ServerConnect on initial contact
Description of the message: Emitted when SPS connects to the serverfor the first time in the session
Example message:
{"vendor":"OneIdentity","user":"","transport":"tcp","src_user":"gwtestauto","src_port":"58140","src_ip":"10.30.0.24","src":"client.acme.com","session_id":"svc-iiCfsG48oJG5smpuocBLAN-my_connection-39","product":"SPS-5.11.0","event_name":"ServerConnect","dvc":"sps1.acme.com","dest_port":"22","dest_ip":"10.170.255.206","dest":"server.acme.com","app":"ssh","action":"added","_time":"1557913195000"}
The message contains the following fields.
|
Field |
Name |
Scope |
Present |
|
vendor |
Device vendor |
product |
always |
Description: fixed to OneIdentity
Example: OneIdentity
|
Field |
Name |
Scope |
Present |
|
product |
Product version |
product |
always |
Description: short product name with version
Example: SPS-5.11.0
|
Field |
Name |
Scope |
Present |
|
dvc |
Device fqdn |
device |
always |
Description: the hostname of SPS
Example: sps1.acme.com
|
Field |
Name |
Scope |
Present |
|
session_id |
Session ID |
session |
always |
Description: the unique identifier of the session
Example: svc-hjdBxA2UWkTadH3juDVwrT-my_connection-0
|
Field |
Name |
Scope |
Present |
|
event_name |
Event name |
message |
always |
Description: the type of the message
Example: ServerConnect
|
Field |
Name |
Scope |
Present |
|
action |
Action |
message |
always |
Description: the taken by the device according to CIM model
Example: added
|
Field |
Name |
Scope |
Present |
|
_time |
Timestamp |
message |
always |
Description: the UNIX time stamp when the event occurred
Example: 1554470652340
|
Field |
Name |
Scope |
Present |
|
app |
Application protocol |
session |
always |
Description: SPS supported protocol
Example: ssh
|
Field |
Name |
Scope |
Present |
|
dest_ip |
Destination address |
session |
always |
Description: the IP address of the server
Example: 10.170.255.206
|
Field |
Name |
Scope |
Present |
|
dest |
Destination host name |
session |
always |
Description: the server hostname or IP address if hostname is not known
Example: server.acme.com
|
Field |
Name |
Scope |
Present |
|
user |
Name of the user |
message |
always |
Description: empty, not known in this message type
Example:
|
Field |
Name |
Scope |
Present |
|
dest_port |
Destination port |
session |
always |
Description: the port number on the server
Example: 22
|
Field |
Name |
Scope |
Present |
|
src_ip |
Source address |
session |
always |
Description: the IP address of the client
Example: 10.30.0.24
|
Field |
Name |
Scope |
Present |
|
src |
Source host name |
session |
always |
Description: the client hostname or IP address if hostname is not known
Example: client.acme.com
|
Field |
Name |
Scope |
Present |
|
src_user |
Source username |
session |
sometimes |
Description: the authenticated gateway username if there was a successful gateway authentication
Example: gwtestauto
|
Field |
Name |
Scope |
Present |
|
src_port |
Source port |
session |
always |
Description: the port number on the client
Example: 38014
|
Field |
Name |
Scope |
Present |
|
transport |
Transport |
session |
always |
Description: the layer 3 protocol
Example: tcp
ServerConnect for secondary channels
Description of the message: Emitted when SPS connects to the serverfor opening further channels. The difference from initial connection is that the server user name is known and authenticated this time.
Example message:
{"vendor":"OneIdentity","user":"","transport":"tcp","src_user":"gwtestauto","src_port":"58140","src_ip":"10.30.0.24","src":"client.acme.com","user":"root","session_id":"svc-iiCfsG48oJG5smpuocBLAN-my_connection-39","product":"SPS-5.11.0","event_name":"ServerConnect","dvc":"sps1.acme.com","dest_port":"22","dest_ip":"10.170.255.206","dest":"server.acme.com","app":"ssh","action":"added","_time":"1557913195000"}
The message contains the following fields.
|
Field |
Name |
Scope |
Present |
|
vendor |
Device vendor |
product |
always |
Description: fixed to OneIdentity
Example: OneIdentity
|
Field |
Name |
Scope |
Present |
|
product |
Product version |
product |
always |
Description: short product name with version
Example: SPS-5.11.0
|
Field |
Name |
Scope |
Present |
|
dvc |
Device fqdn |
device |
always |
Description: the hostname of SPS
Example: sps1.acme.com
|
Field |
Name |
Scope |
Present |
|
session_id |
Session ID |
session |
always |
Description: the unique identifier of the session
Example: svc-hjdBxA2UWkTadH3juDVwrT-my_connection-0
|
Field |
Name |
Scope |
Present |
|
event_name |
Event name |
message |
always |
Description: the type of the message
Example: ServerConnect
|
Field |
Name |
Scope |
Present |
|
action |
Action |
message |
always |
Description: the taken by the device according to CIM model
Example: added
|
Field |
Name |
Scope |
Present |
|
_time |
Timestamp |
message |
always |
Description: the UNIX time stamp when the event occurred
Example: 1554470652340
|
Field |
Name |
Scope |
Present |
|
app |
Application protocol |
session |
always |
Description: SPS supported protocol
Example: ssh
|
Field |
Name |
Scope |
Present |
|
dest_ip |
Destination address |
session |
always |
Description: the IP address of the server
Example: 10.170.255.206
|
Field |
Name |
Scope |
Present |
|
dest |
Destination host name |
session |
always |
Description: the server hostname or IP address if hostname is not known
Example: server.acme.com
|
Field |
Name |
Scope |
Present |
|
user |
Name of the user |
session |
always |
Description: the server username
Example: root
|
Field |
Name |
Scope |
Present |
|
dest_port |
Destination port |
session |
always |
Description: the port number on the server
Example: 22
|
Field |
Name |
Scope |
Present |
|
src_ip |
Source address |
session |
always |
Description: the IP address of the client
Example: 10.30.0.24
|
Field |
Name |
Scope |
Present |
|
src |
Source host name |
session |
always |
Description: the client hostname or IP address if hostname is not known
Example: client.acme.com
|
Field |
Name |
Scope |
Present |
|
src_user |
Source username |
session |
sometimes |
Description: the authenticated gateway username if there was a successful gateway authentication
Example: gwtestauto
|
Field |
Name |
Scope |
Present |
|
src_port |
Source port |
session |
always |
Description: the port number on the client
Example: 38014
|
Field |
Name |
Scope |
Present |
|
transport |
Transport |
session |
always |
Description: the layer 3 protocol
Example: tcp
ServerAuthenticationSuccess
Description of the message: Emitted after the server authentication successfully happened
Example message:
{"vendor":"OneIdentity","user":"root","transport":"tcp","src_user":"gwtestauto","src_port":"57982","src_ip":"10.30.0.24","src":"client.acme.com","session_id":"svc-iiCfsG48oJG5smpuocBLAN-my_connection-38","product":"SPS-5.11.0","event_name":"ServerAuthenticationSuccess","dvc":"sps1.acme.com","dest_port":"22","dest_ip":"10.170.255.206","dest":"server.acme.com","app":"ssh","action":"success","_time":"1557913189329"}
The message contains the following fields.
|
Field |
Name |
Scope |
Present |
|
vendor |
Device vendor |
product |
always |
Description: fixed to OneIdentity
Example: OneIdentity
|
Field |
Name |
Scope |
Present |
|
product |
Product version |
product |
always |
Description: short product name with version
Example: SPS-5.11.0
|
Field |
Name |
Scope |
Present |
|
dvc |
Device fqdn |
device |
always |
Description: the hostname of SPS
Example: sps1.acme.com
|
Field |
Name |
Scope |
Present |
|
session_id |
Session ID |
session |
always |
Description: the unique identifier of the session
Example: svc-hjdBxA2UWkTadH3juDVwrT-my_connection-0
|
Field |
Name |
Scope |
Present |
|
event_name |
Event name |
message |
always |
Description: the type of the message
Example: ServerAuthenticationSuccess
|
Field |
Name |
Scope |
Present |
|
action |
Action |
message |
always |
Description: marks a successful authentication
Example: success
|
Field |
Name |
Scope |
Present |
|
_time |
Timestamp |
message |
always |
Description: the UNIX time stamp when the event occurred
Example: 1554470652340
|
Field |
Name |
Scope |
Present |
|
app |
Application protocol |
session |
always |
Description: SPS supported protocol
Example: ssh
|
Field |
Name |
Scope |
Present |
|
dest_ip |
Destination address |
session |
always |
Description: the IP address of the server
Example: 10.170.255.206
|
Field |
Name |
Scope |
Present |
|
dest |
Destination host name |
session |
always |
Description: the server hostname or IP address if hostname is not known
Example: server.acme.com
|
Field |
Name |
Scope |
Present |
|
user |
Name of the user |
session |
always |
Description: the server username
Example: root
|
Field |
Name |
Scope |
Present |
|
dest_port |
Destination port |
session |
always |
Description: the port number on the server
Example: 22
|
Field |
Name |
Scope |
Present |
|
src_ip |
Source address |
session |
always |
Description: the IP address of the client
Example: 10.30.0.24
|
Field |
Name |
Scope |
Present |
|
src |
Source host name |
session |
always |
Description: the client hostname or IP address if hostname is not known
Example: client.acme.com
|
Field |
Name |
Scope |
Present |
|
src_user |
Source username |
session |
sometimes |
Description: the authenticated gateway username if there was a successful gateway authentication
Example: gwtestauto
|
Field |
Name |
Scope |
Present |
|
src_port |
Source port |
session |
always |
Description: the port number on the client
Example: 38014
|
Field |
Name |
Scope |
Present |
|
transport |
Transport |
session |
always |
Description: the layer 3 protocol
Example: tcp
ServerAuthenticationFailure
Description of the message: Emitted after the server authentication failed
Example message:
{"vendor":"OneIdentity","user":"root","transport":"tcp","src_user":"gwtestauto","src_port":"58140","src_ip":"10.30.0.24","src":"client.acme.com","session_id":"svc-iiCfsG48oJG5smpuocBLAN-my_connection-39","product":"SPS-5.11.0","event_name":"ServerAuthenticationFailure","dvc":"sps1.acme.com","dest_port":"22","dest_ip":"10.170.255.206","dest":"server.acme.com","app":"ssh","action":"failure","_time":"1557913197211"}
The message contains the following fields.
|
Field |
Name |
Scope |
Present |
|
vendor |
Device vendor |
product |
always |
Description: fixed to OneIdentity
Example: OneIdentity
|
Field |
Name |
Scope |
Present |
|
product |
Product version |
product |
always |
Description: short product name with version
Example: SPS-5.11.0
|
Field |
Name |
Scope |
Present |
|
dvc |
Device fqdn |
device |
always |
Description: the hostname of SPS
Example: sps1.acme.com
|
Field |
Name |
Scope |
Present |
|
session_id |
Session ID |
session |
always |
Description: the unique identifier of the session
Example: svc-hjdBxA2UWkTadH3juDVwrT-my_connection-0
|
Field |
Name |
Scope |
Present |
|
event_name |
Event name |
message |
always |
Description: the type of the message
Example: ServerAuthenticationFailure
|
Field |
Name |
Scope |
Present |
|
action |
Action |
message |
always |
Description: marks a failed authentication
Example: failure
|
Field |
Name |
Scope |
Present |
|
_time |
Timestamp |
message |
always |
Description: the UNIX time stamp when the event occurred
Example: 1554470652340
|
Field |
Name |
Scope |
Present |
|
app |
Application protocol |
session |
always |
Description: SPS supported protocol
Example: ssh
|
Field |
Name |
Scope |
Present |
|
dest_ip |
Destination address |
session |
always |
Description: the IP address of the server
Example: 10.170.255.206
|
Field |
Name |
Scope |
Present |
|
dest |
Destination host name |
session |
always |
Description: the server hostname or IP address if hostname is not known
Example: server.acme.com
|
Field |
Name |
Scope |
Present |
|
user |
Name of the user |
session |
always |
Description: contains the non authenticated server username
Example: root
|
Field |
Name |
Scope |
Present |
|
dest_port |
Destination port |
session |
always |
Description: the port number on the server
Example: 22
|
Field |
Name |
Scope |
Present |
|
src_ip |
Source address |
session |
always |
Description: the IP address of the client
Example: 10.30.0.24
|
Field |
Name |
Scope |
Present |
|
src |
Source host name |
session |
always |
Description: the client hostname or IP address if hostname is not known
Example: client.acme.com
|
Field |
Name |
Scope |
Present |
|
src_user |
Source username |
session |
sometimes |
Description: the authenticated gateway username if there was a successful gateway authentication
Example: gwtestauto
|
Field |
Name |
Scope |
Present |
|
src_port |
Source port |
session |
always |
Description: the port number on the client
Example: 38014
|
Field |
Name |
Scope |
Present |
|
transport |
Transport |
session |
always |
Description: the layer 3 protocol
Example: tcp
GatewayAuthenticationFailure
Description of the message: Emitted after a failed gateway authentication. Note that the gateway username here is not authenticated and will not be retained in further messages to avoid confusion with an authenticated gateway user.
Example message:
{"vendor":"OneIdentity","user":"","transport":"tcp","src_user":"gwtestauto","src_port":"49070","src_ip":"10.30.0.24","src":"client.acme.com","session_id":"svc-mBbMWzauBWHQN9TpoZz8mD-my_connection-15","product":"SPS-5.11.0","event_name":"GatewayAuthenticationFailure","dvc":"sps1.acme.com","dest_port":"","dest_ip":"","dest":"","app":"ssh","action":"failure","_time":"1557912792360"}
The message contains the following fields.
|
Field |
Name |
Scope |
Present |
|
vendor |
Device vendor |
product |
always |
Description: fixed to OneIdentity
Example: OneIdentity
|
Field |
Name |
Scope |
Present |
|
product |
Product version |
product |
always |
Description: short product name with version
Example: SPS-5.11.0
|
Field |
Name |
Scope |
Present |
|
dvc |
Device fqdn |
device |
always |
Description: the hostname of SPS
Example: sps1.acme.com
|
Field |
Name |
Scope |
Present |
|
session_id |
Session ID |
session |
always |
Description: the unique identifier of the session
Example: svc-hjdBxA2UWkTadH3juDVwrT-my_connection-0
|
Field |
Name |
Scope |
Present |
|
event_name |
Event name |
message |
always |
Description: the type of the message
Example: GatewayAuthenticationFailure
|
Field |
Name |
Scope |
Present |
|
action |
Action |
message |
always |
Description: marks a failed authentication
Example: failure
|
Field |
Name |
Scope |
Present |
|
dest |
Destination host name |
session |
always |
Description: empty, not known in this message type
Example:
|
Field |
Name |
Scope |
Present |
|
dest_ip |
Destination address |
session |
always |
Description: empty, not known in this message type
Example:
|
Field |
Name |
Scope |
Present |
|
user |
Name of the user |
message |
always |
Description: empty, not known in this message type
Example:
|
Field |
Name |
Scope |
Present |
|
dest_port |
Destination port |
session |
always |
Description: empty, not known in this message type
Example:
|
Field |
Name |
Scope |
Present |
|
_time |
Timestamp |
message |
always |
Description: the UNIX time stamp when the event occurred
Example: 1554470652340
|
Field |
Name |
Scope |
Present |
|
app |
Application protocol |
session |
always |
Description: SPS supported protocol
Example: ssh
|
Field |
Name |
Scope |
Present |
|
src_ip |
Source address |
session |
always |
Description: the IP address of the client
Example: 10.30.0.24
|
Field |
Name |
Scope |
Present |
|
src |
Source host name |
session |
always |
Description: the client hostname or IP address if hostname is not known
Example: client.acme.com
|
Field |
Name |
Scope |
Present |
|
src_user |
Source username |
message |
always |
Description: the non authenticated gateway username
Example: gwtestauto
|
Field |
Name |
Scope |
Present |
|
src_port |
Source port |
session |
always |
Description: the port number on the client
Example: 38014
|
Field |
Name |
Scope |
Present |
|
transport |
Transport |
session |
always |
Description: the layer 3 protocol
Example: tcp
SessionClosed of successfully authenticated session
Description of the message: Emitted when the session ends and server authentication and any gateway authentication was successful. There may be further messages related to the session after this message due to post processing of session data!
Example message:
{"vendor":"OneIdentity","user":"root","transport":"tcp","src_user":"gwtestauto","src_port":"48302","src_ip":"10.30.0.24","src":"client.acme.com","session_id":"svc-mBbMWzauBWHQN9TpoZz8mD-my_connection-12","product":"SPS-5.11.0","event_name":"SessionClosed","dvc":"sps1.acme.com","dest_port":"22","dest_ip":"10.170.255.206","dest":"server.acme.com","app":"ssh","_time":"1557912765545"}
The message contains the following fields.
|
Field |
Name |
Scope |
Present |
|
vendor |
Device vendor |
product |
always |
Description: fixed to OneIdentity
Example: OneIdentity
|
Field |
Name |
Scope |
Present |
|
product |
Product version |
product |
always |
Description: short product name with version
Example: SPS-5.11.0
|
Field |
Name |
Scope |
Present |
|
dvc |
Device fqdn |
device |
always |
Description: the hostname of SPS
Example: sps1.acme.com
|
Field |
Name |
Scope |
Present |
|
session_id |
Session ID |
session |
always |
Description: the unique identifier of the session
Example: svc-hjdBxA2UWkTadH3juDVwrT-my_connection-0
|
Field |
Name |
Scope |
Present |
|
event_name |
Event name |
message |
always |
Description: the type of the message
Example: SessionClosed
|
Field |
Name |
Scope |
Present |
|
_time |
Timestamp |
message |
always |
Description: the UNIX time stamp when the event occurred
Example: 1554470652340
|
Field |
Name |
Scope |
Present |
|
app |
Application protocol |
session |
always |
Description: SPS supported protocol
Example: ssh
|
Field |
Name |
Scope |
Present |
|
dest_ip |
Destination address |
session |
always |
Description: the IP address of the server
Example: 10.170.255.206
|
Field |
Name |
Scope |
Present |
|
dest |
Destination host name |
session |
always |
Description: the server hostname or IP address if hostname is not known
Example: server.acme.com
|
Field |
Name |
Scope |
Present |
|
user |
Name of the user |
session |
always |
Description: the server username
Example: root
|
Field |
Name |
Scope |
Present |
|
dest_port |
Destination port |
session |
always |
Description: the port number on the server
Example: 22
|
Field |
Name |
Scope |
Present |
|
src_ip |
Source address |
session |
always |
Description: the IP address of the client
Example: 10.30.0.24
|
Field |
Name |
Scope |
Present |
|
src |
Source host name |
session |
always |
Description: the client hostname or IP address if hostname is not known
Example: client.acme.com
|
Field |
Name |
Scope |
Present |
|
src_user |
Source username |
session |
sometimes |
Description: the authenticated gateway username if there was a successful gateway authentication
Example: gwtestauto
|
Field |
Name |
Scope |
Present |
|
src_port |
Source port |
session |
always |
Description: the port number on the client
Example: 38014
|
Field |
Name |
Scope |
Present |
|
transport |
Transport |
session |
always |
Description: the layer 3 protocol
Example: tcp
SessionClosed after a failed gateway authentication
Description of the message: Emitted when the session ends because gateway authentication failed.
Example message:
{"vendor":"OneIdentity","user":"","transport":"tcp","src_user":"","src_port":"49070","src_ip":"10.30.0.24","src":"client.acme.com","session_id":"svc-mBbMWzauBWHQN9TpoZz8mD-my_connection-15","product":"SPS-5.11.0","event_name":"SessionClosed","dvc":"sps1.acme.com","dest_port":"","dest_ip":"","dest":"","app":"ssh","_time":"1557912792398"}
The message contains the following fields.
|
Field |
Name |
Scope |
Present |
|
vendor |
Device vendor |
product |
always |
Description: fixed to OneIdentity
Example: OneIdentity
|
Field |
Name |
Scope |
Present |
|
product |
Product version |
product |
always |
Description: short product name with version
Example: SPS-5.11.0
|
Field |
Name |
Scope |
Present |
|
dvc |
Device fqdn |
device |
always |
Description: the hostname of SPS
Example: sps1.acme.com
|
Field |
Name |
Scope |
Present |
|
session_id |
Session ID |
session |
always |
Description: the unique identifier of the session
Example: svc-hjdBxA2UWkTadH3juDVwrT-my_connection-0
|
Field |
Name |
Scope |
Present |
|
event_name |
Event name |
message |
always |
Description: the type of the message
Example: SessionClosed
|
Field |
Name |
Scope |
Present |
|
_time |
Timestamp |
message |
always |
Description: the UNIX time stamp when the event occurred
Example: 1554470652340
|
Field |
Name |
Scope |
Present |
|
app |
Application protocol |
session |
always |
Description: SPS supported protocol
Example: ssh
|
Field |
Name |
Scope |
Present |
|
dest_ip |
Destination address |
session |
always |
Description: empty, not known in this message type
Example:
|
Field |
Name |
Scope |
Present |
|
dest |
Destination host name |
session |
always |
Description: empty, not known in this message type
Example:
|
Field |
Name |
Scope |
Present |
|
user |
Name of the user |
message |
always |
Description: empty, not known in this message type
Example:
|
Field |
Name |
Scope |
Present |
|
dest_port |
Destination port |
session |
always |
Description: empty, not known in this message type
Example:
|
Field |
Name |
Scope |
Present |
|
src_ip |
Source address |
session |
always |
Description: the IP address of the client
Example: 10.30.0.24
|
Field |
Name |
Scope |
Present |
|
src |
Source host name |
session |
always |
Description: the client hostname or IP address if hostname is not known
Example: client.acme.com
|
Field |
Name |
Scope |
Present |
|
src_user |
Source username |
session |
always |
Description: empty, not known in this message type
Example:
|
Field |
Name |
Scope |
Present |
|
src_port |
Source port |
session |
always |
Description: the port number on the client
Example: 38014
|
Field |
Name |
Scope |
Present |
|
transport |
Transport |
session |
always |
Description: the layer 3 protocol
Example: tcp
SessionClosed after a failed server authentication
Description of the message: Emitted when the session ends because server authentication failed.
Example message:
{"vendor":"OneIdentity","user":"","transport":"tcp","src_user":"gwtestauto","src_port":"49426","src_ip":"10.30.0.24","src":"client.acme.com","session_id":"svc-mBbMWzauBWHQN9TpoZz8mD-my_connection-17","product":"SPS-5.11.0","event_name":"SessionClosed","dvc":"sps1.acme.com","dest_port":"22","dest_ip":"10.170.255.206","dest":"server.acme.com","app":"ssh","_time":"1557912813792"}
The message contains the following fields.
|
Field |
Name |
Scope |
Present |
|
vendor |
Device vendor |
product |
always |
Description: fixed to OneIdentity
Example: OneIdentity
|
Field |
Name |
Scope |
Present |
|
product |
Product version |
product |
always |
Description: short product name with version
Example: SPS-5.11.0
|
Field |
Name |
Scope |
Present |
|
dvc |
Device fqdn |
device |
always |
Description: the hostname of SPS
Example: sps1.acme.com
|
Field |
Name |
Scope |
Present |
|
session_id |
Session ID |
session |
always |
Description: the unique identifier of the session
Example: svc-hjdBxA2UWkTadH3juDVwrT-my_connection-0
|
Field |
Name |
Scope |
Present |
|
event_name |
Event name |
message |
always |
Description: the type of the message
Example: SessionClosed
|
Field |
Name |
Scope |
Present |
|
_time |
Timestamp |
message |
always |
Description: the UNIX time stamp when the event occurred
Example: 1554470652340
|
Field |
Name |
Scope |
Present |
|
app |
Application protocol |
session |
always |
Description: SPS supported protocol
Example: ssh
|
Field |
Name |
Scope |
Present |
|
dest_ip |
Destination address |
session |
always |
Description: the IP address of the server
Example: 10.170.255.206
|
Field |
Name |
Scope |
Present |
|
dest |
Destination host name |
session |
always |
Description: the server hostname or IP address if hostname is not known
Example: server.acme.com
|
Field |
Name |
Scope |
Present |
|
user |
Name of the user |
message |
always |
Description: empty, not known in this message type
Example:
|
Field |
Name |
Scope |
Present |
|
dest_port |
Destination port |
session |
always |
Description: the port number on the server
Example: 22
|
Field |
Name |
Scope |
Present |
|
src_ip |
Source address |
session |
always |
Description: the IP address of the client
Example: 10.30.0.24
|
Field |
Name |
Scope |
Present |
|
src |
Source host name |
session |
always |
Description: the client hostname or IP address if hostname is not known
Example: client.acme.com
|
Field |
Name |
Scope |
Present |
|
src_user |
Source username |
session |
sometimes |
Description: the authenticated gateway username if there was a successful gateway authentication
Example: gwtestauto
|
Field |
Name |
Scope |
Present |
|
src_port |
Source port |
session |
always |
Description: the port number on the client
Example: 38014
|
Field |
Name |
Scope |
Present |
|
transport |
Transport |
session |
always |
Description: the layer 3 protocol
Example: tcp
RdpEmbeddedInTsg
Description of the message: Emitted when the gateway user is acquired in a Terminal Service Gateway authentication scenario.
Example message:
{"vendor":"OneIdentity","user":"","transport":"tcp","src_user":"gwtestauto","src_port":"51204","src_ip":"10.30.0.24","src":"client.acme.com","session_id":"svc-oUDm7arcL8zNb3t2CVwSQr-my_connection-47-4","product":"SPS-5.11.0","event_name":"RdpEmbeddedInTsg","dvc":"sps1.acme.com","dest_port":"","dest_ip":"","dest":"","app":"rdp","action":"allowed","_time":"1558006936608"}
The message contains the following fields.
|
Field |
Name |
Scope |
Present |
|
vendor |
Device vendor |
product |
always |
Description: fixed to OneIdentity
Example: OneIdentity
|
Field |
Name |
Scope |
Present |
|
product |
Product version |
product |
always |
Description: short product name with version
Example: SPS-5.11.0
|
Field |
Name |
Scope |
Present |
|
dvc |
Device fqdn |
device |
always |
Description: the hostname of SPS
Example: sps1.acme.com
|
Field |
Name |
Scope |
Present |
|
session_id |
Session ID |
session |
always |
Description: the unique identifier of the session
Example: svc-hjdBxA2UWkTadH3juDVwrT-my_connection-0
|
Field |
Name |
Scope |
Present |
|
event_name |
Event name |
message |
always |
Description: the type of the message
Example: RdpEmbeddedInTsg
|
Field |
Name |
Scope |
Present |
|
action |
Action |
message |
always |
Description: the action taken by the device according to CIM model
Example: allowed
|
Field |
Name |
Scope |
Present |
|
_time |
Timestamp |
message |
always |
Description: the UNIX time stamp when the event occurred
Example: 1554470652340
|
Field |
Name |
Scope |
Present |
|
app |
Application protocol |
session |
always |
Description: SPS supported protocol
Example: ssh
|
Field |
Name |
Scope |
Present |
|
dest_ip |
Destination address |
session |
always |
Description: empty, not known in this message type
Example:
|
Field |
Name |
Scope |
Present |
|
dest |
Destination host name |
session |
always |
Description: empty, not known in this message type
Example:
|
Field |
Name |
Scope |
Present |
|
user |
Name of the user |
message |
always |
Description: empty, not known in this message type
Example:
|
Field |
Name |
Scope |
Present |
|
dest_port |
Destination port |
session |
always |
Description: empty, not known in this message type
Example:
|
Field |
Name |
Scope |
Present |
|
src_ip |
Source address |
session |
always |
Description: the IP address of the client
Example: 10.30.0.24
|
Field |
Name |
Scope |
Present |
|
src |
Source host name |
session |
always |
Description: the client hostname or IP address if hostname is not known
Example: client.acme.com
|
Field |
Name |
Scope |
Present |
|
src_user |
Source username |
session |
always |
Description: the authenticated gateway username
Example: gwtestauto
|
Field |
Name |
Scope |
Present |
|
src_port |
Source port |
session |
always |
Description: the port number on the client
Example: 38014
|
Field |
Name |
Scope |
Present |
|
transport |
Transport |
session |
always |
Description: the layer 3 protocol
Example: tcp
SessionScored
Description of the message: Score messages represent scoring events when SPS has calculated an initial or changed score for the session.
Example message:
{"vendor":"OneIdentity","signature":"keystroke","session_id":"svc-416YVFZMy7rT8RA7T7yeAs-my_connection-0","product":"SPS-5.11.0","event_name":"SessionScored","dvc":"sps1.acme.com","algorithm_score":"18","algorithm_name":"keystroke","aggregated_score":"70","action":"allowed","_time":"1558010880806"}
The message contains the following fields.
|
Field |
Name |
Scope |
Present |
|
vendor |
Device vendor |
product |
always |
Description: fixed to OneIdentity
Example: OneIdentity
|
Field |
Name |
Scope |
Present |
|
product |
Product version |
product |
always |
Description: short product name with version
Example: SPS-5.11.0
|
Field |
Name |
Scope |
Present |
|
dvc |
Device fqdn |
device |
always |
Description: the hostname of SPS
Example: sps1.acme.com
|
Field |
Name |
Scope |
Present |
|
session_id |
Session ID |
session |
always |
Description: the unique identifier of the session
Example: svc-hjdBxA2UWkTadH3juDVwrT-my_connection-0
|
Field |
Name |
Scope |
Present |
|
event_name |
Event name |
message |
always |
Description: the type of the message
Example: SessionScored
|
Field |
Name |
Scope |
Present |
|
action |
Action |
message |
always |
Description: the action taken by the device according to CIM model
Example: allowed
|
Field |
Name |
Scope |
Present |
|
_time |
Timestamp |
message |
always |
Description: the UNIX time stamp when the event occurred
Example: 1554470652340
|
Field |
Name |
Scope |
Present |
|
aggregated_score |
Aggregated score |
message |
always |
Description: the average score from all enabled analytics algorithms
Example: 50
|
Field |
Name |
Scope |
Present |
|
algorithm_name |
Algorithm name |
message |
always |
Description: the name of the algorithm that changed value
Example: keystroke
|
Field |
Name |
Scope |
Present |
|
signature |
Signature |
message |
always |
Description: the algorithm name as CIM intrusion detection signature
Example: hostlogin
|
Field |
Name |
Scope |
Present |
|
algorithm_score |
Algorithm score |
message |
always |
Description: the new score value of the algorithm that changed value
Example: 60
CommandChannelEvent
Description of the message: Emitted when a command is detected in the session channel text.
Example message:
{"vendor":"OneIdentity","session_id":"svc-mBbMWzauBWHQN9TpoZz8mD-my_connection-12","product":"SPS-5.11.0","event_name":"CommandChannelEvent","dvc":"sps1.acme.com","command":"exit","action":"allowed","_time":"1557912765461"}
The message contains the following fields.
|
Field |
Name |
Scope |
Present |
|
vendor |
Device vendor |
product |
always |
Description: fixed to OneIdentity
Example: OneIdentity
|
Field |
Name |
Scope |
Present |
|
product |
Product version |
product |
always |
Description: short product name with version
Example: SPS-5.11.0
|
Field |
Name |
Scope |
Present |
|
dvc |
Device fqdn |
device |
always |
Description: the hostname of SPS
Example: sps1.acme.com
|
Field |
Name |
Scope |
Present |
|
session_id |
Session ID |
session |
always |
Description: the unique identifier of the session
Example: svc-hjdBxA2UWkTadH3juDVwrT-my_connection-0
|
Field |
Name |
Scope |
Present |
|
event_name |
Event name |
message |
always |
Description: the type of the message
Example: CommandChannelEvent
|
Field |
Name |
Scope |
Present |
|
action |
Action |
message |
always |
Description: the action taken by the device according to CIM model
Example: allowed
|
Field |
Name |
Scope |
Present |
|
_time |
Timestamp |
message |
always |
Description: the UNIX time stamp when the event occurred
Example: 1554470652340
|
Field |
Name |
Scope |
Present |
|
command |
Command |
message |
always |
Description: the full command detected
Example: exit
WindowTitleChannelEvent
Description of the message: Emitted when a command is detected in the session channel text.
Example message:
{"window_title":"Shortcut Tools Application Tools Administrative Tools","vendor":"OneIdentity","session_id":"svc-oUDm7arcL8zNb3t2CVwSQr-my_connection-47-4","product":"SPS-5.11.0","event_name":"WindowTitleChannelEvent","dvc":"sps1.acme.com","action":"allowed","_time":"1558007001482"}
The message contains the following fields.
|
Field |
Name |
Scope |
Present |
|
vendor |
Device vendor |
product |
always |
Description: fixed to OneIdentity
Example: OneIdentity
|
Field |
Name |
Scope |
Present |
|
product |
Product version |
product |
always |
Description: short product name with version
Example: SPS-5.11.0
|
Field |
Name |
Scope |
Present |
|
dvc |
Device fqdn |
device |
always |
Description: the hostname of SPS
Example: sps1.acme.com
|
Field |
Name |
Scope |
Present |
|
session_id |
Session ID |
session |
always |
Description: the unique identifier of the session
Example: svc-hjdBxA2UWkTadH3juDVwrT-my_connection-0
|
Field |
Name |
Scope |
Present |
|
event_name |
Event name |
message |
always |
Description: the type of the message
Example: WindowTitleChannelEvent
|
Field |
Name |
Scope |
Present |
|
action |
Action |
message |
always |
Description: the action taken by the device according to CIM model
Example: allowed
|
Field |
Name |
Scope |
Present |
|
_time |
Timestamp |
message |
always |
Description: the UNIX time stamp when the event occurred
Example: 1554470652340
|
Field |
Name |
Scope |
Present |
|
window_title |
Window title |
message |
always |
Description: the window title detected in graphical protocol
Example: firefox
FileTransfer
Description of the message: Emitted when a command is detected in the session channel text.
Example message:
{"vendor":"OneIdentity","session_id":"svc-2L83Phh9J6GKLWTc881awk-my_connection-324","product":"SPS-5.11.0","file_path":"/cpuinfo","file_operation":"UPLOAD","file_name":"cpuinfo","event_name":"FileTransfer","dvc":"sps1.acme.com","action":"allowed","_time":"1558023721326"}
The message contains the following fields.
|
Field |
Name |
Scope |
Present |
|
vendor |
Device vendor |
product |
always |
Description: fixed to OneIdentity
Example: OneIdentity
|
Field |
Name |
Scope |
Present |
|
product |
Product version |
product |
always |
Description: short product name with version
Example: SPS-5.11.0
|
Field |
Name |
Scope |
Present |
|
dvc |
Device fqdn |
device |
always |
Description: the hostname of SPS
Example: sps1.acme.com
|
Field |
Name |
Scope |
Present |
|
session_id |
Session ID |
session |
always |
Description: the unique identifier of the session
Example: svc-hjdBxA2UWkTadH3juDVwrT-my_connection-0
|
Field |
Name |
Scope |
Present |
|
event_name |
Event name |
message |
always |
Description: the type of the message
Example: FileTransfer
|
Field |
Name |
Scope |
Present |
|
action |
Action |
message |
always |
Description: the action taken by the device according to CIM model
Example: allowed
|
Field |
Name |
Scope |
Present |
|
_time |
Timestamp |
message |
always |
Description: the UNIX time stamp when the event occurred
Example: 1554470652340
|
Field |
Name |
Scope |
Present |
|
file_operation |
Operation |
message |
always |
Description: the operation on the file such as UPLOAD/DOWNLOAD. It may contain the suffix 'WARNING', if the operation failed
Example: UPLOAD
|
Field |
Name |
Scope |
Present |
|
file_name |
Filename |
message |
always |
Description: the file name
Example: foobar.txt
|
Field |
Name |
Scope |
Present |
|
file_path |
Full file path |
message |
always |
Description: the name of the file including its path on the server
Example: /tmp/foobar.txt