Data Source: O365 Update application.

Logs updates made to applications in Microsoft 365, including changes to configurations, permissions, and role assignments.

Property Value
Source o365
Sourcetype o365:management:activity
Separator Operation
+ Fields

            1
            _time
          
            3
            ActorContextId
          
            5
            Actor{}.ID
          
            7
            Actor{}.Type
          
            9
            AzureActiveDirectoryEventType
          
            11
            CreationTime
          
            13
            ExtendedProperties{}.Name
          
            15
            ExtendedProperties{}.Value
          
            17
            Id
          
            19
            InterSystemsId
          
            21
            IntraSystemId
          
            23
            ModifiedProperties{}.Name
          
            25
            ModifiedProperties{}.NewValue
          
            27
            ModifiedProperties{}.OldValue
          
            29
            ObjectId
          
            31
            Operation
          
            33
            OrganizationId
          
            35
            RecordType
          
            37
            ResultStatus
          
            39
            SupportTicketId
          
            41
            TargetContextId
          
            43
            Target{}.ID
          
            45
            Target{}.Type
          
            47
            UserId
          
            49
            UserKey
          
            51
            UserType
          
            53
            Version
          
            55
            Workload
          
            57
            action
          
            59
            additionalDetails
          
            61
            app
          
            63
            authentication_service
          
            65
            change_type
          
            67
            command
          
            69
            dataset_name
          
            71
            date_hour
          
            73
            date_mday
          
            75
            date_minute
          
            77
            date_month
          
            79
            date_second
          
            81
            date_wday
          
            83
            date_year
          
            85
            date_zone
          
            87
            dest
          
            89
            dest_name
          
            91
            dvc
          
            93
            event_type
          
            95
            eventtype
          
            97
            extendedAuditEventCategory
          
            99
            host
          
            101
            index
          
            103
            linecount
          
            105
            object
          
            107
            object_attrs
          
            109
            object_category
          
            111
            punct
          
            113
            record_type
          
            115
            signature
          
            117
            source
          
            119
            sourcetype
          
            121
            splunk_server
          
            123
            status
          
            125
            tag
          
            127
            tag::eventtype
          
            129
            timeendpos
          
            131
            timestartpos
          
            133
            user
          
            135
            user_agent
          
            137
            user_agent_change
          
            139
            user_id
          
            141
            user_type
          
            143
            vendor_account
          
            145
            vendor_product
          
            147
            
          
...
not set
1{"CreationTime": "2023-09-01T17:16:20", "Id": "c428c85c-4fa0-4e97-9033-6a76d9dee45d", "Operation": "Update application.", "OrganizationId": "58aee3b9-7433-46a0-b54e-2429487992a0", "RecordType": 8, "ResultStatus": "Success", "UserKey": "1003BFFD98415B4E@contoso.onmicrosoft.com", "UserType": 0, "Version": 1, "Workload": "AzureActiveDirectory", "ObjectId": "Application_a2d68f8b-ab9f-47ac-934f-b966c3ac134f", "UserId": "attacker@contoso.onmicrosoft.com", "AzureActiveDirectoryEventType": 1, "ExtendedProperties": [{"Name": "additionalDetails", "Value": "{\"User-Agent\":\"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Safari/537.36\",\"AppId\":\"95106c0e-3519-450e-8e38-7f326d873454\"}"}, {"Name": "extendedAuditEventCategory", "Value": "Application"}], "ModifiedProperties": [{"Name": "RequiredResourceAccess", "NewValue": "[\r\n  {\r\n    \"ResourceAppId\": \"00000003-0000-0000-c000-000000000000\",\r\n    \"RequiredAppPermissions\": [\r\n      {\r\n        \"EntitlementId\": \"e1fe6dd8-ba31-4d61-89e7-88639da4683d\",\r\n        \"DirectAccessGrant\": false,\r\n        \"ImpersonationAccessGrants\": [\r\n          20\r\n        ]\r\n      },\r\n      {\r\n        \"EntitlementId\": \"810c84a8-4a9e-49e6-bf7d-12d183f40d01\",\r\n        \"DirectAccessGrant\": true,\r\n        \"ImpersonationAccessGrants\": []\r\n      },\r\n      {\r\n        \"EntitlementId\": \"b633e1c5-b582-4048-a93e-9f11b44c7e96\",\r\n        \"DirectAccessGrant\": true,\r\n        \"ImpersonationAccessGrants\": []\r\n      }\r\n    ],\r\n    \"EncodingVersion\": 1\r\n  }\r\n]", "OldValue": "[\r\n  {\r\n    \"ResourceAppId\": \"00000003-0000-0000-c000-000000000000\",\r\n    \"RequiredAppPermissions\": [\r\n      {\r\n        \"EntitlementId\": \"e1fe6dd8-ba31-4d61-89e7-88639da4683d\",\r\n        \"DirectAccessGrant\": false,\r\n        \"ImpersonationAccessGrants\": [\r\n          20\r\n        ]\r\n      }\r\n    ],\r\n    \"EncodingVersion\": 1\r\n  }\r\n]"}, {"Name": "Included Updated Properties", "NewValue": "RequiredResourceAccess", "OldValue": ""}], "Actor": [{"ID": "attacker@contoso.onmicrosoft.com", "Type": 5}, {"ID": "1003BFFD98415B4E", "Type": 3}, {"ID": "18ed3507-a475-4ccb-b669-d66bc9f2a36e", "Type": 2}, {"ID": "User_e4c722ac-3b83-478d-8f52-c388885dc30f", "Type": 2}, {"ID": "e4c722ac-3b83-478d-8f52-c388885dc30f", "Type": 2}, {"ID": "User", "Type": 2}], "ActorContextId": "58aee3b9-7433-46a0-b54e-2429487992a0", "InterSystemsId": "6a0bc9d4-eb2d-4eb0-a524-601dac6914a6", "IntraSystemId": "a2d4d7c4-727c-401b-9e6c-70413a080855", "SupportTicketId": "", "Target": [{"ID": "Application_a2d68f8b-ab9f-47ac-934f-b966c3ac134f", "Type": 2}, {"ID": "a2d68f8b-ab9f-47ac-934f-b966c3ac134f", "Type": 2}, {"ID": "Application", "Type": 2}, {"ID": "TestApp2", "Type": 1}, {"ID": "95106c0e-3519-450e-8e38-7f326d873454", "Type": 2}], "TargetContextId": "58aee3b9-7433-46a0-b54e-2429487992a0"}

Source: GitHub | Version: 2