Data Source: Google Workspace login_success

Description

Data source object for Google Workspace login_success

Details

Property Value
Source gws:reports:admin
Sourcetype gws:reports:admin
Separator event.name

Supported Apps

Event Fields

+ Fields
  <span class="pill kill-chain">_time</span>
  
  <span class="pill kill-chain">actor.email</span>
  
  <span class="pill kill-chain">actor.profileId</span>
  
  <span class="pill kill-chain">date_hour</span>
  
  <span class="pill kill-chain">date_mday</span>
  
  <span class="pill kill-chain">date_minute</span>
  
  <span class="pill kill-chain">date_month</span>
  
  <span class="pill kill-chain">date_second</span>
  
  <span class="pill kill-chain">date_wday</span>
  
  <span class="pill kill-chain">date_year</span>
  
  <span class="pill kill-chain">date_zone</span>
  
  <span class="pill kill-chain">etag</span>
  
  <span class="pill kill-chain">event.name</span>
  
  <span class="pill kill-chain">event.parameters{}.boolValue</span>
  
  <span class="pill kill-chain">event.parameters{}.multiValue{}</span>
  
  <span class="pill kill-chain">event.parameters{}.name</span>
  
  <span class="pill kill-chain">event.parameters{}.value</span>
  
  <span class="pill kill-chain">event.type</span>
  
  <span class="pill kill-chain">host</span>
  
  <span class="pill kill-chain">id.applicationName</span>
  
  <span class="pill kill-chain">id.customerId</span>
  
  <span class="pill kill-chain">id.time</span>
  
  <span class="pill kill-chain">id.uniqueQualifier</span>
  
  <span class="pill kill-chain">index</span>
  
  <span class="pill kill-chain">ipAddress</span>
  
  <span class="pill kill-chain">kind</span>
  
  <span class="pill kill-chain">linecount</span>
  
  <span class="pill kill-chain">punct</span>
  
  <span class="pill kill-chain">source</span>
  
  <span class="pill kill-chain">sourcetype</span>
  
  <span class="pill kill-chain">splunk_server</span>
  
  <span class="pill kill-chain">timeendpos</span>
  
  <span class="pill kill-chain">timestartpos</span>
  
</div>

Example Log

1{"kind": "admin#reports#activity", "id": {"time": "2022-10-13T20:57:35.833Z", "uniqueQualifier": "437744618349", "applicationName": "login", "customerId": "C046r85ir"}, "etag": "\"JCPRxFaiNR1s5TJ6ecIH8OpGdY4efiOYXbIB65itOzY/OgAbD-Tz8hSD1vUJWw7NLiJ5SF4\"", "actor": {"email": "user1@splunkresearch.com", "profileId": "112184723778873345717"}, "ipAddress": "45.23.129.123", "event": {"type": "login", "name": "login_success", "parameters": [{"name": "login_type", "value": "google_password"}, {"name": "login_challenge_method", "multiValue": ["password", "password", "password", "password", "password"]}, {"name": "is_suspicious", "boolValue": false}]}}

Source: GitHub | Version: 1