SessionClosed due to content policy violation
Description of the message: Emitted when content policy with termination action enabled is violated
Example message:
{"verdict":"TERMINATED","timestamp":"1568640063579","severity":"0","session_id":"svc-9S9nqpGqdns6GAJxULWjHp-my_connection-53","server_username":"root","server_port":"22","server_name":"server.acme.com","server_address":"10.170.255.206","protocol":"SSH","event_type_id":"449510124","event_name":"SessionClosed","connection_policy":"my_connection","client_port":"45946","client_name":"client.acme.com","client_address":"10.30.0.24","base_type_name":"meta","auth_method":"password","gateway_username":"gwtestauto"}
The message contains the following fields.
| Field  | Name  | Scope  | Present  | 
| base_type_name | Basic type | message | always | 
Description: basic message type: meta
Example: meta
| Field  | Name  | Scope  | Present  | 
| event_type_id | Signature ID | message | always | 
Description: numeric identifier of message type
Example: 449510124
| Field  | Name  | Scope  | Present  | 
| event_name | Event name | message | always | 
Description: the type of the message
Example: SessionClosed
| Field  | Name  | Scope  | Present  | 
| session_id | Session ID | session | always | 
Description: the unique identifier of the session
Example: svc-hjdBxA2UWkTadH3juDVwrT-my_connection-0
| Field  | Name  | Scope  | Present  | 
| severity | Severity | message | always | 
Description: number between 0-10 inclusive, equal to aggregated analytics score divided by 10 or 0 if analytics is disabled
Example: 0
| Field  | Name  | Scope  | Present  | 
| timestamp | Timestamp | message | always | 
Description: the UNIX time stamp when the event occurred
Example: 1554470652340
| Field  | Name  | Scope  | Present  | 
| server_username | Server user | session | always | 
Description: the server username
Example: root
| Field  | Name  | Scope  | Present  | 
| server_domain | Server user domain if known | session | sometimes | 
Description: the server domain, if known
Example: acme.com
| Field  | Name  | Scope  | Present  | 
| gateway_username | Gateway username | session | sometimes | 
Description: the authenticated gateway username if there was a successful gateway authentication
Example: gwtestauto
| Field  | Name  | Scope  | Present  | 
| gateway_domain | Gateway user domain | session | sometimes | 
Description: the authenticated gateway user domain if there was a successful gateway authentication and known
Example: acme.com
| Field  | Name  | Scope  | Present  | 
| server_name | Server name | session | always | 
Description: the server hostname or IP address if hostname is not known
Example: server.acme.com
| Field  | Name  | Scope  | Present  | 
| server_address | Server address | session | always | 
Description: the IP address of the server
Example: 10.170.255.206
| Field  | Name  | Scope  | Present  | 
| server_port | Server port | session | always | 
Description: the port number on the server
Example: 22
| Field  | Name  | Scope  | Present  | 
| client_name | Client name | session | always | 
Description: the client hostname or IP address if hostname is not known
Example: client.acme.com
| Field  | Name  | Scope  | Present  | 
| client_address | Client address | session | always | 
Description: the IP address of the client
Example: 10.30.0.24
| Field  | Name  | Scope  | Present  | 
| client_port | Client port | session | always | 
Description: the port number on the client
Example: 38014
| Field  | Name  | Scope  | Present  | 
| protocol | Application protocol | session | always | 
Description: SPS supported protocol
Example: SSH
| Field  | Name  | Scope  | Present  | 
| connection_policy | Connection policy name | session | always | 
Description: SPS connection policy name
Example: my_connection
| Field  | Name  | Scope  | Present  | 
| auth_method | Authentication method | session | always | 
Description: the type of authentication used in gateway authentication
Example: password
| Field  | Name  | Scope  | Present  | 
| verdict | Verdict | session | always | 
Description: describes how the session ended, e.g. ACCEPT, AUTH_FAIL, DENY, FAIL, TERMINATED
Example: TERMINATED
 
ChannelAlert triggered
Description of the message: Emitted when channel alert triggered by content policy
Example message:
{"event_type_id":"1244069864","event_name":"ChannelAlert","session_id":"svc-eyKp4M2pDBpbwHW4nCSe36-my_connection-14","severity":"0","timestamp":"1567509110329","server_username":"root", "gateway_username":"gwtestauto","server_name":"server.acme.com","server_address":"10.170.255.206","server_port":"22","client_name":"client.acme.com","client_address":"10.30.0.24","client_port":"56988","protocol":"SSH","connection_policy":"my_connection","base_type_name":"content_alert","alerting_type":"adp.event.command","matched_regexp":"sudo","matched_content":"sudo","rule_name":"PatternMatcherRule"}
The message contains the following fields.
| Field  | Name  | Scope  | Present  | 
| event_type_id | Signature ID | message | always | 
Description: numeric identifier of message type
Example: 1244069864
| Field  | Name  | Scope  | Present  | 
| event_name | Event name | message | always | 
Description: the type of the message
Example: ChannelAlert
| Field  | Name  | Scope  | Present  | 
| session_id | Session ID | session | always | 
Description: the unique identifier of the session
Example: svc-hjdBxA2UWkTadH3juDVwrT-my_connection-0
| Field  | Name  | Scope  | Present  | 
| severity | Severity | message | always | 
Description: number between 0-10 inclusive, equal to aggregated analytics score divided by 10 or 0 if analytics is disabled
Example: 0
| Field  | Name  | Scope  | Present  | 
| timestamp | Timestamp | message | always | 
Description: the UNIX time stamp when the event occurred
Example: 1554470652340
| Field  | Name  | Scope  | Present  | 
| server_username | Server user | session | always | 
Description: the server username
Example: root
| Field  | Name  | Scope  | Present  | 
| gateway_username | Gateway username | session | sometimes | 
Description: the authenticated gateway username if there was a successful gateway authentication
Example: gwtestauto
| Field  | Name  | Scope  | Present  | 
| server_name | Server name | session | always | 
Description: the server hostname or IP address if hostname is not known
Example: server.acme.com
| Field  | Name  | Scope  | Present  | 
| server_address | Server address | session | always | 
Description: the IP address of the server
Example: 10.170.255.206
| Field  | Name  | Scope  | Present  | 
| server_port | Server port | session | always | 
Description: the port number on the server
Example: 22
| Field  | Name  | Scope  | Present  | 
| client_name | Client name | session | always | 
Description: the client hostname or IP address if hostname is not known
Example: client.acme.com
| Field  | Name  | Scope  | Present  | 
| client_address | Client address | session | always | 
Description: the IP address of the client
Example: 10.30.0.24
| Field  | Name  | Scope  | Present  | 
| client_port | Client port | session | always | 
Description: the port number on the client
Example: 38014
| Field  | Name  | Scope  | Present  | 
| protocol | Application protocol | session | always | 
Description: SPS supported protocol
Example: SSH
| Field  | Name  | Scope  | Present  | 
| connection_policy | Connection policy name | session | always | 
Description: SPS connection policy name
Example: my_connection
| Field  | Name  | Scope  | Present  | 
| base_type_name | Basic type | message | always | 
Description: basic message type: content_alert
Example: content_alert
| Field  | Name  | Scope  | Present  | 
| alerting_type | Event type | message | sometimes | 
Description: the type of the event triggering the alert e.g. Command, Full screen content
Example: Command
| Field  | Name  | Scope  | Present  | 
| matched_regexp | Matched regexp | message | sometimes | 
Description: the regexp matching the content that triggered the alert
Example: sudo
| Field  | Name  | Scope  | Present  | 
| matched_content | Matched content | message | sometimes | 
Description: the screen content violating channel policy
Example: $ sudo
| Field  | Name  | Scope  | Present  | 
| rule_name | Reason | message | sometimes | 
Description: the rule triggering alert
Example: PatternMatcherRule
 
Description of the message: Emitted when SPS connects to the serverfor the first time in the session
Example message:
{"timestamp":"1557913242888","severity":"0","session_id":"svc-iiCfsG48oJG5smpuocBLAN-my_connection-43","server_port":"22","server_name":"server.acme.com","server_address":"10.170.255.206","protocol":"SSH","gateway_username":"gwtestauto","event_type_id":"107115592","event_name":"ServerConnect","connection_policy":"my_connection","client_port":"59190","client_name":"client.acme.com","client_address":"10.30.0.24","base_type_name":"meta"}
The message contains the following fields.
| Field  | Name  | Scope  | Present  | 
| base_type_name | Basic type | message | always | 
Description: basic message type: meta
Example: meta
| Field  | Name  | Scope  | Present  | 
| event_type_id | Signature ID | message | always | 
Description: numeric identifier of message type
Example: 107115592
| Field  | Name  | Scope  | Present  | 
| event_name | Event name | message | always | 
Description: the type of the message
Example: ServerConnect
| Field  | Name  | Scope  | Present  | 
| session_id | Session ID | session | always | 
Description: the unique identifier of the session
Example: svc-hjdBxA2UWkTadH3juDVwrT-my_connection-0
| Field  | Name  | Scope  | Present  | 
| severity | Severity | message | always | 
Description: number between 0-10 inclusive, equal to aggregated analytics score divided by 10 or 0 if analytics is disabled
Example: 0
| Field  | Name  | Scope  | Present  | 
| timestamp | Timestamp | message | always | 
Description: the UNIX time stamp when the event occurred
Example: 1554470652340
| Field  | Name  | Scope  | Present  | 
| gateway_username | Gateway username | session | sometimes | 
Description: the authenticated gateway username if there was a successful gateway authentication
Example: gwtestauto
| Field  | Name  | Scope  | Present  | 
| gateway_domain | Gateway user domain | session | sometimes | 
Description: the authenticated gateway user domain if there was a successful gateway authentication and known
Example: acme.com
| Field  | Name  | Scope  | Present  | 
| server_name | Server name | session | always | 
Description: the server hostname or IP address if hostname is not known
Example: server.acme.com
| Field  | Name  | Scope  | Present  | 
| server_address | Server address | session | always | 
Description: the IP address of the server
Example: 10.170.255.206
| Field  | Name  | Scope  | Present  | 
| server_port | Server port | session | always | 
Description: the port number on the server
Example: 22
| Field  | Name  | Scope  | Present  | 
| client_name | Client name | session | always | 
Description: the client hostname or IP address if hostname is not known
Example: client.acme.com
| Field  | Name  | Scope  | Present  | 
| client_address | Client address | session | always | 
Description: the IP address of the client
Example: 10.30.0.24
| Field  | Name  | Scope  | Present  | 
| client_port | Client port | session | always | 
Description: the port number on the client
Example: 38014
| Field  | Name  | Scope  | Present  | 
| protocol | Application protocol | session | always | 
Description: SPS supported protocol
Example: SSH
| Field  | Name  | Scope  | Present  | 
| connection_policy | Connection policy name | session | always | 
Description: SPS connection policy name
Example: my_connection
 
ServerConnect for secondary channels
Description of the message: Emitted when SPS connects to the serverfor opening further channels. The difference from initial connection is that the server user name is known and authenticated this time.
Example message:
{"timestamp":"1557913242888","severity":"0","session_id":"svc-iiCfsG48oJG5smpuocBLAN-my_connection-43","server_port":"22","server_name":"server.acme.com","server_address":"10.170.255.206","protocol":"SSH","gateway_username":"gwtestauto","event_type_id":"107115592","event_name":"ServerConnect","connection_policy":"my_connection","server_username":"root","client_port":"59190","client_name":"client.acme.com","client_address":"10.30.0.24","base_type_name":"meta"}
The message contains the following fields.
| Field  | Name  | Scope  | Present  | 
| base_type_name | Basic type | message | always | 
Description: basic message type: meta
Example: meta
| Field  | Name  | Scope  | Present  | 
| event_type_id | Signature ID | message | always | 
Description: numeric identifier of message type
Example: 107115592
| Field  | Name  | Scope  | Present  | 
| event_name | Event name | message | always | 
Description: the type of the message
Example: ServerConnect
| Field  | Name  | Scope  | Present  | 
| session_id | Session ID | session | always | 
Description: the unique identifier of the session
Example: svc-hjdBxA2UWkTadH3juDVwrT-my_connection-0
| Field  | Name  | Scope  | Present  | 
| severity | Severity | message | always | 
Description: number between 0-10 inclusive, equal to aggregated analytics score divided by 10 or 0 if analytics is disabled
Example: 0
| Field  | Name  | Scope  | Present  | 
| timestamp | Timestamp | message | always | 
Description: the UNIX time stamp when the event occurred
Example: 1554470652340
| Field  | Name  | Scope  | Present  | 
| server_username | Server user | session | always | 
Description: the server username
Example: root
| Field  | Name  | Scope  | Present  | 
| server_domain | Server user domain if known | session | sometimes | 
Description: the server domain, if known
Example: acme.com
| Field  | Name  | Scope  | Present  | 
| gateway_username | Gateway username | session | sometimes | 
Description: the authenticated gateway username if there was a successful gateway authentication
Example: gwtestauto
| Field  | Name  | Scope  | Present  | 
| gateway_domain | Gateway user domain | session | sometimes | 
Description: the authenticated gateway user domain if there was a successful gateway authentication and known
Example: acme.com
| Field  | Name  | Scope  | Present  | 
| server_name | Server name | session | always | 
Description: the server hostname or IP address if hostname is not known
Example: server.acme.com
| Field  | Name  | Scope  | Present  | 
| server_address | Server address | session | always | 
Description: the IP address of the server
Example: 10.170.255.206
| Field  | Name  | Scope  | Present  | 
| server_port | Server port | session | always | 
Description: the port number on the server
Example: 22
| Field  | Name  | Scope  | Present  | 
| client_name | Client name | session | always | 
Description: the client hostname or IP address if hostname is not known
Example: client.acme.com
| Field  | Name  | Scope  | Present  | 
| client_address | Client address | session | always | 
Description: the IP address of the client
Example: 10.30.0.24
| Field  | Name  | Scope  | Present  | 
| client_port | Client port | session | always | 
Description: the port number on the client
Example: 38014
| Field  | Name  | Scope  | Present  | 
| protocol | Application protocol | session | always | 
Description: SPS supported protocol
Example: SSH
| Field  | Name  | Scope  | Present  | 
| connection_policy | Connection policy name | session | always | 
Description: SPS connection policy name
Example: my_connection
 
ServerAuthenticationSuccess
Description of the message: Emitted after the server authentication successfully happened
Example message:
{"timestamp":"1557913243423","severity":"0","session_id":"svc-iiCfsG48oJG5smpuocBLAN-my_connection-43","server_username":"root","server_port":"22","server_name":"server.acme.com","server_address":"10.170.255.206","protocol":"SSH","gateway_username":"gwtestauto","event_type_id":"1865245228","event_name":"ServerAuthenticationSuccess","connection_policy":"my_connection","client_port":"59190","client_name":"client.acme.com","client_address":"10.30.0.24","base_type_name":"meta"}
The message contains the following fields.
| Field  | Name  | Scope  | Present  | 
| base_type_name | Basic type | message | always | 
Description: basic message type: meta
Example: meta
| Field  | Name  | Scope  | Present  | 
| event_type_id | Signature ID | message | always | 
Description: numeric identifier of message type
Example: 1865245228
| Field  | Name  | Scope  | Present  | 
| event_name | Event name | message | always | 
Description: the type of the message
Example: ServerAuthenticationSuccess
| Field  | Name  | Scope  | Present  | 
| session_id | Session ID | session | always | 
Description: the unique identifier of the session
Example: svc-hjdBxA2UWkTadH3juDVwrT-my_connection-0
| Field  | Name  | Scope  | Present  | 
| severity | Severity | message | always | 
Description: number between 0-10 inclusive, equal to aggregated analytics score divided by 10 or 0 if analytics is disabled
Example: 0
| Field  | Name  | Scope  | Present  | 
| timestamp | Timestamp | message | always | 
Description: the UNIX time stamp when the event occurred
Example: 1554470652340
| Field  | Name  | Scope  | Present  | 
| server_username | Server user | session | always | 
Description: the server username
Example: root
| Field  | Name  | Scope  | Present  | 
| server_domain | Server user domain if known | session | sometimes | 
Description: the server domain, if known
Example: acme.com
| Field  | Name  | Scope  | Present  | 
| gateway_username | Gateway username | session | sometimes | 
Description: the authenticated gateway username if there was a successful gateway authentication
Example: gwtestauto
| Field  | Name  | Scope  | Present  | 
| gateway_domain | Gateway user domain | session | sometimes | 
Description: the authenticated gateway user domain if there was a successful gateway authentication and known
Example: acme.com
| Field  | Name  | Scope  | Present  | 
| server_name | Server name | session | always | 
Description: the server hostname or IP address if hostname is not known
Example: server.acme.com
| Field  | Name  | Scope  | Present  | 
| server_address | Server address | session | always | 
Description: the IP address of the server
Example: 10.170.255.206
| Field  | Name  | Scope  | Present  | 
| server_port | Server port | session | always | 
Description: the port number on the server
Example: 22
| Field  | Name  | Scope  | Present  | 
| client_name | Client name | session | always | 
Description: the client hostname or IP address if hostname is not known
Example: client.acme.com
| Field  | Name  | Scope  | Present  | 
| client_address | Client address | session | always | 
Description: the IP address of the client
Example: 10.30.0.24
| Field  | Name  | Scope  | Present  | 
| client_port | Client port | session | always | 
Description: the port number on the client
Example: 38014
| Field  | Name  | Scope  | Present  | 
| protocol | Application protocol | session | always | 
Description: SPS supported protocol
Example: SSH
| Field  | Name  | Scope  | Present  | 
| connection_policy | Connection policy name | session | always | 
Description: SPS connection policy name
Example: my_connection
 
ServerAuthenticationFailure
Description of the message: Emitted after the server authentication failed
Example message:
{"timestamp":"1557913134598","severity":"0","session_id":"svc-iiCfsG48oJG5smpuocBLAN-my_connection-33","server_username":"root","server_port":"22","server_name":"server.acme.com","server_address":"10.170.255.206","protocol":"SSH","gateway_username":"gwtestauto","event_type_id":"1262825953","event_name":"ServerAuthenticationFailure","connection_policy":"my_connection","client_port":"56692","client_name":"client.acme.com","client_address":"10.30.0.24","base_type_name":"meta"}
The message contains the following fields.
| Field  | Name  | Scope  | Present  | 
| base_type_name | Basic type | message | always | 
Description: basic message type: meta
Example: meta
| Field  | Name  | Scope  | Present  | 
| event_type_id | Signature ID | message | always | 
Description: numeric identifier of message type
Example: 1262825953
| Field  | Name  | Scope  | Present  | 
| event_name | Event name | message | always | 
Description: the type of the message
Example: ServerAuthenticationFailure
| Field  | Name  | Scope  | Present  | 
| session_id | Session ID | session | always | 
Description: the unique identifier of the session
Example: svc-hjdBxA2UWkTadH3juDVwrT-my_connection-0
| Field  | Name  | Scope  | Present  | 
| severity | Severity | message | always | 
Description: number between 0-10 inclusive, equal to aggregated analytics score divided by 10 or 0 if analytics is disabled
Example: 0
| Field  | Name  | Scope  | Present  | 
| timestamp | Timestamp | message | always | 
Description: the UNIX time stamp when the event occurred
Example: 1554470652340
| Field  | Name  | Scope  | Present  | 
| server_username | Server user | session | always | 
Description: contains the non authenticated server username
Example: root
| Field  | Name  | Scope  | Present  | 
| server_domain | Server user domain if known | session | sometimes | 
Description: the non authenticated server domain, if known
Example: acme.com
| Field  | Name  | Scope  | Present  | 
| gateway_username | Gateway username | session | sometimes | 
Description: the authenticated gateway username if there was a successful gateway authentication
Example: gwtestauto
| Field  | Name  | Scope  | Present  | 
| gateway_domain | Gateway user domain | session | sometimes | 
Description: the authenticated gateway user domain if there was a successful gateway authentication and known
Example: acme.com
| Field  | Name  | Scope  | Present  | 
| server_name | Server name | session | always | 
Description: the server hostname or IP address if hostname is not known
Example: server.acme.com
| Field  | Name  | Scope  | Present  | 
| server_address | Server address | session | always | 
Description: the IP address of the server
Example: 10.170.255.206
| Field  | Name  | Scope  | Present  | 
| server_port | Server port | session | always | 
Description: the port number on the server
Example: 22
| Field  | Name  | Scope  | Present  | 
| client_name | Client name | session | always | 
Description: the client hostname or IP address if hostname is not known
Example: client.acme.com
| Field  | Name  | Scope  | Present  | 
| client_address | Client address | session | always | 
Description: the IP address of the client
Example: 10.30.0.24
| Field  | Name  | Scope  | Present  | 
| client_port | Client port | session | always | 
Description: the port number on the client
Example: 38014
| Field  | Name  | Scope  | Present  | 
| protocol | Application protocol | session | always | 
Description: SPS supported protocol
Example: SSH
| Field  | Name  | Scope  | Present  | 
| connection_policy | Connection policy name | session | always | 
Description: SPS connection policy name
Example: my_connection
 
GatewayAuthenticationFailure
Description of the message: Emitted after a failed gateway authentication. Note that the gateway username here is not authenticated and will not be retained in further messages to avoid confusion with an authenticated gateway user.
Example message:
{"timestamp":"1557913110027","severity":"0","session_id":"svc-iiCfsG48oJG5smpuocBLAN-my_connection-31","protocol":"SSH","gateway_username":"gwtestauto","event_type_id":"1843867026","event_name":"GatewayAuthenticationFailure","connection_policy":"my_connection","client_port":"56020","client_name":"client.acme.com","client_address":"10.30.0.24","base_type_name":"meta"}
The message contains the following fields.
| Field  | Name  | Scope  | Present  | 
| base_type_name | Basic type | message | always | 
Description: basic message type: meta
Example: meta
| Field  | Name  | Scope  | Present  | 
| event_type_id | Signature ID | message | always | 
Description: numeric identifier of message type
Example: 1843867026
| Field  | Name  | Scope  | Present  | 
| event_name | Event name | message | always | 
Description: the type of the message
Example: GatewayAuthenticationFailure
| Field  | Name  | Scope  | Present  | 
| session_id | Session ID | session | always | 
Description: the unique identifier of the session
Example: svc-hjdBxA2UWkTadH3juDVwrT-my_connection-0
| Field  | Name  | Scope  | Present  | 
| severity | Severity | message | always | 
Description: number between 0-10 inclusive, equal to aggregated analytics score divided by 10 or 0 if analytics is disabled
Example: 0
| Field  | Name  | Scope  | Present  | 
| timestamp | Timestamp | message | always | 
Description: the UNIX time stamp when the event occurred
Example: 1554470652340
| Field  | Name  | Scope  | Present  | 
| gateway_username | Gateway username | message | always | 
Description: the non authenticated gateway username
Example: gwtestauto
| Field  | Name  | Scope  | Present  | 
| gateway_username | Gateway user domain | session | sometimes | 
Description: the non authenticated gateway user domain if known
Example: acme.com
| Field  | Name  | Scope  | Present  | 
| client_name | Client name | session | always | 
Description: the client hostname or IP address if hostname is not known
Example: client.acme.com
| Field  | Name  | Scope  | Present  | 
| client_address | Client address | session | always | 
Description: the IP address of the client
Example: 10.30.0.24
| Field  | Name  | Scope  | Present  | 
| client_port | Client port | session | always | 
Description: the port number on the client
Example: 38014
| Field  | Name  | Scope  | Present  | 
| protocol | Application protocol | session | always | 
Description: SPS supported protocol
Example: SSH
| Field  | Name  | Scope  | Present  | 
| connection_policy | Connection policy name | session | always | 
Description: SPS connection policy name
Example: my_connection
 
SessionClosed of successfully authenticated session
Description of the message: Emitted when the session ends and server authentication and any gateway authentication was successful. There may be further messages related to the session after this message due to post processing of session data!
Example message:
{"timestamp":"1557912701233","severity":"0","session_id":"svc-mBbMWzauBWHQN9TpoZz8mD-my_connection-6","server_username":"root","server_port":"22","server_name":"server.acme.com","server_address":"10.170.255.206","protocol":"SSH","gateway_username":"gwtestauto","event_type_id":"449510124","event_name":"SessionClosed","connection_policy":"my_connection","client_port":"46958","client_name":"client.acme.com","client_address":"10.30.0.24","base_type_name":"meta","auth_method":"password","verdict":"ACCEPT"}
The message contains the following fields.
| Field  | Name  | Scope  | Present  | 
| base_type_name | Basic type | message | always | 
Description: basic message type: meta
Example: meta
| Field  | Name  | Scope  | Present  | 
| event_type_id | Signature ID | message | always | 
Description: numeric identifier of message type
Example: 449510124
| Field  | Name  | Scope  | Present  | 
| event_name | Event name | message | always | 
Description: the type of the message
Example: SessionClosed
| Field  | Name  | Scope  | Present  | 
| session_id | Session ID | session | always | 
Description: the unique identifier of the session
Example: svc-hjdBxA2UWkTadH3juDVwrT-my_connection-0
| Field  | Name  | Scope  | Present  | 
| severity | Severity | message | always | 
Description: number between 0-10 inclusive, equal to aggregated analytics score divided by 10 or 0 if analytics is disabled
Example: 0
| Field  | Name  | Scope  | Present  | 
| timestamp | Timestamp | message | always | 
Description: the UNIX time stamp when the event occurred
Example: 1554470652340
| Field  | Name  | Scope  | Present  | 
| server_username | Server user | session | always | 
Description: the server username
Example: root
| Field  | Name  | Scope  | Present  | 
| server_domain | Server user domain if known | session | sometimes | 
Description: the server domain, if known
Example: acme.com
| Field  | Name  | Scope  | Present  | 
| gateway_username | Gateway username | session | sometimes | 
Description: the authenticated gateway username if there was a successful gateway authentication
Example: gwtestauto
| Field  | Name  | Scope  | Present  | 
| gateway_domain | Gateway user domain | session | sometimes | 
Description: the authenticated gateway user domain if there was a successful gateway authentication and known
Example: acme.com
| Field  | Name  | Scope  | Present  | 
| server_name | Server name | session | always | 
Description: the server hostname or IP address if hostname is not known
Example: server.acme.com
| Field  | Name  | Scope  | Present  | 
| server_address | Server address | session | always | 
Description: the IP address of the server
Example: 10.170.255.206
| Field  | Name  | Scope  | Present  | 
| server_port | Server port | session | always | 
Description: the port number on the server
Example: 22
| Field  | Name  | Scope  | Present  | 
| client_name | Client name | session | always | 
Description: the client hostname or IP address if hostname is not known
Example: client.acme.com
| Field  | Name  | Scope  | Present  | 
| client_address | Client address | session | always | 
Description: the IP address of the client
Example: 10.30.0.24
| Field  | Name  | Scope  | Present  | 
| client_port | Client port | session | always | 
Description: the port number on the client
Example: 38014
| Field  | Name  | Scope  | Present  | 
| protocol | Application protocol | session | always | 
Description: SPS supported protocol
Example: SSH
| Field  | Name  | Scope  | Present  | 
| connection_policy | Connection policy name | session | always | 
Description: SPS connection policy name
Example: my_connection
| Field  | Name  | Scope  | Present  | 
| auth_method | Authentication method | session | always | 
Description: the type of authentication used in gateway authentication
Example: password
| Field  | Name  | Scope  | Present  | 
| verdict | Verdict | session | always | 
Description: describes how the session ended, e.g. ACCEPT, AUTH_FAIL, DENY, FAIL, TERMINATED
Example: ACCEPT
 
SessionClosed after a failed gateway authentication
Description of the message: Emitted when the session ends because gateway authentication failed.
Example message:
{"timestamp":"1557912725391","severity":"0","session_id":"svc-mBbMWzauBWHQN9TpoZz8mD-my_connection-9","protocol":"SSH","event_type_id":"449510124","event_name":"SessionClosed","connection_policy":"my_connection","client_port":"47444","client_name":"client.acme.com","client_address":"10.30.0.24","base_type_name":"meta","verdict":"AUTH_FAIL"}
The message contains the following fields.
| Field  | Name  | Scope  | Present  | 
| base_type_name | Basic type | message | always | 
Description: basic message type: meta
Example: meta
| Field  | Name  | Scope  | Present  | 
| event_type_id | Signature ID | message | always | 
Description: numeric identifier of message type
Example: 449510124
| Field  | Name  | Scope  | Present  | 
| event_name | Event name | message | always | 
Description: the type of the message
Example: SessionClosed
| Field  | Name  | Scope  | Present  | 
| session_id | Session ID | session | always | 
Description: the unique identifier of the session
Example: svc-hjdBxA2UWkTadH3juDVwrT-my_connection-0
| Field  | Name  | Scope  | Present  | 
| severity | Severity | message | always | 
Description: number between 0-10 inclusive, equal to aggregated analytics score divided by 10 or 0 if analytics is disabled
Example: 0
| Field  | Name  | Scope  | Present  | 
| timestamp | Timestamp | message | always | 
Description: the UNIX time stamp when the event occurred
Example: 1554470652340
| Field  | Name  | Scope  | Present  | 
| client_name | Client name | session | always | 
Description: the client hostname or IP address if hostname is not known
Example: client.acme.com
| Field  | Name  | Scope  | Present  | 
| client_address | Client address | session | always | 
Description: the IP address of the client
Example: 10.30.0.24
| Field  | Name  | Scope  | Present  | 
| client_port | Client port | session | always | 
Description: the port number on the client
Example: 38014
| Field  | Name  | Scope  | Present  | 
| protocol | Application protocol | session | always | 
Description: SPS supported protocol
Example: SSH
| Field  | Name  | Scope  | Present  | 
| connection_policy | Connection policy name | session | always | 
Description: SPS connection policy name
Example: my_connection
| Field  | Name  | Scope  | Present  | 
| verdict | Verdict | session | always | 
Description: describes how the session ended, e.g. ACCEPT, AUTH_FAIL, DENY, FAIL, TERMINATED
Example: AUTH_FAIL
 
SessionClosed after a failed server authentication
Description of the message: Emitted when the session ends because server authentication failed.
Example message:
{"timestamp":"1557912748990","severity":"0","session_id":"svc-mBbMWzauBWHQN9TpoZz8mD-my_connection-11","verdict":"AUTH_FAIL","server_port":"22","server_name":"server.acme.com","server_address":"10.170.255.206","protocol":"SSH","gateway_username":"gwtestauto","event_type_id":"449510124","event_name":"SessionClosed","connection_policy":"my_connection","client_port":"47840","client_name":"client.acme.com","client_address":"10.30.0.24","base_type_name":"meta"}
The message contains the following fields.
| Field  | Name  | Scope  | Present  | 
| base_type_name | Basic type | message | always | 
Description: basic message type: meta
Example: meta
| Field  | Name  | Scope  | Present  | 
| event_type_id | Signature ID | message | always | 
Description: numeric identifier of message type
Example: 449510124
| Field  | Name  | Scope  | Present  | 
| event_name | Event name | message | always | 
Description: the type of the message
Example: SessionClosed
| Field  | Name  | Scope  | Present  | 
| session_id | Session ID | session | always | 
Description: the unique identifier of the session
Example: svc-hjdBxA2UWkTadH3juDVwrT-my_connection-0
| Field  | Name  | Scope  | Present  | 
| severity | Severity | message | always | 
Description: number between 0-10 inclusive, equal to aggregated analytics score divided by 10 or 0 if analytics is disabled
Example: 0
| Field  | Name  | Scope  | Present  | 
| timestamp | Timestamp | message | always | 
Description: the UNIX time stamp when the event occurred
Example: 1554470652340
| Field  | Name  | Scope  | Present  | 
| gateway_username | Gateway username | session | sometimes | 
Description: the authenticated gateway username if there was a successful gateway authentication
Example: gwtestauto
| Field  | Name  | Scope  | Present  | 
| gateway_domain | Gateway user domain | session | sometimes | 
Description: the authenticated gateway user domain if there was a successful gateway authentication and known
Example: acme.com
| Field  | Name  | Scope  | Present  | 
| server_name | Server name | session | always | 
Description: the server hostname or IP address if hostname is not known
Example: server.acme.com
| Field  | Name  | Scope  | Present  | 
| server_address | Server address | session | always | 
Description: the IP address of the server
Example: 10.170.255.206
| Field  | Name  | Scope  | Present  | 
| server_port | Server port | session | always | 
Description: the port number on the server
Example: 22
| Field  | Name  | Scope  | Present  | 
| client_name | Client name | session | always | 
Description: the client hostname or IP address if hostname is not known
Example: client.acme.com
| Field  | Name  | Scope  | Present  | 
| client_address | Client address | session | always | 
Description: the IP address of the client
Example: 10.30.0.24
| Field  | Name  | Scope  | Present  | 
| client_port | Client port | session | always | 
Description: the port number on the client
Example: 38014
| Field  | Name  | Scope  | Present  | 
| protocol | Application protocol | session | always | 
Description: SPS supported protocol
Example: SSH
| Field  | Name  | Scope  | Present  | 
| connection_policy | Connection policy name | session | always | 
Description: SPS connection policy name
Example: my_connection
| Field  | Name  | Scope  | Present  | 
| verdict | Verdict | session | always | 
Description: describes how the session ended, e.g. ACCEPT, AUTH_FAIL, DENY, FAIL, TERMINATED
Example: AUTH_FAIL
 
RdpEmbeddedInTsg
Description of the message: Emitted when the gateway user is acquired in a Terminal Service Gateway authentication scenario.
Example message:
{"timestamp":"1558007294417","severity":"0","session_id":"svc-oUDm7arcL8zNb3t2CVwSQr-my_connection-50-4","protocol":"RDP","gateway_username":"gwtestauto","event_type_id":"998298775","event_name":"RdpEmbeddedInTsg","connection_policy":"my_connection","client_port":"51270","client_name":"client.acme.com","client_address":"10.30.0.24","base_type_name":"meta"}
The message contains the following fields.
| Field  | Name  | Scope  | Present  | 
| base_type_name | Basic type | message | always | 
Description: basic message type: meta
Example: meta
| Field  | Name  | Scope  | Present  | 
| event_type_id | Signature ID | message | always | 
Description: numeric identifier of message type
Example: 998298775
| Field  | Name  | Scope  | Present  | 
| event_name | Event name | message | always | 
Description: the type of the message
Example: RdpEmbeddedInTsg
| Field  | Name  | Scope  | Present  | 
| session_id | Session ID | session | always | 
Description: the unique identifier of the session
Example: svc-hjdBxA2UWkTadH3juDVwrT-my_connection-0
| Field  | Name  | Scope  | Present  | 
| severity | Severity | message | always | 
Description: number between 0-10 inclusive, equal to aggregated analytics score divided by 10 or 0 if analytics is disabled
Example: 0
| Field  | Name  | Scope  | Present  | 
| timestamp | Timestamp | message | always | 
Description: the UNIX time stamp when the event occurred
Example: 1554470652340
| Field  | Name  | Scope  | Present  | 
| gateway_username | Gateway username | session | always | 
Description: the authenticated gateway username
Example: gwtestauto
| Field  | Name  | Scope  | Present  | 
| client_name | Client name | session | always | 
Description: the client hostname or IP address if hostname is not known
Example: client.acme.com
| Field  | Name  | Scope  | Present  | 
| client_address | Client address | session | always | 
Description: the IP address of the client
Example: 10.30.0.24
| Field  | Name  | Scope  | Present  | 
| client_port | Client port | session | always | 
Description: the port number on the client
Example: 38014
| Field  | Name  | Scope  | Present  | 
| protocol | Application protocol | session | always | 
Description: SPS supported protocol
Example: SSH
| Field  | Name  | Scope  | Present  | 
| connection_policy | Connection policy name | session | always | 
Description: SPS connection policy name
Example: my_connection
 
SessionScored
Description of the message: Score messages represent scoring events when SPS has calculated an initial or changed score for the session.
Example message:
{"timestamp":"1558009822701","severity":"7","session_id":"svc-62a6XGcPzaFvLYDhVYDYXj-my_connection-0","server_username":"root","server_port":"22","server_name":"server.acme.com","server_address":"10.170.255.206","protocol":"SSH","gateway_username":"gwtestauto","event_type_id":"1991765353","event_name":"SessionScored","connection_policy":"my_connection","client_port":"35620","client_name":"client.acme.com","client_address":"10.30.0.24","base_type_name":"score","algorithm_score":"18","algorithm_name":"keystroke","aggregated_score":"70"}
The message contains the following fields.
| Field  | Name  | Scope  | Present  | 
| base_type_name | Basic type | message | always | 
Description: basic message type: score
Example: score
| Field  | Name  | Scope  | Present  | 
| event_type_id | Signature ID | message | always | 
Description: numeric identifier of message type
Example: 1991765353
| Field  | Name  | Scope  | Present  | 
| event_name | Event name | message | always | 
Description: the type of the message
Example: SessionScored
| Field  | Name  | Scope  | Present  | 
| session_id | Session ID | session | always | 
Description: the unique identifier of the session
Example: svc-hjdBxA2UWkTadH3juDVwrT-my_connection-0
| Field  | Name  | Scope  | Present  | 
| severity | Severity | message | always | 
Description: number between 0-10 inclusive, equal to aggregated analytics score divided by 10 or 0 if analytics is disabled
Example: 0
| Field  | Name  | Scope  | Present  | 
| timestamp | Timestamp | message | always | 
Description: the UNIX time stamp when the event occurred
Example: 1554470652340
| Field  | Name  | Scope  | Present  | 
| server_username | Server user | session | always | 
Description: the server username
Example: root
| Field  | Name  | Scope  | Present  | 
| server_domain | Server user domain if known | session | sometimes | 
Description: the server domain, if known
Example: acme.com
| Field  | Name  | Scope  | Present  | 
| gateway_username | Gateway username | session | sometimes | 
Description: the authenticated gateway username if there was a successful gateway authentication
Example: gwtestauto
| Field  | Name  | Scope  | Present  | 
| gateway_domain | Gateway user domain | session | sometimes | 
Description: the authenticated gateway user domain if there was a successful gateway authentication and known
Example: acme.com
| Field  | Name  | Scope  | Present  | 
| server_name | Server name | session | always | 
Description: the server hostname or IP address if hostname is not known
Example: server.acme.com
| Field  | Name  | Scope  | Present  | 
| server_address | Server address | session | always | 
Description: the IP address of the server
Example: 10.170.255.206
| Field  | Name  | Scope  | Present  | 
| server_port | Server port | session | always | 
Description: the port number on the server
Example: 22
| Field  | Name  | Scope  | Present  | 
| client_name | Client name | session | always | 
Description: the client hostname or IP address if hostname is not known
Example: client.acme.com
| Field  | Name  | Scope  | Present  | 
| client_address | Client address | session | always | 
Description: the IP address of the client
Example: 10.30.0.24
| Field  | Name  | Scope  | Present  | 
| client_port | Client port | session | always | 
Description: the port number on the client
Example: 38014
| Field  | Name  | Scope  | Present  | 
| protocol | Application protocol | session | always | 
Description: SPS supported protocol
Example: SSH
| Field  | Name  | Scope  | Present  | 
| connection_policy | Connection policy name | session | always | 
Description: SPS connection policy name
Example: my_connection
| Field  | Name  | Scope  | Present  | 
| aggregated_score | Aggregated score | message | always | 
Description: the average score from all enabled analytics algorithms
Example: 50
| Field  | Name  | Scope  | Present  | 
| algorithm_name | Algorithm name | message | always | 
Description: the name of the algorithm that changed value
Example: keystroke
| Field  | Name  | Scope  | Present  | 
| algorithm_score | Algorithm score | message | always | 
Description: the new score value of the algorithm that changed value
Example: 60
 
CommandChannelEvent
Description of the message: Emitted when a command is detected in the session channel text.
Example message:
{"timestamp":"1557912701166","severity":"0","session_id":"svc-mBbMWzauBWHQN9TpoZz8mD-my_connection-6","server_username":"root","server_port":"22","server_name":"server.acme.com","server_address":"10.170.255.206","protocol":"SSH","gateway_username":"gwtestauto","event_type_id":"127084214","event_name":"CommandChannelEvent","connection_policy":"my_connection","command":"exit","client_port":"46958","client_name":"client.acme.com","client_address":"10.30.0.24","base_type_name":"content"}
The message contains the following fields.
| Field  | Name  | Scope  | Present  | 
| base_type_name | Basic type | message | always | 
Description: basic message type: content
Example: content
| Field  | Name  | Scope  | Present  | 
| event_type_id | Signature ID | message | always | 
Description: numeric identifier of message type
Example: 127084214
| Field  | Name  | Scope  | Present  | 
| event_name | Event name | message | always | 
Description: the type of the message
Example: CommandChannelEvent
| Field  | Name  | Scope  | Present  | 
| session_id | Session ID | session | always | 
Description: the unique identifier of the session
Example: svc-hjdBxA2UWkTadH3juDVwrT-my_connection-0
| Field  | Name  | Scope  | Present  | 
| severity | Severity | message | always | 
Description: number between 0-10 inclusive, equal to aggregated analytics score divided by 10 or 0 if analytics is disabled
Example: 0
| Field  | Name  | Scope  | Present  | 
| timestamp | Timestamp | message | always | 
Description: the UNIX time stamp when the event occurred
Example: 1554470652340
| Field  | Name  | Scope  | Present  | 
| server_username | Server user | session | always | 
Description: the server username
Example: root
| Field  | Name  | Scope  | Present  | 
| server_domain | Server user domain if known | session | sometimes | 
Description: the server domain, if known
Example: acme.com
| Field  | Name  | Scope  | Present  | 
| gateway_username | Gateway username | session | sometimes | 
Description: the authenticated gateway username if there was a successful gateway authentication
Example: gwtestauto
| Field  | Name  | Scope  | Present  | 
| gateway_domain | Gateway user domain | session | sometimes | 
Description: the authenticated gateway user domain if there was a successful gateway authentication and known
Example: acme.com
| Field  | Name  | Scope  | Present  | 
| server_name | Server name | session | always | 
Description: the server hostname or IP address if hostname is not known
Example: server.acme.com
| Field  | Name  | Scope  | Present  | 
| server_address | Server address | session | always | 
Description: the IP address of the server
Example: 10.170.255.206
| Field  | Name  | Scope  | Present  | 
| server_port | Server port | session | always | 
Description: the port number on the server
Example: 22
| Field  | Name  | Scope  | Present  | 
| client_name | Client name | session | always | 
Description: the client hostname or IP address if hostname is not known
Example: client.acme.com
| Field  | Name  | Scope  | Present  | 
| client_address | Client address | session | always | 
Description: the IP address of the client
Example: 10.30.0.24
| Field  | Name  | Scope  | Present  | 
| client_port | Client port | session | always | 
Description: the port number on the client
Example: 38014
| Field  | Name  | Scope  | Present  | 
| protocol | Application protocol | session | always | 
Description: SPS supported protocol
Example: SSH
| Field  | Name  | Scope  | Present  | 
| connection_policy | Connection policy name | session | always | 
Description: SPS connection policy name
Example: my_connection
| Field  | Name  | Scope  | Present  | 
| command | Command | message | always | 
Description: the full command detected
Example: exit
 
WindowTitleChannelEvent
Description of the message: Emitted when a command is detected in the session channel text.
Example message:
{"window_title":"Shortcut Tools Application Tools Administrative Tools","timestamp":"1558007305516","severity":"0","session_id":"svc-oUDm7arcL8zNb3t2CVwSQr-my_connection-50-4","server_username":"Administrator","server_port":"3389","server_name":"server.acme.com","server_address":"10.170.255.206","protocol":"RDP","gateway_username":"gwtestauto","event_type_id":"911383355","event_name":"WindowTitleChannelEvent","connection_policy":"my_connection","client_port":"51270","client_name":"client.acme.com","client_address":"10.30.0.24","base_type_name":"content"}
The message contains the following fields.
| Field  | Name  | Scope  | Present  | 
| base_type_name | Basic type | message | always | 
Description: basic message type: content
Example: content
| Field  | Name  | Scope  | Present  | 
| event_type_id | Signature ID | message | always | 
Description: numeric identifier of message type
Example: 911383355
| Field  | Name  | Scope  | Present  | 
| event_name | Event name | message | always | 
Description: the type of the message
Example: WindowTitleChannelEvent
| Field  | Name  | Scope  | Present  | 
| session_id | Session ID | session | always | 
Description: the unique identifier of the session
Example: svc-hjdBxA2UWkTadH3juDVwrT-my_connection-0
| Field  | Name  | Scope  | Present  | 
| severity | Severity | message | always | 
Description: number between 0-10 inclusive, equal to aggregated analytics score divided by 10 or 0 if analytics is disabled
Example: 0
| Field  | Name  | Scope  | Present  | 
| timestamp | Timestamp | message | always | 
Description: the UNIX time stamp when the event occurred
Example: 1554470652340
| Field  | Name  | Scope  | Present  | 
| server_username | Server user | session | always | 
Description: the server username
Example: root
| Field  | Name  | Scope  | Present  | 
| server_domain | Server user domain if known | session | sometimes | 
Description: the server domain, if known
Example: acme.com
| Field  | Name  | Scope  | Present  | 
| gateway_username | Gateway username | session | sometimes | 
Description: the authenticated gateway username if there was a successful gateway authentication
Example: gwtestauto
| Field  | Name  | Scope  | Present  | 
| gateway_domain | Gateway user domain | session | sometimes | 
Description: the authenticated gateway user domain if there was a successful gateway authentication and known
Example: acme.com
| Field  | Name  | Scope  | Present  | 
| server_name | Server name | session | always | 
Description: the server hostname or IP address if hostname is not known
Example: server.acme.com
| Field  | Name  | Scope  | Present  | 
| server_address | Server address | session | always | 
Description: the IP address of the server
Example: 10.170.255.206
| Field  | Name  | Scope  | Present  | 
| server_port | Server port | session | always | 
Description: the port number on the server
Example: 22
| Field  | Name  | Scope  | Present  | 
| client_name | Client name | session | always | 
Description: the client hostname or IP address if hostname is not known
Example: client.acme.com
| Field  | Name  | Scope  | Present  | 
| client_address | Client address | session | always | 
Description: the IP address of the client
Example: 10.30.0.24
| Field  | Name  | Scope  | Present  | 
| client_port | Client port | session | always | 
Description: the port number on the client
Example: 38014
| Field  | Name  | Scope  | Present  | 
| protocol | Application protocol | session | always | 
Description: SPS supported protocol
Example: SSH
| Field  | Name  | Scope  | Present  | 
| connection_policy | Connection policy name | session | always | 
Description: SPS connection policy name
Example: my_connection
| Field  | Name  | Scope  | Present  | 
| window_title | Window title | message | always | 
Description: the window title detected in graphical protocol
Example: firefox
 
FileTransfer
Description of the message: Emitted when a command is detected in the session channel text.
Example message:
{"timestamp":"1558023671115","severity":"0","session_id":"svc-2L83Phh9J6GKLWTc881awk-my_connection-316","server_username":"root","server_port":"22","server_name":"server.acme.com","server_address":"10.170.255.206","protocol":"SSH","gateway_username":"gwtestauto","filepath":"","filename":"cpuinfo","file_operation":"UPLOAD","event_type_id":"1127618380","event_name":"FileTransfer","connection_policy":"my_connection","client_port":"44292","client_name":"client.acme.com","client_address":"10.30.0.24","base_type_name":"content"}
The message contains the following fields.
| Field  | Name  | Scope  | Present  | 
| base_type_name | Basic type | message | always | 
Description: basic message type: content
Example: content
| Field  | Name  | Scope  | Present  | 
| event_type_id | Signature ID | message | always | 
Description: numeric identifier of message type
Example: 1127618380
| Field  | Name  | Scope  | Present  | 
| event_name | Event name | message | always | 
Description: the type of the message
Example: FileTransfer
| Field  | Name  | Scope  | Present  | 
| session_id | Session ID | session | always | 
Description: the unique identifier of the session
Example: svc-hjdBxA2UWkTadH3juDVwrT-my_connection-0
| Field  | Name  | Scope  | Present  | 
| severity | Severity | message | always | 
Description: number between 0-10 inclusive, equal to aggregated analytics score divided by 10 or 0 if analytics is disabled
Example: 0
| Field  | Name  | Scope  | Present  | 
| timestamp | Timestamp | message | always | 
Description: the UNIX time stamp when the event occurred
Example: 1554470652340
| Field  | Name  | Scope  | Present  | 
| server_username | Server user | session | always | 
Description: the server username
Example: root
| Field  | Name  | Scope  | Present  | 
| server_domain | Server user domain if known | session | sometimes | 
Description: the server domain, if known
Example: acme.com
| Field  | Name  | Scope  | Present  | 
| gateway_username | Gateway username | session | sometimes | 
Description: the authenticated gateway username if there was a successful gateway authentication
Example: gwtestauto
| Field  | Name  | Scope  | Present  | 
| gateway_domain | Gateway user domain | session | sometimes | 
Description: the authenticated gateway user domain if there was a successful gateway authentication and known
Example: acme.com
| Field  | Name  | Scope  | Present  | 
| server_name | Server name | session | always | 
Description: the server hostname or IP address if hostname is not known
Example: server.acme.com
| Field  | Name  | Scope  | Present  | 
| server_address | Server address | session | always | 
Description: the IP address of the server
Example: 10.170.255.206
| Field  | Name  | Scope  | Present  | 
| server_port | Server port | session | always | 
Description: the port number on the server
Example: 22
| Field  | Name  | Scope  | Present  | 
| client_name | Client name | session | always | 
Description: the client hostname or IP address if hostname is not known
Example: client.acme.com
| Field  | Name  | Scope  | Present  | 
| client_address | Client address | session | always | 
Description: the IP address of the client
Example: 10.30.0.24
| Field  | Name  | Scope  | Present  | 
| client_port | Client port | session | always | 
Description: the port number on the client
Example: 38014
| Field  | Name  | Scope  | Present  | 
| protocol | Application protocol | session | always | 
Description: SPS supported protocol
Example: SSH
| Field  | Name  | Scope  | Present  | 
| connection_policy | Connection policy name | session | always | 
Description: SPS connection policy name
Example: my_connection
| Field  | Name  | Scope  | Present  | 
| file_operation | Operation | message | always | 
Description: the operation on the file such as UPLOAD/DOWNLOAD. It may contain the suffix 'WARNING', if the operation failed
Example: UPLOAD
| Field  | Name  | Scope  | Present  | 
| filename | Filename | message | always | 
Description: the file name
Example: foobar.txt
| Field  | Name  | Scope  | Present  | 
| filepath | File path | message | always | 
Description: the path to the file on the server
Example: /tmp