observable attribute. The meaning of the value depends on the observable type.
If thenamerefers to a scalar attribute, then thevalueis the value of the attribute.
If thenamerefers to an object attribute, then thevalueis not populated. - Source:
client_ip,dn,geoip.country_code,initiated_by.username,user_agent,username - Usage: all events in this service
Other
api.operation
- Description: Verb/Operation associated with the request
- Source:
operation_type - Usage: ldap_srch
api.request.uid
- Description: The unique request identifier.
- Source:
connection_id - Usage: ldap_srch
auth_protocol
- Description: The authentication protocol as defined by the caption of
auth_protocol_id. In the case ofOther, it is defined by the event source. - Source:
auth_method - Usage: ldap_bind
count
- Description: The number of times that events in the same logical group occurred during the event Start Time to End Time period.
- Source:
number_of_results - Usage: ldap_srch
database.name
- Description: The database name, ordinarily as assigned by a database administrator.
- Source:
service - Usage: ldap_srch
logon_type
- Description: The logon type, normalized to the caption of the logon_type_id value. In the case of 'Other', it is defined by the event source.
- Source:
mech - Usage: ldap_bind
session.uid
- Description: The unique identifier of the session.
- Source:
connection_id - Usage: ldap_bind
status_code
- Description: The event status code, as reported by the event source.
For example, in a Windows Failed Authentication event, this would be the value of 'Failure Code', e.g. 0x18. - Source:
error_code - Usage: all events in this service
Unmapped
unmapped.@version
- Description: JumpCloud Directory Insights field
@versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
@version - Usage: all events in this service
unmapped.attr
- Description: JumpCloud Directory Insights field
attrpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
attr - Usage: ldap_srch
unmapped.auth_meta.auth_methods.password.success
- Description: JumpCloud Directory Insights field
auth_meta.auth_methods.password.successpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
auth_meta.auth_methods.password.success - Usage: ldap_bind
unmapped.base
- Description: JumpCloud Directory Insights field
basepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
base - Usage: ldap_srch
unmapped.deref
- Description: JumpCloud Directory Insights field
derefpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
deref - Usage: ldap_srch
unmapped.dn
- Description: JumpCloud Directory Insights field
dnpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
dn - Usage: ldap_srch
unmapped.filter
- Description: JumpCloud Directory Insights field
filterpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
filter - Usage: ldap_srch
unmapped.geoip.region_name
- Description: JumpCloud Directory Insights field
geoip.region_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.region_name - Usage: ldap_bind
unmapped.geoip.timezone
- Description: JumpCloud Directory Insights field
geoip.timezonepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.timezone - Usage: ldap_bind
unmapped.initiated_by.username
- Description: JumpCloud Directory Insights field
initiated_by.usernamepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by.username - Usage: ldap_srch
unmapped.initiated_by_username_hash
- Description: JumpCloud Directory Insights field
initiated_by_username_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_username_hash - Usage: all events in this service
unmapped.is_out_of_bound
- Description: JumpCloud Directory Insights field
is_out_of_boundpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
is_out_of_bound - Usage: all events in this service
unmapped.jc_application_name
- Description: JumpCloud Directory Insights field
jc_application_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_application_name - Usage: all events in this service
unmapped.operation_number
- Description: JumpCloud Directory Insights field
operation_numberpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
operation_number - Usage: all events in this service
unmapped.operation_type
- Description: JumpCloud Directory Insights field
operation_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
operation_type - Usage: ldap_bind
unmapped.scope
- Description: JumpCloud Directory Insights field
scopepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
scope - Usage: ldap_srch
unmapped.start_tls
- Description: JumpCloud Directory Insights field
start_tlspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
start_tls - Usage: all events in this service
unmapped.success
- Description: JumpCloud Directory Insights field
successpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
success - Usage: ldap_srch
unmapped.tls_established
- Description: JumpCloud Directory Insights field
tls_establishedpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
tls_established - Usage: all events in this service
unmapped.username_hash
- Description: JumpCloud Directory Insights field
username_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
username_hash - Usage: all events in this service
MDM#
mdm · 11 events
| Event | Category | Class | Activity | Type UID | Fields |
|---|---|---|---|---|---|
apple_ddm_status_receive |
Discovery (5) | Device Config State Change (5019) | Collect (2) | 501902 | 110 |
apple_mdm_service_discovery |
Discovery (5) | Device Config State Change (5019) | Log (1) | 501901 | 37 |
apple_policy_dispatch |
System Activity (1) | Scheduled Job Activity (1006) | Start (6) | 100606 | 40 |
applemdm_commands_clearactivationlock |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 57 |
applemdm_devicemanagers_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 46 |
applemdm_devicemanagers_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 49 |
applemdm_devicemanagers_patch |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 62 |
applemdm_volumepurchaseprogram_locationspost |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 61 |
configuration_file_download |
Identity & Access Management (3) | Entity Management (3004) | Read (2) | 300402 | 57 |
device_enrollment |
Identity & Access Management (3) | Entity Management (3004) | Enroll (6) | 300406 | 49 |
mdm_command_result |
System Activity (1) | Scheduled Job Activity (1006) | Start (6) | 100606 | 74 |
OCSF field mappings#
Legend
- Description: what the OCSF field represents (from OCSF schema v1.8.0)
- Source: raw JumpCloud event field(s) mapped via
${{placeholder}}template - Transform:
fieldMappingsentry applied at runtime (cast, enum, etc.) - Literal: static value set in the mapping template
- Usage: event types in this service that include this field
Core
activity_id
- Description: The normalized identifier of the activity that triggered the event.
- Literal:
1,2,3,4,6 - Usage: all events in this service
activity_name
- Description: The event activity name, as defined by the activity_id.
- Literal:
Collect,Create,Delete,Enroll,Log,Read,Start,Update - Usage: all events in this service
category_name
- Description: The event category name, as defined by category_uid value:
Discovery. - Literal:
Discovery,Identity & Access Management,System Activity - Usage: all events in this service
category_uid
- Description: The category unique identifier of the event.
- Literal:
1,3,5 - Usage: all events in this service
class_name
- Description: The event class name, as defined by class_uid value:
User Inventory Info. - Literal:
Device Config State Change,Entity Management,Scheduled Job Activity - Usage: all events in this service
class_uid
- Description: The unique identifier of a class. A class describes the attributes available in an event.
- Literal:
1006,3004,5019 - Usage: all events in this service
message
- Description: The description of the event/finding, as defined by the source.
- Source:
result - Usage: apple_ddm_status_receive, apple_mdm_service_discovery, apple_policy_dispatch, configuration_file_download, device_enrollment, mdm_command_result
severity_id
- Description: OCSF severity identifier for the event.
- Literal:
1 - Usage: all events in this service
status_detail
- Description: The status detail contains additional information about the event/finding outcome.
- Source:
error_message - Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost
status_id
- Description: Normalized status of the activity (1=Success, 2=Failure).
- Source:
success - Transform:
success→boolean_to_status_id; true→1, false→2 (all events in this service)- Usage: all events in this service
time
- Description: Event time, in epoch milliseconds (OCSF
time). - Source:
timestamp - Transform:
timestamp→iso8601_to_epoch_millis(all events in this service)- Usage: all events in this service
type_uid
- Description: The event/finding type ID. It identifies the event's semantics and structure. The value is calculated by the logging system as:
class_uid * 100 + activity_id. - Literal:
100606,300401,300402,300403,300404,300406,501901,501902 - Usage: all events in this service
Metadata
metadata.event_code
- Description: JumpCloud event type code.
- Source:
event_type - Usage: all events in this service
metadata.original_time
- Description: The original event time as reported by the event source. For example, the time in the original format from system event log such as Syslog on Unix/Linux and the System event file on Windows. Omit if event is generated instead of collected via logs.
- Source:
server_timestamp - Usage: configuration_file_download
metadata.processed_time
- Description: The event processed time, such as an ETL operation.
- Source:
jc_transformation_ts - Usage: all events in this service
metadata.product.name
- Description: Originating JumpCloud service that produced the event.
- Source:
service - Usage: all events in this service
metadata.tenant_uid
- Description: JumpCloud organization (tenant) identifier.
- Source:
organization - Usage: all events in this service
metadata.uid
- Description: Unique event identifier assigned by JumpCloud.
- Source:
id - Usage: all events in this service
metadata.version
- Description: OCSF schema version used for this event.
- Literal:
1.8.0 - Usage: all events in this service
Actor
actor.user.email_addr
- Description: Email address of the actor who initiated the event.
- Source:
initiated_by.email - Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost, configuration_file_download, device_enrollment
actor.user.name
- Description: Display name of the actor who initiated the event.
- Source:
initiated_by.name - Usage: configuration_file_download, device_enrollment
actor.user.type_id
- Description: OCSF user type of the actor (1=User, 2=Admin, 3=System, 4=Service).
- Source:
initiated_by.type - Transform:
initiated_by.type→enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (applemdm_commands_clearactivationlock, applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost, device_enrollment)- Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost, device_enrollment
actor.user.uid
- Description: Unique identifier of the actor who initiated the event.
- Source:
initiated_by.id - Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost
Device
device.os.type
- Description: The type of the operating system.
- Source:
mdm_type - Usage: apple_ddm_status_receive, apple_mdm_service_discovery, apple_policy_dispatch, mdm_command_result
device.uid
- Description: The unique identifier of the device. For example the Windows TargetSID or AWS EC2 ARN.
- Source:
windows_device_uuid - Usage: apple_ddm_status_receive, apple_mdm_service_discovery, apple_policy_dispatch, mdm_command_result
Entity
entity.data.auth_method
- Description: JumpCloud extension data on the managed entity:
auth_method. - Source:
auth_method - Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost
entity.data.changed_field
- Description: JumpCloud extension data on the managed entity:
changed_field. - Source:
changes.field - Usage: applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost
entity.data.changes_from
- Description: JumpCloud extension data on the managed entity:
changes_from. - Source:
changes.from - Usage: applemdm_devicemanagers_delete, applemdm_devicemanagers_patch
entity.data.mdm_device_manager_id
- Description: JumpCloud extension data on the managed entity:
mdm_device_manager_id. - Source:
mdm_device_manager_id - Usage: configuration_file_download, device_enrollment
entity.device.uid
- Description: The unique identifier of the device. For example the Windows TargetSID or AWS EC2 ARN.
- Source:
resource.device_object_id,windows_device_uuid - Usage: applemdm_commands_clearactivationlock, configuration_file_download, device_enrollment
entity.type
- Description: The managed entity type. For example:
Policy,User,Organization,Device. - Source:
mdm_type,resource.type - Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost, configuration_file_download, device_enrollment
entity.uid
- Description: The identifier of the managed entity. It should match the
uidof the specific entity's object UID if populated, or the source specific ID if thetype_idis 'Other'. - Source:
mdm_device_id,resource.id - Usage: applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, configuration_file_download, device_enrollment
entity_result.data.changes_to
- Description: JumpCloud extension data on the managed entity:
changes_to. - Source:
changes.to - Usage: applemdm_devicemanagers_create
entity_result.data.changes_to_nanos
- Description: JumpCloud extension data on the managed entity:
changes_to_nanos. - Source:
changes.to.nanos - Usage: applemdm_volumepurchaseprogram_locationspost
entity_result.data.changes_to_seconds
- Description: JumpCloud extension data on the managed entity:
changes_to_seconds. - Source:
changes.to.seconds - Usage: applemdm_volumepurchaseprogram_locationspost
Src Endpoint
src_endpoint.autonomous_system.name
- Description: Organization name for the Autonomous System.
- Source:
asn.organization - Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost, configuration_file_download
src_endpoint.autonomous_system.number
- Description: Unique number that the AS is identified by.
- Source:
asn.number - Transform:
asn.number→int(applemdm_commands_clearactivationlock, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost, configuration_file_download)- Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost, configuration_file_download
src_endpoint.ip
- Description: Source IP address the request originated from.
- Source:
client_ip - Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost
src_endpoint.location.city
- Description: The name of the city.
- Source:
geoip.city - Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost, configuration_file_download, device_enrollment
src_endpoint.location.continent
- Description: The name of the continent.
- Source:
geoip.continent_code - Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost, configuration_file_download, device_enrollment
src_endpoint.location.country
- Description: The ISO 3166-1 Alpha-2 country code.
Note: The two letter country code should be capitalized. For example:
USorCA. - Source:
geoip.country_code - Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost, configuration_file_download, device_enrollment
src_endpoint.location.lat
- Description: The geographical Latitude coordinate represented in Decimal Degrees (DD). For example:
42.361145. - Source:
geoip.latitude - Transform:
geoip.latitude→double(applemdm_commands_clearactivationlock, applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost, configuration_file_download, device_enrollment)- Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost, configuration_file_download, device_enrollment
src_endpoint.location.long
- Description: The geographical Longitude coordinate represented in Decimal Degrees (DD). For example:
-71.057083. - Source:
geoip.longitude - Transform:
geoip.longitude→double(applemdm_commands_clearactivationlock, applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost, configuration_file_download, device_enrollment)- Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost, configuration_file_download, device_enrollment
src_endpoint.location.region
- Description: The alphanumeric code that identifies the principal subdivision (e.g. province or state) of the country. For example, 'CH-VD' for the Canton of Vaud, Switzerland
- Source:
geoip.region_code - Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost, configuration_file_download, device_enrollment
Http Request
http_request.user_agent
- Description: The request header that identifies the operating system and web browser.
- Source:
user_agent - Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost
Observables
observables[].name
- Description: The full name of the observable attribute. The
nameis a pointer/reference to an attribute within the OCSF event data. For example:file.name. Array attributes may be represented in one of three ways. For example:resources.uid,resources[].uid,resources[0].uid. - Literal:
actor.user.email_addr,actor.user.name,actor.user.uid,device.uid,entity.device.uid,http_request.user_agent,job.cmd_line,src_endpoint.ip,src_endpoint.location.country - Usage: all events in this service
observables[].type_id
- Description: The observable value type identifier.
- Literal:
13,14,16,2,31,4,47,5 - Usage: all events in this service
observables[].value
- Description: The value associated with the observable attribute. The meaning of the value depends on the observable type.
If thenamerefers to a scalar attribute, then thevalueis the value of the attribute.
If thenamerefers to an object attribute, then thevalueis not populated. - Source:
client_ip,command.payload,geoip.country_code,initiated_by.email,initiated_by.id,initiated_by.name,mdm_device_id,resource.device_object_id,user_agent,windows_device_uuid - Usage: all events in this service
Other
action
- Description: The normalized caption of
action_id. - Source:
action - Usage: apple_policy_dispatch
job.cmd_line
- Description: The job command line.
- Source:
command.payload - Usage: mdm_command_result
job.desc
- Description: The description of the job.
- Source:
request_type - Usage: apple_policy_dispatch, mdm_command_result
job.name
- Description: The name of the job.
- Source:
policy_name - Usage: apple_policy_dispatch
job.run_state
- Description: The run state of the job.
- Source:
status - Usage: apple_policy_dispatch, mdm_command_result
status
- Description: The event status, normalized to the caption of the status_id value. In the case of 'Other', it is defined by the event source.
- Source:
status - Usage: apple_ddm_status_receive, apple_mdm_service_discovery, configuration_file_download, device_enrollment
Unmapped
unmapped.@version
- Description: JumpCloud Directory Insights field
@versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
@version - Usage: all events in this service
unmapped.activation_lock_bypass_code
- Description: JumpCloud Directory Insights field
activation_lock_bypass_codepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
activation_lock_bypass_code - Usage: mdm_command_result
unmapped.asn.network
- Description: JumpCloud Directory Insights field
asn.networkpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
asn.network - Usage: applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost, configuration_file_download
unmapped.association_action_source
- Description: JumpCloud Directory Insights field
association_action_sourcepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
association_action_source - Usage: apple_ddm_status_receive, apple_mdm_service_discovery, apple_policy_dispatch, configuration_file_download, device_enrollment, mdm_command_result
unmapped.association_from_type
- Description: JumpCloud Directory Insights field
association_from_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
association_from_type - Usage: apple_ddm_status_receive, apple_mdm_service_discovery, apple_policy_dispatch, configuration_file_download, device_enrollment, mdm_command_result
unmapped.association_op
- Description: JumpCloud Directory Insights field
association_oppreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
association_op - Usage: apple_ddm_status_receive, apple_mdm_service_discovery, apple_policy_dispatch, configuration_file_download, device_enrollment, mdm_command_result
unmapped.association_to_type
- Description: JumpCloud Directory Insights field
association_to_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
association_to_type - Usage: apple_ddm_status_receive, apple_mdm_service_discovery, apple_policy_dispatch, configuration_file_download, device_enrollment, mdm_command_result
unmapped.changes
- Description: JumpCloud Directory Insights field
changespreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes - Usage: applemdm_commands_clearactivationlock
unmapped.command
- Description: JumpCloud Directory Insights field
commandpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
command - Usage: apple_ddm_status_receive, apple_mdm_service_discovery, apple_policy_dispatch, configuration_file_download, device_enrollment
unmapped.command.current_password
- Description: JumpCloud Directory Insights field
command.current_passwordpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
command.current_password - Usage: mdm_command_result
unmapped.command.data
- Description: JumpCloud Directory Insights field
command.datapreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
command.data - Usage: mdm_command_result
unmapped.command.install_as_managed
- Description: JumpCloud Directory Insights field
command.install_as_managedpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
command.install_as_managed - Usage: mdm_command_result
unmapped.command.manifest.items.assets.kind
- Description: JumpCloud Directory Insights field
command.manifest.items.assets.kindpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
command.manifest.items.assets.kind - Usage: mdm_command_result
unmapped.command.manifest.items.assets.md5Size
- Description: JumpCloud Directory Insights field
command.manifest.items.assets.md5Sizepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
command.manifest.items.assets.md5Size - Usage: mdm_command_result
unmapped.command.manifest.items.assets.md5s
- Description: JumpCloud Directory Insights field
command.manifest.items.assets.md5spreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
command.manifest.items.assets.md5s - Usage: mdm_command_result
unmapped.command.manifest.items.assets.url
- Description: JumpCloud Directory Insights field
command.manifest.items.assets.urlpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
command.manifest.items.assets.url - Usage: mdm_command_result
unmapped.command.manifest.items.metadata.bundleIdentifier
- Description: JumpCloud Directory Insights field
command.manifest.items.metadata.bundleIdentifierpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
command.manifest.items.metadata.bundleIdentifier - Usage: mdm_command_result
unmapped.command.manifest.items.metadata.bundleVersion
- Description: JumpCloud Directory Insights field
command.manifest.items.metadata.bundleVersionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
command.manifest.items.metadata.bundleVersion - Usage: mdm_command_result
unmapped.command.manifest.items.metadata.kind
- Description: JumpCloud Directory Insights field
command.manifest.items.metadata.kindpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
command.manifest.items.metadata.kind - Usage: mdm_command_result
unmapped.command.manifest.items.metadata.subtitle
- Description: JumpCloud Directory Insights field
command.manifest.items.metadata.subtitlepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
command.manifest.items.metadata.subtitle - Usage: mdm_command_result
unmapped.command.manifest.items.metadata.title
- Description: JumpCloud Directory Insights field
command.manifest.items.metadata.titlepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
command.manifest.items.metadata.title - Usage: mdm_command_result
unmapped.command.new_password
- Description: JumpCloud Directory Insights field
command.new_passwordpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
command.new_password - Usage: mdm_command_result
unmapped.command.queries
- Description: JumpCloud Directory Insights field
command.queriespreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
command.queries - Usage: mdm_command_result
unmapped.command_uuid
- Description: JumpCloud Directory Insights field
command_uuidpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
command_uuid - Usage: apple_ddm_status_receive, apple_mdm_service_discovery, apple_policy_dispatch, configuration_file_download, device_enrollment, mdm_command_result
unmapped.enabled
- Description: JumpCloud Directory Insights field
enabledpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
enabled - Usage: apple_mdm_service_discovery
unmapped.error_chain
- Description: JumpCloud Directory Insights field
error_chainpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
error_chain - Usage: apple_ddm_status_receive, apple_mdm_service_discovery, apple_policy_dispatch, configuration_file_download, device_enrollment, mdm_command_result
unmapped.geoip.city
- Description: JumpCloud Directory Insights field
geoip.citypreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.city - Usage: mdm_command_result
unmapped.geoip.continent_code
- Description: JumpCloud Directory Insights field
geoip.continent_codepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.continent_code - Usage: mdm_command_result
unmapped.geoip.country_code
- Description: JumpCloud Directory Insights field
geoip.country_codepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.country_code - Usage: mdm_command_result
unmapped.geoip.latitude
- Description: JumpCloud Directory Insights field
geoip.latitudepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.latitude - Usage: mdm_command_result
unmapped.geoip.longitude
- Description: JumpCloud Directory Insights field
geoip.longitudepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.longitude - Usage: mdm_command_result
unmapped.geoip.region_code
- Description: JumpCloud Directory Insights field
geoip.region_codepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.region_code - Usage: mdm_command_result
unmapped.geoip.region_name
- Description: JumpCloud Directory Insights field
geoip.region_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.region_name - Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost, configuration_file_download, device_enrollment, mdm_command_result
unmapped.geoip.timezone
- Description: JumpCloud Directory Insights field
geoip.timezonepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.timezone - Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost, configuration_file_download, device_enrollment, mdm_command_result
unmapped.initiated_by
- Description: JumpCloud Directory Insights field
initiated_bypreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by - Usage: apple_ddm_status_receive, apple_mdm_service_discovery, apple_policy_dispatch, mdm_command_result
unmapped.initiated_by.provider
- Description: JumpCloud Directory Insights field
initiated_by.providerpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by.provider - Usage: applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost
unmapped.initiated_by_email_hash
- Description: JumpCloud Directory Insights field
initiated_by_email_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_email_hash - Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost, configuration_file_download, device_enrollment
unmapped.initiated_by_id_hash
- Description: JumpCloud Directory Insights field
initiated_by_id_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_id_hash - Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost
unmapped.initiated_by_name_hash
- Description: JumpCloud Directory Insights field
initiated_by_name_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_name_hash - Usage: device_enrollment
unmapped.initiated_by_type
- Description: JumpCloud Directory Insights field
initiated_by_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_type - Usage: apple_ddm_status_receive, apple_mdm_service_discovery, apple_policy_dispatch, configuration_file_download, device_enrollment, mdm_command_result
unmapped.is_out_of_bound
- Description: JumpCloud Directory Insights field
is_out_of_boundpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
is_out_of_bound - Usage: apple_ddm_status_receive, apple_mdm_service_discovery, apple_policy_dispatch, applemdm_commands_clearactivationlock, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost, configuration_file_download, device_enrollment, mdm_command_result
unmapped.jc_application_name
- Description: JumpCloud Directory Insights field
jc_application_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_application_name - Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost
unmapped.jc_initiated_by_email
- Description: JumpCloud Directory Insights field
jc_initiated_by_emailpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_initiated_by_email - Usage: configuration_file_download
unmapped.jc_initiated_by_username
- Description: JumpCloud Directory Insights field
jc_initiated_by_usernamepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_initiated_by_username - Usage: configuration_file_download
unmapped.jc_organization_name
- Description: JumpCloud Directory Insights field
jc_organization_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_organization_name - Usage: configuration_file_download
unmapped.jc_system_display_name
- Description: JumpCloud Directory Insights field
jc_system_display_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_system_display_name - Usage: configuration_file_download
unmapped.jc_system_hostname
- Description: JumpCloud Directory Insights field
jc_system_hostnamepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_system_hostname - Usage: configuration_file_download
unmapped.mdm_device_manager_id
- Description: JumpCloud Directory Insights field
mdm_device_manager_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
mdm_device_manager_id - Usage: apple_ddm_status_receive, apple_mdm_service_discovery, apple_policy_dispatch, mdm_command_result
unmapped.policy_id
- Description: JumpCloud Directory Insights field
policy_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
policy_id - Usage: apple_policy_dispatch
unmapped.provider
- Description: JumpCloud Directory Insights field
providerpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
provider - Usage: applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost
unmapped.query_responses.available_device_capacity
- Description: JumpCloud Directory Insights field
query_responses.available_device_capacitypreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
query_responses.available_device_capacity - Usage: mdm_command_result
unmapped.query_responses.device_capacity
- Description: JumpCloud Directory Insights field
query_responses.device_capacitypreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
query_responses.device_capacity - Usage: mdm_command_result
unmapped.query_responses.device_name
- Description: JumpCloud Directory Insights field
query_responses.device_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
query_responses.device_name - Usage: mdm_command_result
unmapped.query_responses.is_apple_silicon
- Description: JumpCloud Directory Insights field
query_responses.is_apple_siliconpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
query_responses.is_apple_silicon - Usage: mdm_command_result
unmapped.query_responses.is_supervised
- Description: JumpCloud Directory Insights field
query_responses.is_supervisedpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
query_responses.is_supervised - Usage: mdm_command_result
unmapped.query_responses.mdm_options
- Description: JumpCloud Directory Insights field
query_responses.mdm_optionspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
query_responses.mdm_options - Usage: mdm_command_result
unmapped.query_responses.model_name
- Description: JumpCloud Directory Insights field
query_responses.model_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
query_responses.model_name - Usage: mdm_command_result
unmapped.query_responses.os_version
- Description: JumpCloud Directory Insights field
query_responses.os_versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
query_responses.os_version - Usage: mdm_command_result
unmapped.query_responses.product_name
- Description: JumpCloud Directory Insights field
query_responses.product_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
query_responses.product_name - Usage: mdm_command_result
unmapped.request_type
- Description: JumpCloud Directory Insights field
request_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
request_type - Usage: apple_ddm_status_receive, apple_mdm_service_discovery, configuration_file_download, device_enrollment
unmapped.resource_id_hash
- Description: JumpCloud Directory Insights field
resource_id_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource_id_hash - Usage: applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch
unmapped.security_info.is_recovery_lock_enabled
- Description: JumpCloud Directory Insights field
security_info.is_recovery_lock_enabledpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
security_info.is_recovery_lock_enabled - Usage: mdm_command_result
unmapped.security_info.management_status.enrolled_via_dep
- Description: JumpCloud Directory Insights field
security_info.management_status.enrolled_via_deppreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
security_info.management_status.enrolled_via_dep - Usage: mdm_command_result
unmapped.security_info.management_status.is_activation_lock_manageable
- Description: JumpCloud Directory Insights field
security_info.management_status.is_activation_lock_manageablepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
security_info.management_status.is_activation_lock_manageable - Usage: mdm_command_result
unmapped.security_info.management_status.is_user_enrollment
- Description: JumpCloud Directory Insights field
security_info.management_status.is_user_enrollmentpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
security_info.management_status.is_user_enrollment - Usage: mdm_command_result
unmapped.security_info.management_status.user_approved_enrollment
- Description: JumpCloud Directory Insights field
security_info.management_status.user_approved_enrollmentpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
security_info.management_status.user_approved_enrollment - Usage: mdm_command_result
unmapped.security_info.secure_boot.secure_boot_level
- Description: JumpCloud Directory Insights field
security_info.secure_boot.secure_boot_levelpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
security_info.secure_boot.secure_boot_level - Usage: mdm_command_result
unmapped.status_report.Errors.Reasons.Code
- Description: JumpCloud Directory Insights field
status_report.Errors.Reasons.Codepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.Errors.Reasons.Code - Usage: apple_ddm_status_receive
unmapped.status_report.Errors.Reasons.Description
- Description: JumpCloud Directory Insights field
status_report.Errors.Reasons.Descriptionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.Errors.Reasons.Description - Usage: apple_ddm_status_receive
unmapped.status_report.Errors.StatusItem
- Description: JumpCloud Directory Insights field
status_report.Errors.StatusItempreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.Errors.StatusItem - Usage: apple_ddm_status_receive
unmapped.status_report.FullReport
- Description: JumpCloud Directory Insights field
status_report.FullReportpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.FullReport - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.account.list.caldav
- Description: JumpCloud Directory Insights field
status_report.StatusItems.account.list.caldavpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.account.list.caldav - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.account.list.carddav
- Description: JumpCloud Directory Insights field
status_report.StatusItems.account.list.carddavpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.account.list.carddav - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.account.list.exchange
- Description: JumpCloud Directory Insights field
status_report.StatusItems.account.list.exchangepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.account.list.exchange - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.account.list.google
- Description: JumpCloud Directory Insights field
status_report.StatusItems.account.list.googlepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.account.list.google - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.account.list.ldap
- Description: JumpCloud Directory Insights field
status_report.StatusItems.account.list.ldappreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.account.list.ldap - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.account.list.mail.incoming
- Description: JumpCloud Directory Insights field
status_report.StatusItems.account.list.mail.incomingpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.account.list.mail.incoming - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.account.list.mail.outgoing
- Description: JumpCloud Directory Insights field
status_report.StatusItems.account.list.mail.outgoingpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.account.list.mail.outgoing - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.account.list.subscribed-calendar
- Description: JumpCloud Directory Insights field
status_report.StatusItems.account.list.subscribed-calendarpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.account.list.subscribed-calendar - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.app.managed.list
- Description: JumpCloud Directory Insights field
status_report.StatusItems.app.managed.listpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.app.managed.list - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.device.identifier.serial-number
- Description: JumpCloud Directory Insights field
status_report.StatusItems.device.identifier.serial-numberpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.device.identifier.serial-number - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.device.identifier.udid
- Description: JumpCloud Directory Insights field
status_report.StatusItems.device.identifier.udidpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.device.identifier.udid - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.device.model.family
- Description: JumpCloud Directory Insights field
status_report.StatusItems.device.model.familypreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.device.model.family - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.device.model.identifier
- Description: JumpCloud Directory Insights field
status_report.StatusItems.device.model.identifierpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.device.model.identifier - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.device.model.marketing-name
- Description: JumpCloud Directory Insights field
status_report.StatusItems.device.model.marketing-namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.device.model.marketing-name - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.device.model.number
- Description: JumpCloud Directory Insights field
status_report.StatusItems.device.model.numberpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.device.model.number - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.device.operating-system.build-version
- Description: JumpCloud Directory Insights field
status_report.StatusItems.device.operating-system.build-versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.device.operating-system.build-version - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.device.operating-system.family
- Description: JumpCloud Directory Insights field
status_report.StatusItems.device.operating-system.familypreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.device.operating-system.family - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.device.operating-system.marketing-name
- Description: JumpCloud Directory Insights field
status_report.StatusItems.device.operating-system.marketing-namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.device.operating-system.marketing-name - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.device.operating-system.supplemental.build-version
- Description: JumpCloud Directory Insights field
status_report.StatusItems.device.operating-system.supplemental.build-versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.device.operating-system.supplemental.build-version - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.device.operating-system.supplemental.extra-version
- Description: JumpCloud Directory Insights field
status_report.StatusItems.device.operating-system.supplemental.extra-versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.device.operating-system.supplemental.extra-version - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.device.operating-system.version
- Description: JumpCloud Directory Insights field
status_report.StatusItems.device.operating-system.versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.device.operating-system.version - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.diskmanagement.filevault.enabled
- Description: JumpCloud Directory Insights field
status_report.StatusItems.diskmanagement.filevault.enabledpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.diskmanagement.filevault.enabled - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.management.client-capabilities.supported-features
- Description: JumpCloud Directory Insights field
status_report.StatusItems.management.client-capabilities.supported-featurespreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.management.client-capabilities.supported-features - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.management.client-capabilities.supported-payloads.declarations.activations
- Description: JumpCloud Directory Insights field
status_report.StatusItems.management.client-capabilities.supported-payloads.declarations.activationspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.management.client-capabilities.supported-payloads.declarations.activations - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.management.client-capabilities.supported-payloads.declarations.assets
- Description: JumpCloud Directory Insights field
status_report.StatusItems.management.client-capabilities.supported-payloads.declarations.assetspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.management.client-capabilities.supported-payloads.declarations.assets - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.management.client-capabilities.supported-payloads.declarations.configurations
- Description: JumpCloud Directory Insights field
status_report.StatusItems.management.client-capabilities.supported-payloads.declarations.configurationspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.management.client-capabilities.supported-payloads.declarations.configurations - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.management.client-capabilities.supported-payloads.declarations.management
- Description: JumpCloud Directory Insights field
status_report.StatusItems.management.client-capabilities.supported-payloads.declarations.managementpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.management.client-capabilities.supported-payloads.declarations.management - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.management.client-capabilities.supported-payloads.status-items
- Description: JumpCloud Directory Insights field
status_report.StatusItems.management.client-capabilities.supported-payloads.status-itemspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.management.client-capabilities.supported-payloads.status-items - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.management.client-capabilities.supported-versions
- Description: JumpCloud Directory Insights field
status_report.StatusItems.management.client-capabilities.supported-versionspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.management.client-capabilities.supported-versions - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.management.declarations.activations.active
- Description: JumpCloud Directory Insights field
status_report.StatusItems.management.declarations.activations.activepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.management.declarations.activations.active - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.management.declarations.activations.identifier
- Description: JumpCloud Directory Insights field
status_report.StatusItems.management.declarations.activations.identifierpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.management.declarations.activations.identifier - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.management.declarations.activations.server-token
- Description: JumpCloud Directory Insights field
status_report.StatusItems.management.declarations.activations.server-tokenpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.management.declarations.activations.server-token - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.management.declarations.activations.valid
- Description: JumpCloud Directory Insights field
status_report.StatusItems.management.declarations.activations.validpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.management.declarations.activations.valid - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.management.declarations.assets
- Description: JumpCloud Directory Insights field
status_report.StatusItems.management.declarations.assetspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.management.declarations.assets - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.management.declarations.configurations.active
- Description: JumpCloud Directory Insights field
status_report.StatusItems.management.declarations.configurations.activepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.management.declarations.configurations.active - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.management.declarations.configurations.identifier
- Description: JumpCloud Directory Insights field
status_report.StatusItems.management.declarations.configurations.identifierpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.management.declarations.configurations.identifier - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.management.declarations.configurations.server-token
- Description: JumpCloud Directory Insights field
status_report.StatusItems.management.declarations.configurations.server-tokenpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.management.declarations.configurations.server-token - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.management.declarations.configurations.valid
- Description: JumpCloud Directory Insights field
status_report.StatusItems.management.declarations.configurations.validpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.management.declarations.configurations.valid - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.management.declarations.management
- Description: JumpCloud Directory Insights field
status_report.StatusItems.management.declarations.managementpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.management.declarations.management - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.mdm.app._removed
- Description: JumpCloud Directory Insights field
status_report.StatusItems.mdm.app._removedpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.mdm.app._removed - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.mdm.app.external-version-id
- Description: JumpCloud Directory Insights field
status_report.StatusItems.mdm.app.external-version-idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.mdm.app.external-version-id - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.mdm.app.identifier
- Description: JumpCloud Directory Insights field
status_report.StatusItems.mdm.app.identifierpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.mdm.app.identifier - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.mdm.app.name
- Description: JumpCloud Directory Insights field
status_report.StatusItems.mdm.app.namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.mdm.app.name - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.mdm.app.short-version
- Description: JumpCloud Directory Insights field
status_report.StatusItems.mdm.app.short-versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.mdm.app.short-version - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.mdm.app.state
- Description: JumpCloud Directory Insights field
status_report.StatusItems.mdm.app.statepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.mdm.app.state - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.mdm.app.version
- Description: JumpCloud Directory Insights field
status_report.StatusItems.mdm.app.versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.mdm.app.version - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.package.list
- Description: JumpCloud Directory Insights field
status_report.StatusItems.package.listpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.package.list - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.passcode.is-compliant
- Description: JumpCloud Directory Insights field
status_report.StatusItems.passcode.is-compliantpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.passcode.is-compliant - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.passcode.is-present
- Description: JumpCloud Directory Insights field
status_report.StatusItems.passcode.is-presentpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.passcode.is-present - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.services.background-task.code-signature
- Description: JumpCloud Directory Insights field
status_report.StatusItems.services.background-task.code-signaturepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.services.background-task.code-signature - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.services.background-task.identifier
- Description: JumpCloud Directory Insights field
status_report.StatusItems.services.background-task.identifierpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.services.background-task.identifier - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.services.background-task.launchd.checksum
- Description: JumpCloud Directory Insights field
status_report.StatusItems.services.background-task.launchd.checksumpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.services.background-task.launchd.checksum - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.services.background-task.launchd.label
- Description: JumpCloud Directory Insights field
status_report.StatusItems.services.background-task.launchd.labelpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.services.background-task.launchd.label - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.services.background-task.launchd.program
- Description: JumpCloud Directory Insights field
status_report.StatusItems.services.background-task.launchd.programpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.services.background-task.launchd.program - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.services.background-task.launchd.program-arguments
- Description: JumpCloud Directory Insights field
status_report.StatusItems.services.background-task.launchd.program-argumentspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.services.background-task.launchd.program-arguments - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.services.background-task.path
- Description: JumpCloud Directory Insights field
status_report.StatusItems.services.background-task.pathpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.services.background-task.path - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.services.background-task.state
- Description: JumpCloud Directory Insights field
status_report.StatusItems.services.background-task.statepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.services.background-task.state - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.services.background-task.type
- Description: JumpCloud Directory Insights field
status_report.StatusItems.services.background-task.typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.services.background-task.type - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.services.background-task.uid
- Description: JumpCloud Directory Insights field
status_report.StatusItems.services.background-task.uidpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.services.background-task.uid - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.softwareupdate.beta-enrollment
- Description: JumpCloud Directory Insights field
status_report.StatusItems.softwareupdate.beta-enrollmentpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.softwareupdate.beta-enrollment - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.softwareupdate.device-id
- Description: JumpCloud Directory Insights field
status_report.StatusItems.softwareupdate.device-idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.softwareupdate.device-id - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.softwareupdate.failure-reason.count
- Description: JumpCloud Directory Insights field
status_report.StatusItems.softwareupdate.failure-reason.countpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.softwareupdate.failure-reason.count - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.softwareupdate.failure-reason.reason
- Description: JumpCloud Directory Insights field
status_report.StatusItems.softwareupdate.failure-reason.reasonpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.softwareupdate.failure-reason.reason - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.softwareupdate.failure-reason.timestamp
- Description: JumpCloud Directory Insights field
status_report.StatusItems.softwareupdate.failure-reason.timestamppreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.softwareupdate.failure-reason.timestamp - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.softwareupdate.install-reason.reason
- Description: JumpCloud Directory Insights field
status_report.StatusItems.softwareupdate.install-reason.reasonpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.softwareupdate.install-reason.reason - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.softwareupdate.install-state
- Description: JumpCloud Directory Insights field
status_report.StatusItems.softwareupdate.install-statepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.softwareupdate.install-state - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.softwareupdate.pending-version.build-version
- Description: JumpCloud Directory Insights field
status_report.StatusItems.softwareupdate.pending-version.build-versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.softwareupdate.pending-version.build-version - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.softwareupdate.pending-version.os-version
- Description: JumpCloud Directory Insights field
status_report.StatusItems.softwareupdate.pending-version.os-versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.softwareupdate.pending-version.os-version - Usage: apple_ddm_status_receive
unmapped.status_report.StatusItems.softwareupdate.pending-version.softwareupdate.target-local-date-time
- Description: JumpCloud Directory Insights field
status_report.StatusItems.softwareupdate.pending-version.softwareupdate.target-local-date-timepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
status_report.StatusItems.softwareupdate.pending-version.softwareupdate.target-local-date-time - Usage: apple_ddm_status_receive
unmapped.system_id
- Description: JumpCloud Directory Insights field
system_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
system_id - Usage: apple_ddm_status_receive, apple_policy_dispatch
unmapped.timestamp_source
- Description: JumpCloud Directory Insights field
timestamp_sourcepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
timestamp_source - Usage: configuration_file_download
unmapped.useragent.device
- Description: JumpCloud Directory Insights field
useragent.devicepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.device - Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost
unmapped.useragent.major
- Description: JumpCloud Directory Insights field
useragent.majorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.major - Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost
unmapped.useragent.minor
- Description: JumpCloud Directory Insights field
useragent.minorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.minor - Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost
unmapped.useragent.name
- Description: JumpCloud Directory Insights field
useragent.namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.name - Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost
unmapped.useragent.os
- Description: JumpCloud Directory Insights field
useragent.ospreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os - Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost
unmapped.useragent.os_full
- Description: JumpCloud Directory Insights field
useragent.os_fullpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_full - Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost
unmapped.useragent.os_major
- Description: JumpCloud Directory Insights field
useragent.os_majorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_major - Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost
unmapped.useragent.os_minor
- Description: JumpCloud Directory Insights field
useragent.os_minorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_minor - Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost
unmapped.useragent.os_name
- Description: JumpCloud Directory Insights field
useragent.os_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_name - Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_create, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost
unmapped.useragent.os_patch
- Description: JumpCloud Directory Insights field
useragent.os_patchpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_patch - Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost
unmapped.useragent.os_version
- Description: JumpCloud Directory Insights field
useragent.os_versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_version - Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost
unmapped.useragent.patch
- Description: JumpCloud Directory Insights field
useragent.patchpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.patch - Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost
unmapped.useragent.version
- Description: JumpCloud Directory Insights field
useragent.versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.version - Usage: applemdm_commands_clearactivationlock, applemdm_devicemanagers_delete, applemdm_devicemanagers_patch, applemdm_volumepurchaseprogram_locationspost
Notifications#
notifications · 8 events
| Event | Category | Class | Activity | Type UID | Fields |
|---|---|---|---|---|---|
notification_channel_created |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 62 |
notification_channel_deleted |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 60 |
notification_channel_updated |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 71 |
notification_send_emails_from_role_failure |
Application Activity (6) | Application Error (6008) | General Error (1) | 600801 | 41 |
notification_send_failure |
Application Activity (6) | Application Error (6008) | General Error (1) | 600801 | 31 |
notification_send_org_rate_limit_reached |
Application Activity (6) | Application Error (6008) | General Error (1) | 600801 | 33 |
notification_triggered_by_webhook |
Network Activity (4) | Email Activity (4009) | Send (1) | 400901 | 36 |
slack_notification_sent |
Network Activity (4) | Email Activity (4009) | Send (1) | 400901 | 36 |
OCSF field mappings#
Legend
- Description: what the OCSF field represents (from OCSF schema v1.8.0)
- Source: raw JumpCloud event field(s) mapped via
${{placeholder}}template - Transform:
fieldMappingsentry applied at runtime (cast, enum, etc.) - Literal: static value set in the mapping template
- Usage: event types in this service that include this field
Core
activity_id
- Description: The normalized identifier of the activity that triggered the event.
- Literal:
1,3,4 - Usage: all events in this service
activity_name
- Description: The event activity name, as defined by the activity_id.
- Literal:
Create,Delete,General Error,Send,Update - Usage: all events in this service
category_name
- Description: The event category name, as defined by category_uid value:
Discovery. - Literal:
Application Activity,Identity & Access Management,Network Activity - Usage: all events in this service
category_uid
- Description: The category unique identifier of the event.
- Literal:
3,4,6 - Usage: all events in this service
class_name
- Description: The event class name, as defined by class_uid value:
User Inventory Info. - Literal:
Application Error,Email Activity,Entity Management - Usage: all events in this service
class_uid
- Description: The unique identifier of a class. A class describes the attributes available in an event.
- Literal:
3004,4009,6008 - Usage: all events in this service
severity_id
- Description: OCSF severity identifier for the event.
- Literal:
1 - Usage: all events in this service
status_detail
- Description: The status detail contains additional information about the event/finding outcome.
- Source:
error,error_message - Usage: all events in this service
status_id
- Description: Normalized status of the activity (1=Success, 2=Failure).
- Source:
success - Transform:
success→boolean_to_status_id; true→1, false→2 (all events in this service)- Usage: all events in this service
time
- Description: Event time, in epoch milliseconds (OCSF
time). - Source:
timestamp - Transform:
timestamp→iso8601_to_epoch_millis(all events in this service)- Usage: all events in this service
type_uid
- Description: The event/finding type ID. It identifies the event's semantics and structure. The value is calculated by the logging system as:
class_uid * 100 + activity_id. - Literal:
300401,300403,300404,400901,600801 - Usage: all events in this service
Metadata
metadata.event_code
- Description: JumpCloud event type code.
- Source:
event_type - Usage: all events in this service
metadata.original_time
- Description: The original event time as reported by the event source. For example, the time in the original format from system event log such as Syslog on Unix/Linux and the System event file on Windows. Omit if event is generated instead of collected via logs.
- Source:
server_timestamp - Usage: all events in this service
metadata.product.name
- Description: Originating JumpCloud service that produced the event.
- Source:
service - Usage: all events in this service
metadata.tenant_uid
- Description: JumpCloud organization (tenant) identifier.
- Source:
organization - Usage: all events in this service
metadata.uid
- Description: Unique event identifier assigned by JumpCloud.
- Source:
id - Usage: all events in this service
metadata.version
- Description: OCSF schema version used for this event.
- Literal:
1.8.0 - Usage: all events in this service
Actor
actor.user.email_addr
- Description: Email address of the actor who initiated the event.
- Source:
initiated_by.email - Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated
actor.user.type_id
- Description: OCSF user type of the actor (1=User, 2=Admin, 3=System, 4=Service).
- Source:
initiated_by.type - Transform:
initiated_by.type→enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (notification_channel_created, notification_channel_deleted, notification_channel_updated)- Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated
actor.user.uid
- Description: Unique identifier of the actor who initiated the event.
- Source:
initiated_by.id - Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated
Entity
entity.data.address
- Description: JumpCloud extension data on the managed entity:
address. - Source:
config.address - Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated
entity.data.changed_field
- Description: JumpCloud extension data on the managed entity:
changed_field. - Source:
changes.field - Usage: notification_channel_updated
entity.data.changes_from
- Description: JumpCloud extension data on the managed entity:
changes_from. - Source:
changes.from - Usage: notification_channel_updated
entity.data.changes_removed.address
- Description: JumpCloud extension data on the managed entity:
changes_removed.address. - Source:
changes.removed.address - Usage: notification_channel_updated
entity.data.changes_removed.name
- Description: JumpCloud extension data on the managed entity:
changes_removed.name. - Source:
changes.removed.name - Usage: notification_channel_updated
entity.data.changes_removed.object_id
- Description: JumpCloud extension data on the managed entity:
changes_removed.object_id. - Source:
changes.removed.object_id - Usage: notification_channel_updated
entity.data.correlation.id
- Description: JumpCloud extension data on the managed entity:
correlation.id. - Source:
correlation.id - Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated
entity.data.description
- Description: JumpCloud extension data on the managed entity:
description. - Source:
resource.description - Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated
entity.data.name
- Description: JumpCloud extension data on the managed entity:
name. - Source:
config.name - Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated
entity.data.object_id
- Description: JumpCloud extension data on the managed entity:
object_id. - Source:
config.object_id - Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated
entity.data.role_object_id
- Description: JumpCloud extension data on the managed entity:
role_object_id. - Source:
config.role_object_id - Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated
entity.name
- Description: The name of the managed entity. It should match the name of the specific entity object's name if populated, or the name of the managed entity if the
type_idis 'Other'. - Source:
resource.name - Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated
entity.type
- Description: The managed entity type. For example:
Policy,User,Organization,Device. - Source:
resource.type - Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated
entity.uid
- Description: The identifier of the managed entity. It should match the
uidof the specific entity's object UID if populated, or the source specific ID if thetype_idis 'Other'. - Source:
resource.id - Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated
entity_result.data.changes_added.address
- Description: JumpCloud extension data on the managed entity:
changes_added.address. - Source:
changes.added.address - Usage: notification_channel_updated
entity_result.data.changes_added.name
- Description: JumpCloud extension data on the managed entity:
changes_added.name. - Source:
changes.added.name - Usage: notification_channel_updated
entity_result.data.changes_added.object_id
- Description: JumpCloud extension data on the managed entity:
changes_added.object_id. - Source:
changes.added.object_id - Usage: notification_channel_updated
entity_result.data.changes_added.role_object_id
- Description: JumpCloud extension data on the managed entity:
changes_added.role_object_id. - Source:
changes.added.role_object_id - Usage: notification_channel_updated
entity_result.data.changes_to
- Description: JumpCloud extension data on the managed entity:
changes_to. - Source:
changes.to - Usage: notification_channel_updated
Src Endpoint
src_endpoint.autonomous_system.name
- Description: Organization name for the Autonomous System.
- Source:
asn.organization - Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated
src_endpoint.autonomous_system.number
- Description: Unique number that the AS is identified by.
- Source:
asn.number - Transform:
asn.number→int(notification_channel_created, notification_channel_deleted, notification_channel_updated)- Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated
src_endpoint.ip
- Description: Source IP address the request originated from.
- Source:
client_ip - Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated, notification_triggered_by_webhook, slack_notification_sent
src_endpoint.location.city
- Description: The name of the city.
- Source:
geoip.city - Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated
src_endpoint.location.continent
- Description: The name of the continent.
- Source:
geoip.continent_code - Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated
src_endpoint.location.country
- Description: The ISO 3166-1 Alpha-2 country code.
Note: The two letter country code should be capitalized. For example:
USorCA. - Source:
geoip.country_code - Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated
src_endpoint.location.lat
- Description: The geographical Latitude coordinate represented in Decimal Degrees (DD). For example:
42.361145. - Source:
geoip.latitude - Transform:
geoip.latitude→double(notification_channel_created, notification_channel_deleted, notification_channel_updated)- Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated
src_endpoint.location.long
- Description: The geographical Longitude coordinate represented in Decimal Degrees (DD). For example:
-71.057083. - Source:
geoip.longitude - Transform:
geoip.longitude→double(notification_channel_created, notification_channel_deleted, notification_channel_updated)- Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated
src_endpoint.location.region
- Description: The alphanumeric code that identifies the principal subdivision (e.g. province or state) of the country. For example, 'CH-VD' for the Canton of Vaud, Switzerland
- Source:
geoip.region_code - Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated
Http Request
http_request.user_agent
- Description: The request header that identifies the operating system and web browser.
- Source:
user_agent - Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated
Observables
observables[].name
- Description: The full name of the observable attribute. The
nameis a pointer/reference to an attribute within the OCSF event data. For example:file.name. Array attributes may be represented in one of three ways. For example:resources.uid,resources[].uid,resources[0].uid. - Literal:
actor.user.email_addr,actor.user.uid,http_request.user_agent,src_endpoint.ip,src_endpoint.location.country - Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated, notification_triggered_by_webhook, slack_notification_sent
observables[].type_id
- Description: The observable value type identifier.
- Literal:
14,16,2,31,5 - Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated, notification_triggered_by_webhook, slack_notification_sent
observables[].value
- Description: The value associated with the observable attribute. The meaning of the value depends on the observable type.
If thenamerefers to a scalar attribute, then thevalueis the value of the attribute.
If thenamerefers to an object attribute, then thevalueis not populated. - Source:
client_ip,geoip.country_code,initiated_by.email,initiated_by.id,user_agent - Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated, notification_triggered_by_webhook, slack_notification_sent
Other
direction_id
- Description:
The direction of the email relative to the scanning host or organization.
Email scanned at an internet gateway might be characterized as inbound to the organization from the Internet, outbound from the organization to the Internet, or internal within the organization. Email scanned at a workstation might be characterized as inbound to, or outbound from the workstation. - Usage: notification_triggered_by_webhook, slack_notification_sent
Unmapped
unmapped.@version
- Description: JumpCloud Directory Insights field
@versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
@version - Usage: all events in this service
unmapped.asn.network
- Description: JumpCloud Directory Insights field
asn.networkpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
asn.network - Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated
unmapped.client_ip
- Description: JumpCloud Directory Insights field
client_ippreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
client_ip - Usage: notification_send_emails_from_role_failure, notification_send_failure, notification_send_org_rate_limit_reached
unmapped.error_message
- Description: JumpCloud Directory Insights field
error_messagepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
error_message - Usage: notification_send_emails_from_role_failure, notification_send_failure, notification_send_org_rate_limit_reached
unmapped.file_input_timestamp
- Description: JumpCloud Directory Insights field
file_input_timestamppreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
file_input_timestamp - Usage: notification_channel_created
unmapped.geoip.region_name
- Description: JumpCloud Directory Insights field
geoip.region_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.region_name - Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated
unmapped.geoip.timezone
- Description: JumpCloud Directory Insights field
geoip.timezonepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.timezone - Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated
unmapped.initiated_by
- Description: JumpCloud Directory Insights field
initiated_bypreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by - Usage: notification_send_emails_from_role_failure, notification_send_failure, notification_send_org_rate_limit_reached, notification_triggered_by_webhook, slack_notification_sent
unmapped.initiated_by_email_hash
- Description: JumpCloud Directory Insights field
initiated_by_email_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_email_hash - Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated
unmapped.initiated_by_id_hash
- Description: JumpCloud Directory Insights field
initiated_by_id_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_id_hash - Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated
unmapped.is_out_of_bound
- Description: JumpCloud Directory Insights field
is_out_of_boundpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
is_out_of_bound - Usage: all events in this service
unmapped.jc_application_name
- Description: JumpCloud Directory Insights field
jc_application_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_application_name - Usage: all events in this service
unmapped.jc_initiated_by_email
- Description: JumpCloud Directory Insights field
jc_initiated_by_emailpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_initiated_by_email - Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated, notification_send_emails_from_role_failure
unmapped.jc_initiated_by_id
- Description: JumpCloud Directory Insights field
jc_initiated_by_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_initiated_by_id - Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated, notification_send_emails_from_role_failure
unmapped.jc_initiated_by_username
- Description: JumpCloud Directory Insights field
jc_initiated_by_usernamepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_initiated_by_username - Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated, notification_send_emails_from_role_failure
unmapped.jc_organization_name
- Description: JumpCloud Directory Insights field
jc_organization_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_organization_name - Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated, notification_send_emails_from_role_failure
unmapped.jc_provider_id
- Description: JumpCloud Directory Insights field
jc_provider_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_provider_id - Usage: notification_channel_created, notification_channel_updated, notification_send_emails_from_role_failure
unmapped.jc_system_display_name
- Description: JumpCloud Directory Insights field
jc_system_display_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_system_display_name - Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated, notification_send_emails_from_role_failure
unmapped.jc_system_hostname
- Description: JumpCloud Directory Insights field
jc_system_hostnamepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_system_hostname - Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated, notification_send_emails_from_role_failure
unmapped.jc_transformation_ts
- Description: JumpCloud Directory Insights field
jc_transformation_tspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_transformation_ts - Usage: all events in this service
unmapped.notification_type
- Description: JumpCloud Directory Insights field
notification_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
notification_type - Usage: notification_send_emails_from_role_failure, notification_send_failure, notification_send_org_rate_limit_reached, notification_triggered_by_webhook, slack_notification_sent
unmapped.resource.id
- Description: JumpCloud Directory Insights field
resource.idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.id - Usage: notification_send_emails_from_role_failure, notification_send_failure, notification_send_org_rate_limit_reached, notification_triggered_by_webhook, slack_notification_sent
unmapped.resource.name
- Description: JumpCloud Directory Insights field
resource.namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.name - Usage: notification_send_emails_from_role_failure, notification_send_failure, notification_send_org_rate_limit_reached, notification_triggered_by_webhook, slack_notification_sent
unmapped.resource.type
- Description: JumpCloud Directory Insights field
resource.typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.type - Usage: notification_send_emails_from_role_failure, notification_send_failure, notification_send_org_rate_limit_reached, notification_triggered_by_webhook, slack_notification_sent
unmapped.resource_id
- Description: JumpCloud Directory Insights field
resource_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource_id - Usage: notification_send_emails_from_role_failure, notification_send_org_rate_limit_reached, notification_triggered_by_webhook, slack_notification_sent
unmapped.resource_id_hash
- Description: JumpCloud Directory Insights field
resource_id_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource_id_hash - Usage: all events in this service
unmapped.resource_name_hash
- Description: JumpCloud Directory Insights field
resource_name_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource_name_hash - Usage: notification_channel_created, notification_channel_deleted, notification_channel_updated, notification_send_emails_from_role_failure
unmapped.resource_type
- Description: JumpCloud Directory Insights field
resource_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource_type - Usage: notification_send_emails_from_role_failure, notification_send_org_rate_limit_reached, notification_triggered_by_webhook, slack_notification_sent
unmapped.timestamp_source
- Description: JumpCloud Directory Insights field
timestamp_sourcepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
timestamp_source - Usage: all events in this service
unmapped.user_agent
- Description: JumpCloud Directory Insights field
user_agentpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
user_agent - Usage: notification_send_emails_from_role_failure, notification_send_failure, notification_send_org_rate_limit_reached, notification_triggered_by_webhook, slack_notification_sent
Object Storage#
object_storage · 4 events
| Event | Category | Class | Activity | Type UID | Fields |
|---|---|---|---|---|---|
object_storage_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 31 |
object_storage_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 61 |
object_storage_get_download_url_request |
Identity & Access Management (3) | Entity Management (3004) | Read (2) | 300402 | 33 |
object_storage_upload_validation_result |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 31 |
OCSF field mappings#
Legend
- Description: what the OCSF field represents (from OCSF schema v1.8.0)
- Source: raw JumpCloud event field(s) mapped via
${{placeholder}}template - Transform:
fieldMappingsentry applied at runtime (cast, enum, etc.) - Literal: static value set in the mapping template
- Usage: event types in this service that include this field
Core
activity_id
- Description: The normalized identifier of the activity that triggered the event.
- Literal:
1,2,4 - Usage: all events in this service
activity_name
- Description: The event activity name, as defined by the activity_id.
- Literal:
Create,Delete,Read - Usage: all events in this service
category_name
- Description: The event category name, as defined by category_uid value:
Discovery. - Literal:
Identity & Access Management - Usage: all events in this service
category_uid
- Description: The category unique identifier of the event.
- Literal:
3 - Usage: all events in this service
class_name
- Description: The event class name, as defined by class_uid value:
User Inventory Info. - Literal:
Entity Management - Usage: all events in this service
class_uid
- Description: The unique identifier of a class. A class describes the attributes available in an event.
- Literal:
3004 - Usage: all events in this service
severity_id
- Description: OCSF severity identifier for the event.
- Literal:
1 - Usage: all events in this service
status_id
- Description: Normalized status of the activity (1=Success, 2=Failure).
- Source:
result - Transform:
result→boolean_to_status_id; true→1, false→2 (object_storage_create, object_storage_delete, object_storage_upload_validation_result)- Usage: object_storage_create, object_storage_delete, object_storage_upload_validation_result
time
- Description: Event time, in epoch milliseconds (OCSF
time). - Source:
timestamp - Transform:
timestamp→iso8601_to_epoch_millis(all events in this service)- Usage: all events in this service
type_uid
- Description: The event/finding type ID. It identifies the event's semantics and structure. The value is calculated by the logging system as:
class_uid * 100 + activity_id. - Literal:
300401,300402,300404 - Usage: all events in this service
Metadata
metadata.event_code
- Description: JumpCloud event type code.
- Source:
event_type - Usage: all events in this service
metadata.original_time
- Description: The original event time as reported by the event source. For example, the time in the original format from system event log such as Syslog on Unix/Linux and the System event file on Windows. Omit if event is generated instead of collected via logs.
- Source:
server_timestamp - Usage: object_storage_delete, object_storage_get_download_url_request, object_storage_upload_validation_result
metadata.processed_time
- Description: The event processed time, such as an ETL operation.
- Source:
jc_transformation_ts - Usage: all events in this service
metadata.product.name
- Description: Originating JumpCloud service that produced the event.
- Source:
service - Usage: all events in this service
metadata.tenant_uid
- Description: JumpCloud organization (tenant) identifier.
- Source:
organization - Usage: all events in this service
metadata.uid
- Description: Unique event identifier assigned by JumpCloud.
- Source:
id - Usage: all events in this service
metadata.version
- Description: OCSF schema version used for this event.
- Literal:
1.8.0 - Usage: all events in this service
Actor
actor.user.email_addr
- Description: Email address of the actor who initiated the event.
- Source:
initiated_by.email - Usage: object_storage_delete
actor.user.type_id
- Description: OCSF user type of the actor (1=User, 2=Admin, 3=System, 4=Service).
- Source:
initiated_by.type - Usage: object_storage_delete
actor.user.uid
- Description: Unique identifier of the actor who initiated the event.
- Source:
initiated_by.id - Usage: object_storage_delete
Entity
entity.data.referrer_object_id
- Description: JumpCloud extension data on the managed entity:
referrer_object_id. - Source:
referrer_object_id - Usage: object_storage_create, object_storage_delete, object_storage_get_download_url_request
entity.data.sha_256_checksum
- Description: JumpCloud extension data on the managed entity:
sha_256_checksum. - Source:
object_storage_item_version_sha_256_sum - Usage: all events in this service
entity.data.system_object_id
- Description: JumpCloud extension data on the managed entity:
system_object_id. - Source:
system_object_id - Usage: object_storage_create, object_storage_get_download_url_request
entity.data.total_software_item_count
- Description: JumpCloud extension data on the managed entity:
total_software_item_count. - Source:
total_software_item_count - Usage: object_storage_create, object_storage_delete
entity.data.total_space_used
- Description: JumpCloud extension data on the managed entity:
total_space_used. - Source:
total_space_used - Usage: object_storage_create, object_storage_delete
entity.data.version_object_id
- Description: JumpCloud extension data on the managed entity:
version_object_id. - Source:
object_storage_item_version_object_id - Usage: all events in this service
entity.data.version_size_bytes
- Description: JumpCloud extension data on the managed entity:
version_size_bytes. - Source:
object_storage_item_version_size - Usage: all events in this service
entity.name
- Description: The name of the managed entity. It should match the name of the specific entity object's name if populated, or the name of the managed entity if the
type_idis 'Other'. - Source:
object_storage_item_version_name - Usage: all events in this service
entity.type
- Description: The managed entity type. For example:
Policy,User,Organization,Device. - Source:
referrer_type - Usage: object_storage_create, object_storage_delete, object_storage_get_download_url_request
entity.uid
- Description: The identifier of the managed entity. It should match the
uidof the specific entity's object UID if populated, or the source specific ID if thetype_idis 'Other'. - Source:
object_storage_item_object_id - Usage: all events in this service
Src Endpoint
src_endpoint.autonomous_system.name
- Description: Organization name for the Autonomous System.
- Source:
asn.organization - Usage: object_storage_delete
src_endpoint.autonomous_system.number
- Description: Unique number that the AS is identified by.
- Source:
asn.number - Usage: object_storage_delete
src_endpoint.ip
- Description: Source IP address the request originated from.
- Source:
client_ip - Usage: object_storage_delete
src_endpoint.location.city
- Description: The name of the city.
- Source:
geoip.city - Usage: object_storage_delete
src_endpoint.location.continent
- Description: The name of the continent.
- Source:
geoip.continent_code - Usage: object_storage_delete
src_endpoint.location.country
- Description: The ISO 3166-1 Alpha-2 country code.
Note: The two letter country code should be capitalized. For example:
USorCA. - Source:
geoip.country_code - Usage: object_storage_delete
src_endpoint.location.lat
- Description: The geographical Latitude coordinate represented in Decimal Degrees (DD). For example:
42.361145. - Source:
geoip.latitude - Transform:
geoip.latitude→double(object_storage_delete)- Usage: object_storage_delete
src_endpoint.location.long
- Description: The geographical Longitude coordinate represented in Decimal Degrees (DD). For example:
-71.057083. - Source:
geoip.longitude - Transform:
geoip.longitude→double(object_storage_delete)- Usage: object_storage_delete
src_endpoint.location.region
- Description: The alphanumeric code that identifies the principal subdivision (e.g. province or state) of the country. For example, 'CH-VD' for the Canton of Vaud, Switzerland
- Source:
geoip.region_code - Usage: object_storage_delete
Http Request
http_request.user_agent
- Description: The request header that identifies the operating system and web browser.
- Source:
user_agent - Usage: object_storage_delete
Observables
observables[].name
- Description: The full name of the observable attribute. The
nameis a pointer/reference to an attribute within the OCSF event data. For example:file.name. Array attributes may be represented in one of three ways. For example:resources.uid,resources[].uid,resources[0].uid. - Literal:
actor.user.email_addr,actor.user.uid,http_request.user_agent,src_endpoint.ip,src_endpoint.location.country - Usage: object_storage_delete
observables[].type_id
- Description: The observable value type identifier.
- Literal:
14,16,2,31,5 - Usage: object_storage_delete
observables[].value
- Description: The value associated with the observable attribute. The meaning of the value depends on the observable type.
If thenamerefers to a scalar attribute, then thevalueis the value of the attribute.
If thenamerefers to an object attribute, then thevalueis not populated. - Source:
client_ip,geoip.country_code,initiated_by.email,initiated_by.id,user_agent - Usage: object_storage_delete
Unmapped
unmapped.@version
- Description: JumpCloud Directory Insights field
@versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
@version - Usage: all events in this service
unmapped.asn.network
- Description: JumpCloud Directory Insights field
asn.networkpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
asn.network - Usage: object_storage_delete
unmapped.client_ip
- Description: JumpCloud Directory Insights field
client_ippreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
client_ip - Usage: object_storage_create, object_storage_get_download_url_request, object_storage_upload_validation_result
unmapped.error_message
- Description: JumpCloud Directory Insights field
error_messagepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
error_message - Usage: all events in this service
unmapped.geoip.region_name
- Description: JumpCloud Directory Insights field
geoip.region_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.region_name - Usage: object_storage_delete
unmapped.geoip.timezone
- Description: JumpCloud Directory Insights field
geoip.timezonepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.timezone - Usage: object_storage_delete
unmapped.initiated_by
- Description: JumpCloud Directory Insights field
initiated_bypreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by - Usage: object_storage_create, object_storage_get_download_url_request, object_storage_upload_validation_result
unmapped.initiated_by_email_hash
- Description: JumpCloud Directory Insights field
initiated_by_email_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_email_hash - Usage: object_storage_delete
unmapped.initiated_by_id_hash
- Description: JumpCloud Directory Insights field
initiated_by_id_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_id_hash - Usage: object_storage_delete
unmapped.is_out_of_bound
- Description: JumpCloud Directory Insights field
is_out_of_boundpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
is_out_of_bound - Usage: object_storage_delete, object_storage_get_download_url_request, object_storage_upload_validation_result
unmapped.jc_application_name
- Description: JumpCloud Directory Insights field
jc_application_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_application_name - Usage: object_storage_delete, object_storage_get_download_url_request, object_storage_upload_validation_result
unmapped.jc_initiated_by_email
- Description: JumpCloud Directory Insights field
jc_initiated_by_emailpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_initiated_by_email - Usage: object_storage_delete
unmapped.jc_initiated_by_id
- Description: JumpCloud Directory Insights field
jc_initiated_by_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_initiated_by_id - Usage: object_storage_delete
unmapped.jc_initiated_by_username
- Description: JumpCloud Directory Insights field
jc_initiated_by_usernamepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_initiated_by_username - Usage: object_storage_delete
unmapped.jc_organization_name
- Description: JumpCloud Directory Insights field
jc_organization_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_organization_name - Usage: object_storage_delete
unmapped.jc_provider_id
- Description: JumpCloud Directory Insights field
jc_provider_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_provider_id - Usage: object_storage_delete
unmapped.jc_system_display_name
- Description: JumpCloud Directory Insights field
jc_system_display_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_system_display_name - Usage: object_storage_delete
unmapped.jc_system_hostname
- Description: JumpCloud Directory Insights field
jc_system_hostnamepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_system_hostname - Usage: object_storage_delete
unmapped.provider
- Description: JumpCloud Directory Insights field
providerpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
provider - Usage: object_storage_delete
unmapped.success
- Description: JumpCloud Directory Insights field
successpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
success - Usage: all events in this service
unmapped.timestamp_source
- Description: JumpCloud Directory Insights field
timestamp_sourcepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
timestamp_source - Usage: object_storage_delete, object_storage_get_download_url_request, object_storage_upload_validation_result
unmapped.user_agent
- Description: JumpCloud Directory Insights field
user_agentpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
user_agent - Usage: object_storage_get_download_url_request, object_storage_upload_validation_result
Password Manager#
password_manager · 72 events
| Event | Category | Class | Activity | Type UID | Fields |
|---|---|---|---|---|---|
passwordmanager_app_unlock |
Identity & Access Management (3) | Authentication (3002) | Logon (1) | 300201 | 52 |
passwordmanager_app_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 51 |
passwordmanager_backup_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 48 |
passwordmanager_backup_disable |
Identity & Access Management (3) | Entity Management (3004) | Disable (9) | 300409 | 58 |
passwordmanager_backup_enable |
Identity & Access Management (3) | Entity Management (3004) | Enable (8) | 300408 | 67 |
passwordmanager_backup_key_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 67 |
passwordmanager_backup_key_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 63 |
passwordmanager_backup_key_regenerate |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 63 |
passwordmanager_backup_request |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 51 |
passwordmanager_backup_request_approve |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 62 |
passwordmanager_backup_request_cancel |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 48 |
passwordmanager_backup_request_reject |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 68 |
passwordmanager_backup_request_restore |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 48 |
passwordmanager_batch_folder_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 55 |
passwordmanager_disable |
Identity & Access Management (3) | Entity Management (3004) | Disable (9) | 300409 | 69 |
passwordmanager_enable |
Identity & Access Management (3) | Entity Management (3004) | Enable (8) | 300408 | 67 |
passwordmanager_extension_pair |
Identity & Access Management (3) | Entity Management (3004) | Enroll (6) | 300406 | 48 |
passwordmanager_extension_settings_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 51 |
passwordmanager_extension_site_exclusion |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 43 |
passwordmanager_extension_unlock |
Identity & Access Management (3) | Entity Management (3004) | Read (2) | 300402 | 48 |
passwordmanager_folder_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 70 |
passwordmanager_folder_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 46 |
passwordmanager_folder_force_sync |
System Activity (1) | Scheduled Job Activity (1006) | Start (6) | 100606 | 43 |
passwordmanager_folder_group_add |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 74 |
passwordmanager_folder_group_remove |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 72 |
passwordmanager_folder_group_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 70 |
passwordmanager_folder_member_add |
Identity & Access Management (3) | Group Management (3006) | Add User (3) | 300603 | 50 |
passwordmanager_folder_member_remove |
Identity & Access Management (3) | Group Management (3006) | Remove User (4) | 300604 | 73 |
passwordmanager_folder_member_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 74 |
passwordmanager_folder_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 69 |
passwordmanager_force_sync |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 52 |
passwordmanager_get_item_secret |
Identity & Access Management (3) | Entity Management (3004) | Read (2) | 300402 | 36 |
passwordmanager_item_add |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 52 |
passwordmanager_item_autofill |
Identity & Access Management (3) | Entity Management (3004) | Read (2) | 300402 | 35 |
passwordmanager_item_copy |
Identity & Access Management (3) | Entity Management (3004) | Read (2) | 300402 | 45 |
passwordmanager_item_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 39 |
passwordmanager_item_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 38 |
passwordmanager_item_history_restore |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 55 |
passwordmanager_item_history_reveal |
Identity & Access Management (3) | Entity Management (3004) | Read (2) | 300402 | 49 |
passwordmanager_item_move |
Identity & Access Management (3) | Entity Management (3004) | Move (5) | 300405 | 58 |
passwordmanager_item_remove |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 52 |
passwordmanager_item_reveal |
Identity & Access Management (3) | Entity Management (3004) | Read (2) | 300402 | 48 |
passwordmanager_item_settings_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 55 |
passwordmanager_item_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 61 |
passwordmanager_items_export |
Identity & Access Management (3) | Entity Management (3004) | Read (2) | 300402 | 43 |
passwordmanager_items_import |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 45 |
passwordmanager_local_backup_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 47 |
passwordmanager_local_backup_path_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 55 |
passwordmanager_local_backup_restore |
System Activity (1) | Scheduled Job Activity (1006) | Start (6) | 100606 | 50 |
passwordmanager_migration_complete |
System Activity (1) | Scheduled Job Activity (1006) | Update (2) | 100602 | 38 |
passwordmanager_migration_start |
System Activity (1) | Scheduled Job Activity (1006) | Start (6) | 100606 | 38 |
passwordmanager_mini_launch |
System Activity (1) | Scheduled Job Activity (1006) | Start (6) | 100606 | 52 |
passwordmanager_paranoid_mode_disable |
Identity & Access Management (3) | Entity Management (3004) | Disable (9) | 300409 | 55 |
passwordmanager_paranoid_mode_enable |
Identity & Access Management (3) | Entity Management (3004) | Enable (8) | 300408 | 55 |
passwordmanager_pincode_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 55 |
passwordmanager_policy_export_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 71 |
passwordmanager_sharedfolders_policy_group_add |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 66 |
passwordmanager_sharedfolders_policy_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 65 |
passwordmanager_sharedfolders_policy_user_add |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 69 |
passwordmanager_sharedfolders_policy_user_remove |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 65 |
passwordmanager_user_activate |
Identity & Access Management (3) | Account Change (3001) | Enable (2) | 300102 | 52 |
passwordmanager_user_deactivate |
Identity & Access Management (3) | Account Change (3001) | Disable (5) | 300105 | 53 |
passwordmanager_user_device_pair |
Identity & Access Management (3) | Account Change (3001) | Other (99) | 300199 | 48 |
passwordmanager_user_device_unpair |
Identity & Access Management (3) | Account Change (3001) | Other (99) | 300199 | 53 |
passwordmanager_user_disable |
Identity & Access Management (3) | Account Change (3001) | Disable (5) | 300105 | 39 |
passwordmanager_user_enable |
Identity & Access Management (3) | Account Change (3001) | Enable (2) | 300102 | 45 |
passwordmanager_user_migration |
Identity & Access Management (3) | Account Change (3001) | Other (99) | 300199 | 40 |
passwordmanager_user_re-enable |
Identity & Access Management (3) | Account Change (3001) | Enable (2) | 300102 | 43 |
passwordmanager_user_reactivate |
Identity & Access Management (3) | Account Change (3001) | Enable (2) | 300102 | 55 |
passwordmanager_user_remove |
Identity & Access Management (3) | Account Change (3001) | Delete (6) | 300106 | 34 |
passwordmanager_user_signup |
Identity & Access Management (3) | Account Change (3001) | Create (1) | 300101 | 53 |
passwordmanager_user_update |
Identity & Access Management (3) | Account Change (3001) | Other (99) | 300199 | 40 |
OCSF field mappings#
Legend
- Description: what the OCSF field represents (from OCSF schema v1.8.0)
- Source: raw JumpCloud event field(s) mapped via
${{placeholder}}template - Transform:
fieldMappingsentry applied at runtime (cast, enum, etc.) - Literal: static value set in the mapping template
- Usage: event types in this service that include this field
Core
activity_id
- Description: The normalized identifier of the activity that triggered the event.
- Literal:
1,2,3,4,5,6,8,9,99 - Usage: all events in this service
activity_name
- Description: The event activity name, as defined by the activity_id.
- Literal:
Add User,Create,Delete,Disable,Enable,Enroll,Logon,Move,Other,Read,Remove User,Start,Update - Usage: all events in this service
category_name
- Description: The event category name, as defined by category_uid value:
Discovery. - Literal:
Identity & Access Management,System Activity - Usage: all events in this service
category_uid
- Description: The category unique identifier of the event.
- Literal:
1,3 - Usage: all events in this service
class_name
- Description: The event class name, as defined by class_uid value:
User Inventory Info. - Literal:
Account Change,Authentication,Entity Management,Group Management,Scheduled Job Activity - Usage: all events in this service
class_uid
- Description: The unique identifier of a class. A class describes the attributes available in an event.
- Literal:
1006,3001,3002,3004,3006 - Usage: all events in this service
severity_id
- Description: OCSF severity identifier for the event.
- Literal:
1 - Usage: all events in this service
status_detail
- Description: The status detail contains additional information about the event/finding outcome.
- Source:
error_message - Usage: 71 events (missing: passwordmanager_item_autofill)
status_id
- Description: Normalized status of the activity (1=Success, 2=Failure).
- Source:
success - Transform:
success→boolean_to_status_id; true→1, false→2 (all events in this service)- Usage: all events in this service
time
- Description: Event time, in epoch milliseconds (OCSF
time). - Source:
timestamp - Transform:
timestamp→iso8601_to_epoch_millis(all events in this service)- Usage: all events in this service
type_uid
- Description: The event/finding type ID. It identifies the event's semantics and structure. The value is calculated by the logging system as:
class_uid * 100 + activity_id. - Literal:
100602,100606,300101,300102,300105,300106,300199,300201,300401,300402,300403,300404,300405,300406,300408,300409,300603,300604 - Usage: all events in this service
Metadata
metadata.event_code
- Description: JumpCloud event type code.
- Source:
event_type - Usage: all events in this service
metadata.original_time
- Description: The original event time as reported by the event source. For example, the time in the original format from system event log such as Syslog on Unix/Linux and the System event file on Windows. Omit if event is generated instead of collected via logs.
- Source:
server_timestamp - Usage: passwordmanager_get_item_secret, passwordmanager_item_create, passwordmanager_item_delete, passwordmanager_item_update, passwordmanager_migration_complete, passwordmanager_migration_start, passwordmanager_user_migration
metadata.processed_time
- Description: The event processed time, such as an ETL operation.
- Source:
jc_transformation_ts - Usage: 71 events (missing: passwordmanager_item_autofill)
metadata.product.name
- Description: Originating JumpCloud service that produced the event.
- Source:
service - Usage: all events in this service
metadata.tenant_uid
- Description: JumpCloud organization (tenant) identifier.
- Source:
organization - Usage: all events in this service
metadata.uid
- Description: Unique event identifier assigned by JumpCloud.
- Source:
id - Usage: all events in this service
metadata.version
- Description: OCSF schema version used for this event.
- Literal:
1.8.0 - Usage: all events in this service
Actor
actor.user.email_addr
- Description: Email address of the actor who initiated the event.
- Source:
initiated_by.email - Usage: 61 events: passwordmanager_app_unlock, passwordmanager_app_update, passwordmanager_backup_create, passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, ... (+53 more)
actor.user.name
- Description: Display name of the actor who initiated the event.
- Source:
initiated_by.username - Usage: 50 events: passwordmanager_app_update, passwordmanager_backup_create, passwordmanager_backup_request, passwordmanager_backup_request_cancel, passwordmanager_backup_request_restore, passwordmanager_batch_folder_delete, passwordmanager_extension_pair, passwordmanager_extension_settings_update, ... (+42 more)
actor.user.type_id
- Description: OCSF user type of the actor (1=User, 2=Admin, 3=System, 4=Service).
- Source:
initiated_by.type - Transform:
initiated_by.type→enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (71 events (missing: passwordmanager_get_item_secret))- Usage: 71 events (missing: passwordmanager_get_item_secret)
actor.user.uid
- Description: Unique identifier of the actor who initiated the event.
- Source:
initiated_by.id - Usage: 66 events (missing: passwordmanager_get_item_secret, passwordmanager_user_disable, passwordmanager_user_enable, passwordmanager_user_re-enable, passwordmanager_user_remove...)
User
user.email_addr
- Description: Email address of the user associated with the event.
- Source:
association.connection.to.email - Usage: passwordmanager_folder_member_remove
user.name
- Description: The username. For example,
janedoe1. - Source:
association.connection.to.name,initiated_by.username,resource.username - Usage: 15 events: passwordmanager_app_unlock, passwordmanager_folder_member_add, passwordmanager_folder_member_remove, passwordmanager_user_activate, passwordmanager_user_deactivate, passwordmanager_user_device_pair, passwordmanager_user_device_unpair, passwordmanager_user_disable, ... (+7 more)
user.type_id
- Description: OCSF user type (1=User, 2=Admin, 3=System, 4=Service).
- Source:
resource.type - Transform:
resource.type→enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (12 events: passwordmanager_user_activate, passwordmanager_user_deactivate, passwordmanager_user_device_pair, passwordmanager_user_device_unpair, passwordmanager_user_disable, passwordmanager_user_enable, passwordmanager_user_migration, passwordmanager_user_re-enable, ... (+4 more))- Usage: 12 events: passwordmanager_user_activate, passwordmanager_user_deactivate, passwordmanager_user_device_pair, passwordmanager_user_device_unpair, passwordmanager_user_disable, passwordmanager_user_enable, passwordmanager_user_migration, passwordmanager_user_re-enable, ... (+4 more)
user.uid
- Description: Unique identifier of the user associated with the event.
- Source:
association.connection.to.object_id,resource.id - Usage: 14 events: passwordmanager_folder_member_add, passwordmanager_folder_member_remove, passwordmanager_user_activate, passwordmanager_user_deactivate, passwordmanager_user_device_pair, passwordmanager_user_device_unpair, passwordmanager_user_disable, passwordmanager_user_enable, ... (+6 more)
Device
device.hostname
- Description: The device hostname.
- Source:
resource.name - Usage: passwordmanager_app_unlock
device.uid
- Description: The unique identifier of the device. For example the Windows TargetSID or AWS EC2 ARN.
- Source:
resource.id - Usage: passwordmanager_app_unlock
Entity
entity.data.associated_group_name
- Description: JumpCloud extension data on the managed entity:
associated_group_name. - Source:
association.connection.to.name - Usage: passwordmanager_folder_group_add, passwordmanager_folder_group_remove, passwordmanager_folder_group_update, passwordmanager_folder_member_update
entity.data.associated_group_type
- Description: JumpCloud extension data on the managed entity:
associated_group_type. - Source:
association.connection.to.type - Usage: passwordmanager_folder_group_add, passwordmanager_folder_group_remove, passwordmanager_folder_group_update, passwordmanager_folder_member_update
entity.data.associated_group_uid
- Description: JumpCloud extension data on the managed entity:
associated_group_uid. - Source:
association.connection.to.object_id - Usage: passwordmanager_folder_group_add, passwordmanager_folder_group_remove, passwordmanager_folder_group_update, passwordmanager_folder_member_update
entity.data.association_from_name
- Description: JumpCloud extension data on the managed entity:
association_from_name. - Source:
association.connection.from.name - Usage: passwordmanager_backup_request, passwordmanager_disable, passwordmanager_enable
entity.data.association_from_object_id
- Description: JumpCloud extension data on the managed entity:
association_from_object_id. - Source:
association.connection.from.object_id - Usage: passwordmanager_backup_request, passwordmanager_disable, passwordmanager_enable
entity.data.association_from_type
- Description: JumpCloud extension data on the managed entity:
association_from_type. - Source:
association.connection.from.type - Usage: passwordmanager_backup_request, passwordmanager_disable, passwordmanager_enable
entity.data.association_op
- Description: JumpCloud extension data on the managed entity:
association_op. - Source:
association.op - Usage: passwordmanager_backup_request, passwordmanager_disable, passwordmanager_enable, passwordmanager_item_add, passwordmanager_item_move, passwordmanager_item_remove, passwordmanager_item_update, passwordmanager_sharedfolders_policy_group_add, passwordmanager_sharedfolders_policy_user_add, passwordmanager_sharedfolders_policy_user_remove
entity.data.association_to_name
- Description: JumpCloud extension data on the managed entity:
association_to_name. - Source:
association.connection.to.name - Usage: passwordmanager_sharedfolders_policy_group_add, passwordmanager_sharedfolders_policy_user_add, passwordmanager_sharedfolders_policy_user_remove
entity.data.association_to_object_id
- Description: JumpCloud extension data on the managed entity:
association_to_object_id. - Source:
association.connection.to.object_id - Usage: passwordmanager_backup_request, passwordmanager_sharedfolders_policy_group_add, passwordmanager_sharedfolders_policy_user_add, passwordmanager_sharedfolders_policy_user_remove
entity.data.association_to_type
- Description: JumpCloud extension data on the managed entity:
association_to_type. - Source:
association.connection.to.type - Usage: passwordmanager_backup_request, passwordmanager_sharedfolders_policy_group_add, passwordmanager_sharedfolders_policy_user_add, passwordmanager_sharedfolders_policy_user_remove
entity.data.auth_method
- Description: JumpCloud extension data on the managed entity:
auth_method. - Source:
auth_method - Usage: 20 events: passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_backup_request_approve, passwordmanager_backup_request_reject, passwordmanager_disable, ... (+12 more)
entity.data.calling_service
- Description: JumpCloud extension data on the managed entity:
calling_service. - Source:
calling_service - Usage: passwordmanager_get_item_secret
entity.data.changed_field
- Description: JumpCloud extension data on the managed entity:
changed_field. - Source:
changes.field - Usage: 17 events: passwordmanager_app_update, passwordmanager_backup_request_approve, passwordmanager_backup_request_cancel, passwordmanager_backup_request_reject, passwordmanager_backup_request_restore, passwordmanager_disable, passwordmanager_extension_settings_update, passwordmanager_folder_group_add, ... (+9 more)
entity.data.changed_from
- Description: JumpCloud extension data on the managed entity:
changed_from. - Source:
changes.from - Usage: passwordmanager_extension_settings_update, passwordmanager_item_settings_update, passwordmanager_policy_export_update, passwordmanager_sharedfolders_policy_update
entity.data.changes_from
- Description: JumpCloud extension data on the managed entity:
changes_from. - Source:
changes.from - Usage: 11 events: passwordmanager_app_update, passwordmanager_backup_request_approve, passwordmanager_backup_request_cancel, passwordmanager_backup_request_reject, passwordmanager_backup_request_restore, passwordmanager_folder_group_add, passwordmanager_folder_group_remove, passwordmanager_folder_group_update, ... (+3 more)
entity.data.created_at
- Description: JumpCloud extension data on the managed entity:
created_at. - Source:
additional_data.CreatedAt - Usage: passwordmanager_item_create
entity.data.deleted_at
- Description: JumpCloud extension data on the managed entity:
deleted_at. - Source:
additional_data.DeletedAt - Usage: passwordmanager_item_delete
entity.data.deleted_folder_id
- Description: JumpCloud extension data on the managed entity:
deleted_folder_id. - Source:
changes.id - Usage: passwordmanager_batch_folder_delete
entity.data.deleted_folder_name
- Description: JumpCloud extension data on the managed entity:
deleted_folder_name. - Source:
changes.name - Usage: passwordmanager_batch_folder_delete
entity.data.deleted_folder_type
- Description: JumpCloud extension data on the managed entity:
deleted_folder_type. - Source:
changes.type - Usage: passwordmanager_batch_folder_delete
entity.data.description
- Description: JumpCloud extension data on the managed entity:
description. - Source:
additional_data.Description,additional_data.description - Usage: passwordmanager_item_create, passwordmanager_item_delete, passwordmanager_item_update
entity.data.event_schema_version
- Description: JumpCloud extension data on the managed entity:
event_schema_version. - Source:
version - Usage: passwordmanager_get_item_secret, passwordmanager_item_create, passwordmanager_item_delete, passwordmanager_item_update
entity.data.initiator_provider
- Description: JumpCloud extension data on the managed entity:
initiator_provider. - Source:
initiated_by.provider - Usage: passwordmanager_backup_request_reject
entity.data.initiator_user_id
- Description: JumpCloud extension data on the managed entity:
initiator_user_id. - Source:
initiated_by.user_id - Usage: passwordmanager_backup_request_reject
entity.data.provider
- Description: JumpCloud extension data on the managed entity:
provider. - Source:
provider - Usage: passwordmanager_backup_request_reject, passwordmanager_policy_export_update, passwordmanager_sharedfolders_policy_group_add, passwordmanager_sharedfolders_policy_update, passwordmanager_sharedfolders_policy_user_add, passwordmanager_sharedfolders_policy_user_remove
entity.data.resource_id
- Description: JumpCloud extension data on the managed entity:
resource_id. - Source:
resource.id - Usage: passwordmanager_item_move
entity.data.resource_name
- Description: JumpCloud extension data on the managed entity:
resource_name. - Source:
resource.name - Usage: passwordmanager_item_move
entity.data.resource_type
- Description: JumpCloud extension data on the managed entity:
resource_type. - Source:
resource.type - Usage: passwordmanager_item_move
entity.data.secret_id
- Description: JumpCloud extension data on the managed entity:
secret_id. - Source:
secret_id - Usage: passwordmanager_get_item_secret
entity.data.target_object_id
- Description: JumpCloud extension data on the managed entity:
target_object_id. - Source:
target_object_id - Usage: passwordmanager_get_item_secret
entity.data.updated_at
- Description: JumpCloud extension data on the managed entity:
updated_at. - Source:
additional_data.UpdatedAt,additional_data.updated_at - Usage: passwordmanager_item_create, passwordmanager_item_update
entity.data.useragent_device
- Description: JumpCloud extension data on the managed entity:
useragent_device. - Source:
useragent.device - Usage: 12 events: passwordmanager_item_add, passwordmanager_item_autofill, passwordmanager_item_copy, passwordmanager_item_history_restore, passwordmanager_item_history_reveal, passwordmanager_item_move, passwordmanager_item_remove, passwordmanager_item_reveal, ... (+4 more)
entity.data.useragent_name
- Description: JumpCloud extension data on the managed entity:
useragent_name. - Source:
useragent.name - Usage: 12 events: passwordmanager_item_add, passwordmanager_item_autofill, passwordmanager_item_copy, passwordmanager_item_history_restore, passwordmanager_item_history_reveal, passwordmanager_item_move, passwordmanager_item_remove, passwordmanager_item_reveal, ... (+4 more)
entity.data.useragent_os
- Description: JumpCloud extension data on the managed entity:
useragent_os. - Source:
useragent.os - Usage: 12 events: passwordmanager_item_add, passwordmanager_item_autofill, passwordmanager_item_copy, passwordmanager_item_history_restore, passwordmanager_item_history_reveal, passwordmanager_item_move, passwordmanager_item_remove, passwordmanager_item_reveal, ... (+4 more)
entity.data.useragent_os_full
- Description: JumpCloud extension data on the managed entity:
useragent_os_full. - Source:
useragent.os_full - Usage: 12 events: passwordmanager_item_add, passwordmanager_item_autofill, passwordmanager_item_copy, passwordmanager_item_history_restore, passwordmanager_item_history_reveal, passwordmanager_item_move, passwordmanager_item_remove, passwordmanager_item_reveal, ... (+4 more)
entity.data.useragent_os_name
- Description: JumpCloud extension data on the managed entity:
useragent_os_name. - Source:
useragent.os_name - Usage: 12 events: passwordmanager_item_add, passwordmanager_item_autofill, passwordmanager_item_copy, passwordmanager_item_history_restore, passwordmanager_item_history_reveal, passwordmanager_item_move, passwordmanager_item_remove, passwordmanager_item_reveal, ... (+4 more)
entity.device.hostname
- Description: The device hostname.
- Source:
resource.name - Usage: passwordmanager_app_update, passwordmanager_backup_create, passwordmanager_backup_request, passwordmanager_batch_folder_delete, passwordmanager_force_sync, passwordmanager_local_backup_path_update, passwordmanager_paranoid_mode_disable, passwordmanager_paranoid_mode_enable, passwordmanager_pincode_update
entity.device.uid
- Description: The unique identifier of the device. For example the Windows TargetSID or AWS EC2 ARN.
- Source:
resource.id - Usage: passwordmanager_app_update, passwordmanager_backup_create, passwordmanager_backup_request, passwordmanager_batch_folder_delete, passwordmanager_local_backup_path_update
entity.name
- Description: The name of the managed entity. It should match the name of the specific entity object's name if populated, or the name of the managed entity if the
type_idis 'Other'. - Source:
additional_data.ItemName,association.connection.from.name,resource.name - Usage: 38 events: passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_backup_request_approve, passwordmanager_backup_request_cancel, passwordmanager_backup_request_reject, passwordmanager_backup_request_restore, ... (+30 more)
entity.type
- Description: The managed entity type. For example:
Policy,User,Organization,Device. - Source:
additional_data.ItemType,association.connection.from.type,resource.type,target_type - Usage: 51 events: passwordmanager_app_update, passwordmanager_backup_create, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_backup_request, passwordmanager_backup_request_approve, ... (+43 more)
entity.uid
- Description: The identifier of the managed entity. It should match the
uidof the specific entity's object UID if populated, or the source specific ID if thetype_idis 'Other'. - Source:
association.connection.from.object_id,item_id,resource.id - Usage: 43 events: passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_backup_request_approve, passwordmanager_backup_request_cancel, passwordmanager_backup_request_reject, passwordmanager_backup_request_restore, ... (+35 more)
entity.version
- Description: The version of the managed entity. For example:
1.2.3. - Source:
resource.name - Usage: passwordmanager_extension_pair, passwordmanager_extension_settings_update, passwordmanager_extension_unlock
entity_result.data.changed_to
- Description: JumpCloud extension data on the managed entity:
changed_to. - Source:
changes.to - Usage: passwordmanager_extension_settings_update, passwordmanager_item_settings_update, passwordmanager_policy_export_update, passwordmanager_sharedfolders_policy_update
entity_result.data.changes_to
- Description: JumpCloud extension data on the managed entity:
changes_to. - Source:
changes.to - Usage: 12 events: passwordmanager_app_update, passwordmanager_backup_request_approve, passwordmanager_backup_request_cancel, passwordmanager_backup_request_reject, passwordmanager_backup_request_restore, passwordmanager_disable, passwordmanager_folder_group_add, passwordmanager_folder_group_remove, ... (+4 more)
entity_result.name
- Description: The name of the managed entity. It should match the name of the specific entity object's name if populated, or the name of the managed entity if the
type_idis 'Other'. - Source:
association.connection.to.name - Usage: passwordmanager_item_add, passwordmanager_item_move, passwordmanager_item_remove, passwordmanager_item_update
entity_result.type
- Description: The managed entity type. For example:
Policy,User,Organization,Device. - Source:
association.connection.to.type - Usage: passwordmanager_item_add, passwordmanager_item_move, passwordmanager_item_remove, passwordmanager_item_update
entity_result.uid
- Description: The identifier of the managed entity. It should match the
uidof the specific entity's object UID if populated, or the source specific ID if thetype_idis 'Other'. - Source:
association.connection.to.object_id - Usage: passwordmanager_item_add, passwordmanager_item_move, passwordmanager_item_remove, passwordmanager_item_update
Src Endpoint
src_endpoint.autonomous_system.name
- Description: Organization name for the Autonomous System.
- Source:
asn.organization - Usage: 26 events: passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_backup_request_approve, passwordmanager_backup_request_reject, passwordmanager_batch_folder_delete, ... (+18 more)
src_endpoint.autonomous_system.number
- Description: Unique number that the AS is identified by.
- Source:
asn.number - Transform:
asn.number→int(26 events: passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_backup_request_approve, passwordmanager_backup_request_reject, passwordmanager_batch_folder_delete, ... (+18 more))- Usage: 26 events: passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_backup_request_approve, passwordmanager_backup_request_reject, passwordmanager_batch_folder_delete, ... (+18 more)
src_endpoint.ip
- Description: Source IP address the request originated from.
- Source:
client_ip - Usage: 67 events (missing: passwordmanager_folder_force_sync, passwordmanager_local_backup_restore, passwordmanager_migration_complete, passwordmanager_migration_start, passwordmanager_mini_launch)
src_endpoint.location.city
- Description: The name of the city.
- Source:
geoip.city - Usage: 29 events: passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_backup_request_approve, passwordmanager_backup_request_reject, passwordmanager_batch_folder_delete, ... (+21 more)
src_endpoint.location.continent
- Description: The name of the continent.
- Source:
geoip.continent_code - Usage: 29 events: passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_backup_request_approve, passwordmanager_backup_request_reject, passwordmanager_batch_folder_delete, ... (+21 more)
src_endpoint.location.country
- Description: The ISO 3166-1 Alpha-2 country code.
Note: The two letter country code should be capitalized. For example:
USorCA. - Source:
geoip.country_code - Usage: 29 events: passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_backup_request_approve, passwordmanager_backup_request_reject, passwordmanager_batch_folder_delete, ... (+21 more)
src_endpoint.location.lat
- Description: The geographical Latitude coordinate represented in Decimal Degrees (DD). For example:
42.361145. - Source:
geoip.latitude - Transform:
geoip.latitude→double(29 events: passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_backup_request_approve, passwordmanager_backup_request_reject, passwordmanager_batch_folder_delete, ... (+21 more))- Usage: 29 events: passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_backup_request_approve, passwordmanager_backup_request_reject, passwordmanager_batch_folder_delete, ... (+21 more)
src_endpoint.location.long
- Description: The geographical Longitude coordinate represented in Decimal Degrees (DD). For example:
-71.057083. - Source:
geoip.longitude - Transform:
geoip.longitude→double(21 events: passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_backup_request_approve, passwordmanager_backup_request_reject, passwordmanager_batch_folder_delete, ... (+13 more))- Usage: 29 events: passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_backup_request_approve, passwordmanager_backup_request_reject, passwordmanager_batch_folder_delete, ... (+21 more)
src_endpoint.location.region
- Description: The alphanumeric code that identifies the principal subdivision (e.g. province or state) of the country. For example, 'CH-VD' for the Canton of Vaud, Switzerland
- Source:
geoip.region_code - Usage: 29 events: passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_backup_request_approve, passwordmanager_backup_request_reject, passwordmanager_batch_folder_delete, ... (+21 more)
Http Request
http_request.user_agent
- Description: The request header that identifies the operating system and web browser.
- Source:
user_agent - Usage: 63 events: passwordmanager_app_unlock, passwordmanager_app_update, passwordmanager_backup_create, passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, ... (+55 more)
Observables
observables[].name
- Description: The full name of the observable attribute. The
nameis a pointer/reference to an attribute within the OCSF event data. For example:file.name. Array attributes may be represented in one of three ways. For example:resources.uid,resources[].uid,resources[0].uid. - Literal:
actor.user.email_addr,actor.user.name,actor.user.uid,device.hostname,device.uid,entity.device.hostname,entity.device.uid,group.name,group.uid,http_request.user_agent,src_endpoint.ip,src_endpoint.location.country,user.email_addr,user.name,user.uid - Usage: all events in this service
observables[].type_id
- Description: The observable value type identifier.
- Literal:
1,14,16,2,31,32,33,4,47,5 - Usage: all events in this service
observables[].value
- Description: The value associated with the observable attribute. The meaning of the value depends on the observable type.
If thenamerefers to a scalar attribute, then thevalueis the value of the attribute.
If thenamerefers to an object attribute, then thevalueis not populated. - Source:
association.connection.from.name,association.connection.from.object_id,association.connection.to.email,association.connection.to.id,association.connection.to.name,association.connection.to.object_id,client_ip,geoip.country_code,initiated_by.email,initiated_by.id,initiated_by.username,resource.id,resource.name,resource.username,user_agent - Usage: all events in this service
Other
action
- Description: The normalized caption of
action_id. - Source:
association.op - Usage: passwordmanager_folder_group_add, passwordmanager_folder_group_remove, passwordmanager_folder_group_update, passwordmanager_folder_member_add, passwordmanager_folder_member_remove, passwordmanager_folder_member_update
group.name
- Description: The group name.
- Source:
resource.name - Usage: passwordmanager_folder_member_add, passwordmanager_folder_member_remove
group.type
- Description: The type of the group.
- Source:
resource.type - Usage: passwordmanager_folder_member_add, passwordmanager_folder_member_remove
group.uid
- Description: The unique identifier of the group. For example, for Windows events this is the security identifier (SID) of the group. Another example, pool id or desktop id that the device belongs to.
- Source:
resource.id - Usage: passwordmanager_folder_member_add, passwordmanager_folder_member_remove
job.desc
- Description: The description of the job.
- Source:
resource.type - Usage: passwordmanager_folder_force_sync, passwordmanager_local_backup_restore, passwordmanager_migration_complete, passwordmanager_migration_start, passwordmanager_mini_launch
job.name
- Description: The name of the job.
- Source:
resource.name - Usage: passwordmanager_folder_force_sync, passwordmanager_local_backup_restore, passwordmanager_mini_launch
Unmapped
unmapped.@timestamp
- Description: JumpCloud Directory Insights field
@timestamppreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
@timestamp - Usage: 31 events: passwordmanager_app_unlock, passwordmanager_backup_create, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_request_reject, passwordmanager_disable, passwordmanager_folder_create, passwordmanager_folder_member_add, ... (+23 more)
unmapped.@version
- Description: JumpCloud Directory Insights field
@versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
@version - Usage: all events in this service
unmapped.asn.error
- Description: JumpCloud Directory Insights field
asn.errorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
asn.error - Usage: 23 events: passwordmanager_app_unlock, passwordmanager_app_update, passwordmanager_backup_create, passwordmanager_backup_request, passwordmanager_backup_request_cancel, passwordmanager_backup_request_restore, passwordmanager_extension_pair, passwordmanager_extension_settings_update, ... (+15 more)
unmapped.asn.ip_address
- Description: JumpCloud Directory Insights field
asn.ip_addresspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
asn.ip_address - Usage: 23 events: passwordmanager_app_unlock, passwordmanager_app_update, passwordmanager_backup_create, passwordmanager_backup_request, passwordmanager_backup_request_cancel, passwordmanager_backup_request_restore, passwordmanager_extension_pair, passwordmanager_extension_settings_update, ... (+15 more)
unmapped.asn.network
- Description: JumpCloud Directory Insights field
asn.networkpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
asn.network - Usage: 18 events: passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_backup_request_approve, passwordmanager_backup_request_reject, passwordmanager_batch_folder_delete, passwordmanager_disable, ... (+10 more)
unmapped.asn_number
- Description: JumpCloud Directory Insights field
asn_numberpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
asn.number - Usage: passwordmanager_mini_launch
unmapped.asn_organization
- Description: JumpCloud Directory Insights field
asn_organizationpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
asn.organization - Usage: passwordmanager_mini_launch
unmapped.association_connection_to_email
- Description: JumpCloud Directory Insights field
association_connection_to_emailpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
association.connection.to.email - Usage: passwordmanager_folder_member_update
unmapped.association_connection_to_id
- Description: JumpCloud Directory Insights field
association_connection_to_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
association.connection.to.id - Usage: passwordmanager_folder_member_update
unmapped.association_from_name
- Description: JumpCloud Directory Insights field
association_from_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
association.connection.from.name - Usage: passwordmanager_user_device_pair, passwordmanager_user_device_unpair
unmapped.association_from_object_id
- Description: JumpCloud Directory Insights field
association_from_object_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
association.connection.from.object_id - Usage: passwordmanager_user_device_pair, passwordmanager_user_device_unpair
unmapped.association_from_type
- Description: JumpCloud Directory Insights field
association_from_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
association.connection.from.type - Usage: passwordmanager_user_device_pair, passwordmanager_user_device_unpair
unmapped.association_op
- Description: JumpCloud Directory Insights field
association_oppreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
association.op - Usage: passwordmanager_user_device_pair, passwordmanager_user_device_unpair, passwordmanager_user_enable
unmapped.association_to_name
- Description: JumpCloud Directory Insights field
association_to_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
association.connection.to.name - Usage: passwordmanager_user_device_pair, passwordmanager_user_device_unpair, passwordmanager_user_enable
unmapped.association_to_object_id
- Description: JumpCloud Directory Insights field
association_to_object_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
association.connection.to.object_id - Usage: passwordmanager_user_device_pair, passwordmanager_user_device_unpair, passwordmanager_user_enable
unmapped.association_to_type
- Description: JumpCloud Directory Insights field
association_to_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
association.connection.to.type - Usage: passwordmanager_folder_member_add, passwordmanager_folder_member_remove, passwordmanager_user_device_pair, passwordmanager_user_device_unpair, passwordmanager_user_enable
unmapped.auth_method
- Description: JumpCloud Directory Insights field
auth_methodpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
auth_method - Usage: passwordmanager_folder_member_remove, passwordmanager_user_disable, passwordmanager_user_enable, passwordmanager_user_re-enable, passwordmanager_user_remove, passwordmanager_user_update
unmapped.changed_field
- Description: JumpCloud Directory Insights field
changed_fieldpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.field - Usage: passwordmanager_user_activate, passwordmanager_user_disable, passwordmanager_user_re-enable, passwordmanager_user_reactivate, passwordmanager_user_update
unmapped.changes_field
- Description: JumpCloud Directory Insights field
changes_fieldpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.field - Usage: passwordmanager_folder_member_remove
unmapped.changes_from
- Description: JumpCloud Directory Insights field
changes_frompreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.from - Usage: passwordmanager_folder_member_remove
unmapped.changes_to
- Description: JumpCloud Directory Insights field
changes_topreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to - Usage: passwordmanager_folder_member_remove, passwordmanager_user_activate, passwordmanager_user_disable, passwordmanager_user_re-enable, passwordmanager_user_reactivate, passwordmanager_user_update
unmapped.city
- Description: JumpCloud Directory Insights field
citypreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.city - Usage: passwordmanager_local_backup_restore, passwordmanager_mini_launch
unmapped.client_ip
- Description: JumpCloud Directory Insights field
client_ippreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
client_ip - Usage: passwordmanager_folder_force_sync, passwordmanager_local_backup_restore, passwordmanager_migration_complete, passwordmanager_migration_start, passwordmanager_mini_launch
unmapped.continent_code
- Description: JumpCloud Directory Insights field
continent_codepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.continent_code - Usage: passwordmanager_local_backup_restore, passwordmanager_mini_launch
unmapped.country_code
- Description: JumpCloud Directory Insights field
country_codepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.country_code - Usage: passwordmanager_local_backup_restore, passwordmanager_mini_launch
unmapped.error
- Description: JumpCloud Directory Insights field
errorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.error - Usage: passwordmanager_folder_create, passwordmanager_folder_delete, passwordmanager_folder_force_sync, passwordmanager_folder_group_add, passwordmanager_folder_member_add, passwordmanager_folder_update, passwordmanager_local_backup_create
unmapped.file_input_timestamp
- Description: JumpCloud Directory Insights field
file_input_timestamppreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
file_input_timestamp - Usage: 35 events: passwordmanager_app_unlock, passwordmanager_backup_create, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_request_reject, passwordmanager_disable, passwordmanager_extension_pair, passwordmanager_extension_settings_update, ... (+27 more)
unmapped.geoip.error
- Description: JumpCloud Directory Insights field
geoip.errorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.error - Usage: 25 events: passwordmanager_app_unlock, passwordmanager_app_update, passwordmanager_backup_create, passwordmanager_backup_request, passwordmanager_backup_request_cancel, passwordmanager_backup_request_restore, passwordmanager_extension_pair, passwordmanager_extension_settings_update, ... (+17 more)
unmapped.geoip.ip_address
- Description: JumpCloud Directory Insights field
geoip.ip_addresspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.ip_address - Usage: 25 events: passwordmanager_app_unlock, passwordmanager_app_update, passwordmanager_backup_create, passwordmanager_backup_request, passwordmanager_backup_request_cancel, passwordmanager_backup_request_restore, passwordmanager_extension_pair, passwordmanager_extension_settings_update, ... (+17 more)
unmapped.geoip.region_name
- Description: JumpCloud Directory Insights field
geoip.region_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.region_name - Usage: 21 events: passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_backup_request_approve, passwordmanager_backup_request_reject, passwordmanager_batch_folder_delete, ... (+13 more)
unmapped.geoip.timezone
- Description: JumpCloud Directory Insights field
geoip.timezonepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.timezone - Usage: 21 events: passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_backup_request_approve, passwordmanager_backup_request_reject, passwordmanager_batch_folder_delete, ... (+13 more)
unmapped.initiated_by.provider
- Description: JumpCloud Directory Insights field
initiated_by.providerpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by.provider - Usage: passwordmanager_policy_export_update, passwordmanager_sharedfolders_policy_group_add, passwordmanager_sharedfolders_policy_update
unmapped.initiated_by.user_id
- Description: JumpCloud Directory Insights field
initiated_by.user_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by.user_id - Usage: passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_disable, passwordmanager_policy_export_update, passwordmanager_sharedfolders_policy_group_add, passwordmanager_sharedfolders_policy_update, passwordmanager_sharedfolders_policy_user_add, passwordmanager_sharedfolders_policy_user_remove
unmapped.initiated_by_email_hash
- Description: JumpCloud Directory Insights field
initiated_by_email_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_email_hash - Usage: 60 events: passwordmanager_app_unlock, passwordmanager_app_update, passwordmanager_backup_create, passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, ... (+52 more)
unmapped.initiated_by_id_hash
- Description: JumpCloud Directory Insights field
initiated_by_id_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_id_hash - Usage: 65 events (missing: passwordmanager_get_item_secret, passwordmanager_item_autofill, passwordmanager_user_disable, passwordmanager_user_enable, passwordmanager_user_re-enable...)
unmapped.initiated_by_username_hash
- Description: JumpCloud Directory Insights field
initiated_by_username_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_username_hash - Usage: 50 events: passwordmanager_app_unlock, passwordmanager_app_update, passwordmanager_backup_create, passwordmanager_backup_request, passwordmanager_backup_request_cancel, passwordmanager_backup_request_restore, passwordmanager_batch_folder_delete, passwordmanager_extension_pair, ... (+42 more)
unmapped.ip_address
- Description: JumpCloud Directory Insights field
ip_addresspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.ip_address - Usage: passwordmanager_folder_create, passwordmanager_folder_delete, passwordmanager_folder_force_sync, passwordmanager_folder_group_add, passwordmanager_folder_member_add, passwordmanager_folder_update, passwordmanager_local_backup_create
unmapped.is_out_of_bound
- Description: JumpCloud Directory Insights field
is_out_of_boundpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
is_out_of_bound - Usage: 68 events (missing: passwordmanager_item_autofill, passwordmanager_item_history_reveal, passwordmanager_items_export, passwordmanager_user_device_pair)
unmapped.jc_application_name
- Description: JumpCloud Directory Insights field
jc_application_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_application_name - Usage: 68 events (missing: passwordmanager_item_autofill, passwordmanager_item_history_reveal, passwordmanager_items_export, passwordmanager_user_device_pair)
unmapped.jc_initiated_by_email
- Description: JumpCloud Directory Insights field
jc_initiated_by_emailpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_initiated_by_email - Usage: 34 events: passwordmanager_app_unlock, passwordmanager_app_update, passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_enable, ... (+26 more)
unmapped.jc_initiated_by_username
- Description: JumpCloud Directory Insights field
jc_initiated_by_usernamepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_initiated_by_username - Usage: 34 events: passwordmanager_app_unlock, passwordmanager_app_update, passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_enable, ... (+26 more)
unmapped.jc_organization_name
- Description: JumpCloud Directory Insights field
jc_organization_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_organization_name - Usage: 34 events: passwordmanager_app_unlock, passwordmanager_app_update, passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_enable, ... (+26 more)
unmapped.jc_provider_id
- Description: JumpCloud Directory Insights field
jc_provider_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_provider_id - Usage: 26 events: passwordmanager_app_unlock, passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_enable, passwordmanager_folder_create, ... (+18 more)
unmapped.latitude
- Description: JumpCloud Directory Insights field
latitudepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.latitude - Usage: passwordmanager_local_backup_restore, passwordmanager_mini_launch
unmapped.longitude
- Description: JumpCloud Directory Insights field
longitudepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.longitude - Usage: passwordmanager_local_backup_restore, passwordmanager_mini_launch
unmapped.network
- Description: JumpCloud Directory Insights field
networkpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
asn.network - Usage: passwordmanager_folder_create, passwordmanager_folder_group_add, passwordmanager_folder_group_remove, passwordmanager_folder_group_update, passwordmanager_folder_member_remove, passwordmanager_folder_member_update, passwordmanager_folder_update, passwordmanager_mini_launch
unmapped.region_code
- Description: JumpCloud Directory Insights field
region_codepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.region_code - Usage: passwordmanager_local_backup_restore, passwordmanager_mini_launch
unmapped.region_name
- Description: JumpCloud Directory Insights field
region_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.region_name - Usage: passwordmanager_folder_create, passwordmanager_folder_group_add, passwordmanager_folder_group_remove, passwordmanager_folder_group_update, passwordmanager_folder_member_remove, passwordmanager_folder_member_update, passwordmanager_folder_update, passwordmanager_local_backup_path_update, passwordmanager_local_backup_restore, passwordmanager_mini_launch
unmapped.resource_id
- Description: JumpCloud Directory Insights field
resource_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.id - Usage: passwordmanager_folder_force_sync, passwordmanager_migration_complete, passwordmanager_migration_start, passwordmanager_mini_launch
unmapped.resource_id_hash
- Description: JumpCloud Directory Insights field
resource_id_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource_id_hash - Usage: 65 events (missing: passwordmanager_backup_disable, passwordmanager_extension_site_exclusion, passwordmanager_get_item_secret, passwordmanager_item_autofill, passwordmanager_item_create...)
unmapped.resource_type
- Description: JumpCloud Directory Insights field
resource_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.type - Usage: passwordmanager_app_unlock
unmapped.resource_username_hash
- Description: JumpCloud Directory Insights field
resource_username_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource_username_hash - Usage: 12 events: passwordmanager_user_activate, passwordmanager_user_deactivate, passwordmanager_user_device_pair, passwordmanager_user_device_unpair, passwordmanager_user_disable, passwordmanager_user_enable, passwordmanager_user_migration, passwordmanager_user_re-enable, ... (+4 more)
unmapped.tags
- Description: JumpCloud Directory Insights field
tagspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
tags - Usage: 35 events: passwordmanager_app_unlock, passwordmanager_backup_create, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_request_reject, passwordmanager_disable, passwordmanager_extension_pair, passwordmanager_extension_settings_update, ... (+27 more)
unmapped.timestamp
- Description: JumpCloud Directory Insights field
timestamppreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
@timestamp - Usage: passwordmanager_extension_pair, passwordmanager_extension_settings_update, passwordmanager_extension_unlock, passwordmanager_force_sync
unmapped.timestamp_source
- Description: JumpCloud Directory Insights field
timestamp_sourcepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
timestamp_source - Usage: passwordmanager_get_item_secret, passwordmanager_item_create, passwordmanager_item_delete, passwordmanager_item_update, passwordmanager_migration_complete, passwordmanager_migration_start, passwordmanager_user_migration
unmapped.timezone
- Description: JumpCloud Directory Insights field
timezonepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.timezone - Usage: passwordmanager_folder_create, passwordmanager_folder_group_add, passwordmanager_folder_group_remove, passwordmanager_folder_group_update, passwordmanager_folder_member_remove, passwordmanager_folder_member_update, passwordmanager_folder_update, passwordmanager_local_backup_path_update, passwordmanager_local_backup_restore, passwordmanager_mini_launch
unmapped.user_agent
- Description: JumpCloud Directory Insights field
user_agentpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
user_agent - Usage: passwordmanager_folder_force_sync, passwordmanager_local_backup_restore, passwordmanager_migration_complete, passwordmanager_migration_start, passwordmanager_mini_launch
unmapped.useragent.device
- Description: JumpCloud Directory Insights field
useragent.devicepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.device - Usage: 41 events: passwordmanager_app_unlock, passwordmanager_app_update, passwordmanager_backup_create, passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, ... (+33 more)
unmapped.useragent.major
- Description: JumpCloud Directory Insights field
useragent.majorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.major - Usage: 21 events: passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_backup_request_approve, passwordmanager_backup_request_reject, passwordmanager_disable, ... (+13 more)
unmapped.useragent.minor
- Description: JumpCloud Directory Insights field
useragent.minorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.minor - Usage: 21 events: passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_backup_request_approve, passwordmanager_backup_request_reject, passwordmanager_disable, ... (+13 more)
unmapped.useragent.name
- Description: JumpCloud Directory Insights field
useragent.namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.name - Usage: 41 events: passwordmanager_app_unlock, passwordmanager_app_update, passwordmanager_backup_create, passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, ... (+33 more)
unmapped.useragent.os
- Description: JumpCloud Directory Insights field
useragent.ospreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os - Usage: 41 events: passwordmanager_app_unlock, passwordmanager_app_update, passwordmanager_backup_create, passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, ... (+33 more)
unmapped.useragent.os_full
- Description: JumpCloud Directory Insights field
useragent.os_fullpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_full - Usage: 41 events: passwordmanager_app_unlock, passwordmanager_app_update, passwordmanager_backup_create, passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, ... (+33 more)
unmapped.useragent.os_major
- Description: JumpCloud Directory Insights field
useragent.os_majorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_major - Usage: 21 events: passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_backup_request_approve, passwordmanager_backup_request_reject, passwordmanager_disable, ... (+13 more)
unmapped.useragent.os_minor
- Description: JumpCloud Directory Insights field
useragent.os_minorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_minor - Usage: 21 events: passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_backup_request_approve, passwordmanager_backup_request_reject, passwordmanager_disable, ... (+13 more)
unmapped.useragent.os_name
- Description: JumpCloud Directory Insights field
useragent.os_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_name - Usage: 41 events: passwordmanager_app_unlock, passwordmanager_app_update, passwordmanager_backup_create, passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, ... (+33 more)
unmapped.useragent.os_patch
- Description: JumpCloud Directory Insights field
useragent.os_patchpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_patch - Usage: 21 events: passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_backup_request_approve, passwordmanager_backup_request_reject, passwordmanager_disable, ... (+13 more)
unmapped.useragent.os_version
- Description: JumpCloud Directory Insights field
useragent.os_versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_version - Usage: 21 events: passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_backup_request_approve, passwordmanager_backup_request_reject, passwordmanager_disable, ... (+13 more)
unmapped.useragent.patch
- Description: JumpCloud Directory Insights field
useragent.patchpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.patch - Usage: 21 events: passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_backup_request_approve, passwordmanager_backup_request_reject, passwordmanager_disable, ... (+13 more)
unmapped.useragent.version
- Description: JumpCloud Directory Insights field
useragent.versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.version - Usage: 21 events: passwordmanager_backup_disable, passwordmanager_backup_enable, passwordmanager_backup_key_create, passwordmanager_backup_key_delete, passwordmanager_backup_key_regenerate, passwordmanager_backup_request_approve, passwordmanager_backup_request_reject, passwordmanager_disable, ... (+13 more)
unmapped.useragent_device
- Description: JumpCloud Directory Insights field
useragent_devicepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.device - Usage: passwordmanager_extension_pair, passwordmanager_extension_settings_update, passwordmanager_extension_site_exclusion, passwordmanager_extension_unlock, passwordmanager_force_sync, passwordmanager_paranoid_mode_disable, passwordmanager_paranoid_mode_enable, passwordmanager_pincode_update
unmapped.useragent_name
- Description: JumpCloud Directory Insights field
useragent_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.name - Usage: passwordmanager_extension_pair, passwordmanager_extension_settings_update, passwordmanager_extension_site_exclusion, passwordmanager_extension_unlock, passwordmanager_force_sync, passwordmanager_paranoid_mode_disable, passwordmanager_paranoid_mode_enable, passwordmanager_pincode_update
unmapped.useragent_os
- Description: JumpCloud Directory Insights field
useragent_ospreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os - Usage: passwordmanager_extension_pair, passwordmanager_extension_settings_update, passwordmanager_extension_site_exclusion, passwordmanager_extension_unlock, passwordmanager_force_sync, passwordmanager_paranoid_mode_disable, passwordmanager_paranoid_mode_enable, passwordmanager_pincode_update
unmapped.useragent_os_full
- Description: JumpCloud Directory Insights field
useragent_os_fullpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_full - Usage: passwordmanager_extension_pair, passwordmanager_extension_settings_update, passwordmanager_extension_site_exclusion, passwordmanager_extension_unlock, passwordmanager_force_sync, passwordmanager_paranoid_mode_disable, passwordmanager_paranoid_mode_enable, passwordmanager_pincode_update
unmapped.useragent_os_name
- Description: JumpCloud Directory Insights field
useragent_os_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_name - Usage: passwordmanager_extension_pair, passwordmanager_extension_settings_update, passwordmanager_extension_site_exclusion, passwordmanager_extension_unlock, passwordmanager_force_sync, passwordmanager_paranoid_mode_disable, passwordmanager_paranoid_mode_enable, passwordmanager_pincode_update
unmapped.version
- Description: JumpCloud Directory Insights field
versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
version - Usage: passwordmanager_migration_complete, passwordmanager_migration_start, passwordmanager_user_migration
Password Vault#
password_vault · 47 events
| Event | Category | Class | Activity | Type UID | Fields |
|---|---|---|---|---|---|
passwordvault_credential_add |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 51 |
passwordvault_credential_archive |
Identity & Access Management (3) | Entity Management (3004) | Suspend (12) | 300412 | 39 |
passwordvault_credential_autofill |
Identity & Access Management (3) | Entity Management (3004) | Read (2) | 300402 | 39 |
passwordvault_credential_copy |
Identity & Access Management (3) | Entity Management (3004) | Read (2) | 300402 | 40 |
passwordvault_credential_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 39 |
passwordvault_credential_duplicate |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 39 |
passwordvault_credential_export |
Identity & Access Management (3) | Entity Management (3004) | Read (2) | 300402 | 42 |
passwordvault_credential_history_reveal |
Identity & Access Management (3) | Entity Management (3004) | Read (2) | 300402 | 42 |
passwordvault_credential_import |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 36 |
passwordvault_credential_reveal |
Identity & Access Management (3) | Entity Management (3004) | Read (2) | 300402 | 40 |
passwordvault_credential_shareuser |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 49 |
passwordvault_credential_shareusergroup |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 52 |
passwordvault_credential_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 47 |
passwordvault_credential_viewdetail |
Identity & Access Management (3) | Entity Management (3004) | Read (2) | 300402 | 39 |
passwordvault_credential_viewsecret |
Identity & Access Management (3) | Entity Management (3004) | Read (2) | 300402 | 39 |
passwordvault_enable |
Identity & Access Management (3) | Entity Management (3004) | Enable (8) | 300408 | 64 |
passwordvault_group_disable |
Identity & Access Management (3) | Entity Management (3004) | Disable (9) | 300409 | 43 |
passwordvault_personalfolder_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 43 |
passwordvault_personalfolder_credential_add |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 42 |
passwordvault_personalfolder_credential_remove |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 46 |
passwordvault_personalfolder_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 39 |
passwordvault_personalfolder_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 42 |
passwordvault_personalfolder_website_add |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 47 |
passwordvault_personalfolder_website_remove |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 51 |
passwordvault_sharedfolder_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 43 |
passwordvault_sharedfolder_credential_add |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 51 |
passwordvault_sharedfolder_credential_remove |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 49 |
passwordvault_sharedfolder_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 42 |
passwordvault_sharedfolder_group_add |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 48 |
passwordvault_sharedfolder_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 42 |
passwordvault_sharedfolder_user_add |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 49 |
passwordvault_sharedfolder_user_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 53 |
passwordvault_sharedfolder_website_add |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 51 |
passwordvault_sharedfolder_website_remove |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 43 |
passwordvault_user_disable |
Identity & Access Management (3) | Account Change (3001) | Disable (5) | 300105 | 42 |
passwordvault_user_enable |
Identity & Access Management (3) | Account Change (3001) | Enable (2) | 300102 | 40 |
passwordvault_website_add |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 51 |
passwordvault_website_archive |
Identity & Access Management (3) | Entity Management (3004) | Deactivate (11) | 300411 | 39 |
passwordvault_website_connect |
Identity & Access Management (3) | Entity Management (3004) | Read (2) | 300402 | 42 |
passwordvault_website_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 43 |
passwordvault_website_duplicate |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 43 |
passwordvault_website_linkcredential |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 52 |
passwordvault_website_shareuser |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 49 |
passwordvault_website_shareusergroup |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 48 |
passwordvault_website_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 51 |
passwordvault_website_viewdetails |
Identity & Access Management (3) | Entity Management (3004) | Read (2) | 300402 | 43 |
passwordvault_websites_export |
Identity & Access Management (3) | Entity Management (3004) | Read (2) | 300402 | 36 |
OCSF field mappings#
Legend
- Description: what the OCSF field represents (from OCSF schema v1.8.0)
- Source: raw JumpCloud event field(s) mapped via
${{placeholder}}template - Transform:
fieldMappingsentry applied at runtime (cast, enum, etc.) - Literal: static value set in the mapping template
- Usage: event types in this service that include this field
Core
activity_id
- Description: The normalized identifier of the activity that triggered the event.
- Literal:
1,11,12,2,3,4,5,8,9 - Usage: all events in this service
activity_name
- Description: The event activity name, as defined by the activity_id.
- Literal:
Create,Deactivate,Delete,Disable,Enable,Read,Suspend,Update - Usage: all events in this service
category_name
- Description: The event category name, as defined by category_uid value:
Discovery. - Literal:
Identity & Access Management - Usage: all events in this service
category_uid
- Description: The category unique identifier of the event.
- Literal:
3 - Usage: all events in this service
class_name
- Description: The event class name, as defined by class_uid value:
User Inventory Info. - Literal:
Account Change,Entity Management - Usage: all events in this service
class_uid
- Description: The unique identifier of a class. A class describes the attributes available in an event.
- Literal:
3001,3004 - Usage: all events in this service
severity_id
- Description: OCSF severity identifier for the event.
- Literal:
1 - Usage: all events in this service
status_detail
- Description: The status detail contains additional information about the event/finding outcome.
- Source:
error_message - Usage: all events in this service
status_id
- Description: Normalized status of the activity (1=Success, 2=Failure).
- Source:
success - Transform:
success→boolean_to_status_id; true→1, false→2 (all events in this service)- Usage: all events in this service
time
- Description: Event time, in epoch milliseconds (OCSF
time). - Source:
timestamp - Transform:
timestamp→iso8601_to_epoch_millis(all events in this service)- Usage: all events in this service
type_uid
- Description: The event/finding type ID. It identifies the event's semantics and structure. The value is calculated by the logging system as:
class_uid * 100 + activity_id. - Literal:
300102,300105,300401,300402,300403,300404,300408,300409,300411,300412 - Usage: all events in this service
Metadata
metadata.event_code
- Description: JumpCloud event type code.
- Source:
event_type - Usage: all events in this service
metadata.original_time
- Description: The original event time as reported by the event source. For example, the time in the original format from system event log such as Syslog on Unix/Linux and the System event file on Windows. Omit if event is generated instead of collected via logs.
- Source:
server_timestamp - Usage: all events in this service
metadata.processed_time
- Description: The event processed time, such as an ETL operation.
- Source:
jc_transformation_ts - Usage: all events in this service
metadata.product.name
- Description: Originating JumpCloud service that produced the event.
- Source:
service - Usage: all events in this service
metadata.tenant_uid
- Description: JumpCloud organization (tenant) identifier.
- Source:
organization - Usage: all events in this service
metadata.uid
- Description: Unique event identifier assigned by JumpCloud.
- Source:
id - Usage: all events in this service
metadata.version
- Description: OCSF schema version used for this event.
- Literal:
1.8.0 - Usage: all events in this service
Actor
actor.user.email_addr
- Description: Email address of the actor who initiated the event.
- Source:
initiated_by.email - Usage: all events in this service
actor.user.name
- Description: Display name of the actor who initiated the event.
- Source:
initiated_by.username - Usage: 42 events: passwordvault_credential_add, passwordvault_credential_archive, passwordvault_credential_autofill, passwordvault_credential_copy, passwordvault_credential_delete, passwordvault_credential_duplicate, passwordvault_credential_export, passwordvault_credential_history_reveal, ... (+34 more)
actor.user.type_id
- Description: OCSF user type of the actor (1=User, 2=Admin, 3=System, 4=Service).
- Source:
initiated_by.type - Transform:
initiated_by.type→enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (all events in this service)- Usage: all events in this service
actor.user.uid
- Description: Unique identifier of the actor who initiated the event.
- Source:
initiated_by.id - Usage: all events in this service
User
user.email_addr
- Description: Email address of the user associated with the event.
- Source:
resource.name - Usage: passwordvault_user_disable, passwordvault_user_enable
user.type_id
- Description: OCSF user type (1=User, 2=Admin, 3=System, 4=Service).
- Source:
resource.type - Transform:
resource.type→enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (passwordvault_user_disable, passwordvault_user_enable)- Usage: passwordvault_user_disable, passwordvault_user_enable
user.uid
- Description: Unique identifier of the user associated with the event.
- Source:
resource.id - Usage: passwordvault_user_disable, passwordvault_user_enable
Entity
entity.data.action_source
- Description: JumpCloud extension data on the managed entity:
action_source. - Source:
association.action_source - Usage: 20 events: passwordvault_credential_add, passwordvault_credential_shareuser, passwordvault_credential_shareusergroup, passwordvault_credential_update, passwordvault_personalfolder_credential_add, passwordvault_personalfolder_credential_remove, passwordvault_personalfolder_website_add, passwordvault_personalfolder_website_remove, ... (+12 more)
entity.data.association_attributes
- Description: JumpCloud extension data on the managed entity:
association_attributes. - Source:
association.attributes - Usage: 20 events: passwordvault_credential_add, passwordvault_credential_shareuser, passwordvault_credential_shareusergroup, passwordvault_credential_update, passwordvault_personalfolder_credential_add, passwordvault_personalfolder_credential_remove, passwordvault_personalfolder_website_add, passwordvault_personalfolder_website_remove, ... (+12 more)
entity.data.association_from_name
- Description: JumpCloud extension data on the managed entity:
association_from_name. - Source:
association.connection.from.name - Usage: 14 events: passwordvault_credential_add, passwordvault_credential_shareuser, passwordvault_credential_shareusergroup, passwordvault_personalfolder_website_add, passwordvault_personalfolder_website_remove, passwordvault_sharedfolder_credential_add, passwordvault_sharedfolder_group_add, passwordvault_sharedfolder_user_add, ... (+6 more)
entity.data.association_from_object_id
- Description: JumpCloud extension data on the managed entity:
association_from_object_id. - Source:
association.connection.from.object_id - Usage: 16 events: passwordvault_credential_add, passwordvault_credential_shareuser, passwordvault_credential_shareusergroup, passwordvault_personalfolder_credential_remove, passwordvault_personalfolder_website_add, passwordvault_personalfolder_website_remove, passwordvault_sharedfolder_credential_add, passwordvault_sharedfolder_credential_remove, ... (+8 more)
entity.data.association_from_type
- Description: JumpCloud extension data on the managed entity:
association_from_type. - Source:
association.connection.from.type - Usage: 16 events: passwordvault_credential_add, passwordvault_credential_shareuser, passwordvault_credential_shareusergroup, passwordvault_personalfolder_credential_remove, passwordvault_personalfolder_website_add, passwordvault_personalfolder_website_remove, passwordvault_sharedfolder_credential_add, passwordvault_sharedfolder_credential_remove, ... (+8 more)
entity.data.association_op
- Description: JumpCloud extension data on the managed entity:
association_op. - Source:
association.op - Usage: 16 events: passwordvault_credential_add, passwordvault_credential_shareuser, passwordvault_credential_shareusergroup, passwordvault_personalfolder_credential_remove, passwordvault_personalfolder_website_add, passwordvault_personalfolder_website_remove, passwordvault_sharedfolder_credential_add, passwordvault_sharedfolder_credential_remove, ... (+8 more)
entity.data.association_to_email
- Description: JumpCloud extension data on the managed entity:
association_to_email. - Source:
association.connection.to.email - Usage: passwordvault_credential_shareuser, passwordvault_sharedfolder_user_add, passwordvault_sharedfolder_user_update, passwordvault_website_shareuser
entity.data.association_to_name
- Description: JumpCloud extension data on the managed entity:
association_to_name. - Source:
association.connection.to.name - Usage: 11 events: passwordvault_credential_shareuser, passwordvault_credential_shareusergroup, passwordvault_personalfolder_credential_remove, passwordvault_sharedfolder_credential_add, passwordvault_sharedfolder_credential_remove, passwordvault_sharedfolder_group_add, passwordvault_sharedfolder_user_add, passwordvault_sharedfolder_user_update, ... (+3 more)
entity.data.association_to_object_id
- Description: JumpCloud extension data on the managed entity:
association_to_object_id. - Source:
association.connection.to.object_id - Usage: 20 events: passwordvault_credential_add, passwordvault_credential_shareuser, passwordvault_credential_shareusergroup, passwordvault_credential_update, passwordvault_personalfolder_credential_add, passwordvault_personalfolder_credential_remove, passwordvault_personalfolder_website_add, passwordvault_personalfolder_website_remove, ... (+12 more)
entity.data.association_to_type
- Description: JumpCloud extension data on the managed entity:
association_to_type. - Source:
association.connection.to.type - Usage: 20 events: passwordvault_credential_add, passwordvault_credential_shareuser, passwordvault_credential_shareusergroup, passwordvault_credential_update, passwordvault_personalfolder_credential_add, passwordvault_personalfolder_credential_remove, passwordvault_personalfolder_website_add, passwordvault_personalfolder_website_remove, ... (+12 more)
entity.data.auth_method
- Description: JumpCloud extension data on the managed entity:
auth_method. - Source:
auth_method - Usage: passwordvault_enable
entity.data.changed_field
- Description: JumpCloud extension data on the managed entity:
changed_field. - Source:
changes.field - Usage: passwordvault_credential_update, passwordvault_enable, passwordvault_personalfolder_update, passwordvault_sharedfolder_update, passwordvault_website_update
entity.data.changes_from
- Description: JumpCloud extension data on the managed entity:
changes_from. - Source:
changes.from - Usage: passwordvault_credential_update, passwordvault_enable, passwordvault_personalfolder_update, passwordvault_sharedfolder_update, passwordvault_website_update
entity.data.connection.from
- Description: JumpCloud extension data on the managed entity:
connection.from. - Source:
association.connection.from - Usage: passwordvault_credential_update, passwordvault_personalfolder_credential_add, passwordvault_sharedfolder_website_remove, passwordvault_website_update
entity.data.display_name
- Description: JumpCloud extension data on the managed entity:
display_name. - Source:
resource.displayName - Usage: passwordvault_credential_copy, passwordvault_credential_reveal
entity.name
- Description: The name of the managed entity. It should match the name of the specific entity object's name if populated, or the name of the managed entity if the
type_idis 'Other'. - Source:
resource.name - Usage: 38 events: passwordvault_credential_add, passwordvault_credential_archive, passwordvault_credential_autofill, passwordvault_credential_copy, passwordvault_credential_delete, passwordvault_credential_duplicate, passwordvault_credential_history_reveal, passwordvault_credential_reveal, ... (+30 more)
entity.org.uid
- Description: The unique identifier of the organization, Oracle Cloud Tenancy, Google Cloud Organization, or AWS Organization. For example, an
AWS Org IDorOracle Cloud Domain ID. - Source:
resource.id - Usage: passwordvault_credential_export, passwordvault_credential_import
entity.type
- Description: The managed entity type. For example:
Policy,User,Organization,Device. - Source:
resource.type - Usage: 45 events (missing: passwordvault_user_disable, passwordvault_user_enable)
entity.uid
- Description: The identifier of the managed entity. It should match the
uidof the specific entity's object UID if populated, or the source specific ID if thetype_idis 'Other'. - Source:
resource.id - Usage: 43 events (missing: passwordvault_credential_export, passwordvault_credential_import, passwordvault_user_disable, passwordvault_user_enable)
entity_result.data.changes_to
- Description: JumpCloud extension data on the managed entity:
changes_to. - Source:
changes.to - Usage: passwordvault_credential_update, passwordvault_enable, passwordvault_personalfolder_update, passwordvault_sharedfolder_update, passwordvault_website_update
Src Endpoint
src_endpoint.autonomous_system.name
- Description: Organization name for the Autonomous System.
- Source:
asn.organization - Usage: passwordvault_enable
src_endpoint.autonomous_system.number
- Description: Unique number that the AS is identified by.
- Source:
asn.number - Transform:
asn.number→int(passwordvault_enable)- Usage: passwordvault_enable
src_endpoint.ip
- Description: Source IP address the request originated from.
- Source:
client_ip - Usage: all events in this service
src_endpoint.location.city
- Description: The name of the city.
- Source:
geoip.city - Usage: passwordvault_enable
src_endpoint.location.continent
- Description: The name of the continent.
- Source:
geoip.continent_code - Usage: passwordvault_enable
src_endpoint.location.country
- Description: The ISO 3166-1 Alpha-2 country code.
Note: The two letter country code should be capitalized. For example:
USorCA. - Source:
geoip.country_code - Usage: passwordvault_enable
src_endpoint.location.lat
- Description: The geographical Latitude coordinate represented in Decimal Degrees (DD). For example:
42.361145. - Source:
geoip.latitude - Transform:
geoip.latitude→double(passwordvault_enable)- Usage: passwordvault_enable
src_endpoint.location.long
- Description: The geographical Longitude coordinate represented in Decimal Degrees (DD). For example:
-71.057083. - Source:
geoip.longitude - Transform:
geoip.longitude→double(passwordvault_enable)- Usage: passwordvault_enable
src_endpoint.location.region
- Description: The alphanumeric code that identifies the principal subdivision (e.g. province or state) of the country. For example, 'CH-VD' for the Canton of Vaud, Switzerland
- Source:
geoip.region_code - Usage: passwordvault_enable
Http Request
http_request.user_agent
- Description: The request header that identifies the operating system and web browser.
- Source:
user_agent - Usage: all events in this service
Observables
observables[].name
- Description: The full name of the observable attribute. The
nameis a pointer/reference to an attribute within the OCSF event data. For example:file.name. Array attributes may be represented in one of three ways. For example:resources.uid,resources[].uid,resources[0].uid. - Literal:
actor.user.email_addr,actor.user.name,actor.user.uid,http_request.user_agent,src_endpoint.ip,src_endpoint.location.country,user.email_addr,user.uid - Usage: all events in this service
observables[].type_id
- Description: The observable value type identifier.
- Literal:
14,16,2,31,4,5 - Usage: all events in this service
observables[].value
- Description: The value associated with the observable attribute. The meaning of the value depends on the observable type.
If thenamerefers to a scalar attribute, then thevalueis the value of the attribute.
If thenamerefers to an object attribute, then thevalueis not populated. - Source:
client_ip,geoip.country_code,initiated_by.email,initiated_by.id,initiated_by.username,resource.id,resource.name,user_agent - Usage: all events in this service
Unmapped
unmapped.@version
- Description: JumpCloud Directory Insights field
@versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
@version - Usage: all events in this service
unmapped.asn.network
- Description: JumpCloud Directory Insights field
asn.networkpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
asn.network - Usage: passwordvault_enable
unmapped.changed_field
- Description: JumpCloud Directory Insights field
changed_fieldpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.field - Usage: passwordvault_user_disable, passwordvault_user_enable
unmapped.changes_from
- Description: JumpCloud Directory Insights field
changes_frompreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.from - Usage: passwordvault_user_disable, passwordvault_user_enable
unmapped.changes_to
- Description: JumpCloud Directory Insights field
changes_topreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to - Usage: passwordvault_user_disable, passwordvault_user_enable
unmapped.geoip.region_name
- Description: JumpCloud Directory Insights field
geoip.region_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.region_name - Usage: passwordvault_enable
unmapped.geoip.timezone
- Description: JumpCloud Directory Insights field
geoip.timezonepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.timezone - Usage: passwordvault_enable
unmapped.initiated_by.administrator
- Description: JumpCloud Directory Insights field
initiated_by.administratorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by.administrator - Usage: all events in this service
unmapped.initiated_by_email_hash
- Description: JumpCloud Directory Insights field
initiated_by_email_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_email_hash - Usage: all events in this service
unmapped.initiated_by_id_hash
- Description: JumpCloud Directory Insights field
initiated_by_id_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_id_hash - Usage: all events in this service
unmapped.initiated_by_username_hash
- Description: JumpCloud Directory Insights field
initiated_by_username_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_username_hash - Usage: 42 events: passwordvault_credential_add, passwordvault_credential_archive, passwordvault_credential_autofill, passwordvault_credential_copy, passwordvault_credential_delete, passwordvault_credential_duplicate, passwordvault_credential_export, passwordvault_credential_history_reveal, ... (+34 more)
unmapped.is_out_of_bound
- Description: JumpCloud Directory Insights field
is_out_of_boundpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
is_out_of_bound - Usage: all events in this service
unmapped.jc_application_name
- Description: JumpCloud Directory Insights field
jc_application_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_application_name - Usage: all events in this service
unmapped.jc_initiated_by_email
- Description: JumpCloud Directory Insights field
jc_initiated_by_emailpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_initiated_by_email - Usage: 20 events: passwordvault_credential_add, passwordvault_credential_export, passwordvault_credential_history_reveal, passwordvault_credential_shareusergroup, passwordvault_group_disable, passwordvault_personalfolder_create, passwordvault_personalfolder_website_remove, passwordvault_sharedfolder_create, ... (+12 more)
unmapped.jc_initiated_by_username
- Description: JumpCloud Directory Insights field
jc_initiated_by_usernamepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_initiated_by_username - Usage: 20 events: passwordvault_credential_add, passwordvault_credential_export, passwordvault_credential_history_reveal, passwordvault_credential_shareusergroup, passwordvault_group_disable, passwordvault_personalfolder_create, passwordvault_personalfolder_website_remove, passwordvault_sharedfolder_create, ... (+12 more)
unmapped.jc_organization_name
- Description: JumpCloud Directory Insights field
jc_organization_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_organization_name - Usage: 20 events: passwordvault_credential_add, passwordvault_credential_export, passwordvault_credential_history_reveal, passwordvault_credential_shareusergroup, passwordvault_group_disable, passwordvault_personalfolder_create, passwordvault_personalfolder_website_remove, passwordvault_sharedfolder_create, ... (+12 more)
unmapped.jc_provider_id
- Description: JumpCloud Directory Insights field
jc_provider_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_provider_id - Usage: 15 events: passwordvault_credential_add, passwordvault_credential_export, passwordvault_credential_shareusergroup, passwordvault_group_disable, passwordvault_personalfolder_create, passwordvault_personalfolder_website_remove, passwordvault_sharedfolder_create, passwordvault_sharedfolder_user_update, ... (+7 more)
unmapped.resource_id_hash
- Description: JumpCloud Directory Insights field
resource_id_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource_id_hash - Usage: all events in this service
unmapped.timestamp_source
- Description: JumpCloud Directory Insights field
timestamp_sourcepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
timestamp_source - Usage: all events in this service
unmapped.useragent.device
- Description: JumpCloud Directory Insights field
useragent.devicepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.device - Usage: passwordvault_enable
unmapped.useragent.major
- Description: JumpCloud Directory Insights field
useragent.majorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.major - Usage: passwordvault_enable
unmapped.useragent.minor
- Description: JumpCloud Directory Insights field
useragent.minorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.minor - Usage: passwordvault_enable
unmapped.useragent.name
- Description: JumpCloud Directory Insights field
useragent.namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.name - Usage: passwordvault_enable
unmapped.useragent.os
- Description: JumpCloud Directory Insights field
useragent.ospreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os - Usage: passwordvault_enable
unmapped.useragent.os_full
- Description: JumpCloud Directory Insights field
useragent.os_fullpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_full - Usage: passwordvault_enable
unmapped.useragent.os_major
- Description: JumpCloud Directory Insights field
useragent.os_majorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_major - Usage: passwordvault_enable
unmapped.useragent.os_minor
- Description: JumpCloud Directory Insights field
useragent.os_minorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_minor - Usage: passwordvault_enable
unmapped.useragent.os_name
- Description: JumpCloud Directory Insights field
useragent.os_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_name - Usage: passwordvault_enable
unmapped.useragent.os_patch
- Description: JumpCloud Directory Insights field
useragent.os_patchpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_patch - Usage: passwordvault_enable
unmapped.useragent.os_version
- Description: JumpCloud Directory Insights field
useragent.os_versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_version - Usage: passwordvault_enable
unmapped.useragent.patch
- Description: JumpCloud Directory Insights field
useragent.patchpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.patch - Usage: passwordvault_enable
unmapped.useragent.version
- Description: JumpCloud Directory Insights field
useragent.versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.version - Usage: passwordvault_enable
RADIUS#
radius · 1 event
| Event | Category | Class | Activity | Type UID | Fields |
|---|---|---|---|---|---|
radius_auth_attempt |
Identity & Access Management (3) | Authentication (3002) | Logon (1) | 300201 | 50 |
OCSF field mappings#
Legend
- Description: what the OCSF field represents (from OCSF schema v1.8.0)
- Source: raw JumpCloud event field(s) mapped via
${{placeholder}}template - Transform:
fieldMappingsentry applied at runtime (cast, enum, etc.) - Literal: static value set in the mapping template
- Usage: event types in this service that include this field
Core
activity_id
- Description: The normalized identifier of the activity that triggered the event.
- Literal:
1 - Usage: all events in this service
activity_name
- Description: The event activity name, as defined by the activity_id.
- Literal:
Logon - Usage: all events in this service
category_name
- Description: The event category name, as defined by category_uid value:
Discovery. - Literal:
Identity & Access Management - Usage: all events in this service
category_uid
- Description: The category unique identifier of the event.
- Literal:
3 - Usage: all events in this service
class_name
- Description: The event class name, as defined by class_uid value:
User Inventory Info. - Literal:
Authentication - Usage: all events in this service
class_uid
- Description: The unique identifier of a class. A class describes the attributes available in an event.
- Literal:
3002 - Usage: all events in this service
severity_id
- Description: OCSF severity identifier for the event.
- Literal:
1 - Usage: all events in this service
status_id
- Description: Normalized status of the activity (1=Success, 2=Failure).
- Source:
success - Transform:
success→boolean_to_status_id; true→1, false→2 (all events in this service)- Usage: all events in this service
time
- Description: Event time, in epoch milliseconds (OCSF
time). - Source:
timestamp - Transform:
timestamp→iso8601_to_epoch_millis(all events in this service)- Usage: all events in this service
type_uid
- Description: The event/finding type ID. It identifies the event's semantics and structure. The value is calculated by the logging system as:
class_uid * 100 + activity_id. - Literal:
300201 - Usage: all events in this service
Metadata
metadata.event_code
- Description: JumpCloud event type code.
- Source:
event_type - Usage: all events in this service
metadata.processed_time
- Description: The event processed time, such as an ETL operation.
- Source:
jc_transformation_ts - Usage: all events in this service
metadata.product.name
- Description: Originating JumpCloud service that produced the event.
- Source:
service - Usage: all events in this service
metadata.tenant_uid
- Description: JumpCloud organization (tenant) identifier.
- Source:
organization - Usage: all events in this service
metadata.uid
- Description: Unique event identifier assigned by JumpCloud.
- Source:
id - Usage: all events in this service
metadata.version
- Description: OCSF schema version used for this event.
- Literal:
1.8.0 - Usage: all events in this service
Actor
actor.user.type_id
- Description: OCSF user type of the actor (1=User, 2=Admin, 3=System, 4=Service).
- Source:
initiated_by.type - Transform:
initiated_by.type→enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (all events in this service)- Usage: all events in this service
User
user.email_addr
- Description: Email address of the user associated with the event.
- Source:
initiated_by.username - Usage: all events in this service
user.name
- Description: The username. For example,
janedoe1. - Source:
username - Usage: all events in this service
Src Endpoint
src_endpoint.ip
- Description: Source IP address the request originated from.
- Source:
client_ip - Usage: all events in this service
src_endpoint.location.city
- Description: The name of the city.
- Source:
geoip.city - Usage: all events in this service
src_endpoint.location.continent
- Description: The name of the continent.
- Source:
geoip.continent_code - Usage: all events in this service
src_endpoint.location.country
- Description: The ISO 3166-1 Alpha-2 country code.
Note: The two letter country code should be capitalized. For example:
USorCA. - Source:
geoip.country_code - Usage: all events in this service
src_endpoint.location.lat
- Description: The geographical Latitude coordinate represented in Decimal Degrees (DD). For example:
42.361145. - Source:
geoip.latitude - Transform:
geoip.latitude→double(all events in this service)- Usage: all events in this service
src_endpoint.location.long
- Description: The geographical Longitude coordinate represented in Decimal Degrees (DD). For example:
-71.057083. - Source:
geoip.longitude - Transform:
geoip.longitude→double(all events in this service)- Usage: all events in this service
src_endpoint.location.region
- Description: The alphanumeric code that identifies the principal subdivision (e.g. province or state) of the country. For example, 'CH-VD' for the Canton of Vaud, Switzerland
- Source:
geoip.region_code - Usage: all events in this service
Http Request
http_request.user_agent
- Description: The request header that identifies the operating system and web browser.
- Source:
user_agent - Usage: all events in this service
Observables
observables[].name
- Description: The full name of the observable attribute. The
nameis a pointer/reference to an attribute within the OCSF event data. For example:file.name. Array attributes may be represented in one of three ways. For example:resources.uid,resources[].uid,resources[0].uid. - Literal:
http_request.user_agent,src_endpoint.ip,src_endpoint.location.country,user.email_addr,user.name - Usage: all events in this service
observables[].type_id
- Description: The observable value type identifier.
- Literal:
14,16,2,4,5 - Usage: all events in this service
observables[].value
- Description: The value associated with the observable attribute. The meaning of the value depends on the observable type.
If thenamerefers to a scalar attribute, then thevalueis the value of the attribute.
If thenamerefers to an object attribute, then thevalueis not populated. - Source:
client_ip,geoip.country_code,initiated_by.username,user_agent,username - Usage: all events in this service
Other
auth_protocol
- Description: The authentication protocol as defined by the caption of
auth_protocol_id. In the case ofOther, it is defined by the event source. - Source:
auth_type - Usage: all events in this service
is_mfa
- Description: Indicates whether Multi Factor Authentication was used during authentication.
- Source:
mfa - Usage: all events in this service
raw_data
- Description: The raw event/finding data as received from the source.
- Source:
event.original - Usage: all events in this service
Unmapped
unmapped.@version
- Description: JumpCloud Directory Insights field
@versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
@version - Usage: all events in this service
unmapped.auth_meta.auth_idp
- Description: JumpCloud Directory Insights field
auth_meta.auth_idppreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
auth_meta.auth_idp - Usage: all events in this service
unmapped.auth_meta.device_cert_enabled
- Description: JumpCloud Directory Insights field
auth_meta.device_cert_enabledpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
auth_meta.device_cert_enabled - Usage: all events in this service
unmapped.auth_meta.user_cert_enabled
- Description: JumpCloud Directory Insights field
auth_meta.user_cert_enabledpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
auth_meta.user_cert_enabled - Usage: all events in this service
unmapped.auth_meta.user_password_enabled
- Description: JumpCloud Directory Insights field
auth_meta.user_password_enabledpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
auth_meta.user_password_enabled - Usage: all events in this service
unmapped.auth_meta.userid_type
- Description: JumpCloud Directory Insights field
auth_meta.userid_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
auth_meta.userid_type - Usage: all events in this service
unmapped.geoip.region_name
- Description: JumpCloud Directory Insights field
geoip.region_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.region_name - Usage: all events in this service
unmapped.geoip.timezone
- Description: JumpCloud Directory Insights field
geoip.timezonepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.timezone - Usage: all events in this service
unmapped.initiated_by_username_hash
- Description: JumpCloud Directory Insights field
initiated_by_username_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_username_hash - Usage: all events in this service
unmapped.is_out_of_bound
- Description: JumpCloud Directory Insights field
is_out_of_boundpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
is_out_of_bound - Usage: all events in this service
unmapped.log.file.path
- Description: JumpCloud Directory Insights field
log.file.pathpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
log.file.path - Usage: all events in this service
unmapped.mfa_meta.type
- Description: JumpCloud Directory Insights field
mfa_meta.typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
mfa_meta.type - Usage: all events in this service
unmapped.nas_mfa_state
- Description: JumpCloud Directory Insights field
nas_mfa_statepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
nas_mfa_state - Usage: all events in this service
unmapped.protocol
- Description: JumpCloud Directory Insights field
protocolpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
protocol - Usage: all events in this service
unmapped.radsec
- Description: JumpCloud Directory Insights field
radsecpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
radsec - Usage: all events in this service
unmapped.require_tls_auth
- Description: JumpCloud Directory Insights field
require_tls_authpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
require_tls_auth - Usage: all events in this service
unmapped.username_hash
- Description: JumpCloud Directory Insights field
username_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
username_hash - Usage: all events in this service
Reports#
reports · 13 events
| Event | Category | Class | Activity | Type UID | Fields |
|---|---|---|---|---|---|
custom_report_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 85 |
custom_report_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 79 |
custom_report_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 104 |
report_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 63 |
report_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 63 |
report_export |
Identity & Access Management (3) | Entity Management (3004) | Read (2) | 300402 | 66 |
report_run |
Identity & Access Management (3) | Entity Management (3004) | Read (2) | 300402 | 71 |
report_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 86 |
scheduled_report_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 70 |
scheduled_report_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 70 |
scheduled_report_run_failed |
System Activity (1) | Scheduled Job Activity (1006) | Start (6) | 100606 | 39 |
scheduled_report_run_success |
System Activity (1) | Scheduled Job Activity (1006) | Start (6) | 100606 | 36 |
scheduled_report_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 77 |
OCSF field mappings#
Legend
- Description: what the OCSF field represents (from OCSF schema v1.8.0)
- Source: raw JumpCloud event field(s) mapped via
${{placeholder}}template - Transform:
fieldMappingsentry applied at runtime (cast, enum, etc.) - Literal: static value set in the mapping template
- Usage: event types in this service that include this field
Core
activity_id
- Description: The normalized identifier of the activity that triggered the event.
- Literal:
1,2,3,4,6 - Usage: all events in this service
activity_name
- Description: The event activity name, as defined by the activity_id.
- Literal:
Create,Delete,Read,Start,Update - Usage: all events in this service
category_name
- Description: The event category name, as defined by category_uid value:
Discovery. - Literal:
Identity & Access Management,System Activity - Usage: all events in this service
category_uid
- Description: The category unique identifier of the event.
- Literal:
1,3 - Usage: all events in this service
class_name
- Description: The event class name, as defined by class_uid value:
User Inventory Info. - Literal:
Entity Management,Scheduled Job Activity - Usage: all events in this service
class_uid
- Description: The unique identifier of a class. A class describes the attributes available in an event.
- Literal:
1006,3004 - Usage: all events in this service
severity_id
- Description: OCSF severity identifier for the event.
- Literal:
1 - Usage: all events in this service
status_detail
- Description: The status detail contains additional information about the event/finding outcome.
- Source:
error_message - Usage: all events in this service
status_id
- Description: Normalized status of the activity (1=Success, 2=Failure).
- Source:
success - Transform:
success→boolean_to_status_id; true→1, false→2 (all events in this service)- Usage: all events in this service
time
- Description: Event time, in epoch milliseconds (OCSF
time). - Source:
timestamp - Transform:
timestamp→iso8601_to_epoch_millis(all events in this service)- Usage: all events in this service
type_uid
- Description: The event/finding type ID. It identifies the event's semantics and structure. The value is calculated by the logging system as:
class_uid * 100 + activity_id. - Literal:
100606,300401,300402,300403,300404 - Usage: all events in this service
Metadata
metadata.event_code
- Description: JumpCloud event type code.
- Source:
event_type - Usage: all events in this service
metadata.original_time
- Description: The original event time as reported by the event source. For example, the time in the original format from system event log such as Syslog on Unix/Linux and the System event file on Windows. Omit if event is generated instead of collected via logs.
- Source:
server_timestamp - Usage: all events in this service
metadata.processed_time
- Description: The event processed time, such as an ETL operation.
- Source:
jc_transformation_ts - Usage: all events in this service
metadata.product.name
- Description: Originating JumpCloud service that produced the event.
- Source:
service - Usage: all events in this service
metadata.tenant_uid
- Description: JumpCloud organization (tenant) identifier.
- Source:
organization - Usage: all events in this service
metadata.uid
- Description: Unique event identifier assigned by JumpCloud.
- Source:
id - Usage: all events in this service
metadata.version
- Description: OCSF schema version used for this event.
- Literal:
1.8.0 - Usage: all events in this service
Actor
actor.user.email_addr
- Description: Email address of the actor who initiated the event.
- Source:
initiated_by.email - Usage: 11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more)
actor.user.name
- Description: Display name of the actor who initiated the event.
- Source:
initiated_by.name - Usage: report_run
actor.user.type_id
- Description: OCSF user type of the actor (1=User, 2=Admin, 3=System, 4=Service).
- Source:
initiated_by.type - Transform:
initiated_by.type→enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more))- Usage: 11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more)
actor.user.uid
- Description: Unique identifier of the actor who initiated the event.
- Source:
initiated_by.id - Usage: 11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more)
Entity
entity.data.auth_method
- Description: JumpCloud extension data on the managed entity:
auth_method. - Source:
auth_method - Usage: 11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more)
entity.data.changed_field
- Description: JumpCloud extension data on the managed entity:
changed_field. - Source:
changes.field - Usage: custom_report_update, report_update
entity.data.changes_from_aggregations
- Description: JumpCloud extension data on the managed entity:
changes_from_aggregations. - Source:
changes.from.aggregations - Usage: custom_report_update, report_update
entity.data.changes_from_fields_exclude
- Description: JumpCloud extension data on the managed entity:
changes_from_fields_exclude. - Source:
changes.from.fields.exclude - Usage: custom_report_update, report_update
entity.data.changes_from_fields_include
- Description: JumpCloud extension data on the managed entity:
changes_from_fields_include. - Source:
changes.from.fields.include - Usage: custom_report_update, report_update
entity.data.changes_from_filters_field
- Description: JumpCloud extension data on the managed entity:
changes_from_filters_field. - Source:
changes.from.filters.field - Usage: custom_report_update, report_update
entity.data.changes_from_filters_filters
- Description: JumpCloud extension data on the managed entity:
changes_from_filters_filters. - Source:
changes.from.filters.filters - Usage: custom_report_update, report_update
entity.data.changes_from_filters_operation
- Description: JumpCloud extension data on the managed entity:
changes_from_filters_operation. - Source:
changes.from.filters.operation - Usage: custom_report_update, report_update
entity.data.changes_from_filters_value
- Description: JumpCloud extension data on the managed entity:
changes_from_filters_value. - Source:
changes.from.filters.value - Usage: custom_report_update, report_update
entity.data.changes_from_limit
- Description: JumpCloud extension data on the managed entity:
changes_from_limit. - Source:
changes.from.limit - Usage: custom_report_update, report_update
entity.data.changes_from_requestCache
- Description: JumpCloud extension data on the managed entity:
changes_from_requestCache. - Source:
changes.from.requestCache - Usage: custom_report_update, report_update
entity.data.changes_from_sort
- Description: JumpCloud extension data on the managed entity:
changes_from_sort. - Source:
changes.from.sort - Usage: custom_report_update
entity.data.changes_from_sort_field
- Description: JumpCloud extension data on the managed entity:
changes_from_sort_field. - Source:
changes.from.sort.field - Usage: report_update
entity.data.changes_from_sort_order
- Description: JumpCloud extension data on the managed entity:
changes_from_sort_order. - Source:
changes.from.sort.order - Usage: report_update
entity.data.columns
- Description: JumpCloud extension data on the managed entity:
columns. - Source:
resource.columns - Usage: custom_report_create, custom_report_delete, custom_report_update
entity.data.configuration.column_settings.fixed
- Description: JumpCloud extension data on the managed entity:
configuration.column_settings.fixed. - Source:
resource.configuration.column_settings.fixed - Usage: report_create, report_delete, report_run, report_update
entity.data.configurations
- Description: JumpCloud extension data on the managed entity:
configurations. - Source:
resource.configurations - Usage: report_run
entity.data.cron_expression
- Description: JumpCloud extension data on the managed entity:
cron_expression. - Source:
resource.cron_expression - Usage: scheduled_report_create, scheduled_report_delete, scheduled_report_update
entity.data.description
- Description: JumpCloud extension data on the managed entity:
description. - Source:
resource.description - Usage: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_run, report_update
entity.data.export_mechanism
- Description: JumpCloud extension data on the managed entity:
export_mechanism. - Source:
resource.export_mechanism - Usage: report_export
entity.data.export_method
- Description: JumpCloud extension data on the managed entity:
export_method. - Source:
resource.export_method - Usage: report_export
entity.data.export_type
- Description: JumpCloud extension data on the managed entity:
export_type. - Source:
resource.export_type - Usage: report_export, scheduled_report_create, scheduled_report_delete, scheduled_report_update
entity.data.filters.field
- Description: JumpCloud extension data on the managed entity:
filters.field. - Source:
resource.filters.field - Usage: custom_report_create, custom_report_delete, custom_report_update
entity.data.filters.operation
- Description: JumpCloud extension data on the managed entity:
filters.operation. - Source:
resource.filters.operation - Usage: custom_report_create, custom_report_delete, custom_report_update
entity.data.filters.value
- Description: JumpCloud extension data on the managed entity:
filters.value. - Source:
resource.filters.value - Usage: custom_report_create, custom_report_delete, custom_report_update
entity.data.is_active
- Description: JumpCloud extension data on the managed entity:
is_active. - Source:
resource.is_active - Usage: scheduled_report_create, scheduled_report_delete, scheduled_report_update
entity.data.new_value
- Description: JumpCloud extension data on the managed entity:
new_value. - Source:
changes.new_value - Usage: custom_report_update
entity.data.old_value
- Description: JumpCloud extension data on the managed entity:
old_value. - Source:
changes.old_value - Usage: custom_report_update
entity.data.recipient_count
- Description: JumpCloud extension data on the managed entity:
recipient_count. - Source:
resource.recipient_count - Usage: scheduled_report_create, scheduled_report_delete, scheduled_report_update
entity.data.report_id
- Description: JumpCloud extension data on the managed entity:
report_id. - Source:
resource.report_id - Usage: scheduled_report_create, scheduled_report_delete, scheduled_report_update
entity.data.report_type
- Description: JumpCloud extension data on the managed entity:
report_type. - Source:
resource.report_type - Usage: scheduled_report_create, scheduled_report_delete, scheduled_report_update
entity.data.resources
- Description: JumpCloud extension data on the managed entity:
resources. - Source:
resource.resources - Usage: report_create, report_delete, report_export, report_run, report_update
entity.data.schedule_frequency
- Description: JumpCloud extension data on the managed entity:
schedule_frequency. - Source:
resource.schedule_frequency - Usage: scheduled_report_create, scheduled_report_delete, scheduled_report_update
entity.data.schedule_time
- Description: JumpCloud extension data on the managed entity:
schedule_time. - Source:
resource.schedule_time - Usage: scheduled_report_create, scheduled_report_delete, scheduled_report_update
entity.data.search_request.aggregations
- Description: JumpCloud extension data on the managed entity:
search_request.aggregations. - Source:
resource.search_request.aggregations - Usage: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update
entity.data.search_request.fields.exclude
- Description: JumpCloud extension data on the managed entity:
search_request.fields.exclude. - Source:
resource.search_request.fields.exclude - Usage: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update
entity.data.search_request.fields.include
- Description: JumpCloud extension data on the managed entity:
search_request.fields.include. - Source:
resource.search_request.fields.include - Usage: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update
entity.data.search_request.filters.field
- Description: JumpCloud extension data on the managed entity:
search_request.filters.field. - Source:
resource.search_request.filters.field - Usage: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update
entity.data.search_request.filters.filters
- Description: JumpCloud extension data on the managed entity:
search_request.filters.filters. - Source:
resource.search_request.filters.filters - Usage: custom_report_delete, custom_report_update, report_create, report_delete, report_update
entity.data.search_request.filters.filters.field
- Description: JumpCloud extension data on the managed entity:
search_request.filters.filters.field. - Source:
resource.search_request.filters.filters.field - Usage: custom_report_create, report_export, report_run
entity.data.search_request.filters.filters.filters
- Description: JumpCloud extension data on the managed entity:
search_request.filters.filters.filters. - Source:
resource.search_request.filters.filters.filters - Usage: report_export, report_run
entity.data.search_request.filters.filters.filters.field
- Description: JumpCloud extension data on the managed entity:
search_request.filters.filters.filters.field. - Source:
resource.search_request.filters.filters.filters.field - Usage: custom_report_create
entity.data.search_request.filters.filters.filters.filters
- Description: JumpCloud extension data on the managed entity:
search_request.filters.filters.filters.filters. - Source:
resource.search_request.filters.filters.filters.filters - Usage: custom_report_create
entity.data.search_request.filters.filters.filters.operation
- Description: JumpCloud extension data on the managed entity:
search_request.filters.filters.filters.operation. - Source:
resource.search_request.filters.filters.filters.operation - Usage: custom_report_create
entity.data.search_request.filters.filters.filters.value
- Description: JumpCloud extension data on the managed entity:
search_request.filters.filters.filters.value. - Source:
resource.search_request.filters.filters.filters.value - Usage: custom_report_create
entity.data.search_request.filters.filters.operation
- Description: JumpCloud extension data on the managed entity:
search_request.filters.filters.operation. - Source:
resource.search_request.filters.filters.operation - Usage: custom_report_create, report_export, report_run
entity.data.search_request.filters.filters.value
- Description: JumpCloud extension data on the managed entity:
search_request.filters.filters.value. - Source:
resource.search_request.filters.filters.value - Usage: custom_report_create, report_export, report_run
entity.data.search_request.filters.operation
- Description: JumpCloud extension data on the managed entity:
search_request.filters.operation. - Source:
resource.search_request.filters.operation - Usage: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update
entity.data.search_request.filters.value
- Description: JumpCloud extension data on the managed entity:
search_request.filters.value. - Source:
resource.search_request.filters.value - Usage: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update
entity.data.search_request.limit
- Description: JumpCloud extension data on the managed entity:
search_request.limit. - Source:
resource.search_request.limit - Usage: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_run, report_update
entity.data.search_request.metadata.context
- Description: JumpCloud extension data on the managed entity:
search_request.metadata.context. - Source:
resource.search_request.metadata.context - Usage: custom_report_delete
entity.data.search_request.metadata.context.key
- Description: JumpCloud extension data on the managed entity:
search_request.metadata.context.key. - Source:
resource.search_request.metadata.context.key - Usage: custom_report_update
entity.data.search_request.metadata.context.value
- Description: JumpCloud extension data on the managed entity:
search_request.metadata.context.value. - Source:
resource.search_request.metadata.context.value - Usage: custom_report_update
entity.data.search_request.metadata.source
- Description: JumpCloud extension data on the managed entity:
search_request.metadata.source. - Source:
resource.search_request.metadata.source - Usage: custom_report_update
entity.data.search_request.requestCache
- Description: JumpCloud extension data on the managed entity:
search_request.requestCache. - Source:
resource.search_request.requestCache - Usage: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_update
entity.data.search_request.sort.field
- Description: JumpCloud extension data on the managed entity:
search_request.sort.field. - Source:
resource.search_request.sort.field - Usage: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update
entity.data.search_request.sort.order
- Description: JumpCloud extension data on the managed entity:
search_request.sort.order. - Source:
resource.search_request.sort.order - Usage: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update
entity.data.secondary_objects
- Description: JumpCloud extension data on the managed entity:
secondary_objects. - Source:
resource.secondary_objects - Usage: custom_report_create, custom_report_delete, custom_report_update
entity.data.temporal_schedule_id
- Description: JumpCloud extension data on the managed entity:
temporal_schedule_id. - Source:
resource.temporal_schedule_id - Usage: scheduled_report_create, scheduled_report_delete, scheduled_report_update
entity.data.time_zone
- Description: JumpCloud extension data on the managed entity:
time_zone. - Source:
resource.time_zone - Usage: scheduled_report_create, scheduled_report_delete, scheduled_report_update
entity.name
- Description: The name of the managed entity. It should match the name of the specific entity object's name if populated, or the name of the managed entity if the
type_idis 'Other'. - Source:
resource.display_name,resource.name - Usage: 11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more)
entity.type
- Description: The managed entity type. For example:
Policy,User,Organization,Device. - Source:
resource.primary_object - Usage: custom_report_create, custom_report_delete, custom_report_update
entity.uid
- Description: The identifier of the managed entity. It should match the
uidof the specific entity's object UID if populated, or the source specific ID if thetype_idis 'Other'. - Source:
resource.id - Usage: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_run, report_update, scheduled_report_create, scheduled_report_delete, scheduled_report_update
entity_result.data.changes_to_aggregations
- Description: JumpCloud extension data on the managed entity:
changes_to_aggregations. - Source:
changes.to.aggregations - Usage: custom_report_update, report_update
entity_result.data.changes_to_fields_exclude
- Description: JumpCloud extension data on the managed entity:
changes_to_fields_exclude. - Source:
changes.to.fields.exclude - Usage: custom_report_update, report_update
entity_result.data.changes_to_fields_include
- Description: JumpCloud extension data on the managed entity:
changes_to_fields_include. - Source:
changes.to.fields.include - Usage: custom_report_update, report_update
entity_result.data.changes_to_filters_field
- Description: JumpCloud extension data on the managed entity:
changes_to_filters_field. - Source:
changes.to.filters.field - Usage: custom_report_update, report_update
entity_result.data.changes_to_filters_filters
- Description: JumpCloud extension data on the managed entity:
changes_to_filters_filters. - Source:
changes.to.filters.filters - Usage: custom_report_update, report_update
entity_result.data.changes_to_filters_operation
- Description: JumpCloud extension data on the managed entity:
changes_to_filters_operation. - Source:
changes.to.filters.operation - Usage: custom_report_update, report_update
entity_result.data.changes_to_filters_value
- Description: JumpCloud extension data on the managed entity:
changes_to_filters_value. - Source:
changes.to.filters.value - Usage: custom_report_update, report_update
entity_result.data.changes_to_limit
- Description: JumpCloud extension data on the managed entity:
changes_to_limit. - Source:
changes.to.limit - Usage: custom_report_update, report_update
entity_result.data.changes_to_requestCache
- Description: JumpCloud extension data on the managed entity:
changes_to_requestCache. - Source:
changes.to.requestCache - Usage: custom_report_update, report_update
entity_result.data.changes_to_sort
- Description: JumpCloud extension data on the managed entity:
changes_to_sort. - Source:
changes.to.sort - Usage: custom_report_update
entity_result.data.changes_to_sort_field
- Description: JumpCloud extension data on the managed entity:
changes_to_sort_field. - Source:
changes.to.sort.field - Usage: report_update
entity_result.data.changes_to_sort_order
- Description: JumpCloud extension data on the managed entity:
changes_to_sort_order. - Source:
changes.to.sort.order - Usage: report_update
Src Endpoint
src_endpoint.autonomous_system.name
- Description: Organization name for the Autonomous System.
- Source:
asn.organization - Usage: custom_report_create, custom_report_delete, custom_report_update, scheduled_report_create, scheduled_report_delete, scheduled_report_update
src_endpoint.autonomous_system.number
- Description: Unique number that the AS is identified by.
- Source:
asn.number - Transform:
asn.number→int(custom_report_create, custom_report_delete, custom_report_update, scheduled_report_create, scheduled_report_delete, scheduled_report_update)- Usage: custom_report_create, custom_report_delete, custom_report_update, scheduled_report_create, scheduled_report_delete, scheduled_report_update
src_endpoint.ip
- Description: Source IP address the request originated from.
- Source:
client_ip - Usage: 11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more)
src_endpoint.location.city
- Description: The name of the city.
- Source:
geoip.city - Usage: 11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more)
src_endpoint.location.continent
- Description: The name of the continent.
- Source:
geoip.continent_code - Usage: 11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more)
src_endpoint.location.country
- Description: The ISO 3166-1 Alpha-2 country code.
Note: The two letter country code should be capitalized. For example:
USorCA. - Source:
geoip.country_code - Usage: 11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more)
src_endpoint.location.lat
- Description: The geographical Latitude coordinate represented in Decimal Degrees (DD). For example:
42.361145. - Source:
geoip.latitude - Transform:
geoip.latitude→double(11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more))- Usage: 11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more)
src_endpoint.location.long
- Description: The geographical Longitude coordinate represented in Decimal Degrees (DD). For example:
-71.057083. - Source:
geoip.longitude - Transform:
geoip.longitude→double(11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more))- Usage: 11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more)
src_endpoint.location.region
- Description: The alphanumeric code that identifies the principal subdivision (e.g. province or state) of the country. For example, 'CH-VD' for the Canton of Vaud, Switzerland
- Source:
geoip.region_code - Usage: 11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more)
Http Request
http_request.user_agent
- Description: The request header that identifies the operating system and web browser.
- Source:
user_agent - Usage: custom_report_create, custom_report_delete, custom_report_update, scheduled_report_create, scheduled_report_delete, scheduled_report_update
Observables
observables[].name
- Description: The full name of the observable attribute. The
nameis a pointer/reference to an attribute within the OCSF event data. For example:file.name. Array attributes may be represented in one of three ways. For example:resources.uid,resources[].uid,resources[0].uid. - Literal:
actor.user.email_addr,actor.user.name,actor.user.uid,http_request.user_agent,src_endpoint.ip,src_endpoint.location.country - Usage: 11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more)
observables[].type_id
- Description: The observable value type identifier.
- Literal:
14,16,2,31,4,5 - Usage: 11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more)
observables[].value
- Description: The value associated with the observable attribute. The meaning of the value depends on the observable type.
If thenamerefers to a scalar attribute, then thevalueis the value of the attribute.
If thenamerefers to an object attribute, then thevalueis not populated. - Source:
client_ip,geoip.country_code,initiated_by.email,initiated_by.id,initiated_by.name,user_agent - Usage: 11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more)
Other
end_time
- Description: The end time of a time period, or the time of the most recent event included in the aggregate event.
- Source:
completed_at - Usage: scheduled_report_run_failed, scheduled_report_run_success
job.name
- Description: The name of the job.
- Source:
display_name - Usage: scheduled_report_run_failed, scheduled_report_run_success
Unmapped
unmapped.@version
- Description: JumpCloud Directory Insights field
@versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
@version - Usage: all events in this service
unmapped.artifact_id
- Description: JumpCloud Directory Insights field
artifact_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
artifact_id - Usage: scheduled_report_run_success
unmapped.asn.network
- Description: JumpCloud Directory Insights field
asn.networkpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
asn.network - Usage: custom_report_create, custom_report_delete, custom_report_update, scheduled_report_create, scheduled_report_delete, scheduled_report_update
unmapped.client_ip
- Description: JumpCloud Directory Insights field
client_ippreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
client_ip - Usage: scheduled_report_run_failed, scheduled_report_run_success
unmapped.export_type
- Description: JumpCloud Directory Insights field
export_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
export_type - Usage: scheduled_report_run_failed, scheduled_report_run_success
unmapped.file_size
- Description: JumpCloud Directory Insights field
file_sizepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
file_size - Usage: scheduled_report_run_success
unmapped.geoip.error
- Description: JumpCloud Directory Insights field
geoip.errorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.error - Usage: report_export, report_run
unmapped.geoip.ip_address
- Description: JumpCloud Directory Insights field
geoip.ip_addresspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.ip_address - Usage: report_export, report_run
unmapped.geoip.region_name
- Description: JumpCloud Directory Insights field
geoip.region_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.region_name - Usage: 11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more)
unmapped.geoip.timezone
- Description: JumpCloud Directory Insights field
geoip.timezonepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.timezone - Usage: 11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more)
unmapped.initiated_by
- Description: JumpCloud Directory Insights field
initiated_bypreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by - Usage: scheduled_report_run_failed, scheduled_report_run_success
unmapped.initiated_by_email_hash
- Description: JumpCloud Directory Insights field
initiated_by_email_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_email_hash - Usage: 11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more)
unmapped.initiated_by_id_hash
- Description: JumpCloud Directory Insights field
initiated_by_id_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_id_hash - Usage: 11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more)
unmapped.initiated_by_name_hash
- Description: JumpCloud Directory Insights field
initiated_by_name_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_name_hash - Usage: report_run
unmapped.is_out_of_bound
- Description: JumpCloud Directory Insights field
is_out_of_boundpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
is_out_of_bound - Usage: custom_report_create, custom_report_delete, custom_report_update, scheduled_report_create, scheduled_report_delete, scheduled_report_run_failed, scheduled_report_run_success, scheduled_report_update
unmapped.jc_application_name
- Description: JumpCloud Directory Insights field
jc_application_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_application_name - Usage: custom_report_create, custom_report_delete, custom_report_update, scheduled_report_create, scheduled_report_delete, scheduled_report_run_failed, scheduled_report_run_success, scheduled_report_update
unmapped.jc_initiated_by_email
- Description: JumpCloud Directory Insights field
jc_initiated_by_emailpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_initiated_by_email - Usage: scheduled_report_run_failed, scheduled_report_update
unmapped.jc_initiated_by_id
- Description: JumpCloud Directory Insights field
jc_initiated_by_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_initiated_by_id - Usage: scheduled_report_run_failed, scheduled_report_update
unmapped.jc_initiated_by_username
- Description: JumpCloud Directory Insights field
jc_initiated_by_usernamepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_initiated_by_username - Usage: scheduled_report_run_failed, scheduled_report_update
unmapped.jc_organization_name
- Description: JumpCloud Directory Insights field
jc_organization_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_organization_name - Usage: scheduled_report_run_failed, scheduled_report_update
unmapped.jc_provider_id
- Description: JumpCloud Directory Insights field
jc_provider_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_provider_id - Usage: scheduled_report_run_failed, scheduled_report_update
unmapped.jc_system_display_name
- Description: JumpCloud Directory Insights field
jc_system_display_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_system_display_name - Usage: scheduled_report_run_failed, scheduled_report_update
unmapped.jc_system_hostname
- Description: JumpCloud Directory Insights field
jc_system_hostnamepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_system_hostname - Usage: scheduled_report_run_failed, scheduled_report_update
unmapped.provider
- Description: JumpCloud Directory Insights field
providerpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
provider - Usage: report_export, report_run
unmapped.report_id
- Description: JumpCloud Directory Insights field
report_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
report_id - Usage: scheduled_report_run_success
unmapped.resource_id_hash
- Description: JumpCloud Directory Insights field
resource_id_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource_id_hash - Usage: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_run, report_update, scheduled_report_create, scheduled_report_delete, scheduled_report_update
unmapped.resource_name_hash
- Description: JumpCloud Directory Insights field
resource_name_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource_name_hash - Usage: custom_report_create
unmapped.row_count
- Description: JumpCloud Directory Insights field
row_countpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
row_count - Usage: scheduled_report_run_success
unmapped.schedule_frequency
- Description: JumpCloud Directory Insights field
schedule_frequencypreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
schedule_frequency - Usage: scheduled_report_run_failed, scheduled_report_run_success
unmapped.scheduled_report_id
- Description: JumpCloud Directory Insights field
scheduled_report_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
scheduled_report_id - Usage: scheduled_report_run_failed, scheduled_report_run_success
unmapped.temporal_schedule_id
- Description: JumpCloud Directory Insights field
temporal_schedule_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
temporal_schedule_id - Usage: scheduled_report_run_failed, scheduled_report_run_success
unmapped.timestamp_source
- Description: JumpCloud Directory Insights field
timestamp_sourcepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
timestamp_source - Usage: all events in this service
unmapped.user_agent
- Description: JumpCloud Directory Insights field
user_agentpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
user_agent - Usage: scheduled_report_run_failed, scheduled_report_run_success
unmapped.useragent.device
- Description: JumpCloud Directory Insights field
useragent.devicepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.device - Usage: 11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more)
unmapped.useragent.major
- Description: JumpCloud Directory Insights field
useragent.majorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.major - Usage: 11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more)
unmapped.useragent.minor
- Description: JumpCloud Directory Insights field
useragent.minorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.minor - Usage: 11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more)
unmapped.useragent.name
- Description: JumpCloud Directory Insights field
useragent.namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.name - Usage: 11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more)
unmapped.useragent.os
- Description: JumpCloud Directory Insights field
useragent.ospreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os - Usage: 11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more)
unmapped.useragent.os_full
- Description: JumpCloud Directory Insights field
useragent.os_fullpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_full - Usage: 11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more)
unmapped.useragent.os_major
- Description: JumpCloud Directory Insights field
useragent.os_majorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_major - Usage: custom_report_create, custom_report_delete, custom_report_update, scheduled_report_create, scheduled_report_delete, scheduled_report_update
unmapped.useragent.os_minor
- Description: JumpCloud Directory Insights field
useragent.os_minorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_minor - Usage: custom_report_create, custom_report_delete, custom_report_update, scheduled_report_create, scheduled_report_delete, scheduled_report_update
unmapped.useragent.os_name
- Description: JumpCloud Directory Insights field
useragent.os_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_name - Usage: 11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more)
unmapped.useragent.os_patch
- Description: JumpCloud Directory Insights field
useragent.os_patchpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_patch - Usage: custom_report_create, custom_report_delete, custom_report_update, scheduled_report_create, scheduled_report_delete, scheduled_report_update
unmapped.useragent.os_version
- Description: JumpCloud Directory Insights field
useragent.os_versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_version - Usage: custom_report_create, custom_report_delete, custom_report_update, scheduled_report_create, scheduled_report_delete, scheduled_report_update
unmapped.useragent.patch
- Description: JumpCloud Directory Insights field
useragent.patchpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.patch - Usage: custom_report_create, custom_report_delete, custom_report_update, scheduled_report_create, scheduled_report_delete, scheduled_report_update
unmapped.useragent.version
- Description: JumpCloud Directory Insights field
useragent.versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.version - Usage: 11 events: custom_report_create, custom_report_delete, custom_report_update, report_create, report_delete, report_export, report_run, report_update, ... (+3 more)
unmapped.workflow_execution_id
- Description: JumpCloud Directory Insights field
workflow_execution_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
workflow_execution_id - Usage: scheduled_report_run_failed, scheduled_report_run_success
SaaS Management#
saas_management · 16 events
| Event | Category | Class | Activity | Type UID | Fields |
|---|---|---|---|---|---|
saas_management_account_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 40 |
saas_management_account_discover |
Discovery (5) | User Inventory Info (5003) | Collect (2) | 500302 | 42 |
saas_management_account_user_assign |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 45 |
saas_management_application_access_restriction_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 68 |
saas_management_application_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 43 |
saas_management_application_discover |
Discovery (5) | Software Inventory Info (5020) | Collect (2) | 502002 | 30 |
saas_management_application_review |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 63 |
saas_management_application_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 68 |
saas_management_connector_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 41 |
saas_management_connector_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 39 |
saas_management_connector_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 42 |
saas_management_disable |
Identity & Access Management (3) | Entity Management (3004) | Disable (9) | 300409 | 41 |
saas_management_enable |
Identity & Access Management (3) | Entity Management (3004) | Enable (8) | 300408 | 43 |
saas_management_login_event |
Identity & Access Management (3) | Authentication (3002) | Logon (1) | 300201 | 38 |
saas_management_settings_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 54 |
saas_management_tenant_discover |
Discovery (5) | Cloud Resources Inventory Info (5023) | Collect (2) | 502302 | 31 |
OCSF field mappings#
Legend
- Description: what the OCSF field represents (from OCSF schema v1.8.0)
- Source: raw JumpCloud event field(s) mapped via
${{placeholder}}template - Transform:
fieldMappingsentry applied at runtime (cast, enum, etc.) - Literal: static value set in the mapping template
- Usage: event types in this service that include this field
Core
activity_id
- Description: The normalized identifier of the activity that triggered the event.
- Literal:
1,2,3,4,8,9 - Usage: all events in this service
activity_name
- Description: The event activity name, as defined by the activity_id.
- Literal:
Collect,Create,Delete,Disable,Enable,Logon,Update - Usage: all events in this service
category_name
- Description: The event category name, as defined by category_uid value:
Discovery. - Literal:
Discovery,Identity & Access Management - Usage: all events in this service
category_uid
- Description: The category unique identifier of the event.
- Literal:
3,5 - Usage: all events in this service
class_name
- Description: The event class name, as defined by class_uid value:
User Inventory Info. - Literal:
Authentication,Cloud Resources Inventory Info,Entity Management,Software Inventory Info,User Inventory Info - Usage: all events in this service
class_uid
- Description: The unique identifier of a class. A class describes the attributes available in an event.
- Literal:
3002,3004,5003,5020,5023 - Usage: all events in this service
message
- Description: The description of the event/finding, as defined by the source.
- Source:
detail - Usage: all events in this service
severity_id
- Description: OCSF severity identifier for the event.
- Literal:
1 - Usage: all events in this service
status_detail
- Description: The status detail contains additional information about the event/finding outcome.
- Source:
error_message - Usage: all events in this service
status_id
- Description: Normalized status of the activity (1=Success, 2=Failure).
- Source:
success - Transform:
success→boolean_to_status_id; true→1, false→2 (all events in this service)- Usage: all events in this service
time
- Description: Event time, in epoch milliseconds (OCSF
time). - Source:
timestamp - Transform:
timestamp→iso8601_to_epoch_millis(all events in this service)- Usage: all events in this service
type_uid
- Description: The event/finding type ID. It identifies the event's semantics and structure. The value is calculated by the logging system as:
class_uid * 100 + activity_id. - Literal:
300201,300401,300403,300404,300408,300409,500302,502002,502302 - Usage: all events in this service
Metadata
metadata.event_code
- Description: JumpCloud event type code.
- Source:
event_type - Usage: all events in this service
metadata.original_time
- Description: The original event time as reported by the event source. For example, the time in the original format from system event log such as Syslog on Unix/Linux and the System event file on Windows. Omit if event is generated instead of collected via logs.
- Source:
server_timestamp - Usage: saas_management_account_discover, saas_management_application_access_restriction_update, saas_management_application_discover, saas_management_application_review, saas_management_application_update, saas_management_enable, saas_management_login_event
metadata.processed_time
- Description: The event processed time, such as an ETL operation.
- Source:
jc_transformation_ts - Usage: all events in this service
metadata.product.name
- Description: Originating JumpCloud service that produced the event.
- Source:
service - Usage: all events in this service
metadata.tenant_uid
- Description: JumpCloud organization (tenant) identifier.
- Source:
organization - Usage: all events in this service
metadata.uid
- Description: Unique event identifier assigned by JumpCloud.
- Source:
id - Usage: all events in this service
metadata.version
- Description: OCSF schema version used for this event.
- Literal:
1.8.0 - Usage: all events in this service
Actor
actor.user.email_addr
- Description: Email address of the actor who initiated the event.
- Source:
initiated_by.email - Usage: 12 events: saas_management_account_delete, saas_management_account_user_assign, saas_management_application_access_restriction_update, saas_management_application_delete, saas_management_application_review, saas_management_application_update, saas_management_connector_create, saas_management_connector_delete, ... (+4 more)
actor.user.full_name
- Description: The full name of the user, as reported by the product.
- Source:
initiated_by.name - Usage: saas_management_application_access_restriction_update, saas_management_application_update, saas_management_connector_create
actor.user.name
- Description: Display name of the actor who initiated the event.
- Source:
initiated_by.username - Usage: saas_management_disable, saas_management_enable, saas_management_settings_update
actor.user.type_id
- Description: OCSF user type of the actor (1=User, 2=Admin, 3=System, 4=Service).
- Source:
initiated_by.type - Transform:
initiated_by.type→enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (12 events: saas_management_account_delete, saas_management_account_user_assign, saas_management_application_access_restriction_update, saas_management_application_delete, saas_management_application_review, saas_management_application_update, saas_management_connector_create, saas_management_connector_delete, ... (+4 more))- Usage: 12 events: saas_management_account_delete, saas_management_account_user_assign, saas_management_application_access_restriction_update, saas_management_application_delete, saas_management_application_review, saas_management_application_update, saas_management_connector_create, saas_management_connector_delete, ... (+4 more)
actor.user.uid
- Description: Unique identifier of the actor who initiated the event.
- Source:
initiated_by.id - Usage: 12 events: saas_management_account_delete, saas_management_account_user_assign, saas_management_application_access_restriction_update, saas_management_application_delete, saas_management_application_review, saas_management_application_update, saas_management_connector_create, saas_management_connector_delete, ... (+4 more)
User
user.email_addr
- Description: Email address of the user associated with the event.
- Source:
resource.account_email,resource.account_identifier - Usage: saas_management_account_discover, saas_management_login_event
user.name
- Description: The username. For example,
janedoe1. - Source:
resource.account_username - Usage: saas_management_account_discover
user.uid
- Description: Unique identifier of the user associated with the event.
- Source:
resource.account_id,resource.user_id - Usage: saas_management_account_discover, saas_management_login_event
Entity
entity.data.access_restriction
- Description: JumpCloud extension data on the managed entity:
access_restriction. - Source:
resource.access_restriction - Usage: saas_management_application_access_restriction_update, saas_management_application_review, saas_management_application_update
entity.data.account_count
- Description: JumpCloud extension data on the managed entity:
account_count. - Source:
resource.account_count - Usage: saas_management_application_delete
entity.data.alternative_button_text
- Description: JumpCloud extension data on the managed entity:
alternative_button_text. - Source:
resource.alternative_button_text - Usage: saas_management_application_access_restriction_update, saas_management_application_update
entity.data.alternative_button_url
- Description: JumpCloud extension data on the managed entity:
alternative_button_url. - Source:
resource.alternative_button_url - Usage: saas_management_application_access_restriction_update, saas_management_application_update
entity.data.application_account_count
- Description: JumpCloud extension data on the managed entity:
application_account_count. - Source:
resource.application_account_count - Usage: saas_management_application_delete
entity.data.application_category
- Description: JumpCloud extension data on the managed entity:
application_category. - Source:
resource.application_category - Usage: saas_management_application_access_restriction_update, saas_management_application_review, saas_management_application_update
entity.data.application_name
- Description: JumpCloud extension data on the managed entity:
application_name. - Source:
resource.application_name - Usage: saas_management_account_delete, saas_management_account_user_assign
entity.data.application_owner
- Description: JumpCloud extension data on the managed entity:
application_owner. - Source:
resource.application_owner - Usage: saas_management_application_delete
entity.data.application_status
- Description: JumpCloud extension data on the managed entity:
application_status. - Source:
resource.application_status - Usage: saas_management_application_delete
entity.data.block_restriction_message
- Description: JumpCloud extension data on the managed entity:
block_restriction_message. - Source:
resource.block_restriction_message - Usage: saas_management_settings_update
entity.data.catalog_app_id
- Description: JumpCloud extension data on the managed entity:
catalog_app_id. - Source:
resource.catalog_app_id - Usage: saas_management_application_access_restriction_update, saas_management_application_delete, saas_management_application_review, saas_management_application_update
entity.data.changed_field
- Description: JumpCloud extension data on the managed entity:
changed_field. - Source:
changes.field - Usage: saas_management_account_user_assign, saas_management_application_access_restriction_update, saas_management_application_review, saas_management_application_update, saas_management_connector_update, saas_management_settings_update
entity.data.changes_from
- Description: JumpCloud extension data on the managed entity:
changes_from. - Source:
changes.from - Usage: saas_management_application_access_restriction_update, saas_management_application_review, saas_management_application_update, saas_management_connector_update, saas_management_settings_update
entity.data.default_access_restriction
- Description: JumpCloud extension data on the managed entity:
default_access_restriction. - Source:
resource.default_access_restriction - Usage: saas_management_settings_update
entity.data.discovered_apps_notification_frequency
- Description: JumpCloud extension data on the managed entity:
discovered_apps_notification_frequency. - Source:
resource.discovered_apps_notification_frequency - Usage: saas_management_settings_update
entity.data.excluded_group_ids
- Description: JumpCloud extension data on the managed entity:
excluded_group_ids. - Source:
resource.excluded_group_ids - Usage: saas_management_settings_update
entity.data.former_employee_auto_delete_period
- Description: JumpCloud extension data on the managed entity:
former_employee_auto_delete_period. - Source:
resource.former_employee_auto_delete_period - Usage: saas_management_settings_update
entity.data.is_enabled
- Description: JumpCloud extension data on the managed entity:
is_enabled. - Source:
resource.is_enabled - Usage: saas_management_settings_update
entity.data.owner_user_email
- Description: JumpCloud extension data on the managed entity:
owner_user_email. - Source:
resource.owner_user.email - Usage: saas_management_application_access_restriction_update, saas_management_application_review, saas_management_application_update
entity.data.owner_user_id
- Description: JumpCloud extension data on the managed entity:
owner_user_id. - Source:
resource.owner_user.id - Usage: saas_management_application_access_restriction_update, saas_management_application_review, saas_management_application_update
entity.data.owner_user_name
- Description: JumpCloud extension data on the managed entity:
owner_user_name. - Source:
resource.owner_user.name - Usage: saas_management_application_access_restriction_update, saas_management_application_review, saas_management_application_update
entity.data.status
- Description: JumpCloud extension data on the managed entity:
status. - Source:
resource.status - Usage: saas_management_application_access_restriction_update, saas_management_application_review, saas_management_application_update
entity.data.tracked_domains
- Description: JumpCloud extension data on the managed entity:
tracked_domains. - Source:
resource.tracked_domains - Usage: saas_management_settings_update
entity.data.unapproved_accounts_notification_frequency
- Description: JumpCloud extension data on the managed entity:
unapproved_accounts_notification_frequency. - Source:
resource.unapproved_accounts_notification_frequency - Usage: saas_management_settings_update
entity.data.upcoming_renewal_notification_frequency
- Description: JumpCloud extension data on the managed entity:
upcoming_renewal_notification_frequency. - Source:
resource.upcoming_renewal_notification_frequency - Usage: saas_management_settings_update
entity.data.warning_restriction_message
- Description: JumpCloud extension data on the managed entity:
warning_restriction_message. - Source:
resource.warning_restriction_message - Usage: saas_management_settings_update
entity.name
- Description: The name of the managed entity. It should match the name of the specific entity object's name if populated, or the name of the managed entity if the
type_idis 'Other'. - Source:
resource.application_name,resource.connector_name - Usage: saas_management_application_access_restriction_update, saas_management_application_delete, saas_management_application_review, saas_management_application_update, saas_management_connector_create, saas_management_connector_delete, saas_management_connector_update
entity.type
- Description: The managed entity type. For example:
Policy,User,Organization,Device. - Source:
resource.connector_type - Usage: saas_management_connector_create, saas_management_connector_delete, saas_management_connector_update
entity.uid
- Description: The identifier of the managed entity. It should match the
uidof the specific entity's object UID if populated, or the source specific ID if thetype_idis 'Other'. - Source:
resource.account_id,resource.application_id,resource.connector_id,service - Usage: 12 events: saas_management_account_delete, saas_management_account_user_assign, saas_management_application_access_restriction_update, saas_management_application_delete, saas_management_application_review, saas_management_application_update, saas_management_connector_create, saas_management_connector_delete, ... (+4 more)
entity.user.email_addr
- Description: The user's primary email address.
- Source:
resource.account_email - Usage: saas_management_account_delete, saas_management_account_user_assign
entity.user.name
- Description: The username. For example,
janedoe1. - Source:
resource.account_username - Usage: saas_management_account_delete, saas_management_account_user_assign
entity_result.data.changes_to
- Description: JumpCloud extension data on the managed entity:
changes_to. - Source:
changes.to - Usage: saas_management_account_user_assign, saas_management_application_access_restriction_update, saas_management_application_review, saas_management_application_update, saas_management_connector_update, saas_management_settings_update
entity_result.user.email_addr
- Description: The user's primary email address.
- Source:
resource.user_email - Usage: saas_management_account_user_assign
entity_result.user.name
- Description: The username. For example,
janedoe1. - Source:
resource.user_display_name - Usage: saas_management_account_user_assign
entity_result.user.uid
- Description: The unique user identifier. For example, the Windows user SID, ActiveDirectory DN or AWS user ARN.
- Source:
resource.user_id - Usage: saas_management_account_user_assign
Src Endpoint
src_endpoint.autonomous_system.name
- Description: Organization name for the Autonomous System.
- Source:
asn.organization - Usage: saas_management_application_access_restriction_update, saas_management_application_review, saas_management_application_update
src_endpoint.autonomous_system.number
- Description: Unique number that the AS is identified by.
- Source:
asn.number - Transform:
asn.number→int(saas_management_application_access_restriction_update, saas_management_application_review, saas_management_application_update)- Usage: saas_management_application_access_restriction_update, saas_management_application_review, saas_management_application_update
src_endpoint.ip
- Description: Source IP address the request originated from.
- Source:
client_ip - Usage: 12 events: saas_management_account_delete, saas_management_account_user_assign, saas_management_application_access_restriction_update, saas_management_application_delete, saas_management_application_review, saas_management_application_update, saas_management_connector_create, saas_management_connector_delete, ... (+4 more)
src_endpoint.location.city
- Description: The name of the city.
- Source:
geoip.city - Usage: 12 events: saas_management_account_delete, saas_management_account_user_assign, saas_management_application_access_restriction_update, saas_management_application_delete, saas_management_application_review, saas_management_application_update, saas_management_connector_create, saas_management_connector_delete, ... (+4 more)
src_endpoint.location.continent
- Description: The name of the continent.
- Source:
geoip.continent_code - Usage: 12 events: saas_management_account_delete, saas_management_account_user_assign, saas_management_application_access_restriction_update, saas_management_application_delete, saas_management_application_review, saas_management_application_update, saas_management_connector_create, saas_management_connector_delete, ... (+4 more)
src_endpoint.location.country
- Description: The ISO 3166-1 Alpha-2 country code.
Note: The two letter country code should be capitalized. For example:
USorCA. - Source:
geoip.country_code - Usage: 12 events: saas_management_account_delete, saas_management_account_user_assign, saas_management_application_access_restriction_update, saas_management_application_delete, saas_management_application_review, saas_management_application_update, saas_management_connector_create, saas_management_connector_delete, ... (+4 more)
src_endpoint.location.lat
- Description: The geographical Latitude coordinate represented in Decimal Degrees (DD). For example:
42.361145. - Source:
geoip.latitude - Transform:
geoip.latitude→double(12 events: saas_management_account_delete, saas_management_account_user_assign, saas_management_application_access_restriction_update, saas_management_application_delete, saas_management_application_review, saas_management_application_update, saas_management_connector_create, saas_management_connector_delete, ... (+4 more))- Usage: 12 events: saas_management_account_delete, saas_management_account_user_assign, saas_management_application_access_restriction_update, saas_management_application_delete, saas_management_application_review, saas_management_application_update, saas_management_connector_create, saas_management_connector_delete, ... (+4 more)
src_endpoint.location.long
- Description: The geographical Longitude coordinate represented in Decimal Degrees (DD). For example:
-71.057083. - Source:
geoip.longitude - Transform:
geoip.longitude→double(12 events: saas_management_account_delete, saas_management_account_user_assign, saas_management_application_access_restriction_update, saas_management_application_delete, saas_management_application_review, saas_management_application_update, saas_management_connector_create, saas_management_connector_delete, ... (+4 more))- Usage: 12 events: saas_management_account_delete, saas_management_account_user_assign, saas_management_application_access_restriction_update, saas_management_application_delete, saas_management_application_review, saas_management_application_update, saas_management_connector_create, saas_management_connector_delete, ... (+4 more)
src_endpoint.location.region
- Description: The alphanumeric code that identifies the principal subdivision (e.g. province or state) of the country. For example, 'CH-VD' for the Canton of Vaud, Switzerland
- Source:
geoip.region_code - Usage: 12 events: saas_management_account_delete, saas_management_account_user_assign, saas_management_application_access_restriction_update, saas_management_application_delete, saas_management_application_review, saas_management_application_update, saas_management_connector_create, saas_management_connector_delete, ... (+4 more)
Http Request
http_request.user_agent
- Description: The request header that identifies the operating system and web browser.
- Source:
user_agent - Usage: saas_management_application_access_restriction_update, saas_management_application_review, saas_management_application_update
Observables
observables[].name
- Description: The full name of the observable attribute. The
nameis a pointer/reference to an attribute within the OCSF event data. For example:file.name. Array attributes may be represented in one of three ways. For example:resources.uid,resources[].uid,resources[0].uid. - Literal:
actor.user.email_addr,actor.user.name,actor.user.uid,cloud.account.name,cloud.account.uid,entity.user.email_addr,entity.user.name,entity_result.user.email_addr,entity_result.user.name,entity_result.user.uid,http_request.user_agent,src_endpoint.ip,src_endpoint.location.country,user.email_addr,user.name,user.uid - Usage: 15 events (missing: saas_management_application_discover)
observables[].type_id
- Description: The observable value type identifier.
- Literal:
14,16,2,31,34,35,4,5 - Usage: 15 events (missing: saas_management_application_discover)
observables[].value
- Description: The value associated with the observable attribute. The meaning of the value depends on the observable type.
If thenamerefers to a scalar attribute, then thevalueis the value of the attribute.
If thenamerefers to an object attribute, then thevalueis not populated. - Source:
client_ip,geoip.country_code,initiated_by.email,initiated_by.id,initiated_by.username,resource.account_email,resource.account_id,resource.account_identifier,resource.account_username,resource.tenant_display_name,resource.tenant_id,resource.user_display_name,resource.user_email,resource.user_id,user_agent - Usage: 15 events (missing: saas_management_application_discover)
Other
cloud.account.name
- Description: The name of the account (e.g.
GCP Project name,Linux Account nameorAWS Account name). - Source:
resource.tenant_display_name - Usage: saas_management_login_event, saas_management_tenant_discover
cloud.account.uid
- Description: The unique identifier of the account (e.g.
AWS Account ID,OCID,GCP Project ID,Azure Subscription ID,Google Workspace Customer ID, orM365 Tenant UID). - Source:
resource.tenant_id - Usage: saas_management_tenant_discover
product.name
- Description: The name of the product.
- Source:
resource.application_name - Usage: saas_management_application_discover
product.uid
- Description: The unique identifier of the product.
- Source:
resource.application_id - Usage: saas_management_application_discover
service.name
- Description: The name of the service.
- Source:
resource.application_name - Usage: saas_management_login_event
Unmapped
unmapped.@version
- Description: JumpCloud Directory Insights field
@versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
@version - Usage: all events in this service
unmapped.asn.network
- Description: JumpCloud Directory Insights field
asn.networkpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
asn.network - Usage: saas_management_application_access_restriction_update, saas_management_application_review, saas_management_application_update
unmapped.client_ip
- Description: JumpCloud Directory Insights field
client_ippreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
client_ip - Usage: saas_management_account_discover, saas_management_application_discover, saas_management_login_event, saas_management_tenant_discover
unmapped.file_input_timestamp
- Description: JumpCloud Directory Insights field
file_input_timestamppreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
file_input_timestamp - Usage: saas_management_application_access_restriction_update, saas_management_application_update
unmapped.geoip.region_name
- Description: JumpCloud Directory Insights field
geoip.region_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.region_name - Usage: 12 events: saas_management_account_delete, saas_management_account_user_assign, saas_management_application_access_restriction_update, saas_management_application_delete, saas_management_application_review, saas_management_application_update, saas_management_connector_create, saas_management_connector_delete, ... (+4 more)
unmapped.geoip.timezone
- Description: JumpCloud Directory Insights field
geoip.timezonepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.timezone - Usage: 12 events: saas_management_account_delete, saas_management_account_user_assign, saas_management_application_access_restriction_update, saas_management_application_delete, saas_management_application_review, saas_management_application_update, saas_management_connector_create, saas_management_connector_delete, ... (+4 more)
unmapped.initiated_by
- Description: JumpCloud Directory Insights field
initiated_bypreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by - Usage: saas_management_account_discover, saas_management_application_discover, saas_management_login_event, saas_management_tenant_discover
unmapped.initiated_by.hostname
- Description: JumpCloud Directory Insights field
initiated_by.hostnamepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by.hostname - Usage: saas_management_disable, saas_management_enable, saas_management_settings_update
unmapped.initiated_by.uid
- Description: JumpCloud Directory Insights field
initiated_by.uidpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by.uid - Usage: saas_management_disable, saas_management_enable, saas_management_settings_update
unmapped.initiated_by_email_hash
- Description: JumpCloud Directory Insights field
initiated_by_email_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_email_hash - Usage: 12 events: saas_management_account_delete, saas_management_account_user_assign, saas_management_application_access_restriction_update, saas_management_application_delete, saas_management_application_review, saas_management_application_update, saas_management_connector_create, saas_management_connector_delete, ... (+4 more)
unmapped.initiated_by_id_hash
- Description: JumpCloud Directory Insights field
initiated_by_id_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_id_hash - Usage: 12 events: saas_management_account_delete, saas_management_account_user_assign, saas_management_application_access_restriction_update, saas_management_application_delete, saas_management_application_review, saas_management_application_update, saas_management_connector_create, saas_management_connector_delete, ... (+4 more)
unmapped.initiated_by_name_hash
- Description: JumpCloud Directory Insights field
initiated_by_name_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_name_hash - Usage: saas_management_application_access_restriction_update, saas_management_application_update, saas_management_connector_create
unmapped.initiated_by_username_hash
- Description: JumpCloud Directory Insights field
initiated_by_username_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_username_hash - Usage: saas_management_disable, saas_management_enable, saas_management_settings_update
unmapped.is_out_of_bound
- Description: JumpCloud Directory Insights field
is_out_of_boundpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
is_out_of_bound - Usage: saas_management_application_access_restriction_update, saas_management_application_discover, saas_management_application_review, saas_management_application_update
unmapped.jc_application_name
- Description: JumpCloud Directory Insights field
jc_application_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_application_name - Usage: saas_management_application_access_restriction_update, saas_management_application_discover, saas_management_application_review, saas_management_application_update
unmapped.jc_initiated_by_email
- Description: JumpCloud Directory Insights field
jc_initiated_by_emailpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_initiated_by_email - Usage: saas_management_application_access_restriction_update, saas_management_application_review, saas_management_application_update
unmapped.jc_initiated_by_id
- Description: JumpCloud Directory Insights field
jc_initiated_by_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_initiated_by_id - Usage: saas_management_application_access_restriction_update, saas_management_application_review, saas_management_application_update
unmapped.jc_initiated_by_username
- Description: JumpCloud Directory Insights field
jc_initiated_by_usernamepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_initiated_by_username - Usage: saas_management_application_access_restriction_update, saas_management_application_review, saas_management_application_update
unmapped.jc_organization_name
- Description: JumpCloud Directory Insights field
jc_organization_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_organization_name - Usage: saas_management_application_access_restriction_update, saas_management_application_review, saas_management_application_update
unmapped.jc_provider_id
- Description: JumpCloud Directory Insights field
jc_provider_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_provider_id - Usage: saas_management_application_access_restriction_update, saas_management_application_review, saas_management_application_update
unmapped.jc_system_display_name
- Description: JumpCloud Directory Insights field
jc_system_display_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_system_display_name - Usage: saas_management_application_access_restriction_update, saas_management_application_review, saas_management_application_update
unmapped.jc_system_hostname
- Description: JumpCloud Directory Insights field
jc_system_hostnamepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_system_hostname - Usage: saas_management_application_access_restriction_update, saas_management_application_review, saas_management_application_update
unmapped.resource.application_category
- Description: JumpCloud Directory Insights field
resource.application_categorypreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.application_category - Usage: saas_management_application_discover
unmapped.resource.application_name
- Description: JumpCloud Directory Insights field
resource.application_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.application_name - Usage: saas_management_account_discover
unmapped.resource.catalog_app_id
- Description: JumpCloud Directory Insights field
resource.catalog_app_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.catalog_app_id - Usage: saas_management_application_discover
unmapped.resource.discovery_info.browser_id
- Description: JumpCloud Directory Insights field
resource.discovery_info.browser_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.discovery_info.browser_id - Usage: saas_management_account_discover, saas_management_login_event
unmapped.resource.discovery_info.browser_type
- Description: JumpCloud Directory Insights field
resource.discovery_info.browser_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.discovery_info.browser_type - Usage: saas_management_account_discover, saas_management_login_event
unmapped.resource.discovery_info.browser_version
- Description: JumpCloud Directory Insights field
resource.discovery_info.browser_versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.discovery_info.browser_version - Usage: saas_management_account_discover, saas_management_login_event
unmapped.resource.discovery_info.connector_id
- Description: JumpCloud Directory Insights field
resource.discovery_info.connector_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.discovery_info.connector_id - Usage: saas_management_account_discover, saas_management_tenant_discover
unmapped.resource.discovery_info.connector_name
- Description: JumpCloud Directory Insights field
resource.discovery_info.connector_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.discovery_info.connector_name - Usage: saas_management_account_discover, saas_management_tenant_discover
unmapped.resource.discovery_info.connector_type
- Description: JumpCloud Directory Insights field
resource.discovery_info.connector_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.discovery_info.connector_type - Usage: saas_management_account_discover, saas_management_tenant_discover
unmapped.resource.discovery_info.discovery_type
- Description: JumpCloud Directory Insights field
resource.discovery_info.discovery_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.discovery_info.discovery_type - Usage: saas_management_account_discover, saas_management_login_event, saas_management_tenant_discover
unmapped.resource.discovery_info.extension_version
- Description: JumpCloud Directory Insights field
resource.discovery_info.extension_versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.discovery_info.extension_version - Usage: saas_management_account_discover, saas_management_login_event
unmapped.resource.discovery_info.source_event_id
- Description: JumpCloud Directory Insights field
resource.discovery_info.source_event_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.discovery_info.source_event_id - Usage: saas_management_account_discover
unmapped.resource.discovery_info.user_agent_name
- Description: JumpCloud Directory Insights field
resource.discovery_info.user_agent_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.discovery_info.user_agent_name - Usage: saas_management_account_discover
unmapped.resource.discovery_info.user_agent_os
- Description: JumpCloud Directory Insights field
resource.discovery_info.user_agent_ospreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.discovery_info.user_agent_os - Usage: saas_management_account_discover
unmapped.resource.discovery_info.user_agent_version
- Description: JumpCloud Directory Insights field
resource.discovery_info.user_agent_versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.discovery_info.user_agent_version - Usage: saas_management_account_discover
unmapped.resource.login_at
- Description: JumpCloud Directory Insights field
resource.login_atpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.login_at - Usage: saas_management_login_event
unmapped.resource.login_type
- Description: JumpCloud Directory Insights field
resource.login_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.login_type - Usage: saas_management_login_event
unmapped.resource.sso_provider
- Description: JumpCloud Directory Insights field
resource.sso_providerpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.sso_provider - Usage: saas_management_login_event
unmapped.resource.tenant_application_name
- Description: JumpCloud Directory Insights field
resource.tenant_application_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.tenant_application_name - Usage: saas_management_tenant_discover
unmapped.timestamp_source
- Description: JumpCloud Directory Insights field
timestamp_sourcepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
timestamp_source - Usage: saas_management_account_discover, saas_management_application_access_restriction_update, saas_management_application_discover, saas_management_application_review, saas_management_application_update, saas_management_enable, saas_management_login_event
unmapped.user_agent
- Description: JumpCloud Directory Insights field
user_agentpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
user_agent - Usage: saas_management_application_discover
Slack Integration#
slack_integration · 2 events
| Event | Category | Class | Activity | Type UID | Fields |
|---|---|---|---|---|---|
slack_integration_added |
Application Activity (6) | Application Lifecycle (6002) | Install (1) | 600201 | 58 |
slack_integration_removed |
Application Activity (6) | Application Lifecycle (6002) | Remove (2) | 600202 | 58 |
OCSF field mappings#
Legend
- Description: what the OCSF field represents (from OCSF schema v1.8.0)
- Source: raw JumpCloud event field(s) mapped via
${{placeholder}}template - Transform:
fieldMappingsentry applied at runtime (cast, enum, etc.) - Literal: static value set in the mapping template
- Usage: event types in this service that include this field
Core
activity_id
- Description: The normalized identifier of the activity that triggered the event.
- Literal:
1,2 - Usage: all events in this service
activity_name
- Description: The event activity name, as defined by the activity_id.
- Literal:
Install,Remove - Usage: all events in this service
category_name
- Description: The event category name, as defined by category_uid value:
Discovery. - Literal:
Application Activity - Usage: all events in this service
category_uid
- Description: The category unique identifier of the event.
- Literal:
6 - Usage: all events in this service
class_name
- Description: The event class name, as defined by class_uid value:
User Inventory Info. - Literal:
Application Lifecycle - Usage: all events in this service
class_uid
- Description: The unique identifier of a class. A class describes the attributes available in an event.
- Literal:
6002 - Usage: all events in this service
severity_id
- Description: OCSF severity identifier for the event.
- Literal:
1 - Usage: all events in this service
status_detail
- Description: The status detail contains additional information about the event/finding outcome.
- Source:
error_message - Usage: all events in this service
status_id
- Description: Normalized status of the activity (1=Success, 2=Failure).
- Source:
success - Transform:
success→boolean_to_status_id; true→1, false→2 (all events in this service)- Usage: all events in this service
time
- Description: Event time, in epoch milliseconds (OCSF
time). - Source:
timestamp - Transform:
timestamp→iso8601_to_epoch_millis(all events in this service)- Usage: all events in this service
type_uid
- Description: The event/finding type ID. It identifies the event's semantics and structure. The value is calculated by the logging system as:
class_uid * 100 + activity_id. - Literal:
600201,600202 - Usage: all events in this service
Metadata
metadata.event_code
- Description: JumpCloud event type code.
- Source:
event_type - Usage: all events in this service
metadata.original_time
- Description: The original event time as reported by the event source. For example, the time in the original format from system event log such as Syslog on Unix/Linux and the System event file on Windows. Omit if event is generated instead of collected via logs.
- Source:
server_timestamp - Usage: all events in this service
metadata.processed_time
- Description: The event processed time, such as an ETL operation.
- Source:
jc_transformation_ts - Usage: all events in this service
metadata.product.name
- Description: Originating JumpCloud service that produced the event.
- Source:
service - Usage: all events in this service
metadata.tenant_uid
- Description: JumpCloud organization (tenant) identifier.
- Source:
organization - Usage: all events in this service
metadata.uid
- Description: Unique event identifier assigned by JumpCloud.
- Source:
id - Usage: all events in this service
metadata.version
- Description: OCSF schema version used for this event.
- Literal:
1.8.0 - Usage: all events in this service
Actor
actor.user.email_addr
- Description: Email address of the actor who initiated the event.
- Source:
initiated_by.email - Usage: all events in this service
actor.user.type_id
- Description: OCSF user type of the actor (1=User, 2=Admin, 3=System, 4=Service).
- Source:
initiated_by.type - Transform:
initiated_by.type→enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (all events in this service)- Usage: all events in this service
actor.user.uid
- Description: Unique identifier of the actor who initiated the event.
- Source:
initiated_by.id - Usage: all events in this service
Observables
observables[].name
- Description: The full name of the observable attribute. The
nameis a pointer/reference to an attribute within the OCSF event data. For example:file.name. Array attributes may be represented in one of three ways. For example:resources.uid,resources[].uid,resources[0].uid. - Literal:
actor.user.email_addr,actor.user.uid - Usage: all events in this service
observables[].type_id
- Description: The observable value type identifier.
- Literal:
31,5 - Usage: all events in this service
observables[].value
- Description: The value associated with the observable attribute. The meaning of the value depends on the observable type.
If thenamerefers to a scalar attribute, then thevalueis the value of the attribute.
If thenamerefers to an object attribute, then thevalueis not populated. - Source:
initiated_by.email,initiated_by.id - Usage: all events in this service
Other
app.name
- Description: The name of the product.
- Source:
resource.context.slack_workspace_name - Usage: all events in this service
app.uid
- Description: The unique identifier of the product.
- Source:
resource.id - Usage: all events in this service
Unmapped
unmapped.@version
- Description: JumpCloud Directory Insights field
@versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
@version - Usage: all events in this service
unmapped.asn.error
- Description: JumpCloud Directory Insights field
asn.errorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
asn.error - Usage: all events in this service
unmapped.asn.ip_address
- Description: JumpCloud Directory Insights field
asn.ip_addresspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
asn.ip_address - Usage: all events in this service
unmapped.asn.network
- Description: JumpCloud Directory Insights field
asn.networkpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
asn.network - Usage: all events in this service
unmapped.asn.number
- Description: JumpCloud Directory Insights field
asn.numberpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
asn.number - Usage: all events in this service
unmapped.asn.organization
- Description: JumpCloud Directory Insights field
asn.organizationpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
asn.organization - Usage: all events in this service
unmapped.client_ip
- Description: JumpCloud Directory Insights field
client_ippreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
client_ip - Usage: all events in this service
unmapped.geoip.city
- Description: JumpCloud Directory Insights field
geoip.citypreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.city - Usage: all events in this service
unmapped.geoip.continent_code
- Description: JumpCloud Directory Insights field
geoip.continent_codepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.continent_code - Usage: all events in this service
unmapped.geoip.country_code
- Description: JumpCloud Directory Insights field
geoip.country_codepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.country_code - Usage: all events in this service
unmapped.geoip.latitude
- Description: JumpCloud Directory Insights field
geoip.latitudepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.latitude - Usage: all events in this service
unmapped.geoip.longitude
- Description: JumpCloud Directory Insights field
geoip.longitudepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.longitude - Usage: all events in this service
unmapped.geoip.region_code
- Description: JumpCloud Directory Insights field
geoip.region_codepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.region_code - Usage: all events in this service
unmapped.geoip.region_name
- Description: JumpCloud Directory Insights field
geoip.region_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.region_name - Usage: all events in this service
unmapped.geoip.timezone
- Description: JumpCloud Directory Insights field
geoip.timezonepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.timezone - Usage: all events in this service
unmapped.initiated_by_email_hash
- Description: JumpCloud Directory Insights field
initiated_by_email_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_email_hash - Usage: all events in this service
unmapped.initiated_by_id_hash
- Description: JumpCloud Directory Insights field
initiated_by_id_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_id_hash - Usage: all events in this service
unmapped.is_out_of_bound
- Description: JumpCloud Directory Insights field
is_out_of_boundpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
is_out_of_bound - Usage: all events in this service
unmapped.jc_application_name
- Description: JumpCloud Directory Insights field
jc_application_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_application_name - Usage: all events in this service
unmapped.jc_initiated_by_email
- Description: JumpCloud Directory Insights field
jc_initiated_by_emailpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_initiated_by_email - Usage: all events in this service
unmapped.jc_initiated_by_id
- Description: JumpCloud Directory Insights field
jc_initiated_by_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_initiated_by_id - Usage: all events in this service
unmapped.jc_initiated_by_username
- Description: JumpCloud Directory Insights field
jc_initiated_by_usernamepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_initiated_by_username - Usage: all events in this service
unmapped.jc_organization_name
- Description: JumpCloud Directory Insights field
jc_organization_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_organization_name - Usage: all events in this service
unmapped.jc_provider_id
- Description: JumpCloud Directory Insights field
jc_provider_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_provider_id - Usage: all events in this service
unmapped.jc_system_display_name
- Description: JumpCloud Directory Insights field
jc_system_display_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_system_display_name - Usage: all events in this service
unmapped.jc_system_hostname
- Description: JumpCloud Directory Insights field
jc_system_hostnamepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_system_hostname - Usage: all events in this service
unmapped.resource.type
- Description: JumpCloud Directory Insights field
resource.typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.type - Usage: all events in this service
unmapped.resource_id_hash
- Description: JumpCloud Directory Insights field
resource_id_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource_id_hash - Usage: all events in this service
unmapped.slack_workspace_domain
- Description: JumpCloud Directory Insights field
slack_workspace_domainpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.slack_workspace_domain - Usage: all events in this service
unmapped.slack_workspace_id
- Description: JumpCloud Directory Insights field
slack_workspace_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.context.slack_workspace_id - Usage: all events in this service
unmapped.timestamp_source
- Description: JumpCloud Directory Insights field
timestamp_sourcepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
timestamp_source - Usage: all events in this service
unmapped.user_agent
- Description: JumpCloud Directory Insights field
user_agentpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
user_agent - Usage: all events in this service
Software#
software · 7 events
| Event | Category | Class | Activity | Type UID | Fields |
|---|---|---|---|---|---|
software_add |
Application Activity (6) | Application Lifecycle (6002) | Install (1) | 600201 | 72 |
software_add_request |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 42 |
software_change |
Application Activity (6) | Application Lifecycle (6002) | Update (8) | 600208 | 62 |
software_change_request |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 43 |
software_remove |
Application Activity (6) | Application Lifecycle (6002) | Remove (2) | 600202 | 65 |
software_remove_request |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 42 |
software_status_update |
Application Activity (6) | Application Lifecycle (6002) | Update (8) | 600208 | 37 |
OCSF field mappings#
Legend
- Description: what the OCSF field represents (from OCSF schema v1.8.0)
- Source: raw JumpCloud event field(s) mapped via
${{placeholder}}template - Transform:
fieldMappingsentry applied at runtime (cast, enum, etc.) - Literal: static value set in the mapping template
- Usage: event types in this service that include this field
Core
activity_id
- Description: The normalized identifier of the activity that triggered the event.
- Literal:
1,2,3,4,8 - Usage: all events in this service
activity_name
- Description: The event activity name, as defined by the activity_id.
- Literal:
Create,Delete,Install,Remove,Update - Usage: all events in this service
category_name
- Description: The event category name, as defined by category_uid value:
Discovery. - Literal:
Application Activity,Identity & Access Management - Usage: all events in this service
category_uid
- Description: The category unique identifier of the event.
- Literal:
3,6 - Usage: all events in this service
class_name
- Description: The event class name, as defined by class_uid value:
User Inventory Info. - Literal:
Application Lifecycle,Entity Management - Usage: all events in this service
class_uid
- Description: The unique identifier of a class. A class describes the attributes available in an event.
- Literal:
3004,6002 - Usage: all events in this service
severity_id
- Description: OCSF severity identifier for the event.
- Literal:
1 - Usage: all events in this service
status_detail
- Description: The status detail contains additional information about the event/finding outcome.
- Source:
error_message - Usage: software_add, software_change, software_remove, software_status_update
status_id
- Description: Normalized status of the activity (1=Success, 2=Failure).
- Source:
success - Transform:
success→boolean_to_status_id; true→1, false→2 (all events in this service)- Usage: all events in this service
time
- Description: Event time, in epoch milliseconds (OCSF
time). - Source:
timestamp - Transform:
timestamp→iso8601_to_epoch_millis(all events in this service)- Usage: all events in this service
type_uid
- Description: The event/finding type ID. It identifies the event's semantics and structure. The value is calculated by the logging system as:
class_uid * 100 + activity_id. - Literal:
300401,300403,300404,600201,600202,600208 - Usage: all events in this service
Metadata
metadata.event_code
- Description: JumpCloud event type code.
- Source:
event_type - Usage: all events in this service
metadata.original_time
- Description: The original event time as reported by the event source. For example, the time in the original format from system event log such as Syslog on Unix/Linux and the System event file on Windows. Omit if event is generated instead of collected via logs.
- Source:
server_timestamp - Usage: all events in this service
metadata.product.name
- Description: Originating JumpCloud service that produced the event.
- Source:
service - Usage: all events in this service
metadata.tenant_uid
- Description: JumpCloud organization (tenant) identifier.
- Source:
organization - Usage: all events in this service
metadata.uid
- Description: Unique event identifier assigned by JumpCloud.
- Source:
id - Usage: all events in this service
metadata.version
- Description: OCSF schema version used for this event.
- Literal:
1.8.0 - Usage: all events in this service
Actor
actor.user.email_addr
- Description: Email address of the actor who initiated the event.
- Source:
initiated_by.email - Usage: software_add, software_add_request, software_change, software_change_request, software_remove, software_remove_request
actor.user.type_id
- Description: OCSF user type of the actor (1=User, 2=Admin, 3=System, 4=Service).
- Source:
initiated_by.type - Transform:
initiated_by.type→enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (software_add, software_add_request, software_change, software_change_request, software_remove, software_remove_request)- Usage: software_add, software_add_request, software_change, software_change_request, software_remove, software_remove_request
actor.user.uid
- Description: Unique identifier of the actor who initiated the event.
- Source:
initiated_by.id - Usage: software_add, software_add_request, software_change, software_change_request, software_remove, software_remove_request
Entity
entity.data.app_management_source
- Description: JumpCloud extension data on the managed entity:
app_management_source. - Source:
app_management_source - Usage: software_add_request, software_change_request, software_remove_request
entity.data.application_display_name
- Description: JumpCloud extension data on the managed entity:
application_display_name. - Source:
application.display_name - Usage: software_add_request, software_change_request, software_remove_request
entity.data.application_id
- Description: JumpCloud extension data on the managed entity:
application_id. - Source:
application.id - Usage: software_add_request, software_change_request, software_remove_request
entity.data.changes
- Description: JumpCloud extension data on the managed entity:
changes. - Source:
changes - Usage: software_change_request
entity.data.package_manager
- Description: JumpCloud extension data on the managed entity:
package_manager. - Source:
application.package_manager - Usage: software_add_request, software_change_request, software_remove_request
entity.name
- Description: The name of the managed entity. It should match the name of the specific entity object's name if populated, or the name of the managed entity if the
type_idis 'Other'. - Source:
resource.display_name - Usage: software_add_request, software_change_request, software_remove_request
entity.type
- Description: The managed entity type. For example:
Policy,User,Organization,Device. - Source:
resource.type - Usage: software_add_request, software_change_request, software_remove_request
entity.uid
- Description: The identifier of the managed entity. It should match the
uidof the specific entity's object UID if populated, or the source specific ID if thetype_idis 'Other'. - Source:
resource.id - Usage: software_add_request, software_change_request, software_remove_request
Src Endpoint
src_endpoint.ip
- Description: Source IP address the request originated from.
- Source:
client_ip - Usage: software_add_request, software_change_request, software_remove_request
src_endpoint.location.continent
- Description: The name of the continent.
- Source:
geoip.continent_code - Usage: software_add_request, software_change_request, software_remove_request
src_endpoint.location.country
- Description: The ISO 3166-1 Alpha-2 country code.
Note: The two letter country code should be capitalized. For example:
USorCA. - Source:
geoip.country_code - Usage: software_add_request, software_change_request, software_remove_request
src_endpoint.location.lat
- Description: The geographical Latitude coordinate represented in Decimal Degrees (DD). For example:
42.361145. - Source:
geoip.latitude - Transform:
geoip.latitude→double(software_add_request, software_change_request, software_remove_request)- Usage: software_add_request, software_change_request, software_remove_request
src_endpoint.location.long
- Description: The geographical Longitude coordinate represented in Decimal Degrees (DD). For example:
-71.057083. - Source:
geoip.longitude - Transform:
geoip.longitude→double(software_add_request, software_change_request, software_remove_request)- Usage: software_add_request, software_change_request, software_remove_request
src_endpoint.location.region
- Description: The alphanumeric code that identifies the principal subdivision (e.g. province or state) of the country. For example, 'CH-VD' for the Canton of Vaud, Switzerland
- Source:
geoip.region_code - Usage: software_add_request, software_change_request, software_remove_request
Observables
observables[].name
- Description: The full name of the observable attribute. The
nameis a pointer/reference to an attribute within the OCSF event data. For example:file.name. Array attributes may be represented in one of three ways. For example:resources.uid,resources[].uid,resources[0].uid. - Literal:
actor.user.email_addr,actor.user.uid,src_endpoint.ip,src_endpoint.location.country - Usage: software_add, software_add_request, software_change, software_change_request, software_remove, software_remove_request
observables[].type_id
- Description: The observable value type identifier.
- Literal:
14,2,31,5 - Usage: software_add, software_add_request, software_change, software_change_request, software_remove, software_remove_request
observables[].value
- Description: The value associated with the observable attribute. The meaning of the value depends on the observable type.
If thenamerefers to a scalar attribute, then thevalueis the value of the attribute.
If thenamerefers to an object attribute, then thevalueis not populated. - Source:
client_ip,geoip.country_code,initiated_by.email,initiated_by.id - Usage: software_add, software_add_request, software_change, software_change_request, software_remove, software_remove_request
Other
app.name
- Description: The name of the product.
- Source:
application.display_name,application.name,resource.app_name - Usage: software_add, software_change, software_remove, software_status_update
app.path
- Description: The installation path of the product.
- Source:
application.path - Usage: software_add, software_remove
app.uid
- Description: The unique identifier of the product.
- Source:
resource.app_id,resource.id - Usage: software_add, software_change, software_remove, software_status_update
app.vendor_name
- Description: The name of the vendor of the product.
- Source:
app_management_source,application.publisher - Usage: software_add, software_remove, software_status_update
app.version
- Description: The version of the product, as defined by the event source. For example:
2013.1.3-beta. - Source:
application.version - Usage: software_add, software_remove
Unmapped
unmapped.@timestamp
- Description: JumpCloud Directory Insights field
@timestamppreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
@timestamp - Usage: software_add_request, software_change_request, software_remove_request
unmapped.@version
- Description: JumpCloud Directory Insights field
@versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
@version - Usage: all events in this service
unmapped.application.package_manager
- Description: JumpCloud Directory Insights field
application.package_managerpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
application.package_manager - Usage: software_add, software_change, software_remove
unmapped.application.uninstall_string
- Description: JumpCloud Directory Insights field
application.uninstall_stringpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
application.uninstall_string - Usage: software_add, software_remove
unmapped.application_id_hash
- Description: JumpCloud Directory Insights field
application_id_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
application_id_hash - Usage: software_add, software_remove
unmapped.asn.error
- Description: JumpCloud Directory Insights field
asn.errorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
asn.error - Usage: software_add, software_change
unmapped.asn.ip_address
- Description: JumpCloud Directory Insights field
asn.ip_addresspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
asn.ip_address - Usage: software_add, software_change
unmapped.asn.network
- Description: JumpCloud Directory Insights field
asn.networkpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
asn.network - Usage: software_add, software_change, software_remove
unmapped.asn.number
- Description: JumpCloud Directory Insights field
asn.numberpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
asn.number - Usage: software_add, software_change, software_remove
unmapped.asn.organization
- Description: JumpCloud Directory Insights field
asn.organizationpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
asn.organization - Usage: software_add, software_change, software_remove
unmapped.changes
- Description: JumpCloud Directory Insights field
changespreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes - Usage: software_add, software_remove
unmapped.changes.field
- Description: JumpCloud Directory Insights field
changes.fieldpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.field - Usage: software_change, software_status_update
unmapped.changes.from
- Description: JumpCloud Directory Insights field
changes.frompreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.from - Usage: software_change, software_status_update
unmapped.changes.to
- Description: JumpCloud Directory Insights field
changes.topreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to - Usage: software_change, software_status_update
unmapped.client_ip
- Description: JumpCloud Directory Insights field
client_ippreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
client_ip - Usage: software_add, software_change, software_remove, software_status_update
unmapped.file_input_timestamp
- Description: JumpCloud Directory Insights field
file_input_timestamppreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
file_input_timestamp - Usage: software_add, software_add_request, software_change_request, software_remove_request
unmapped.geoip.city
- Description: JumpCloud Directory Insights field
geoip.citypreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.city - Usage: software_add, software_change, software_remove
unmapped.geoip.continent_code
- Description: JumpCloud Directory Insights field
geoip.continent_codepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.continent_code - Usage: software_add, software_change, software_remove
unmapped.geoip.country_code
- Description: JumpCloud Directory Insights field
geoip.country_codepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.country_code - Usage: software_add, software_change, software_remove
unmapped.geoip.latitude
- Description: JumpCloud Directory Insights field
geoip.latitudepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.latitude - Usage: software_add, software_change, software_remove
unmapped.geoip.longitude
- Description: JumpCloud Directory Insights field
geoip.longitudepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.longitude - Usage: software_add, software_change, software_remove
unmapped.geoip.region_code
- Description: JumpCloud Directory Insights field
geoip.region_codepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.region_code - Usage: software_add, software_change, software_remove
unmapped.geoip.region_name
- Description: JumpCloud Directory Insights field
geoip.region_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.region_name - Usage: software_add, software_add_request, software_change, software_change_request, software_remove, software_remove_request
unmapped.geoip.timezone
- Description: JumpCloud Directory Insights field
geoip.timezonepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.timezone - Usage: software_add, software_add_request, software_change, software_change_request, software_remove, software_remove_request
unmapped.initiated_by
- Description: JumpCloud Directory Insights field
initiated_bypreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by - Usage: software_status_update
unmapped.initiated_by_email_hash
- Description: JumpCloud Directory Insights field
initiated_by_email_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_email_hash - Usage: software_add, software_change, software_remove
unmapped.initiated_by_id_hash
- Description: JumpCloud Directory Insights field
initiated_by_id_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_id_hash - Usage: software_add, software_change, software_remove
unmapped.is_out_of_bound
- Description: JumpCloud Directory Insights field
is_out_of_boundpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
is_out_of_bound - Usage: software_add, software_change, software_remove, software_status_update
unmapped.jc_application_name
- Description: JumpCloud Directory Insights field
jc_application_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_application_name - Usage: software_add, software_change, software_remove, software_status_update
unmapped.jc_initiated_by_email
- Description: JumpCloud Directory Insights field
jc_initiated_by_emailpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_initiated_by_email - Usage: software_add
unmapped.jc_initiated_by_username
- Description: JumpCloud Directory Insights field
jc_initiated_by_usernamepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_initiated_by_username - Usage: software_add
unmapped.jc_organization_name
- Description: JumpCloud Directory Insights field
jc_organization_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_organization_name - Usage: software_add
unmapped.jc_provider_id
- Description: JumpCloud Directory Insights field
jc_provider_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_provider_id - Usage: software_add
unmapped.jc_transformation_ts
- Description: JumpCloud Directory Insights field
jc_transformation_tspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_transformation_ts - Usage: software_add, software_change, software_remove, software_status_update
unmapped.provider
- Description: JumpCloud Directory Insights field
providerpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
provider - Usage: software_add, software_change, software_remove
unmapped.resource.application_type
- Description: JumpCloud Directory Insights field
resource.application_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.application_type - Usage: software_add, software_change, software_remove
unmapped.resource.display_name
- Description: JumpCloud Directory Insights field
resource.display_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.display_name - Usage: software_add, software_change, software_remove
unmapped.resource.enterprise_id
- Description: JumpCloud Directory Insights field
resource.enterprise_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.enterprise_id - Usage: software_add, software_change, software_remove
unmapped.resource.id
- Description: JumpCloud Directory Insights field
resource.idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.id - Usage: software_status_update
unmapped.resource.install_type
- Description: JumpCloud Directory Insights field
resource.install_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.install_type - Usage: software_add, software_change, software_remove
unmapped.resource.managed_configuration
- Description: JumpCloud Directory Insights field
resource.managed_configurationpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.managed_configuration - Usage: software_add, software_change, software_remove
unmapped.resource.package_manager
- Description: JumpCloud Directory Insights field
resource.package_managerpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.package_manager - Usage: software_add, software_change, software_remove
unmapped.resource.runtime_permissions
- Description: JumpCloud Directory Insights field
resource.runtime_permissionspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.runtime_permissions - Usage: software_add, software_change, software_remove
unmapped.resource.system_id
- Description: JumpCloud Directory Insights field
resource.system_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.system_id - Usage: software_status_update
unmapped.resource.type
- Description: JumpCloud Directory Insights field
resource.typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.type - Usage: software_add, software_change, software_remove, software_status_update
unmapped.resource.update_mode
- Description: JumpCloud Directory Insights field
resource.update_modepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.update_mode - Usage: software_add, software_change, software_remove
unmapped.resource_id_hash
- Description: JumpCloud Directory Insights field
resource_id_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource_id_hash - Usage: software_add, software_change, software_remove, software_status_update
unmapped.state
- Description: JumpCloud Directory Insights field
statepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
state - Usage: software_status_update
unmapped.system.hostname
- Description: JumpCloud Directory Insights field
system.hostnamepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
system.hostname - Usage: software_add, software_remove
unmapped.system.id
- Description: JumpCloud Directory Insights field
system.idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
system.id - Usage: software_add, software_remove
unmapped.tags
- Description: JumpCloud Directory Insights field
tagspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
tags - Usage: software_add_request, software_change_request, software_remove_request
unmapped.timestamp_source
- Description: JumpCloud Directory Insights field
timestamp_sourcepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
timestamp_source - Usage: all events in this service
unmapped.update_trigger
- Description: JumpCloud Directory Insights field
update_triggerpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
update_trigger - Usage: software_status_update
unmapped.user_agent
- Description: JumpCloud Directory Insights field
user_agentpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
user_agent - Usage: software_add, software_change, software_remove, software_status_update
SSO#
sso · 1 event
| Event | Category | Class | Activity | Type UID | Fields |
|---|---|---|---|---|---|
sso_auth |
Identity & Access Management (3) | Authentication (3002) | Logon (1) | 300201 | 67 |
OCSF field mappings#
Legend
- Description: what the OCSF field represents (from OCSF schema v1.8.0)
- Source: raw JumpCloud event field(s) mapped via
${{placeholder}}template - Transform:
fieldMappingsentry applied at runtime (cast, enum, etc.) - Literal: static value set in the mapping template
- Usage: event types in this service that include this field
Core
activity_id
- Description: The normalized identifier of the activity that triggered the event.
- Literal:
1 - Usage: all events in this service
activity_name
- Description: The event activity name, as defined by the activity_id.
- Literal:
Logon - Usage: all events in this service
category_name
- Description: The event category name, as defined by category_uid value:
Discovery. - Literal:
Identity & Access Management - Usage: all events in this service
category_uid
- Description: The category unique identifier of the event.
- Literal:
3 - Usage: all events in this service
class_name
- Description: The event class name, as defined by class_uid value:
User Inventory Info. - Literal:
Authentication - Usage: all events in this service
class_uid
- Description: The unique identifier of a class. A class describes the attributes available in an event.
- Literal:
3002 - Usage: all events in this service
severity_id
- Description: OCSF severity identifier for the event.
- Literal:
1 - Usage: all events in this service
status_detail
- Description: The status detail contains additional information about the event/finding outcome.
- Source:
error_message - Usage: all events in this service
status_id
- Description: Normalized status of the activity (1=Success, 2=Failure).
- Source:
sso_token_success - Transform:
sso_token_success→boolean_to_status_id; true→1, false→2 (all events in this service)- Usage: all events in this service
time
- Description: Event time, in epoch milliseconds (OCSF
time). - Source:
timestamp - Transform:
timestamp→iso8601_to_epoch_millis(all events in this service)- Usage: all events in this service
type_uid
- Description: The event/finding type ID. It identifies the event's semantics and structure. The value is calculated by the logging system as:
class_uid * 100 + activity_id. - Literal:
300201 - Usage: all events in this service
Metadata
metadata.event_code
- Description: JumpCloud event type code.
- Source:
event_type - Usage: all events in this service
metadata.original_time
- Description: The original event time as reported by the event source. For example, the time in the original format from system event log such as Syslog on Unix/Linux and the System event file on Windows. Omit if event is generated instead of collected via logs.
- Source:
server_timestamp - Usage: all events in this service
metadata.product.name
- Description: Originating JumpCloud service that produced the event.
- Source:
service - Usage: all events in this service
metadata.tenant_uid
- Description: JumpCloud organization (tenant) identifier.
- Source:
organization - Usage: all events in this service
metadata.uid
- Description: Unique event identifier assigned by JumpCloud.
- Source:
id - Usage: all events in this service
metadata.version
- Description: OCSF schema version used for this event.
- Literal:
1.8.0 - Usage: all events in this service
Actor
actor.user.type_id
- Description: OCSF user type of the actor (1=User, 2=Admin, 3=System, 4=Service).
- Source:
initiated_by.type - Transform:
initiated_by.type→enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (all events in this service)- Usage: all events in this service
actor.user.uid
- Description: Unique identifier of the actor who initiated the event.
- Source:
initiated_by.id - Usage: all events in this service
User
user.email_addr
- Description: Email address of the user associated with the event.
- Source:
initiated_by.username - Usage: all events in this service
Src Endpoint
src_endpoint.ip
- Description: Source IP address the request originated from.
- Source:
client_ip - Usage: all events in this service
src_endpoint.location.continent
- Description: The name of the continent.
- Source:
geoip.continent_code - Usage: all events in this service
src_endpoint.location.country
- Description: The ISO 3166-1 Alpha-2 country code.
Note: The two letter country code should be capitalized. For example:
USorCA. - Source:
geoip.country_code - Usage: all events in this service
src_endpoint.location.lat
- Description: The geographical Latitude coordinate represented in Decimal Degrees (DD). For example:
42.361145. - Source:
geoip.latitude - Transform:
geoip.latitude→double(all events in this service)- Usage: all events in this service
src_endpoint.location.long
- Description: The geographical Longitude coordinate represented in Decimal Degrees (DD). For example:
-71.057083. - Source:
geoip.longitude - Transform:
geoip.longitude→double(all events in this service)- Usage: all events in this service
src_endpoint.location.region
- Description: The alphanumeric code that identifies the principal subdivision (e.g. province or state) of the country. For example, 'CH-VD' for the Canton of Vaud, Switzerland
- Source:
geoip.region_code - Usage: all events in this service
Observables
observables[].name
- Description: The full name of the observable attribute. The
nameis a pointer/reference to an attribute within the OCSF event data. For example:file.name. Array attributes may be represented in one of three ways. For example:resources.uid,resources[].uid,resources[0].uid. - Literal:
actor.user.uid,src_endpoint.ip,src_endpoint.location.country,user.email_addr - Usage: all events in this service
observables[].type_id
- Description: The observable value type identifier.
- Literal:
14,2,31,5 - Usage: all events in this service
observables[].value
- Description: The value associated with the observable attribute. The meaning of the value depends on the observable type.
If thenamerefers to a scalar attribute, then thevalueis the value of the attribute.
If thenamerefers to an object attribute, then thevalueis not populated. - Source:
client_ip,geoip.country_code,initiated_by.id,initiated_by.username - Usage: all events in this service
Other
auth_protocol
- Description: The authentication protocol as defined by the caption of
auth_protocol_id. In the case ofOther, it is defined by the event source. - Source:
application.sso_type - Usage: all events in this service
is_mfa
- Description: Indicates whether Multi Factor Authentication was used during authentication.
- Source:
mfa - Usage: all events in this service
service.name
- Description: The name of the service.
- Source:
application.display_label - Usage: all events in this service
service.uid
- Description: The unique identifier of the service.
- Source:
application.id - Usage: all events in this service
Unmapped
unmapped.@timestamp
- Description: JumpCloud Directory Insights field
@timestamppreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
@timestamp - Usage: all events in this service
unmapped.@version
- Description: JumpCloud Directory Insights field
@versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
@version - Usage: all events in this service
unmapped.application.name
- Description: JumpCloud Directory Insights field
application.namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
application.name - Usage: all events in this service
unmapped.application.sso_url
- Description: JumpCloud Directory Insights field
application.sso_urlpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
application.sso_url - Usage: all events in this service
unmapped.auth_context.auth_methods.totp.success
- Description: JumpCloud Directory Insights field
auth_context.auth_methods.totp.successpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
auth_context.auth_methods.totp.success - Usage: all events in this service
unmapped.auth_context.policies_applied.id
- Description: JumpCloud Directory Insights field
auth_context.policies_applied.idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
auth_context.policies_applied.id - Usage: all events in this service
unmapped.auth_context.policies_applied.metadata.action
- Description: JumpCloud Directory Insights field
auth_context.policies_applied.metadata.actionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
auth_context.policies_applied.metadata.action - Usage: all events in this service
unmapped.auth_context.policies_applied.metadata.conditions
- Description: JumpCloud Directory Insights field
auth_context.policies_applied.metadata.conditionspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
auth_context.policies_applied.metadata.conditions - Usage: all events in this service
unmapped.auth_context.policies_applied.metadata.resource_type
- Description: JumpCloud Directory Insights field
auth_context.policies_applied.metadata.resource_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
auth_context.policies_applied.metadata.resource_type - Usage: all events in this service
unmapped.auth_context.policies_applied.metadata.targets
- Description: JumpCloud Directory Insights field
auth_context.policies_applied.metadata.targetspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
auth_context.policies_applied.metadata.targets - Usage: all events in this service
unmapped.auth_context.policies_applied.name
- Description: JumpCloud Directory Insights field
auth_context.policies_applied.namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
auth_context.policies_applied.name - Usage: all events in this service
unmapped.file_input_timestamp
- Description: JumpCloud Directory Insights field
file_input_timestamppreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
file_input_timestamp - Usage: all events in this service
unmapped.geoip.region_name
- Description: JumpCloud Directory Insights field
geoip.region_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.region_name - Usage: all events in this service
unmapped.geoip.timezone
- Description: JumpCloud Directory Insights field
geoip.timezonepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.timezone - Usage: all events in this service
unmapped.idp_initiated
- Description: JumpCloud Directory Insights field
idp_initiatedpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
idp_initiated - Usage: all events in this service
unmapped.initiated_by.administrator
- Description: JumpCloud Directory Insights field
initiated_by.administratorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by.administrator - Usage: all events in this service
unmapped.mfa_meta.type
- Description: JumpCloud Directory Insights field
mfa_meta.typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
mfa_meta.type - Usage: all events in this service
unmapped.provider
- Description: JumpCloud Directory Insights field
providerpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
provider - Usage: all events in this service
unmapped.tags
- Description: JumpCloud Directory Insights field
tagspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
tags - Usage: all events in this service
unmapped.target_resource.type
- Description: JumpCloud Directory Insights field
target_resource.typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
target_resource.type - Usage: all events in this service
unmapped.timestamp_source
- Description: JumpCloud Directory Insights field
timestamp_sourcepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
timestamp_source - Usage: all events in this service
unmapped.useragent.device
- Description: JumpCloud Directory Insights field
useragent.devicepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.device - Usage: all events in this service
unmapped.useragent.major
- Description: JumpCloud Directory Insights field
useragent.majorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.major - Usage: all events in this service
unmapped.useragent.minor
- Description: JumpCloud Directory Insights field
useragent.minorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.minor - Usage: all events in this service
unmapped.useragent.name
- Description: JumpCloud Directory Insights field
useragent.namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.name - Usage: all events in this service
unmapped.useragent.os
- Description: JumpCloud Directory Insights field
useragent.ospreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os - Usage: all events in this service
unmapped.useragent.os_full
- Description: JumpCloud Directory Insights field
useragent.os_fullpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_full - Usage: all events in this service
unmapped.useragent.os_major
- Description: JumpCloud Directory Insights field
useragent.os_majorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_major - Usage: all events in this service
unmapped.useragent.os_minor
- Description: JumpCloud Directory Insights field
useragent.os_minorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_minor - Usage: all events in this service
unmapped.useragent.os_name
- Description: JumpCloud Directory Insights field
useragent.os_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_name - Usage: all events in this service
unmapped.useragent.os_patch
- Description: JumpCloud Directory Insights field
useragent.os_patchpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_patch - Usage: all events in this service
unmapped.useragent.os_version
- Description: JumpCloud Directory Insights field
useragent.os_versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_version - Usage: all events in this service
unmapped.useragent.patch
- Description: JumpCloud Directory Insights field
useragent.patchpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.patch - Usage: all events in this service
unmapped.useragent.version
- Description: JumpCloud Directory Insights field
useragent.versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.version - Usage: all events in this service
Systems#
systems · 51 events
| Event | Category | Class | Activity | Type UID | Fields |
|---|---|---|---|---|---|
device_command |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 59 |
google_emm_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 50 |
google_emm_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 48 |
google_emm_enrollment_token_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 55 |
google_emm_enrollment_token_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 56 |
google_emm_enterprise_upgrade |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 47 |
google_emm_lost_mode_disabled |
Identity & Access Management (3) | Entity Management (3004) | Disable (9) | 300409 | 34 |
google_emm_lost_mode_enabled |
Identity & Access Management (3) | Entity Management (3004) | Enable (8) | 300408 | 34 |
google_emm_lost_mode_outgoing_phone_call |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 38 |
google_emm_patch |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 49 |
google_emm_policy_bind |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 29 |
google_emm_policy_unbind |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 29 |
google_emm_reset_password_recently |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 34 |
google_emm_stop_lost_mode_user_attempt |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 38 |
google_emm_sw_app_bind |
Application Activity (6) | Application Lifecycle (6002) | Install (1) | 600201 | 29 |
google_emm_sw_app_unbind |
Application Activity (6) | Application Lifecycle (6002) | Remove (2) | 600202 | 30 |
google_emm_user_exit_lost_mode_recently |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 36 |
linux_commands_devicelock |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 58 |
linux_commands_erasedevice |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 66 |
linux_commands_restartdevice |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 62 |
linux_commands_shutdowndevice |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 61 |
login_attempt |
Identity & Access Management (3) | Authentication (3002) | Logon (1) | 300201 | 66 |
os_major_rollback |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 32 |
os_major_upgrade |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 53 |
os_minor_rollback |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 44 |
os_minor_upgrade |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 53 |
recovery_lock_auto_rotation_success |
System Activity (1) | Scheduled Job Activity (1006) | Start (6) | 100606 | 44 |
recovery_lock_cleared_success |
System Activity (1) | Scheduled Job Activity (1006) | Start (6) | 100606 | 38 |
recovery_lock_password_viewed |
Identity & Access Management (3) | Entity Management (3004) | Read (2) | 300402 | 47 |
recovery_lock_set_success |
System Activity (1) | Scheduled Job Activity (1006) | Start (6) | 100606 | 36 |
remote_assist_settings |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 57 |
remote_session_end |
Identity & Access Management (3) | Entity Management (3004) | Deactivate (11) | 300411 | 52 |
remote_session_feedback |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 58 |
remote_session_join |
Identity & Access Management (3) | Entity Management (3004) | Read (2) | 300402 | 65 |
remote_session_launch_token |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 65 |
remote_session_rejoin |
Identity & Access Management (3) | Entity Management (3004) | Resume (13) | 300413 | 59 |
remote_session_start |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 51 |
system_admin_grant |
Identity & Access Management (3) | User Access Management (3005) | Assign Privileges (1) | 300501 | 52 |
system_admin_revoke |
Identity & Access Management (3) | User Access Management (3005) | Revoke Privileges (2) | 300502 | 52 |
system_fde_key_decrypt |
Identity & Access Management (3) | Entity Management (3004) | Read (2) | 300402 | 64 |
system_fde_key_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 44 |
system_group_admin_grant |
Identity & Access Management (3) | Group Management (3006) | Assign Privileges (1) | 300601 | 58 |
system_group_admin_revoke |
Identity & Access Management (3) | Group Management (3006) | Revoke Privileges (2) | 300602 | 66 |
user_lockout |
Identity & Access Management (3) | Account Change (3001) | Lock (9) | 300109 | 51 |
user_password_change |
Identity & Access Management (3) | Account Change (3001) | Password Change (3) | 300103 | 73 |
windows_commands_devicelock |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 66 |
windows_commands_erasedevice |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 61 |
windows_commands_restartdevice |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 63 |
windows_commands_shutdowndevice |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 61 |
windows_patch_export |
Identity & Access Management (3) | Entity Management (3004) | Read (2) | 300402 | 45 |
windows_patch_install |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 48 |
OCSF field mappings#
Legend
- Description: what the OCSF field represents (from OCSF schema v1.8.0)
- Source: raw JumpCloud event field(s) mapped via
${{placeholder}}template - Transform:
fieldMappingsentry applied at runtime (cast, enum, etc.) - Literal: static value set in the mapping template
- Usage: event types in this service that include this field
Core
activity_id
- Description: The normalized identifier of the activity that triggered the event.
- Literal:
1,11,13,2,3,4,6,8,9 - Usage: all events in this service
activity_name
- Description: The event activity name, as defined by the activity_id.
- Literal:
Assign Privileges,Create,Deactivate,Delete,Disable,Enable,Install,Lock,Logon,Password Change,Read,Remove,Resume,Revoke Privileges,Start,Update - Usage: all events in this service
category_name
- Description: The event category name, as defined by category_uid value:
Discovery. - Literal:
Application Activity,Identity & Access Management,System Activity - Usage: all events in this service
category_uid
- Description: The category unique identifier of the event.
- Literal:
1,3,6 - Usage: all events in this service
class_name
- Description: The event class name, as defined by class_uid value:
User Inventory Info. - Literal:
Account Change,Application Lifecycle,Authentication,Entity Management,Group Management,Scheduled Job Activity,User Access Management - Usage: all events in this service
class_uid
- Description: The unique identifier of a class. A class describes the attributes available in an event.
- Literal:
1006,3001,3002,3004,3005,3006,6002 - Usage: all events in this service
message
- Description: The description of the event/finding, as defined by the source.
- Source:
message,result - Usage: 11 events: login_attempt, recovery_lock_auto_rotation_success, recovery_lock_cleared_success, recovery_lock_password_viewed, recovery_lock_set_success, remote_session_end, remote_session_feedback, remote_session_join, ... (+3 more)
severity_id
- Description: OCSF severity identifier for the event.
- Literal:
1 - Usage: all events in this service
status_detail
- Description: The status detail contains additional information about the event/finding outcome.
- Source:
error_message - Usage: 44 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_lost_mode_disabled, google_emm_lost_mode_enabled, ... (+36 more)
status_id
- Description: Normalized status of the activity (1=Success, 2=Failure).
- Source:
success - Transform:
success→boolean_to_status_id; true→1, false→2 (48 events (missing: os_major_rollback, system_admin_grant, system_admin_revoke))- Usage: 48 events (missing: os_major_rollback, system_admin_grant, system_admin_revoke)
time
- Description: Event time, in epoch milliseconds (OCSF
time). - Source:
timestamp - Transform:
timestamp→iso8601_to_epoch_millis(all events in this service)- Usage: all events in this service
type_uid
- Description: The event/finding type ID. It identifies the event's semantics and structure. The value is calculated by the logging system as:
class_uid * 100 + activity_id. - Literal:
100606,300103,300109,300201,300401,300402,300403,300404,300408,300409,300411,300413,300501,300502,300601,300602,600201,600202 - Usage: all events in this service
Metadata
metadata.event_code
- Description: JumpCloud event type code.
- Source:
event_type - Usage: all events in this service
metadata.original_time
- Description: The original event time as reported by the event source. For example, the time in the original format from system event log such as Syslog on Unix/Linux and the System event file on Windows. Omit if event is generated instead of collected via logs.
- Source:
server_timestamp,system_timestamp - Usage: 35 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_lost_mode_disabled, google_emm_lost_mode_enabled, ... (+27 more)
metadata.processed_time
- Description: The event processed time, such as an ETL operation.
- Source:
jc_transformation_ts - Usage: 48 events (missing: os_major_rollback, system_admin_grant, system_admin_revoke)
metadata.product.name
- Description: Originating JumpCloud service that produced the event.
- Source:
service - Usage: all events in this service
metadata.tenant_uid
- Description: JumpCloud organization (tenant) identifier.
- Source:
organization - Usage: all events in this service
metadata.uid
- Description: Unique event identifier assigned by JumpCloud.
- Source:
id - Usage: all events in this service
metadata.version
- Description: OCSF schema version used for this event.
- Literal:
1.8.0 - Usage: all events in this service
Actor
actor.user.domain
- Description: The domain where the user is defined. For example: the LDAP or Active Directory domain.
- Source:
initiated_by.hostname - Usage: remote_assist_settings, remote_session_end, remote_session_feedback, remote_session_join, remote_session_launch_token, remote_session_rejoin, remote_session_start
actor.user.email_addr
- Description: Email address of the actor who initiated the event.
- Source:
initiated_by.email - Usage: 31 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_patch, linux_commands_devicelock, ... (+23 more)
actor.user.full_name
- Description: The full name of the user, as reported by the product.
- Source:
initiated_by.name - Usage: remote_assist_settings, remote_session_end, remote_session_feedback, remote_session_join, remote_session_launch_token, remote_session_rejoin, remote_session_start
actor.user.name
- Description: Display name of the actor who initiated the event.
- Source:
initiated_by.name,initiated_by.username - Usage: 11 events: login_attempt, remote_assist_settings, remote_session_end, remote_session_feedback, remote_session_join, remote_session_launch_token, remote_session_rejoin, remote_session_start, ... (+3 more)
actor.user.type_id
- Description: OCSF user type of the actor (1=User, 2=Admin, 3=System, 4=Service).
- Source:
initiated_by.type - Transform:
initiated_by.type→enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (39 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_lost_mode_disabled, google_emm_lost_mode_enabled, ... (+31 more))- Usage: 39 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_lost_mode_disabled, google_emm_lost_mode_enabled, ... (+31 more)
actor.user.uid
- Description: Unique identifier of the actor who initiated the event.
- Source:
initiated_by.id,initiated_by.uid - Usage: 31 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_patch, linux_commands_devicelock, ... (+23 more)
User
user.full_name
- Description: The full name of the user, as reported by the product.
- Source:
user.name - Usage: system_admin_grant, system_admin_revoke, system_group_admin_grant
user.name
- Description: The username. For example,
janedoe1. - Source:
resource.username,user.username,username - Usage: login_attempt, system_admin_grant, system_admin_revoke, system_group_admin_grant, user_lockout, user_password_change
user.type
- Description: The type of the user. For example, System, AWS IAM User, etc.
- Source:
resource.type,user.type - Usage: system_admin_grant, system_admin_revoke, system_group_admin_grant, user_lockout, user_password_change
user.uid
- Description: Unique identifier of the user associated with the event.
- Source:
resource.id,user.id - Usage: system_admin_grant, system_admin_revoke, system_group_admin_grant, user_lockout, user_password_change
Device
device.hostname
- Description: The device hostname.
- Source:
system.hostname - Usage: login_attempt, user_lockout, user_password_change
device.name
- Description: The alternate device name, ordinarily as assigned by an administrator.
Note: The Name could be any other string that helps to identify the device, such as a phone number; for example
310-555-1234. - Source:
system.displayName - Usage: login_attempt, user_lockout, user_password_change
device.os.type
- Description: The type of the operating system.
- Source:
mdm_type,system.osFamily - Usage: login_attempt, recovery_lock_auto_rotation_success, recovery_lock_cleared_success, recovery_lock_set_success
device.uid
- Description: The unique identifier of the device. For example the Windows TargetSID or AWS EC2 ARN.
- Source:
system.id,windows_device_uuid - Usage: login_attempt, recovery_lock_auto_rotation_success, recovery_lock_cleared_success, recovery_lock_set_success, user_lockout, user_password_change
Entity
entity.data.admin_email
- Description: JumpCloud extension data on the managed entity:
admin_email. - Source:
admin_info.email - Usage: remote_session_end, remote_session_feedback, remote_session_join, remote_session_launch_token, remote_session_rejoin, remote_session_start
entity.data.admin_id
- Description: JumpCloud extension data on the managed entity:
admin_id. - Source:
admin_info.id - Usage: remote_session_end, remote_session_feedback, remote_session_join, remote_session_launch_token, remote_session_rejoin, remote_session_start
entity.data.admin_name
- Description: JumpCloud extension data on the managed entity:
admin_name. - Source:
admin_info.name - Usage: remote_session_end, remote_session_feedback, remote_session_join, remote_session_launch_token, remote_session_rejoin, remote_session_start
entity.data.auth_method
- Description: JumpCloud extension data on the managed entity:
auth_method. - Source:
auth_method - Usage: linux_commands_devicelock, linux_commands_erasedevice, linux_commands_restartdevice, linux_commands_shutdowndevice, system_fde_key_decrypt, windows_commands_devicelock, windows_commands_erasedevice, windows_commands_restartdevice, windows_commands_shutdowndevice
entity.data.background_access_enabled
- Description: JumpCloud extension data on the managed entity:
background_access_enabled. - Source:
changes.from.background_access_enabled - Usage: remote_assist_settings
entity.data.changed_field
- Description: JumpCloud extension data on the managed entity:
changed_field. - Source:
changes.field - Usage: os_major_rollback, os_major_upgrade, os_minor_rollback, os_minor_upgrade, system_fde_key_update
entity.data.changes_from
- Description: JumpCloud extension data on the managed entity:
changes_from. - Source:
changes.from - Usage: os_major_rollback, os_major_upgrade, os_minor_rollback, os_minor_upgrade, remote_assist_settings
entity.data.command
- Description: JumpCloud extension data on the managed entity:
command. - Source:
command - Usage: device_command
entity.data.device_count
- Description: JumpCloud extension data on the managed entity:
device_count. - Source:
device_count - Usage: windows_patch_install
entity.data.directive_count
- Description: JumpCloud extension data on the managed entity:
directive_count. - Source:
directive_count - Usage: windows_patch_install
entity.data.enrollment_type
- Description: JumpCloud extension data on the managed entity:
enrollment_type. - Source:
resource.enrollment_type - Usage: google_emm_lost_mode_disabled, google_emm_lost_mode_enabled, google_emm_lost_mode_outgoing_phone_call, google_emm_reset_password_recently, google_emm_stop_lost_mode_user_attempt, google_emm_user_exit_lost_mode_recently
entity.data.experience_survey_enabled
- Description: JumpCloud extension data on the managed entity:
experience_survey_enabled. - Source:
changes.from.experience_survey_enabled - Usage: remote_assist_settings
entity.data.feedback
- Description: JumpCloud extension data on the managed entity:
feedback. - Source:
message_chain.feedback - Usage: remote_session_feedback
entity.data.format
- Description: JumpCloud extension data on the managed entity:
format. - Source:
format - Usage: windows_patch_export
entity.data.initiated_by_provider
- Description: JumpCloud extension data on the managed entity:
initiated_by_provider. - Source:
initiated_by.provider - Usage: windows_commands_erasedevice, windows_commands_restartdevice
entity.data.install_type
- Description: JumpCloud extension data on the managed entity:
install_type. - Source:
install_type - Usage: windows_patch_install
entity.data.management_mode
- Description: JumpCloud extension data on the managed entity:
management_mode. - Source:
resource.management_mode - Usage: google_emm_lost_mode_outgoing_phone_call, google_emm_stop_lost_mode_user_attempt
entity.data.notes
- Description: JumpCloud extension data on the managed entity:
notes. - Source:
message_chain.notes - Usage: remote_session_feedback
entity.data.operation_type
- Description: JumpCloud extension data on the managed entity:
operation_type. - Source:
operation_type - Usage: windows_patch_install
entity.data.ownership_type
- Description: JumpCloud extension data on the managed entity:
ownership_type. - Source:
resource.ownership_type - Usage: google_emm_lost_mode_outgoing_phone_call, google_emm_stop_lost_mode_user_attempt
entity.data.patch_count
- Description: JumpCloud extension data on the managed entity:
patch_count. - Source:
patch_count - Usage: windows_patch_export
entity.data.provider
- Description: JumpCloud extension data on the managed entity:
provider. - Source:
provider - Usage: device_command, google_emm_create, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_patch, linux_commands_erasedevice, windows_commands_erasedevice, windows_commands_restartdevice
entity.data.rating
- Description: JumpCloud extension data on the managed entity:
rating. - Source:
message_chain.rating - Usage: remote_session_feedback
entity.data.remote_assist_enabled
- Description: JumpCloud extension data on the managed entity:
remote_assist_enabled. - Source:
changes.from.remote_assist_enabled - Usage: remote_assist_settings
entity.data.session_duration
- Description: JumpCloud extension data on the managed entity:
session_duration. - Source:
correlation.session_duration - Usage: remote_session_end, remote_session_feedback, remote_session_join, remote_session_launch_token, remote_session_rejoin, remote_session_start
entity.data.session_timeout_duration
- Description: JumpCloud extension data on the managed entity:
session_timeout_duration. - Source:
changes.from.session_timeout_duration - Usage: remote_assist_settings
entity.data.silent_assist_enabled
- Description: JumpCloud extension data on the managed entity:
silent_assist_enabled. - Source:
changes.from.silent_assist_enabled - Usage: remote_assist_settings
entity.data.status
- Description: JumpCloud extension data on the managed entity:
status. - Source:
status - Usage: recovery_lock_password_viewed
entity.data.tags
- Description: JumpCloud extension data on the managed entity:
tags. - Source:
tags - Usage: google_emm_create, google_emm_delete, os_major_upgrade, os_minor_upgrade
entity.data.target_type
- Description: JumpCloud extension data on the managed entity:
target_type. - Source:
target_type - Usage: windows_patch_install
entity.data.workflow_id
- Description: JumpCloud extension data on the managed entity:
workflow_id. - Source:
initiated_by.source_metadata.workflow.id - Usage: windows_commands_devicelock
entity.data.workflow_run_id
- Description: JumpCloud extension data on the managed entity:
workflow_run_id. - Source:
initiated_by.source_metadata.workflow.run_id - Usage: windows_commands_devicelock
entity.data.workflow_type
- Description: JumpCloud extension data on the managed entity:
workflow_type. - Source:
initiated_by.source_metadata.workflow.type - Usage: windows_commands_devicelock
entity.device.hostname
- Description: The device hostname.
- Source:
resource.hostname,system.hostname - Usage: 20 events: linux_commands_devicelock, linux_commands_erasedevice, linux_commands_restartdevice, linux_commands_shutdowndevice, os_major_rollback, os_major_upgrade, os_minor_rollback, os_minor_upgrade, ... (+12 more)
entity.device.hw_info.serial_number
- Description: The device manufacturer serial number.
- Source:
system.serialno - Usage: remote_session_end, remote_session_feedback, remote_session_join, remote_session_launch_token, remote_session_rejoin, remote_session_start
entity.device.name
- Description: The alternate device name, ordinarily as assigned by an administrator.
Note: The Name could be any other string that helps to identify the device, such as a phone number; for example
310-555-1234. - Source:
resource.displayName,system.displayName - Usage: 24 events: device_command, google_emm_lost_mode_disabled, google_emm_lost_mode_enabled, google_emm_lost_mode_outgoing_phone_call, google_emm_reset_password_recently, google_emm_stop_lost_mode_user_attempt, google_emm_user_exit_lost_mode_recently, linux_commands_devicelock, ... (+16 more)
entity.device.os.type
- Description: The type of the operating system.
- Source:
system.osFamily - Usage: 12 events: device_command, google_emm_enterprise_upgrade, google_emm_lost_mode_disabled, google_emm_lost_mode_enabled, google_emm_lost_mode_outgoing_phone_call, google_emm_reset_password_recently, google_emm_stop_lost_mode_user_attempt, google_emm_user_exit_lost_mode_recently, ... (+4 more)
entity.device.uid
- Description: The unique identifier of the device. For example the Windows TargetSID or AWS EC2 ARN.
- Source:
resource.id,system.id - Usage: 27 events: device_command, google_emm_lost_mode_disabled, google_emm_lost_mode_enabled, google_emm_lost_mode_outgoing_phone_call, google_emm_reset_password_recently, google_emm_stop_lost_mode_user_attempt, google_emm_user_exit_lost_mode_recently, linux_commands_devicelock, ... (+19 more)
entity.name
- Description: The name of the managed entity. It should match the name of the specific entity object's name if populated, or the name of the managed entity if the
type_idis 'Other'. - Source:
resource.displayName,resource.name - Usage: google_emm_create, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_patch, google_emm_policy_bind, google_emm_policy_unbind, windows_commands_devicelock, windows_commands_restartdevice, windows_commands_shutdowndevice
entity.type
- Description: The managed entity type. For example:
Policy,User,Organization,Device. - Source:
correlation.type,mdm_type,resource.type - Usage: 36 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_lost_mode_disabled, google_emm_lost_mode_enabled, ... (+28 more)
entity.uid
- Description: The identifier of the managed entity. It should match the
uidof the specific entity's object UID if populated, or the source specific ID if thetype_idis 'Other'. - Source:
correlation.id,mdm_device_id,organization,resource.id - Usage: 16 events: google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_patch, google_emm_policy_bind, google_emm_policy_unbind, ... (+8 more)
entity_result.data.background_access_enabled
- Description: JumpCloud extension data on the managed entity:
background_access_enabled. - Source:
changes.to.background_access_enabled - Usage: remote_assist_settings
entity_result.data.changes_to
- Description: JumpCloud extension data on the managed entity:
changes_to. - Source:
changes.to - Usage: os_major_rollback, os_major_upgrade, os_minor_rollback, os_minor_upgrade, remote_assist_settings
entity_result.data.experience_survey_enabled
- Description: JumpCloud extension data on the managed entity:
experience_survey_enabled. - Source:
changes.to.experience_survey_enabled - Usage: remote_assist_settings
entity_result.data.remote_assist_enabled
- Description: JumpCloud extension data on the managed entity:
remote_assist_enabled. - Source:
changes.to.remote_assist_enabled - Usage: remote_assist_settings
entity_result.data.session_timeout_duration
- Description: JumpCloud extension data on the managed entity:
session_timeout_duration. - Source:
changes.to.session_timeout_duration - Usage: remote_assist_settings
entity_result.data.silent_assist_enabled
- Description: JumpCloud extension data on the managed entity:
silent_assist_enabled. - Source:
changes.to.silent_assist_enabled - Usage: remote_assist_settings
Src Endpoint
src_endpoint.autonomous_system.name
- Description: Organization name for the Autonomous System.
- Source:
asn.organization - Usage: 20 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_patch, linux_commands_erasedevice, ... (+12 more)
src_endpoint.autonomous_system.number
- Description: Unique number that the AS is identified by.
- Source:
asn.number - Transform:
asn.number→int(20 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_patch, linux_commands_erasedevice, ... (+12 more))- Usage: 20 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_patch, linux_commands_erasedevice, ... (+12 more)
src_endpoint.ip
- Description: Source IP address the request originated from.
- Source:
client_ip - Usage: 37 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_patch, linux_commands_devicelock, ... (+29 more)
src_endpoint.location.city
- Description: The name of the city.
- Source:
geoip.city - Usage: 25 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_patch, linux_commands_devicelock, ... (+17 more)
src_endpoint.location.continent
- Description: The name of the continent.
- Source:
geoip.continent_code - Usage: 29 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_patch, linux_commands_devicelock, ... (+21 more)
src_endpoint.location.country
- Description: The ISO 3166-1 Alpha-2 country code.
Note: The two letter country code should be capitalized. For example:
USorCA. - Source:
geoip.country_code - Usage: 29 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_patch, linux_commands_devicelock, ... (+21 more)
src_endpoint.location.lat
- Description: The geographical Latitude coordinate represented in Decimal Degrees (DD). For example:
42.361145. - Source:
geoip.latitude - Transform:
geoip.latitude→double(29 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_patch, linux_commands_devicelock, ... (+21 more))- Usage: 29 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_patch, linux_commands_devicelock, ... (+21 more)
src_endpoint.location.long
- Description: The geographical Longitude coordinate represented in Decimal Degrees (DD). For example:
-71.057083. - Source:
geoip.longitude - Transform:
geoip.longitude→double(29 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_patch, linux_commands_devicelock, ... (+21 more))- Usage: 29 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_patch, linux_commands_devicelock, ... (+21 more)
src_endpoint.location.region
- Description: The alphanumeric code that identifies the principal subdivision (e.g. province or state) of the country. For example, 'CH-VD' for the Canton of Vaud, Switzerland
- Source:
geoip.region_code - Usage: 29 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_patch, linux_commands_devicelock, ... (+21 more)
Http Request
http_request.user_agent
- Description: The request header that identifies the operating system and web browser.
- Source:
user_agent,useragent.device - Usage: 23 events: linux_commands_devicelock, linux_commands_erasedevice, linux_commands_restartdevice, linux_commands_shutdowndevice, remote_assist_settings, remote_session_end, remote_session_join, remote_session_launch_token, ... (+15 more)
Observables
observables[].name
- Description: The full name of the observable attribute. The
nameis a pointer/reference to an attribute within the OCSF event data. For example:file.name. Array attributes may be represented in one of three ways. For example:resources.uid,resources[].uid,resources[0].uid. - Literal:
actor.user.email_addr,actor.user.name,actor.user.uid,device.hostname,device.uid,entity.device.hostname,entity.device.hw_info.serial_number,entity.device.uid,group.name,group.uid,http_request.user_agent,resource.name,resource.uid,src_endpoint.ip,src_endpoint.location.country,user.name,user.uid - Usage: 47 events (missing: google_emm_policy_bind, google_emm_policy_unbind, google_emm_sw_app_bind, google_emm_sw_app_unbind)
observables[].type_id
- Description: The observable value type identifier.
- Literal:
1,10,14,16,2,31,32,33,37,38,4,47,5 - Usage: 47 events (missing: google_emm_policy_bind, google_emm_policy_unbind, google_emm_sw_app_bind, google_emm_sw_app_unbind)
observables[].value
- Description: The value associated with the observable attribute. The meaning of the value depends on the observable type.
If thenamerefers to a scalar attribute, then thevalueis the value of the attribute.
If thenamerefers to an object attribute, then thevalueis not populated. - Source:
client_ip,geoip.country_code,initiated_by.email,initiated_by.id,initiated_by.name,initiated_by.uid,initiated_by.username,mdm_device_id,resource.displayName,resource.hostname,resource.id,resource.name,resource.username,system.hostname,system.id,system.serialno,user.id,user.username,user_agent,useragent.device,username,windows_device_uuid - Usage: 47 events (missing: google_emm_policy_bind, google_emm_policy_unbind, google_emm_sw_app_bind, google_emm_sw_app_unbind)
Other
app.name
- Description: The name of the product.
- Source:
resource.name - Usage: google_emm_sw_app_bind, google_emm_sw_app_unbind
app.uid
- Description: The unique identifier of the product.
- Source:
resource.id - Usage: google_emm_sw_app_bind, google_emm_sw_app_unbind
group.name
- Description: The group name.
- Source:
resource.name - Usage: system_group_admin_grant, system_group_admin_revoke
group.type
- Description: The type of the group.
- Source:
resource.type - Usage: system_group_admin_grant, system_group_admin_revoke
group.uid
- Description: The unique identifier of the group. For example, for Windows events this is the security identifier (SID) of the group. Another example, pool id or desktop id that the device belongs to.
- Source:
resource.id - Usage: system_group_admin_grant, system_group_admin_revoke
job.desc
- Description: The description of the job.
- Source:
request_type - Usage: recovery_lock_auto_rotation_success, recovery_lock_cleared_success, recovery_lock_set_success
job.run_state
- Description: The run state of the job.
- Source:
status - Usage: recovery_lock_auto_rotation_success, recovery_lock_cleared_success, recovery_lock_set_success
resource.name
- Description: The name of the resource.
- Source:
resource.displayName - Usage: system_admin_grant, system_admin_revoke
resource.type
- Description: The resource type as defined by the event source.
- Source:
resource.type - Usage: system_admin_grant, system_admin_revoke
resource.uid
- Description: The unique identifier of the resource.
- Source:
resource.id - Usage: system_admin_grant, system_admin_revoke
Unmapped
unmapped.@timestamp
- Description: JumpCloud Directory Insights field
@timestamppreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
@timestamp - Usage: linux_commands_erasedevice, system_admin_grant, system_admin_revoke, user_lockout, user_password_change, windows_commands_erasedevice
unmapped.@version
- Description: JumpCloud Directory Insights field
@versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
@version - Usage: all events in this service
unmapped.asn
- Description: JumpCloud Directory Insights field
asnpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
asn - Usage: linux_commands_restartdevice, linux_commands_shutdowndevice, os_major_upgrade, os_minor_rollback, os_minor_upgrade
unmapped.asn.error
- Description: JumpCloud Directory Insights field
asn.errorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
asn.error - Usage: os_major_upgrade, os_minor_rollback, os_minor_upgrade, remote_session_end, remote_session_join, remote_session_launch_token, remote_session_rejoin, remote_session_start
unmapped.asn.ip_address
- Description: JumpCloud Directory Insights field
asn.ip_addresspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
asn.ip_address - Usage: os_major_upgrade, os_minor_rollback, os_minor_upgrade, remote_session_end, remote_session_join, remote_session_launch_token, remote_session_rejoin, remote_session_start
unmapped.asn.network
- Description: JumpCloud Directory Insights field
asn.networkpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
asn.network - Usage: 19 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_patch, linux_commands_erasedevice, ... (+11 more)
unmapped.association_action_source
- Description: JumpCloud Directory Insights field
association_action_sourcepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
association_action_source - Usage: recovery_lock_auto_rotation_success, recovery_lock_cleared_success, recovery_lock_password_viewed, recovery_lock_set_success
unmapped.association_from_type
- Description: JumpCloud Directory Insights field
association_from_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
association_from_type - Usage: recovery_lock_auto_rotation_success, recovery_lock_cleared_success, recovery_lock_password_viewed, recovery_lock_set_success
unmapped.association_op
- Description: JumpCloud Directory Insights field
association_oppreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
association_op - Usage: recovery_lock_auto_rotation_success, recovery_lock_cleared_success, recovery_lock_password_viewed, recovery_lock_set_success
unmapped.association_to_type
- Description: JumpCloud Directory Insights field
association_to_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
association_to_type - Usage: recovery_lock_auto_rotation_success, recovery_lock_cleared_success, recovery_lock_password_viewed, recovery_lock_set_success
unmapped.auth_method
- Description: JumpCloud Directory Insights field
auth_methodpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
auth_method - Usage: system_admin_grant, system_admin_revoke, system_group_admin_grant, system_group_admin_revoke, user_password_change
unmapped.changed_field
- Description: JumpCloud Directory Insights field
changed_fieldpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.field - Usage: user_password_change
unmapped.changes
- Description: JumpCloud Directory Insights field
changespreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes - Usage: linux_commands_erasedevice, user_lockout, windows_commands_devicelock, windows_commands_erasedevice, windows_commands_restartdevice, windows_commands_shutdowndevice
unmapped.changes_from
- Description: JumpCloud Directory Insights field
changes_frompreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.from - Usage: user_password_change
unmapped.changes_to
- Description: JumpCloud Directory Insights field
changes_topreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to - Usage: user_password_change
unmapped.client_ip
- Description: JumpCloud Directory Insights field
client_ippreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
client_ip - Usage: google_emm_lost_mode_disabled, google_emm_lost_mode_enabled, google_emm_lost_mode_outgoing_phone_call, google_emm_policy_bind, google_emm_policy_unbind, google_emm_reset_password_recently, google_emm_stop_lost_mode_user_attempt, google_emm_sw_app_bind, google_emm_sw_app_unbind, google_emm_user_exit_lost_mode_recently
unmapped.command
- Description: JumpCloud Directory Insights field
commandpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
command - Usage: recovery_lock_auto_rotation_success, recovery_lock_cleared_success, recovery_lock_password_viewed, recovery_lock_set_success
unmapped.command_uuid
- Description: JumpCloud Directory Insights field
command_uuidpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
command_uuid - Usage: recovery_lock_auto_rotation_success, recovery_lock_cleared_success, recovery_lock_password_viewed, recovery_lock_set_success
unmapped.error_chain
- Description: JumpCloud Directory Insights field
error_chainpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
error_chain - Usage: recovery_lock_auto_rotation_success, recovery_lock_cleared_success, recovery_lock_password_viewed, recovery_lock_set_success
unmapped.file_input_timestamp
- Description: JumpCloud Directory Insights field
file_input_timestamppreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
file_input_timestamp - Usage: 18 events: google_emm_create, google_emm_delete, linux_commands_erasedevice, login_attempt, os_major_rollback, os_major_upgrade, os_minor_upgrade, remote_assist_settings, ... (+10 more)
unmapped.geoip
- Description: JumpCloud Directory Insights field
geoippreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip - Usage: linux_commands_devicelock, linux_commands_restartdevice, linux_commands_shutdowndevice, login_attempt, os_major_rollback, os_major_upgrade, os_minor_rollback, os_minor_upgrade
unmapped.geoip.error
- Description: JumpCloud Directory Insights field
geoip.errorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.error - Usage: os_major_upgrade, os_minor_rollback, os_minor_upgrade, remote_session_end, remote_session_join, remote_session_launch_token, remote_session_rejoin, remote_session_start
unmapped.geoip.ip_address
- Description: JumpCloud Directory Insights field
geoip.ip_addresspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.ip_address - Usage: os_major_upgrade, os_minor_rollback, os_minor_upgrade, remote_session_end, remote_session_join, remote_session_launch_token, remote_session_rejoin, remote_session_start
unmapped.geoip.region_name
- Description: JumpCloud Directory Insights field
geoip.region_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.region_name - Usage: 29 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_patch, linux_commands_devicelock, ... (+21 more)
unmapped.geoip.timezone
- Description: JumpCloud Directory Insights field
geoip.timezonepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.timezone - Usage: 29 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_patch, linux_commands_devicelock, ... (+21 more)
unmapped.initiated_by
- Description: JumpCloud Directory Insights field
initiated_bypreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by - Usage: 11 events: google_emm_policy_bind, google_emm_policy_unbind, google_emm_sw_app_bind, google_emm_sw_app_unbind, os_major_upgrade, os_minor_rollback, os_minor_upgrade, recovery_lock_auto_rotation_success, ... (+3 more)
unmapped.initiated_by_email_hash
- Description: JumpCloud Directory Insights field
initiated_by_email_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_email_hash - Usage: 26 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_patch, linux_commands_devicelock, ... (+18 more)
unmapped.initiated_by_id_hash
- Description: JumpCloud Directory Insights field
initiated_by_id_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_id_hash - Usage: 26 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_patch, linux_commands_devicelock, ... (+18 more)
unmapped.initiated_by_name_hash
- Description: JumpCloud Directory Insights field
initiated_by_name_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_name_hash - Usage: login_attempt, windows_commands_devicelock
unmapped.initiated_by_type
- Description: JumpCloud Directory Insights field
initiated_by_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_type - Usage: recovery_lock_auto_rotation_success, recovery_lock_cleared_success, recovery_lock_password_viewed, recovery_lock_set_success
unmapped.initiated_by_uid
- Description: JumpCloud Directory Insights field
initiated_by_uidpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by.uid - Usage: remote_session_feedback
unmapped.initiated_by_user_id
- Description: JumpCloud Directory Insights field
initiated_by_user_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by.user_id - Usage: linux_commands_erasedevice, system_group_admin_grant, system_group_admin_revoke, windows_commands_erasedevice
unmapped.initiated_by_username_hash
- Description: JumpCloud Directory Insights field
initiated_by_username_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_username_hash - Usage: login_attempt, remote_session_end, remote_session_join, remote_session_launch_token, user_lockout, user_password_change
unmapped.is_out_of_bound
- Description: JumpCloud Directory Insights field
is_out_of_boundpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
is_out_of_bound - Usage: 46 events (missing: os_major_rollback, remote_session_feedback, system_admin_grant, system_admin_revoke, windows_commands_erasedevice)
unmapped.jc_application_name
- Description: JumpCloud Directory Insights field
jc_application_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_application_name - Usage: 42 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_lost_mode_disabled, google_emm_lost_mode_enabled, ... (+34 more)
unmapped.jc_initiated_by_email
- Description: JumpCloud Directory Insights field
jc_initiated_by_emailpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_initiated_by_email - Usage: 11 events: device_command, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, login_attempt, os_major_upgrade, os_minor_upgrade, recovery_lock_auto_rotation_success, recovery_lock_password_viewed, ... (+3 more)
unmapped.jc_initiated_by_id
- Description: JumpCloud Directory Insights field
jc_initiated_by_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_initiated_by_id - Usage: device_command, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, login_attempt, os_major_upgrade, os_minor_upgrade, remote_assist_settings, system_fde_key_update
unmapped.jc_initiated_by_username
- Description: JumpCloud Directory Insights field
jc_initiated_by_usernamepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_initiated_by_username - Usage: device_command, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, os_major_upgrade, os_minor_upgrade, recovery_lock_auto_rotation_success, recovery_lock_password_viewed, remote_assist_settings, system_fde_key_decrypt, system_fde_key_update
unmapped.jc_organization_name
- Description: JumpCloud Directory Insights field
jc_organization_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_organization_name - Usage: device_command, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, os_major_upgrade, os_minor_upgrade, recovery_lock_auto_rotation_success, recovery_lock_password_viewed, remote_assist_settings, system_fde_key_decrypt, system_fde_key_update
unmapped.jc_provider_id
- Description: JumpCloud Directory Insights field
jc_provider_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_provider_id - Usage: device_command, google_emm_enrollment_token_delete, os_major_upgrade, os_minor_upgrade, recovery_lock_auto_rotation_success, recovery_lock_password_viewed, remote_assist_settings, system_fde_key_decrypt, system_fde_key_update
unmapped.jc_system_display_name
- Description: JumpCloud Directory Insights field
jc_system_display_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_system_display_name - Usage: device_command, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, os_major_upgrade, os_minor_upgrade, recovery_lock_auto_rotation_success, recovery_lock_password_viewed, remote_assist_settings, system_fde_key_update
unmapped.jc_system_hostname
- Description: JumpCloud Directory Insights field
jc_system_hostnamepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_system_hostname - Usage: device_command, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, os_major_upgrade, os_minor_upgrade, recovery_lock_auto_rotation_success, recovery_lock_password_viewed, remote_assist_settings, system_fde_key_update
unmapped.mdm_device_manager_id
- Description: JumpCloud Directory Insights field
mdm_device_manager_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
mdm_device_manager_id - Usage: recovery_lock_auto_rotation_success, recovery_lock_cleared_success, recovery_lock_password_viewed, recovery_lock_set_success
unmapped.message_chain
- Description: JumpCloud Directory Insights field
message_chainpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
message_chain - Usage: remote_session_join, remote_session_launch_token, remote_session_rejoin, user_password_change
unmapped.privilege_field
- Description: JumpCloud Directory Insights field
privilege_fieldpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.field - Usage: system_admin_grant, system_admin_revoke, system_group_admin_grant, system_group_admin_revoke
unmapped.privilege_from
- Description: JumpCloud Directory Insights field
privilege_frompreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.from - Usage: system_admin_revoke, system_group_admin_revoke
unmapped.privilege_to
- Description: JumpCloud Directory Insights field
privilege_topreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
changes.to - Usage: system_admin_grant, system_group_admin_grant
unmapped.process_name
- Description: JumpCloud Directory Insights field
process_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
process_name - Usage: login_attempt
unmapped.provider
- Description: JumpCloud Directory Insights field
providerpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
provider - Usage: system_admin_grant, system_admin_revoke, system_group_admin_revoke, user_lockout, user_password_change
unmapped.repeat_count
- Description: JumpCloud Directory Insights field
repeat_countpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
repeat_count - Usage: login_attempt
unmapped.request_type
- Description: JumpCloud Directory Insights field
request_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
request_type - Usage: recovery_lock_password_viewed
unmapped.resource_id_hash
- Description: JumpCloud Directory Insights field
resource_id_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource_id_hash - Usage: 34 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_lost_mode_disabled, google_emm_lost_mode_enabled, ... (+26 more)
unmapped.resource_name
- Description: JumpCloud Directory Insights field
resource_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.name - Usage: system_admin_grant, system_admin_revoke
unmapped.resource_name_hash
- Description: JumpCloud Directory Insights field
resource_name_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource_name_hash - Usage: device_command, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_lost_mode_outgoing_phone_call, google_emm_patch, google_emm_stop_lost_mode_user_attempt, google_emm_sw_app_unbind, google_emm_user_exit_lost_mode_recently
unmapped.resource_type
- Description: JumpCloud Directory Insights field
resource_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.type - Usage: google_emm_sw_app_bind, google_emm_sw_app_unbind
unmapped.resource_username_hash
- Description: JumpCloud Directory Insights field
resource_username_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource_username_hash - Usage: user_lockout, user_password_change
unmapped.system.correlation.id
- Description: JumpCloud Directory Insights field
system.correlation.idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
system.correlation.id - Usage: login_attempt
unmapped.system.correlation.session_duration
- Description: JumpCloud Directory Insights field
system.correlation.session_durationpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
system.correlation.session_duration - Usage: login_attempt
unmapped.system.correlation.type
- Description: JumpCloud Directory Insights field
system.correlation.typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
system.correlation.type - Usage: login_attempt
unmapped.system.message_chain.feedback
- Description: JumpCloud Directory Insights field
system.message_chain.feedbackpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
system.message_chain.feedback - Usage: login_attempt
unmapped.system.message_chain.message_details
- Description: JumpCloud Directory Insights field
system.message_chain.message_detailspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
system.message_chain.message_details - Usage: login_attempt
unmapped.system.message_chain.notes
- Description: JumpCloud Directory Insights field
system.message_chain.notespreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
system.message_chain.notes - Usage: login_attempt
unmapped.system.message_chain.rating
- Description: JumpCloud Directory Insights field
system.message_chain.ratingpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
system.message_chain.rating - Usage: login_attempt
unmapped.system.message_chain.response_code
- Description: JumpCloud Directory Insights field
system.message_chain.response_codepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
system.message_chain.response_code - Usage: login_attempt
unmapped.system.message_chain.response_message
- Description: JumpCloud Directory Insights field
system.message_chain.response_messagepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
system.message_chain.response_message - Usage: login_attempt
unmapped.system_id_hash
- Description: JumpCloud Directory Insights field
system_id_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
system_id_hash - Usage: device_command, google_emm_lost_mode_outgoing_phone_call, google_emm_stop_lost_mode_user_attempt, google_emm_user_exit_lost_mode_recently, os_major_upgrade, os_minor_rollback, os_minor_upgrade, remote_session_join, remote_session_launch_token, system_fde_key_update
unmapped.tags
- Description: JumpCloud Directory Insights field
tagspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
tags - Usage: 13 events: linux_commands_erasedevice, os_major_rollback, remote_assist_settings, remote_session_feedback, remote_session_join, remote_session_launch_token, remote_session_rejoin, system_admin_grant, ... (+5 more)
unmapped.testing_event
- Description: JumpCloud Directory Insights field
testing_eventpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
testing_event - Usage: user_password_change
unmapped.timestamp_source
- Description: JumpCloud Directory Insights field
timestamp_sourcepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
timestamp_source - Usage: 35 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_lost_mode_disabled, google_emm_lost_mode_enabled, ... (+27 more)
unmapped.user_agent
- Description: JumpCloud Directory Insights field
user_agentpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
user_agent - Usage: 21 events: device_command, google_emm_create, google_emm_delete, google_emm_enrollment_token_create, google_emm_enrollment_token_delete, google_emm_enterprise_upgrade, google_emm_lost_mode_disabled, google_emm_lost_mode_enabled, ... (+13 more)
unmapped.user_group_id
- Description: JumpCloud Directory Insights field
user_group_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
user_group.id - Usage: system_group_admin_revoke
unmapped.user_group_name
- Description: JumpCloud Directory Insights field
user_group_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
user_group.name - Usage: system_group_admin_revoke
unmapped.user_group_type
- Description: JumpCloud Directory Insights field
user_group_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
user_group.type - Usage: system_group_admin_revoke
unmapped.useragent.device
- Description: JumpCloud Directory Insights field
useragent.devicepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.device - Usage: 11 events: linux_commands_devicelock, linux_commands_erasedevice, linux_commands_restartdevice, linux_commands_shutdowndevice, system_fde_key_decrypt, system_group_admin_grant, system_group_admin_revoke, windows_commands_devicelock, ... (+3 more)
unmapped.useragent.major
- Description: JumpCloud Directory Insights field
useragent.majorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.major - Usage: 14 events: linux_commands_devicelock, linux_commands_erasedevice, linux_commands_restartdevice, linux_commands_shutdowndevice, system_admin_grant, system_admin_revoke, system_fde_key_decrypt, system_group_admin_grant, ... (+6 more)
unmapped.useragent.minor
- Description: JumpCloud Directory Insights field
useragent.minorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.minor - Usage: 14 events: linux_commands_devicelock, linux_commands_erasedevice, linux_commands_restartdevice, linux_commands_shutdowndevice, system_admin_grant, system_admin_revoke, system_fde_key_decrypt, system_group_admin_grant, ... (+6 more)
unmapped.useragent.name
- Description: JumpCloud Directory Insights field
useragent.namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.name - Usage: 14 events: linux_commands_devicelock, linux_commands_erasedevice, linux_commands_restartdevice, linux_commands_shutdowndevice, system_admin_grant, system_admin_revoke, system_fde_key_decrypt, system_group_admin_grant, ... (+6 more)
unmapped.useragent.os
- Description: JumpCloud Directory Insights field
useragent.ospreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os - Usage: 14 events: linux_commands_devicelock, linux_commands_erasedevice, linux_commands_restartdevice, linux_commands_shutdowndevice, system_admin_grant, system_admin_revoke, system_fde_key_decrypt, system_group_admin_grant, ... (+6 more)
unmapped.useragent.os_full
- Description: JumpCloud Directory Insights field
useragent.os_fullpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_full - Usage: 14 events: linux_commands_devicelock, linux_commands_erasedevice, linux_commands_restartdevice, linux_commands_shutdowndevice, system_admin_grant, system_admin_revoke, system_fde_key_decrypt, system_group_admin_grant, ... (+6 more)
unmapped.useragent.os_major
- Description: JumpCloud Directory Insights field
useragent.os_majorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_major - Usage: 11 events: linux_commands_devicelock, linux_commands_erasedevice, linux_commands_restartdevice, linux_commands_shutdowndevice, system_fde_key_decrypt, system_group_admin_revoke, user_password_change, windows_commands_devicelock, ... (+3 more)
unmapped.useragent.os_minor
- Description: JumpCloud Directory Insights field
useragent.os_minorpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_minor - Usage: 11 events: linux_commands_devicelock, linux_commands_erasedevice, linux_commands_restartdevice, linux_commands_shutdowndevice, system_fde_key_decrypt, system_group_admin_revoke, user_password_change, windows_commands_devicelock, ... (+3 more)
unmapped.useragent.os_name
- Description: JumpCloud Directory Insights field
useragent.os_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_name - Usage: 14 events: linux_commands_devicelock, linux_commands_erasedevice, linux_commands_restartdevice, linux_commands_shutdowndevice, system_admin_grant, system_admin_revoke, system_fde_key_decrypt, system_group_admin_grant, ... (+6 more)
unmapped.useragent.os_patch
- Description: JumpCloud Directory Insights field
useragent.os_patchpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_patch - Usage: 11 events: linux_commands_devicelock, linux_commands_erasedevice, linux_commands_restartdevice, linux_commands_shutdowndevice, system_fde_key_decrypt, system_group_admin_revoke, user_password_change, windows_commands_devicelock, ... (+3 more)
unmapped.useragent.os_version
- Description: JumpCloud Directory Insights field
useragent.os_versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.os_version - Usage: 11 events: linux_commands_devicelock, linux_commands_erasedevice, linux_commands_restartdevice, linux_commands_shutdowndevice, system_fde_key_decrypt, system_group_admin_revoke, user_password_change, windows_commands_devicelock, ... (+3 more)
unmapped.useragent.patch
- Description: JumpCloud Directory Insights field
useragent.patchpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.patch - Usage: 12 events: linux_commands_devicelock, linux_commands_erasedevice, linux_commands_restartdevice, linux_commands_shutdowndevice, system_fde_key_decrypt, system_group_admin_grant, system_group_admin_revoke, user_password_change, ... (+4 more)
unmapped.useragent.version
- Description: JumpCloud Directory Insights field
useragent.versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
useragent.version - Usage: 14 events: linux_commands_devicelock, linux_commands_erasedevice, linux_commands_restartdevice, linux_commands_shutdowndevice, system_admin_grant, system_admin_revoke, system_fde_key_decrypt, system_group_admin_grant, ... (+6 more)
unmapped.username
- Description: JumpCloud Directory Insights field
usernamepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
username - Usage: remote_session_end, remote_session_feedback, remote_session_join, remote_session_launch_token, remote_session_rejoin, remote_session_start
unmapped.username_hash
- Description: JumpCloud Directory Insights field
username_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
username_hash - Usage: login_attempt
unmapped.windows_device_uuid
- Description: JumpCloud Directory Insights field
windows_device_uuidpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
windows_device_uuid - Usage: recovery_lock_password_viewed
unmapped.windows_meta.elevated
- Description: JumpCloud Directory Insights field
windows_meta.elevatedpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
windows_meta.elevated - Usage: login_attempt
unmapped.windows_meta.logon_type
- Description: JumpCloud Directory Insights field
windows_meta.logon_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
windows_meta.logon_type - Usage: login_attempt
unmapped.windows_meta.user_process
- Description: JumpCloud Directory Insights field
windows_meta.user_processpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
windows_meta.user_process - Usage: login_attempt
unmapped.windows_meta.user_services
- Description: JumpCloud Directory Insights field
windows_meta.user_servicespreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
windows_meta.user_services - Usage: login_attempt
unmapped.windows_meta.user_tasks
- Description: JumpCloud Directory Insights field
windows_meta.user_taskspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
windows_meta.user_tasks - Usage: login_attempt
Workflow#
workflow · 5 events
| Event | Category | Class | Activity | Type UID | Fields |
|---|---|---|---|---|---|
workflow_create |
Identity & Access Management (3) | Entity Management (3004) | Create (1) | 300401 | 920 |
workflow_delete |
Identity & Access Management (3) | Entity Management (3004) | Delete (4) | 300404 | 924 |
workflow_run |
System Activity (1) | Scheduled Job Activity (1006) | Start (6) | 100606 | 37 |
workflow_run_rate_limited |
System Activity (1) | Scheduled Job Activity (1006) | Start (6) | 100606 | 35 |
workflow_update |
Identity & Access Management (3) | Entity Management (3004) | Update (3) | 300403 | 552 |
OCSF field mappings#
Legend
- Description: what the OCSF field represents (from OCSF schema v1.8.0)
- Source: raw JumpCloud event field(s) mapped via
${{placeholder}}template - Transform:
fieldMappingsentry applied at runtime (cast, enum, etc.) - Literal: static value set in the mapping template
- Usage: event types in this service that include this field
Core
activity_id
- Description: The normalized identifier of the activity that triggered the event.
- Literal:
1,3,4,6 - Usage: all events in this service
activity_name
- Description: The event activity name, as defined by the activity_id.
- Literal:
Create,Delete,Start,Update - Usage: all events in this service
category_name
- Description: The event category name, as defined by category_uid value:
Discovery. - Literal:
Identity & Access Management,System Activity - Usage: all events in this service
category_uid
- Description: The category unique identifier of the event.
- Literal:
1,3 - Usage: all events in this service
class_name
- Description: The event class name, as defined by class_uid value:
User Inventory Info. - Literal:
Entity Management,Scheduled Job Activity - Usage: all events in this service
class_uid
- Description: The unique identifier of a class. A class describes the attributes available in an event.
- Literal:
1006,3004 - Usage: all events in this service
severity_id
- Description: OCSF severity identifier for the event.
- Literal:
1 - Usage: all events in this service
status_detail
- Description: The status detail contains additional information about the event/finding outcome.
- Source:
error_message - Usage: all events in this service
status_id
- Description: Normalized status of the activity (1=Success, 2=Failure).
- Source:
success - Transform:
success→boolean_to_status_id; true→1, false→2 (all events in this service)- Usage: all events in this service
time
- Description: Event time, in epoch milliseconds (OCSF
time). - Source:
timestamp - Transform:
timestamp→iso8601_to_epoch_millis(all events in this service)- Usage: all events in this service
type_uid
- Description: The event/finding type ID. It identifies the event's semantics and structure. The value is calculated by the logging system as:
class_uid * 100 + activity_id. - Literal:
100606,300401,300403,300404 - Usage: all events in this service
Metadata
metadata.event_code
- Description: JumpCloud event type code.
- Source:
event_type - Usage: all events in this service
metadata.original_time
- Description: The original event time as reported by the event source. For example, the time in the original format from system event log such as Syslog on Unix/Linux and the System event file on Windows. Omit if event is generated instead of collected via logs.
- Source:
server_timestamp - Usage: all events in this service
metadata.product.name
- Description: Originating JumpCloud service that produced the event.
- Source:
service - Usage: all events in this service
metadata.tenant_uid
- Description: JumpCloud organization (tenant) identifier.
- Source:
organization - Usage: all events in this service
metadata.uid
- Description: Unique event identifier assigned by JumpCloud.
- Source:
id - Usage: all events in this service
metadata.version
- Description: OCSF schema version used for this event.
- Literal:
1.8.0 - Usage: all events in this service
Actor
actor.user.type_id
- Description: OCSF user type of the actor (1=User, 2=Admin, 3=System, 4=Service).
- Source:
initiated_by.type - Transform:
initiated_by.type→enum; enumValues: {'user': 1, 'admin': 2, 'system': 3, 'service': 4, 'device': 99}; default: 99 (all events in this service)- Usage: all events in this service
actor.user.uid
- Description: Unique identifier of the actor who initiated the event.
- Source:
initiated_by.id - Usage: all events in this service
Entity
entity.data.auth_method
- Description: JumpCloud extension data on the managed entity:
auth_method. - Source:
auth_method - Usage: workflow_create, workflow_delete, workflow_update
entity.data.changed_field
- Description: JumpCloud extension data on the managed entity:
changed_field. - Source:
changes.field - Usage: workflow_update
entity.data.changes_from_do_activateUser_call
- Description: JumpCloud extension data on the managed entity:
changes_from_do_activateUser_call. - Source:
changes.from.do.activateUser.call - Usage: workflow_update
entity.data.changes_from_do_activateUser_metadata_displayLabels_email
- Description: JumpCloud extension data on the managed entity:
changes_from_do_activateUser_metadata_displayLabels_email. - Source:
changes.from.do.activateUser.metadata.displayLabels.email - Usage: workflow_update
entity.data.changes_from_do_activateUser_metadata_displayLabels_user
- Description: JumpCloud extension data on the managed entity:
changes_from_do_activateUser_metadata_displayLabels_user. - Source:
changes.from.do.activateUser.metadata.displayLabels.user - Usage: workflow_update
entity.data.changes_from_do_activateUser_metadata_inputModes_email
- Description: JumpCloud extension data on the managed entity:
changes_from_do_activateUser_metadata_inputModes_email. - Source:
changes.from.do.activateUser.metadata.inputModes.email - Usage: workflow_update
entity.data.changes_from_do_activateUser_metadata_inputModes_user
- Description: JumpCloud extension data on the managed entity:
changes_from_do_activateUser_metadata_inputModes_user. - Source:
changes.from.do.activateUser.metadata.inputModes.user - Usage: workflow_update
entity.data.changes_from_do_activateUser_with_bodyParams_email
- Description: JumpCloud extension data on the managed entity:
changes_from_do_activateUser_with_bodyParams_email. - Source:
changes.from.do.activateUser.with.bodyParams.email - Usage: workflow_update
entity.data.changes_from_do_activateUser_with_operationId
- Description: JumpCloud extension data on the managed entity:
changes_from_do_activateUser_with_operationId. - Source:
changes.from.do.activateUser.with.operationId - Usage: workflow_update
entity.data.changes_from_do_activateUser_with_pathParams_id
- Description: JumpCloud extension data on the managed entity:
changes_from_do_activateUser_with_pathParams_id. - Source:
changes.from.do.activateUser.with.pathParams.id - Usage: workflow_update
entity.data.changes_from_do_activateUser_with_version
- Description: JumpCloud extension data on the managed entity:
changes_from_do_activateUser_with_version. - Source:
changes.from.do.activateUser.with.version - Usage: workflow_update
entity.data.changes_from_do_callConnector_call
- Description: JumpCloud extension data on the managed entity:
changes_from_do_callConnector_call. - Source:
changes.from.do.callConnector.call - Usage: workflow_update
entity.data.changes_from_do_callConnector_with_body_data
- Description: JumpCloud extension data on the managed entity:
changes_from_do_callConnector_with_body_data. - Source:
changes.from.do.callConnector.with.body.data - Usage: workflow_update
entity.data.changes_from_do_callConnector_with_body_id
- Description: JumpCloud extension data on the managed entity:
changes_from_do_callConnector_with_body_id. - Source:
changes.from.do.callConnector.with.body.id - Usage: workflow_update
entity.data.changes_from_do_callConnector_with_body_timestamp
- Description: JumpCloud extension data on the managed entity:
changes_from_do_callConnector_with_body_timestamp. - Source:
changes.from.do.callConnector.with.body.timestamp - Usage: workflow_update
entity.data.changes_from_do_callConnector_with_endpointPath
- Description: JumpCloud extension data on the managed entity:
changes_from_do_callConnector_with_endpointPath. - Source:
changes.from.do.callConnector.with.endpointPath - Usage: workflow_update
entity.data.changes_from_do_callConnector_with_headers_Accept
- Description: JumpCloud extension data on the managed entity:
changes_from_do_callConnector_with_headers_Accept. - Source:
changes.from.do.callConnector.with.headers.Accept - Usage: workflow_update
entity.data.changes_from_do_callConnector_with_headers_EWrwer
- Description: JumpCloud extension data on the managed entity:
changes_from_do_callConnector_with_headers_EWrwer. - Source:
changes.from.do.callConnector.with.headers.EWrwer - Usage: workflow_update
entity.data.changes_from_do_callConnector_with_headers_ew
- Description: JumpCloud extension data on the managed entity:
changes_from_do_callConnector_with_headers_ew. - Source:
changes.from.do.callConnector.with.headers.ew - Usage: workflow_update
entity.data.changes_from_do_callConnector_with_headers_ewe
- Description: JumpCloud extension data on the managed entity:
changes_from_do_callConnector_with_headers_ewe. - Source:
changes.from.do.callConnector.with.headers.ewe - Usage: workflow_update
entity.data.changes_from_do_callConnector_with_httpMethod
- Description: JumpCloud extension data on the managed entity:
changes_from_do_callConnector_with_httpMethod. - Source:
changes.from.do.callConnector.with.httpMethod - Usage: workflow_update
entity.data.changes_from_do_callConnector_with_id
- Description: JumpCloud extension data on the managed entity:
changes_from_do_callConnector_with_id. - Source:
changes.from.do.callConnector.with.id - Usage: workflow_update
entity.data.changes_from_do_checkActivated_call
- Description: JumpCloud extension data on the managed entity:
changes_from_do_checkActivated_call. - Source:
changes.from.do.checkActivated.call - Usage: workflow_update
entity.data.changes_from_do_checkActivated_if
- Description: JumpCloud extension data on the managed entity:
changes_from_do_checkActivated_if. - Source:
changes.from.do.checkActivated.if - Usage: workflow_update
entity.data.changes_from_do_checkActivated_with_operationId
- Description: JumpCloud extension data on the managed entity:
changes_from_do_checkActivated_with_operationId. - Source:
changes.from.do.checkActivated.with.operationId - Usage: workflow_update
entity.data.changes_from_do_checkActivated_with_pathParams_id
- Description: JumpCloud extension data on the managed entity:
changes_from_do_checkActivated_with_pathParams_id. - Source:
changes.from.do.checkActivated.with.pathParams.id - Usage: workflow_update
entity.data.changes_from_do_checkActivated_with_queryParams_fields
- Description: JumpCloud extension data on the managed entity:
changes_from_do_checkActivated_with_queryParams_fields. - Source:
changes.from.do.checkActivated.with.queryParams.fields - Usage: workflow_update
entity.data.changes_from_do_checkActivated_with_version
- Description: JumpCloud extension data on the managed entity:
changes_from_do_checkActivated_with_version. - Source:
changes.from.do.checkActivated.with.version - Usage: workflow_update
entity.data.changes_from_do_checkDelegatedAuthorityExists_call
- Description: JumpCloud extension data on the managed entity:
changes_from_do_checkDelegatedAuthorityExists_call. - Source:
changes.from.do.checkDelegatedAuthorityExists.call - Usage: workflow_update
entity.data.changes_from_do_checkDelegatedAuthorityExists_if
- Description: JumpCloud extension data on the managed entity:
changes_from_do_checkDelegatedAuthorityExists_if. - Source:
changes.from.do.checkDelegatedAuthorityExists.if - Usage: workflow_update
entity.data.changes_from_do_checkDelegatedAuthorityExists_with_operationId
- Description: JumpCloud extension data on the managed entity:
changes_from_do_checkDelegatedAuthorityExists_with_operationId. - Source:
changes.from.do.checkDelegatedAuthorityExists.with.operationId - Usage: workflow_update
entity.data.changes_from_do_checkDelegatedAuthorityExists_with_pathParams_id
- Description: JumpCloud extension data on the managed entity:
changes_from_do_checkDelegatedAuthorityExists_with_pathParams_id. - Source:
changes.from.do.checkDelegatedAuthorityExists.with.pathParams.id - Usage: workflow_update
entity.data.changes_from_do_checkDelegatedAuthorityExists_with_queryParams_fields
- Description: JumpCloud extension data on the managed entity:
changes_from_do_checkDelegatedAuthorityExists_with_queryParams_fields. - Source:
changes.from.do.checkDelegatedAuthorityExists.with.queryParams.fields - Usage: workflow_update
entity.data.changes_from_do_checkDelegatedAuthorityExists_with_version
- Description: JumpCloud extension data on the managed entity:
changes_from_do_checkDelegatedAuthorityExists_with_version. - Source:
changes.from.do.checkDelegatedAuthorityExists.with.version - Usage: workflow_update
entity.data.changes_from_do_checkPasswordDate_call
- Description: JumpCloud extension data on the managed entity:
changes_from_do_checkPasswordDate_call. - Source:
changes.from.do.checkPasswordDate.call - Usage: workflow_update
entity.data.changes_from_do_checkPasswordDate_if
- Description: JumpCloud extension data on the managed entity:
changes_from_do_checkPasswordDate_if. - Source:
changes.from.do.checkPasswordDate.if - Usage: workflow_update
entity.data.changes_from_do_checkPasswordDate_with_operationId
- Description: JumpCloud extension data on the managed entity:
changes_from_do_checkPasswordDate_with_operationId. - Source:
changes.from.do.checkPasswordDate.with.operationId - Usage: workflow_update
entity.data.changes_from_do_checkPasswordDate_with_pathParams_id
- Description: JumpCloud extension data on the managed entity:
changes_from_do_checkPasswordDate_with_pathParams_id. - Source:
changes.from.do.checkPasswordDate.with.pathParams.id - Usage: workflow_update
entity.data.changes_from_do_checkPasswordDate_with_queryParams_fields
- Description: JumpCloud extension data on the managed entity:
changes_from_do_checkPasswordDate_with_queryParams_fields. - Source:
changes.from.do.checkPasswordDate.with.queryParams.fields - Usage: workflow_update
entity.data.changes_from_do_checkPasswordDate_with_version
- Description: JumpCloud extension data on the managed entity:
changes_from_do_checkPasswordDate_with_version. - Source:
changes.from.do.checkPasswordDate.with.version - Usage: workflow_update
entity.data.changes_from_do_getUser_call
- Description: JumpCloud extension data on the managed entity:
changes_from_do_getUser_call. - Source:
changes.from.do.getUser.call - Usage: workflow_update
entity.data.changes_from_do_getUser_with_operationId
- Description: JumpCloud extension data on the managed entity:
changes_from_do_getUser_with_operationId. - Source:
changes.from.do.getUser.with.operationId - Usage: workflow_update
entity.data.changes_from_do_getUser_with_pathParams_id
- Description: JumpCloud extension data on the managed entity:
changes_from_do_getUser_with_pathParams_id. - Source:
changes.from.do.getUser.with.pathParams.id - Usage: workflow_update
entity.data.changes_from_do_getUser_with_version
- Description: JumpCloud extension data on the managed entity:
changes_from_do_getUser_with_version. - Source:
changes.from.do.getUser.with.version - Usage: workflow_update
entity.data.changes_from_do_removeDelegatedAuthority_call
- Description: JumpCloud extension data on the managed entity:
changes_from_do_removeDelegatedAuthority_call. - Source:
changes.from.do.removeDelegatedAuthority.call - Usage: workflow_update
entity.data.changes_from_do_removeDelegatedAuthority_if
- Description: JumpCloud extension data on the managed entity:
changes_from_do_removeDelegatedAuthority_if. - Source:
changes.from.do.removeDelegatedAuthority.if - Usage: workflow_update
entity.data.changes_from_do_removeDelegatedAuthority_with_bodyParams_delegatedAuthority
- Description: JumpCloud extension data on the managed entity:
changes_from_do_removeDelegatedAuthority_with_bodyParams_delegatedAuthority. - Source:
changes.from.do.removeDelegatedAuthority.with.bodyParams.delegatedAuthority - Usage: workflow_update
entity.data.changes_from_do_removeDelegatedAuthority_with_operationId
- Description: JumpCloud extension data on the managed entity:
changes_from_do_removeDelegatedAuthority_with_operationId. - Source:
changes.from.do.removeDelegatedAuthority.with.operationId - Usage: workflow_update
entity.data.changes_from_do_removeDelegatedAuthority_with_pathParams_id
- Description: JumpCloud extension data on the managed entity:
changes_from_do_removeDelegatedAuthority_with_pathParams_id. - Source:
changes.from.do.removeDelegatedAuthority.with.pathParams.id - Usage: workflow_update
entity.data.changes_from_do_removeDelegatedAuthority_with_version
- Description: JumpCloud extension data on the managed entity:
changes_from_do_removeDelegatedAuthority_with_version. - Source:
changes.from.do.removeDelegatedAuthority.with.version - Usage: workflow_update
entity.data.changes_from_do_sendEmailAddresses_call
- Description: JumpCloud extension data on the managed entity:
changes_from_do_sendEmailAddresses_call. - Source:
changes.from.do.sendEmailAddresses.call - Usage: workflow_update
entity.data.changes_from_do_sendEmailAddresses_with_message_body
- Description: JumpCloud extension data on the managed entity:
changes_from_do_sendEmailAddresses_with_message_body. - Source:
changes.from.do.sendEmailAddresses.with.message.body - Usage: workflow_update
entity.data.changes_from_do_sendEmailAddresses_with_message_subject
- Description: JumpCloud extension data on the managed entity:
changes_from_do_sendEmailAddresses_with_message_subject. - Source:
changes.from.do.sendEmailAddresses.with.message.subject - Usage: workflow_update
entity.data.changes_from_do_sendEmailAddresses_with_recipients_to_addresses
- Description: JumpCloud extension data on the managed entity:
changes_from_do_sendEmailAddresses_with_recipients_to_addresses. - Source:
changes.from.do.sendEmailAddresses.with.recipients.to_addresses - Usage: workflow_update
entity.data.changes_from_do_systemusersGet_call
- Description: JumpCloud extension data on the managed entity:
changes_from_do_systemusersGet_call. - Source:
changes.from.do.systemusersGet.call - Usage: workflow_update
entity.data.changes_from_do_systemusersGet_with_operationId
- Description: JumpCloud extension data on the managed entity:
changes_from_do_systemusersGet_with_operationId. - Source:
changes.from.do.systemusersGet.with.operationId - Usage: workflow_update
entity.data.changes_from_do_systemusersGet_with_pathParams_id
- Description: JumpCloud extension data on the managed entity:
changes_from_do_systemusersGet_with_pathParams_id. - Source:
changes.from.do.systemusersGet.with.pathParams.id - Usage: workflow_update
entity.data.changes_from_do_systemusersGet_with_queryParams_fields
- Description: JumpCloud extension data on the managed entity:
changes_from_do_systemusersGet_with_queryParams_fields. - Source:
changes.from.do.systemusersGet.with.queryParams.fields - Usage: workflow_update
entity.data.changes_from_do_systemusersGet_with_version
- Description: JumpCloud extension data on the managed entity:
changes_from_do_systemusersGet_with_version. - Source:
changes.from.do.systemusersGet.with.version - Usage: workflow_update
entity.data.changes_from_do_updateIsApproved_call
- Description: JumpCloud extension data on the managed entity:
changes_from_do_updateIsApproved_call. - Source:
changes.from.do.updateIsApproved.call - Usage: workflow_update
entity.data.changes_from_do_updateIsApproved_if
- Description: JumpCloud extension data on the managed entity:
changes_from_do_updateIsApproved_if. - Source:
changes.from.do.updateIsApproved.if - Usage: workflow_update
entity.data.changes_from_do_updateIsApproved_with_bodyParams_attributes
- Description: JumpCloud extension data on the managed entity:
changes_from_do_updateIsApproved_with_bodyParams_attributes. - Source:
changes.from.do.updateIsApproved.with.bodyParams.attributes - Usage: workflow_update
entity.data.changes_from_do_updateIsApproved_with_operationId
- Description: JumpCloud extension data on the managed entity:
changes_from_do_updateIsApproved_with_operationId. - Source:
changes.from.do.updateIsApproved.with.operationId - Usage: workflow_update
entity.data.changes_from_do_updateIsApproved_with_pathParams_id
- Description: JumpCloud extension data on the managed entity:
changes_from_do_updateIsApproved_with_pathParams_id. - Source:
changes.from.do.updateIsApproved.with.pathParams.id - Usage: workflow_update
entity.data.changes_from_do_updateIsApproved_with_version
- Description: JumpCloud extension data on the managed entity:
changes_from_do_updateIsApproved_with_version. - Source:
changes.from.do.updateIsApproved.with.version - Usage: workflow_update
entity.data.changes_from_schedule_frequency
- Description: JumpCloud extension data on the managed entity:
changes_from_schedule_frequency. - Source:
changes.from.schedule.frequency - Usage: workflow_update
entity.data.changes_from_schedule_interval
- Description: JumpCloud extension data on the managed entity:
changes_from_schedule_interval. - Source:
changes.from.schedule.interval - Usage: workflow_update
entity.data.changes_from_schedule_on_one_with_condition
- Description: JumpCloud extension data on the managed entity:
changes_from_schedule_on_one_with_condition. - Source:
changes.from.schedule.on.one.with.condition - Usage: workflow_update
entity.data.changes_from_schedule_on_one_with_source
- Description: JumpCloud extension data on the managed entity:
changes_from_schedule_on_one_with_source. - Source:
changes.from.schedule.on.one.with.source - Usage: workflow_update
entity.data.changes_from_schedule_on_one_with_type
- Description: JumpCloud extension data on the managed entity:
changes_from_schedule_on_one_with_type. - Source:
changes.from.schedule.on.one.with.type - Usage: workflow_update
entity.data.changes_from_schedule_start_date
- Description: JumpCloud extension data on the managed entity:
changes_from_schedule_start_date. - Source:
changes.from.schedule.start_date - Usage: workflow_update
entity.data.changes_from_schedule_start_time
- Description: JumpCloud extension data on the managed entity:
changes_from_schedule_start_time. - Source:
changes.from.schedule.start_time - Usage: workflow_update
entity.data.changes_from_schedule_timezone
- Description: JumpCloud extension data on the managed entity:
changes_from_schedule_timezone. - Source:
changes.from.schedule.timezone - Usage: workflow_update
entity.data.description
- Description: JumpCloud extension data on the managed entity:
description. - Source:
resource.description - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.Fetch_User_Details.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.Fetch_User_Details.call. - Source:
resource.dsl.do.Fetch_User_Details.call - Usage: workflow_delete, workflow_update
entity.data.dsl.do.Fetch_User_Details.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.Fetch_User_Details.with.operationId. - Source:
resource.dsl.do.Fetch_User_Details.with.operationId - Usage: workflow_delete, workflow_update
entity.data.dsl.do.Fetch_User_Details.with.pathParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.Fetch_User_Details.with.pathParams.id. - Source:
resource.dsl.do.Fetch_User_Details.with.pathParams.id - Usage: workflow_delete, workflow_update
entity.data.dsl.do.Fetch_User_Details.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.Fetch_User_Details.with.version. - Source:
resource.dsl.do.Fetch_User_Details.with.version - Usage: workflow_delete, workflow_update
entity.data.dsl.do.Step1_UpdateCommand.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.Step1_UpdateCommand.call. - Source:
resource.dsl.do.Step1_UpdateCommand.call - Usage: workflow_delete, workflow_update
entity.data.dsl.do.Step1_UpdateCommand.with.bodyParams.command
- Description: JumpCloud extension data on the managed entity:
dsl.do.Step1_UpdateCommand.with.bodyParams.command. - Source:
resource.dsl.do.Step1_UpdateCommand.with.bodyParams.command - Usage: workflow_delete, workflow_update
entity.data.dsl.do.Step1_UpdateCommand.with.bodyParams.commandType
- Description: JumpCloud extension data on the managed entity:
dsl.do.Step1_UpdateCommand.with.bodyParams.commandType. - Source:
resource.dsl.do.Step1_UpdateCommand.with.bodyParams.commandType - Usage: workflow_delete, workflow_update
entity.data.dsl.do.Step1_UpdateCommand.with.bodyParams.name
- Description: JumpCloud extension data on the managed entity:
dsl.do.Step1_UpdateCommand.with.bodyParams.name. - Source:
resource.dsl.do.Step1_UpdateCommand.with.bodyParams.name - Usage: workflow_delete, workflow_update
entity.data.dsl.do.Step1_UpdateCommand.with.bodyParams.user
- Description: JumpCloud extension data on the managed entity:
dsl.do.Step1_UpdateCommand.with.bodyParams.user. - Source:
resource.dsl.do.Step1_UpdateCommand.with.bodyParams.user - Usage: workflow_delete, workflow_update
entity.data.dsl.do.Step1_UpdateCommand.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.Step1_UpdateCommand.with.operationId. - Source:
resource.dsl.do.Step1_UpdateCommand.with.operationId - Usage: workflow_delete, workflow_update
entity.data.dsl.do.Step1_UpdateCommand.with.pathParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.Step1_UpdateCommand.with.pathParams.id. - Source:
resource.dsl.do.Step1_UpdateCommand.with.pathParams.id - Usage: workflow_delete, workflow_update
entity.data.dsl.do.Step1_UpdateCommand.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.Step1_UpdateCommand.with.version. - Source:
resource.dsl.do.Step1_UpdateCommand.with.version - Usage: workflow_delete, workflow_update
entity.data.dsl.do.Step2_RunCommand.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.Step2_RunCommand.call. - Source:
resource.dsl.do.Step2_RunCommand.call - Usage: workflow_delete, workflow_update
entity.data.dsl.do.Step2_RunCommand.with.bodyParams._id
- Description: JumpCloud extension data on the managed entity:
dsl.do.Step2_RunCommand.with.bodyParams._id. - Source:
resource.dsl.do.Step2_RunCommand.with.bodyParams._id - Usage: workflow_delete, workflow_update
entity.data.dsl.do.Step2_RunCommand.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.Step2_RunCommand.with.operationId. - Source:
resource.dsl.do.Step2_RunCommand.with.operationId - Usage: workflow_delete, workflow_update
entity.data.dsl.do.Step2_RunCommand.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.Step2_RunCommand.with.version. - Source:
resource.dsl.do.Step2_RunCommand.with.version - Usage: workflow_delete, workflow_update
entity.data.dsl.do.accessWorkflowApiGetAccessWorkflow.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.accessWorkflowApiGetAccessWorkflow.call. - Source:
resource.dsl.do.accessWorkflowApiGetAccessWorkflow.call - Usage: workflow_create, workflow_delete
entity.data.dsl.do.accessWorkflowApiGetAccessWorkflow.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.accessWorkflowApiGetAccessWorkflow.with.operationId. - Source:
resource.dsl.do.accessWorkflowApiGetAccessWorkflow.with.operationId - Usage: workflow_create, workflow_delete
entity.data.dsl.do.accessWorkflowApiGetAccessWorkflow.with.pathParams.approvalFlowId
- Description: JumpCloud extension data on the managed entity:
dsl.do.accessWorkflowApiGetAccessWorkflow.with.pathParams.approvalFlowId. - Source:
resource.dsl.do.accessWorkflowApiGetAccessWorkflow.with.pathParams.approvalFlowId - Usage: workflow_create, workflow_delete
entity.data.dsl.do.accessWorkflowApiGetAccessWorkflow.with.queryParams.organizationObjectId
- Description: JumpCloud extension data on the managed entity:
dsl.do.accessWorkflowApiGetAccessWorkflow.with.queryParams.organizationObjectId. - Source:
resource.dsl.do.accessWorkflowApiGetAccessWorkflow.with.queryParams.organizationObjectId - Usage: workflow_create, workflow_delete
entity.data.dsl.do.accessWorkflowApiGetAccessWorkflow.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.accessWorkflowApiGetAccessWorkflow.with.version. - Source:
resource.dsl.do.accessWorkflowApiGetAccessWorkflow.with.version - Usage: workflow_create, workflow_delete
entity.data.dsl.do.actionActivateUser.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionActivateUser.call. - Source:
resource.dsl.do.actionActivateUser.call - Usage: workflow_delete
entity.data.dsl.do.actionActivateUser.metadata.displayLabels.user
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionActivateUser.metadata.displayLabels.user. - Source:
resource.dsl.do.actionActivateUser.metadata.displayLabels.user - Usage: workflow_delete
entity.data.dsl.do.actionActivateUser.metadata.inputModes.user
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionActivateUser.metadata.inputModes.user. - Source:
resource.dsl.do.actionActivateUser.metadata.inputModes.user - Usage: workflow_delete
entity.data.dsl.do.actionActivateUser.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionActivateUser.with.operationId. - Source:
resource.dsl.do.actionActivateUser.with.operationId - Usage: workflow_delete
entity.data.dsl.do.actionActivateUser.with.pathParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionActivateUser.with.pathParams.id. - Source:
resource.dsl.do.actionActivateUser.with.pathParams.id - Usage: workflow_delete
entity.data.dsl.do.actionActivateUser.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionActivateUser.with.version. - Source:
resource.dsl.do.actionActivateUser.with.version - Usage: workflow_delete
entity.data.dsl.do.actionAddUserToUserGroup.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionAddUserToUserGroup.call. - Source:
resource.dsl.do.actionAddUserToUserGroup.call - Usage: workflow_delete
entity.data.dsl.do.actionAddUserToUserGroup.metadata.displayLabels.user
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionAddUserToUserGroup.metadata.displayLabels.user. - Source:
resource.dsl.do.actionAddUserToUserGroup.metadata.displayLabels.user - Usage: workflow_delete
entity.data.dsl.do.actionAddUserToUserGroup.metadata.displayLabels.userGroup
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionAddUserToUserGroup.metadata.displayLabels.userGroup. - Source:
resource.dsl.do.actionAddUserToUserGroup.metadata.displayLabels.userGroup - Usage: workflow_delete
entity.data.dsl.do.actionAddUserToUserGroup.metadata.inputModes.user
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionAddUserToUserGroup.metadata.inputModes.user. - Source:
resource.dsl.do.actionAddUserToUserGroup.metadata.inputModes.user - Usage: workflow_delete
entity.data.dsl.do.actionAddUserToUserGroup.metadata.inputModes.userGroup
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionAddUserToUserGroup.metadata.inputModes.userGroup. - Source:
resource.dsl.do.actionAddUserToUserGroup.metadata.inputModes.userGroup - Usage: workflow_delete
entity.data.dsl.do.actionAddUserToUserGroup.with.bodyParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionAddUserToUserGroup.with.bodyParams.id. - Source:
resource.dsl.do.actionAddUserToUserGroup.with.bodyParams.id - Usage: workflow_delete
entity.data.dsl.do.actionAddUserToUserGroup.with.bodyParams.op
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionAddUserToUserGroup.with.bodyParams.op. - Source:
resource.dsl.do.actionAddUserToUserGroup.with.bodyParams.op - Usage: workflow_delete
entity.data.dsl.do.actionAddUserToUserGroup.with.bodyParams.type
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionAddUserToUserGroup.with.bodyParams.type. - Source:
resource.dsl.do.actionAddUserToUserGroup.with.bodyParams.type - Usage: workflow_delete
entity.data.dsl.do.actionAddUserToUserGroup.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionAddUserToUserGroup.with.operationId. - Source:
resource.dsl.do.actionAddUserToUserGroup.with.operationId - Usage: workflow_delete
entity.data.dsl.do.actionAddUserToUserGroup.with.pathParams.group_id
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionAddUserToUserGroup.with.pathParams.group_id. - Source:
resource.dsl.do.actionAddUserToUserGroup.with.pathParams.group_id - Usage: workflow_delete
entity.data.dsl.do.actionAddUserToUserGroup.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionAddUserToUserGroup.with.version. - Source:
resource.dsl.do.actionAddUserToUserGroup.with.version - Usage: workflow_delete
entity.data.dsl.do.actionAddUserToUserGroup_v2.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionAddUserToUserGroup_v2.call. - Source:
resource.dsl.do.actionAddUserToUserGroup_v2.call - Usage: workflow_delete
entity.data.dsl.do.actionAddUserToUserGroup_v2.metadata.displayLabels.user
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionAddUserToUserGroup_v2.metadata.displayLabels.user. - Source:
resource.dsl.do.actionAddUserToUserGroup_v2.metadata.displayLabels.user - Usage: workflow_delete
entity.data.dsl.do.actionAddUserToUserGroup_v2.metadata.displayLabels.userGroup
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionAddUserToUserGroup_v2.metadata.displayLabels.userGroup. - Source:
resource.dsl.do.actionAddUserToUserGroup_v2.metadata.displayLabels.userGroup - Usage: workflow_delete
entity.data.dsl.do.actionAddUserToUserGroup_v2.metadata.inputModes.user
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionAddUserToUserGroup_v2.metadata.inputModes.user. - Source:
resource.dsl.do.actionAddUserToUserGroup_v2.metadata.inputModes.user - Usage: workflow_delete
entity.data.dsl.do.actionAddUserToUserGroup_v2.metadata.inputModes.userGroup
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionAddUserToUserGroup_v2.metadata.inputModes.userGroup. - Source:
resource.dsl.do.actionAddUserToUserGroup_v2.metadata.inputModes.userGroup - Usage: workflow_delete
entity.data.dsl.do.actionAddUserToUserGroup_v2.with.bodyParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionAddUserToUserGroup_v2.with.bodyParams.id. - Source:
resource.dsl.do.actionAddUserToUserGroup_v2.with.bodyParams.id - Usage: workflow_delete
entity.data.dsl.do.actionAddUserToUserGroup_v2.with.bodyParams.op
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionAddUserToUserGroup_v2.with.bodyParams.op. - Source:
resource.dsl.do.actionAddUserToUserGroup_v2.with.bodyParams.op - Usage: workflow_delete
entity.data.dsl.do.actionAddUserToUserGroup_v2.with.bodyParams.type
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionAddUserToUserGroup_v2.with.bodyParams.type. - Source:
resource.dsl.do.actionAddUserToUserGroup_v2.with.bodyParams.type - Usage: workflow_delete
entity.data.dsl.do.actionAddUserToUserGroup_v2.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionAddUserToUserGroup_v2.with.operationId. - Source:
resource.dsl.do.actionAddUserToUserGroup_v2.with.operationId - Usage: workflow_delete
entity.data.dsl.do.actionAddUserToUserGroup_v2.with.pathParams.group_id
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionAddUserToUserGroup_v2.with.pathParams.group_id. - Source:
resource.dsl.do.actionAddUserToUserGroup_v2.with.pathParams.group_id - Usage: workflow_delete
entity.data.dsl.do.actionAddUserToUserGroup_v2.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionAddUserToUserGroup_v2.with.version. - Source:
resource.dsl.do.actionAddUserToUserGroup_v2.with.version - Usage: workflow_delete
entity.data.dsl.do.actionEraseDevice.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionEraseDevice.call. - Source:
resource.dsl.do.actionEraseDevice.call - Usage: workflow_delete
entity.data.dsl.do.actionEraseDevice.metadata.displayLabels.device
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionEraseDevice.metadata.displayLabels.device. - Source:
resource.dsl.do.actionEraseDevice.metadata.displayLabels.device - Usage: workflow_delete
entity.data.dsl.do.actionEraseDevice.metadata.inputModes.device
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionEraseDevice.metadata.inputModes.device. - Source:
resource.dsl.do.actionEraseDevice.metadata.inputModes.device - Usage: workflow_delete
entity.data.dsl.do.actionEraseDevice.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionEraseDevice.with.operationId. - Source:
resource.dsl.do.actionEraseDevice.with.operationId - Usage: workflow_delete
entity.data.dsl.do.actionEraseDevice.with.pathParams.system_id
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionEraseDevice.with.pathParams.system_id. - Source:
resource.dsl.do.actionEraseDevice.with.pathParams.system_id - Usage: workflow_delete
entity.data.dsl.do.actionEraseDevice.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionEraseDevice.with.version. - Source:
resource.dsl.do.actionEraseDevice.with.version - Usage: workflow_delete
entity.data.dsl.do.actionReactivateUser.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionReactivateUser.call. - Source:
resource.dsl.do.actionReactivateUser.call - Usage: workflow_delete
entity.data.dsl.do.actionReactivateUser.metadata.displayLabels.user
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionReactivateUser.metadata.displayLabels.user. - Source:
resource.dsl.do.actionReactivateUser.metadata.displayLabels.user - Usage: workflow_delete
entity.data.dsl.do.actionReactivateUser.metadata.inputModes.user
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionReactivateUser.metadata.inputModes.user. - Source:
resource.dsl.do.actionReactivateUser.metadata.inputModes.user - Usage: workflow_delete
entity.data.dsl.do.actionReactivateUser.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionReactivateUser.with.operationId. - Source:
resource.dsl.do.actionReactivateUser.with.operationId - Usage: workflow_delete
entity.data.dsl.do.actionReactivateUser.with.pathParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionReactivateUser.with.pathParams.id. - Source:
resource.dsl.do.actionReactivateUser.with.pathParams.id - Usage: workflow_delete
entity.data.dsl.do.actionReactivateUser.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionReactivateUser.with.version. - Source:
resource.dsl.do.actionReactivateUser.with.version - Usage: workflow_delete
entity.data.dsl.do.actionRemoveUserFromUserGroup.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionRemoveUserFromUserGroup.call. - Source:
resource.dsl.do.actionRemoveUserFromUserGroup.call - Usage: workflow_delete
entity.data.dsl.do.actionRemoveUserFromUserGroup.metadata.displayLabels.user
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionRemoveUserFromUserGroup.metadata.displayLabels.user. - Source:
resource.dsl.do.actionRemoveUserFromUserGroup.metadata.displayLabels.user - Usage: workflow_delete
entity.data.dsl.do.actionRemoveUserFromUserGroup.metadata.displayLabels.userGroup
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionRemoveUserFromUserGroup.metadata.displayLabels.userGroup. - Source:
resource.dsl.do.actionRemoveUserFromUserGroup.metadata.displayLabels.userGroup - Usage: workflow_delete
entity.data.dsl.do.actionRemoveUserFromUserGroup.metadata.inputModes.user
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionRemoveUserFromUserGroup.metadata.inputModes.user. - Source:
resource.dsl.do.actionRemoveUserFromUserGroup.metadata.inputModes.user - Usage: workflow_delete
entity.data.dsl.do.actionRemoveUserFromUserGroup.metadata.inputModes.userGroup
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionRemoveUserFromUserGroup.metadata.inputModes.userGroup. - Source:
resource.dsl.do.actionRemoveUserFromUserGroup.metadata.inputModes.userGroup - Usage: workflow_delete
entity.data.dsl.do.actionRemoveUserFromUserGroup.with.bodyParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionRemoveUserFromUserGroup.with.bodyParams.id. - Source:
resource.dsl.do.actionRemoveUserFromUserGroup.with.bodyParams.id - Usage: workflow_delete
entity.data.dsl.do.actionRemoveUserFromUserGroup.with.bodyParams.op
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionRemoveUserFromUserGroup.with.bodyParams.op. - Source:
resource.dsl.do.actionRemoveUserFromUserGroup.with.bodyParams.op - Usage: workflow_delete
entity.data.dsl.do.actionRemoveUserFromUserGroup.with.bodyParams.type
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionRemoveUserFromUserGroup.with.bodyParams.type. - Source:
resource.dsl.do.actionRemoveUserFromUserGroup.with.bodyParams.type - Usage: workflow_delete
entity.data.dsl.do.actionRemoveUserFromUserGroup.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionRemoveUserFromUserGroup.with.operationId. - Source:
resource.dsl.do.actionRemoveUserFromUserGroup.with.operationId - Usage: workflow_delete
entity.data.dsl.do.actionRemoveUserFromUserGroup.with.pathParams.group_id
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionRemoveUserFromUserGroup.with.pathParams.group_id. - Source:
resource.dsl.do.actionRemoveUserFromUserGroup.with.pathParams.group_id - Usage: workflow_delete
entity.data.dsl.do.actionRemoveUserFromUserGroup.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionRemoveUserFromUserGroup.with.version. - Source:
resource.dsl.do.actionRemoveUserFromUserGroup.with.version - Usage: workflow_delete
entity.data.dsl.do.actionRunCommandOnDevice.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionRunCommandOnDevice.call. - Source:
resource.dsl.do.actionRunCommandOnDevice.call - Usage: workflow_delete
entity.data.dsl.do.actionRunCommandOnDevice.metadata.displayLabels.command
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionRunCommandOnDevice.metadata.displayLabels.command. - Source:
resource.dsl.do.actionRunCommandOnDevice.metadata.displayLabels.command - Usage: workflow_delete
entity.data.dsl.do.actionRunCommandOnDevice.metadata.displayLabels.devices
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionRunCommandOnDevice.metadata.displayLabels.devices. - Source:
resource.dsl.do.actionRunCommandOnDevice.metadata.displayLabels.devices - Usage: workflow_delete
entity.data.dsl.do.actionRunCommandOnDevice.metadata.inputModes.command
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionRunCommandOnDevice.metadata.inputModes.command. - Source:
resource.dsl.do.actionRunCommandOnDevice.metadata.inputModes.command - Usage: workflow_delete
entity.data.dsl.do.actionRunCommandOnDevice.metadata.inputModes.devices
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionRunCommandOnDevice.metadata.inputModes.devices. - Source:
resource.dsl.do.actionRunCommandOnDevice.metadata.inputModes.devices - Usage: workflow_delete
entity.data.dsl.do.actionRunCommandOnDevice.with.bodyParams._id
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionRunCommandOnDevice.with.bodyParams._id. - Source:
resource.dsl.do.actionRunCommandOnDevice.with.bodyParams._id - Usage: workflow_delete
entity.data.dsl.do.actionRunCommandOnDevice.with.bodyParams.systemIds
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionRunCommandOnDevice.with.bodyParams.systemIds. - Source:
resource.dsl.do.actionRunCommandOnDevice.with.bodyParams.systemIds - Usage: workflow_delete
entity.data.dsl.do.actionRunCommandOnDevice.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionRunCommandOnDevice.with.operationId. - Source:
resource.dsl.do.actionRunCommandOnDevice.with.operationId - Usage: workflow_delete
entity.data.dsl.do.actionRunCommandOnDevice.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.actionRunCommandOnDevice.with.version. - Source:
resource.dsl.do.actionRunCommandOnDevice.with.version - Usage: workflow_delete
entity.data.dsl.do.activateUser.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser.call. - Source:
resource.dsl.do.activateUser.call - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.activateUser.metadata.displayLabels.email
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser.metadata.displayLabels.email. - Source:
resource.dsl.do.activateUser.metadata.displayLabels.email - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.activateUser.metadata.displayLabels.user
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser.metadata.displayLabels.user. - Source:
resource.dsl.do.activateUser.metadata.displayLabels.user - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.activateUser.metadata.inputModes.email
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser.metadata.inputModes.email. - Source:
resource.dsl.do.activateUser.metadata.inputModes.email - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.activateUser.metadata.inputModes.user
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser.metadata.inputModes.user. - Source:
resource.dsl.do.activateUser.metadata.inputModes.user - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.activateUser.with.bodyParams.email
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser.with.bodyParams.email. - Source:
resource.dsl.do.activateUser.with.bodyParams.email - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.activateUser.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser.with.operationId. - Source:
resource.dsl.do.activateUser.with.operationId - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.activateUser.with.pathParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser.with.pathParams.id. - Source:
resource.dsl.do.activateUser.with.pathParams.id - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.activateUser.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser.with.version. - Source:
resource.dsl.do.activateUser.with.version - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.activateUser2.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser2.call. - Source:
resource.dsl.do.activateUser2.call - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.activateUser2.metadata.displayLabels.email
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser2.metadata.displayLabels.email. - Source:
resource.dsl.do.activateUser2.metadata.displayLabels.email - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.activateUser2.metadata.displayLabels.user
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser2.metadata.displayLabels.user. - Source:
resource.dsl.do.activateUser2.metadata.displayLabels.user - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.activateUser2.metadata.inputModes.email
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser2.metadata.inputModes.email. - Source:
resource.dsl.do.activateUser2.metadata.inputModes.email - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.activateUser2.metadata.inputModes.user
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser2.metadata.inputModes.user. - Source:
resource.dsl.do.activateUser2.metadata.inputModes.user - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.activateUser2.with.bodyParams.email
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser2.with.bodyParams.email. - Source:
resource.dsl.do.activateUser2.with.bodyParams.email - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.activateUser2.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser2.with.operationId. - Source:
resource.dsl.do.activateUser2.with.operationId - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.activateUser2.with.pathParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser2.with.pathParams.id. - Source:
resource.dsl.do.activateUser2.with.pathParams.id - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.activateUser2.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser2.with.version. - Source:
resource.dsl.do.activateUser2.with.version - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.activateUser3.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser3.call. - Source:
resource.dsl.do.activateUser3.call - Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser3.metadata.displayLabels.email
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser3.metadata.displayLabels.email. - Source:
resource.dsl.do.activateUser3.metadata.displayLabels.email - Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser3.metadata.displayLabels.user
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser3.metadata.displayLabels.user. - Source:
resource.dsl.do.activateUser3.metadata.displayLabels.user - Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser3.metadata.inputModes.email
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser3.metadata.inputModes.email. - Source:
resource.dsl.do.activateUser3.metadata.inputModes.email - Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser3.metadata.inputModes.user
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser3.metadata.inputModes.user. - Source:
resource.dsl.do.activateUser3.metadata.inputModes.user - Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser3.with.bodyParams.email
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser3.with.bodyParams.email. - Source:
resource.dsl.do.activateUser3.with.bodyParams.email - Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser3.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser3.with.operationId. - Source:
resource.dsl.do.activateUser3.with.operationId - Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser3.with.pathParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser3.with.pathParams.id. - Source:
resource.dsl.do.activateUser3.with.pathParams.id - Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser3.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser3.with.version. - Source:
resource.dsl.do.activateUser3.with.version - Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser4.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser4.call. - Source:
resource.dsl.do.activateUser4.call - Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser4.metadata.displayLabels.email
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser4.metadata.displayLabels.email. - Source:
resource.dsl.do.activateUser4.metadata.displayLabels.email - Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser4.metadata.displayLabels.user
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser4.metadata.displayLabels.user. - Source:
resource.dsl.do.activateUser4.metadata.displayLabels.user - Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser4.metadata.inputModes.email
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser4.metadata.inputModes.email. - Source:
resource.dsl.do.activateUser4.metadata.inputModes.email - Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser4.metadata.inputModes.user
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser4.metadata.inputModes.user. - Source:
resource.dsl.do.activateUser4.metadata.inputModes.user - Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser4.with.bodyParams.email
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser4.with.bodyParams.email. - Source:
resource.dsl.do.activateUser4.with.bodyParams.email - Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser4.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser4.with.operationId. - Source:
resource.dsl.do.activateUser4.with.operationId - Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser4.with.pathParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser4.with.pathParams.id. - Source:
resource.dsl.do.activateUser4.with.pathParams.id - Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser4.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser4.with.version. - Source:
resource.dsl.do.activateUser4.with.version - Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser5.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser5.call. - Source:
resource.dsl.do.activateUser5.call - Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser5.metadata.displayLabels.email
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser5.metadata.displayLabels.email. - Source:
resource.dsl.do.activateUser5.metadata.displayLabels.email - Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser5.metadata.displayLabels.user
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser5.metadata.displayLabels.user. - Source:
resource.dsl.do.activateUser5.metadata.displayLabels.user - Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser5.metadata.inputModes.email
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser5.metadata.inputModes.email. - Source:
resource.dsl.do.activateUser5.metadata.inputModes.email - Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser5.metadata.inputModes.user
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser5.metadata.inputModes.user. - Source:
resource.dsl.do.activateUser5.metadata.inputModes.user - Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser5.with.bodyParams.email
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser5.with.bodyParams.email. - Source:
resource.dsl.do.activateUser5.with.bodyParams.email - Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser5.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser5.with.operationId. - Source:
resource.dsl.do.activateUser5.with.operationId - Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser5.with.pathParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser5.with.pathParams.id. - Source:
resource.dsl.do.activateUser5.with.pathParams.id - Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser5.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser5.with.version. - Source:
resource.dsl.do.activateUser5.with.version - Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser6.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser6.call. - Source:
resource.dsl.do.activateUser6.call - Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser6.metadata.displayLabels.email
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser6.metadata.displayLabels.email. - Source:
resource.dsl.do.activateUser6.metadata.displayLabels.email - Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser6.metadata.displayLabels.user
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser6.metadata.displayLabels.user. - Source:
resource.dsl.do.activateUser6.metadata.displayLabels.user - Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser6.metadata.inputModes.email
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser6.metadata.inputModes.email. - Source:
resource.dsl.do.activateUser6.metadata.inputModes.email - Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser6.metadata.inputModes.user
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser6.metadata.inputModes.user. - Source:
resource.dsl.do.activateUser6.metadata.inputModes.user - Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser6.with.bodyParams.email
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser6.with.bodyParams.email. - Source:
resource.dsl.do.activateUser6.with.bodyParams.email - Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser6.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser6.with.operationId. - Source:
resource.dsl.do.activateUser6.with.operationId - Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser6.with.pathParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser6.with.pathParams.id. - Source:
resource.dsl.do.activateUser6.with.pathParams.id - Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser6.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser6.with.version. - Source:
resource.dsl.do.activateUser6.with.version - Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser7.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser7.call. - Source:
resource.dsl.do.activateUser7.call - Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser7.metadata.displayLabels.email
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser7.metadata.displayLabels.email. - Source:
resource.dsl.do.activateUser7.metadata.displayLabels.email - Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser7.metadata.displayLabels.user
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser7.metadata.displayLabels.user. - Source:
resource.dsl.do.activateUser7.metadata.displayLabels.user - Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser7.metadata.inputModes.email
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser7.metadata.inputModes.email. - Source:
resource.dsl.do.activateUser7.metadata.inputModes.email - Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser7.metadata.inputModes.user
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser7.metadata.inputModes.user. - Source:
resource.dsl.do.activateUser7.metadata.inputModes.user - Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser7.with.bodyParams.email
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser7.with.bodyParams.email. - Source:
resource.dsl.do.activateUser7.with.bodyParams.email - Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser7.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser7.with.operationId. - Source:
resource.dsl.do.activateUser7.with.operationId - Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser7.with.pathParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser7.with.pathParams.id. - Source:
resource.dsl.do.activateUser7.with.pathParams.id - Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser7.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser7.with.version. - Source:
resource.dsl.do.activateUser7.with.version - Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser8.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser8.call. - Source:
resource.dsl.do.activateUser8.call - Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser8.metadata.displayLabels.email
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser8.metadata.displayLabels.email. - Source:
resource.dsl.do.activateUser8.metadata.displayLabels.email - Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser8.metadata.displayLabels.user
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser8.metadata.displayLabels.user. - Source:
resource.dsl.do.activateUser8.metadata.displayLabels.user - Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser8.metadata.inputModes.email
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser8.metadata.inputModes.email. - Source:
resource.dsl.do.activateUser8.metadata.inputModes.email - Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser8.metadata.inputModes.user
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser8.metadata.inputModes.user. - Source:
resource.dsl.do.activateUser8.metadata.inputModes.user - Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser8.with.bodyParams.email
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser8.with.bodyParams.email. - Source:
resource.dsl.do.activateUser8.with.bodyParams.email - Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser8.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser8.with.operationId. - Source:
resource.dsl.do.activateUser8.with.operationId - Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser8.with.pathParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser8.with.pathParams.id. - Source:
resource.dsl.do.activateUser8.with.pathParams.id - Usage: workflow_create, workflow_delete
entity.data.dsl.do.activateUser8.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.activateUser8.with.version. - Source:
resource.dsl.do.activateUser8.with.version - Usage: workflow_create, workflow_delete
entity.data.dsl.do.activedirectoriesTranslationRules_recommendations.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.activedirectoriesTranslationRules_recommendations.call. - Source:
resource.dsl.do.activedirectoriesTranslationRules_recommendations.call - Usage: workflow_delete
entity.data.dsl.do.activedirectoriesTranslationRules_recommendations.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.activedirectoriesTranslationRules_recommendations.with.operationId. - Source:
resource.dsl.do.activedirectoriesTranslationRules_recommendations.with.operationId - Usage: workflow_delete
entity.data.dsl.do.activedirectoriesTranslationRules_recommendations.with.pathParams.provider_name
- Description: JumpCloud extension data on the managed entity:
dsl.do.activedirectoriesTranslationRules_recommendations.with.pathParams.provider_name. - Source:
resource.dsl.do.activedirectoriesTranslationRules_recommendations.with.pathParams.provider_name - Usage: workflow_delete
entity.data.dsl.do.activedirectoriesTranslationRules_recommendations.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.activedirectoriesTranslationRules_recommendations.with.version. - Source:
resource.dsl.do.activedirectoriesTranslationRules_recommendations.with.version - Usage: workflow_delete
entity.data.dsl.do.addDepartmentGroup1.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDepartmentGroup1.call. - Source:
resource.dsl.do.addDepartmentGroup1.call - Usage: workflow_create, workflow_update
entity.data.dsl.do.addDepartmentGroup1.with.bodyParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDepartmentGroup1.with.bodyParams.id. - Source:
resource.dsl.do.addDepartmentGroup1.with.bodyParams.id - Usage: workflow_create, workflow_update
entity.data.dsl.do.addDepartmentGroup1.with.bodyParams.op
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDepartmentGroup1.with.bodyParams.op. - Source:
resource.dsl.do.addDepartmentGroup1.with.bodyParams.op - Usage: workflow_create, workflow_update
entity.data.dsl.do.addDepartmentGroup1.with.bodyParams.type
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDepartmentGroup1.with.bodyParams.type. - Source:
resource.dsl.do.addDepartmentGroup1.with.bodyParams.type - Usage: workflow_create, workflow_update
entity.data.dsl.do.addDepartmentGroup1.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDepartmentGroup1.with.operationId. - Source:
resource.dsl.do.addDepartmentGroup1.with.operationId - Usage: workflow_create, workflow_update
entity.data.dsl.do.addDepartmentGroup1.with.pathParams.group_id
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDepartmentGroup1.with.pathParams.group_id. - Source:
resource.dsl.do.addDepartmentGroup1.with.pathParams.group_id - Usage: workflow_create, workflow_update
entity.data.dsl.do.addDepartmentGroup1.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDepartmentGroup1.with.version. - Source:
resource.dsl.do.addDepartmentGroup1.with.version - Usage: workflow_create, workflow_update
entity.data.dsl.do.addDepartmentGroup2.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDepartmentGroup2.call. - Source:
resource.dsl.do.addDepartmentGroup2.call - Usage: workflow_create, workflow_update
entity.data.dsl.do.addDepartmentGroup2.with.bodyParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDepartmentGroup2.with.bodyParams.id. - Source:
resource.dsl.do.addDepartmentGroup2.with.bodyParams.id - Usage: workflow_create, workflow_update
entity.data.dsl.do.addDepartmentGroup2.with.bodyParams.op
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDepartmentGroup2.with.bodyParams.op. - Source:
resource.dsl.do.addDepartmentGroup2.with.bodyParams.op - Usage: workflow_create, workflow_update
entity.data.dsl.do.addDepartmentGroup2.with.bodyParams.type
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDepartmentGroup2.with.bodyParams.type. - Source:
resource.dsl.do.addDepartmentGroup2.with.bodyParams.type - Usage: workflow_create, workflow_update
entity.data.dsl.do.addDepartmentGroup2.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDepartmentGroup2.with.operationId. - Source:
resource.dsl.do.addDepartmentGroup2.with.operationId - Usage: workflow_create, workflow_update
entity.data.dsl.do.addDepartmentGroup2.with.pathParams.group_id
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDepartmentGroup2.with.pathParams.group_id. - Source:
resource.dsl.do.addDepartmentGroup2.with.pathParams.group_id - Usage: workflow_create, workflow_update
entity.data.dsl.do.addDepartmentGroup2.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDepartmentGroup2.with.version. - Source:
resource.dsl.do.addDepartmentGroup2.with.version - Usage: workflow_create, workflow_update
entity.data.dsl.do.addDepartmentGroup3.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDepartmentGroup3.call. - Source:
resource.dsl.do.addDepartmentGroup3.call - Usage: workflow_create, workflow_update
entity.data.dsl.do.addDepartmentGroup3.with.bodyParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDepartmentGroup3.with.bodyParams.id. - Source:
resource.dsl.do.addDepartmentGroup3.with.bodyParams.id - Usage: workflow_create, workflow_update
entity.data.dsl.do.addDepartmentGroup3.with.bodyParams.op
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDepartmentGroup3.with.bodyParams.op. - Source:
resource.dsl.do.addDepartmentGroup3.with.bodyParams.op - Usage: workflow_create, workflow_update
entity.data.dsl.do.addDepartmentGroup3.with.bodyParams.type
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDepartmentGroup3.with.bodyParams.type. - Source:
resource.dsl.do.addDepartmentGroup3.with.bodyParams.type - Usage: workflow_create, workflow_update
entity.data.dsl.do.addDepartmentGroup3.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDepartmentGroup3.with.operationId. - Source:
resource.dsl.do.addDepartmentGroup3.with.operationId - Usage: workflow_create, workflow_update
entity.data.dsl.do.addDepartmentGroup3.with.pathParams.group_id
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDepartmentGroup3.with.pathParams.group_id. - Source:
resource.dsl.do.addDepartmentGroup3.with.pathParams.group_id - Usage: workflow_create, workflow_update
entity.data.dsl.do.addDepartmentGroup3.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDepartmentGroup3.with.version. - Source:
resource.dsl.do.addDepartmentGroup3.with.version - Usage: workflow_create, workflow_update
entity.data.dsl.do.addDeviceToDeviceGroup.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDeviceToDeviceGroup.call. - Source:
resource.dsl.do.addDeviceToDeviceGroup.call - Usage: workflow_create, workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup.metadata.displayLabels.device
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDeviceToDeviceGroup.metadata.displayLabels.device. - Source:
resource.dsl.do.addDeviceToDeviceGroup.metadata.displayLabels.device - Usage: workflow_create, workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup.metadata.displayLabels.deviceGroup
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDeviceToDeviceGroup.metadata.displayLabels.deviceGroup. - Source:
resource.dsl.do.addDeviceToDeviceGroup.metadata.displayLabels.deviceGroup - Usage: workflow_create, workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup.metadata.inputModes.device
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDeviceToDeviceGroup.metadata.inputModes.device. - Source:
resource.dsl.do.addDeviceToDeviceGroup.metadata.inputModes.device - Usage: workflow_create, workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup.metadata.inputModes.deviceGroup
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDeviceToDeviceGroup.metadata.inputModes.deviceGroup. - Source:
resource.dsl.do.addDeviceToDeviceGroup.metadata.inputModes.deviceGroup - Usage: workflow_create, workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDeviceToDeviceGroup.then. - Source:
resource.dsl.do.addDeviceToDeviceGroup.then - Usage: workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup.with.bodyParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDeviceToDeviceGroup.with.bodyParams.id. - Source:
resource.dsl.do.addDeviceToDeviceGroup.with.bodyParams.id - Usage: workflow_create, workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup.with.bodyParams.op
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDeviceToDeviceGroup.with.bodyParams.op. - Source:
resource.dsl.do.addDeviceToDeviceGroup.with.bodyParams.op - Usage: workflow_create, workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup.with.bodyParams.type
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDeviceToDeviceGroup.with.bodyParams.type. - Source:
resource.dsl.do.addDeviceToDeviceGroup.with.bodyParams.type - Usage: workflow_create, workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDeviceToDeviceGroup.with.operationId. - Source:
resource.dsl.do.addDeviceToDeviceGroup.with.operationId - Usage: workflow_create, workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup.with.pathParams.group_id
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDeviceToDeviceGroup.with.pathParams.group_id. - Source:
resource.dsl.do.addDeviceToDeviceGroup.with.pathParams.group_id - Usage: workflow_create, workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDeviceToDeviceGroup.with.version. - Source:
resource.dsl.do.addDeviceToDeviceGroup.with.version - Usage: workflow_create, workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup2.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDeviceToDeviceGroup2.call. - Source:
resource.dsl.do.addDeviceToDeviceGroup2.call - Usage: workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup2.metadata.displayLabels.device
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDeviceToDeviceGroup2.metadata.displayLabels.device. - Source:
resource.dsl.do.addDeviceToDeviceGroup2.metadata.displayLabels.device - Usage: workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup2.metadata.displayLabels.deviceGroup
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDeviceToDeviceGroup2.metadata.displayLabels.deviceGroup. - Source:
resource.dsl.do.addDeviceToDeviceGroup2.metadata.displayLabels.deviceGroup - Usage: workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup2.metadata.inputModes.device
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDeviceToDeviceGroup2.metadata.inputModes.device. - Source:
resource.dsl.do.addDeviceToDeviceGroup2.metadata.inputModes.device - Usage: workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup2.metadata.inputModes.deviceGroup
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDeviceToDeviceGroup2.metadata.inputModes.deviceGroup. - Source:
resource.dsl.do.addDeviceToDeviceGroup2.metadata.inputModes.deviceGroup - Usage: workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup2.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDeviceToDeviceGroup2.then. - Source:
resource.dsl.do.addDeviceToDeviceGroup2.then - Usage: workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup2.with.bodyParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDeviceToDeviceGroup2.with.bodyParams.id. - Source:
resource.dsl.do.addDeviceToDeviceGroup2.with.bodyParams.id - Usage: workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup2.with.bodyParams.op
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDeviceToDeviceGroup2.with.bodyParams.op. - Source:
resource.dsl.do.addDeviceToDeviceGroup2.with.bodyParams.op - Usage: workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup2.with.bodyParams.type
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDeviceToDeviceGroup2.with.bodyParams.type. - Source:
resource.dsl.do.addDeviceToDeviceGroup2.with.bodyParams.type - Usage: workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup2.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDeviceToDeviceGroup2.with.operationId. - Source:
resource.dsl.do.addDeviceToDeviceGroup2.with.operationId - Usage: workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup2.with.pathParams.group_id
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDeviceToDeviceGroup2.with.pathParams.group_id. - Source:
resource.dsl.do.addDeviceToDeviceGroup2.with.pathParams.group_id - Usage: workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup2.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDeviceToDeviceGroup2.with.version. - Source:
resource.dsl.do.addDeviceToDeviceGroup2.with.version - Usage: workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup3.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDeviceToDeviceGroup3.call. - Source:
resource.dsl.do.addDeviceToDeviceGroup3.call - Usage: workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup3.metadata.displayLabels.device
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDeviceToDeviceGroup3.metadata.displayLabels.device. - Source:
resource.dsl.do.addDeviceToDeviceGroup3.metadata.displayLabels.device - Usage: workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup3.metadata.displayLabels.deviceGroup
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDeviceToDeviceGroup3.metadata.displayLabels.deviceGroup. - Source:
resource.dsl.do.addDeviceToDeviceGroup3.metadata.displayLabels.deviceGroup - Usage: workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup3.metadata.inputModes.device
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDeviceToDeviceGroup3.metadata.inputModes.device. - Source:
resource.dsl.do.addDeviceToDeviceGroup3.metadata.inputModes.device - Usage: workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup3.metadata.inputModes.deviceGroup
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDeviceToDeviceGroup3.metadata.inputModes.deviceGroup. - Source:
resource.dsl.do.addDeviceToDeviceGroup3.metadata.inputModes.deviceGroup - Usage: workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup3.with.bodyParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDeviceToDeviceGroup3.with.bodyParams.id. - Source:
resource.dsl.do.addDeviceToDeviceGroup3.with.bodyParams.id - Usage: workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup3.with.bodyParams.op
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDeviceToDeviceGroup3.with.bodyParams.op. - Source:
resource.dsl.do.addDeviceToDeviceGroup3.with.bodyParams.op - Usage: workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup3.with.bodyParams.type
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDeviceToDeviceGroup3.with.bodyParams.type. - Source:
resource.dsl.do.addDeviceToDeviceGroup3.with.bodyParams.type - Usage: workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup3.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDeviceToDeviceGroup3.with.operationId. - Source:
resource.dsl.do.addDeviceToDeviceGroup3.with.operationId - Usage: workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup3.with.pathParams.group_id
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDeviceToDeviceGroup3.with.pathParams.group_id. - Source:
resource.dsl.do.addDeviceToDeviceGroup3.with.pathParams.group_id - Usage: workflow_delete
entity.data.dsl.do.addDeviceToDeviceGroup3.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.addDeviceToDeviceGroup3.with.version. - Source:
resource.dsl.do.addDeviceToDeviceGroup3.with.version - Usage: workflow_delete
entity.data.dsl.do.addToElevatedGroup.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.addToElevatedGroup.call. - Source:
resource.dsl.do.addToElevatedGroup.call - Usage: workflow_delete
entity.data.dsl.do.addToElevatedGroup.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.addToElevatedGroup.then. - Source:
resource.dsl.do.addToElevatedGroup.then - Usage: workflow_delete
entity.data.dsl.do.addToElevatedGroup.with.bodyParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.addToElevatedGroup.with.bodyParams.id. - Source:
resource.dsl.do.addToElevatedGroup.with.bodyParams.id - Usage: workflow_delete
entity.data.dsl.do.addToElevatedGroup.with.bodyParams.op
- Description: JumpCloud extension data on the managed entity:
dsl.do.addToElevatedGroup.with.bodyParams.op. - Source:
resource.dsl.do.addToElevatedGroup.with.bodyParams.op - Usage: workflow_delete
entity.data.dsl.do.addToElevatedGroup.with.bodyParams.type
- Description: JumpCloud extension data on the managed entity:
dsl.do.addToElevatedGroup.with.bodyParams.type. - Source:
resource.dsl.do.addToElevatedGroup.with.bodyParams.type - Usage: workflow_delete
entity.data.dsl.do.addToElevatedGroup.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.addToElevatedGroup.with.operationId. - Source:
resource.dsl.do.addToElevatedGroup.with.operationId - Usage: workflow_delete
entity.data.dsl.do.addToElevatedGroup.with.pathParams.group_id
- Description: JumpCloud extension data on the managed entity:
dsl.do.addToElevatedGroup.with.pathParams.group_id. - Source:
resource.dsl.do.addToElevatedGroup.with.pathParams.group_id - Usage: workflow_delete
entity.data.dsl.do.addToElevatedGroup.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.addToElevatedGroup.with.version. - Source:
resource.dsl.do.addToElevatedGroup.with.version - Usage: workflow_delete
entity.data.dsl.do.addUserToGroup.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.addUserToGroup.call. - Source:
resource.dsl.do.addUserToGroup.call - Usage: workflow_create
entity.data.dsl.do.addUserToGroup.if
- Description: JumpCloud extension data on the managed entity:
dsl.do.addUserToGroup.if. - Source:
resource.dsl.do.addUserToGroup.if - Usage: workflow_create
entity.data.dsl.do.addUserToGroup.with.bodyParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.addUserToGroup.with.bodyParams.id. - Source:
resource.dsl.do.addUserToGroup.with.bodyParams.id - Usage: workflow_create
entity.data.dsl.do.addUserToGroup.with.bodyParams.op
- Description: JumpCloud extension data on the managed entity:
dsl.do.addUserToGroup.with.bodyParams.op. - Source:
resource.dsl.do.addUserToGroup.with.bodyParams.op - Usage: workflow_create
entity.data.dsl.do.addUserToGroup.with.bodyParams.type
- Description: JumpCloud extension data on the managed entity:
dsl.do.addUserToGroup.with.bodyParams.type. - Source:
resource.dsl.do.addUserToGroup.with.bodyParams.type - Usage: workflow_create
entity.data.dsl.do.addUserToGroup.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.addUserToGroup.with.operationId. - Source:
resource.dsl.do.addUserToGroup.with.operationId - Usage: workflow_create
entity.data.dsl.do.addUserToGroup.with.pathParams.group_id
- Description: JumpCloud extension data on the managed entity:
dsl.do.addUserToGroup.with.pathParams.group_id. - Source:
resource.dsl.do.addUserToGroup.with.pathParams.group_id - Usage: workflow_create
entity.data.dsl.do.addUserToGroup.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.addUserToGroup.with.version. - Source:
resource.dsl.do.addUserToGroup.with.version - Usage: workflow_create
entity.data.dsl.do.addUserToUserGroup.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.addUserToUserGroup.call. - Source:
resource.dsl.do.addUserToUserGroup.call - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.addUserToUserGroup.metadata.displayLabels.user
- Description: JumpCloud extension data on the managed entity:
dsl.do.addUserToUserGroup.metadata.displayLabels.user. - Source:
resource.dsl.do.addUserToUserGroup.metadata.displayLabels.user - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.addUserToUserGroup.metadata.displayLabels.userGroup
- Description: JumpCloud extension data on the managed entity:
dsl.do.addUserToUserGroup.metadata.displayLabels.userGroup. - Source:
resource.dsl.do.addUserToUserGroup.metadata.displayLabels.userGroup - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.addUserToUserGroup.metadata.inputModes.user
- Description: JumpCloud extension data on the managed entity:
dsl.do.addUserToUserGroup.metadata.inputModes.user. - Source:
resource.dsl.do.addUserToUserGroup.metadata.inputModes.user - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.addUserToUserGroup.metadata.inputModes.userGroup
- Description: JumpCloud extension data on the managed entity:
dsl.do.addUserToUserGroup.metadata.inputModes.userGroup. - Source:
resource.dsl.do.addUserToUserGroup.metadata.inputModes.userGroup - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.addUserToUserGroup.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.addUserToUserGroup.then. - Source:
resource.dsl.do.addUserToUserGroup.then - Usage: workflow_delete
entity.data.dsl.do.addUserToUserGroup.with.bodyParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.addUserToUserGroup.with.bodyParams.id. - Source:
resource.dsl.do.addUserToUserGroup.with.bodyParams.id - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.addUserToUserGroup.with.bodyParams.op
- Description: JumpCloud extension data on the managed entity:
dsl.do.addUserToUserGroup.with.bodyParams.op. - Source:
resource.dsl.do.addUserToUserGroup.with.bodyParams.op - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.addUserToUserGroup.with.bodyParams.type
- Description: JumpCloud extension data on the managed entity:
dsl.do.addUserToUserGroup.with.bodyParams.type. - Source:
resource.dsl.do.addUserToUserGroup.with.bodyParams.type - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.addUserToUserGroup.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.addUserToUserGroup.with.operationId. - Source:
resource.dsl.do.addUserToUserGroup.with.operationId - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.addUserToUserGroup.with.pathParams.group_id
- Description: JumpCloud extension data on the managed entity:
dsl.do.addUserToUserGroup.with.pathParams.group_id. - Source:
resource.dsl.do.addUserToUserGroup.with.pathParams.group_id - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.addUserToUserGroup.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.addUserToUserGroup.with.version. - Source:
resource.dsl.do.addUserToUserGroup.with.version - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.addUserToUserGroup2.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.addUserToUserGroup2.call. - Source:
resource.dsl.do.addUserToUserGroup2.call - Usage: workflow_create, workflow_delete
entity.data.dsl.do.addUserToUserGroup2.metadata.displayLabels.user
- Description: JumpCloud extension data on the managed entity:
dsl.do.addUserToUserGroup2.metadata.displayLabels.user. - Source:
resource.dsl.do.addUserToUserGroup2.metadata.displayLabels.user - Usage: workflow_create, workflow_delete
entity.data.dsl.do.addUserToUserGroup2.metadata.displayLabels.userGroup
- Description: JumpCloud extension data on the managed entity:
dsl.do.addUserToUserGroup2.metadata.displayLabels.userGroup. - Source:
resource.dsl.do.addUserToUserGroup2.metadata.displayLabels.userGroup - Usage: workflow_create, workflow_delete
entity.data.dsl.do.addUserToUserGroup2.metadata.inputModes.user
- Description: JumpCloud extension data on the managed entity:
dsl.do.addUserToUserGroup2.metadata.inputModes.user. - Source:
resource.dsl.do.addUserToUserGroup2.metadata.inputModes.user - Usage: workflow_create, workflow_delete
entity.data.dsl.do.addUserToUserGroup2.metadata.inputModes.userGroup
- Description: JumpCloud extension data on the managed entity:
dsl.do.addUserToUserGroup2.metadata.inputModes.userGroup. - Source:
resource.dsl.do.addUserToUserGroup2.metadata.inputModes.userGroup - Usage: workflow_create, workflow_delete
entity.data.dsl.do.addUserToUserGroup2.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.addUserToUserGroup2.then. - Source:
resource.dsl.do.addUserToUserGroup2.then - Usage: workflow_delete
entity.data.dsl.do.addUserToUserGroup2.with.bodyParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.addUserToUserGroup2.with.bodyParams.id. - Source:
resource.dsl.do.addUserToUserGroup2.with.bodyParams.id - Usage: workflow_create, workflow_delete
entity.data.dsl.do.addUserToUserGroup2.with.bodyParams.op
- Description: JumpCloud extension data on the managed entity:
dsl.do.addUserToUserGroup2.with.bodyParams.op. - Source:
resource.dsl.do.addUserToUserGroup2.with.bodyParams.op - Usage: workflow_create, workflow_delete
entity.data.dsl.do.addUserToUserGroup2.with.bodyParams.type
- Description: JumpCloud extension data on the managed entity:
dsl.do.addUserToUserGroup2.with.bodyParams.type. - Source:
resource.dsl.do.addUserToUserGroup2.with.bodyParams.type - Usage: workflow_create, workflow_delete
entity.data.dsl.do.addUserToUserGroup2.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.addUserToUserGroup2.with.operationId. - Source:
resource.dsl.do.addUserToUserGroup2.with.operationId - Usage: workflow_create, workflow_delete
entity.data.dsl.do.addUserToUserGroup2.with.pathParams.group_id
- Description: JumpCloud extension data on the managed entity:
dsl.do.addUserToUserGroup2.with.pathParams.group_id. - Source:
resource.dsl.do.addUserToUserGroup2.with.pathParams.group_id - Usage: workflow_create, workflow_delete
entity.data.dsl.do.addUserToUserGroup2.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.addUserToUserGroup2.with.version. - Source:
resource.dsl.do.addUserToUserGroup2.with.version - Usage: workflow_create, workflow_delete
entity.data.dsl.do.allUsers.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.allUsers.call. - Source:
resource.dsl.do.allUsers.call - Usage: workflow_create
entity.data.dsl.do.allUsers.with.extract
- Description: JumpCloud extension data on the managed entity:
dsl.do.allUsers.with.extract. - Source:
resource.dsl.do.allUsers.with.extract - Usage: workflow_create
entity.data.dsl.do.allUsers.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.allUsers.with.operationId. - Source:
resource.dsl.do.allUsers.with.operationId - Usage: workflow_create
entity.data.dsl.do.allUsers.with.pagination.until
- Description: JumpCloud extension data on the managed entity:
dsl.do.allUsers.with.pagination.until. - Source:
resource.dsl.do.allUsers.with.pagination.until - Usage: workflow_create
entity.data.dsl.do.allUsers.with.pagination.update.in
- Description: JumpCloud extension data on the managed entity:
dsl.do.allUsers.with.pagination.update.in. - Source:
resource.dsl.do.allUsers.with.pagination.update.in - Usage: workflow_create
entity.data.dsl.do.allUsers.with.pagination.update.key
- Description: JumpCloud extension data on the managed entity:
dsl.do.allUsers.with.pagination.update.key. - Source:
resource.dsl.do.allUsers.with.pagination.update.key - Usage: workflow_create
entity.data.dsl.do.allUsers.with.pagination.update.value
- Description: JumpCloud extension data on the managed entity:
dsl.do.allUsers.with.pagination.update.value. - Source:
resource.dsl.do.allUsers.with.pagination.update.value - Usage: workflow_create
entity.data.dsl.do.allUsers.with.queryParams.limit
- Description: JumpCloud extension data on the managed entity:
dsl.do.allUsers.with.queryParams.limit. - Source:
resource.dsl.do.allUsers.with.queryParams.limit - Usage: workflow_create
entity.data.dsl.do.allUsers.with.queryParams.skip
- Description: JumpCloud extension data on the managed entity:
dsl.do.allUsers.with.queryParams.skip. - Source:
resource.dsl.do.allUsers.with.queryParams.skip - Usage: workflow_create
entity.data.dsl.do.allUsers.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.allUsers.with.version. - Source:
resource.dsl.do.allUsers.with.version - Usage: workflow_create
entity.data.dsl.do.appleMdmEraseDevice.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.appleMdmEraseDevice.call. - Source:
resource.dsl.do.appleMdmEraseDevice.call - Usage: workflow_delete
entity.data.dsl.do.appleMdmEraseDevice.metadata.displayLabels.device
- Description: JumpCloud extension data on the managed entity:
dsl.do.appleMdmEraseDevice.metadata.displayLabels.device. - Source:
resource.dsl.do.appleMdmEraseDevice.metadata.displayLabels.device - Usage: workflow_delete
entity.data.dsl.do.appleMdmEraseDevice.metadata.displayLabels.pin
- Description: JumpCloud extension data on the managed entity:
dsl.do.appleMdmEraseDevice.metadata.displayLabels.pin. - Source:
resource.dsl.do.appleMdmEraseDevice.metadata.displayLabels.pin - Usage: workflow_delete
entity.data.dsl.do.appleMdmEraseDevice.metadata.inputModes.device
- Description: JumpCloud extension data on the managed entity:
dsl.do.appleMdmEraseDevice.metadata.inputModes.device. - Source:
resource.dsl.do.appleMdmEraseDevice.metadata.inputModes.device - Usage: workflow_delete
entity.data.dsl.do.appleMdmEraseDevice.metadata.inputModes.pin
- Description: JumpCloud extension data on the managed entity:
dsl.do.appleMdmEraseDevice.metadata.inputModes.pin. - Source:
resource.dsl.do.appleMdmEraseDevice.metadata.inputModes.pin - Usage: workflow_delete
entity.data.dsl.do.appleMdmEraseDevice.with.bodyParams.pin
- Description: JumpCloud extension data on the managed entity:
dsl.do.appleMdmEraseDevice.with.bodyParams.pin. - Source:
resource.dsl.do.appleMdmEraseDevice.with.bodyParams.pin - Usage: workflow_delete
entity.data.dsl.do.appleMdmEraseDevice.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.appleMdmEraseDevice.with.operationId. - Source:
resource.dsl.do.appleMdmEraseDevice.with.operationId - Usage: workflow_delete
entity.data.dsl.do.appleMdmEraseDevice.with.pathParams.apple_mdm_id
- Description: JumpCloud extension data on the managed entity:
dsl.do.appleMdmEraseDevice.with.pathParams.apple_mdm_id. - Source:
resource.dsl.do.appleMdmEraseDevice.with.pathParams.apple_mdm_id - Usage: workflow_delete
entity.data.dsl.do.appleMdmEraseDevice.with.pathParams.device_id
- Description: JumpCloud extension data on the managed entity:
dsl.do.appleMdmEraseDevice.with.pathParams.device_id. - Source:
resource.dsl.do.appleMdmEraseDevice.with.pathParams.device_id - Usage: workflow_delete
entity.data.dsl.do.appleMdmEraseDevice.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.appleMdmEraseDevice.with.version. - Source:
resource.dsl.do.appleMdmEraseDevice.with.version - Usage: workflow_delete
entity.data.dsl.do.bindApplicationToUserGroup.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.bindApplicationToUserGroup.call. - Source:
resource.dsl.do.bindApplicationToUserGroup.call - Usage: workflow_create, workflow_delete
entity.data.dsl.do.bindApplicationToUserGroup.metadata.displayLabels.application
- Description: JumpCloud extension data on the managed entity:
dsl.do.bindApplicationToUserGroup.metadata.displayLabels.application. - Source:
resource.dsl.do.bindApplicationToUserGroup.metadata.displayLabels.application - Usage: workflow_create, workflow_delete
entity.data.dsl.do.bindApplicationToUserGroup.metadata.displayLabels.userGroup
- Description: JumpCloud extension data on the managed entity:
dsl.do.bindApplicationToUserGroup.metadata.displayLabels.userGroup. - Source:
resource.dsl.do.bindApplicationToUserGroup.metadata.displayLabels.userGroup - Usage: workflow_create, workflow_delete
entity.data.dsl.do.bindApplicationToUserGroup.metadata.inputModes.application
- Description: JumpCloud extension data on the managed entity:
dsl.do.bindApplicationToUserGroup.metadata.inputModes.application. - Source:
resource.dsl.do.bindApplicationToUserGroup.metadata.inputModes.application - Usage: workflow_create, workflow_delete
entity.data.dsl.do.bindApplicationToUserGroup.metadata.inputModes.userGroup
- Description: JumpCloud extension data on the managed entity:
dsl.do.bindApplicationToUserGroup.metadata.inputModes.userGroup. - Source:
resource.dsl.do.bindApplicationToUserGroup.metadata.inputModes.userGroup - Usage: workflow_create, workflow_delete
entity.data.dsl.do.bindApplicationToUserGroup.with.bodyParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.bindApplicationToUserGroup.with.bodyParams.id. - Source:
resource.dsl.do.bindApplicationToUserGroup.with.bodyParams.id - Usage: workflow_create, workflow_delete
entity.data.dsl.do.bindApplicationToUserGroup.with.bodyParams.op
- Description: JumpCloud extension data on the managed entity:
dsl.do.bindApplicationToUserGroup.with.bodyParams.op. - Source:
resource.dsl.do.bindApplicationToUserGroup.with.bodyParams.op - Usage: workflow_create, workflow_delete
entity.data.dsl.do.bindApplicationToUserGroup.with.bodyParams.type
- Description: JumpCloud extension data on the managed entity:
dsl.do.bindApplicationToUserGroup.with.bodyParams.type. - Source:
resource.dsl.do.bindApplicationToUserGroup.with.bodyParams.type - Usage: workflow_create, workflow_delete
entity.data.dsl.do.bindApplicationToUserGroup.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.bindApplicationToUserGroup.with.operationId. - Source:
resource.dsl.do.bindApplicationToUserGroup.with.operationId - Usage: workflow_create, workflow_delete
entity.data.dsl.do.bindApplicationToUserGroup.with.pathParams.application_id
- Description: JumpCloud extension data on the managed entity:
dsl.do.bindApplicationToUserGroup.with.pathParams.application_id. - Source:
resource.dsl.do.bindApplicationToUserGroup.with.pathParams.application_id - Usage: workflow_create, workflow_delete
entity.data.dsl.do.bindApplicationToUserGroup.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.bindApplicationToUserGroup.with.version. - Source:
resource.dsl.do.bindApplicationToUserGroup.with.version - Usage: workflow_create, workflow_delete
entity.data.dsl.do.bindPolicyToDevice.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.bindPolicyToDevice.call. - Source:
resource.dsl.do.bindPolicyToDevice.call - Usage: workflow_delete
entity.data.dsl.do.bindPolicyToDevice.metadata.displayLabels.device
- Description: JumpCloud extension data on the managed entity:
dsl.do.bindPolicyToDevice.metadata.displayLabels.device. - Source:
resource.dsl.do.bindPolicyToDevice.metadata.displayLabels.device - Usage: workflow_delete
entity.data.dsl.do.bindPolicyToDevice.metadata.displayLabels.policy
- Description: JumpCloud extension data on the managed entity:
dsl.do.bindPolicyToDevice.metadata.displayLabels.policy. - Source:
resource.dsl.do.bindPolicyToDevice.metadata.displayLabels.policy - Usage: workflow_delete
entity.data.dsl.do.bindPolicyToDevice.metadata.inputModes.device
- Description: JumpCloud extension data on the managed entity:
dsl.do.bindPolicyToDevice.metadata.inputModes.device. - Source:
resource.dsl.do.bindPolicyToDevice.metadata.inputModes.device - Usage: workflow_delete
entity.data.dsl.do.bindPolicyToDevice.metadata.inputModes.policy
- Description: JumpCloud extension data on the managed entity:
dsl.do.bindPolicyToDevice.metadata.inputModes.policy. - Source:
resource.dsl.do.bindPolicyToDevice.metadata.inputModes.policy - Usage: workflow_delete
entity.data.dsl.do.bindPolicyToDevice.with.bodyParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.bindPolicyToDevice.with.bodyParams.id. - Source:
resource.dsl.do.bindPolicyToDevice.with.bodyParams.id - Usage: workflow_delete
entity.data.dsl.do.bindPolicyToDevice.with.bodyParams.op
- Description: JumpCloud extension data on the managed entity:
dsl.do.bindPolicyToDevice.with.bodyParams.op. - Source:
resource.dsl.do.bindPolicyToDevice.with.bodyParams.op - Usage: workflow_delete
entity.data.dsl.do.bindPolicyToDevice.with.bodyParams.type
- Description: JumpCloud extension data on the managed entity:
dsl.do.bindPolicyToDevice.with.bodyParams.type. - Source:
resource.dsl.do.bindPolicyToDevice.with.bodyParams.type - Usage: workflow_delete
entity.data.dsl.do.bindPolicyToDevice.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.bindPolicyToDevice.with.operationId. - Source:
resource.dsl.do.bindPolicyToDevice.with.operationId - Usage: workflow_delete
entity.data.dsl.do.bindPolicyToDevice.with.pathParams.policy_id
- Description: JumpCloud extension data on the managed entity:
dsl.do.bindPolicyToDevice.with.pathParams.policy_id. - Source:
resource.dsl.do.bindPolicyToDevice.with.pathParams.policy_id - Usage: workflow_delete
entity.data.dsl.do.bindPolicyToDevice.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.bindPolicyToDevice.with.version. - Source:
resource.dsl.do.bindPolicyToDevice.with.version - Usage: workflow_delete
entity.data.dsl.do.bindPolicyToDeviceGroup.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.bindPolicyToDeviceGroup.call. - Source:
resource.dsl.do.bindPolicyToDeviceGroup.call - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.bindPolicyToDeviceGroup.metadata.displayLabels.deviceGroup
- Description: JumpCloud extension data on the managed entity:
dsl.do.bindPolicyToDeviceGroup.metadata.displayLabels.deviceGroup. - Source:
resource.dsl.do.bindPolicyToDeviceGroup.metadata.displayLabels.deviceGroup - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.bindPolicyToDeviceGroup.metadata.displayLabels.policy
- Description: JumpCloud extension data on the managed entity:
dsl.do.bindPolicyToDeviceGroup.metadata.displayLabels.policy. - Source:
resource.dsl.do.bindPolicyToDeviceGroup.metadata.displayLabels.policy - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.bindPolicyToDeviceGroup.metadata.inputModes.deviceGroup
- Description: JumpCloud extension data on the managed entity:
dsl.do.bindPolicyToDeviceGroup.metadata.inputModes.deviceGroup. - Source:
resource.dsl.do.bindPolicyToDeviceGroup.metadata.inputModes.deviceGroup - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.bindPolicyToDeviceGroup.metadata.inputModes.policy
- Description: JumpCloud extension data on the managed entity:
dsl.do.bindPolicyToDeviceGroup.metadata.inputModes.policy. - Source:
resource.dsl.do.bindPolicyToDeviceGroup.metadata.inputModes.policy - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.bindPolicyToDeviceGroup.with.bodyParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.bindPolicyToDeviceGroup.with.bodyParams.id. - Source:
resource.dsl.do.bindPolicyToDeviceGroup.with.bodyParams.id - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.bindPolicyToDeviceGroup.with.bodyParams.op
- Description: JumpCloud extension data on the managed entity:
dsl.do.bindPolicyToDeviceGroup.with.bodyParams.op. - Source:
resource.dsl.do.bindPolicyToDeviceGroup.with.bodyParams.op - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.bindPolicyToDeviceGroup.with.bodyParams.type
- Description: JumpCloud extension data on the managed entity:
dsl.do.bindPolicyToDeviceGroup.with.bodyParams.type. - Source:
resource.dsl.do.bindPolicyToDeviceGroup.with.bodyParams.type - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.bindPolicyToDeviceGroup.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.bindPolicyToDeviceGroup.with.operationId. - Source:
resource.dsl.do.bindPolicyToDeviceGroup.with.operationId - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.bindPolicyToDeviceGroup.with.pathParams.policy_id
- Description: JumpCloud extension data on the managed entity:
dsl.do.bindPolicyToDeviceGroup.with.pathParams.policy_id. - Source:
resource.dsl.do.bindPolicyToDeviceGroup.with.pathParams.policy_id - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.bindPolicyToDeviceGroup.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.bindPolicyToDeviceGroup.with.version. - Source:
resource.dsl.do.bindPolicyToDeviceGroup.with.version - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.bind_policy_to_device_group.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.bind_policy_to_device_group.call. - Source:
resource.dsl.do.bind_policy_to_device_group.call - Usage: workflow_delete
entity.data.dsl.do.bind_policy_to_device_group.metadata.displayLabels.deviceGroup
- Description: JumpCloud extension data on the managed entity:
dsl.do.bind_policy_to_device_group.metadata.displayLabels.deviceGroup. - Source:
resource.dsl.do.bind_policy_to_device_group.metadata.displayLabels.deviceGroup - Usage: workflow_delete
entity.data.dsl.do.bind_policy_to_device_group.metadata.displayLabels.policy
- Description: JumpCloud extension data on the managed entity:
dsl.do.bind_policy_to_device_group.metadata.displayLabels.policy. - Source:
resource.dsl.do.bind_policy_to_device_group.metadata.displayLabels.policy - Usage: workflow_delete
entity.data.dsl.do.bind_policy_to_device_group.metadata.inputModes.deviceGroup
- Description: JumpCloud extension data on the managed entity:
dsl.do.bind_policy_to_device_group.metadata.inputModes.deviceGroup. - Source:
resource.dsl.do.bind_policy_to_device_group.metadata.inputModes.deviceGroup - Usage: workflow_delete
entity.data.dsl.do.bind_policy_to_device_group.metadata.inputModes.policy
- Description: JumpCloud extension data on the managed entity:
dsl.do.bind_policy_to_device_group.metadata.inputModes.policy. - Source:
resource.dsl.do.bind_policy_to_device_group.metadata.inputModes.policy - Usage: workflow_delete
entity.data.dsl.do.bind_policy_to_device_group.with.bodyParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.bind_policy_to_device_group.with.bodyParams.id. - Source:
resource.dsl.do.bind_policy_to_device_group.with.bodyParams.id - Usage: workflow_delete
entity.data.dsl.do.bind_policy_to_device_group.with.bodyParams.op
- Description: JumpCloud extension data on the managed entity:
dsl.do.bind_policy_to_device_group.with.bodyParams.op. - Source:
resource.dsl.do.bind_policy_to_device_group.with.bodyParams.op - Usage: workflow_delete
entity.data.dsl.do.bind_policy_to_device_group.with.bodyParams.type
- Description: JumpCloud extension data on the managed entity:
dsl.do.bind_policy_to_device_group.with.bodyParams.type. - Source:
resource.dsl.do.bind_policy_to_device_group.with.bodyParams.type - Usage: workflow_delete
entity.data.dsl.do.bind_policy_to_device_group.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.bind_policy_to_device_group.with.operationId. - Source:
resource.dsl.do.bind_policy_to_device_group.with.operationId - Usage: workflow_delete
entity.data.dsl.do.bind_policy_to_device_group.with.pathParams.policy_id
- Description: JumpCloud extension data on the managed entity:
dsl.do.bind_policy_to_device_group.with.pathParams.policy_id. - Source:
resource.dsl.do.bind_policy_to_device_group.with.pathParams.policy_id - Usage: workflow_delete
entity.data.dsl.do.bind_policy_to_device_group.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.bind_policy_to_device_group.with.version. - Source:
resource.dsl.do.bind_policy_to_device_group.with.version - Usage: workflow_delete
entity.data.dsl.do.bind_user_to_system.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.bind_user_to_system.call. - Source:
resource.dsl.do.bind_user_to_system.call - Usage: workflow_create, workflow_delete
entity.data.dsl.do.bind_user_to_system.if
- Description: JumpCloud extension data on the managed entity:
dsl.do.bind_user_to_system.if. - Source:
resource.dsl.do.bind_user_to_system.if - Usage: workflow_create, workflow_delete
entity.data.dsl.do.bind_user_to_system.with.bodyParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.bind_user_to_system.with.bodyParams.id. - Source:
resource.dsl.do.bind_user_to_system.with.bodyParams.id - Usage: workflow_create, workflow_delete
entity.data.dsl.do.bind_user_to_system.with.bodyParams.op
- Description: JumpCloud extension data on the managed entity:
dsl.do.bind_user_to_system.with.bodyParams.op. - Source:
resource.dsl.do.bind_user_to_system.with.bodyParams.op - Usage: workflow_create, workflow_delete
entity.data.dsl.do.bind_user_to_system.with.bodyParams.type
- Description: JumpCloud extension data on the managed entity:
dsl.do.bind_user_to_system.with.bodyParams.type. - Source:
resource.dsl.do.bind_user_to_system.with.bodyParams.type - Usage: workflow_create, workflow_delete
entity.data.dsl.do.bind_user_to_system.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.bind_user_to_system.with.operationId. - Source:
resource.dsl.do.bind_user_to_system.with.operationId - Usage: workflow_create, workflow_delete
entity.data.dsl.do.bind_user_to_system.with.pathParams.system_id
- Description: JumpCloud extension data on the managed entity:
dsl.do.bind_user_to_system.with.pathParams.system_id. - Source:
resource.dsl.do.bind_user_to_system.with.pathParams.system_id - Usage: workflow_create, workflow_delete
entity.data.dsl.do.bind_user_to_system.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.bind_user_to_system.with.version. - Source:
resource.dsl.do.bind_user_to_system.with.version - Usage: workflow_create, workflow_delete
entity.data.dsl.do.callConnector.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.callConnector.call. - Source:
resource.dsl.do.callConnector.call - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.callConnector.with.body.data
- Description: JumpCloud extension data on the managed entity:
dsl.do.callConnector.with.body.data. - Source:
resource.dsl.do.callConnector.with.body.data - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.callConnector.with.body.fields.description.content.content.text
- Description: JumpCloud extension data on the managed entity:
dsl.do.callConnector.with.body.fields.description.content.content.text. - Source:
resource.dsl.do.callConnector.with.body.fields.description.content.content.text - Usage: workflow_create
entity.data.dsl.do.callConnector.with.body.fields.description.content.content.type
- Description: JumpCloud extension data on the managed entity:
dsl.do.callConnector.with.body.fields.description.content.content.type. - Source:
resource.dsl.do.callConnector.with.body.fields.description.content.content.type - Usage: workflow_create
entity.data.dsl.do.callConnector.with.body.fields.description.content.type
- Description: JumpCloud extension data on the managed entity:
dsl.do.callConnector.with.body.fields.description.content.type. - Source:
resource.dsl.do.callConnector.with.body.fields.description.content.type - Usage: workflow_create
entity.data.dsl.do.callConnector.with.body.fields.description.type
- Description: JumpCloud extension data on the managed entity:
dsl.do.callConnector.with.body.fields.description.type. - Source:
resource.dsl.do.callConnector.with.body.fields.description.type - Usage: workflow_create
entity.data.dsl.do.callConnector.with.body.fields.description.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.callConnector.with.body.fields.description.version. - Source:
resource.dsl.do.callConnector.with.body.fields.description.version - Usage: workflow_create
entity.data.dsl.do.callConnector.with.body.fields.issuetype.name
- Description: JumpCloud extension data on the managed entity:
dsl.do.callConnector.with.body.fields.issuetype.name. - Source:
resource.dsl.do.callConnector.with.body.fields.issuetype.name - Usage: workflow_create
entity.data.dsl.do.callConnector.with.body.fields.project.key
- Description: JumpCloud extension data on the managed entity:
dsl.do.callConnector.with.body.fields.project.key. - Source:
resource.dsl.do.callConnector.with.body.fields.project.key - Usage: workflow_create
entity.data.dsl.do.callConnector.with.body.fields.summary
- Description: JumpCloud extension data on the managed entity:
dsl.do.callConnector.with.body.fields.summary. - Source:
resource.dsl.do.callConnector.with.body.fields.summary - Usage: workflow_create
entity.data.dsl.do.callConnector.with.body.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.callConnector.with.body.id. - Source:
resource.dsl.do.callConnector.with.body.id - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.callConnector.with.body.timestamp
- Description: JumpCloud extension data on the managed entity:
dsl.do.callConnector.with.body.timestamp. - Source:
resource.dsl.do.callConnector.with.body.timestamp - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.callConnector.with.endpointPath
- Description: JumpCloud extension data on the managed entity:
dsl.do.callConnector.with.endpointPath. - Source:
resource.dsl.do.callConnector.with.endpointPath - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.callConnector.with.headers.Accept
- Description: JumpCloud extension data on the managed entity:
dsl.do.callConnector.with.headers.Accept. - Source:
resource.dsl.do.callConnector.with.headers.Accept - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.callConnector.with.headers.EWrwer
- Description: JumpCloud extension data on the managed entity:
dsl.do.callConnector.with.headers.EWrwer. - Source:
resource.dsl.do.callConnector.with.headers.EWrwer - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.callConnector.with.headers.ew
- Description: JumpCloud extension data on the managed entity:
dsl.do.callConnector.with.headers.ew. - Source:
resource.dsl.do.callConnector.with.headers.ew - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.callConnector.with.headers.ewd
- Description: JumpCloud extension data on the managed entity:
dsl.do.callConnector.with.headers.ewd. - Source:
resource.dsl.do.callConnector.with.headers.ewd - Usage: workflow_delete, workflow_update
entity.data.dsl.do.callConnector.with.headers.ewe
- Description: JumpCloud extension data on the managed entity:
dsl.do.callConnector.with.headers.ewe. - Source:
resource.dsl.do.callConnector.with.headers.ewe - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.callConnector.with.httpMethod
- Description: JumpCloud extension data on the managed entity:
dsl.do.callConnector.with.httpMethod. - Source:
resource.dsl.do.callConnector.with.httpMethod - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.callConnector.with.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.callConnector.with.id. - Source:
resource.dsl.do.callConnector.with.id - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.callConnector2.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.callConnector2.call. - Source:
resource.dsl.do.callConnector2.call - Usage: workflow_delete
entity.data.dsl.do.callConnector2.with.endpointPath
- Description: JumpCloud extension data on the managed entity:
dsl.do.callConnector2.with.endpointPath. - Source:
resource.dsl.do.callConnector2.with.endpointPath - Usage: workflow_delete
entity.data.dsl.do.callConnector2.with.httpMethod
- Description: JumpCloud extension data on the managed entity:
dsl.do.callConnector2.with.httpMethod. - Source:
resource.dsl.do.callConnector2.with.httpMethod - Usage: workflow_delete
entity.data.dsl.do.callConnector2.with.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.callConnector2.with.id. - Source:
resource.dsl.do.callConnector2.with.id - Usage: workflow_delete
entity.data.dsl.do.callConnector3.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.callConnector3.call. - Source:
resource.dsl.do.callConnector3.call - Usage: workflow_delete
entity.data.dsl.do.callConnector3.with.endpointPath
- Description: JumpCloud extension data on the managed entity:
dsl.do.callConnector3.with.endpointPath. - Source:
resource.dsl.do.callConnector3.with.endpointPath - Usage: workflow_delete
entity.data.dsl.do.callConnector3.with.httpMethod
- Description: JumpCloud extension data on the managed entity:
dsl.do.callConnector3.with.httpMethod. - Source:
resource.dsl.do.callConnector3.with.httpMethod - Usage: workflow_delete
entity.data.dsl.do.callConnector3.with.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.callConnector3.with.id. - Source:
resource.dsl.do.callConnector3.with.id - Usage: workflow_delete
entity.data.dsl.do.checkActivated.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.checkActivated.call. - Source:
resource.dsl.do.checkActivated.call - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.checkActivated.if
- Description: JumpCloud extension data on the managed entity:
dsl.do.checkActivated.if. - Source:
resource.dsl.do.checkActivated.if - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.checkActivated.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.checkActivated.with.operationId. - Source:
resource.dsl.do.checkActivated.with.operationId - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.checkActivated.with.pathParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.checkActivated.with.pathParams.id. - Source:
resource.dsl.do.checkActivated.with.pathParams.id - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.checkActivated.with.queryParams.fields
- Description: JumpCloud extension data on the managed entity:
dsl.do.checkActivated.with.queryParams.fields. - Source:
resource.dsl.do.checkActivated.with.queryParams.fields - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.checkActivated.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.checkActivated.with.version. - Source:
resource.dsl.do.checkActivated.with.version - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.checkDelegatedAuthorityExists.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.checkDelegatedAuthorityExists.call. - Source:
resource.dsl.do.checkDelegatedAuthorityExists.call - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.checkDelegatedAuthorityExists.if
- Description: JumpCloud extension data on the managed entity:
dsl.do.checkDelegatedAuthorityExists.if. - Source:
resource.dsl.do.checkDelegatedAuthorityExists.if - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.checkDelegatedAuthorityExists.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.checkDelegatedAuthorityExists.with.operationId. - Source:
resource.dsl.do.checkDelegatedAuthorityExists.with.operationId - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.checkDelegatedAuthorityExists.with.pathParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.checkDelegatedAuthorityExists.with.pathParams.id. - Source:
resource.dsl.do.checkDelegatedAuthorityExists.with.pathParams.id - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.checkDelegatedAuthorityExists.with.queryParams.fields
- Description: JumpCloud extension data on the managed entity:
dsl.do.checkDelegatedAuthorityExists.with.queryParams.fields. - Source:
resource.dsl.do.checkDelegatedAuthorityExists.with.queryParams.fields - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.checkDelegatedAuthorityExists.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.checkDelegatedAuthorityExists.with.version. - Source:
resource.dsl.do.checkDelegatedAuthorityExists.with.version - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.checkPasswordDate.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.checkPasswordDate.call. - Source:
resource.dsl.do.checkPasswordDate.call - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.checkPasswordDate.if
- Description: JumpCloud extension data on the managed entity:
dsl.do.checkPasswordDate.if. - Source:
resource.dsl.do.checkPasswordDate.if - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.checkPasswordDate.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.checkPasswordDate.with.operationId. - Source:
resource.dsl.do.checkPasswordDate.with.operationId - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.checkPasswordDate.with.pathParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.checkPasswordDate.with.pathParams.id. - Source:
resource.dsl.do.checkPasswordDate.with.pathParams.id - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.checkPasswordDate.with.queryParams.fields
- Description: JumpCloud extension data on the managed entity:
dsl.do.checkPasswordDate.with.queryParams.fields. - Source:
resource.dsl.do.checkPasswordDate.with.queryParams.fields - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.checkPasswordDate.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.checkPasswordDate.with.version. - Source:
resource.dsl.do.checkPasswordDate.with.version - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.checkUserInUserGroupListMembership.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.checkUserInUserGroupListMembership.call. - Source:
resource.dsl.do.checkUserInUserGroupListMembership.call - Usage: workflow_create, workflow_delete
entity.data.dsl.do.checkUserInUserGroupListMembership.metadata.compositeGroupId
- Description: JumpCloud extension data on the managed entity:
dsl.do.checkUserInUserGroupListMembership.metadata.compositeGroupId. - Source:
resource.dsl.do.checkUserInUserGroupListMembership.metadata.compositeGroupId - Usage: workflow_create, workflow_delete
entity.data.dsl.do.checkUserInUserGroupListMembership.metadata.compositeNodeId
- Description: JumpCloud extension data on the managed entity:
dsl.do.checkUserInUserGroupListMembership.metadata.compositeNodeId. - Source:
resource.dsl.do.checkUserInUserGroupListMembership.metadata.compositeNodeId - Usage: workflow_create, workflow_delete
entity.data.dsl.do.checkUserInUserGroupListMembership.metadata.compositeStepId
- Description: JumpCloud extension data on the managed entity:
dsl.do.checkUserInUserGroupListMembership.metadata.compositeStepId. - Source:
resource.dsl.do.checkUserInUserGroupListMembership.metadata.compositeStepId - Usage: workflow_create, workflow_delete
entity.data.dsl.do.checkUserInUserGroupListMembership.metadata.compositeStepIndex
- Description: JumpCloud extension data on the managed entity:
dsl.do.checkUserInUserGroupListMembership.metadata.compositeStepIndex. - Source:
resource.dsl.do.checkUserInUserGroupListMembership.metadata.compositeStepIndex - Usage: workflow_create, workflow_delete
entity.data.dsl.do.checkUserInUserGroupListMembership.metadata.compositeTemplateId
- Description: JumpCloud extension data on the managed entity:
dsl.do.checkUserInUserGroupListMembership.metadata.compositeTemplateId. - Source:
resource.dsl.do.checkUserInUserGroupListMembership.metadata.compositeTemplateId - Usage: workflow_create, workflow_delete
entity.data.dsl.do.checkUserInUserGroupListMembership.metadata.displayLabels.user
- Description: JumpCloud extension data on the managed entity:
dsl.do.checkUserInUserGroupListMembership.metadata.displayLabels.user. - Source:
resource.dsl.do.checkUserInUserGroupListMembership.metadata.displayLabels.user - Usage: workflow_create, workflow_delete
entity.data.dsl.do.checkUserInUserGroupListMembership.metadata.displayLabels.userGroup
- Description: JumpCloud extension data on the managed entity:
dsl.do.checkUserInUserGroupListMembership.metadata.displayLabels.userGroup. - Source:
resource.dsl.do.checkUserInUserGroupListMembership.metadata.displayLabels.userGroup - Usage: workflow_create, workflow_delete
entity.data.dsl.do.checkUserInUserGroupListMembership.metadata.inputModes.user
- Description: JumpCloud extension data on the managed entity:
dsl.do.checkUserInUserGroupListMembership.metadata.inputModes.user. - Source:
resource.dsl.do.checkUserInUserGroupListMembership.metadata.inputModes.user - Usage: workflow_create, workflow_delete
entity.data.dsl.do.checkUserInUserGroupListMembership.metadata.inputModes.userGroup
- Description: JumpCloud extension data on the managed entity:
dsl.do.checkUserInUserGroupListMembership.metadata.inputModes.userGroup. - Source:
resource.dsl.do.checkUserInUserGroupListMembership.metadata.inputModes.userGroup - Usage: workflow_create, workflow_delete
entity.data.dsl.do.checkUserInUserGroupListMembership.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.checkUserInUserGroupListMembership.with.operationId. - Source:
resource.dsl.do.checkUserInUserGroupListMembership.with.operationId - Usage: workflow_create, workflow_delete
entity.data.dsl.do.checkUserInUserGroupListMembership.with.pathParams.group_id
- Description: JumpCloud extension data on the managed entity:
dsl.do.checkUserInUserGroupListMembership.with.pathParams.group_id. - Source:
resource.dsl.do.checkUserInUserGroupListMembership.with.pathParams.group_id - Usage: workflow_create, workflow_delete
entity.data.dsl.do.checkUserInUserGroupListMembership.with.queryParams.filter
- Description: JumpCloud extension data on the managed entity:
dsl.do.checkUserInUserGroupListMembership.with.queryParams.filter. - Source:
resource.dsl.do.checkUserInUserGroupListMembership.with.queryParams.filter - Usage: workflow_create, workflow_delete
entity.data.dsl.do.checkUserInUserGroupListMembership.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.checkUserInUserGroupListMembership.with.version. - Source:
resource.dsl.do.checkUserInUserGroupListMembership.with.version - Usage: workflow_create, workflow_delete
entity.data.dsl.do.checkUserInUserGroupRouteMembership.metadata.compositeGroupId
- Description: JumpCloud extension data on the managed entity:
dsl.do.checkUserInUserGroupRouteMembership.metadata.compositeGroupId. - Source:
resource.dsl.do.checkUserInUserGroupRouteMembership.metadata.compositeGroupId - Usage: workflow_create, workflow_delete
entity.data.dsl.do.checkUserInUserGroupRouteMembership.metadata.compositeNodeId
- Description: JumpCloud extension data on the managed entity:
dsl.do.checkUserInUserGroupRouteMembership.metadata.compositeNodeId. - Source:
resource.dsl.do.checkUserInUserGroupRouteMembership.metadata.compositeNodeId - Usage: workflow_create, workflow_delete
entity.data.dsl.do.checkUserInUserGroupRouteMembership.metadata.compositeStepId
- Description: JumpCloud extension data on the managed entity:
dsl.do.checkUserInUserGroupRouteMembership.metadata.compositeStepId. - Source:
resource.dsl.do.checkUserInUserGroupRouteMembership.metadata.compositeStepId - Usage: workflow_create, workflow_delete
entity.data.dsl.do.checkUserInUserGroupRouteMembership.metadata.compositeStepIndex
- Description: JumpCloud extension data on the managed entity:
dsl.do.checkUserInUserGroupRouteMembership.metadata.compositeStepIndex. - Source:
resource.dsl.do.checkUserInUserGroupRouteMembership.metadata.compositeStepIndex - Usage: workflow_create, workflow_delete
entity.data.dsl.do.checkUserInUserGroupRouteMembership.metadata.compositeTemplateId
- Description: JumpCloud extension data on the managed entity:
dsl.do.checkUserInUserGroupRouteMembership.metadata.compositeTemplateId. - Source:
resource.dsl.do.checkUserInUserGroupRouteMembership.metadata.compositeTemplateId - Usage: workflow_create, workflow_delete
entity.data.dsl.do.checkUserInUserGroupRouteMembership.switch.default.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.checkUserInUserGroupRouteMembership.switch.default.then. - Source:
resource.dsl.do.checkUserInUserGroupRouteMembership.switch.default.then - Usage: workflow_create, workflow_delete
entity.data.dsl.do.checkUserInUserGroupRouteMembership.switch.isMember.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.checkUserInUserGroupRouteMembership.switch.isMember.then. - Source:
resource.dsl.do.checkUserInUserGroupRouteMembership.switch.isMember.then - Usage: workflow_create, workflow_delete
entity.data.dsl.do.checkUserInUserGroupRouteMembership.switch.isMember.when
- Description: JumpCloud extension data on the managed entity:
dsl.do.checkUserInUserGroupRouteMembership.switch.isMember.when. - Source:
resource.dsl.do.checkUserInUserGroupRouteMembership.switch.isMember.when - Usage: workflow_create, workflow_delete
entity.data.dsl.do.commands_get.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.commands_get.call. - Source:
resource.dsl.do.commands_get.call - Usage: workflow_create, workflow_delete
entity.data.dsl.do.commands_get.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.commands_get.with.operationId. - Source:
resource.dsl.do.commands_get.with.operationId - Usage: workflow_create, workflow_delete
entity.data.dsl.do.commands_get.with.pathParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.commands_get.with.pathParams.id. - Source:
resource.dsl.do.commands_get.with.pathParams.id - Usage: workflow_create, workflow_delete
entity.data.dsl.do.commands_get.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.commands_get.with.version. - Source:
resource.dsl.do.commands_get.with.version - Usage: workflow_create, workflow_delete
entity.data.dsl.do.commands_put.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.commands_put.call. - Source:
resource.dsl.do.commands_put.call - Usage: workflow_delete
entity.data.dsl.do.commands_put.with.bodyParams.aiGenerated
- Description: JumpCloud extension data on the managed entity:
dsl.do.commands_put.with.bodyParams.aiGenerated. - Source:
resource.dsl.do.commands_put.with.bodyParams.aiGenerated - Usage: workflow_delete
entity.data.dsl.do.commands_put.with.bodyParams.command
- Description: JumpCloud extension data on the managed entity:
dsl.do.commands_put.with.bodyParams.command. - Source:
resource.dsl.do.commands_put.with.bodyParams.command - Usage: workflow_delete
entity.data.dsl.do.commands_put.with.bodyParams.commandRunners
- Description: JumpCloud extension data on the managed entity:
dsl.do.commands_put.with.bodyParams.commandRunners. - Source:
resource.dsl.do.commands_put.with.bodyParams.commandRunners - Usage: workflow_delete
entity.data.dsl.do.commands_put.with.bodyParams.commandType
- Description: JumpCloud extension data on the managed entity:
dsl.do.commands_put.with.bodyParams.commandType. - Source:
resource.dsl.do.commands_put.with.bodyParams.commandType - Usage: workflow_delete
entity.data.dsl.do.commands_put.with.bodyParams.description
- Description: JumpCloud extension data on the managed entity:
dsl.do.commands_put.with.bodyParams.description. - Source:
resource.dsl.do.commands_put.with.bodyParams.description - Usage: workflow_delete
entity.data.dsl.do.commands_put.with.bodyParams.files
- Description: JumpCloud extension data on the managed entity:
dsl.do.commands_put.with.bodyParams.files. - Source:
resource.dsl.do.commands_put.with.bodyParams.files - Usage: workflow_delete
entity.data.dsl.do.commands_put.with.bodyParams.filesS3
- Description: JumpCloud extension data on the managed entity:
dsl.do.commands_put.with.bodyParams.filesS3. - Source:
resource.dsl.do.commands_put.with.bodyParams.filesS3 - Usage: workflow_delete
entity.data.dsl.do.commands_put.with.bodyParams.launchType
- Description: JumpCloud extension data on the managed entity:
dsl.do.commands_put.with.bodyParams.launchType. - Source:
resource.dsl.do.commands_put.with.bodyParams.launchType - Usage: workflow_delete
entity.data.dsl.do.commands_put.with.bodyParams.listensTo
- Description: JumpCloud extension data on the managed entity:
dsl.do.commands_put.with.bodyParams.listensTo. - Source:
resource.dsl.do.commands_put.with.bodyParams.listensTo - Usage: workflow_delete
entity.data.dsl.do.commands_put.with.bodyParams.name
- Description: JumpCloud extension data on the managed entity:
dsl.do.commands_put.with.bodyParams.name. - Source:
resource.dsl.do.commands_put.with.bodyParams.name - Usage: workflow_delete
entity.data.dsl.do.commands_put.with.bodyParams.organization
- Description: JumpCloud extension data on the managed entity:
dsl.do.commands_put.with.bodyParams.organization. - Source:
resource.dsl.do.commands_put.with.bodyParams.organization - Usage: workflow_delete
entity.data.dsl.do.commands_put.with.bodyParams.schedule
- Description: JumpCloud extension data on the managed entity:
dsl.do.commands_put.with.bodyParams.schedule. - Source:
resource.dsl.do.commands_put.with.bodyParams.schedule - Usage: workflow_delete
entity.data.dsl.do.commands_put.with.bodyParams.scheduleRepeatType
- Description: JumpCloud extension data on the managed entity:
dsl.do.commands_put.with.bodyParams.scheduleRepeatType. - Source:
resource.dsl.do.commands_put.with.bodyParams.scheduleRepeatType - Usage: workflow_delete
entity.data.dsl.do.commands_put.with.bodyParams.scheduleYear
- Description: JumpCloud extension data on the managed entity:
dsl.do.commands_put.with.bodyParams.scheduleYear. - Source:
resource.dsl.do.commands_put.with.bodyParams.scheduleYear - Usage: workflow_delete
entity.data.dsl.do.commands_put.with.bodyParams.shell
- Description: JumpCloud extension data on the managed entity:
dsl.do.commands_put.with.bodyParams.shell. - Source:
resource.dsl.do.commands_put.with.bodyParams.shell - Usage: workflow_delete
entity.data.dsl.do.commands_put.with.bodyParams.sudo
- Description: JumpCloud extension data on the managed entity:
dsl.do.commands_put.with.bodyParams.sudo. - Source:
resource.dsl.do.commands_put.with.bodyParams.sudo - Usage: workflow_delete
entity.data.dsl.do.commands_put.with.bodyParams.systems
- Description: JumpCloud extension data on the managed entity:
dsl.do.commands_put.with.bodyParams.systems. - Source:
resource.dsl.do.commands_put.with.bodyParams.systems - Usage: workflow_delete
entity.data.dsl.do.commands_put.with.bodyParams.template
- Description: JumpCloud extension data on the managed entity:
dsl.do.commands_put.with.bodyParams.template. - Source:
resource.dsl.do.commands_put.with.bodyParams.template - Usage: workflow_delete
entity.data.dsl.do.commands_put.with.bodyParams.timeToLiveSeconds
- Description: JumpCloud extension data on the managed entity:
dsl.do.commands_put.with.bodyParams.timeToLiveSeconds. - Source:
resource.dsl.do.commands_put.with.bodyParams.timeToLiveSeconds - Usage: workflow_delete
entity.data.dsl.do.commands_put.with.bodyParams.timeout
- Description: JumpCloud extension data on the managed entity:
dsl.do.commands_put.with.bodyParams.timeout. - Source:
resource.dsl.do.commands_put.with.bodyParams.timeout - Usage: workflow_delete
entity.data.dsl.do.commands_put.with.bodyParams.trigger
- Description: JumpCloud extension data on the managed entity:
dsl.do.commands_put.with.bodyParams.trigger. - Source:
resource.dsl.do.commands_put.with.bodyParams.trigger - Usage: workflow_delete
entity.data.dsl.do.commands_put.with.bodyParams.user
- Description: JumpCloud extension data on the managed entity:
dsl.do.commands_put.with.bodyParams.user. - Source:
resource.dsl.do.commands_put.with.bodyParams.user - Usage: workflow_delete
entity.data.dsl.do.commands_put.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.commands_put.with.operationId. - Source:
resource.dsl.do.commands_put.with.operationId - Usage: workflow_delete
entity.data.dsl.do.commands_put.with.pathParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.commands_put.with.pathParams.id. - Source:
resource.dsl.do.commands_put.with.pathParams.id - Usage: workflow_delete
entity.data.dsl.do.commands_put.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.commands_put.with.version. - Source:
resource.dsl.do.commands_put.with.version - Usage: workflow_delete
entity.data.dsl.do.createAccessRequestWorkflow.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.createAccessRequestWorkflow.call. - Source:
resource.dsl.do.createAccessRequestWorkflow.call - Usage: workflow_create
entity.data.dsl.do.createAccessRequestWorkflow.if
- Description: JumpCloud extension data on the managed entity:
dsl.do.createAccessRequestWorkflow.if. - Source:
resource.dsl.do.createAccessRequestWorkflow.if - Usage: workflow_create
entity.data.dsl.do.createAccessRequestWorkflow.with.bodyParams.approvalType
- Description: JumpCloud extension data on the managed entity:
dsl.do.createAccessRequestWorkflow.with.bodyParams.approvalType. - Source:
resource.dsl.do.createAccessRequestWorkflow.with.bodyParams.approvalType - Usage: workflow_create
entity.data.dsl.do.createAccessRequestWorkflow.with.bodyParams.approverRequirement
- Description: JumpCloud extension data on the managed entity:
dsl.do.createAccessRequestWorkflow.with.bodyParams.approverRequirement. - Source:
resource.dsl.do.createAccessRequestWorkflow.with.bodyParams.approverRequirement - Usage: workflow_create
entity.data.dsl.do.createAccessRequestWorkflow.with.bodyParams.approverResources
- Description: JumpCloud extension data on the managed entity:
dsl.do.createAccessRequestWorkflow.with.bodyParams.approverResources. - Source:
resource.dsl.do.createAccessRequestWorkflow.with.bodyParams.approverResources - Usage: workflow_create
entity.data.dsl.do.createAccessRequestWorkflow.with.bodyParams.description
- Description: JumpCloud extension data on the managed entity:
dsl.do.createAccessRequestWorkflow.with.bodyParams.description. - Source:
resource.dsl.do.createAccessRequestWorkflow.with.bodyParams.description - Usage: workflow_create
entity.data.dsl.do.createAccessRequestWorkflow.with.bodyParams.name
- Description: JumpCloud extension data on the managed entity:
dsl.do.createAccessRequestWorkflow.with.bodyParams.name. - Source:
resource.dsl.do.createAccessRequestWorkflow.with.bodyParams.name - Usage: workflow_create
entity.data.dsl.do.createAccessRequestWorkflow.with.bodyParams.nonAdminApproval
- Description: JumpCloud extension data on the managed entity:
dsl.do.createAccessRequestWorkflow.with.bodyParams.nonAdminApproval. - Source:
resource.dsl.do.createAccessRequestWorkflow.with.bodyParams.nonAdminApproval - Usage: workflow_create
entity.data.dsl.do.createAccessRequestWorkflow.with.bodyParams.resourceId
- Description: JumpCloud extension data on the managed entity:
dsl.do.createAccessRequestWorkflow.with.bodyParams.resourceId. - Source:
resource.dsl.do.createAccessRequestWorkflow.with.bodyParams.resourceId - Usage: workflow_create
entity.data.dsl.do.createAccessRequestWorkflow.with.bodyParams.resourceType
- Description: JumpCloud extension data on the managed entity:
dsl.do.createAccessRequestWorkflow.with.bodyParams.resourceType. - Source:
resource.dsl.do.createAccessRequestWorkflow.with.bodyParams.resourceType - Usage: workflow_create
entity.data.dsl.do.createAccessRequestWorkflow.with.bodyParams.status
- Description: JumpCloud extension data on the managed entity:
dsl.do.createAccessRequestWorkflow.with.bodyParams.status. - Source:
resource.dsl.do.createAccessRequestWorkflow.with.bodyParams.status - Usage: workflow_create
entity.data.dsl.do.createAccessRequestWorkflow.with.bodyParams.timeBasedAccess
- Description: JumpCloud extension data on the managed entity:
dsl.do.createAccessRequestWorkflow.with.bodyParams.timeBasedAccess. - Source:
resource.dsl.do.createAccessRequestWorkflow.with.bodyParams.timeBasedAccess - Usage: workflow_create
entity.data.dsl.do.createAccessRequestWorkflow.with.bodyParams.ttlConfig
- Description: JumpCloud extension data on the managed entity:
dsl.do.createAccessRequestWorkflow.with.bodyParams.ttlConfig. - Source:
resource.dsl.do.createAccessRequestWorkflow.with.bodyParams.ttlConfig - Usage: workflow_create
entity.data.dsl.do.createAccessRequestWorkflow.with.bodyParams.visibleTo
- Description: JumpCloud extension data on the managed entity:
dsl.do.createAccessRequestWorkflow.with.bodyParams.visibleTo. - Source:
resource.dsl.do.createAccessRequestWorkflow.with.bodyParams.visibleTo - Usage: workflow_create
entity.data.dsl.do.createAccessRequestWorkflow.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.createAccessRequestWorkflow.with.operationId. - Source:
resource.dsl.do.createAccessRequestWorkflow.with.operationId - Usage: workflow_create
entity.data.dsl.do.createAccessRequestWorkflow.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.createAccessRequestWorkflow.with.version. - Source:
resource.dsl.do.createAccessRequestWorkflow.with.version - Usage: workflow_create
entity.data.dsl.do.createGroup.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.createGroup.call. - Source:
resource.dsl.do.createGroup.call - Usage: workflow_create, workflow_delete
entity.data.dsl.do.createGroup.with.bodyParams.name
- Description: JumpCloud extension data on the managed entity:
dsl.do.createGroup.with.bodyParams.name. - Source:
resource.dsl.do.createGroup.with.bodyParams.name - Usage: workflow_create
entity.data.dsl.do.createGroup.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.createGroup.with.operationId. - Source:
resource.dsl.do.createGroup.with.operationId - Usage: workflow_create, workflow_delete
entity.data.dsl.do.createGroup.with.pathParams.objectId
- Description: JumpCloud extension data on the managed entity:
dsl.do.createGroup.with.pathParams.objectId. - Source:
resource.dsl.do.createGroup.with.pathParams.objectId - Usage: workflow_delete
entity.data.dsl.do.createGroup.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.createGroup.with.version. - Source:
resource.dsl.do.createGroup.with.version - Usage: workflow_create, workflow_delete
entity.data.dsl.do.deviceLockBranch.if
- Description: JumpCloud extension data on the managed entity:
dsl.do.deviceLockBranch.if. - Source:
resource.dsl.do.deviceLockBranch.if - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.deviceLockBranch.switch.default.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.deviceLockBranch.switch.default.then. - Source:
resource.dsl.do.deviceLockBranch.switch.default.then - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.deviceLockBranch.switch.isMac.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.deviceLockBranch.switch.isMac.then. - Source:
resource.dsl.do.deviceLockBranch.switch.isMac.then - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.deviceLockBranch.switch.isMac.when
- Description: JumpCloud extension data on the managed entity:
dsl.do.deviceLockBranch.switch.isMac.when. - Source:
resource.dsl.do.deviceLockBranch.switch.isMac.when - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.deviceLockBranch.switch.otherDevice.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.deviceLockBranch.switch.otherDevice.then. - Source:
resource.dsl.do.deviceLockBranch.switch.otherDevice.then - Usage: workflow_create
entity.data.dsl.do.deviceLockBranch.switch.otherDevice.when
- Description: JumpCloud extension data on the managed entity:
dsl.do.deviceLockBranch.switch.otherDevice.when. - Source:
resource.dsl.do.deviceLockBranch.switch.otherDevice.when - Usage: workflow_create
entity.data.dsl.do.duo_accountPost.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.duo_accountPost.call. - Source:
resource.dsl.do.duo_accountPost.call - Usage: workflow_delete
entity.data.dsl.do.duo_accountPost.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.duo_accountPost.with.operationId. - Source:
resource.dsl.do.duo_accountPost.with.operationId - Usage: workflow_delete
entity.data.dsl.do.duo_accountPost.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.duo_accountPost.with.version. - Source:
resource.dsl.do.duo_accountPost.with.version - Usage: workflow_delete
entity.data.dsl.do.emailITOps.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.emailITOps.call. - Source:
resource.dsl.do.emailITOps.call - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.emailITOps.with.message.body
- Description: JumpCloud extension data on the managed entity:
dsl.do.emailITOps.with.message.body. - Source:
resource.dsl.do.emailITOps.with.message.body - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.emailITOps.with.message.subject
- Description: JumpCloud extension data on the managed entity:
dsl.do.emailITOps.with.message.subject. - Source:
resource.dsl.do.emailITOps.with.message.subject - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.emailITOps.with.recipients.to_addresses
- Description: JumpCloud extension data on the managed entity:
dsl.do.emailITOps.with.recipients.to_addresses. - Source:
resource.dsl.do.emailITOps.with.recipients.to_addresses - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.emailManager.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.emailManager.call. - Source:
resource.dsl.do.emailManager.call - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.emailManager.if
- Description: JumpCloud extension data on the managed entity:
dsl.do.emailManager.if. - Source:
resource.dsl.do.emailManager.if - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.emailManager.with.message.body
- Description: JumpCloud extension data on the managed entity:
dsl.do.emailManager.with.message.body. - Source:
resource.dsl.do.emailManager.with.message.body - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.emailManager.with.message.subject
- Description: JumpCloud extension data on the managed entity:
dsl.do.emailManager.with.message.subject. - Source:
resource.dsl.do.emailManager.with.message.subject - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.emailManager.with.recipients.to_addresses
- Description: JumpCloud extension data on the managed entity:
dsl.do.emailManager.with.recipients.to_addresses. - Source:
resource.dsl.do.emailManager.with.recipients.to_addresses - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.eraseDevice.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.eraseDevice.call. - Source:
resource.dsl.do.eraseDevice.call - Usage: workflow_create, workflow_delete
entity.data.dsl.do.eraseDevice.metadata.displayLabels.device
- Description: JumpCloud extension data on the managed entity:
dsl.do.eraseDevice.metadata.displayLabels.device. - Source:
resource.dsl.do.eraseDevice.metadata.displayLabels.device - Usage: workflow_create, workflow_delete
entity.data.dsl.do.eraseDevice.metadata.inputModes.device
- Description: JumpCloud extension data on the managed entity:
dsl.do.eraseDevice.metadata.inputModes.device. - Source:
resource.dsl.do.eraseDevice.metadata.inputModes.device - Usage: workflow_create, workflow_delete
entity.data.dsl.do.eraseDevice.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.eraseDevice.with.operationId. - Source:
resource.dsl.do.eraseDevice.with.operationId - Usage: workflow_create, workflow_delete
entity.data.dsl.do.eraseDevice.with.pathParams.system_id
- Description: JumpCloud extension data on the managed entity:
dsl.do.eraseDevice.with.pathParams.system_id. - Source:
resource.dsl.do.eraseDevice.with.pathParams.system_id - Usage: workflow_create, workflow_delete
entity.data.dsl.do.eraseDevice.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.eraseDevice.with.version. - Source:
resource.dsl.do.eraseDevice.with.version - Usage: workflow_create, workflow_delete
entity.data.dsl.do.eraseMacDevice.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.eraseMacDevice.call. - Source:
resource.dsl.do.eraseMacDevice.call - Usage: workflow_create, workflow_delete
entity.data.dsl.do.eraseMacDevice.if
- Description: JumpCloud extension data on the managed entity:
dsl.do.eraseMacDevice.if. - Source:
resource.dsl.do.eraseMacDevice.if - Usage: workflow_create, workflow_delete
entity.data.dsl.do.eraseMacDevice.metadata.displayLabels.device
- Description: JumpCloud extension data on the managed entity:
dsl.do.eraseMacDevice.metadata.displayLabels.device. - Source:
resource.dsl.do.eraseMacDevice.metadata.displayLabels.device - Usage: workflow_create, workflow_delete
entity.data.dsl.do.eraseMacDevice.metadata.displayLabels.mdmId
- Description: JumpCloud extension data on the managed entity:
dsl.do.eraseMacDevice.metadata.displayLabels.mdmId. - Source:
resource.dsl.do.eraseMacDevice.metadata.displayLabels.mdmId - Usage: workflow_delete
entity.data.dsl.do.eraseMacDevice.metadata.displayLabels.pin
- Description: JumpCloud extension data on the managed entity:
dsl.do.eraseMacDevice.metadata.displayLabels.pin. - Source:
resource.dsl.do.eraseMacDevice.metadata.displayLabels.pin - Usage: workflow_create, workflow_delete
entity.data.dsl.do.eraseMacDevice.metadata.inputModes.device
- Description: JumpCloud extension data on the managed entity:
dsl.do.eraseMacDevice.metadata.inputModes.device. - Source:
resource.dsl.do.eraseMacDevice.metadata.inputModes.device - Usage: workflow_create, workflow_delete
entity.data.dsl.do.eraseMacDevice.metadata.inputModes.mdmId
- Description: JumpCloud extension data on the managed entity:
dsl.do.eraseMacDevice.metadata.inputModes.mdmId. - Source:
resource.dsl.do.eraseMacDevice.metadata.inputModes.mdmId - Usage: workflow_delete
entity.data.dsl.do.eraseMacDevice.metadata.inputModes.pin
- Description: JumpCloud extension data on the managed entity:
dsl.do.eraseMacDevice.metadata.inputModes.pin. - Source:
resource.dsl.do.eraseMacDevice.metadata.inputModes.pin - Usage: workflow_create, workflow_delete
entity.data.dsl.do.eraseMacDevice.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.eraseMacDevice.then. - Source:
resource.dsl.do.eraseMacDevice.then - Usage: workflow_create
entity.data.dsl.do.eraseMacDevice.with.bodyParams.pin
- Description: JumpCloud extension data on the managed entity:
dsl.do.eraseMacDevice.with.bodyParams.pin. - Source:
resource.dsl.do.eraseMacDevice.with.bodyParams.pin - Usage: workflow_create, workflow_delete
entity.data.dsl.do.eraseMacDevice.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.eraseMacDevice.with.operationId. - Source:
resource.dsl.do.eraseMacDevice.with.operationId - Usage: workflow_create, workflow_delete
entity.data.dsl.do.eraseMacDevice.with.pathParams.apple_mdm_id
- Description: JumpCloud extension data on the managed entity:
dsl.do.eraseMacDevice.with.pathParams.apple_mdm_id. - Source:
resource.dsl.do.eraseMacDevice.with.pathParams.apple_mdm_id - Usage: workflow_create, workflow_delete
entity.data.dsl.do.eraseMacDevice.with.pathParams.device_id
- Description: JumpCloud extension data on the managed entity:
dsl.do.eraseMacDevice.with.pathParams.device_id. - Source:
resource.dsl.do.eraseMacDevice.with.pathParams.device_id - Usage: workflow_create, workflow_delete
entity.data.dsl.do.eraseMacDevice.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.eraseMacDevice.with.version. - Source:
resource.dsl.do.eraseMacDevice.with.version - Usage: workflow_create, workflow_delete
entity.data.dsl.do.eraseOtherDevice.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.eraseOtherDevice.call. - Source:
resource.dsl.do.eraseOtherDevice.call - Usage: workflow_create, workflow_delete
entity.data.dsl.do.eraseOtherDevice.if
- Description: JumpCloud extension data on the managed entity:
dsl.do.eraseOtherDevice.if. - Source:
resource.dsl.do.eraseOtherDevice.if - Usage: workflow_create, workflow_delete
entity.data.dsl.do.eraseOtherDevice.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.eraseOtherDevice.then. - Source:
resource.dsl.do.eraseOtherDevice.then - Usage: workflow_create, workflow_delete
entity.data.dsl.do.eraseOtherDevice.with.bodyParams
- Description: JumpCloud extension data on the managed entity:
dsl.do.eraseOtherDevice.with.bodyParams. - Source:
resource.dsl.do.eraseOtherDevice.with.bodyParams - Usage: workflow_create, workflow_delete
entity.data.dsl.do.eraseOtherDevice.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.eraseOtherDevice.with.operationId. - Source:
resource.dsl.do.eraseOtherDevice.with.operationId - Usage: workflow_create, workflow_delete
entity.data.dsl.do.eraseOtherDevice.with.pathParams.system_id
- Description: JumpCloud extension data on the managed entity:
dsl.do.eraseOtherDevice.with.pathParams.system_id. - Source:
resource.dsl.do.eraseOtherDevice.with.pathParams.system_id - Usage: workflow_create, workflow_delete
entity.data.dsl.do.eraseOtherDevice.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.eraseOtherDevice.with.version. - Source:
resource.dsl.do.eraseOtherDevice.with.version - Usage: workflow_create, workflow_delete
entity.data.dsl.do.evaluateGates.switch.default.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.evaluateGates.switch.default.then. - Source:
resource.dsl.do.evaluateGates.switch.default.then - Usage: workflow_create, workflow_delete
entity.data.dsl.do.evaluateGates.switch.shouldStrip.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.evaluateGates.switch.shouldStrip.then. - Source:
resource.dsl.do.evaluateGates.switch.shouldStrip.then - Usage: workflow_create, workflow_delete
entity.data.dsl.do.evaluateGates.switch.shouldStrip.when
- Description: JumpCloud extension data on the managed entity:
dsl.do.evaluateGates.switch.shouldStrip.when. - Source:
resource.dsl.do.evaluateGates.switch.shouldStrip.when - Usage: workflow_create, workflow_delete
entity.data.dsl.do.externalAppConnectorAction.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.externalAppConnectorAction.call. - Source:
resource.dsl.do.externalAppConnectorAction.call - Usage: workflow_create
entity.data.dsl.do.externalAppConnectorAction.with.body.userId
- Description: JumpCloud extension data on the managed entity:
dsl.do.externalAppConnectorAction.with.body.userId. - Source:
resource.dsl.do.externalAppConnectorAction.with.body.userId - Usage: workflow_create
entity.data.dsl.do.externalAppConnectorAction.with.endpointPath
- Description: JumpCloud extension data on the managed entity:
dsl.do.externalAppConnectorAction.with.endpointPath. - Source:
resource.dsl.do.externalAppConnectorAction.with.endpointPath - Usage: workflow_create
entity.data.dsl.do.externalAppConnectorAction.with.headers.Custom-Header
- Description: JumpCloud extension data on the managed entity:
dsl.do.externalAppConnectorAction.with.headers.Custom-Header. - Source:
resource.dsl.do.externalAppConnectorAction.with.headers.Custom-Header - Usage: workflow_create
entity.data.dsl.do.externalAppConnectorAction.with.httpMethod
- Description: JumpCloud extension data on the managed entity:
dsl.do.externalAppConnectorAction.with.httpMethod. - Source:
resource.dsl.do.externalAppConnectorAction.with.httpMethod - Usage: workflow_create
entity.data.dsl.do.externalAppConnectorAction.with.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.externalAppConnectorAction.with.id. - Source:
resource.dsl.do.externalAppConnectorAction.with.id - Usage: workflow_create
entity.data.dsl.do.findScheduledActivations.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.findScheduledActivations.call. - Source:
resource.dsl.do.findScheduledActivations.call - Usage: workflow_create
entity.data.dsl.do.findScheduledActivations.with.extract
- Description: JumpCloud extension data on the managed entity:
dsl.do.findScheduledActivations.with.extract. - Source:
resource.dsl.do.findScheduledActivations.with.extract - Usage: workflow_create
entity.data.dsl.do.findScheduledActivations.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.findScheduledActivations.with.operationId. - Source:
resource.dsl.do.findScheduledActivations.with.operationId - Usage: workflow_create
entity.data.dsl.do.findScheduledActivations.with.pagination.until
- Description: JumpCloud extension data on the managed entity:
dsl.do.findScheduledActivations.with.pagination.until. - Source:
resource.dsl.do.findScheduledActivations.with.pagination.until - Usage: workflow_create
entity.data.dsl.do.findScheduledActivations.with.pagination.update.in
- Description: JumpCloud extension data on the managed entity:
dsl.do.findScheduledActivations.with.pagination.update.in. - Source:
resource.dsl.do.findScheduledActivations.with.pagination.update.in - Usage: workflow_create
entity.data.dsl.do.findScheduledActivations.with.pagination.update.key
- Description: JumpCloud extension data on the managed entity:
dsl.do.findScheduledActivations.with.pagination.update.key. - Source:
resource.dsl.do.findScheduledActivations.with.pagination.update.key - Usage: workflow_create
entity.data.dsl.do.findScheduledActivations.with.pagination.update.value
- Description: JumpCloud extension data on the managed entity:
dsl.do.findScheduledActivations.with.pagination.update.value. - Source:
resource.dsl.do.findScheduledActivations.with.pagination.update.value - Usage: workflow_create
entity.data.dsl.do.findScheduledActivations.with.queryParams.filter
- Description: JumpCloud extension data on the managed entity:
dsl.do.findScheduledActivations.with.queryParams.filter. - Source:
resource.dsl.do.findScheduledActivations.with.queryParams.filter - Usage: workflow_create
entity.data.dsl.do.findScheduledActivations.with.queryParams.limit
- Description: JumpCloud extension data on the managed entity:
dsl.do.findScheduledActivations.with.queryParams.limit. - Source:
resource.dsl.do.findScheduledActivations.with.queryParams.limit - Usage: workflow_create
entity.data.dsl.do.findScheduledActivations.with.queryParams.skip
- Description: JumpCloud extension data on the managed entity:
dsl.do.findScheduledActivations.with.queryParams.skip. - Source:
resource.dsl.do.findScheduledActivations.with.queryParams.skip - Usage: workflow_create
entity.data.dsl.do.findScheduledActivations.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.findScheduledActivations.with.version. - Source:
resource.dsl.do.findScheduledActivations.with.version - Usage: workflow_create
entity.data.dsl.do.getAllUsersGroup.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.getAllUsersGroup.call. - Source:
resource.dsl.do.getAllUsersGroup.call - Usage: workflow_create
entity.data.dsl.do.getAllUsersGroup.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.getAllUsersGroup.with.operationId. - Source:
resource.dsl.do.getAllUsersGroup.with.operationId - Usage: workflow_create
entity.data.dsl.do.getAllUsersGroup.with.queryParams.fields
- Description: JumpCloud extension data on the managed entity:
dsl.do.getAllUsersGroup.with.queryParams.fields. - Source:
resource.dsl.do.getAllUsersGroup.with.queryParams.fields - Usage: workflow_create
entity.data.dsl.do.getAllUsersGroup.with.queryParams.filter
- Description: JumpCloud extension data on the managed entity:
dsl.do.getAllUsersGroup.with.queryParams.filter. - Source:
resource.dsl.do.getAllUsersGroup.with.queryParams.filter - Usage: workflow_create
entity.data.dsl.do.getAllUsersGroup.with.queryParams.limit
- Description: JumpCloud extension data on the managed entity:
dsl.do.getAllUsersGroup.with.queryParams.limit. - Source:
resource.dsl.do.getAllUsersGroup.with.queryParams.limit - Usage: workflow_create
entity.data.dsl.do.getAllUsersGroup.with.queryParams.skip
- Description: JumpCloud extension data on the managed entity:
dsl.do.getAllUsersGroup.with.queryParams.skip. - Source:
resource.dsl.do.getAllUsersGroup.with.queryParams.skip - Usage: workflow_create
entity.data.dsl.do.getAllUsersGroup.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.getAllUsersGroup.with.version. - Source:
resource.dsl.do.getAllUsersGroup.with.version - Usage: workflow_create
entity.data.dsl.do.getAppAssociations.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.getAppAssociations.call. - Source:
resource.dsl.do.getAppAssociations.call - Usage: workflow_create
entity.data.dsl.do.getAppAssociations.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.getAppAssociations.with.operationId. - Source:
resource.dsl.do.getAppAssociations.with.operationId - Usage: workflow_create
entity.data.dsl.do.getAppAssociations.with.pathParams.application_id
- Description: JumpCloud extension data on the managed entity:
dsl.do.getAppAssociations.with.pathParams.application_id. - Source:
resource.dsl.do.getAppAssociations.with.pathParams.application_id - Usage: workflow_create
entity.data.dsl.do.getAppAssociations.with.queryParams.limit
- Description: JumpCloud extension data on the managed entity:
dsl.do.getAppAssociations.with.queryParams.limit. - Source:
resource.dsl.do.getAppAssociations.with.queryParams.limit - Usage: workflow_create
entity.data.dsl.do.getAppAssociations.with.queryParams.skip
- Description: JumpCloud extension data on the managed entity:
dsl.do.getAppAssociations.with.queryParams.skip. - Source:
resource.dsl.do.getAppAssociations.with.queryParams.skip - Usage: workflow_create
entity.data.dsl.do.getAppAssociations.with.queryParams.targets
- Description: JumpCloud extension data on the managed entity:
dsl.do.getAppAssociations.with.queryParams.targets. - Source:
resource.dsl.do.getAppAssociations.with.queryParams.targets - Usage: workflow_create
entity.data.dsl.do.getAppAssociations.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.getAppAssociations.with.version. - Source:
resource.dsl.do.getAppAssociations.with.version - Usage: workflow_create
entity.data.dsl.do.getDeviceAsset.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.getDeviceAsset.call. - Source:
resource.dsl.do.getDeviceAsset.call - Usage: workflow_create, workflow_delete
entity.data.dsl.do.getDeviceAsset.if
- Description: JumpCloud extension data on the managed entity:
dsl.do.getDeviceAsset.if. - Source:
resource.dsl.do.getDeviceAsset.if - Usage: workflow_create, workflow_delete
entity.data.dsl.do.getDeviceAsset.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.getDeviceAsset.then. - Source:
resource.dsl.do.getDeviceAsset.then - Usage: workflow_create, workflow_delete
entity.data.dsl.do.getDeviceAsset.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.getDeviceAsset.with.operationId. - Source:
resource.dsl.do.getDeviceAsset.with.operationId - Usage: workflow_create, workflow_delete
entity.data.dsl.do.getDeviceAsset.with.pathParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.getDeviceAsset.with.pathParams.id. - Source:
resource.dsl.do.getDeviceAsset.with.pathParams.id - Usage: workflow_create, workflow_delete
entity.data.dsl.do.getDeviceAsset.with.pathParams.jcSystemId
- Description: JumpCloud extension data on the managed entity:
dsl.do.getDeviceAsset.with.pathParams.jcSystemId. - Source:
resource.dsl.do.getDeviceAsset.with.pathParams.jcSystemId - Usage: workflow_create
entity.data.dsl.do.getDeviceAsset.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.getDeviceAsset.with.version. - Source:
resource.dsl.do.getDeviceAsset.with.version - Usage: workflow_create, workflow_delete
entity.data.dsl.do.getDeviceAssetByJCSystemID.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.getDeviceAssetByJCSystemID.call. - Source:
resource.dsl.do.getDeviceAssetByJCSystemID.call - Usage: workflow_create, workflow_delete
entity.data.dsl.do.getDeviceAssetByJCSystemID.if
- Description: JumpCloud extension data on the managed entity:
dsl.do.getDeviceAssetByJCSystemID.if. - Source:
resource.dsl.do.getDeviceAssetByJCSystemID.if - Usage: workflow_create, workflow_delete
entity.data.dsl.do.getDeviceAssetByJCSystemID.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.getDeviceAssetByJCSystemID.then. - Source:
resource.dsl.do.getDeviceAssetByJCSystemID.then - Usage: workflow_create, workflow_delete
entity.data.dsl.do.getDeviceAssetByJCSystemID.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.getDeviceAssetByJCSystemID.with.operationId. - Source:
resource.dsl.do.getDeviceAssetByJCSystemID.with.operationId - Usage: workflow_create, workflow_delete
entity.data.dsl.do.getDeviceAssetByJCSystemID.with.pathParams.jcSystemId
- Description: JumpCloud extension data on the managed entity:
dsl.do.getDeviceAssetByJCSystemID.with.pathParams.jcSystemId. - Source:
resource.dsl.do.getDeviceAssetByJCSystemID.with.pathParams.jcSystemId - Usage: workflow_create, workflow_delete
entity.data.dsl.do.getDeviceAssetByJCSystemID.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.getDeviceAssetByJCSystemID.with.version. - Source:
resource.dsl.do.getDeviceAssetByJCSystemID.with.version - Usage: workflow_create, workflow_delete
entity.data.dsl.do.getDeviceAssetFull.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.getDeviceAssetFull.call. - Source:
resource.dsl.do.getDeviceAssetFull.call - Usage: workflow_create
entity.data.dsl.do.getDeviceAssetFull.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.getDeviceAssetFull.with.operationId. - Source:
resource.dsl.do.getDeviceAssetFull.with.operationId - Usage: workflow_create
entity.data.dsl.do.getDeviceAssetFull.with.pathParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.getDeviceAssetFull.with.pathParams.id. - Source:
resource.dsl.do.getDeviceAssetFull.with.pathParams.id - Usage: workflow_create
entity.data.dsl.do.getDeviceAssetFull.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.getDeviceAssetFull.with.version. - Source:
resource.dsl.do.getDeviceAssetFull.with.version - Usage: workflow_create
entity.data.dsl.do.getManagerDetails.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.getManagerDetails.call. - Source:
resource.dsl.do.getManagerDetails.call - Usage: workflow_create, workflow_delete
entity.data.dsl.do.getManagerDetails.if
- Description: JumpCloud extension data on the managed entity:
dsl.do.getManagerDetails.if. - Source:
resource.dsl.do.getManagerDetails.if - Usage: workflow_create, workflow_delete
entity.data.dsl.do.getManagerDetails.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.getManagerDetails.with.operationId. - Source:
resource.dsl.do.getManagerDetails.with.operationId - Usage: workflow_create, workflow_delete
entity.data.dsl.do.getManagerDetails.with.pathParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.getManagerDetails.with.pathParams.id. - Source:
resource.dsl.do.getManagerDetails.with.pathParams.id - Usage: workflow_create, workflow_delete
entity.data.dsl.do.getManagerDetails.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.getManagerDetails.with.version. - Source:
resource.dsl.do.getManagerDetails.with.version - Usage: workflow_create, workflow_delete
entity.data.dsl.do.getPolicyResults.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.getPolicyResults.call. - Source:
resource.dsl.do.getPolicyResults.call - Usage: workflow_create
entity.data.dsl.do.getPolicyResults.with.extract
- Description: JumpCloud extension data on the managed entity:
dsl.do.getPolicyResults.with.extract. - Source:
resource.dsl.do.getPolicyResults.with.extract - Usage: workflow_create
entity.data.dsl.do.getPolicyResults.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.getPolicyResults.with.operationId. - Source:
resource.dsl.do.getPolicyResults.with.operationId - Usage: workflow_create
entity.data.dsl.do.getPolicyResults.with.pagination.until
- Description: JumpCloud extension data on the managed entity:
dsl.do.getPolicyResults.with.pagination.until. - Source:
resource.dsl.do.getPolicyResults.with.pagination.until - Usage: workflow_create
entity.data.dsl.do.getPolicyResults.with.pagination.update.in
- Description: JumpCloud extension data on the managed entity:
dsl.do.getPolicyResults.with.pagination.update.in. - Source:
resource.dsl.do.getPolicyResults.with.pagination.update.in - Usage: workflow_create
entity.data.dsl.do.getPolicyResults.with.pagination.update.key
- Description: JumpCloud extension data on the managed entity:
dsl.do.getPolicyResults.with.pagination.update.key. - Source:
resource.dsl.do.getPolicyResults.with.pagination.update.key - Usage: workflow_create
entity.data.dsl.do.getPolicyResults.with.pagination.update.value
- Description: JumpCloud extension data on the managed entity:
dsl.do.getPolicyResults.with.pagination.update.value. - Source:
resource.dsl.do.getPolicyResults.with.pagination.update.value - Usage: workflow_create
entity.data.dsl.do.getPolicyResults.with.pathParams.policy_id
- Description: JumpCloud extension data on the managed entity:
dsl.do.getPolicyResults.with.pathParams.policy_id. - Source:
resource.dsl.do.getPolicyResults.with.pathParams.policy_id - Usage: workflow_create
entity.data.dsl.do.getPolicyResults.with.queryParams.filter
- Description: JumpCloud extension data on the managed entity:
dsl.do.getPolicyResults.with.queryParams.filter. - Source:
resource.dsl.do.getPolicyResults.with.queryParams.filter - Usage: workflow_create
entity.data.dsl.do.getPolicyResults.with.queryParams.limit
- Description: JumpCloud extension data on the managed entity:
dsl.do.getPolicyResults.with.queryParams.limit. - Source:
resource.dsl.do.getPolicyResults.with.queryParams.limit - Usage: workflow_create
entity.data.dsl.do.getPolicyResults.with.queryParams.skip
- Description: JumpCloud extension data on the managed entity:
dsl.do.getPolicyResults.with.queryParams.skip. - Source:
resource.dsl.do.getPolicyResults.with.queryParams.skip - Usage: workflow_create
entity.data.dsl.do.getPolicyResults.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.getPolicyResults.with.version. - Source:
resource.dsl.do.getPolicyResults.with.version - Usage: workflow_create
entity.data.dsl.do.getPrimaryDevice.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.getPrimaryDevice.call. - Source:
resource.dsl.do.getPrimaryDevice.call - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.getPrimaryDevice.if
- Description: JumpCloud extension data on the managed entity:
dsl.do.getPrimaryDevice.if. - Source:
resource.dsl.do.getPrimaryDevice.if - Usage: workflow_create, workflow_delete
entity.data.dsl.do.getPrimaryDevice.metadata.displayLabels.filter
- Description: JumpCloud extension data on the managed entity:
dsl.do.getPrimaryDevice.metadata.displayLabels.filter. - Source:
resource.dsl.do.getPrimaryDevice.metadata.displayLabels.filter - Usage: workflow_create, workflow_delete
entity.data.dsl.do.getPrimaryDevice.metadata.displayLabels.limit
- Description: JumpCloud extension data on the managed entity:
dsl.do.getPrimaryDevice.metadata.displayLabels.limit. - Source:
resource.dsl.do.getPrimaryDevice.metadata.displayLabels.limit - Usage: workflow_create
entity.data.dsl.do.getPrimaryDevice.metadata.displayLabels.skip
- Description: JumpCloud extension data on the managed entity:
dsl.do.getPrimaryDevice.metadata.displayLabels.skip. - Source:
resource.dsl.do.getPrimaryDevice.metadata.displayLabels.skip - Usage: workflow_create
entity.data.dsl.do.getPrimaryDevice.metadata.inputModes.fields
- Description: JumpCloud extension data on the managed entity:
dsl.do.getPrimaryDevice.metadata.inputModes.fields. - Source:
resource.dsl.do.getPrimaryDevice.metadata.inputModes.fields - Usage: workflow_create, workflow_delete
entity.data.dsl.do.getPrimaryDevice.metadata.inputModes.filter
- Description: JumpCloud extension data on the managed entity:
dsl.do.getPrimaryDevice.metadata.inputModes.filter. - Source:
resource.dsl.do.getPrimaryDevice.metadata.inputModes.filter - Usage: workflow_create, workflow_delete
entity.data.dsl.do.getPrimaryDevice.metadata.inputModes.limit
- Description: JumpCloud extension data on the managed entity:
dsl.do.getPrimaryDevice.metadata.inputModes.limit. - Source:
resource.dsl.do.getPrimaryDevice.metadata.inputModes.limit - Usage: workflow_create, workflow_delete
entity.data.dsl.do.getPrimaryDevice.metadata.inputModes.skip
- Description: JumpCloud extension data on the managed entity:
dsl.do.getPrimaryDevice.metadata.inputModes.skip. - Source:
resource.dsl.do.getPrimaryDevice.metadata.inputModes.skip - Usage: workflow_create, workflow_delete
entity.data.dsl.do.getPrimaryDevice.with.bodyParams.fields
- Description: JumpCloud extension data on the managed entity:
dsl.do.getPrimaryDevice.with.bodyParams.fields. - Source:
resource.dsl.do.getPrimaryDevice.with.bodyParams.fields - Usage: workflow_create, workflow_delete
entity.data.dsl.do.getPrimaryDevice.with.bodyParams.filter.and.primarySystemUser._id
- Description: JumpCloud extension data on the managed entity:
dsl.do.getPrimaryDevice.with.bodyParams.filter.and.primarySystemUser._id. - Source:
resource.dsl.do.getPrimaryDevice.with.bodyParams.filter.and.primarySystemUser._id - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.getPrimaryDevice.with.bodyParams.filter.and.primarySystemUser.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.getPrimaryDevice.with.bodyParams.filter.and.primarySystemUser.id. - Source:
resource.dsl.do.getPrimaryDevice.with.bodyParams.filter.and.primarySystemUser.id - Usage: workflow_create, workflow_delete
entity.data.dsl.do.getPrimaryDevice.with.extract
- Description: JumpCloud extension data on the managed entity:
dsl.do.getPrimaryDevice.with.extract. - Source:
resource.dsl.do.getPrimaryDevice.with.extract - Usage: workflow_create
entity.data.dsl.do.getPrimaryDevice.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.getPrimaryDevice.with.operationId. - Source:
resource.dsl.do.getPrimaryDevice.with.operationId - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.getPrimaryDevice.with.pagination.until
- Description: JumpCloud extension data on the managed entity:
dsl.do.getPrimaryDevice.with.pagination.until. - Source:
resource.dsl.do.getPrimaryDevice.with.pagination.until - Usage: workflow_create
entity.data.dsl.do.getPrimaryDevice.with.pagination.update.in
- Description: JumpCloud extension data on the managed entity:
dsl.do.getPrimaryDevice.with.pagination.update.in. - Source:
resource.dsl.do.getPrimaryDevice.with.pagination.update.in - Usage: workflow_create
entity.data.dsl.do.getPrimaryDevice.with.pagination.update.key
- Description: JumpCloud extension data on the managed entity:
dsl.do.getPrimaryDevice.with.pagination.update.key. - Source:
resource.dsl.do.getPrimaryDevice.with.pagination.update.key - Usage: workflow_create
entity.data.dsl.do.getPrimaryDevice.with.pagination.update.value
- Description: JumpCloud extension data on the managed entity:
dsl.do.getPrimaryDevice.with.pagination.update.value. - Source:
resource.dsl.do.getPrimaryDevice.with.pagination.update.value - Usage: workflow_create
entity.data.dsl.do.getPrimaryDevice.with.queryParams.limit
- Description: JumpCloud extension data on the managed entity:
dsl.do.getPrimaryDevice.with.queryParams.limit. - Source:
resource.dsl.do.getPrimaryDevice.with.queryParams.limit - Usage: workflow_create
entity.data.dsl.do.getPrimaryDevice.with.queryParams.skip
- Description: JumpCloud extension data on the managed entity:
dsl.do.getPrimaryDevice.with.queryParams.skip. - Source:
resource.dsl.do.getPrimaryDevice.with.queryParams.skip - Usage: workflow_create
entity.data.dsl.do.getPrimaryDevice.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.getPrimaryDevice.with.version. - Source:
resource.dsl.do.getPrimaryDevice.with.version - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.getPrimaryDeviceForUser.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.getPrimaryDeviceForUser.call. - Source:
resource.dsl.do.getPrimaryDeviceForUser.call - Usage: workflow_create
entity.data.dsl.do.getPrimaryDeviceForUser.metadata.displayLabels.user
- Description: JumpCloud extension data on the managed entity:
dsl.do.getPrimaryDeviceForUser.metadata.displayLabels.user. - Source:
resource.dsl.do.getPrimaryDeviceForUser.metadata.displayLabels.user - Usage: workflow_create
entity.data.dsl.do.getPrimaryDeviceForUser.metadata.inputModes.user
- Description: JumpCloud extension data on the managed entity:
dsl.do.getPrimaryDeviceForUser.metadata.inputModes.user. - Source:
resource.dsl.do.getPrimaryDeviceForUser.metadata.inputModes.user - Usage: workflow_create
entity.data.dsl.do.getPrimaryDeviceForUser.with.bodyParams.fields
- Description: JumpCloud extension data on the managed entity:
dsl.do.getPrimaryDeviceForUser.with.bodyParams.fields. - Source:
resource.dsl.do.getPrimaryDeviceForUser.with.bodyParams.fields - Usage: workflow_create
entity.data.dsl.do.getPrimaryDeviceForUser.with.bodyParams.filter.and.primarySystemUser.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.getPrimaryDeviceForUser.with.bodyParams.filter.and.primarySystemUser.id. - Source:
resource.dsl.do.getPrimaryDeviceForUser.with.bodyParams.filter.and.primarySystemUser.id - Usage: workflow_create
entity.data.dsl.do.getPrimaryDeviceForUser.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.getPrimaryDeviceForUser.with.operationId. - Source:
resource.dsl.do.getPrimaryDeviceForUser.with.operationId - Usage: workflow_create
entity.data.dsl.do.getPrimaryDeviceForUser.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.getPrimaryDeviceForUser.with.version. - Source:
resource.dsl.do.getPrimaryDeviceForUser.with.version - Usage: workflow_create
entity.data.dsl.do.getPrimaryUserFromDevice.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.getPrimaryUserFromDevice.call. - Source:
resource.dsl.do.getPrimaryUserFromDevice.call - Usage: workflow_create
entity.data.dsl.do.getPrimaryUserFromDevice.metadata.displayLabels.device
- Description: JumpCloud extension data on the managed entity:
dsl.do.getPrimaryUserFromDevice.metadata.displayLabels.device. - Source:
resource.dsl.do.getPrimaryUserFromDevice.metadata.displayLabels.device - Usage: workflow_create
entity.data.dsl.do.getPrimaryUserFromDevice.metadata.inputModes.device
- Description: JumpCloud extension data on the managed entity:
dsl.do.getPrimaryUserFromDevice.metadata.inputModes.device. - Source:
resource.dsl.do.getPrimaryUserFromDevice.metadata.inputModes.device - Usage: workflow_create
entity.data.dsl.do.getPrimaryUserFromDevice.metadata.inputModes.fields
- Description: JumpCloud extension data on the managed entity:
dsl.do.getPrimaryUserFromDevice.metadata.inputModes.fields. - Source:
resource.dsl.do.getPrimaryUserFromDevice.metadata.inputModes.fields - Usage: workflow_create
entity.data.dsl.do.getPrimaryUserFromDevice.metadata.inputModes.filter
- Description: JumpCloud extension data on the managed entity:
dsl.do.getPrimaryUserFromDevice.metadata.inputModes.filter. - Source:
resource.dsl.do.getPrimaryUserFromDevice.metadata.inputModes.filter - Usage: workflow_create
entity.data.dsl.do.getPrimaryUserFromDevice.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.getPrimaryUserFromDevice.with.operationId. - Source:
resource.dsl.do.getPrimaryUserFromDevice.with.operationId - Usage: workflow_create
entity.data.dsl.do.getPrimaryUserFromDevice.with.pathParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.getPrimaryUserFromDevice.with.pathParams.id. - Source:
resource.dsl.do.getPrimaryUserFromDevice.with.pathParams.id - Usage: workflow_create
entity.data.dsl.do.getPrimaryUserFromDevice.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.getPrimaryUserFromDevice.with.version. - Source:
resource.dsl.do.getPrimaryUserFromDevice.with.version - Usage: workflow_create
entity.data.dsl.do.getReportTemplate.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.getReportTemplate.call. - Source:
resource.dsl.do.getReportTemplate.call - Usage: workflow_delete
entity.data.dsl.do.getReportTemplate.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.getReportTemplate.with.operationId. - Source:
resource.dsl.do.getReportTemplate.with.operationId - Usage: workflow_delete
entity.data.dsl.do.getReportTemplate.with.pathParams.objectId
- Description: JumpCloud extension data on the managed entity:
dsl.do.getReportTemplate.with.pathParams.objectId. - Source:
resource.dsl.do.getReportTemplate.with.pathParams.objectId - Usage: workflow_delete
entity.data.dsl.do.getReportTemplate.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.getReportTemplate.with.version. - Source:
resource.dsl.do.getReportTemplate.with.version - Usage: workflow_delete
entity.data.dsl.do.getSystemDetails.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.getSystemDetails.call. - Source:
resource.dsl.do.getSystemDetails.call - Usage: workflow_create
entity.data.dsl.do.getSystemDetails.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.getSystemDetails.with.operationId. - Source:
resource.dsl.do.getSystemDetails.with.operationId - Usage: workflow_create
entity.data.dsl.do.getSystemDetails.with.pathParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.getSystemDetails.with.pathParams.id. - Source:
resource.dsl.do.getSystemDetails.with.pathParams.id - Usage: workflow_create
entity.data.dsl.do.getSystemDetails.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.getSystemDetails.with.version. - Source:
resource.dsl.do.getSystemDetails.with.version - Usage: workflow_create
entity.data.dsl.do.getSystemUsers.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.getSystemUsers.call. - Source:
resource.dsl.do.getSystemUsers.call - Usage: workflow_delete, workflow_update
entity.data.dsl.do.getSystemUsers.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.getSystemUsers.with.operationId. - Source:
resource.dsl.do.getSystemUsers.with.operationId - Usage: workflow_delete, workflow_update
entity.data.dsl.do.getSystemUsers.with.queryParams.limit
- Description: JumpCloud extension data on the managed entity:
dsl.do.getSystemUsers.with.queryParams.limit. - Source:
resource.dsl.do.getSystemUsers.with.queryParams.limit - Usage: workflow_delete, workflow_update
entity.data.dsl.do.getSystemUsers.with.queryParams.skip
- Description: JumpCloud extension data on the managed entity:
dsl.do.getSystemUsers.with.queryParams.skip. - Source:
resource.dsl.do.getSystemUsers.with.queryParams.skip - Usage: workflow_delete, workflow_update
entity.data.dsl.do.getSystemUsers.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.getSystemUsers.with.version. - Source:
resource.dsl.do.getSystemUsers.with.version - Usage: workflow_delete, workflow_update
entity.data.dsl.do.getUser.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.getUser.call. - Source:
resource.dsl.do.getUser.call - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.getUser.if
- Description: JumpCloud extension data on the managed entity:
dsl.do.getUser.if. - Source:
resource.dsl.do.getUser.if - Usage: workflow_create
entity.data.dsl.do.getUser.metadata.compositePocUpdateUserAttrs.attributePairs
- Description: JumpCloud extension data on the managed entity:
dsl.do.getUser.metadata.compositePocUpdateUserAttrs.attributePairs. - Source:
resource.dsl.do.getUser.metadata.compositePocUpdateUserAttrs.attributePairs - Usage: workflow_delete
entity.data.dsl.do.getUser.metadata.compositePocUpdateUserAttrs.getTaskName
- Description: JumpCloud extension data on the managed entity:
dsl.do.getUser.metadata.compositePocUpdateUserAttrs.getTaskName. - Source:
resource.dsl.do.getUser.metadata.compositePocUpdateUserAttrs.getTaskName - Usage: workflow_delete
entity.data.dsl.do.getUser.metadata.compositePocUpdateUserAttrs.putTaskName
- Description: JumpCloud extension data on the managed entity:
dsl.do.getUser.metadata.compositePocUpdateUserAttrs.putTaskName. - Source:
resource.dsl.do.getUser.metadata.compositePocUpdateUserAttrs.putTaskName - Usage: workflow_delete
entity.data.dsl.do.getUser.metadata.compositePocUpdateUserAttrs.role
- Description: JumpCloud extension data on the managed entity:
dsl.do.getUser.metadata.compositePocUpdateUserAttrs.role. - Source:
resource.dsl.do.getUser.metadata.compositePocUpdateUserAttrs.role - Usage: workflow_delete
entity.data.dsl.do.getUser.metadata.compositePocUpdateUserAttrs.templateId
- Description: JumpCloud extension data on the managed entity:
dsl.do.getUser.metadata.compositePocUpdateUserAttrs.templateId. - Source:
resource.dsl.do.getUser.metadata.compositePocUpdateUserAttrs.templateId - Usage: workflow_delete
entity.data.dsl.do.getUser.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.getUser.with.operationId. - Source:
resource.dsl.do.getUser.with.operationId - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.getUser.with.pathParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.getUser.with.pathParams.id. - Source:
resource.dsl.do.getUser.with.pathParams.id - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.getUser.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.getUser.with.version. - Source:
resource.dsl.do.getUser.with.version - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.getUserDetails.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.getUserDetails.call. - Source:
resource.dsl.do.getUserDetails.call - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.getUserDetails.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.getUserDetails.with.operationId. - Source:
resource.dsl.do.getUserDetails.with.operationId - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.getUserDetails.with.pathParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.getUserDetails.with.pathParams.id. - Source:
resource.dsl.do.getUserDetails.with.pathParams.id - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.getUserDetails.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.getUserDetails.with.version. - Source:
resource.dsl.do.getUserDetails.with.version - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.get_system_details.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.get_system_details.call. - Source:
resource.dsl.do.get_system_details.call - Usage: workflow_create, workflow_delete
entity.data.dsl.do.get_system_details.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.get_system_details.with.operationId. - Source:
resource.dsl.do.get_system_details.with.operationId - Usage: workflow_create, workflow_delete
entity.data.dsl.do.get_system_details.with.pathParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.get_system_details.with.pathParams.id. - Source:
resource.dsl.do.get_system_details.with.pathParams.id - Usage: workflow_create, workflow_delete
entity.data.dsl.do.get_system_details.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.get_system_details.with.version. - Source:
resource.dsl.do.get_system_details.with.version - Usage: workflow_create, workflow_delete
entity.data.dsl.do.graphUserTraverseSystem.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.graphUserTraverseSystem.call. - Source:
resource.dsl.do.graphUserTraverseSystem.call - Usage: workflow_delete, workflow_update
entity.data.dsl.do.graphUserTraverseSystem.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.graphUserTraverseSystem.with.operationId. - Source:
resource.dsl.do.graphUserTraverseSystem.with.operationId - Usage: workflow_delete, workflow_update
entity.data.dsl.do.graphUserTraverseSystem.with.pathParams.user_id
- Description: JumpCloud extension data on the managed entity:
dsl.do.graphUserTraverseSystem.with.pathParams.user_id. - Source:
resource.dsl.do.graphUserTraverseSystem.with.pathParams.user_id - Usage: workflow_delete, workflow_update
entity.data.dsl.do.graphUserTraverseSystem.with.queryParams.filter
- Description: JumpCloud extension data on the managed entity:
dsl.do.graphUserTraverseSystem.with.queryParams.filter. - Source:
resource.dsl.do.graphUserTraverseSystem.with.queryParams.filter - Usage: workflow_delete, workflow_update
entity.data.dsl.do.graphUserTraverseSystem.with.queryParams.limit
- Description: JumpCloud extension data on the managed entity:
dsl.do.graphUserTraverseSystem.with.queryParams.limit. - Source:
resource.dsl.do.graphUserTraverseSystem.with.queryParams.limit - Usage: workflow_delete, workflow_update
entity.data.dsl.do.graphUserTraverseSystem.with.queryParams.skip
- Description: JumpCloud extension data on the managed entity:
dsl.do.graphUserTraverseSystem.with.queryParams.skip. - Source:
resource.dsl.do.graphUserTraverseSystem.with.queryParams.skip - Usage: workflow_delete, workflow_update
entity.data.dsl.do.graphUserTraverseSystem.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.graphUserTraverseSystem.with.version. - Source:
resource.dsl.do.graphUserTraverseSystem.with.version - Usage: workflow_delete, workflow_update
entity.data.dsl.do.graph_userAssociationsPost.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.graph_userAssociationsPost.call. - Source:
resource.dsl.do.graph_userAssociationsPost.call - Usage: workflow_delete
entity.data.dsl.do.graph_userAssociationsPost.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.graph_userAssociationsPost.with.operationId. - Source:
resource.dsl.do.graph_userAssociationsPost.with.operationId - Usage: workflow_delete
entity.data.dsl.do.graph_userAssociationsPost.with.pathParams.user_id
- Description: JumpCloud extension data on the managed entity:
dsl.do.graph_userAssociationsPost.with.pathParams.user_id. - Source:
resource.dsl.do.graph_userAssociationsPost.with.pathParams.user_id - Usage: workflow_delete
entity.data.dsl.do.graph_userAssociationsPost.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.graph_userAssociationsPost.with.version. - Source:
resource.dsl.do.graph_userAssociationsPost.with.version - Usage: workflow_delete
entity.data.dsl.do.groups_policy_post.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.groups_policy_post.call. - Source:
resource.dsl.do.groups_policy_post.call - Usage: workflow_delete
entity.data.dsl.do.groups_policy_post.with.bodyParams.name
- Description: JumpCloud extension data on the managed entity:
dsl.do.groups_policy_post.with.bodyParams.name. - Source:
resource.dsl.do.groups_policy_post.with.bodyParams.name - Usage: workflow_delete
entity.data.dsl.do.groups_policy_post.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.groups_policy_post.with.operationId. - Source:
resource.dsl.do.groups_policy_post.with.operationId - Usage: workflow_delete
entity.data.dsl.do.groups_policy_post.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.groups_policy_post.with.version. - Source:
resource.dsl.do.groups_policy_post.with.version - Usage: workflow_delete
entity.data.dsl.do.idsourcesGet.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.idsourcesGet.call. - Source:
resource.dsl.do.idsourcesGet.call - Usage: workflow_create
entity.data.dsl.do.idsourcesGet.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.idsourcesGet.with.operationId. - Source:
resource.dsl.do.idsourcesGet.with.operationId - Usage: workflow_create
entity.data.dsl.do.idsourcesGet.with.pathParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.idsourcesGet.with.pathParams.id. - Source:
resource.dsl.do.idsourcesGet.with.pathParams.id - Usage: workflow_create
entity.data.dsl.do.idsourcesGet.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.idsourcesGet.with.version. - Source:
resource.dsl.do.idsourcesGet.with.version - Usage: workflow_create
entity.data.dsl.do.ifElse.switch.condition1.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.ifElse.switch.condition1.then. - Source:
resource.dsl.do.ifElse.switch.condition1.then - Usage: workflow_create, workflow_delete
entity.data.dsl.do.ifElse.switch.condition1.when
- Description: JumpCloud extension data on the managed entity:
dsl.do.ifElse.switch.condition1.when. - Source:
resource.dsl.do.ifElse.switch.condition1.when - Usage: workflow_create, workflow_delete
entity.data.dsl.do.ifElse.switch.condition2.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.ifElse.switch.condition2.then. - Source:
resource.dsl.do.ifElse.switch.condition2.then - Usage: workflow_delete
entity.data.dsl.do.ifElse.switch.condition2.when
- Description: JumpCloud extension data on the managed entity:
dsl.do.ifElse.switch.condition2.when. - Source:
resource.dsl.do.ifElse.switch.condition2.when - Usage: workflow_delete
entity.data.dsl.do.ifElse.switch.condition3.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.ifElse.switch.condition3.then. - Source:
resource.dsl.do.ifElse.switch.condition3.then - Usage: workflow_delete
entity.data.dsl.do.ifElse.switch.condition3.when
- Description: JumpCloud extension data on the managed entity:
dsl.do.ifElse.switch.condition3.when. - Source:
resource.dsl.do.ifElse.switch.condition3.when - Usage: workflow_delete
entity.data.dsl.do.ifElse.switch.default.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.ifElse.switch.default.then. - Source:
resource.dsl.do.ifElse.switch.default.then - Usage: workflow_create, workflow_delete
entity.data.dsl.do.ifElse2.switch.condition1.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.ifElse2.switch.condition1.then. - Source:
resource.dsl.do.ifElse2.switch.condition1.then - Usage: workflow_delete
entity.data.dsl.do.ifElse2.switch.condition1.when
- Description: JumpCloud extension data on the managed entity:
dsl.do.ifElse2.switch.condition1.when. - Source:
resource.dsl.do.ifElse2.switch.condition1.when - Usage: workflow_delete
entity.data.dsl.do.ifElse2.switch.default.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.ifElse2.switch.default.then. - Source:
resource.dsl.do.ifElse2.switch.default.then - Usage: workflow_delete
entity.data.dsl.do.installSlack.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.installSlack.call. - Source:
resource.dsl.do.installSlack.call - Usage: workflow_update
entity.data.dsl.do.installSlack.with.bodyParams.displayName
- Description: JumpCloud extension data on the managed entity:
dsl.do.installSlack.with.bodyParams.displayName. - Source:
resource.dsl.do.installSlack.with.bodyParams.displayName - Usage: workflow_update
entity.data.dsl.do.installSlack.with.bodyParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.installSlack.with.bodyParams.id. - Source:
resource.dsl.do.installSlack.with.bodyParams.id - Usage: workflow_update
entity.data.dsl.do.installSlack.with.bodyParams.settings.allowUpdateDelay
- Description: JumpCloud extension data on the managed entity:
dsl.do.installSlack.with.bodyParams.settings.allowUpdateDelay. - Source:
resource.dsl.do.installSlack.with.bodyParams.settings.allowUpdateDelay - Usage: workflow_update
entity.data.dsl.do.installSlack.with.bodyParams.settings.appleVpp
- Description: JumpCloud extension data on the managed entity:
dsl.do.installSlack.with.bodyParams.settings.appleVpp. - Source:
resource.dsl.do.installSlack.with.bodyParams.settings.appleVpp - Usage: workflow_update
entity.data.dsl.do.installSlack.with.bodyParams.settings.assetKind
- Description: JumpCloud extension data on the managed entity:
dsl.do.installSlack.with.bodyParams.settings.assetKind. - Source:
resource.dsl.do.installSlack.with.bodyParams.settings.assetKind - Usage: workflow_update
entity.data.dsl.do.installSlack.with.bodyParams.settings.assetSha256Size
- Description: JumpCloud extension data on the managed entity:
dsl.do.installSlack.with.bodyParams.settings.assetSha256Size. - Source:
resource.dsl.do.installSlack.with.bodyParams.settings.assetSha256Size - Usage: workflow_update
entity.data.dsl.do.installSlack.with.bodyParams.settings.assetSha256Strings
- Description: JumpCloud extension data on the managed entity:
dsl.do.installSlack.with.bodyParams.settings.assetSha256Strings. - Source:
resource.dsl.do.installSlack.with.bodyParams.settings.assetSha256Strings - Usage: workflow_update
entity.data.dsl.do.installSlack.with.bodyParams.settings.autoUpdate
- Description: JumpCloud extension data on the managed entity:
dsl.do.installSlack.with.bodyParams.settings.autoUpdate. - Source:
resource.dsl.do.installSlack.with.bodyParams.settings.autoUpdate - Usage: workflow_update
entity.data.dsl.do.installSlack.with.bodyParams.settings.commandLineArguments
- Description: JumpCloud extension data on the managed entity:
dsl.do.installSlack.with.bodyParams.settings.commandLineArguments. - Source:
resource.dsl.do.installSlack.with.bodyParams.settings.commandLineArguments - Usage: workflow_update
entity.data.dsl.do.installSlack.with.bodyParams.settings.description
- Description: JumpCloud extension data on the managed entity:
dsl.do.installSlack.with.bodyParams.settings.description. - Source:
resource.dsl.do.installSlack.with.bodyParams.settings.description - Usage: workflow_update
entity.data.dsl.do.installSlack.with.bodyParams.settings.desiredState
- Description: JumpCloud extension data on the managed entity:
dsl.do.installSlack.with.bodyParams.settings.desiredState. - Source:
resource.dsl.do.installSlack.with.bodyParams.settings.desiredState - Usage: workflow_update
entity.data.dsl.do.installSlack.with.bodyParams.settings.location
- Description: JumpCloud extension data on the managed entity:
dsl.do.installSlack.with.bodyParams.settings.location. - Source:
resource.dsl.do.installSlack.with.bodyParams.settings.location - Usage: workflow_update
entity.data.dsl.do.installSlack.with.bodyParams.settings.locationObjectId
- Description: JumpCloud extension data on the managed entity:
dsl.do.installSlack.with.bodyParams.settings.locationObjectId. - Source:
resource.dsl.do.installSlack.with.bodyParams.settings.locationObjectId - Usage: workflow_update
entity.data.dsl.do.installSlack.with.bodyParams.settings.microsoftStore.doNotUpdate
- Description: JumpCloud extension data on the managed entity:
dsl.do.installSlack.with.bodyParams.settings.microsoftStore.doNotUpdate. - Source:
resource.dsl.do.installSlack.with.bodyParams.settings.microsoftStore.doNotUpdate - Usage: workflow_update
entity.data.dsl.do.installSlack.with.bodyParams.settings.microsoftStore.nonRemovable
- Description: JumpCloud extension data on the managed entity:
dsl.do.installSlack.with.bodyParams.settings.microsoftStore.nonRemovable. - Source:
resource.dsl.do.installSlack.with.bodyParams.settings.microsoftStore.nonRemovable - Usage: workflow_update
entity.data.dsl.do.installSlack.with.bodyParams.settings.microsoftStore.packageFamilyName
- Description: JumpCloud extension data on the managed entity:
dsl.do.installSlack.with.bodyParams.settings.microsoftStore.packageFamilyName. - Source:
resource.dsl.do.installSlack.with.bodyParams.settings.microsoftStore.packageFamilyName - Usage: workflow_update
entity.data.dsl.do.installSlack.with.bodyParams.settings.packageId
- Description: JumpCloud extension data on the managed entity:
dsl.do.installSlack.with.bodyParams.settings.packageId. - Source:
resource.dsl.do.installSlack.with.bodyParams.settings.packageId - Usage: workflow_update
entity.data.dsl.do.installSlack.with.bodyParams.settings.packageKind
- Description: JumpCloud extension data on the managed entity:
dsl.do.installSlack.with.bodyParams.settings.packageKind. - Source:
resource.dsl.do.installSlack.with.bodyParams.settings.packageKind - Usage: workflow_update
entity.data.dsl.do.installSlack.with.bodyParams.settings.packageManager
- Description: JumpCloud extension data on the managed entity:
dsl.do.installSlack.with.bodyParams.settings.packageManager. - Source:
resource.dsl.do.installSlack.with.bodyParams.settings.packageManager - Usage: workflow_update
entity.data.dsl.do.installSlack.with.bodyParams.settings.packageVersion
- Description: JumpCloud extension data on the managed entity:
dsl.do.installSlack.with.bodyParams.settings.packageVersion. - Source:
resource.dsl.do.installSlack.with.bodyParams.settings.packageVersion - Usage: workflow_update
entity.data.dsl.do.installSlack.with.bodyParams.softwareAppId
- Description: JumpCloud extension data on the managed entity:
dsl.do.installSlack.with.bodyParams.softwareAppId. - Source:
resource.dsl.do.installSlack.with.bodyParams.softwareAppId - Usage: workflow_update
entity.data.dsl.do.installSlack.with.bodyParams.uploadUrl
- Description: JumpCloud extension data on the managed entity:
dsl.do.installSlack.with.bodyParams.uploadUrl. - Source:
resource.dsl.do.installSlack.with.bodyParams.uploadUrl - Usage: workflow_update
entity.data.dsl.do.installSlack.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.installSlack.with.operationId. - Source:
resource.dsl.do.installSlack.with.operationId - Usage: workflow_update
entity.data.dsl.do.installSlack.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.installSlack.with.version. - Source:
resource.dsl.do.installSlack.with.version - Usage: workflow_update
entity.data.dsl.do.listFailedPolicyResults.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.listFailedPolicyResults.call. - Source:
resource.dsl.do.listFailedPolicyResults.call - Usage: workflow_delete, workflow_update
entity.data.dsl.do.listFailedPolicyResults.with.extract
- Description: JumpCloud extension data on the managed entity:
dsl.do.listFailedPolicyResults.with.extract. - Source:
resource.dsl.do.listFailedPolicyResults.with.extract - Usage: workflow_delete, workflow_update
entity.data.dsl.do.listFailedPolicyResults.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.listFailedPolicyResults.with.operationId. - Source:
resource.dsl.do.listFailedPolicyResults.with.operationId - Usage: workflow_delete, workflow_update
entity.data.dsl.do.listFailedPolicyResults.with.pagination.until
- Description: JumpCloud extension data on the managed entity:
dsl.do.listFailedPolicyResults.with.pagination.until. - Source:
resource.dsl.do.listFailedPolicyResults.with.pagination.until - Usage: workflow_delete, workflow_update
entity.data.dsl.do.listFailedPolicyResults.with.pagination.update.in
- Description: JumpCloud extension data on the managed entity:
dsl.do.listFailedPolicyResults.with.pagination.update.in. - Source:
resource.dsl.do.listFailedPolicyResults.with.pagination.update.in - Usage: workflow_delete, workflow_update
entity.data.dsl.do.listFailedPolicyResults.with.pagination.update.key
- Description: JumpCloud extension data on the managed entity:
dsl.do.listFailedPolicyResults.with.pagination.update.key. - Source:
resource.dsl.do.listFailedPolicyResults.with.pagination.update.key - Usage: workflow_delete, workflow_update
entity.data.dsl.do.listFailedPolicyResults.with.pagination.update.value
- Description: JumpCloud extension data on the managed entity:
dsl.do.listFailedPolicyResults.with.pagination.update.value. - Source:
resource.dsl.do.listFailedPolicyResults.with.pagination.update.value - Usage: workflow_delete, workflow_update
entity.data.dsl.do.listFailedPolicyResults.with.queryParams.filter
- Description: JumpCloud extension data on the managed entity:
dsl.do.listFailedPolicyResults.with.queryParams.filter. - Source:
resource.dsl.do.listFailedPolicyResults.with.queryParams.filter - Usage: workflow_delete, workflow_update
entity.data.dsl.do.listFailedPolicyResults.with.queryParams.limit
- Description: JumpCloud extension data on the managed entity:
dsl.do.listFailedPolicyResults.with.queryParams.limit. - Source:
resource.dsl.do.listFailedPolicyResults.with.queryParams.limit - Usage: workflow_delete, workflow_update
entity.data.dsl.do.listFailedPolicyResults.with.queryParams.skip
- Description: JumpCloud extension data on the managed entity:
dsl.do.listFailedPolicyResults.with.queryParams.skip. - Source:
resource.dsl.do.listFailedPolicyResults.with.queryParams.skip - Usage: workflow_delete, workflow_update
entity.data.dsl.do.listFailedPolicyResults.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.listFailedPolicyResults.with.version. - Source:
resource.dsl.do.listFailedPolicyResults.with.version - Usage: workflow_delete, workflow_update
entity.data.dsl.do.listInactiveUsers.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.listInactiveUsers.call. - Source:
resource.dsl.do.listInactiveUsers.call - Usage: workflow_delete
entity.data.dsl.do.listInactiveUsers.with.extract
- Description: JumpCloud extension data on the managed entity:
dsl.do.listInactiveUsers.with.extract. - Source:
resource.dsl.do.listInactiveUsers.with.extract - Usage: workflow_delete
entity.data.dsl.do.listInactiveUsers.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.listInactiveUsers.with.operationId. - Source:
resource.dsl.do.listInactiveUsers.with.operationId - Usage: workflow_delete
entity.data.dsl.do.listInactiveUsers.with.pagination.until
- Description: JumpCloud extension data on the managed entity:
dsl.do.listInactiveUsers.with.pagination.until. - Source:
resource.dsl.do.listInactiveUsers.with.pagination.until - Usage: workflow_delete
entity.data.dsl.do.listInactiveUsers.with.pagination.update.in
- Description: JumpCloud extension data on the managed entity:
dsl.do.listInactiveUsers.with.pagination.update.in. - Source:
resource.dsl.do.listInactiveUsers.with.pagination.update.in - Usage: workflow_delete
entity.data.dsl.do.listInactiveUsers.with.pagination.update.key
- Description: JumpCloud extension data on the managed entity:
dsl.do.listInactiveUsers.with.pagination.update.key. - Source:
resource.dsl.do.listInactiveUsers.with.pagination.update.key - Usage: workflow_delete
entity.data.dsl.do.listInactiveUsers.with.pagination.update.value
- Description: JumpCloud extension data on the managed entity:
dsl.do.listInactiveUsers.with.pagination.update.value. - Source:
resource.dsl.do.listInactiveUsers.with.pagination.update.value - Usage: workflow_delete
entity.data.dsl.do.listInactiveUsers.with.queryParams.filter
- Description: JumpCloud extension data on the managed entity:
dsl.do.listInactiveUsers.with.queryParams.filter. - Source:
resource.dsl.do.listInactiveUsers.with.queryParams.filter - Usage: workflow_delete
entity.data.dsl.do.listInactiveUsers.with.queryParams.limit
- Description: JumpCloud extension data on the managed entity:
dsl.do.listInactiveUsers.with.queryParams.limit. - Source:
resource.dsl.do.listInactiveUsers.with.queryParams.limit - Usage: workflow_delete
entity.data.dsl.do.listInactiveUsers.with.queryParams.skip
- Description: JumpCloud extension data on the managed entity:
dsl.do.listInactiveUsers.with.queryParams.skip. - Source:
resource.dsl.do.listInactiveUsers.with.queryParams.skip - Usage: workflow_delete
entity.data.dsl.do.listInactiveUsers.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.listInactiveUsers.with.version. - Source:
resource.dsl.do.listInactiveUsers.with.version - Usage: workflow_delete
entity.data.dsl.do.listUserGroups.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.listUserGroups.call. - Source:
resource.dsl.do.listUserGroups.call - Usage: workflow_delete
entity.data.dsl.do.listUserGroups.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.listUserGroups.then. - Source:
resource.dsl.do.listUserGroups.then - Usage: workflow_delete
entity.data.dsl.do.listUserGroups.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.listUserGroups.with.operationId. - Source:
resource.dsl.do.listUserGroups.with.operationId - Usage: workflow_delete
entity.data.dsl.do.listUserGroups.with.pathParams.user_id
- Description: JumpCloud extension data on the managed entity:
dsl.do.listUserGroups.with.pathParams.user_id. - Source:
resource.dsl.do.listUserGroups.with.pathParams.user_id - Usage: workflow_delete
entity.data.dsl.do.listUserGroups.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.listUserGroups.with.version. - Source:
resource.dsl.do.listUserGroups.with.version - Usage: workflow_delete
entity.data.dsl.do.listUserSystems.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.listUserSystems.call. - Source:
resource.dsl.do.listUserSystems.call - Usage: workflow_delete
entity.data.dsl.do.listUserSystems.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.listUserSystems.with.operationId. - Source:
resource.dsl.do.listUserSystems.with.operationId - Usage: workflow_delete
entity.data.dsl.do.listUserSystems.with.pathParams.user_id
- Description: JumpCloud extension data on the managed entity:
dsl.do.listUserSystems.with.pathParams.user_id. - Source:
resource.dsl.do.listUserSystems.with.pathParams.user_id - Usage: workflow_delete
entity.data.dsl.do.listUserSystems.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.listUserSystems.with.version. - Source:
resource.dsl.do.listUserSystems.with.version - Usage: workflow_delete
entity.data.dsl.do.listUsersWithoutMFA.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.listUsersWithoutMFA.call. - Source:
resource.dsl.do.listUsersWithoutMFA.call - Usage: workflow_create
entity.data.dsl.do.listUsersWithoutMFA.with.extract
- Description: JumpCloud extension data on the managed entity:
dsl.do.listUsersWithoutMFA.with.extract. - Source:
resource.dsl.do.listUsersWithoutMFA.with.extract - Usage: workflow_create
entity.data.dsl.do.listUsersWithoutMFA.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.listUsersWithoutMFA.with.operationId. - Source:
resource.dsl.do.listUsersWithoutMFA.with.operationId - Usage: workflow_create
entity.data.dsl.do.listUsersWithoutMFA.with.pagination.until
- Description: JumpCloud extension data on the managed entity:
dsl.do.listUsersWithoutMFA.with.pagination.until. - Source:
resource.dsl.do.listUsersWithoutMFA.with.pagination.until - Usage: workflow_create
entity.data.dsl.do.listUsersWithoutMFA.with.pagination.update.in
- Description: JumpCloud extension data on the managed entity:
dsl.do.listUsersWithoutMFA.with.pagination.update.in. - Source:
resource.dsl.do.listUsersWithoutMFA.with.pagination.update.in - Usage: workflow_create
entity.data.dsl.do.listUsersWithoutMFA.with.pagination.update.key
- Description: JumpCloud extension data on the managed entity:
dsl.do.listUsersWithoutMFA.with.pagination.update.key. - Source:
resource.dsl.do.listUsersWithoutMFA.with.pagination.update.key - Usage: workflow_create
entity.data.dsl.do.listUsersWithoutMFA.with.pagination.update.value
- Description: JumpCloud extension data on the managed entity:
dsl.do.listUsersWithoutMFA.with.pagination.update.value. - Source:
resource.dsl.do.listUsersWithoutMFA.with.pagination.update.value - Usage: workflow_create
entity.data.dsl.do.listUsersWithoutMFA.with.queryParams.filter
- Description: JumpCloud extension data on the managed entity:
dsl.do.listUsersWithoutMFA.with.queryParams.filter. - Source:
resource.dsl.do.listUsersWithoutMFA.with.queryParams.filter - Usage: workflow_create
entity.data.dsl.do.listUsersWithoutMFA.with.queryParams.limit
- Description: JumpCloud extension data on the managed entity:
dsl.do.listUsersWithoutMFA.with.queryParams.limit. - Source:
resource.dsl.do.listUsersWithoutMFA.with.queryParams.limit - Usage: workflow_create
entity.data.dsl.do.listUsersWithoutMFA.with.queryParams.skip
- Description: JumpCloud extension data on the managed entity:
dsl.do.listUsersWithoutMFA.with.queryParams.skip. - Source:
resource.dsl.do.listUsersWithoutMFA.with.queryParams.skip - Usage: workflow_create
entity.data.dsl.do.listUsersWithoutMFA.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.listUsersWithoutMFA.with.version. - Source:
resource.dsl.do.listUsersWithoutMFA.with.version - Usage: workflow_create
entity.data.dsl.do.lockMacDevice.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.lockMacDevice.call. - Source:
resource.dsl.do.lockMacDevice.call - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.lockMacDevice.metadata.displayLabels.device
- Description: JumpCloud extension data on the managed entity:
dsl.do.lockMacDevice.metadata.displayLabels.device. - Source:
resource.dsl.do.lockMacDevice.metadata.displayLabels.device - Usage: workflow_create
entity.data.dsl.do.lockMacDevice.metadata.displayLabels.pin
- Description: JumpCloud extension data on the managed entity:
dsl.do.lockMacDevice.metadata.displayLabels.pin. - Source:
resource.dsl.do.lockMacDevice.metadata.displayLabels.pin - Usage: workflow_create
entity.data.dsl.do.lockMacDevice.metadata.inputModes.device
- Description: JumpCloud extension data on the managed entity:
dsl.do.lockMacDevice.metadata.inputModes.device. - Source:
resource.dsl.do.lockMacDevice.metadata.inputModes.device - Usage: workflow_create
entity.data.dsl.do.lockMacDevice.metadata.inputModes.pin
- Description: JumpCloud extension data on the managed entity:
dsl.do.lockMacDevice.metadata.inputModes.pin. - Source:
resource.dsl.do.lockMacDevice.metadata.inputModes.pin - Usage: workflow_create
entity.data.dsl.do.lockMacDevice.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.lockMacDevice.then. - Source:
resource.dsl.do.lockMacDevice.then - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.lockMacDevice.with.bodyParams.pin
- Description: JumpCloud extension data on the managed entity:
dsl.do.lockMacDevice.with.bodyParams.pin. - Source:
resource.dsl.do.lockMacDevice.with.bodyParams.pin - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.lockMacDevice.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.lockMacDevice.with.operationId. - Source:
resource.dsl.do.lockMacDevice.with.operationId - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.lockMacDevice.with.pathParams.apple_mdm_id
- Description: JumpCloud extension data on the managed entity:
dsl.do.lockMacDevice.with.pathParams.apple_mdm_id. - Source:
resource.dsl.do.lockMacDevice.with.pathParams.apple_mdm_id - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.lockMacDevice.with.pathParams.device_id
- Description: JumpCloud extension data on the managed entity:
dsl.do.lockMacDevice.with.pathParams.device_id. - Source:
resource.dsl.do.lockMacDevice.with.pathParams.device_id - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.lockMacDevice.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.lockMacDevice.with.version. - Source:
resource.dsl.do.lockMacDevice.with.version - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.lockOtherDevice.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.lockOtherDevice.call. - Source:
resource.dsl.do.lockOtherDevice.call - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.lockOtherDevice.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.lockOtherDevice.then. - Source:
resource.dsl.do.lockOtherDevice.then - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.lockOtherDevice.with.bodyParams
- Description: JumpCloud extension data on the managed entity:
dsl.do.lockOtherDevice.with.bodyParams. - Source:
resource.dsl.do.lockOtherDevice.with.bodyParams - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.lockOtherDevice.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.lockOtherDevice.with.operationId. - Source:
resource.dsl.do.lockOtherDevice.with.operationId - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.lockOtherDevice.with.pathParams.system_id
- Description: JumpCloud extension data on the managed entity:
dsl.do.lockOtherDevice.with.pathParams.system_id. - Source:
resource.dsl.do.lockOtherDevice.with.pathParams.system_id - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.lockOtherDevice.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.lockOtherDevice.with.version. - Source:
resource.dsl.do.lockOtherDevice.with.version - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.lockUserDevices.do.lockDevice.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.lockUserDevices.do.lockDevice.call. - Source:
resource.dsl.do.lockUserDevices.do.lockDevice.call - Usage: workflow_delete
entity.data.dsl.do.lockUserDevices.do.lockDevice.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.lockUserDevices.do.lockDevice.with.operationId. - Source:
resource.dsl.do.lockUserDevices.do.lockDevice.with.operationId - Usage: workflow_delete
entity.data.dsl.do.lockUserDevices.do.lockDevice.with.pathParams.system_id
- Description: JumpCloud extension data on the managed entity:
dsl.do.lockUserDevices.do.lockDevice.with.pathParams.system_id. - Source:
resource.dsl.do.lockUserDevices.do.lockDevice.with.pathParams.system_id - Usage: workflow_delete
entity.data.dsl.do.lockUserDevices.do.lockDevice.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.lockUserDevices.do.lockDevice.with.version. - Source:
resource.dsl.do.lockUserDevices.do.lockDevice.with.version - Usage: workflow_delete
entity.data.dsl.do.lockUserDevices.for.each
- Description: JumpCloud extension data on the managed entity:
dsl.do.lockUserDevices.for.each. - Source:
resource.dsl.do.lockUserDevices.for.each - Usage: workflow_delete
entity.data.dsl.do.lockUserDevices.for.in
- Description: JumpCloud extension data on the managed entity:
dsl.do.lockUserDevices.for.in. - Source:
resource.dsl.do.lockUserDevices.for.in - Usage: workflow_delete
entity.data.dsl.do.loops.do.addUserToUserGroup.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.loops.do.addUserToUserGroup.call. - Source:
resource.dsl.do.loops.do.addUserToUserGroup.call - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.loops.do.addUserToUserGroup.metadata.displayLabels.user
- Description: JumpCloud extension data on the managed entity:
dsl.do.loops.do.addUserToUserGroup.metadata.displayLabels.user. - Source:
resource.dsl.do.loops.do.addUserToUserGroup.metadata.displayLabels.user - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.loops.do.addUserToUserGroup.metadata.displayLabels.userGroup
- Description: JumpCloud extension data on the managed entity:
dsl.do.loops.do.addUserToUserGroup.metadata.displayLabels.userGroup. - Source:
resource.dsl.do.loops.do.addUserToUserGroup.metadata.displayLabels.userGroup - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.loops.do.addUserToUserGroup.metadata.inputModes.user
- Description: JumpCloud extension data on the managed entity:
dsl.do.loops.do.addUserToUserGroup.metadata.inputModes.user. - Source:
resource.dsl.do.loops.do.addUserToUserGroup.metadata.inputModes.user - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.loops.do.addUserToUserGroup.metadata.inputModes.userGroup
- Description: JumpCloud extension data on the managed entity:
dsl.do.loops.do.addUserToUserGroup.metadata.inputModes.userGroup. - Source:
resource.dsl.do.loops.do.addUserToUserGroup.metadata.inputModes.userGroup - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.loops.do.addUserToUserGroup.with.bodyParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.loops.do.addUserToUserGroup.with.bodyParams.id. - Source:
resource.dsl.do.loops.do.addUserToUserGroup.with.bodyParams.id - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.loops.do.addUserToUserGroup.with.bodyParams.op
- Description: JumpCloud extension data on the managed entity:
dsl.do.loops.do.addUserToUserGroup.with.bodyParams.op. - Source:
resource.dsl.do.loops.do.addUserToUserGroup.with.bodyParams.op - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.loops.do.addUserToUserGroup.with.bodyParams.type
- Description: JumpCloud extension data on the managed entity:
dsl.do.loops.do.addUserToUserGroup.with.bodyParams.type. - Source:
resource.dsl.do.loops.do.addUserToUserGroup.with.bodyParams.type - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.loops.do.addUserToUserGroup.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.loops.do.addUserToUserGroup.with.operationId. - Source:
resource.dsl.do.loops.do.addUserToUserGroup.with.operationId - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.loops.do.addUserToUserGroup.with.pathParams.group_id
- Description: JumpCloud extension data on the managed entity:
dsl.do.loops.do.addUserToUserGroup.with.pathParams.group_id. - Source:
resource.dsl.do.loops.do.addUserToUserGroup.with.pathParams.group_id - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.loops.do.addUserToUserGroup.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.loops.do.addUserToUserGroup.with.version. - Source:
resource.dsl.do.loops.do.addUserToUserGroup.with.version - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.loops.do.bindUserToDevice.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.loops.do.bindUserToDevice.call. - Source:
resource.dsl.do.loops.do.bindUserToDevice.call - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.loops.do.bindUserToDevice.metadata.displayLabels.device
- Description: JumpCloud extension data on the managed entity:
dsl.do.loops.do.bindUserToDevice.metadata.displayLabels.device. - Source:
resource.dsl.do.loops.do.bindUserToDevice.metadata.displayLabels.device - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.loops.do.bindUserToDevice.metadata.displayLabels.user
- Description: JumpCloud extension data on the managed entity:
dsl.do.loops.do.bindUserToDevice.metadata.displayLabels.user. - Source:
resource.dsl.do.loops.do.bindUserToDevice.metadata.displayLabels.user - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.loops.do.bindUserToDevice.metadata.inputModes.device
- Description: JumpCloud extension data on the managed entity:
dsl.do.loops.do.bindUserToDevice.metadata.inputModes.device. - Source:
resource.dsl.do.loops.do.bindUserToDevice.metadata.inputModes.device - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.loops.do.bindUserToDevice.metadata.inputModes.user
- Description: JumpCloud extension data on the managed entity:
dsl.do.loops.do.bindUserToDevice.metadata.inputModes.user. - Source:
resource.dsl.do.loops.do.bindUserToDevice.metadata.inputModes.user - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.loops.do.bindUserToDevice.with.bodyParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.loops.do.bindUserToDevice.with.bodyParams.id. - Source:
resource.dsl.do.loops.do.bindUserToDevice.with.bodyParams.id - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.loops.do.bindUserToDevice.with.bodyParams.op
- Description: JumpCloud extension data on the managed entity:
dsl.do.loops.do.bindUserToDevice.with.bodyParams.op. - Source:
resource.dsl.do.loops.do.bindUserToDevice.with.bodyParams.op - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.loops.do.bindUserToDevice.with.bodyParams.type
- Description: JumpCloud extension data on the managed entity:
dsl.do.loops.do.bindUserToDevice.with.bodyParams.type. - Source:
resource.dsl.do.loops.do.bindUserToDevice.with.bodyParams.type - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.loops.do.bindUserToDevice.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.loops.do.bindUserToDevice.with.operationId. - Source:
resource.dsl.do.loops.do.bindUserToDevice.with.operationId - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.loops.do.bindUserToDevice.with.pathParams.system_id
- Description: JumpCloud extension data on the managed entity:
dsl.do.loops.do.bindUserToDevice.with.pathParams.system_id. - Source:
resource.dsl.do.loops.do.bindUserToDevice.with.pathParams.system_id - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.loops.do.bindUserToDevice.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.loops.do.bindUserToDevice.with.version. - Source:
resource.dsl.do.loops.do.bindUserToDevice.with.version - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.loops.do.ifElse.switch.condition1.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.loops.do.ifElse.switch.condition1.then. - Source:
resource.dsl.do.loops.do.ifElse.switch.condition1.then - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.loops.do.ifElse.switch.condition1.when
- Description: JumpCloud extension data on the managed entity:
dsl.do.loops.do.ifElse.switch.condition1.when. - Source:
resource.dsl.do.loops.do.ifElse.switch.condition1.when - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.loops.do.ifElse.switch.condition2.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.loops.do.ifElse.switch.condition2.then. - Source:
resource.dsl.do.loops.do.ifElse.switch.condition2.then - Usage: workflow_update
entity.data.dsl.do.loops.do.ifElse.switch.condition2.when
- Description: JumpCloud extension data on the managed entity:
dsl.do.loops.do.ifElse.switch.condition2.when. - Source:
resource.dsl.do.loops.do.ifElse.switch.condition2.when - Usage: workflow_update
entity.data.dsl.do.loops.do.ifElse.switch.default.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.loops.do.ifElse.switch.default.then. - Source:
resource.dsl.do.loops.do.ifElse.switch.default.then - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.loops.do.runCommandOnDevice.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.loops.do.runCommandOnDevice.call. - Source:
resource.dsl.do.loops.do.runCommandOnDevice.call - Usage: workflow_update
entity.data.dsl.do.loops.do.runCommandOnDevice.metadata.displayLabels.command
- Description: JumpCloud extension data on the managed entity:
dsl.do.loops.do.runCommandOnDevice.metadata.displayLabels.command. - Source:
resource.dsl.do.loops.do.runCommandOnDevice.metadata.displayLabels.command - Usage: workflow_update
entity.data.dsl.do.loops.do.runCommandOnDevice.metadata.displayLabels.devices
- Description: JumpCloud extension data on the managed entity:
dsl.do.loops.do.runCommandOnDevice.metadata.displayLabels.devices. - Source:
resource.dsl.do.loops.do.runCommandOnDevice.metadata.displayLabels.devices - Usage: workflow_update
entity.data.dsl.do.loops.do.runCommandOnDevice.metadata.inputModes.command
- Description: JumpCloud extension data on the managed entity:
dsl.do.loops.do.runCommandOnDevice.metadata.inputModes.command. - Source:
resource.dsl.do.loops.do.runCommandOnDevice.metadata.inputModes.command - Usage: workflow_update
entity.data.dsl.do.loops.do.runCommandOnDevice.metadata.inputModes.devices
- Description: JumpCloud extension data on the managed entity:
dsl.do.loops.do.runCommandOnDevice.metadata.inputModes.devices. - Source:
resource.dsl.do.loops.do.runCommandOnDevice.metadata.inputModes.devices - Usage: workflow_update
entity.data.dsl.do.loops.do.runCommandOnDevice.with.bodyParams._id
- Description: JumpCloud extension data on the managed entity:
dsl.do.loops.do.runCommandOnDevice.with.bodyParams._id. - Source:
resource.dsl.do.loops.do.runCommandOnDevice.with.bodyParams._id - Usage: workflow_update
entity.data.dsl.do.loops.do.runCommandOnDevice.with.bodyParams.systemIds
- Description: JumpCloud extension data on the managed entity:
dsl.do.loops.do.runCommandOnDevice.with.bodyParams.systemIds. - Source:
resource.dsl.do.loops.do.runCommandOnDevice.with.bodyParams.systemIds - Usage: workflow_update
entity.data.dsl.do.loops.do.runCommandOnDevice.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.loops.do.runCommandOnDevice.with.operationId. - Source:
resource.dsl.do.loops.do.runCommandOnDevice.with.operationId - Usage: workflow_update
entity.data.dsl.do.loops.do.runCommandOnDevice.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.loops.do.runCommandOnDevice.with.version. - Source:
resource.dsl.do.loops.do.runCommandOnDevice.with.version - Usage: workflow_update
entity.data.dsl.do.loops.do.runCommandOnDevice2.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.loops.do.runCommandOnDevice2.call. - Source:
resource.dsl.do.loops.do.runCommandOnDevice2.call - Usage: workflow_update
entity.data.dsl.do.loops.do.runCommandOnDevice2.metadata.displayLabels.command
- Description: JumpCloud extension data on the managed entity:
dsl.do.loops.do.runCommandOnDevice2.metadata.displayLabels.command. - Source:
resource.dsl.do.loops.do.runCommandOnDevice2.metadata.displayLabels.command - Usage: workflow_update
entity.data.dsl.do.loops.do.runCommandOnDevice2.metadata.displayLabels.devices
- Description: JumpCloud extension data on the managed entity:
dsl.do.loops.do.runCommandOnDevice2.metadata.displayLabels.devices. - Source:
resource.dsl.do.loops.do.runCommandOnDevice2.metadata.displayLabels.devices - Usage: workflow_update
entity.data.dsl.do.loops.do.runCommandOnDevice2.metadata.inputModes.command
- Description: JumpCloud extension data on the managed entity:
dsl.do.loops.do.runCommandOnDevice2.metadata.inputModes.command. - Source:
resource.dsl.do.loops.do.runCommandOnDevice2.metadata.inputModes.command - Usage: workflow_update
entity.data.dsl.do.loops.do.runCommandOnDevice2.metadata.inputModes.devices
- Description: JumpCloud extension data on the managed entity:
dsl.do.loops.do.runCommandOnDevice2.metadata.inputModes.devices. - Source:
resource.dsl.do.loops.do.runCommandOnDevice2.metadata.inputModes.devices - Usage: workflow_update
entity.data.dsl.do.loops.do.runCommandOnDevice2.with.bodyParams._id
- Description: JumpCloud extension data on the managed entity:
dsl.do.loops.do.runCommandOnDevice2.with.bodyParams._id. - Source:
resource.dsl.do.loops.do.runCommandOnDevice2.with.bodyParams._id - Usage: workflow_update
entity.data.dsl.do.loops.do.runCommandOnDevice2.with.bodyParams.systemIds
- Description: JumpCloud extension data on the managed entity:
dsl.do.loops.do.runCommandOnDevice2.with.bodyParams.systemIds. - Source:
resource.dsl.do.loops.do.runCommandOnDevice2.with.bodyParams.systemIds - Usage: workflow_update
entity.data.dsl.do.loops.do.runCommandOnDevice2.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.loops.do.runCommandOnDevice2.with.operationId. - Source:
resource.dsl.do.loops.do.runCommandOnDevice2.with.operationId - Usage: workflow_update
entity.data.dsl.do.loops.do.runCommandOnDevice2.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.loops.do.runCommandOnDevice2.with.version. - Source:
resource.dsl.do.loops.do.runCommandOnDevice2.with.version - Usage: workflow_update
entity.data.dsl.do.loops.do.systemsGet.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.loops.do.systemsGet.call. - Source:
resource.dsl.do.loops.do.systemsGet.call - Usage: workflow_update
entity.data.dsl.do.loops.do.systemsGet.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.loops.do.systemsGet.with.operationId. - Source:
resource.dsl.do.loops.do.systemsGet.with.operationId - Usage: workflow_update
entity.data.dsl.do.loops.do.systemsGet.with.pathParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.loops.do.systemsGet.with.pathParams.id. - Source:
resource.dsl.do.loops.do.systemsGet.with.pathParams.id - Usage: workflow_update
entity.data.dsl.do.loops.do.systemsGet.with.queryParams
- Description: JumpCloud extension data on the managed entity:
dsl.do.loops.do.systemsGet.with.queryParams. - Source:
resource.dsl.do.loops.do.systemsGet.with.queryParams - Usage: workflow_update
entity.data.dsl.do.loops.do.systemsGet.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.loops.do.systemsGet.with.version. - Source:
resource.dsl.do.loops.do.systemsGet.with.version - Usage: workflow_update
entity.data.dsl.do.loops.for.each
- Description: JumpCloud extension data on the managed entity:
dsl.do.loops.for.each. - Source:
resource.dsl.do.loops.for.each - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.loops.for.in
- Description: JumpCloud extension data on the managed entity:
dsl.do.loops.for.in. - Source:
resource.dsl.do.loops.for.in - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.merge.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.merge.call. - Source:
resource.dsl.do.merge.call - Usage: workflow_delete
entity.data.dsl.do.merge.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.merge.then. - Source:
resource.dsl.do.merge.then - Usage: workflow_delete
entity.data.dsl.do.merge.with.message.body
- Description: JumpCloud extension data on the managed entity:
dsl.do.merge.with.message.body. - Source:
resource.dsl.do.merge.with.message.body - Usage: workflow_delete
entity.data.dsl.do.merge.with.message.subject
- Description: JumpCloud extension data on the managed entity:
dsl.do.merge.with.message.subject. - Source:
resource.dsl.do.merge.with.message.subject - Usage: workflow_delete
entity.data.dsl.do.merge.with.recipients.channel_object_ids
- Description: JumpCloud extension data on the managed entity:
dsl.do.merge.with.recipients.channel_object_ids. - Source:
resource.dsl.do.merge.with.recipients.channel_object_ids - Usage: workflow_delete
entity.data.dsl.do.nliQuestion.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.nliQuestion.call. - Source:
resource.dsl.do.nliQuestion.call - Usage: workflow_delete
entity.data.dsl.do.nliQuestion.with.bodyParams.data
- Description: JumpCloud extension data on the managed entity:
dsl.do.nliQuestion.with.bodyParams.data. - Source:
resource.dsl.do.nliQuestion.with.bodyParams.data - Usage: workflow_delete
entity.data.dsl.do.nliQuestion.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.nliQuestion.with.operationId. - Source:
resource.dsl.do.nliQuestion.with.operationId - Usage: workflow_delete
entity.data.dsl.do.nliQuestion.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.nliQuestion.with.version. - Source:
resource.dsl.do.nliQuestion.with.version - Usage: workflow_delete
entity.data.dsl.do.notifyITReview.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.notifyITReview.call. - Source:
resource.dsl.do.notifyITReview.call - Usage: workflow_delete
entity.data.dsl.do.notifyITReview.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.notifyITReview.then. - Source:
resource.dsl.do.notifyITReview.then - Usage: workflow_delete
entity.data.dsl.do.notifyITReview.with.message.body
- Description: JumpCloud extension data on the managed entity:
dsl.do.notifyITReview.with.message.body. - Source:
resource.dsl.do.notifyITReview.with.message.body - Usage: workflow_delete
entity.data.dsl.do.notifyITReview.with.message.subject
- Description: JumpCloud extension data on the managed entity:
dsl.do.notifyITReview.with.message.subject. - Source:
resource.dsl.do.notifyITReview.with.message.subject - Usage: workflow_delete
entity.data.dsl.do.notifyITReview.with.recipients.channel_object_ids
- Description: JumpCloud extension data on the managed entity:
dsl.do.notifyITReview.with.recipients.channel_object_ids. - Source:
resource.dsl.do.notifyITReview.with.recipients.channel_object_ids - Usage: workflow_delete
entity.data.dsl.do.notifyManagerEmail.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.notifyManagerEmail.call. - Source:
resource.dsl.do.notifyManagerEmail.call - Usage: workflow_delete
entity.data.dsl.do.notifyManagerEmail.if
- Description: JumpCloud extension data on the managed entity:
dsl.do.notifyManagerEmail.if. - Source:
resource.dsl.do.notifyManagerEmail.if - Usage: workflow_delete
entity.data.dsl.do.notifyManagerEmail.with.message.body
- Description: JumpCloud extension data on the managed entity:
dsl.do.notifyManagerEmail.with.message.body. - Source:
resource.dsl.do.notifyManagerEmail.with.message.body - Usage: workflow_delete
entity.data.dsl.do.notifyManagerEmail.with.message.subject
- Description: JumpCloud extension data on the managed entity:
dsl.do.notifyManagerEmail.with.message.subject. - Source:
resource.dsl.do.notifyManagerEmail.with.message.subject - Usage: workflow_delete
entity.data.dsl.do.notifyManagerEmail.with.recipients.to_addresses
- Description: JumpCloud extension data on the managed entity:
dsl.do.notifyManagerEmail.with.recipients.to_addresses. - Source:
resource.dsl.do.notifyManagerEmail.with.recipients.to_addresses - Usage: workflow_delete
entity.data.dsl.do.notifyNoResults.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.notifyNoResults.call. - Source:
resource.dsl.do.notifyNoResults.call - Usage: workflow_delete, workflow_update
entity.data.dsl.do.notifyNoResults.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.notifyNoResults.then. - Source:
resource.dsl.do.notifyNoResults.then - Usage: workflow_delete, workflow_update
entity.data.dsl.do.notifyNoResults.with.message.body
- Description: JumpCloud extension data on the managed entity:
dsl.do.notifyNoResults.with.message.body. - Source:
resource.dsl.do.notifyNoResults.with.message.body - Usage: workflow_delete, workflow_update
entity.data.dsl.do.notifyNoResults.with.message.subject
- Description: JumpCloud extension data on the managed entity:
dsl.do.notifyNoResults.with.message.subject. - Source:
resource.dsl.do.notifyNoResults.with.message.subject - Usage: workflow_delete, workflow_update
entity.data.dsl.do.notifyNoResults.with.recipients.channel_object_ids
- Description: JumpCloud extension data on the managed entity:
dsl.do.notifyNoResults.with.recipients.channel_object_ids. - Source:
resource.dsl.do.notifyNoResults.with.recipients.channel_object_ids - Usage: workflow_delete, workflow_update
entity.data.dsl.do.notifyOps.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.notifyOps.call. - Source:
resource.dsl.do.notifyOps.call - Usage: workflow_delete
entity.data.dsl.do.notifyOps.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.notifyOps.then. - Source:
resource.dsl.do.notifyOps.then - Usage: workflow_delete
entity.data.dsl.do.notifyOps.with.message.body
- Description: JumpCloud extension data on the managed entity:
dsl.do.notifyOps.with.message.body. - Source:
resource.dsl.do.notifyOps.with.message.body - Usage: workflow_delete
entity.data.dsl.do.notifyOps.with.message.subject
- Description: JumpCloud extension data on the managed entity:
dsl.do.notifyOps.with.message.subject. - Source:
resource.dsl.do.notifyOps.with.message.subject - Usage: workflow_delete
entity.data.dsl.do.notifyOps.with.recipients.channel_object_ids
- Description: JumpCloud extension data on the managed entity:
dsl.do.notifyOps.with.recipients.channel_object_ids. - Source:
resource.dsl.do.notifyOps.with.recipients.channel_object_ids - Usage: workflow_delete
entity.data.dsl.do.notifyOpsChannel.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.notifyOpsChannel.call. - Source:
resource.dsl.do.notifyOpsChannel.call - Usage: workflow_delete
entity.data.dsl.do.notifyOpsChannel.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.notifyOpsChannel.then. - Source:
resource.dsl.do.notifyOpsChannel.then - Usage: workflow_delete
entity.data.dsl.do.notifyOpsChannel.with.message.body
- Description: JumpCloud extension data on the managed entity:
dsl.do.notifyOpsChannel.with.message.body. - Source:
resource.dsl.do.notifyOpsChannel.with.message.body - Usage: workflow_delete
entity.data.dsl.do.notifyOpsChannel.with.message.subject
- Description: JumpCloud extension data on the managed entity:
dsl.do.notifyOpsChannel.with.message.subject. - Source:
resource.dsl.do.notifyOpsChannel.with.message.subject - Usage: workflow_delete
entity.data.dsl.do.notifyOpsChannel.with.recipients.channel_object_ids
- Description: JumpCloud extension data on the managed entity:
dsl.do.notifyOpsChannel.with.recipients.channel_object_ids. - Source:
resource.dsl.do.notifyOpsChannel.with.recipients.channel_object_ids - Usage: workflow_delete
entity.data.dsl.do.postLoopAuditVerification.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.postLoopAuditVerification.call. - Source:
resource.dsl.do.postLoopAuditVerification.call - Usage: workflow_create
entity.data.dsl.do.postLoopAuditVerification.if
- Description: JumpCloud extension data on the managed entity:
dsl.do.postLoopAuditVerification.if. - Source:
resource.dsl.do.postLoopAuditVerification.if - Usage: workflow_create
entity.data.dsl.do.postLoopAuditVerification.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.postLoopAuditVerification.with.operationId. - Source:
resource.dsl.do.postLoopAuditVerification.with.operationId - Usage: workflow_create
entity.data.dsl.do.postLoopAuditVerification.with.queryParams.limit
- Description: JumpCloud extension data on the managed entity:
dsl.do.postLoopAuditVerification.with.queryParams.limit. - Source:
resource.dsl.do.postLoopAuditVerification.with.queryParams.limit - Usage: workflow_create
entity.data.dsl.do.postLoopAuditVerification.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.postLoopAuditVerification.with.version. - Source:
resource.dsl.do.postLoopAuditVerification.with.version - Usage: workflow_create
entity.data.dsl.do.postSwitchCheck.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.postSwitchCheck.call. - Source:
resource.dsl.do.postSwitchCheck.call - Usage: workflow_create
entity.data.dsl.do.postSwitchCheck.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.postSwitchCheck.with.operationId. - Source:
resource.dsl.do.postSwitchCheck.with.operationId - Usage: workflow_create
entity.data.dsl.do.postSwitchCheck.with.queryParams.limit
- Description: JumpCloud extension data on the managed entity:
dsl.do.postSwitchCheck.with.queryParams.limit. - Source:
resource.dsl.do.postSwitchCheck.with.queryParams.limit - Usage: workflow_create
entity.data.dsl.do.postSwitchCheck.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.postSwitchCheck.with.version. - Source:
resource.dsl.do.postSwitchCheck.with.version - Usage: workflow_create
entity.data.dsl.do.processEachUser.do.auditActiveUser.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.processEachUser.do.auditActiveUser.call. - Source:
resource.dsl.do.processEachUser.do.auditActiveUser.call - Usage: workflow_create
entity.data.dsl.do.processEachUser.do.auditActiveUser.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.processEachUser.do.auditActiveUser.then. - Source:
resource.dsl.do.processEachUser.do.auditActiveUser.then - Usage: workflow_create
entity.data.dsl.do.processEachUser.do.auditActiveUser.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.processEachUser.do.auditActiveUser.with.operationId. - Source:
resource.dsl.do.processEachUser.do.auditActiveUser.with.operationId - Usage: workflow_create
entity.data.dsl.do.processEachUser.do.auditActiveUser.with.pathParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.processEachUser.do.auditActiveUser.with.pathParams.id. - Source:
resource.dsl.do.processEachUser.do.auditActiveUser.with.pathParams.id - Usage: workflow_create
entity.data.dsl.do.processEachUser.do.auditActiveUser.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.processEachUser.do.auditActiveUser.with.version. - Source:
resource.dsl.do.processEachUser.do.auditActiveUser.with.version - Usage: workflow_create
entity.data.dsl.do.processEachUser.do.auditSuspendedUser.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.processEachUser.do.auditSuspendedUser.call. - Source:
resource.dsl.do.processEachUser.do.auditSuspendedUser.call - Usage: workflow_create
entity.data.dsl.do.processEachUser.do.auditSuspendedUser.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.processEachUser.do.auditSuspendedUser.then. - Source:
resource.dsl.do.processEachUser.do.auditSuspendedUser.then - Usage: workflow_create
entity.data.dsl.do.processEachUser.do.auditSuspendedUser.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.processEachUser.do.auditSuspendedUser.with.operationId. - Source:
resource.dsl.do.processEachUser.do.auditSuspendedUser.with.operationId - Usage: workflow_create
entity.data.dsl.do.processEachUser.do.auditSuspendedUser.with.pathParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.processEachUser.do.auditSuspendedUser.with.pathParams.id. - Source:
resource.dsl.do.processEachUser.do.auditSuspendedUser.with.pathParams.id - Usage: workflow_create
entity.data.dsl.do.processEachUser.do.auditSuspendedUser.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.processEachUser.do.auditSuspendedUser.with.version. - Source:
resource.dsl.do.processEachUser.do.auditSuspendedUser.with.version - Usage: workflow_create
entity.data.dsl.do.processEachUser.do.routeByState.switch.default.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.processEachUser.do.routeByState.switch.default.then. - Source:
resource.dsl.do.processEachUser.do.routeByState.switch.default.then - Usage: workflow_create
entity.data.dsl.do.processEachUser.do.routeByState.switch.suspendedCase.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.processEachUser.do.routeByState.switch.suspendedCase.then. - Source:
resource.dsl.do.processEachUser.do.routeByState.switch.suspendedCase.then - Usage: workflow_create
entity.data.dsl.do.processEachUser.do.routeByState.switch.suspendedCase.when
- Description: JumpCloud extension data on the managed entity:
dsl.do.processEachUser.do.routeByState.switch.suspendedCase.when. - Source:
resource.dsl.do.processEachUser.do.routeByState.switch.suspendedCase.when - Usage: workflow_create
entity.data.dsl.do.processEachUser.for.each
- Description: JumpCloud extension data on the managed entity:
dsl.do.processEachUser.for.each. - Source:
resource.dsl.do.processEachUser.for.each - Usage: workflow_create
entity.data.dsl.do.processEachUser.for.in
- Description: JumpCloud extension data on the managed entity:
dsl.do.processEachUser.for.in. - Source:
resource.dsl.do.processEachUser.for.in - Usage: workflow_create
entity.data.dsl.do.processFailedPolicies.do.addDeviceToFailedGroup.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.processFailedPolicies.do.addDeviceToFailedGroup.call. - Source:
resource.dsl.do.processFailedPolicies.do.addDeviceToFailedGroup.call - Usage: workflow_create
entity.data.dsl.do.processFailedPolicies.do.addDeviceToFailedGroup.with.bodyParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.processFailedPolicies.do.addDeviceToFailedGroup.with.bodyParams.id. - Source:
resource.dsl.do.processFailedPolicies.do.addDeviceToFailedGroup.with.bodyParams.id - Usage: workflow_create
entity.data.dsl.do.processFailedPolicies.do.addDeviceToFailedGroup.with.bodyParams.op
- Description: JumpCloud extension data on the managed entity:
dsl.do.processFailedPolicies.do.addDeviceToFailedGroup.with.bodyParams.op. - Source:
resource.dsl.do.processFailedPolicies.do.addDeviceToFailedGroup.with.bodyParams.op - Usage: workflow_create
entity.data.dsl.do.processFailedPolicies.do.addDeviceToFailedGroup.with.bodyParams.type
- Description: JumpCloud extension data on the managed entity:
dsl.do.processFailedPolicies.do.addDeviceToFailedGroup.with.bodyParams.type. - Source:
resource.dsl.do.processFailedPolicies.do.addDeviceToFailedGroup.with.bodyParams.type - Usage: workflow_create
entity.data.dsl.do.processFailedPolicies.do.addDeviceToFailedGroup.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.processFailedPolicies.do.addDeviceToFailedGroup.with.operationId. - Source:
resource.dsl.do.processFailedPolicies.do.addDeviceToFailedGroup.with.operationId - Usage: workflow_create
entity.data.dsl.do.processFailedPolicies.do.addDeviceToFailedGroup.with.pathParams.group_id
- Description: JumpCloud extension data on the managed entity:
dsl.do.processFailedPolicies.do.addDeviceToFailedGroup.with.pathParams.group_id. - Source:
resource.dsl.do.processFailedPolicies.do.addDeviceToFailedGroup.with.pathParams.group_id - Usage: workflow_create
entity.data.dsl.do.processFailedPolicies.do.addDeviceToFailedGroup.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.processFailedPolicies.do.addDeviceToFailedGroup.with.version. - Source:
resource.dsl.do.processFailedPolicies.do.addDeviceToFailedGroup.with.version - Usage: workflow_create
entity.data.dsl.do.processFailedPolicies.do.getSystemDetails.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.processFailedPolicies.do.getSystemDetails.call. - Source:
resource.dsl.do.processFailedPolicies.do.getSystemDetails.call - Usage: workflow_create
entity.data.dsl.do.processFailedPolicies.do.getSystemDetails.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.processFailedPolicies.do.getSystemDetails.with.operationId. - Source:
resource.dsl.do.processFailedPolicies.do.getSystemDetails.with.operationId - Usage: workflow_create
entity.data.dsl.do.processFailedPolicies.do.getSystemDetails.with.pathParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.processFailedPolicies.do.getSystemDetails.with.pathParams.id. - Source:
resource.dsl.do.processFailedPolicies.do.getSystemDetails.with.pathParams.id - Usage: workflow_create
entity.data.dsl.do.processFailedPolicies.do.getSystemDetails.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.processFailedPolicies.do.getSystemDetails.with.version. - Source:
resource.dsl.do.processFailedPolicies.do.getSystemDetails.with.version - Usage: workflow_create
entity.data.dsl.do.processFailedPolicies.do.getUserDetails.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.processFailedPolicies.do.getUserDetails.call. - Source:
resource.dsl.do.processFailedPolicies.do.getUserDetails.call - Usage: workflow_create
entity.data.dsl.do.processFailedPolicies.do.getUserDetails.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.processFailedPolicies.do.getUserDetails.with.operationId. - Source:
resource.dsl.do.processFailedPolicies.do.getUserDetails.with.operationId - Usage: workflow_create
entity.data.dsl.do.processFailedPolicies.do.getUserDetails.with.pathParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.processFailedPolicies.do.getUserDetails.with.pathParams.id. - Source:
resource.dsl.do.processFailedPolicies.do.getUserDetails.with.pathParams.id - Usage: workflow_create
entity.data.dsl.do.processFailedPolicies.do.getUserDetails.with.queryParams.fields
- Description: JumpCloud extension data on the managed entity:
dsl.do.processFailedPolicies.do.getUserDetails.with.queryParams.fields. - Source:
resource.dsl.do.processFailedPolicies.do.getUserDetails.with.queryParams.fields - Usage: workflow_create
entity.data.dsl.do.processFailedPolicies.do.getUserDetails.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.processFailedPolicies.do.getUserDetails.with.version. - Source:
resource.dsl.do.processFailedPolicies.do.getUserDetails.with.version - Usage: workflow_create
entity.data.dsl.do.processFailedPolicies.do.sendRemediationEmail.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.processFailedPolicies.do.sendRemediationEmail.call. - Source:
resource.dsl.do.processFailedPolicies.do.sendRemediationEmail.call - Usage: workflow_create
entity.data.dsl.do.processFailedPolicies.do.sendRemediationEmail.if
- Description: JumpCloud extension data on the managed entity:
dsl.do.processFailedPolicies.do.sendRemediationEmail.if. - Source:
resource.dsl.do.processFailedPolicies.do.sendRemediationEmail.if - Usage: workflow_create
entity.data.dsl.do.processFailedPolicies.do.sendRemediationEmail.with.message.body
- Description: JumpCloud extension data on the managed entity:
dsl.do.processFailedPolicies.do.sendRemediationEmail.with.message.body. - Source:
resource.dsl.do.processFailedPolicies.do.sendRemediationEmail.with.message.body - Usage: workflow_create
entity.data.dsl.do.processFailedPolicies.do.sendRemediationEmail.with.message.subject
- Description: JumpCloud extension data on the managed entity:
dsl.do.processFailedPolicies.do.sendRemediationEmail.with.message.subject. - Source:
resource.dsl.do.processFailedPolicies.do.sendRemediationEmail.with.message.subject - Usage: workflow_create
entity.data.dsl.do.processFailedPolicies.do.sendRemediationEmail.with.recipients.to_addresses
- Description: JumpCloud extension data on the managed entity:
dsl.do.processFailedPolicies.do.sendRemediationEmail.with.recipients.to_addresses. - Source:
resource.dsl.do.processFailedPolicies.do.sendRemediationEmail.with.recipients.to_addresses - Usage: workflow_create
entity.data.dsl.do.processFailedPolicies.for.each
- Description: JumpCloud extension data on the managed entity:
dsl.do.processFailedPolicies.for.each. - Source:
resource.dsl.do.processFailedPolicies.for.each - Usage: workflow_create
entity.data.dsl.do.processFailedPolicies.for.in
- Description: JumpCloud extension data on the managed entity:
dsl.do.processFailedPolicies.for.in. - Source:
resource.dsl.do.processFailedPolicies.for.in - Usage: workflow_create
entity.data.dsl.do.processNonCompliantDevices.do.getSystemDetails.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.processNonCompliantDevices.do.getSystemDetails.call. - Source:
resource.dsl.do.processNonCompliantDevices.do.getSystemDetails.call - Usage: workflow_delete, workflow_update
entity.data.dsl.do.processNonCompliantDevices.do.getSystemDetails.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.processNonCompliantDevices.do.getSystemDetails.with.operationId. - Source:
resource.dsl.do.processNonCompliantDevices.do.getSystemDetails.with.operationId - Usage: workflow_delete, workflow_update
entity.data.dsl.do.processNonCompliantDevices.do.getSystemDetails.with.pathParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.processNonCompliantDevices.do.getSystemDetails.with.pathParams.id. - Source:
resource.dsl.do.processNonCompliantDevices.do.getSystemDetails.with.pathParams.id - Usage: workflow_delete, workflow_update
entity.data.dsl.do.processNonCompliantDevices.do.getSystemDetails.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.processNonCompliantDevices.do.getSystemDetails.with.version. - Source:
resource.dsl.do.processNonCompliantDevices.do.getSystemDetails.with.version - Usage: workflow_delete, workflow_update
entity.data.dsl.do.processNonCompliantDevices.do.lockDevice.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.processNonCompliantDevices.do.lockDevice.call. - Source:
resource.dsl.do.processNonCompliantDevices.do.lockDevice.call - Usage: workflow_delete, workflow_update
entity.data.dsl.do.processNonCompliantDevices.do.lockDevice.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.processNonCompliantDevices.do.lockDevice.with.operationId. - Source:
resource.dsl.do.processNonCompliantDevices.do.lockDevice.with.operationId - Usage: workflow_delete, workflow_update
entity.data.dsl.do.processNonCompliantDevices.do.lockDevice.with.pathParams.system_id
- Description: JumpCloud extension data on the managed entity:
dsl.do.processNonCompliantDevices.do.lockDevice.with.pathParams.system_id. - Source:
resource.dsl.do.processNonCompliantDevices.do.lockDevice.with.pathParams.system_id - Usage: workflow_delete, workflow_update
entity.data.dsl.do.processNonCompliantDevices.do.lockDevice.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.processNonCompliantDevices.do.lockDevice.with.version. - Source:
resource.dsl.do.processNonCompliantDevices.do.lockDevice.with.version - Usage: workflow_delete, workflow_update
entity.data.dsl.do.processNonCompliantDevices.do.notifyToChannel.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.processNonCompliantDevices.do.notifyToChannel.call. - Source:
resource.dsl.do.processNonCompliantDevices.do.notifyToChannel.call - Usage: workflow_delete, workflow_update
entity.data.dsl.do.processNonCompliantDevices.do.notifyToChannel.with.message.body
- Description: JumpCloud extension data on the managed entity:
dsl.do.processNonCompliantDevices.do.notifyToChannel.with.message.body. - Source:
resource.dsl.do.processNonCompliantDevices.do.notifyToChannel.with.message.body - Usage: workflow_delete, workflow_update
entity.data.dsl.do.processNonCompliantDevices.do.notifyToChannel.with.message.subject
- Description: JumpCloud extension data on the managed entity:
dsl.do.processNonCompliantDevices.do.notifyToChannel.with.message.subject. - Source:
resource.dsl.do.processNonCompliantDevices.do.notifyToChannel.with.message.subject - Usage: workflow_delete, workflow_update
entity.data.dsl.do.processNonCompliantDevices.do.notifyToChannel.with.recipients.channel_object_ids
- Description: JumpCloud extension data on the managed entity:
dsl.do.processNonCompliantDevices.do.notifyToChannel.with.recipients.channel_object_ids. - Source:
resource.dsl.do.processNonCompliantDevices.do.notifyToChannel.with.recipients.channel_object_ids - Usage: workflow_delete, workflow_update
entity.data.dsl.do.processNonCompliantDevices.for.each
- Description: JumpCloud extension data on the managed entity:
dsl.do.processNonCompliantDevices.for.each. - Source:
resource.dsl.do.processNonCompliantDevices.for.each - Usage: workflow_delete, workflow_update
entity.data.dsl.do.processNonCompliantDevices.for.in
- Description: JumpCloud extension data on the managed entity:
dsl.do.processNonCompliantDevices.for.in. - Source:
resource.dsl.do.processNonCompliantDevices.for.in - Usage: workflow_delete, workflow_update
entity.data.dsl.do.processNonCompliantDevices.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.processNonCompliantDevices.then. - Source:
resource.dsl.do.processNonCompliantDevices.then - Usage: workflow_delete, workflow_update
entity.data.dsl.do.processNonMFAUsers.do.addUserToNonMFAGroup.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.processNonMFAUsers.do.addUserToNonMFAGroup.call. - Source:
resource.dsl.do.processNonMFAUsers.do.addUserToNonMFAGroup.call - Usage: workflow_create
entity.data.dsl.do.processNonMFAUsers.do.addUserToNonMFAGroup.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.processNonMFAUsers.do.addUserToNonMFAGroup.then. - Source:
resource.dsl.do.processNonMFAUsers.do.addUserToNonMFAGroup.then - Usage: workflow_create
entity.data.dsl.do.processNonMFAUsers.do.addUserToNonMFAGroup.with.bodyParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.processNonMFAUsers.do.addUserToNonMFAGroup.with.bodyParams.id. - Source:
resource.dsl.do.processNonMFAUsers.do.addUserToNonMFAGroup.with.bodyParams.id - Usage: workflow_create
entity.data.dsl.do.processNonMFAUsers.do.addUserToNonMFAGroup.with.bodyParams.op
- Description: JumpCloud extension data on the managed entity:
dsl.do.processNonMFAUsers.do.addUserToNonMFAGroup.with.bodyParams.op. - Source:
resource.dsl.do.processNonMFAUsers.do.addUserToNonMFAGroup.with.bodyParams.op - Usage: workflow_create
entity.data.dsl.do.processNonMFAUsers.do.addUserToNonMFAGroup.with.bodyParams.type
- Description: JumpCloud extension data on the managed entity:
dsl.do.processNonMFAUsers.do.addUserToNonMFAGroup.with.bodyParams.type. - Source:
resource.dsl.do.processNonMFAUsers.do.addUserToNonMFAGroup.with.bodyParams.type - Usage: workflow_create
entity.data.dsl.do.processNonMFAUsers.do.addUserToNonMFAGroup.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.processNonMFAUsers.do.addUserToNonMFAGroup.with.operationId. - Source:
resource.dsl.do.processNonMFAUsers.do.addUserToNonMFAGroup.with.operationId - Usage: workflow_create
entity.data.dsl.do.processNonMFAUsers.do.addUserToNonMFAGroup.with.pathParams.group_id
- Description: JumpCloud extension data on the managed entity:
dsl.do.processNonMFAUsers.do.addUserToNonMFAGroup.with.pathParams.group_id. - Source:
resource.dsl.do.processNonMFAUsers.do.addUserToNonMFAGroup.with.pathParams.group_id - Usage: workflow_create
entity.data.dsl.do.processNonMFAUsers.do.addUserToNonMFAGroup.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.processNonMFAUsers.do.addUserToNonMFAGroup.with.version. - Source:
resource.dsl.do.processNonMFAUsers.do.addUserToNonMFAGroup.with.version - Usage: workflow_create
entity.data.dsl.do.processNonMFAUsers.do.routeActiveUsers.switch.default.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.processNonMFAUsers.do.routeActiveUsers.switch.default.then. - Source:
resource.dsl.do.processNonMFAUsers.do.routeActiveUsers.switch.default.then - Usage: workflow_create
entity.data.dsl.do.processNonMFAUsers.do.routeActiveUsers.switch.isActive.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.processNonMFAUsers.do.routeActiveUsers.switch.isActive.then. - Source:
resource.dsl.do.processNonMFAUsers.do.routeActiveUsers.switch.isActive.then - Usage: workflow_create
entity.data.dsl.do.processNonMFAUsers.do.routeActiveUsers.switch.isActive.when
- Description: JumpCloud extension data on the managed entity:
dsl.do.processNonMFAUsers.do.routeActiveUsers.switch.isActive.when. - Source:
resource.dsl.do.processNonMFAUsers.do.routeActiveUsers.switch.isActive.when - Usage: workflow_create
entity.data.dsl.do.processNonMFAUsers.do.sendMFAReminderEmail.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.processNonMFAUsers.do.sendMFAReminderEmail.call. - Source:
resource.dsl.do.processNonMFAUsers.do.sendMFAReminderEmail.call - Usage: workflow_create
entity.data.dsl.do.processNonMFAUsers.do.sendMFAReminderEmail.if
- Description: JumpCloud extension data on the managed entity:
dsl.do.processNonMFAUsers.do.sendMFAReminderEmail.if. - Source:
resource.dsl.do.processNonMFAUsers.do.sendMFAReminderEmail.if - Usage: workflow_create
entity.data.dsl.do.processNonMFAUsers.do.sendMFAReminderEmail.with.message.body
- Description: JumpCloud extension data on the managed entity:
dsl.do.processNonMFAUsers.do.sendMFAReminderEmail.with.message.body. - Source:
resource.dsl.do.processNonMFAUsers.do.sendMFAReminderEmail.with.message.body - Usage: workflow_create
entity.data.dsl.do.processNonMFAUsers.do.sendMFAReminderEmail.with.message.subject
- Description: JumpCloud extension data on the managed entity:
dsl.do.processNonMFAUsers.do.sendMFAReminderEmail.with.message.subject. - Source:
resource.dsl.do.processNonMFAUsers.do.sendMFAReminderEmail.with.message.subject - Usage: workflow_create
entity.data.dsl.do.processNonMFAUsers.do.sendMFAReminderEmail.with.recipients.to_addresses
- Description: JumpCloud extension data on the managed entity:
dsl.do.processNonMFAUsers.do.sendMFAReminderEmail.with.recipients.to_addresses. - Source:
resource.dsl.do.processNonMFAUsers.do.sendMFAReminderEmail.with.recipients.to_addresses - Usage: workflow_create
entity.data.dsl.do.processNonMFAUsers.for.each
- Description: JumpCloud extension data on the managed entity:
dsl.do.processNonMFAUsers.for.each. - Source:
resource.dsl.do.processNonMFAUsers.for.each - Usage: workflow_create
entity.data.dsl.do.processNonMFAUsers.for.in
- Description: JumpCloud extension data on the managed entity:
dsl.do.processNonMFAUsers.for.in. - Source:
resource.dsl.do.processNonMFAUsers.for.in - Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.addUserToPreHireGroup.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.processScheduledUsers.do.addUserToPreHireGroup.call. - Source:
resource.dsl.do.processScheduledUsers.do.addUserToPreHireGroup.call - Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.addUserToPreHireGroup.metadata.displayLabels.user
- Description: JumpCloud extension data on the managed entity:
dsl.do.processScheduledUsers.do.addUserToPreHireGroup.metadata.displayLabels.user. - Source:
resource.dsl.do.processScheduledUsers.do.addUserToPreHireGroup.metadata.displayLabels.user - Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.addUserToPreHireGroup.metadata.displayLabels.userGroup
- Description: JumpCloud extension data on the managed entity:
dsl.do.processScheduledUsers.do.addUserToPreHireGroup.metadata.displayLabels.userGroup. - Source:
resource.dsl.do.processScheduledUsers.do.addUserToPreHireGroup.metadata.displayLabels.userGroup - Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.addUserToPreHireGroup.metadata.inputModes.user
- Description: JumpCloud extension data on the managed entity:
dsl.do.processScheduledUsers.do.addUserToPreHireGroup.metadata.inputModes.user. - Source:
resource.dsl.do.processScheduledUsers.do.addUserToPreHireGroup.metadata.inputModes.user - Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.addUserToPreHireGroup.metadata.inputModes.userGroup
- Description: JumpCloud extension data on the managed entity:
dsl.do.processScheduledUsers.do.addUserToPreHireGroup.metadata.inputModes.userGroup. - Source:
resource.dsl.do.processScheduledUsers.do.addUserToPreHireGroup.metadata.inputModes.userGroup - Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.addUserToPreHireGroup.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.processScheduledUsers.do.addUserToPreHireGroup.then. - Source:
resource.dsl.do.processScheduledUsers.do.addUserToPreHireGroup.then - Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.addUserToPreHireGroup.with.bodyParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.processScheduledUsers.do.addUserToPreHireGroup.with.bodyParams.id. - Source:
resource.dsl.do.processScheduledUsers.do.addUserToPreHireGroup.with.bodyParams.id - Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.addUserToPreHireGroup.with.bodyParams.op
- Description: JumpCloud extension data on the managed entity:
dsl.do.processScheduledUsers.do.addUserToPreHireGroup.with.bodyParams.op. - Source:
resource.dsl.do.processScheduledUsers.do.addUserToPreHireGroup.with.bodyParams.op - Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.addUserToPreHireGroup.with.bodyParams.type
- Description: JumpCloud extension data on the managed entity:
dsl.do.processScheduledUsers.do.addUserToPreHireGroup.with.bodyParams.type. - Source:
resource.dsl.do.processScheduledUsers.do.addUserToPreHireGroup.with.bodyParams.type - Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.addUserToPreHireGroup.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.processScheduledUsers.do.addUserToPreHireGroup.with.operationId. - Source:
resource.dsl.do.processScheduledUsers.do.addUserToPreHireGroup.with.operationId - Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.addUserToPreHireGroup.with.pathParams.group_id
- Description: JumpCloud extension data on the managed entity:
dsl.do.processScheduledUsers.do.addUserToPreHireGroup.with.pathParams.group_id. - Source:
resource.dsl.do.processScheduledUsers.do.addUserToPreHireGroup.with.pathParams.group_id - Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.addUserToPreHireGroup.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.processScheduledUsers.do.addUserToPreHireGroup.with.version. - Source:
resource.dsl.do.processScheduledUsers.do.addUserToPreHireGroup.with.version - Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.emailITOps.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.processScheduledUsers.do.emailITOps.call. - Source:
resource.dsl.do.processScheduledUsers.do.emailITOps.call - Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.emailITOps.with.message.body
- Description: JumpCloud extension data on the managed entity:
dsl.do.processScheduledUsers.do.emailITOps.with.message.body. - Source:
resource.dsl.do.processScheduledUsers.do.emailITOps.with.message.body - Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.emailITOps.with.message.subject
- Description: JumpCloud extension data on the managed entity:
dsl.do.processScheduledUsers.do.emailITOps.with.message.subject. - Source:
resource.dsl.do.processScheduledUsers.do.emailITOps.with.message.subject - Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.emailITOps.with.recipients.to_addresses
- Description: JumpCloud extension data on the managed entity:
dsl.do.processScheduledUsers.do.emailITOps.with.recipients.to_addresses. - Source:
resource.dsl.do.processScheduledUsers.do.emailITOps.with.recipients.to_addresses - Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.emailManager.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.processScheduledUsers.do.emailManager.call. - Source:
resource.dsl.do.processScheduledUsers.do.emailManager.call - Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.emailManager.if
- Description: JumpCloud extension data on the managed entity:
dsl.do.processScheduledUsers.do.emailManager.if. - Source:
resource.dsl.do.processScheduledUsers.do.emailManager.if - Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.emailManager.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.processScheduledUsers.do.emailManager.then. - Source:
resource.dsl.do.processScheduledUsers.do.emailManager.then - Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.emailManager.with.message.body
- Description: JumpCloud extension data on the managed entity:
dsl.do.processScheduledUsers.do.emailManager.with.message.body. - Source:
resource.dsl.do.processScheduledUsers.do.emailManager.with.message.body - Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.emailManager.with.message.subject
- Description: JumpCloud extension data on the managed entity:
dsl.do.processScheduledUsers.do.emailManager.with.message.subject. - Source:
resource.dsl.do.processScheduledUsers.do.emailManager.with.message.subject - Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.emailManager.with.recipients.to_addresses
- Description: JumpCloud extension data on the managed entity:
dsl.do.processScheduledUsers.do.emailManager.with.recipients.to_addresses. - Source:
resource.dsl.do.processScheduledUsers.do.emailManager.with.recipients.to_addresses - Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.getManagerDetails.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.processScheduledUsers.do.getManagerDetails.call. - Source:
resource.dsl.do.processScheduledUsers.do.getManagerDetails.call - Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.getManagerDetails.if
- Description: JumpCloud extension data on the managed entity:
dsl.do.processScheduledUsers.do.getManagerDetails.if. - Source:
resource.dsl.do.processScheduledUsers.do.getManagerDetails.if - Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.getManagerDetails.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.processScheduledUsers.do.getManagerDetails.with.operationId. - Source:
resource.dsl.do.processScheduledUsers.do.getManagerDetails.with.operationId - Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.getManagerDetails.with.pathParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.processScheduledUsers.do.getManagerDetails.with.pathParams.id. - Source:
resource.dsl.do.processScheduledUsers.do.getManagerDetails.with.pathParams.id - Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.getManagerDetails.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.processScheduledUsers.do.getManagerDetails.with.version. - Source:
resource.dsl.do.processScheduledUsers.do.getManagerDetails.with.version - Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.getUserDetails.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.processScheduledUsers.do.getUserDetails.call. - Source:
resource.dsl.do.processScheduledUsers.do.getUserDetails.call - Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.getUserDetails.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.processScheduledUsers.do.getUserDetails.then. - Source:
resource.dsl.do.processScheduledUsers.do.getUserDetails.then - Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.getUserDetails.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.processScheduledUsers.do.getUserDetails.with.operationId. - Source:
resource.dsl.do.processScheduledUsers.do.getUserDetails.with.operationId - Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.getUserDetails.with.pathParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.processScheduledUsers.do.getUserDetails.with.pathParams.id. - Source:
resource.dsl.do.processScheduledUsers.do.getUserDetails.with.pathParams.id - Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.getUserDetails.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.processScheduledUsers.do.getUserDetails.with.version. - Source:
resource.dsl.do.processScheduledUsers.do.getUserDetails.with.version - Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.routeByScheduledDateWindow.switch.default.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.processScheduledUsers.do.routeByScheduledDateWindow.switch.default.then. - Source:
resource.dsl.do.processScheduledUsers.do.routeByScheduledDateWindow.switch.default.then - Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.routeByScheduledDateWindow.switch.scheduledSoon.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.processScheduledUsers.do.routeByScheduledDateWindow.switch.scheduledSoon.then. - Source:
resource.dsl.do.processScheduledUsers.do.routeByScheduledDateWindow.switch.scheduledSoon.then - Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.do.routeByScheduledDateWindow.switch.scheduledSoon.when
- Description: JumpCloud extension data on the managed entity:
dsl.do.processScheduledUsers.do.routeByScheduledDateWindow.switch.scheduledSoon.when. - Source:
resource.dsl.do.processScheduledUsers.do.routeByScheduledDateWindow.switch.scheduledSoon.when - Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.for.each
- Description: JumpCloud extension data on the managed entity:
dsl.do.processScheduledUsers.for.each. - Source:
resource.dsl.do.processScheduledUsers.for.each - Usage: workflow_create
entity.data.dsl.do.processScheduledUsers.for.in
- Description: JumpCloud extension data on the managed entity:
dsl.do.processScheduledUsers.for.in. - Source:
resource.dsl.do.processScheduledUsers.for.in - Usage: workflow_create
entity.data.dsl.do.putCommandFullSync.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.putCommandFullSync.call. - Source:
resource.dsl.do.putCommandFullSync.call - Usage: workflow_create
entity.data.dsl.do.putCommandFullSync.if
- Description: JumpCloud extension data on the managed entity:
dsl.do.putCommandFullSync.if. - Source:
resource.dsl.do.putCommandFullSync.if - Usage: workflow_create
entity.data.dsl.do.putCommandFullSync.with.bodyParams.command
- Description: JumpCloud extension data on the managed entity:
dsl.do.putCommandFullSync.with.bodyParams.command. - Source:
resource.dsl.do.putCommandFullSync.with.bodyParams.command - Usage: workflow_create
entity.data.dsl.do.putCommandFullSync.with.bodyParams.commandRunners
- Description: JumpCloud extension data on the managed entity:
dsl.do.putCommandFullSync.with.bodyParams.commandRunners. - Source:
resource.dsl.do.putCommandFullSync.with.bodyParams.commandRunners - Usage: workflow_create
entity.data.dsl.do.putCommandFullSync.with.bodyParams.commandType
- Description: JumpCloud extension data on the managed entity:
dsl.do.putCommandFullSync.with.bodyParams.commandType. - Source:
resource.dsl.do.putCommandFullSync.with.bodyParams.commandType - Usage: workflow_create
entity.data.dsl.do.putCommandFullSync.with.bodyParams.description
- Description: JumpCloud extension data on the managed entity:
dsl.do.putCommandFullSync.with.bodyParams.description. - Source:
resource.dsl.do.putCommandFullSync.with.bodyParams.description - Usage: workflow_create
entity.data.dsl.do.putCommandFullSync.with.bodyParams.files
- Description: JumpCloud extension data on the managed entity:
dsl.do.putCommandFullSync.with.bodyParams.files. - Source:
resource.dsl.do.putCommandFullSync.with.bodyParams.files - Usage: workflow_create
entity.data.dsl.do.putCommandFullSync.with.bodyParams.launchType
- Description: JumpCloud extension data on the managed entity:
dsl.do.putCommandFullSync.with.bodyParams.launchType. - Source:
resource.dsl.do.putCommandFullSync.with.bodyParams.launchType - Usage: workflow_create
entity.data.dsl.do.putCommandFullSync.with.bodyParams.listensTo
- Description: JumpCloud extension data on the managed entity:
dsl.do.putCommandFullSync.with.bodyParams.listensTo. - Source:
resource.dsl.do.putCommandFullSync.with.bodyParams.listensTo - Usage: workflow_create
entity.data.dsl.do.putCommandFullSync.with.bodyParams.name
- Description: JumpCloud extension data on the managed entity:
dsl.do.putCommandFullSync.with.bodyParams.name. - Source:
resource.dsl.do.putCommandFullSync.with.bodyParams.name - Usage: workflow_create
entity.data.dsl.do.putCommandFullSync.with.bodyParams.organization
- Description: JumpCloud extension data on the managed entity:
dsl.do.putCommandFullSync.with.bodyParams.organization. - Source:
resource.dsl.do.putCommandFullSync.with.bodyParams.organization - Usage: workflow_create
entity.data.dsl.do.putCommandFullSync.with.bodyParams.schedule
- Description: JumpCloud extension data on the managed entity:
dsl.do.putCommandFullSync.with.bodyParams.schedule. - Source:
resource.dsl.do.putCommandFullSync.with.bodyParams.schedule - Usage: workflow_create
entity.data.dsl.do.putCommandFullSync.with.bodyParams.scheduleRepeatType
- Description: JumpCloud extension data on the managed entity:
dsl.do.putCommandFullSync.with.bodyParams.scheduleRepeatType. - Source:
resource.dsl.do.putCommandFullSync.with.bodyParams.scheduleRepeatType - Usage: workflow_create
entity.data.dsl.do.putCommandFullSync.with.bodyParams.scheduleYear
- Description: JumpCloud extension data on the managed entity:
dsl.do.putCommandFullSync.with.bodyParams.scheduleYear. - Source:
resource.dsl.do.putCommandFullSync.with.bodyParams.scheduleYear - Usage: workflow_create
entity.data.dsl.do.putCommandFullSync.with.bodyParams.shell
- Description: JumpCloud extension data on the managed entity:
dsl.do.putCommandFullSync.with.bodyParams.shell. - Source:
resource.dsl.do.putCommandFullSync.with.bodyParams.shell - Usage: workflow_create
entity.data.dsl.do.putCommandFullSync.with.bodyParams.sudo
- Description: JumpCloud extension data on the managed entity:
dsl.do.putCommandFullSync.with.bodyParams.sudo. - Source:
resource.dsl.do.putCommandFullSync.with.bodyParams.sudo - Usage: workflow_create
entity.data.dsl.do.putCommandFullSync.with.bodyParams.systems
- Description: JumpCloud extension data on the managed entity:
dsl.do.putCommandFullSync.with.bodyParams.systems. - Source:
resource.dsl.do.putCommandFullSync.with.bodyParams.systems - Usage: workflow_create
entity.data.dsl.do.putCommandFullSync.with.bodyParams.template
- Description: JumpCloud extension data on the managed entity:
dsl.do.putCommandFullSync.with.bodyParams.template. - Source:
resource.dsl.do.putCommandFullSync.with.bodyParams.template - Usage: workflow_create
entity.data.dsl.do.putCommandFullSync.with.bodyParams.timeToLiveSeconds
- Description: JumpCloud extension data on the managed entity:
dsl.do.putCommandFullSync.with.bodyParams.timeToLiveSeconds. - Source:
resource.dsl.do.putCommandFullSync.with.bodyParams.timeToLiveSeconds - Usage: workflow_create
entity.data.dsl.do.putCommandFullSync.with.bodyParams.timeout
- Description: JumpCloud extension data on the managed entity:
dsl.do.putCommandFullSync.with.bodyParams.timeout. - Source:
resource.dsl.do.putCommandFullSync.with.bodyParams.timeout - Usage: workflow_create
entity.data.dsl.do.putCommandFullSync.with.bodyParams.trigger
- Description: JumpCloud extension data on the managed entity:
dsl.do.putCommandFullSync.with.bodyParams.trigger. - Source:
resource.dsl.do.putCommandFullSync.with.bodyParams.trigger - Usage: workflow_create
entity.data.dsl.do.putCommandFullSync.with.bodyParams.user
- Description: JumpCloud extension data on the managed entity:
dsl.do.putCommandFullSync.with.bodyParams.user. - Source:
resource.dsl.do.putCommandFullSync.with.bodyParams.user - Usage: workflow_create
entity.data.dsl.do.putCommandFullSync.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.putCommandFullSync.with.operationId. - Source:
resource.dsl.do.putCommandFullSync.with.operationId - Usage: workflow_create
entity.data.dsl.do.putCommandFullSync.with.pathParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.putCommandFullSync.with.pathParams.id. - Source:
resource.dsl.do.putCommandFullSync.with.pathParams.id - Usage: workflow_create
entity.data.dsl.do.putCommandFullSync.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.putCommandFullSync.with.version. - Source:
resource.dsl.do.putCommandFullSync.with.version - Usage: workflow_create
entity.data.dsl.do.putUserFullSync.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserFullSync.call. - Source:
resource.dsl.do.putUserFullSync.call - Usage: workflow_create
entity.data.dsl.do.putUserFullSync.if
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserFullSync.if. - Source:
resource.dsl.do.putUserFullSync.if - Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.account_locked
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserFullSync.with.bodyParams.account_locked. - Source:
resource.dsl.do.putUserFullSync.with.bodyParams.account_locked - Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.addresses
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserFullSync.with.bodyParams.addresses. - Source:
resource.dsl.do.putUserFullSync.with.bodyParams.addresses - Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.allow_public_key
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserFullSync.with.bodyParams.allow_public_key. - Source:
resource.dsl.do.putUserFullSync.with.bodyParams.allow_public_key - Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.alternateEmail
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserFullSync.with.bodyParams.alternateEmail. - Source:
resource.dsl.do.putUserFullSync.with.bodyParams.alternateEmail - Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.attributes
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserFullSync.with.bodyParams.attributes. - Source:
resource.dsl.do.putUserFullSync.with.bodyParams.attributes - Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.company
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserFullSync.with.bodyParams.company. - Source:
resource.dsl.do.putUserFullSync.with.bodyParams.company - Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.costCenter
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserFullSync.with.bodyParams.costCenter. - Source:
resource.dsl.do.putUserFullSync.with.bodyParams.costCenter - Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.department
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserFullSync.with.bodyParams.department. - Source:
resource.dsl.do.putUserFullSync.with.bodyParams.department - Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.description
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserFullSync.with.bodyParams.description. - Source:
resource.dsl.do.putUserFullSync.with.bodyParams.description - Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.disableDeviceMaxLoginAttempts
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserFullSync.with.bodyParams.disableDeviceMaxLoginAttempts. - Source:
resource.dsl.do.putUserFullSync.with.bodyParams.disableDeviceMaxLoginAttempts - Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.displayname
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserFullSync.with.bodyParams.displayname. - Source:
resource.dsl.do.putUserFullSync.with.bodyParams.displayname - Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.email
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserFullSync.with.bodyParams.email. - Source:
resource.dsl.do.putUserFullSync.with.bodyParams.email - Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.employeeIdentifier
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserFullSync.with.bodyParams.employeeIdentifier. - Source:
resource.dsl.do.putUserFullSync.with.bodyParams.employeeIdentifier - Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.employeeType
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserFullSync.with.bodyParams.employeeType. - Source:
resource.dsl.do.putUserFullSync.with.bodyParams.employeeType - Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.enable_managed_uid
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserFullSync.with.bodyParams.enable_managed_uid. - Source:
resource.dsl.do.putUserFullSync.with.bodyParams.enable_managed_uid - Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.enable_user_portal_multifactor
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserFullSync.with.bodyParams.enable_user_portal_multifactor. - Source:
resource.dsl.do.putUserFullSync.with.bodyParams.enable_user_portal_multifactor - Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.external_dn
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserFullSync.with.bodyParams.external_dn. - Source:
resource.dsl.do.putUserFullSync.with.bodyParams.external_dn - Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.external_password_expiration_date
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserFullSync.with.bodyParams.external_password_expiration_date. - Source:
resource.dsl.do.putUserFullSync.with.bodyParams.external_password_expiration_date - Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.external_source_type
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserFullSync.with.bodyParams.external_source_type. - Source:
resource.dsl.do.putUserFullSync.with.bodyParams.external_source_type - Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.externally_managed
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserFullSync.with.bodyParams.externally_managed. - Source:
resource.dsl.do.putUserFullSync.with.bodyParams.externally_managed - Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.firstname
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserFullSync.with.bodyParams.firstname. - Source:
resource.dsl.do.putUserFullSync.with.bodyParams.firstname - Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.jobTitle
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserFullSync.with.bodyParams.jobTitle. - Source:
resource.dsl.do.putUserFullSync.with.bodyParams.jobTitle - Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.lastname
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserFullSync.with.bodyParams.lastname. - Source:
resource.dsl.do.putUserFullSync.with.bodyParams.lastname - Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.ldap_binding_user
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserFullSync.with.bodyParams.ldap_binding_user. - Source:
resource.dsl.do.putUserFullSync.with.bodyParams.ldap_binding_user - Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.location
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserFullSync.with.bodyParams.location. - Source:
resource.dsl.do.putUserFullSync.with.bodyParams.location - Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.managedAppleId
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserFullSync.with.bodyParams.managedAppleId. - Source:
resource.dsl.do.putUserFullSync.with.bodyParams.managedAppleId - Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.manager
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserFullSync.with.bodyParams.manager. - Source:
resource.dsl.do.putUserFullSync.with.bodyParams.manager - Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.mfa
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserFullSync.with.bodyParams.mfa. - Source:
resource.dsl.do.putUserFullSync.with.bodyParams.mfa - Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.middlename
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserFullSync.with.bodyParams.middlename. - Source:
resource.dsl.do.putUserFullSync.with.bodyParams.middlename - Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.password_never_expires
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserFullSync.with.bodyParams.password_never_expires. - Source:
resource.dsl.do.putUserFullSync.with.bodyParams.password_never_expires - Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.phoneNumbers
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserFullSync.with.bodyParams.phoneNumbers. - Source:
resource.dsl.do.putUserFullSync.with.bodyParams.phoneNumbers - Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.public_key
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserFullSync.with.bodyParams.public_key. - Source:
resource.dsl.do.putUserFullSync.with.bodyParams.public_key - Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.relationships
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserFullSync.with.bodyParams.relationships. - Source:
resource.dsl.do.putUserFullSync.with.bodyParams.relationships - Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.restrictedFields
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserFullSync.with.bodyParams.restrictedFields. - Source:
resource.dsl.do.putUserFullSync.with.bodyParams.restrictedFields - Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.samba_service_user
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserFullSync.with.bodyParams.samba_service_user. - Source:
resource.dsl.do.putUserFullSync.with.bodyParams.samba_service_user - Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.ssh_keys
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserFullSync.with.bodyParams.ssh_keys. - Source:
resource.dsl.do.putUserFullSync.with.bodyParams.ssh_keys - Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.state
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserFullSync.with.bodyParams.state. - Source:
resource.dsl.do.putUserFullSync.with.bodyParams.state - Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.sudo
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserFullSync.with.bodyParams.sudo. - Source:
resource.dsl.do.putUserFullSync.with.bodyParams.sudo - Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.suspended
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserFullSync.with.bodyParams.suspended. - Source:
resource.dsl.do.putUserFullSync.with.bodyParams.suspended - Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.tags
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserFullSync.with.bodyParams.tags. - Source:
resource.dsl.do.putUserFullSync.with.bodyParams.tags - Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.bodyParams.username
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserFullSync.with.bodyParams.username. - Source:
resource.dsl.do.putUserFullSync.with.bodyParams.username - Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserFullSync.with.operationId. - Source:
resource.dsl.do.putUserFullSync.with.operationId - Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.pathParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserFullSync.with.pathParams.id. - Source:
resource.dsl.do.putUserFullSync.with.pathParams.id - Usage: workflow_create
entity.data.dsl.do.putUserFullSync.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserFullSync.with.version. - Source:
resource.dsl.do.putUserFullSync.with.version - Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserWithApproval.call. - Source:
resource.dsl.do.putUserWithApproval.call - Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.if
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserWithApproval.if. - Source:
resource.dsl.do.putUserWithApproval.if - Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.account_locked
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserWithApproval.with.bodyParams.account_locked. - Source:
resource.dsl.do.putUserWithApproval.with.bodyParams.account_locked - Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.addresses
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserWithApproval.with.bodyParams.addresses. - Source:
resource.dsl.do.putUserWithApproval.with.bodyParams.addresses - Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.allow_public_key
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserWithApproval.with.bodyParams.allow_public_key. - Source:
resource.dsl.do.putUserWithApproval.with.bodyParams.allow_public_key - Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.alternateEmail
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserWithApproval.with.bodyParams.alternateEmail. - Source:
resource.dsl.do.putUserWithApproval.with.bodyParams.alternateEmail - Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.attributes
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserWithApproval.with.bodyParams.attributes. - Source:
resource.dsl.do.putUserWithApproval.with.bodyParams.attributes - Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.company
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserWithApproval.with.bodyParams.company. - Source:
resource.dsl.do.putUserWithApproval.with.bodyParams.company - Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.costCenter
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserWithApproval.with.bodyParams.costCenter. - Source:
resource.dsl.do.putUserWithApproval.with.bodyParams.costCenter - Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.department
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserWithApproval.with.bodyParams.department. - Source:
resource.dsl.do.putUserWithApproval.with.bodyParams.department - Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.description
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserWithApproval.with.bodyParams.description. - Source:
resource.dsl.do.putUserWithApproval.with.bodyParams.description - Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.disableDeviceMaxLoginAttempts
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserWithApproval.with.bodyParams.disableDeviceMaxLoginAttempts. - Source:
resource.dsl.do.putUserWithApproval.with.bodyParams.disableDeviceMaxLoginAttempts - Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.displayname
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserWithApproval.with.bodyParams.displayname. - Source:
resource.dsl.do.putUserWithApproval.with.bodyParams.displayname - Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.email
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserWithApproval.with.bodyParams.email. - Source:
resource.dsl.do.putUserWithApproval.with.bodyParams.email - Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.employeeIdentifier
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserWithApproval.with.bodyParams.employeeIdentifier. - Source:
resource.dsl.do.putUserWithApproval.with.bodyParams.employeeIdentifier - Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.employeeType
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserWithApproval.with.bodyParams.employeeType. - Source:
resource.dsl.do.putUserWithApproval.with.bodyParams.employeeType - Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.enable_managed_uid
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserWithApproval.with.bodyParams.enable_managed_uid. - Source:
resource.dsl.do.putUserWithApproval.with.bodyParams.enable_managed_uid - Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.enable_user_portal_multifactor
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserWithApproval.with.bodyParams.enable_user_portal_multifactor. - Source:
resource.dsl.do.putUserWithApproval.with.bodyParams.enable_user_portal_multifactor - Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.external_dn
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserWithApproval.with.bodyParams.external_dn. - Source:
resource.dsl.do.putUserWithApproval.with.bodyParams.external_dn - Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.external_password_expiration_date
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserWithApproval.with.bodyParams.external_password_expiration_date. - Source:
resource.dsl.do.putUserWithApproval.with.bodyParams.external_password_expiration_date - Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.external_source_type
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserWithApproval.with.bodyParams.external_source_type. - Source:
resource.dsl.do.putUserWithApproval.with.bodyParams.external_source_type - Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.externally_managed
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserWithApproval.with.bodyParams.externally_managed. - Source:
resource.dsl.do.putUserWithApproval.with.bodyParams.externally_managed - Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.firstname
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserWithApproval.with.bodyParams.firstname. - Source:
resource.dsl.do.putUserWithApproval.with.bodyParams.firstname - Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.jobTitle
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserWithApproval.with.bodyParams.jobTitle. - Source:
resource.dsl.do.putUserWithApproval.with.bodyParams.jobTitle - Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.lastname
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserWithApproval.with.bodyParams.lastname. - Source:
resource.dsl.do.putUserWithApproval.with.bodyParams.lastname - Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.ldap_binding_user
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserWithApproval.with.bodyParams.ldap_binding_user. - Source:
resource.dsl.do.putUserWithApproval.with.bodyParams.ldap_binding_user - Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.location
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserWithApproval.with.bodyParams.location. - Source:
resource.dsl.do.putUserWithApproval.with.bodyParams.location - Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.managedAppleId
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserWithApproval.with.bodyParams.managedAppleId. - Source:
resource.dsl.do.putUserWithApproval.with.bodyParams.managedAppleId - Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.manager
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserWithApproval.with.bodyParams.manager. - Source:
resource.dsl.do.putUserWithApproval.with.bodyParams.manager - Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.mfa
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserWithApproval.with.bodyParams.mfa. - Source:
resource.dsl.do.putUserWithApproval.with.bodyParams.mfa - Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.middlename
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserWithApproval.with.bodyParams.middlename. - Source:
resource.dsl.do.putUserWithApproval.with.bodyParams.middlename - Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.password_never_expires
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserWithApproval.with.bodyParams.password_never_expires. - Source:
resource.dsl.do.putUserWithApproval.with.bodyParams.password_never_expires - Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.phoneNumbers
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserWithApproval.with.bodyParams.phoneNumbers. - Source:
resource.dsl.do.putUserWithApproval.with.bodyParams.phoneNumbers - Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.public_key
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserWithApproval.with.bodyParams.public_key. - Source:
resource.dsl.do.putUserWithApproval.with.bodyParams.public_key - Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.relationships
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserWithApproval.with.bodyParams.relationships. - Source:
resource.dsl.do.putUserWithApproval.with.bodyParams.relationships - Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.restrictedFields
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserWithApproval.with.bodyParams.restrictedFields. - Source:
resource.dsl.do.putUserWithApproval.with.bodyParams.restrictedFields - Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.samba_service_user
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserWithApproval.with.bodyParams.samba_service_user. - Source:
resource.dsl.do.putUserWithApproval.with.bodyParams.samba_service_user - Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.ssh_keys
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserWithApproval.with.bodyParams.ssh_keys. - Source:
resource.dsl.do.putUserWithApproval.with.bodyParams.ssh_keys - Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.state
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserWithApproval.with.bodyParams.state. - Source:
resource.dsl.do.putUserWithApproval.with.bodyParams.state - Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.sudo
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserWithApproval.with.bodyParams.sudo. - Source:
resource.dsl.do.putUserWithApproval.with.bodyParams.sudo - Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.suspended
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserWithApproval.with.bodyParams.suspended. - Source:
resource.dsl.do.putUserWithApproval.with.bodyParams.suspended - Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.tags
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserWithApproval.with.bodyParams.tags. - Source:
resource.dsl.do.putUserWithApproval.with.bodyParams.tags - Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.bodyParams.username
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserWithApproval.with.bodyParams.username. - Source:
resource.dsl.do.putUserWithApproval.with.bodyParams.username - Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserWithApproval.with.operationId. - Source:
resource.dsl.do.putUserWithApproval.with.operationId - Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.pathParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserWithApproval.with.pathParams.id. - Source:
resource.dsl.do.putUserWithApproval.with.pathParams.id - Usage: workflow_create
entity.data.dsl.do.putUserWithApproval.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.putUserWithApproval.with.version. - Source:
resource.dsl.do.putUserWithApproval.with.version - Usage: workflow_create
entity.data.dsl.do.reactivateUser.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.reactivateUser.call. - Source:
resource.dsl.do.reactivateUser.call - Usage: workflow_create, workflow_delete
entity.data.dsl.do.reactivateUser.metadata.displayLabels.user
- Description: JumpCloud extension data on the managed entity:
dsl.do.reactivateUser.metadata.displayLabels.user. - Source:
resource.dsl.do.reactivateUser.metadata.displayLabels.user - Usage: workflow_create, workflow_delete
entity.data.dsl.do.reactivateUser.metadata.inputModes.email
- Description: JumpCloud extension data on the managed entity:
dsl.do.reactivateUser.metadata.inputModes.email. - Source:
resource.dsl.do.reactivateUser.metadata.inputModes.email - Usage: workflow_create, workflow_delete
entity.data.dsl.do.reactivateUser.metadata.inputModes.user
- Description: JumpCloud extension data on the managed entity:
dsl.do.reactivateUser.metadata.inputModes.user. - Source:
resource.dsl.do.reactivateUser.metadata.inputModes.user - Usage: workflow_create, workflow_delete
entity.data.dsl.do.reactivateUser.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.reactivateUser.with.operationId. - Source:
resource.dsl.do.reactivateUser.with.operationId - Usage: workflow_create, workflow_delete
entity.data.dsl.do.reactivateUser.with.pathParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.reactivateUser.with.pathParams.id. - Source:
resource.dsl.do.reactivateUser.with.pathParams.id - Usage: workflow_create, workflow_delete
entity.data.dsl.do.reactivateUser.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.reactivateUser.with.version. - Source:
resource.dsl.do.reactivateUser.with.version - Usage: workflow_create, workflow_delete
entity.data.dsl.do.removeDelegatedAuthority.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.removeDelegatedAuthority.call. - Source:
resource.dsl.do.removeDelegatedAuthority.call - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.removeDelegatedAuthority.if
- Description: JumpCloud extension data on the managed entity:
dsl.do.removeDelegatedAuthority.if. - Source:
resource.dsl.do.removeDelegatedAuthority.if - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.removeDelegatedAuthority.with.bodyParams.delegatedAuthority
- Description: JumpCloud extension data on the managed entity:
dsl.do.removeDelegatedAuthority.with.bodyParams.delegatedAuthority. - Source:
resource.dsl.do.removeDelegatedAuthority.with.bodyParams.delegatedAuthority - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.removeDelegatedAuthority.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.removeDelegatedAuthority.with.operationId. - Source:
resource.dsl.do.removeDelegatedAuthority.with.operationId - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.removeDelegatedAuthority.with.pathParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.removeDelegatedAuthority.with.pathParams.id. - Source:
resource.dsl.do.removeDelegatedAuthority.with.pathParams.id - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.removeDelegatedAuthority.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.removeDelegatedAuthority.with.version. - Source:
resource.dsl.do.removeDelegatedAuthority.with.version - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.removeFromAllGroups.do.removeFromGroup.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.removeFromAllGroups.do.removeFromGroup.call. - Source:
resource.dsl.do.removeFromAllGroups.do.removeFromGroup.call - Usage: workflow_delete
entity.data.dsl.do.removeFromAllGroups.do.removeFromGroup.with.bodyParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.removeFromAllGroups.do.removeFromGroup.with.bodyParams.id. - Source:
resource.dsl.do.removeFromAllGroups.do.removeFromGroup.with.bodyParams.id - Usage: workflow_delete
entity.data.dsl.do.removeFromAllGroups.do.removeFromGroup.with.bodyParams.op
- Description: JumpCloud extension data on the managed entity:
dsl.do.removeFromAllGroups.do.removeFromGroup.with.bodyParams.op. - Source:
resource.dsl.do.removeFromAllGroups.do.removeFromGroup.with.bodyParams.op - Usage: workflow_delete
entity.data.dsl.do.removeFromAllGroups.do.removeFromGroup.with.bodyParams.type
- Description: JumpCloud extension data on the managed entity:
dsl.do.removeFromAllGroups.do.removeFromGroup.with.bodyParams.type. - Source:
resource.dsl.do.removeFromAllGroups.do.removeFromGroup.with.bodyParams.type - Usage: workflow_delete
entity.data.dsl.do.removeFromAllGroups.do.removeFromGroup.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.removeFromAllGroups.do.removeFromGroup.with.operationId. - Source:
resource.dsl.do.removeFromAllGroups.do.removeFromGroup.with.operationId - Usage: workflow_delete
entity.data.dsl.do.removeFromAllGroups.do.removeFromGroup.with.pathParams.group_id
- Description: JumpCloud extension data on the managed entity:
dsl.do.removeFromAllGroups.do.removeFromGroup.with.pathParams.group_id. - Source:
resource.dsl.do.removeFromAllGroups.do.removeFromGroup.with.pathParams.group_id - Usage: workflow_delete
entity.data.dsl.do.removeFromAllGroups.do.removeFromGroup.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.removeFromAllGroups.do.removeFromGroup.with.version. - Source:
resource.dsl.do.removeFromAllGroups.do.removeFromGroup.with.version - Usage: workflow_delete
entity.data.dsl.do.removeFromAllGroups.do.removeUserFromGroup.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.removeFromAllGroups.do.removeUserFromGroup.call. - Source:
resource.dsl.do.removeFromAllGroups.do.removeUserFromGroup.call - Usage: workflow_delete
entity.data.dsl.do.removeFromAllGroups.do.removeUserFromGroup.with.bodyParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.removeFromAllGroups.do.removeUserFromGroup.with.bodyParams.id. - Source:
resource.dsl.do.removeFromAllGroups.do.removeUserFromGroup.with.bodyParams.id - Usage: workflow_delete
entity.data.dsl.do.removeFromAllGroups.do.removeUserFromGroup.with.bodyParams.op
- Description: JumpCloud extension data on the managed entity:
dsl.do.removeFromAllGroups.do.removeUserFromGroup.with.bodyParams.op. - Source:
resource.dsl.do.removeFromAllGroups.do.removeUserFromGroup.with.bodyParams.op - Usage: workflow_delete
entity.data.dsl.do.removeFromAllGroups.do.removeUserFromGroup.with.bodyParams.type
- Description: JumpCloud extension data on the managed entity:
dsl.do.removeFromAllGroups.do.removeUserFromGroup.with.bodyParams.type. - Source:
resource.dsl.do.removeFromAllGroups.do.removeUserFromGroup.with.bodyParams.type - Usage: workflow_delete
entity.data.dsl.do.removeFromAllGroups.do.removeUserFromGroup.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.removeFromAllGroups.do.removeUserFromGroup.with.operationId. - Source:
resource.dsl.do.removeFromAllGroups.do.removeUserFromGroup.with.operationId - Usage: workflow_delete
entity.data.dsl.do.removeFromAllGroups.do.removeUserFromGroup.with.pathParams.group_id
- Description: JumpCloud extension data on the managed entity:
dsl.do.removeFromAllGroups.do.removeUserFromGroup.with.pathParams.group_id. - Source:
resource.dsl.do.removeFromAllGroups.do.removeUserFromGroup.with.pathParams.group_id - Usage: workflow_delete
entity.data.dsl.do.removeFromAllGroups.do.removeUserFromGroup.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.removeFromAllGroups.do.removeUserFromGroup.with.version. - Source:
resource.dsl.do.removeFromAllGroups.do.removeUserFromGroup.with.version - Usage: workflow_delete
entity.data.dsl.do.removeFromAllGroups.for.each
- Description: JumpCloud extension data on the managed entity:
dsl.do.removeFromAllGroups.for.each. - Source:
resource.dsl.do.removeFromAllGroups.for.each - Usage: workflow_delete
entity.data.dsl.do.removeFromAllGroups.for.in
- Description: JumpCloud extension data on the managed entity:
dsl.do.removeFromAllGroups.for.in. - Source:
resource.dsl.do.removeFromAllGroups.for.in - Usage: workflow_delete
entity.data.dsl.do.removeFromElevatedGroup.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.removeFromElevatedGroup.call. - Source:
resource.dsl.do.removeFromElevatedGroup.call - Usage: workflow_delete
entity.data.dsl.do.removeFromElevatedGroup.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.removeFromElevatedGroup.then. - Source:
resource.dsl.do.removeFromElevatedGroup.then - Usage: workflow_delete
entity.data.dsl.do.removeFromElevatedGroup.with.bodyParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.removeFromElevatedGroup.with.bodyParams.id. - Source:
resource.dsl.do.removeFromElevatedGroup.with.bodyParams.id - Usage: workflow_delete
entity.data.dsl.do.removeFromElevatedGroup.with.bodyParams.op
- Description: JumpCloud extension data on the managed entity:
dsl.do.removeFromElevatedGroup.with.bodyParams.op. - Source:
resource.dsl.do.removeFromElevatedGroup.with.bodyParams.op - Usage: workflow_delete
entity.data.dsl.do.removeFromElevatedGroup.with.bodyParams.type
- Description: JumpCloud extension data on the managed entity:
dsl.do.removeFromElevatedGroup.with.bodyParams.type. - Source:
resource.dsl.do.removeFromElevatedGroup.with.bodyParams.type - Usage: workflow_delete
entity.data.dsl.do.removeFromElevatedGroup.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.removeFromElevatedGroup.with.operationId. - Source:
resource.dsl.do.removeFromElevatedGroup.with.operationId - Usage: workflow_delete
entity.data.dsl.do.removeFromElevatedGroup.with.pathParams.group_id
- Description: JumpCloud extension data on the managed entity:
dsl.do.removeFromElevatedGroup.with.pathParams.group_id. - Source:
resource.dsl.do.removeFromElevatedGroup.with.pathParams.group_id - Usage: workflow_delete
entity.data.dsl.do.removeFromElevatedGroup.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.removeFromElevatedGroup.with.version. - Source:
resource.dsl.do.removeFromElevatedGroup.with.version - Usage: workflow_delete
entity.data.dsl.do.removeUserFromUserGroup.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.removeUserFromUserGroup.call. - Source:
resource.dsl.do.removeUserFromUserGroup.call - Usage: workflow_create, workflow_delete
entity.data.dsl.do.removeUserFromUserGroup.metadata.displayLabels.user
- Description: JumpCloud extension data on the managed entity:
dsl.do.removeUserFromUserGroup.metadata.displayLabels.user. - Source:
resource.dsl.do.removeUserFromUserGroup.metadata.displayLabels.user - Usage: workflow_create, workflow_delete
entity.data.dsl.do.removeUserFromUserGroup.metadata.displayLabels.userGroup
- Description: JumpCloud extension data on the managed entity:
dsl.do.removeUserFromUserGroup.metadata.displayLabels.userGroup. - Source:
resource.dsl.do.removeUserFromUserGroup.metadata.displayLabels.userGroup - Usage: workflow_create, workflow_delete
entity.data.dsl.do.removeUserFromUserGroup.metadata.inputModes.user
- Description: JumpCloud extension data on the managed entity:
dsl.do.removeUserFromUserGroup.metadata.inputModes.user. - Source:
resource.dsl.do.removeUserFromUserGroup.metadata.inputModes.user - Usage: workflow_create, workflow_delete
entity.data.dsl.do.removeUserFromUserGroup.metadata.inputModes.userGroup
- Description: JumpCloud extension data on the managed entity:
dsl.do.removeUserFromUserGroup.metadata.inputModes.userGroup. - Source:
resource.dsl.do.removeUserFromUserGroup.metadata.inputModes.userGroup - Usage: workflow_create, workflow_delete
entity.data.dsl.do.removeUserFromUserGroup.with.bodyParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.removeUserFromUserGroup.with.bodyParams.id. - Source:
resource.dsl.do.removeUserFromUserGroup.with.bodyParams.id - Usage: workflow_create, workflow_delete
entity.data.dsl.do.removeUserFromUserGroup.with.bodyParams.op
- Description: JumpCloud extension data on the managed entity:
dsl.do.removeUserFromUserGroup.with.bodyParams.op. - Source:
resource.dsl.do.removeUserFromUserGroup.with.bodyParams.op - Usage: workflow_create, workflow_delete
entity.data.dsl.do.removeUserFromUserGroup.with.bodyParams.type
- Description: JumpCloud extension data on the managed entity:
dsl.do.removeUserFromUserGroup.with.bodyParams.type. - Source:
resource.dsl.do.removeUserFromUserGroup.with.bodyParams.type - Usage: workflow_create, workflow_delete
entity.data.dsl.do.removeUserFromUserGroup.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.removeUserFromUserGroup.with.operationId. - Source:
resource.dsl.do.removeUserFromUserGroup.with.operationId - Usage: workflow_create, workflow_delete
entity.data.dsl.do.removeUserFromUserGroup.with.pathParams.group_id
- Description: JumpCloud extension data on the managed entity:
dsl.do.removeUserFromUserGroup.with.pathParams.group_id. - Source:
resource.dsl.do.removeUserFromUserGroup.with.pathParams.group_id - Usage: workflow_create, workflow_delete
entity.data.dsl.do.removeUserFromUserGroup.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.removeUserFromUserGroup.with.version. - Source:
resource.dsl.do.removeUserFromUserGroup.with.version - Usage: workflow_create, workflow_delete
entity.data.dsl.do.reportsExportReport.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.reportsExportReport.call. - Source:
resource.dsl.do.reportsExportReport.call - Usage: workflow_create, workflow_delete
entity.data.dsl.do.reportsExportReport.with.bodyParams.dsds
- Description: JumpCloud extension data on the managed entity:
dsl.do.reportsExportReport.with.bodyParams.dsds. - Source:
resource.dsl.do.reportsExportReport.with.bodyParams.dsds - Usage: workflow_create, workflow_delete
entity.data.dsl.do.reportsExportReport.with.bodyParams.euyfe
- Description: JumpCloud extension data on the managed entity:
dsl.do.reportsExportReport.with.bodyParams.euyfe. - Source:
resource.dsl.do.reportsExportReport.with.bodyParams.euyfe - Usage: workflow_create
entity.data.dsl.do.reportsExportReport.with.bodyParams.exportType
- Description: JumpCloud extension data on the managed entity:
dsl.do.reportsExportReport.with.bodyParams.exportType. - Source:
resource.dsl.do.reportsExportReport.with.bodyParams.exportType - Usage: workflow_delete
entity.data.dsl.do.reportsExportReport.with.bodyParams.ff
- Description: JumpCloud extension data on the managed entity:
dsl.do.reportsExportReport.with.bodyParams.ff. - Source:
resource.dsl.do.reportsExportReport.with.bodyParams.ff - Usage: workflow_create
entity.data.dsl.do.reportsExportReport.with.bodyParams.notifyByEmail
- Description: JumpCloud extension data on the managed entity:
dsl.do.reportsExportReport.with.bodyParams.notifyByEmail. - Source:
resource.dsl.do.reportsExportReport.with.bodyParams.notifyByEmail - Usage: workflow_create, workflow_delete
entity.data.dsl.do.reportsExportReport.with.bodyParams.reportName
- Description: JumpCloud extension data on the managed entity:
dsl.do.reportsExportReport.with.bodyParams.reportName. - Source:
resource.dsl.do.reportsExportReport.with.bodyParams.reportName - Usage: workflow_delete
entity.data.dsl.do.reportsExportReport.with.bodyParams.searchRequest.fields.include
- Description: JumpCloud extension data on the managed entity:
dsl.do.reportsExportReport.with.bodyParams.searchRequest.fields.include. - Source:
resource.dsl.do.reportsExportReport.with.bodyParams.searchRequest.fields.include - Usage: workflow_delete
entity.data.dsl.do.reportsExportReport.with.bodyParams.searchRequest.filters
- Description: JumpCloud extension data on the managed entity:
dsl.do.reportsExportReport.with.bodyParams.searchRequest.filters. - Source:
resource.dsl.do.reportsExportReport.with.bodyParams.searchRequest.filters - Usage: workflow_delete
entity.data.dsl.do.reportsExportReport.with.bodyParams.searchRequest.gh
- Description: JumpCloud extension data on the managed entity:
dsl.do.reportsExportReport.with.bodyParams.searchRequest.gh. - Source:
resource.dsl.do.reportsExportReport.with.bodyParams.searchRequest.gh - Usage: workflow_create, workflow_delete
entity.data.dsl.do.reportsExportReport.with.bodyParams.searchRequest.sort.field
- Description: JumpCloud extension data on the managed entity:
dsl.do.reportsExportReport.with.bodyParams.searchRequest.sort.field. - Source:
resource.dsl.do.reportsExportReport.with.bodyParams.searchRequest.sort.field - Usage: workflow_delete
entity.data.dsl.do.reportsExportReport.with.bodyParams.searchRequest.sort.order
- Description: JumpCloud extension data on the managed entity:
dsl.do.reportsExportReport.with.bodyParams.searchRequest.sort.order. - Source:
resource.dsl.do.reportsExportReport.with.bodyParams.searchRequest.sort.order - Usage: workflow_delete
entity.data.dsl.do.reportsExportReport.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.reportsExportReport.with.operationId. - Source:
resource.dsl.do.reportsExportReport.with.operationId - Usage: workflow_create, workflow_delete
entity.data.dsl.do.reportsExportReport.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.reportsExportReport.with.version. - Source:
resource.dsl.do.reportsExportReport.with.version - Usage: workflow_create, workflow_delete
entity.data.dsl.do.reportsGetReportTemplate.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.reportsGetReportTemplate.call. - Source:
resource.dsl.do.reportsGetReportTemplate.call - Usage: workflow_create, workflow_delete
entity.data.dsl.do.reportsGetReportTemplate.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.reportsGetReportTemplate.with.operationId. - Source:
resource.dsl.do.reportsGetReportTemplate.with.operationId - Usage: workflow_create, workflow_delete
entity.data.dsl.do.reportsGetReportTemplate.with.pathParams.objectId
- Description: JumpCloud extension data on the managed entity:
dsl.do.reportsGetReportTemplate.with.pathParams.objectId. - Source:
resource.dsl.do.reportsGetReportTemplate.with.pathParams.objectId - Usage: workflow_create, workflow_delete
entity.data.dsl.do.reportsGetReportTemplate.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.reportsGetReportTemplate.with.version. - Source:
resource.dsl.do.reportsGetReportTemplate.with.version - Usage: workflow_create, workflow_delete
entity.data.dsl.do.restartDevice.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.restartDevice.call. - Source:
resource.dsl.do.restartDevice.call - Usage: workflow_create, workflow_update
entity.data.dsl.do.restartDevice.metadata.displayLabels.device
- Description: JumpCloud extension data on the managed entity:
dsl.do.restartDevice.metadata.displayLabels.device. - Source:
resource.dsl.do.restartDevice.metadata.displayLabels.device - Usage: workflow_create, workflow_update
entity.data.dsl.do.restartDevice.metadata.inputModes.device
- Description: JumpCloud extension data on the managed entity:
dsl.do.restartDevice.metadata.inputModes.device. - Source:
resource.dsl.do.restartDevice.metadata.inputModes.device - Usage: workflow_create, workflow_update
entity.data.dsl.do.restartDevice.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.restartDevice.with.operationId. - Source:
resource.dsl.do.restartDevice.with.operationId - Usage: workflow_create, workflow_update
entity.data.dsl.do.restartDevice.with.pathParams.system_id
- Description: JumpCloud extension data on the managed entity:
dsl.do.restartDevice.with.pathParams.system_id. - Source:
resource.dsl.do.restartDevice.with.pathParams.system_id - Usage: workflow_create, workflow_update
entity.data.dsl.do.restartDevice.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.restartDevice.with.version. - Source:
resource.dsl.do.restartDevice.with.version - Usage: workflow_create, workflow_update
entity.data.dsl.do.routeAssetUpdate.switch.default.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.routeAssetUpdate.switch.default.then. - Source:
resource.dsl.do.routeAssetUpdate.switch.default.then - Usage: workflow_create
entity.data.dsl.do.routeAssetUpdate.switch.preserveTypeIfPresent.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.routeAssetUpdate.switch.preserveTypeIfPresent.then. - Source:
resource.dsl.do.routeAssetUpdate.switch.preserveTypeIfPresent.then - Usage: workflow_create
entity.data.dsl.do.routeAssetUpdate.switch.preserveTypeIfPresent.when
- Description: JumpCloud extension data on the managed entity:
dsl.do.routeAssetUpdate.switch.preserveTypeIfPresent.when. - Source:
resource.dsl.do.routeAssetUpdate.switch.preserveTypeIfPresent.when - Usage: workflow_create
entity.data.dsl.do.routeByOsFamily.if
- Description: JumpCloud extension data on the managed entity:
dsl.do.routeByOsFamily.if. - Source:
resource.dsl.do.routeByOsFamily.if - Usage: workflow_create
entity.data.dsl.do.routeByOsFamily.switch.default.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.routeByOsFamily.switch.default.then. - Source:
resource.dsl.do.routeByOsFamily.switch.default.then - Usage: workflow_create, workflow_delete
entity.data.dsl.do.routeByOsFamily.switch.isMac.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.routeByOsFamily.switch.isMac.then. - Source:
resource.dsl.do.routeByOsFamily.switch.isMac.then - Usage: workflow_create, workflow_delete
entity.data.dsl.do.routeByOsFamily.switch.isMac.when
- Description: JumpCloud extension data on the managed entity:
dsl.do.routeByOsFamily.switch.isMac.when. - Source:
resource.dsl.do.routeByOsFamily.switch.isMac.when - Usage: workflow_create, workflow_delete
entity.data.dsl.do.routeByOsFamily.switch.isOtherOs.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.routeByOsFamily.switch.isOtherOs.then. - Source:
resource.dsl.do.routeByOsFamily.switch.isOtherOs.then - Usage: workflow_create, workflow_delete
entity.data.dsl.do.routeByOsFamily.switch.isOtherOs.when
- Description: JumpCloud extension data on the managed entity:
dsl.do.routeByOsFamily.switch.isOtherOs.when. - Source:
resource.dsl.do.routeByOsFamily.switch.isOtherOs.when - Usage: workflow_create, workflow_delete
entity.data.dsl.do.routeByTitle.switch.default.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.routeByTitle.switch.default.then. - Source:
resource.dsl.do.routeByTitle.switch.default.then - Usage: workflow_delete
entity.data.dsl.do.routeByTitle.switch.demotionTitle.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.routeByTitle.switch.demotionTitle.then. - Source:
resource.dsl.do.routeByTitle.switch.demotionTitle.then - Usage: workflow_delete
entity.data.dsl.do.routeByTitle.switch.demotionTitle.when
- Description: JumpCloud extension data on the managed entity:
dsl.do.routeByTitle.switch.demotionTitle.when. - Source:
resource.dsl.do.routeByTitle.switch.demotionTitle.when - Usage: workflow_delete
entity.data.dsl.do.routeByTitle.switch.elevatedTitle.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.routeByTitle.switch.elevatedTitle.then. - Source:
resource.dsl.do.routeByTitle.switch.elevatedTitle.then - Usage: workflow_delete
entity.data.dsl.do.routeByTitle.switch.elevatedTitle.when
- Description: JumpCloud extension data on the managed entity:
dsl.do.routeByTitle.switch.elevatedTitle.when. - Source:
resource.dsl.do.routeByTitle.switch.elevatedTitle.when - Usage: workflow_delete
entity.data.dsl.do.routeByUserState.switch.activatedCase.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.routeByUserState.switch.activatedCase.then. - Source:
resource.dsl.do.routeByUserState.switch.activatedCase.then - Usage: workflow_create
entity.data.dsl.do.routeByUserState.switch.activatedCase.when
- Description: JumpCloud extension data on the managed entity:
dsl.do.routeByUserState.switch.activatedCase.when. - Source:
resource.dsl.do.routeByUserState.switch.activatedCase.when - Usage: workflow_create
entity.data.dsl.do.routeByUserState.switch.default.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.routeByUserState.switch.default.then. - Source:
resource.dsl.do.routeByUserState.switch.default.then - Usage: workflow_create
entity.data.dsl.do.routeByUserState.switch.suspendedCase.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.routeByUserState.switch.suspendedCase.then. - Source:
resource.dsl.do.routeByUserState.switch.suspendedCase.then - Usage: workflow_create
entity.data.dsl.do.routeByUserState.switch.suspendedCase.when
- Description: JumpCloud extension data on the managed entity:
dsl.do.routeByUserState.switch.suspendedCase.when. - Source:
resource.dsl.do.routeByUserState.switch.suspendedCase.when - Usage: workflow_create
entity.data.dsl.do.routeHasAnyResults.switch.default.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.routeHasAnyResults.switch.default.then. - Source:
resource.dsl.do.routeHasAnyResults.switch.default.then - Usage: workflow_delete, workflow_update
entity.data.dsl.do.routeHasAnyResults.switch.hasResults.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.routeHasAnyResults.switch.hasResults.then. - Source:
resource.dsl.do.routeHasAnyResults.switch.hasResults.then - Usage: workflow_delete, workflow_update
entity.data.dsl.do.routeHasAnyResults.switch.hasResults.when
- Description: JumpCloud extension data on the managed entity:
dsl.do.routeHasAnyResults.switch.hasResults.when. - Source:
resource.dsl.do.routeHasAnyResults.switch.hasResults.when - Usage: workflow_delete, workflow_update
entity.data.dsl.do.runCommandOnDevice.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.runCommandOnDevice.call. - Source:
resource.dsl.do.runCommandOnDevice.call - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.runCommandOnDevice.metadata.displayLabels.command
- Description: JumpCloud extension data on the managed entity:
dsl.do.runCommandOnDevice.metadata.displayLabels.command. - Source:
resource.dsl.do.runCommandOnDevice.metadata.displayLabels.command - Usage: workflow_create, workflow_delete
entity.data.dsl.do.runCommandOnDevice.metadata.displayLabels.devices
- Description: JumpCloud extension data on the managed entity:
dsl.do.runCommandOnDevice.metadata.displayLabels.devices. - Source:
resource.dsl.do.runCommandOnDevice.metadata.displayLabels.devices - Usage: workflow_create, workflow_delete
entity.data.dsl.do.runCommandOnDevice.metadata.inputModes.command
- Description: JumpCloud extension data on the managed entity:
dsl.do.runCommandOnDevice.metadata.inputModes.command. - Source:
resource.dsl.do.runCommandOnDevice.metadata.inputModes.command - Usage: workflow_create, workflow_delete
entity.data.dsl.do.runCommandOnDevice.metadata.inputModes.devices
- Description: JumpCloud extension data on the managed entity:
dsl.do.runCommandOnDevice.metadata.inputModes.devices. - Source:
resource.dsl.do.runCommandOnDevice.metadata.inputModes.devices - Usage: workflow_create, workflow_delete
entity.data.dsl.do.runCommandOnDevice.with.bodyParams._id
- Description: JumpCloud extension data on the managed entity:
dsl.do.runCommandOnDevice.with.bodyParams._id. - Source:
resource.dsl.do.runCommandOnDevice.with.bodyParams._id - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.runCommandOnDevice.with.bodyParams.systemIds
- Description: JumpCloud extension data on the managed entity:
dsl.do.runCommandOnDevice.with.bodyParams.systemIds. - Source:
resource.dsl.do.runCommandOnDevice.with.bodyParams.systemIds - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.runCommandOnDevice.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.runCommandOnDevice.with.operationId. - Source:
resource.dsl.do.runCommandOnDevice.with.operationId - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.runCommandOnDevice.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.runCommandOnDevice.with.version. - Source:
resource.dsl.do.runCommandOnDevice.with.version - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.runCommandOnDevice2.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.runCommandOnDevice2.call. - Source:
resource.dsl.do.runCommandOnDevice2.call - Usage: workflow_delete
entity.data.dsl.do.runCommandOnDevice2.metadata.displayLabels.command
- Description: JumpCloud extension data on the managed entity:
dsl.do.runCommandOnDevice2.metadata.displayLabels.command. - Source:
resource.dsl.do.runCommandOnDevice2.metadata.displayLabels.command - Usage: workflow_delete
entity.data.dsl.do.runCommandOnDevice2.metadata.displayLabels.devices
- Description: JumpCloud extension data on the managed entity:
dsl.do.runCommandOnDevice2.metadata.displayLabels.devices. - Source:
resource.dsl.do.runCommandOnDevice2.metadata.displayLabels.devices - Usage: workflow_delete
entity.data.dsl.do.runCommandOnDevice2.metadata.inputModes.command
- Description: JumpCloud extension data on the managed entity:
dsl.do.runCommandOnDevice2.metadata.inputModes.command. - Source:
resource.dsl.do.runCommandOnDevice2.metadata.inputModes.command - Usage: workflow_delete
entity.data.dsl.do.runCommandOnDevice2.metadata.inputModes.devices
- Description: JumpCloud extension data on the managed entity:
dsl.do.runCommandOnDevice2.metadata.inputModes.devices. - Source:
resource.dsl.do.runCommandOnDevice2.metadata.inputModes.devices - Usage: workflow_delete
entity.data.dsl.do.runCommandOnDevice2.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.runCommandOnDevice2.then. - Source:
resource.dsl.do.runCommandOnDevice2.then - Usage: workflow_delete
entity.data.dsl.do.runCommandOnDevice2.with.bodyParams._id
- Description: JumpCloud extension data on the managed entity:
dsl.do.runCommandOnDevice2.with.bodyParams._id. - Source:
resource.dsl.do.runCommandOnDevice2.with.bodyParams._id - Usage: workflow_delete
entity.data.dsl.do.runCommandOnDevice2.with.bodyParams.systemIds
- Description: JumpCloud extension data on the managed entity:
dsl.do.runCommandOnDevice2.with.bodyParams.systemIds. - Source:
resource.dsl.do.runCommandOnDevice2.with.bodyParams.systemIds - Usage: workflow_delete
entity.data.dsl.do.runCommandOnDevice2.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.runCommandOnDevice2.with.operationId. - Source:
resource.dsl.do.runCommandOnDevice2.with.operationId - Usage: workflow_delete
entity.data.dsl.do.runCommandOnDevice2.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.runCommandOnDevice2.with.version. - Source:
resource.dsl.do.runCommandOnDevice2.with.version - Usage: workflow_delete
entity.data.dsl.do.runCommandOnPrimaryDevice.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.runCommandOnPrimaryDevice.call. - Source:
resource.dsl.do.runCommandOnPrimaryDevice.call - Usage: workflow_create, workflow_update
entity.data.dsl.do.runCommandOnPrimaryDevice.if
- Description: JumpCloud extension data on the managed entity:
dsl.do.runCommandOnPrimaryDevice.if. - Source:
resource.dsl.do.runCommandOnPrimaryDevice.if - Usage: workflow_create, workflow_update
entity.data.dsl.do.runCommandOnPrimaryDevice.with.bodyParams._id
- Description: JumpCloud extension data on the managed entity:
dsl.do.runCommandOnPrimaryDevice.with.bodyParams._id. - Source:
resource.dsl.do.runCommandOnPrimaryDevice.with.bodyParams._id - Usage: workflow_create, workflow_update
entity.data.dsl.do.runCommandOnPrimaryDevice.with.bodyParams.systemIds
- Description: JumpCloud extension data on the managed entity:
dsl.do.runCommandOnPrimaryDevice.with.bodyParams.systemIds. - Source:
resource.dsl.do.runCommandOnPrimaryDevice.with.bodyParams.systemIds - Usage: workflow_create, workflow_update
entity.data.dsl.do.runCommandOnPrimaryDevice.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.runCommandOnPrimaryDevice.with.operationId. - Source:
resource.dsl.do.runCommandOnPrimaryDevice.with.operationId - Usage: workflow_create, workflow_update
entity.data.dsl.do.runCommandOnPrimaryDevice.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.runCommandOnPrimaryDevice.with.version. - Source:
resource.dsl.do.runCommandOnPrimaryDevice.with.version - Usage: workflow_create, workflow_update
entity.data.dsl.do.searchSystems.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.searchSystems.call. - Source:
resource.dsl.do.searchSystems.call - Usage: workflow_update
entity.data.dsl.do.searchSystems.with.bodyParams.filter.and.primarySystemUser._id
- Description: JumpCloud extension data on the managed entity:
dsl.do.searchSystems.with.bodyParams.filter.and.primarySystemUser._id. - Source:
resource.dsl.do.searchSystems.with.bodyParams.filter.and.primarySystemUser._id - Usage: workflow_update
entity.data.dsl.do.searchSystems.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.searchSystems.with.operationId. - Source:
resource.dsl.do.searchSystems.with.operationId - Usage: workflow_update
entity.data.dsl.do.searchSystems.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.searchSystems.with.version. - Source:
resource.dsl.do.searchSystems.with.version - Usage: workflow_update
entity.data.dsl.do.searchSystemsPost.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.searchSystemsPost.call. - Source:
resource.dsl.do.searchSystemsPost.call - Usage: workflow_delete
entity.data.dsl.do.searchSystemsPost.with.bodyParams.filter
- Description: JumpCloud extension data on the managed entity:
dsl.do.searchSystemsPost.with.bodyParams.filter. - Source:
resource.dsl.do.searchSystemsPost.with.bodyParams.filter - Usage: workflow_delete
entity.data.dsl.do.searchSystemsPost.with.bodyParams.searchFilter
- Description: JumpCloud extension data on the managed entity:
dsl.do.searchSystemsPost.with.bodyParams.searchFilter. - Source:
resource.dsl.do.searchSystemsPost.with.bodyParams.searchFilter - Usage: workflow_delete
entity.data.dsl.do.searchSystemsPost.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.searchSystemsPost.with.operationId. - Source:
resource.dsl.do.searchSystemsPost.with.operationId - Usage: workflow_delete
entity.data.dsl.do.searchSystemsPost.with.queryParams.limit
- Description: JumpCloud extension data on the managed entity:
dsl.do.searchSystemsPost.with.queryParams.limit. - Source:
resource.dsl.do.searchSystemsPost.with.queryParams.limit - Usage: workflow_delete
entity.data.dsl.do.searchSystemsPost.with.queryParams.skip
- Description: JumpCloud extension data on the managed entity:
dsl.do.searchSystemsPost.with.queryParams.skip. - Source:
resource.dsl.do.searchSystemsPost.with.queryParams.skip - Usage: workflow_delete
entity.data.dsl.do.searchSystemsPost.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.searchSystemsPost.with.version. - Source:
resource.dsl.do.searchSystemsPost.with.version - Usage: workflow_delete
entity.data.dsl.do.search_matching_user.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.search_matching_user.call. - Source:
resource.dsl.do.search_matching_user.call - Usage: workflow_create, workflow_delete
entity.data.dsl.do.search_matching_user.with.bodyParams.filter.and.username
- Description: JumpCloud extension data on the managed entity:
dsl.do.search_matching_user.with.bodyParams.filter.and.username. - Source:
resource.dsl.do.search_matching_user.with.bodyParams.filter.and.username - Usage: workflow_create, workflow_delete
entity.data.dsl.do.search_matching_user.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.search_matching_user.with.operationId. - Source:
resource.dsl.do.search_matching_user.with.operationId - Usage: workflow_create, workflow_delete
entity.data.dsl.do.search_matching_user.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.search_matching_user.with.version. - Source:
resource.dsl.do.search_matching_user.with.version - Usage: workflow_create, workflow_delete
entity.data.dsl.do.sendEmailAddresses.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.sendEmailAddresses.call. - Source:
resource.dsl.do.sendEmailAddresses.call - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.sendEmailAddresses.with.message.body
- Description: JumpCloud extension data on the managed entity:
dsl.do.sendEmailAddresses.with.message.body. - Source:
resource.dsl.do.sendEmailAddresses.with.message.body - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.sendEmailAddresses.with.message.subject
- Description: JumpCloud extension data on the managed entity:
dsl.do.sendEmailAddresses.with.message.subject. - Source:
resource.dsl.do.sendEmailAddresses.with.message.subject - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.sendEmailAddresses.with.recipients.to_addresses
- Description: JumpCloud extension data on the managed entity:
dsl.do.sendEmailAddresses.with.recipients.to_addresses. - Source:
resource.dsl.do.sendEmailAddresses.with.recipients.to_addresses - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.sendEmailChannels.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.sendEmailChannels.call. - Source:
resource.dsl.do.sendEmailChannels.call - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.sendEmailChannels.with.message.body
- Description: JumpCloud extension data on the managed entity:
dsl.do.sendEmailChannels.with.message.body. - Source:
resource.dsl.do.sendEmailChannels.with.message.body - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.sendEmailChannels.with.message.subject
- Description: JumpCloud extension data on the managed entity:
dsl.do.sendEmailChannels.with.message.subject. - Source:
resource.dsl.do.sendEmailChannels.with.message.subject - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.sendEmailChannels.with.recipients.channel_object_ids
- Description: JumpCloud extension data on the managed entity:
dsl.do.sendEmailChannels.with.recipients.channel_object_ids. - Source:
resource.dsl.do.sendEmailChannels.with.recipients.channel_object_ids - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.sendSummaryEmail.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.sendSummaryEmail.call. - Source:
resource.dsl.do.sendSummaryEmail.call - Usage: workflow_create
entity.data.dsl.do.sendSummaryEmail.with.message.body
- Description: JumpCloud extension data on the managed entity:
dsl.do.sendSummaryEmail.with.message.body. - Source:
resource.dsl.do.sendSummaryEmail.with.message.body - Usage: workflow_create
entity.data.dsl.do.sendSummaryEmail.with.message.subject
- Description: JumpCloud extension data on the managed entity:
dsl.do.sendSummaryEmail.with.message.subject. - Source:
resource.dsl.do.sendSummaryEmail.with.message.subject - Usage: workflow_create
entity.data.dsl.do.sendSummaryEmail.with.recipients.to_addresses
- Description: JumpCloud extension data on the managed entity:
dsl.do.sendSummaryEmail.with.recipients.to_addresses. - Source:
resource.dsl.do.sendSummaryEmail.with.recipients.to_addresses - Usage: workflow_create
entity.data.dsl.do.stageUsers.do.addToStagingGroup.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.stageUsers.do.addToStagingGroup.call. - Source:
resource.dsl.do.stageUsers.do.addToStagingGroup.call - Usage: workflow_delete
entity.data.dsl.do.stageUsers.do.addToStagingGroup.with.bodyParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.stageUsers.do.addToStagingGroup.with.bodyParams.id. - Source:
resource.dsl.do.stageUsers.do.addToStagingGroup.with.bodyParams.id - Usage: workflow_delete
entity.data.dsl.do.stageUsers.do.addToStagingGroup.with.bodyParams.op
- Description: JumpCloud extension data on the managed entity:
dsl.do.stageUsers.do.addToStagingGroup.with.bodyParams.op. - Source:
resource.dsl.do.stageUsers.do.addToStagingGroup.with.bodyParams.op - Usage: workflow_delete
entity.data.dsl.do.stageUsers.do.addToStagingGroup.with.bodyParams.type
- Description: JumpCloud extension data on the managed entity:
dsl.do.stageUsers.do.addToStagingGroup.with.bodyParams.type. - Source:
resource.dsl.do.stageUsers.do.addToStagingGroup.with.bodyParams.type - Usage: workflow_delete
entity.data.dsl.do.stageUsers.do.addToStagingGroup.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.stageUsers.do.addToStagingGroup.with.operationId. - Source:
resource.dsl.do.stageUsers.do.addToStagingGroup.with.operationId - Usage: workflow_delete
entity.data.dsl.do.stageUsers.do.addToStagingGroup.with.pathParams.group_id
- Description: JumpCloud extension data on the managed entity:
dsl.do.stageUsers.do.addToStagingGroup.with.pathParams.group_id. - Source:
resource.dsl.do.stageUsers.do.addToStagingGroup.with.pathParams.group_id - Usage: workflow_delete
entity.data.dsl.do.stageUsers.do.addToStagingGroup.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.stageUsers.do.addToStagingGroup.with.version. - Source:
resource.dsl.do.stageUsers.do.addToStagingGroup.with.version - Usage: workflow_delete
entity.data.dsl.do.stageUsers.do.getManagerDetails.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.stageUsers.do.getManagerDetails.call. - Source:
resource.dsl.do.stageUsers.do.getManagerDetails.call - Usage: workflow_delete
entity.data.dsl.do.stageUsers.do.getManagerDetails.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.stageUsers.do.getManagerDetails.with.operationId. - Source:
resource.dsl.do.stageUsers.do.getManagerDetails.with.operationId - Usage: workflow_delete
entity.data.dsl.do.stageUsers.do.getManagerDetails.with.pathParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.stageUsers.do.getManagerDetails.with.pathParams.id. - Source:
resource.dsl.do.stageUsers.do.getManagerDetails.with.pathParams.id - Usage: workflow_delete
entity.data.dsl.do.stageUsers.do.getManagerDetails.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.stageUsers.do.getManagerDetails.with.version. - Source:
resource.dsl.do.stageUsers.do.getManagerDetails.with.version - Usage: workflow_delete
entity.data.dsl.do.stageUsers.do.getUserFullDetails.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.stageUsers.do.getUserFullDetails.call. - Source:
resource.dsl.do.stageUsers.do.getUserFullDetails.call - Usage: workflow_delete
entity.data.dsl.do.stageUsers.do.getUserFullDetails.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.stageUsers.do.getUserFullDetails.with.operationId. - Source:
resource.dsl.do.stageUsers.do.getUserFullDetails.with.operationId - Usage: workflow_delete
entity.data.dsl.do.stageUsers.do.getUserFullDetails.with.pathParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.stageUsers.do.getUserFullDetails.with.pathParams.id. - Source:
resource.dsl.do.stageUsers.do.getUserFullDetails.with.pathParams.id - Usage: workflow_delete
entity.data.dsl.do.stageUsers.do.getUserFullDetails.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.stageUsers.do.getUserFullDetails.with.version. - Source:
resource.dsl.do.stageUsers.do.getUserFullDetails.with.version - Usage: workflow_delete
entity.data.dsl.do.stageUsers.do.notifyManager.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.stageUsers.do.notifyManager.call. - Source:
resource.dsl.do.stageUsers.do.notifyManager.call - Usage: workflow_delete
entity.data.dsl.do.stageUsers.do.notifyManager.with.message.body
- Description: JumpCloud extension data on the managed entity:
dsl.do.stageUsers.do.notifyManager.with.message.body. - Source:
resource.dsl.do.stageUsers.do.notifyManager.with.message.body - Usage: workflow_delete
entity.data.dsl.do.stageUsers.do.notifyManager.with.message.subject
- Description: JumpCloud extension data on the managed entity:
dsl.do.stageUsers.do.notifyManager.with.message.subject. - Source:
resource.dsl.do.stageUsers.do.notifyManager.with.message.subject - Usage: workflow_delete
entity.data.dsl.do.stageUsers.do.notifyManager.with.recipients.to_addresses
- Description: JumpCloud extension data on the managed entity:
dsl.do.stageUsers.do.notifyManager.with.recipients.to_addresses. - Source:
resource.dsl.do.stageUsers.do.notifyManager.with.recipients.to_addresses - Usage: workflow_delete
entity.data.dsl.do.stageUsers.for.each
- Description: JumpCloud extension data on the managed entity:
dsl.do.stageUsers.for.each. - Source:
resource.dsl.do.stageUsers.for.each - Usage: workflow_delete
entity.data.dsl.do.stageUsers.for.in
- Description: JumpCloud extension data on the managed entity:
dsl.do.stageUsers.for.in. - Source:
resource.dsl.do.stageUsers.for.in - Usage: workflow_delete
entity.data.dsl.do.stageUsers.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.stageUsers.then. - Source:
resource.dsl.do.stageUsers.then - Usage: workflow_delete
entity.data.dsl.do.stripDelegation.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.stripDelegation.call. - Source:
resource.dsl.do.stripDelegation.call - Usage: workflow_create, workflow_delete
entity.data.dsl.do.stripDelegation.with.bodyParams.externally_managed
- Description: JumpCloud extension data on the managed entity:
dsl.do.stripDelegation.with.bodyParams.externally_managed. - Source:
resource.dsl.do.stripDelegation.with.bodyParams.externally_managed - Usage: workflow_create, workflow_delete
entity.data.dsl.do.stripDelegation.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.stripDelegation.with.operationId. - Source:
resource.dsl.do.stripDelegation.with.operationId - Usage: workflow_create, workflow_delete
entity.data.dsl.do.stripDelegation.with.pathParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.stripDelegation.with.pathParams.id. - Source:
resource.dsl.do.stripDelegation.with.pathParams.id - Usage: workflow_create, workflow_delete
entity.data.dsl.do.stripDelegation.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.stripDelegation.with.version. - Source:
resource.dsl.do.stripDelegation.with.version - Usage: workflow_create, workflow_delete
entity.data.dsl.do.summary.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.summary.call. - Source:
resource.dsl.do.summary.call - Usage: workflow_delete, workflow_update
entity.data.dsl.do.summary.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.summary.then. - Source:
resource.dsl.do.summary.then - Usage: workflow_delete, workflow_update
entity.data.dsl.do.summary.with.message.body
- Description: JumpCloud extension data on the managed entity:
dsl.do.summary.with.message.body. - Source:
resource.dsl.do.summary.with.message.body - Usage: workflow_delete, workflow_update
entity.data.dsl.do.summary.with.message.subject
- Description: JumpCloud extension data on the managed entity:
dsl.do.summary.with.message.subject. - Source:
resource.dsl.do.summary.with.message.subject - Usage: workflow_delete, workflow_update
entity.data.dsl.do.summary.with.recipients.channel_object_ids
- Description: JumpCloud extension data on the managed entity:
dsl.do.summary.with.recipients.channel_object_ids. - Source:
resource.dsl.do.summary.with.recipients.channel_object_ids - Usage: workflow_delete, workflow_update
entity.data.dsl.do.suspendAccount.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.suspendAccount.call. - Source:
resource.dsl.do.suspendAccount.call - Usage: workflow_delete
entity.data.dsl.do.suspendAccount.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.suspendAccount.with.operationId. - Source:
resource.dsl.do.suspendAccount.with.operationId - Usage: workflow_delete
entity.data.dsl.do.suspendAccount.with.pathParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.suspendAccount.with.pathParams.id. - Source:
resource.dsl.do.suspendAccount.with.pathParams.id - Usage: workflow_delete
entity.data.dsl.do.suspendAccount.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.suspendAccount.with.version. - Source:
resource.dsl.do.suspendAccount.with.version - Usage: workflow_delete
entity.data.dsl.do.suspendUser.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.suspendUser.call. - Source:
resource.dsl.do.suspendUser.call - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.suspendUser.metadata.displayLabels.user
- Description: JumpCloud extension data on the managed entity:
dsl.do.suspendUser.metadata.displayLabels.user. - Source:
resource.dsl.do.suspendUser.metadata.displayLabels.user - Usage: workflow_create, workflow_delete
entity.data.dsl.do.suspendUser.metadata.inputModes.user
- Description: JumpCloud extension data on the managed entity:
dsl.do.suspendUser.metadata.inputModes.user. - Source:
resource.dsl.do.suspendUser.metadata.inputModes.user - Usage: workflow_create, workflow_delete
entity.data.dsl.do.suspendUser.with.bodyParams.suspended
- Description: JumpCloud extension data on the managed entity:
dsl.do.suspendUser.with.bodyParams.suspended. - Source:
resource.dsl.do.suspendUser.with.bodyParams.suspended - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.suspendUser.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.suspendUser.with.operationId. - Source:
resource.dsl.do.suspendUser.with.operationId - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.suspendUser.with.pathParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.suspendUser.with.pathParams.id. - Source:
resource.dsl.do.suspendUser.with.pathParams.id - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.suspendUser.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.suspendUser.with.version. - Source:
resource.dsl.do.suspendUser.with.version - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.systemsGet.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.systemsGet.call. - Source:
resource.dsl.do.systemsGet.call - Usage: workflow_delete
entity.data.dsl.do.systemsGet.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.systemsGet.with.operationId. - Source:
resource.dsl.do.systemsGet.with.operationId - Usage: workflow_delete
entity.data.dsl.do.systemsGet.with.pathParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.systemsGet.with.pathParams.id. - Source:
resource.dsl.do.systemsGet.with.pathParams.id - Usage: workflow_delete
entity.data.dsl.do.systemsGet.with.queryParams.fields
- Description: JumpCloud extension data on the managed entity:
dsl.do.systemsGet.with.queryParams.fields. - Source:
resource.dsl.do.systemsGet.with.queryParams.fields - Usage: workflow_delete
entity.data.dsl.do.systemsGet.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.systemsGet.with.version. - Source:
resource.dsl.do.systemsGet.with.version - Usage: workflow_delete
entity.data.dsl.do.systemusersGet.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.systemusersGet.call. - Source:
resource.dsl.do.systemusersGet.call - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.systemusersGet.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.systemusersGet.with.operationId. - Source:
resource.dsl.do.systemusersGet.with.operationId - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.systemusersGet.with.pathParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.systemusersGet.with.pathParams.id. - Source:
resource.dsl.do.systemusersGet.with.pathParams.id - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.systemusersGet.with.queryParams.fields
- Description: JumpCloud extension data on the managed entity:
dsl.do.systemusersGet.with.queryParams.fields. - Source:
resource.dsl.do.systemusersGet.with.queryParams.fields - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.systemusersGet.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.systemusersGet.with.version. - Source:
resource.dsl.do.systemusersGet.with.version - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.systemusersList.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.systemusersList.call. - Source:
resource.dsl.do.systemusersList.call - Usage: workflow_create, workflow_delete
entity.data.dsl.do.systemusersList.with.extract
- Description: JumpCloud extension data on the managed entity:
dsl.do.systemusersList.with.extract. - Source:
resource.dsl.do.systemusersList.with.extract - Usage: workflow_delete
entity.data.dsl.do.systemusersList.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.systemusersList.with.operationId. - Source:
resource.dsl.do.systemusersList.with.operationId - Usage: workflow_create, workflow_delete
entity.data.dsl.do.systemusersList.with.pagination.until
- Description: JumpCloud extension data on the managed entity:
dsl.do.systemusersList.with.pagination.until. - Source:
resource.dsl.do.systemusersList.with.pagination.until - Usage: workflow_delete
entity.data.dsl.do.systemusersList.with.pagination.update.in
- Description: JumpCloud extension data on the managed entity:
dsl.do.systemusersList.with.pagination.update.in. - Source:
resource.dsl.do.systemusersList.with.pagination.update.in - Usage: workflow_delete
entity.data.dsl.do.systemusersList.with.pagination.update.key
- Description: JumpCloud extension data on the managed entity:
dsl.do.systemusersList.with.pagination.update.key. - Source:
resource.dsl.do.systemusersList.with.pagination.update.key - Usage: workflow_delete
entity.data.dsl.do.systemusersList.with.pagination.update.value
- Description: JumpCloud extension data on the managed entity:
dsl.do.systemusersList.with.pagination.update.value. - Source:
resource.dsl.do.systemusersList.with.pagination.update.value - Usage: workflow_delete
entity.data.dsl.do.systemusersList.with.queryParams.limit
- Description: JumpCloud extension data on the managed entity:
dsl.do.systemusersList.with.queryParams.limit. - Source:
resource.dsl.do.systemusersList.with.queryParams.limit - Usage: workflow_create, workflow_delete
entity.data.dsl.do.systemusersList.with.queryParams.skip
- Description: JumpCloud extension data on the managed entity:
dsl.do.systemusersList.with.queryParams.skip. - Source:
resource.dsl.do.systemusersList.with.queryParams.skip - Usage: workflow_create, workflow_delete
entity.data.dsl.do.systemusersList.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.systemusersList.with.version. - Source:
resource.dsl.do.systemusersList.with.version - Usage: workflow_create, workflow_delete
entity.data.dsl.do.systemusersPut.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.systemusersPut.call. - Source:
resource.dsl.do.systemusersPut.call - Usage: workflow_update
entity.data.dsl.do.systemusersPut.with.bodyParams.attributes
- Description: JumpCloud extension data on the managed entity:
dsl.do.systemusersPut.with.bodyParams.attributes. - Source:
resource.dsl.do.systemusersPut.with.bodyParams.attributes - Usage: workflow_update
entity.data.dsl.do.systemusersPut.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.systemusersPut.with.operationId. - Source:
resource.dsl.do.systemusersPut.with.operationId - Usage: workflow_update
entity.data.dsl.do.systemusersPut.with.pathParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.systemusersPut.with.pathParams.id. - Source:
resource.dsl.do.systemusersPut.with.pathParams.id - Usage: workflow_update
entity.data.dsl.do.systemusersPut.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.systemusersPut.with.version. - Source:
resource.dsl.do.systemusersPut.with.version - Usage: workflow_update
entity.data.dsl.do.systemusers_get.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.systemusers_get.call. - Source:
resource.dsl.do.systemusers_get.call - Usage: workflow_create, workflow_delete
entity.data.dsl.do.systemusers_get.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.systemusers_get.with.operationId. - Source:
resource.dsl.do.systemusers_get.with.operationId - Usage: workflow_create, workflow_delete
entity.data.dsl.do.systemusers_get.with.pathParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.systemusers_get.with.pathParams.id. - Source:
resource.dsl.do.systemusers_get.with.pathParams.id - Usage: workflow_create, workflow_delete
entity.data.dsl.do.systemusers_get.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.systemusers_get.with.version. - Source:
resource.dsl.do.systemusers_get.with.version - Usage: workflow_create, workflow_delete
entity.data.dsl.do.updateAssetStatus.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.updateAssetStatus.call. - Source:
resource.dsl.do.updateAssetStatus.call - Usage: workflow_create, workflow_delete
entity.data.dsl.do.updateAssetStatus.if
- Description: JumpCloud extension data on the managed entity:
dsl.do.updateAssetStatus.if. - Source:
resource.dsl.do.updateAssetStatus.if - Usage: workflow_create, workflow_delete
entity.data.dsl.do.updateAssetStatus.metadata.displayLabels.assetFields
- Description: JumpCloud extension data on the managed entity:
dsl.do.updateAssetStatus.metadata.displayLabels.assetFields. - Source:
resource.dsl.do.updateAssetStatus.metadata.displayLabels.assetFields - Usage: workflow_create
entity.data.dsl.do.updateAssetStatus.metadata.displayLabels.assetId
- Description: JumpCloud extension data on the managed entity:
dsl.do.updateAssetStatus.metadata.displayLabels.assetId. - Source:
resource.dsl.do.updateAssetStatus.metadata.displayLabels.assetId - Usage: workflow_create
entity.data.dsl.do.updateAssetStatus.metadata.inputModes.assetFields
- Description: JumpCloud extension data on the managed entity:
dsl.do.updateAssetStatus.metadata.inputModes.assetFields. - Source:
resource.dsl.do.updateAssetStatus.metadata.inputModes.assetFields - Usage: workflow_create
entity.data.dsl.do.updateAssetStatus.metadata.inputModes.assetId
- Description: JumpCloud extension data on the managed entity:
dsl.do.updateAssetStatus.metadata.inputModes.assetId. - Source:
resource.dsl.do.updateAssetStatus.metadata.inputModes.assetId - Usage: workflow_create
entity.data.dsl.do.updateAssetStatus.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.updateAssetStatus.then. - Source:
resource.dsl.do.updateAssetStatus.then - Usage: workflow_delete
entity.data.dsl.do.updateAssetStatus.with.bodyParams.fields.Name
- Description: JumpCloud extension data on the managed entity:
dsl.do.updateAssetStatus.with.bodyParams.fields.Name. - Source:
resource.dsl.do.updateAssetStatus.with.bodyParams.fields.Name - Usage: workflow_create, workflow_delete
entity.data.dsl.do.updateAssetStatus.with.bodyParams.fields.Status.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.updateAssetStatus.with.bodyParams.fields.Status.id. - Source:
resource.dsl.do.updateAssetStatus.with.bodyParams.fields.Status.id - Usage: workflow_create, workflow_delete
entity.data.dsl.do.updateAssetStatus.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.updateAssetStatus.with.operationId. - Source:
resource.dsl.do.updateAssetStatus.with.operationId - Usage: workflow_create, workflow_delete
entity.data.dsl.do.updateAssetStatus.with.pathParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.updateAssetStatus.with.pathParams.id. - Source:
resource.dsl.do.updateAssetStatus.with.pathParams.id - Usage: workflow_create, workflow_delete
entity.data.dsl.do.updateAssetStatus.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.updateAssetStatus.with.version. - Source:
resource.dsl.do.updateAssetStatus.with.version - Usage: workflow_create, workflow_delete
entity.data.dsl.do.updateAssetStatusWithType.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.updateAssetStatusWithType.call. - Source:
resource.dsl.do.updateAssetStatusWithType.call - Usage: workflow_create
entity.data.dsl.do.updateAssetStatusWithType.with.bodyParams.fields.Name
- Description: JumpCloud extension data on the managed entity:
dsl.do.updateAssetStatusWithType.with.bodyParams.fields.Name. - Source:
resource.dsl.do.updateAssetStatusWithType.with.bodyParams.fields.Name - Usage: workflow_create
entity.data.dsl.do.updateAssetStatusWithType.with.bodyParams.fields.Status.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.updateAssetStatusWithType.with.bodyParams.fields.Status.id. - Source:
resource.dsl.do.updateAssetStatusWithType.with.bodyParams.fields.Status.id - Usage: workflow_create
entity.data.dsl.do.updateAssetStatusWithType.with.bodyParams.fields.Type.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.updateAssetStatusWithType.with.bodyParams.fields.Type.id. - Source:
resource.dsl.do.updateAssetStatusWithType.with.bodyParams.fields.Type.id - Usage: workflow_create
entity.data.dsl.do.updateAssetStatusWithType.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.updateAssetStatusWithType.with.operationId. - Source:
resource.dsl.do.updateAssetStatusWithType.with.operationId - Usage: workflow_create
entity.data.dsl.do.updateAssetStatusWithType.with.pathParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.updateAssetStatusWithType.with.pathParams.id. - Source:
resource.dsl.do.updateAssetStatusWithType.with.pathParams.id - Usage: workflow_create
entity.data.dsl.do.updateAssetStatusWithType.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.updateAssetStatusWithType.with.version. - Source:
resource.dsl.do.updateAssetStatusWithType.with.version - Usage: workflow_create
entity.data.dsl.do.updateCustomAttribute.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.updateCustomAttribute.call. - Source:
resource.dsl.do.updateCustomAttribute.call - Usage: workflow_update
entity.data.dsl.do.updateCustomAttribute.with.bodyParams.attributes.name
- Description: JumpCloud extension data on the managed entity:
dsl.do.updateCustomAttribute.with.bodyParams.attributes.name. - Source:
resource.dsl.do.updateCustomAttribute.with.bodyParams.attributes.name - Usage: workflow_update
entity.data.dsl.do.updateCustomAttribute.with.bodyParams.attributes.value
- Description: JumpCloud extension data on the managed entity:
dsl.do.updateCustomAttribute.with.bodyParams.attributes.value. - Source:
resource.dsl.do.updateCustomAttribute.with.bodyParams.attributes.value - Usage: workflow_update
entity.data.dsl.do.updateCustomAttribute.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.updateCustomAttribute.with.operationId. - Source:
resource.dsl.do.updateCustomAttribute.with.operationId - Usage: workflow_update
entity.data.dsl.do.updateCustomAttribute.with.pathParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.updateCustomAttribute.with.pathParams.id. - Source:
resource.dsl.do.updateCustomAttribute.with.pathParams.id - Usage: workflow_update
entity.data.dsl.do.updateCustomAttribute.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.updateCustomAttribute.with.version. - Source:
resource.dsl.do.updateCustomAttribute.with.version - Usage: workflow_update
entity.data.dsl.do.updateCustomAttributes.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.updateCustomAttributes.call. - Source:
resource.dsl.do.updateCustomAttributes.call - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.updateCustomAttributes.with.bodyParams.attributes
- Description: JumpCloud extension data on the managed entity:
dsl.do.updateCustomAttributes.with.bodyParams.attributes. - Source:
resource.dsl.do.updateCustomAttributes.with.bodyParams.attributes - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.updateCustomAttributes.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.updateCustomAttributes.with.operationId. - Source:
resource.dsl.do.updateCustomAttributes.with.operationId - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.updateCustomAttributes.with.pathParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.updateCustomAttributes.with.pathParams.id. - Source:
resource.dsl.do.updateCustomAttributes.with.pathParams.id - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.updateCustomAttributes.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.updateCustomAttributes.with.version. - Source:
resource.dsl.do.updateCustomAttributes.with.version - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.do.updateIsApproved.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.updateIsApproved.call. - Source:
resource.dsl.do.updateIsApproved.call - Usage: workflow_update
entity.data.dsl.do.updateIsApproved.if
- Description: JumpCloud extension data on the managed entity:
dsl.do.updateIsApproved.if. - Source:
resource.dsl.do.updateIsApproved.if - Usage: workflow_update
entity.data.dsl.do.updateIsApproved.with.bodyParams.attributes
- Description: JumpCloud extension data on the managed entity:
dsl.do.updateIsApproved.with.bodyParams.attributes. - Source:
resource.dsl.do.updateIsApproved.with.bodyParams.attributes - Usage: workflow_update
entity.data.dsl.do.updateIsApproved.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.updateIsApproved.with.operationId. - Source:
resource.dsl.do.updateIsApproved.with.operationId - Usage: workflow_update
entity.data.dsl.do.updateIsApproved.with.pathParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.updateIsApproved.with.pathParams.id. - Source:
resource.dsl.do.updateIsApproved.with.pathParams.id - Usage: workflow_update
entity.data.dsl.do.updateIsApproved.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.updateIsApproved.with.version. - Source:
resource.dsl.do.updateIsApproved.with.version - Usage: workflow_update
entity.data.dsl.do.updateUserAttributes.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.updateUserAttributes.call. - Source:
resource.dsl.do.updateUserAttributes.call - Usage: workflow_delete
entity.data.dsl.do.updateUserAttributes.if
- Description: JumpCloud extension data on the managed entity:
dsl.do.updateUserAttributes.if. - Source:
resource.dsl.do.updateUserAttributes.if - Usage: workflow_delete
entity.data.dsl.do.updateUserAttributes.metadata.compositePocUpdateUserAttrs.attributePairs.name
- Description: JumpCloud extension data on the managed entity:
dsl.do.updateUserAttributes.metadata.compositePocUpdateUserAttrs.attributePairs.name. - Source:
resource.dsl.do.updateUserAttributes.metadata.compositePocUpdateUserAttrs.attributePairs.name - Usage: workflow_delete
entity.data.dsl.do.updateUserAttributes.metadata.compositePocUpdateUserAttrs.attributePairs.value
- Description: JumpCloud extension data on the managed entity:
dsl.do.updateUserAttributes.metadata.compositePocUpdateUserAttrs.attributePairs.value. - Source:
resource.dsl.do.updateUserAttributes.metadata.compositePocUpdateUserAttrs.attributePairs.value - Usage: workflow_delete
entity.data.dsl.do.updateUserAttributes.metadata.compositePocUpdateUserAttrs.getTaskName
- Description: JumpCloud extension data on the managed entity:
dsl.do.updateUserAttributes.metadata.compositePocUpdateUserAttrs.getTaskName. - Source:
resource.dsl.do.updateUserAttributes.metadata.compositePocUpdateUserAttrs.getTaskName - Usage: workflow_delete
entity.data.dsl.do.updateUserAttributes.metadata.compositePocUpdateUserAttrs.role
- Description: JumpCloud extension data on the managed entity:
dsl.do.updateUserAttributes.metadata.compositePocUpdateUserAttrs.role. - Source:
resource.dsl.do.updateUserAttributes.metadata.compositePocUpdateUserAttrs.role - Usage: workflow_delete
entity.data.dsl.do.updateUserAttributes.metadata.compositePocUpdateUserAttrs.templateId
- Description: JumpCloud extension data on the managed entity:
dsl.do.updateUserAttributes.metadata.compositePocUpdateUserAttrs.templateId. - Source:
resource.dsl.do.updateUserAttributes.metadata.compositePocUpdateUserAttrs.templateId - Usage: workflow_delete
entity.data.dsl.do.updateUserAttributes.metadata.displayLabels.__pocAttributes
- Description: JumpCloud extension data on the managed entity:
dsl.do.updateUserAttributes.metadata.displayLabels.__pocAttributes. - Source:
resource.dsl.do.updateUserAttributes.metadata.displayLabels.__pocAttributes - Usage: workflow_delete
entity.data.dsl.do.updateUserAttributes.with.bodyParams.attributes
- Description: JumpCloud extension data on the managed entity:
dsl.do.updateUserAttributes.with.bodyParams.attributes. - Source:
resource.dsl.do.updateUserAttributes.with.bodyParams.attributes - Usage: workflow_delete
entity.data.dsl.do.updateUserAttributes.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.updateUserAttributes.with.operationId. - Source:
resource.dsl.do.updateUserAttributes.with.operationId - Usage: workflow_delete
entity.data.dsl.do.updateUserAttributes.with.pathParams.id
- Description: JumpCloud extension data on the managed entity:
dsl.do.updateUserAttributes.with.pathParams.id. - Source:
resource.dsl.do.updateUserAttributes.with.pathParams.id - Usage: workflow_delete
entity.data.dsl.do.updateUserAttributes.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.updateUserAttributes.with.version. - Source:
resource.dsl.do.updateUserAttributes.with.version - Usage: workflow_delete
entity.data.dsl.do.userServiceGetAllUsers.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.userServiceGetAllUsers.call. - Source:
resource.dsl.do.userServiceGetAllUsers.call - Usage: workflow_delete
entity.data.dsl.do.userServiceGetAllUsers.with.extract
- Description: JumpCloud extension data on the managed entity:
dsl.do.userServiceGetAllUsers.with.extract. - Source:
resource.dsl.do.userServiceGetAllUsers.with.extract - Usage: workflow_delete
entity.data.dsl.do.userServiceGetAllUsers.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.userServiceGetAllUsers.with.operationId. - Source:
resource.dsl.do.userServiceGetAllUsers.with.operationId - Usage: workflow_delete
entity.data.dsl.do.userServiceGetAllUsers.with.pagination.until
- Description: JumpCloud extension data on the managed entity:
dsl.do.userServiceGetAllUsers.with.pagination.until. - Source:
resource.dsl.do.userServiceGetAllUsers.with.pagination.until - Usage: workflow_delete
entity.data.dsl.do.userServiceGetAllUsers.with.pagination.update.in
- Description: JumpCloud extension data on the managed entity:
dsl.do.userServiceGetAllUsers.with.pagination.update.in. - Source:
resource.dsl.do.userServiceGetAllUsers.with.pagination.update.in - Usage: workflow_delete
entity.data.dsl.do.userServiceGetAllUsers.with.pagination.update.key
- Description: JumpCloud extension data on the managed entity:
dsl.do.userServiceGetAllUsers.with.pagination.update.key. - Source:
resource.dsl.do.userServiceGetAllUsers.with.pagination.update.key - Usage: workflow_delete
entity.data.dsl.do.userServiceGetAllUsers.with.pagination.update.value
- Description: JumpCloud extension data on the managed entity:
dsl.do.userServiceGetAllUsers.with.pagination.update.value. - Source:
resource.dsl.do.userServiceGetAllUsers.with.pagination.update.value - Usage: workflow_delete
entity.data.dsl.do.userServiceGetAllUsers.with.queryParams.filter
- Description: JumpCloud extension data on the managed entity:
dsl.do.userServiceGetAllUsers.with.queryParams.filter. - Source:
resource.dsl.do.userServiceGetAllUsers.with.queryParams.filter - Usage: workflow_delete
entity.data.dsl.do.userServiceGetAllUsers.with.queryParams.limit
- Description: JumpCloud extension data on the managed entity:
dsl.do.userServiceGetAllUsers.with.queryParams.limit. - Source:
resource.dsl.do.userServiceGetAllUsers.with.queryParams.limit - Usage: workflow_delete
entity.data.dsl.do.userServiceGetAllUsers.with.queryParams.search
- Description: JumpCloud extension data on the managed entity:
dsl.do.userServiceGetAllUsers.with.queryParams.search. - Source:
resource.dsl.do.userServiceGetAllUsers.with.queryParams.search - Usage: workflow_delete
entity.data.dsl.do.userServiceGetAllUsers.with.queryParams.skip
- Description: JumpCloud extension data on the managed entity:
dsl.do.userServiceGetAllUsers.with.queryParams.skip. - Source:
resource.dsl.do.userServiceGetAllUsers.with.queryParams.skip - Usage: workflow_delete
entity.data.dsl.do.userServiceGetAllUsers.with.queryParams.sort
- Description: JumpCloud extension data on the managed entity:
dsl.do.userServiceGetAllUsers.with.queryParams.sort. - Source:
resource.dsl.do.userServiceGetAllUsers.with.queryParams.sort - Usage: workflow_delete
entity.data.dsl.do.userServiceGetAllUsers.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.userServiceGetAllUsers.with.version. - Source:
resource.dsl.do.userServiceGetAllUsers.with.version - Usage: workflow_delete
entity.data.dsl.do.verifyActiveStatus.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.verifyActiveStatus.call. - Source:
resource.dsl.do.verifyActiveStatus.call - Usage: workflow_create
entity.data.dsl.do.verifyActiveStatus.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.verifyActiveStatus.then. - Source:
resource.dsl.do.verifyActiveStatus.then - Usage: workflow_create
entity.data.dsl.do.verifyActiveStatus.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.verifyActiveStatus.with.operationId. - Source:
resource.dsl.do.verifyActiveStatus.with.operationId - Usage: workflow_create
entity.data.dsl.do.verifyActiveStatus.with.queryParams.limit
- Description: JumpCloud extension data on the managed entity:
dsl.do.verifyActiveStatus.with.queryParams.limit. - Source:
resource.dsl.do.verifyActiveStatus.with.queryParams.limit - Usage: workflow_create
entity.data.dsl.do.verifyActiveStatus.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.verifyActiveStatus.with.version. - Source:
resource.dsl.do.verifyActiveStatus.with.version - Usage: workflow_create
entity.data.dsl.do.verifyDefaultStatus.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.verifyDefaultStatus.call. - Source:
resource.dsl.do.verifyDefaultStatus.call - Usage: workflow_create
entity.data.dsl.do.verifyDefaultStatus.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.verifyDefaultStatus.then. - Source:
resource.dsl.do.verifyDefaultStatus.then - Usage: workflow_create
entity.data.dsl.do.verifyDefaultStatus.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.verifyDefaultStatus.with.operationId. - Source:
resource.dsl.do.verifyDefaultStatus.with.operationId - Usage: workflow_create
entity.data.dsl.do.verifyDefaultStatus.with.queryParams.limit
- Description: JumpCloud extension data on the managed entity:
dsl.do.verifyDefaultStatus.with.queryParams.limit. - Source:
resource.dsl.do.verifyDefaultStatus.with.queryParams.limit - Usage: workflow_create
entity.data.dsl.do.verifyDefaultStatus.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.verifyDefaultStatus.with.version. - Source:
resource.dsl.do.verifyDefaultStatus.with.version - Usage: workflow_create
entity.data.dsl.do.verifySuspendedStatus.call
- Description: JumpCloud extension data on the managed entity:
dsl.do.verifySuspendedStatus.call. - Source:
resource.dsl.do.verifySuspendedStatus.call - Usage: workflow_create
entity.data.dsl.do.verifySuspendedStatus.then
- Description: JumpCloud extension data on the managed entity:
dsl.do.verifySuspendedStatus.then. - Source:
resource.dsl.do.verifySuspendedStatus.then - Usage: workflow_create
entity.data.dsl.do.verifySuspendedStatus.with.operationId
- Description: JumpCloud extension data on the managed entity:
dsl.do.verifySuspendedStatus.with.operationId. - Source:
resource.dsl.do.verifySuspendedStatus.with.operationId - Usage: workflow_create
entity.data.dsl.do.verifySuspendedStatus.with.queryParams.limit
- Description: JumpCloud extension data on the managed entity:
dsl.do.verifySuspendedStatus.with.queryParams.limit. - Source:
resource.dsl.do.verifySuspendedStatus.with.queryParams.limit - Usage: workflow_create
entity.data.dsl.do.verifySuspendedStatus.with.version
- Description: JumpCloud extension data on the managed entity:
dsl.do.verifySuspendedStatus.with.version. - Source:
resource.dsl.do.verifySuspendedStatus.with.version - Usage: workflow_create
entity.data.dsl.input.schema.document.filters
- Description: JumpCloud extension data on the managed entity:
dsl.input.schema.document.filters. - Source:
resource.dsl.input.schema.document.filters - Usage: workflow_delete
entity.data.dsl.input.schema.document.properties.channelId.type
- Description: JumpCloud extension data on the managed entity:
dsl.input.schema.document.properties.channelId.type. - Source:
resource.dsl.input.schema.document.properties.channelId.type - Usage: workflow_delete, workflow_update
entity.data.dsl.input.schema.document.properties.commandId.type
- Description: JumpCloud extension data on the managed entity:
dsl.input.schema.document.properties.commandId.type. - Source:
resource.dsl.input.schema.document.properties.commandId.type - Usage: workflow_delete
entity.data.dsl.input.schema.document.properties.defenderExclusionPath.type
- Description: JumpCloud extension data on the managed entity:
dsl.input.schema.document.properties.defenderExclusionPath.type. - Source:
resource.dsl.input.schema.document.properties.defenderExclusionPath.type - Usage: workflow_delete
entity.data.dsl.input.schema.document.properties.elevatedGroupId.type
- Description: JumpCloud extension data on the managed entity:
dsl.input.schema.document.properties.elevatedGroupId.type. - Source:
resource.dsl.input.schema.document.properties.elevatedGroupId.type - Usage: workflow_delete
entity.data.dsl.input.schema.document.properties.id.description
- Description: JumpCloud extension data on the managed entity:
dsl.input.schema.document.properties.id.description. - Source:
resource.dsl.input.schema.document.properties.id.description - Usage: workflow_create
entity.data.dsl.input.schema.document.properties.id.type
- Description: JumpCloud extension data on the managed entity:
dsl.input.schema.document.properties.id.type. - Source:
resource.dsl.input.schema.document.properties.id.type - Usage: workflow_create
entity.data.dsl.input.schema.document.properties.itReviewChannelId.type
- Description: JumpCloud extension data on the managed entity:
dsl.input.schema.document.properties.itReviewChannelId.type. - Source:
resource.dsl.input.schema.document.properties.itReviewChannelId.type - Usage: workflow_delete
entity.data.dsl.input.schema.document.properties.jobTitle.type
- Description: JumpCloud extension data on the managed entity:
dsl.input.schema.document.properties.jobTitle.type. - Source:
resource.dsl.input.schema.document.properties.jobTitle.type - Usage: workflow_delete
entity.data.dsl.input.schema.document.properties.name.type
- Description: JumpCloud extension data on the managed entity:
dsl.input.schema.document.properties.name.type. - Source:
resource.dsl.input.schema.document.properties.name.type - Usage: workflow_delete
entity.data.dsl.input.schema.document.properties.opsChannelId.type
- Description: JumpCloud extension data on the managed entity:
dsl.input.schema.document.properties.opsChannelId.type. - Source:
resource.dsl.input.schema.document.properties.opsChannelId.type - Usage: workflow_delete
entity.data.dsl.input.schema.document.properties.previousJobTitle.type
- Description: JumpCloud extension data on the managed entity:
dsl.input.schema.document.properties.previousJobTitle.type. - Source:
resource.dsl.input.schema.document.properties.previousJobTitle.type - Usage: workflow_delete
entity.data.dsl.input.schema.document.properties.stagingGroupId.type
- Description: JumpCloud extension data on the managed entity:
dsl.input.schema.document.properties.stagingGroupId.type. - Source:
resource.dsl.input.schema.document.properties.stagingGroupId.type - Usage: workflow_delete
entity.data.dsl.input.schema.document.properties.userId.description
- Description: JumpCloud extension data on the managed entity:
dsl.input.schema.document.properties.userId.description. - Source:
resource.dsl.input.schema.document.properties.userId.description - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.input.schema.document.properties.userId.type
- Description: JumpCloud extension data on the managed entity:
dsl.input.schema.document.properties.userId.type. - Source:
resource.dsl.input.schema.document.properties.userId.type - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.input.schema.document.required
- Description: JumpCloud extension data on the managed entity:
dsl.input.schema.document.required. - Source:
resource.dsl.input.schema.document.required - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.input.schema.document.type
- Description: JumpCloud extension data on the managed entity:
dsl.input.schema.document.type. - Source:
resource.dsl.input.schema.document.type - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.input.schema.format
- Description: JumpCloud extension data on the managed entity:
dsl.input.schema.format. - Source:
resource.dsl.input.schema.format - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.schedule.day_of_week
- Description: JumpCloud extension data on the managed entity:
dsl.schedule.day_of_week. - Source:
resource.dsl.schedule.day_of_week - Usage: workflow_create
entity.data.dsl.schedule.frequency
- Description: JumpCloud extension data on the managed entity:
dsl.schedule.frequency. - Source:
resource.dsl.schedule.frequency - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.schedule.interval
- Description: JumpCloud extension data on the managed entity:
dsl.schedule.interval. - Source:
resource.dsl.schedule.interval - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.schedule.on.one.with.condition
- Description: JumpCloud extension data on the managed entity:
dsl.schedule.on.one.with.condition. - Source:
resource.dsl.schedule.on.one.with.condition - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.schedule.on.one.with.source
- Description: JumpCloud extension data on the managed entity:
dsl.schedule.on.one.with.source. - Source:
resource.dsl.schedule.on.one.with.source - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.schedule.on.one.with.type
- Description: JumpCloud extension data on the managed entity:
dsl.schedule.on.one.with.type. - Source:
resource.dsl.schedule.on.one.with.type - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.schedule.start_date
- Description: JumpCloud extension data on the managed entity:
dsl.schedule.start_date. - Source:
resource.dsl.schedule.start_date - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.schedule.start_time
- Description: JumpCloud extension data on the managed entity:
dsl.schedule.start_time. - Source:
resource.dsl.schedule.start_time - Usage: workflow_create, workflow_delete, workflow_update
entity.data.dsl.schedule.time
- Description: JumpCloud extension data on the managed entity:
dsl.schedule.time. - Source:
resource.dsl.schedule.time - Usage: workflow_create, workflow_delete
entity.data.dsl.schedule.timezone
- Description: JumpCloud extension data on the managed entity:
dsl.schedule.timezone. - Source:
resource.dsl.schedule.timezone - Usage: workflow_create, workflow_delete, workflow_update
entity.data.status
- Description: JumpCloud extension data on the managed entity:
status. - Source:
resource.status - Usage: workflow_create, workflow_delete, workflow_update
entity.name
- Description: The name of the managed entity. It should match the name of the specific entity object's name if populated, or the name of the managed entity if the
type_idis 'Other'. - Source:
resource.name - Usage: workflow_create, workflow_delete, workflow_update
entity.type
- Description: The managed entity type. For example:
Policy,User,Organization,Device. - Source:
resource.type - Usage: workflow_create, workflow_delete, workflow_update
entity.uid
- Description: The identifier of the managed entity. It should match the
uidof the specific entity's object UID if populated, or the source specific ID if thetype_idis 'Other'. - Source:
resource.id - Usage: workflow_create, workflow_delete, workflow_update
entity_result.data.changes_to_do_activateUser2_call
- Description: JumpCloud extension data on the managed entity:
changes_to_do_activateUser2_call. - Source:
changes.to.do.activateUser2.call - Usage: workflow_update
entity_result.data.changes_to_do_activateUser2_metadata_displayLabels_email
- Description: JumpCloud extension data on the managed entity:
changes_to_do_activateUser2_metadata_displayLabels_email. - Source:
changes.to.do.activateUser2.metadata.displayLabels.email - Usage: workflow_update
entity_result.data.changes_to_do_activateUser2_metadata_displayLabels_user
- Description: JumpCloud extension data on the managed entity:
changes_to_do_activateUser2_metadata_displayLabels_user. - Source:
changes.to.do.activateUser2.metadata.displayLabels.user - Usage: workflow_update
entity_result.data.changes_to_do_activateUser2_metadata_inputModes_email
- Description: JumpCloud extension data on the managed entity:
changes_to_do_activateUser2_metadata_inputModes_email. - Source:
changes.to.do.activateUser2.metadata.inputModes.email - Usage: workflow_update
entity_result.data.changes_to_do_activateUser2_metadata_inputModes_user
- Description: JumpCloud extension data on the managed entity:
changes_to_do_activateUser2_metadata_inputModes_user. - Source:
changes.to.do.activateUser2.metadata.inputModes.user - Usage: workflow_update
entity_result.data.changes_to_do_activateUser2_with_bodyParams_email
- Description: JumpCloud extension data on the managed entity:
changes_to_do_activateUser2_with_bodyParams_email. - Source:
changes.to.do.activateUser2.with.bodyParams.email - Usage: workflow_update
entity_result.data.changes_to_do_activateUser2_with_operationId
- Description: JumpCloud extension data on the managed entity:
changes_to_do_activateUser2_with_operationId. - Source:
changes.to.do.activateUser2.with.operationId - Usage: workflow_update
entity_result.data.changes_to_do_activateUser2_with_pathParams_id
- Description: JumpCloud extension data on the managed entity:
changes_to_do_activateUser2_with_pathParams_id. - Source:
changes.to.do.activateUser2.with.pathParams.id - Usage: workflow_update
entity_result.data.changes_to_do_activateUser2_with_version
- Description: JumpCloud extension data on the managed entity:
changes_to_do_activateUser2_with_version. - Source:
changes.to.do.activateUser2.with.version - Usage: workflow_update
entity_result.data.changes_to_do_activateUser_call
- Description: JumpCloud extension data on the managed entity:
changes_to_do_activateUser_call. - Source:
changes.to.do.activateUser.call - Usage: workflow_update
entity_result.data.changes_to_do_activateUser_metadata_displayLabels_email
- Description: JumpCloud extension data on the managed entity:
changes_to_do_activateUser_metadata_displayLabels_email. - Source:
changes.to.do.activateUser.metadata.displayLabels.email - Usage: workflow_update
entity_result.data.changes_to_do_activateUser_metadata_displayLabels_user
- Description: JumpCloud extension data on the managed entity:
changes_to_do_activateUser_metadata_displayLabels_user. - Source:
changes.to.do.activateUser.metadata.displayLabels.user - Usage: workflow_update
entity_result.data.changes_to_do_activateUser_metadata_inputModes_email
- Description: JumpCloud extension data on the managed entity:
changes_to_do_activateUser_metadata_inputModes_email. - Source:
changes.to.do.activateUser.metadata.inputModes.email - Usage: workflow_update
entity_result.data.changes_to_do_activateUser_metadata_inputModes_user
- Description: JumpCloud extension data on the managed entity:
changes_to_do_activateUser_metadata_inputModes_user. - Source:
changes.to.do.activateUser.metadata.inputModes.user - Usage: workflow_update
entity_result.data.changes_to_do_activateUser_with_bodyParams_email
- Description: JumpCloud extension data on the managed entity:
changes_to_do_activateUser_with_bodyParams_email. - Source:
changes.to.do.activateUser.with.bodyParams.email - Usage: workflow_update
entity_result.data.changes_to_do_activateUser_with_operationId
- Description: JumpCloud extension data on the managed entity:
changes_to_do_activateUser_with_operationId. - Source:
changes.to.do.activateUser.with.operationId - Usage: workflow_update
entity_result.data.changes_to_do_activateUser_with_pathParams_id
- Description: JumpCloud extension data on the managed entity:
changes_to_do_activateUser_with_pathParams_id. - Source:
changes.to.do.activateUser.with.pathParams.id - Usage: workflow_update
entity_result.data.changes_to_do_activateUser_with_version
- Description: JumpCloud extension data on the managed entity:
changes_to_do_activateUser_with_version. - Source:
changes.to.do.activateUser.with.version - Usage: workflow_update
entity_result.data.changes_to_do_callConnector_call
- Description: JumpCloud extension data on the managed entity:
changes_to_do_callConnector_call. - Source:
changes.to.do.callConnector.call - Usage: workflow_update
entity_result.data.changes_to_do_callConnector_with_body_data
- Description: JumpCloud extension data on the managed entity:
changes_to_do_callConnector_with_body_data. - Source:
changes.to.do.callConnector.with.body.data - Usage: workflow_update
entity_result.data.changes_to_do_callConnector_with_body_id
- Description: JumpCloud extension data on the managed entity:
changes_to_do_callConnector_with_body_id. - Source:
changes.to.do.callConnector.with.body.id - Usage: workflow_update
entity_result.data.changes_to_do_callConnector_with_body_timestamp
- Description: JumpCloud extension data on the managed entity:
changes_to_do_callConnector_with_body_timestamp. - Source:
changes.to.do.callConnector.with.body.timestamp - Usage: workflow_update
entity_result.data.changes_to_do_callConnector_with_endpointPath
- Description: JumpCloud extension data on the managed entity:
changes_to_do_callConnector_with_endpointPath. - Source:
changes.to.do.callConnector.with.endpointPath - Usage: workflow_update
entity_result.data.changes_to_do_callConnector_with_headers_Accept
- Description: JumpCloud extension data on the managed entity:
changes_to_do_callConnector_with_headers_Accept. - Source:
changes.to.do.callConnector.with.headers.Accept - Usage: workflow_update
entity_result.data.changes_to_do_callConnector_with_headers_EWrwer
- Description: JumpCloud extension data on the managed entity:
changes_to_do_callConnector_with_headers_EWrwer. - Source:
changes.to.do.callConnector.with.headers.EWrwer - Usage: workflow_update
entity_result.data.changes_to_do_callConnector_with_headers_ew
- Description: JumpCloud extension data on the managed entity:
changes_to_do_callConnector_with_headers_ew. - Source:
changes.to.do.callConnector.with.headers.ew - Usage: workflow_update
entity_result.data.changes_to_do_callConnector_with_headers_ewd
- Description: JumpCloud extension data on the managed entity:
changes_to_do_callConnector_with_headers_ewd. - Source:
changes.to.do.callConnector.with.headers.ewd - Usage: workflow_update
entity_result.data.changes_to_do_callConnector_with_headers_ewe
- Description: JumpCloud extension data on the managed entity:
changes_to_do_callConnector_with_headers_ewe. - Source:
changes.to.do.callConnector.with.headers.ewe - Usage: workflow_update
entity_result.data.changes_to_do_callConnector_with_httpMethod
- Description: JumpCloud extension data on the managed entity:
changes_to_do_callConnector_with_httpMethod. - Source:
changes.to.do.callConnector.with.httpMethod - Usage: workflow_update
entity_result.data.changes_to_do_callConnector_with_id
- Description: JumpCloud extension data on the managed entity:
changes_to_do_callConnector_with_id. - Source:
changes.to.do.callConnector.with.id - Usage: workflow_update
entity_result.data.changes_to_do_checkActivated_call
- Description: JumpCloud extension data on the managed entity:
changes_to_do_checkActivated_call. - Source:
changes.to.do.checkActivated.call - Usage: workflow_update
entity_result.data.changes_to_do_checkActivated_if
- Description: JumpCloud extension data on the managed entity:
changes_to_do_checkActivated_if. - Source:
changes.to.do.checkActivated.if - Usage: workflow_update
entity_result.data.changes_to_do_checkActivated_with_operationId
- Description: JumpCloud extension data on the managed entity:
changes_to_do_checkActivated_with_operationId. - Source:
changes.to.do.checkActivated.with.operationId - Usage: workflow_update
entity_result.data.changes_to_do_checkActivated_with_pathParams_id
- Description: JumpCloud extension data on the managed entity:
changes_to_do_checkActivated_with_pathParams_id. - Source:
changes.to.do.checkActivated.with.pathParams.id - Usage: workflow_update
entity_result.data.changes_to_do_checkActivated_with_queryParams_fields
- Description: JumpCloud extension data on the managed entity:
changes_to_do_checkActivated_with_queryParams_fields. - Source:
changes.to.do.checkActivated.with.queryParams.fields - Usage: workflow_update
entity_result.data.changes_to_do_checkActivated_with_version
- Description: JumpCloud extension data on the managed entity:
changes_to_do_checkActivated_with_version. - Source:
changes.to.do.checkActivated.with.version - Usage: workflow_update
entity_result.data.changes_to_do_checkDelegatedAuthorityExists_call
- Description: JumpCloud extension data on the managed entity:
changes_to_do_checkDelegatedAuthorityExists_call. - Source:
changes.to.do.checkDelegatedAuthorityExists.call - Usage: workflow_update
entity_result.data.changes_to_do_checkDelegatedAuthorityExists_if
- Description: JumpCloud extension data on the managed entity:
changes_to_do_checkDelegatedAuthorityExists_if. - Source:
changes.to.do.checkDelegatedAuthorityExists.if - Usage: workflow_update
entity_result.data.changes_to_do_checkDelegatedAuthorityExists_with_operationId
- Description: JumpCloud extension data on the managed entity:
changes_to_do_checkDelegatedAuthorityExists_with_operationId. - Source:
changes.to.do.checkDelegatedAuthorityExists.with.operationId - Usage: workflow_update
entity_result.data.changes_to_do_checkDelegatedAuthorityExists_with_pathParams_id
- Description: JumpCloud extension data on the managed entity:
changes_to_do_checkDelegatedAuthorityExists_with_pathParams_id. - Source:
changes.to.do.checkDelegatedAuthorityExists.with.pathParams.id - Usage: workflow_update
entity_result.data.changes_to_do_checkDelegatedAuthorityExists_with_queryParams_fields
- Description: JumpCloud extension data on the managed entity:
changes_to_do_checkDelegatedAuthorityExists_with_queryParams_fields. - Source:
changes.to.do.checkDelegatedAuthorityExists.with.queryParams.fields - Usage: workflow_update
entity_result.data.changes_to_do_checkDelegatedAuthorityExists_with_version
- Description: JumpCloud extension data on the managed entity:
changes_to_do_checkDelegatedAuthorityExists_with_version. - Source:
changes.to.do.checkDelegatedAuthorityExists.with.version - Usage: workflow_update
entity_result.data.changes_to_do_checkPasswordDate_call
- Description: JumpCloud extension data on the managed entity:
changes_to_do_checkPasswordDate_call. - Source:
changes.to.do.checkPasswordDate.call - Usage: workflow_update
entity_result.data.changes_to_do_checkPasswordDate_if
- Description: JumpCloud extension data on the managed entity:
changes_to_do_checkPasswordDate_if. - Source:
changes.to.do.checkPasswordDate.if - Usage: workflow_update
entity_result.data.changes_to_do_checkPasswordDate_with_operationId
- Description: JumpCloud extension data on the managed entity:
changes_to_do_checkPasswordDate_with_operationId. - Source:
changes.to.do.checkPasswordDate.with.operationId - Usage: workflow_update
entity_result.data.changes_to_do_checkPasswordDate_with_pathParams_id
- Description: JumpCloud extension data on the managed entity:
changes_to_do_checkPasswordDate_with_pathParams_id. - Source:
changes.to.do.checkPasswordDate.with.pathParams.id - Usage: workflow_update
entity_result.data.changes_to_do_checkPasswordDate_with_queryParams_fields
- Description: JumpCloud extension data on the managed entity:
changes_to_do_checkPasswordDate_with_queryParams_fields. - Source:
changes.to.do.checkPasswordDate.with.queryParams.fields - Usage: workflow_update
entity_result.data.changes_to_do_checkPasswordDate_with_version
- Description: JumpCloud extension data on the managed entity:
changes_to_do_checkPasswordDate_with_version. - Source:
changes.to.do.checkPasswordDate.with.version - Usage: workflow_update
entity_result.data.changes_to_do_getUser_call
- Description: JumpCloud extension data on the managed entity:
changes_to_do_getUser_call. - Source:
changes.to.do.getUser.call - Usage: workflow_update
entity_result.data.changes_to_do_getUser_with_operationId
- Description: JumpCloud extension data on the managed entity:
changes_to_do_getUser_with_operationId. - Source:
changes.to.do.getUser.with.operationId - Usage: workflow_update
entity_result.data.changes_to_do_getUser_with_pathParams_id
- Description: JumpCloud extension data on the managed entity:
changes_to_do_getUser_with_pathParams_id. - Source:
changes.to.do.getUser.with.pathParams.id - Usage: workflow_update
entity_result.data.changes_to_do_getUser_with_version
- Description: JumpCloud extension data on the managed entity:
changes_to_do_getUser_with_version. - Source:
changes.to.do.getUser.with.version - Usage: workflow_update
entity_result.data.changes_to_do_removeDelegatedAuthority_call
- Description: JumpCloud extension data on the managed entity:
changes_to_do_removeDelegatedAuthority_call. - Source:
changes.to.do.removeDelegatedAuthority.call - Usage: workflow_update
entity_result.data.changes_to_do_removeDelegatedAuthority_if
- Description: JumpCloud extension data on the managed entity:
changes_to_do_removeDelegatedAuthority_if. - Source:
changes.to.do.removeDelegatedAuthority.if - Usage: workflow_update
entity_result.data.changes_to_do_removeDelegatedAuthority_with_bodyParams_delegatedAuthority
- Description: JumpCloud extension data on the managed entity:
changes_to_do_removeDelegatedAuthority_with_bodyParams_delegatedAuthority. - Source:
changes.to.do.removeDelegatedAuthority.with.bodyParams.delegatedAuthority - Usage: workflow_update
entity_result.data.changes_to_do_removeDelegatedAuthority_with_operationId
- Description: JumpCloud extension data on the managed entity:
changes_to_do_removeDelegatedAuthority_with_operationId. - Source:
changes.to.do.removeDelegatedAuthority.with.operationId - Usage: workflow_update
entity_result.data.changes_to_do_removeDelegatedAuthority_with_pathParams_id
- Description: JumpCloud extension data on the managed entity:
changes_to_do_removeDelegatedAuthority_with_pathParams_id. - Source:
changes.to.do.removeDelegatedAuthority.with.pathParams.id - Usage: workflow_update
entity_result.data.changes_to_do_removeDelegatedAuthority_with_version
- Description: JumpCloud extension data on the managed entity:
changes_to_do_removeDelegatedAuthority_with_version. - Source:
changes.to.do.removeDelegatedAuthority.with.version - Usage: workflow_update
entity_result.data.changes_to_do_sendEmailAddresses_call
- Description: JumpCloud extension data on the managed entity:
changes_to_do_sendEmailAddresses_call. - Source:
changes.to.do.sendEmailAddresses.call - Usage: workflow_update
entity_result.data.changes_to_do_sendEmailAddresses_with_message_body
- Description: JumpCloud extension data on the managed entity:
changes_to_do_sendEmailAddresses_with_message_body. - Source:
changes.to.do.sendEmailAddresses.with.message.body - Usage: workflow_update
entity_result.data.changes_to_do_sendEmailAddresses_with_message_subject
- Description: JumpCloud extension data on the managed entity:
changes_to_do_sendEmailAddresses_with_message_subject. - Source:
changes.to.do.sendEmailAddresses.with.message.subject - Usage: workflow_update
entity_result.data.changes_to_do_sendEmailAddresses_with_recipients_to_addresses
- Description: JumpCloud extension data on the managed entity:
changes_to_do_sendEmailAddresses_with_recipients_to_addresses. - Source:
changes.to.do.sendEmailAddresses.with.recipients.to_addresses - Usage: workflow_update
entity_result.data.changes_to_do_systemusersGet_call
- Description: JumpCloud extension data on the managed entity:
changes_to_do_systemusersGet_call. - Source:
changes.to.do.systemusersGet.call - Usage: workflow_update
entity_result.data.changes_to_do_systemusersGet_with_operationId
- Description: JumpCloud extension data on the managed entity:
changes_to_do_systemusersGet_with_operationId. - Source:
changes.to.do.systemusersGet.with.operationId - Usage: workflow_update
entity_result.data.changes_to_do_systemusersGet_with_pathParams_id
- Description: JumpCloud extension data on the managed entity:
changes_to_do_systemusersGet_with_pathParams_id. - Source:
changes.to.do.systemusersGet.with.pathParams.id - Usage: workflow_update
entity_result.data.changes_to_do_systemusersGet_with_queryParams_fields
- Description: JumpCloud extension data on the managed entity:
changes_to_do_systemusersGet_with_queryParams_fields. - Source:
changes.to.do.systemusersGet.with.queryParams.fields - Usage: workflow_update
entity_result.data.changes_to_do_systemusersGet_with_version
- Description: JumpCloud extension data on the managed entity:
changes_to_do_systemusersGet_with_version. - Source:
changes.to.do.systemusersGet.with.version - Usage: workflow_update
entity_result.data.changes_to_do_updateIsApproved_call
- Description: JumpCloud extension data on the managed entity:
changes_to_do_updateIsApproved_call. - Source:
changes.to.do.updateIsApproved.call - Usage: workflow_update
entity_result.data.changes_to_do_updateIsApproved_if
- Description: JumpCloud extension data on the managed entity:
changes_to_do_updateIsApproved_if. - Source:
changes.to.do.updateIsApproved.if - Usage: workflow_update
entity_result.data.changes_to_do_updateIsApproved_with_bodyParams_attributes
- Description: JumpCloud extension data on the managed entity:
changes_to_do_updateIsApproved_with_bodyParams_attributes. - Source:
changes.to.do.updateIsApproved.with.bodyParams.attributes - Usage: workflow_update
entity_result.data.changes_to_do_updateIsApproved_with_operationId
- Description: JumpCloud extension data on the managed entity:
changes_to_do_updateIsApproved_with_operationId. - Source:
changes.to.do.updateIsApproved.with.operationId - Usage: workflow_update
entity_result.data.changes_to_do_updateIsApproved_with_pathParams_id
- Description: JumpCloud extension data on the managed entity:
changes_to_do_updateIsApproved_with_pathParams_id. - Source:
changes.to.do.updateIsApproved.with.pathParams.id - Usage: workflow_update
entity_result.data.changes_to_do_updateIsApproved_with_version
- Description: JumpCloud extension data on the managed entity:
changes_to_do_updateIsApproved_with_version. - Source:
changes.to.do.updateIsApproved.with.version - Usage: workflow_update
entity_result.data.changes_to_schedule_frequency
- Description: JumpCloud extension data on the managed entity:
changes_to_schedule_frequency. - Source:
changes.to.schedule.frequency - Usage: workflow_update
entity_result.data.changes_to_schedule_interval
- Description: JumpCloud extension data on the managed entity:
changes_to_schedule_interval. - Source:
changes.to.schedule.interval - Usage: workflow_update
entity_result.data.changes_to_schedule_on_one_with_condition
- Description: JumpCloud extension data on the managed entity:
changes_to_schedule_on_one_with_condition. - Source:
changes.to.schedule.on.one.with.condition - Usage: workflow_update
entity_result.data.changes_to_schedule_on_one_with_source
- Description: JumpCloud extension data on the managed entity:
changes_to_schedule_on_one_with_source. - Source:
changes.to.schedule.on.one.with.source - Usage: workflow_update
entity_result.data.changes_to_schedule_on_one_with_type
- Description: JumpCloud extension data on the managed entity:
changes_to_schedule_on_one_with_type. - Source:
changes.to.schedule.on.one.with.type - Usage: workflow_update
entity_result.data.changes_to_schedule_start_date
- Description: JumpCloud extension data on the managed entity:
changes_to_schedule_start_date. - Source:
changes.to.schedule.start_date - Usage: workflow_update
entity_result.data.changes_to_schedule_start_time
- Description: JumpCloud extension data on the managed entity:
changes_to_schedule_start_time. - Source:
changes.to.schedule.start_time - Usage: workflow_update
entity_result.data.changes_to_schedule_timezone
- Description: JumpCloud extension data on the managed entity:
changes_to_schedule_timezone. - Source:
changes.to.schedule.timezone - Usage: workflow_update
Src Endpoint
src_endpoint.autonomous_system.name
- Description: Organization name for the Autonomous System.
- Source:
asn.organization - Usage: workflow_create, workflow_delete
src_endpoint.autonomous_system.number
- Description: Unique number that the AS is identified by.
- Source:
asn.number - Transform:
asn.number→int(workflow_create, workflow_delete)- Usage: workflow_create, workflow_delete
src_endpoint.ip
- Description: Source IP address the request originated from.
- Source:
client_ip - Usage: workflow_create, workflow_delete, workflow_update
src_endpoint.location.city
- Description: The name of the city.
- Source:
geoip.city - Usage: workflow_create, workflow_delete, workflow_update
src_endpoint.location.continent
- Description: The name of the continent.
- Source:
geoip.continent_code - Usage: workflow_create, workflow_delete, workflow_update
src_endpoint.location.country
- Description: The ISO 3166-1 Alpha-2 country code.
Note: The two letter country code should be capitalized. For example:
USorCA. - Source:
geoip.country_code - Usage: workflow_create, workflow_delete, workflow_update
src_endpoint.location.lat
- Description: The geographical Latitude coordinate represented in Decimal Degrees (DD). For example:
42.361145. - Source:
geoip.latitude - Transform:
geoip.latitude→double(workflow_create, workflow_delete, workflow_update)- Usage: workflow_create, workflow_delete, workflow_update
src_endpoint.location.long
- Description: The geographical Longitude coordinate represented in Decimal Degrees (DD). For example:
-71.057083. - Source:
geoip.longitude - Transform:
geoip.longitude→double(workflow_create, workflow_delete, workflow_update)- Usage: workflow_create, workflow_delete, workflow_update
src_endpoint.location.region
- Description: The alphanumeric code that identifies the principal subdivision (e.g. province or state) of the country. For example, 'CH-VD' for the Canton of Vaud, Switzerland
- Source:
geoip.region_code - Usage: workflow_create, workflow_delete, workflow_update
Http Request
http_request.user_agent
- Description: The request header that identifies the operating system and web browser.
- Source:
user_agent - Usage: workflow_create, workflow_delete, workflow_update
Observables
observables[].name
- Description: The full name of the observable attribute. The
nameis a pointer/reference to an attribute within the OCSF event data. For example:file.name. Array attributes may be represented in one of three ways. For example:resources.uid,resources[].uid,resources[0].uid. - Literal:
actor.user.uid,http_request.user_agent,src_endpoint.ip,src_endpoint.location.country - Usage: all events in this service
observables[].type_id
- Description: The observable value type identifier.
- Literal:
14,16,2,31 - Usage: all events in this service
observables[].value
- Description: The value associated with the observable attribute. The meaning of the value depends on the observable type.
If thenamerefers to a scalar attribute, then thevalueis the value of the attribute.
If thenamerefers to an object attribute, then thevalueis not populated. - Source:
client_ip,geoip.country_code,initiated_by.id,user_agent - Usage: all events in this service
Other
job.run_state
- Description: The run state of the job.
- Source:
resource.status - Usage: workflow_run, workflow_run_rate_limited
Unmapped
unmapped.@version
- Description: JumpCloud Directory Insights field
@versionpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
@version - Usage: all events in this service
unmapped.asn.network
- Description: JumpCloud Directory Insights field
asn.networkpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
asn.network - Usage: workflow_create, workflow_delete
unmapped.client_ip
- Description: JumpCloud Directory Insights field
client_ippreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
client_ip - Usage: workflow_run, workflow_run_rate_limited
unmapped.geoip.region_name
- Description: JumpCloud Directory Insights field
geoip.region_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.region_name - Usage: workflow_create, workflow_delete, workflow_update
unmapped.geoip.timezone
- Description: JumpCloud Directory Insights field
geoip.timezonepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
geoip.timezone - Usage: workflow_create, workflow_delete, workflow_update
unmapped.initiated_by_id_hash
- Description: JumpCloud Directory Insights field
initiated_by_id_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
initiated_by_id_hash - Usage: all events in this service
unmapped.is_out_of_bound
- Description: JumpCloud Directory Insights field
is_out_of_boundpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
is_out_of_bound - Usage: all events in this service
unmapped.jc_application_name
- Description: JumpCloud Directory Insights field
jc_application_namepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_application_name - Usage: all events in this service
unmapped.jc_transformation_ts
- Description: JumpCloud Directory Insights field
jc_transformation_tspreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
jc_transformation_ts - Usage: all events in this service
unmapped.resource.id
- Description: JumpCloud Directory Insights field
resource.idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.id - Usage: workflow_run, workflow_run_rate_limited
unmapped.resource.meta_data.event_id
- Description: JumpCloud Directory Insights field
resource.meta_data.event_idpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.meta_data.event_id - Usage: workflow_run
unmapped.resource.meta_data.event_type
- Description: JumpCloud Directory Insights field
resource.meta_data.event_typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.meta_data.event_type - Usage: workflow_run
unmapped.resource.meta_data.trigger_source
- Description: JumpCloud Directory Insights field
resource.meta_data.trigger_sourcepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.meta_data.trigger_source - Usage: workflow_run, workflow_run_rate_limited
unmapped.resource.type
- Description: JumpCloud Directory Insights field
resource.typepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource.type - Usage: workflow_run, workflow_run_rate_limited
unmapped.resource_id_hash
- Description: JumpCloud Directory Insights field
resource_id_hashpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
resource_id_hash - Usage: all events in this service
unmapped.timestamp_source
- Description: JumpCloud Directory Insights field
timestamp_sourcepreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
timestamp_source - Usage: all events in this service
unmapped.user_agent
- Description: JumpCloud Directory Insights field
user_agentpreserved in the OCSFunmappedobject (no dedicated OCSF mapping). - Source:
user_agent - Usage: workflow_run, workflow_run_rate_limited