Data Source: Google Workspace login_failure

Description

Data source object for Google Workspace login_failure

Details

Property Value
Source gws:reports:admin
Sourcetype gws:reports:admin
Separator event.name

Supported Apps

Event Fields

+ Fields
  <span class="pill kill-chain">_time</span>
  
  <span class="pill kill-chain">actor.email</span>
  
  <span class="pill kill-chain">actor.profileId</span>
  
  <span class="pill kill-chain">date_hour</span>
  
  <span class="pill kill-chain">date_mday</span>
  
  <span class="pill kill-chain">date_minute</span>
  
  <span class="pill kill-chain">date_month</span>
  
  <span class="pill kill-chain">date_second</span>
  
  <span class="pill kill-chain">date_wday</span>
  
  <span class="pill kill-chain">date_year</span>
  
  <span class="pill kill-chain">date_zone</span>
  
  <span class="pill kill-chain">etag</span>
  
  <span class="pill kill-chain">event.name</span>
  
  <span class="pill kill-chain">event.parameters{}.multiValue{}</span>
  
  <span class="pill kill-chain">event.parameters{}.name</span>
  
  <span class="pill kill-chain">event.parameters{}.value</span>
  
  <span class="pill kill-chain">event.type</span>
  
  <span class="pill kill-chain">eventtype</span>
  
  <span class="pill kill-chain">host</span>
  
  <span class="pill kill-chain">id.applicationName</span>
  
  <span class="pill kill-chain">id.customerId</span>
  
  <span class="pill kill-chain">id.time</span>
  
  <span class="pill kill-chain">id.uniqueQualifier</span>
  
  <span class="pill kill-chain">index</span>
  
  <span class="pill kill-chain">ipAddress</span>
  
  <span class="pill kill-chain">kind</span>
  
  <span class="pill kill-chain">linecount</span>
  
  <span class="pill kill-chain">punct</span>
  
  <span class="pill kill-chain">source</span>
  
  <span class="pill kill-chain">sourcetype</span>
  
  <span class="pill kill-chain">splunk_server</span>
  
  <span class="pill kill-chain">tag</span>
  
  <span class="pill kill-chain">tag::eventtype</span>
  
  <span class="pill kill-chain">timeendpos</span>
  
  <span class="pill kill-chain">timestartpos</span>
  
</div>

Example Log

1{"kind": "admin#reports#activity", "id": {"time": "2022-10-12T01:05:35.119Z", "uniqueQualifier": "720229394436", "applicationName": "login", "customerId": "C046r85ir"}, "etag": "\"JCPRxFaiNR1s5TJ6ecIH8OpGdY4efiOYXbIB65itOzY/_lixtTooT11WXorGf6w6ElN0m0g\"", "actor": {"email": "user29@daftpunk.com", "profileId": "114679690119024644513"}, "ipAddress": "141.254.89.27", "event": {"type": "login", "name": "login_failure", "parameters": [{"name": "login_type", "value": "unknown"}, {"name": "login_challenge_method", "multiValue": ["password"]}]}}

Source: GitHub | Version: 1