AppOmni

Top Level Fieldset: True

Contains fields related to the service, organization, and collection of an event.

AppOmni Fields

appomni.alert.channel

Required Field: False
Type: STRING
Example: prod
Detection Supported Field: False

The channel of a rule is determined by the stage of the rule lifecycle.

Allowed Values

NameDescription
prodReflects rule that has been made Generally Available to AppOmni Customers.
betaReflects rule that is in beta.
testingReflects rule that is in development.
ao_only_prodRule for internal AppOmni usage that is in production.
ao_only_betaRule for internal AppOmni usage that is in beta.
ao_only_testingRule for internal AppOmni usage that is in testing.

appomni.event.collected_time

Required Field: False
Type: DATETIME
Example: 2022-11-17T06:33:55.589Z
Detection Supported Field: False

Timestamp when the event was collected by AppOmni.


appomni.event.dataset

Required Field: True
Type: STRING
Example: appomni_qa
Detection Supported Field: True

The dataset of the event. A dataset is generally a collection of similar events.

Allowed Values

NameDescription
onepassword_auditlogOnePassword Audit Events
ao_auditlogsAppOmni Audit Events
ao_canaryAppOmni Canary Events
appomni_alertAppOmni Alerts
appomni_eventAppOmni Events
appomni_qaAppOmni QA Events
arista_auditlogArista Audit Events
asana_eventlogAsana Audit Events
auth0_auditlogAuth0 Audit Events
bitbucket_auditlogBitbucket Audit Events
box_admin_logsBox Audit Events
confluence_eventlogConfluence Audit Events
cradlepoint_activity_logCradlepoint Activity Logs
crowdstrike_audit_logCrowdStrike Audit Events
crowdstrike_auth_activityCrowdStrike Authentication Audit Events
crowdstrike_cspm_ioa_eventCrowdStrike Falcon Horizon CSPM Assessment Events
crowdstrike_cspm_search_eventCrowdStrike Falcon Horizon CSPM Audit Events
crowdstrike_detection_summaryCrowdStrike Detection Events
crowdstrike_external_api_activityCrowdStrike 3rd Party App Audit Events
crowdstrike_identity_protection_eventCrowdStrike Identity Protection Events
crowdstrike_idp_detection_summaryCrowdStrike Identity Detection Events
crowdstrike_incident_summaryCrowdStrike Incident Events
crowdstrike_ioc_eventCrowdStrike Custom IOC Audit Events
crowdstrike_firewall_matchCrowdStrike Firewall Audit Events
crowdstrike_mobile_detection_summaryCrowdStrike Mobile Detection Events
crowdstrike_realtime_response_endCrowdStrike Real Time Response End Audit Events
crowdstrike_realtime_response_startCrowdStrike Real Time Response Start Audit Events
crowdstrike_recon_summaryCrowdStrike Intelligence Monitoring Events
crowdstrike_user_activityCrowdStrike User Activity Audit Events
crowdstrike_xdr_detection_summaryCrowdStrike XDR Detection Events
crowdstrike_unknownCrowdStrike Unidentified Event Types
custom_eventlog_pushCustom App Events
custom_rawlogCustom Raw Events
databricks_auditlogDatabricks Audit Events
datadog_auditlogDatadog Audit Events
duo_adminDuo Administrative Activity
duo_authDuo Authentication Activity
docusign_envelope_auditDocuSign Audit Events
docusign_monitorDocuSign Monitor Alerts
fastly_auditlogFastly Audit Events
github_auditGitHub Audit Events
github_webhookGitHub Webhook Events
gitlab_audit_eventsGitLab Audit Events
gsuite_admin_logGoogle Workspace Admin Events
gsuite_alert_center_logGoogle Workspace Alert Center Alerts
gsuite_drive_logGoogle Workspace Drive Events
gsuite_login_logGoogle Workspace Login Events
gsuite_mobile_logGoogle Workspace Mobile Events
gsuite_token_logGoogle Workspace Token Events
hubspot_auditlogHubSpot Audit Events
imanage_auditlogiManage Audit Events
jamf_auditlogJamf Audit Events
jira_eventlogJira Events
jumpcloud_auditlogJumpCloud Audit Events
juniper_system_logJuniper System Log Messages
lucid_eventlogLucidchart Events
miro_auditlogMiro Events
monday_auditlogMonday Audit Events
netsuite_login_logNetSuite Login Events
netsuite_perm_change_logNetSuite Permission Changes Events
netsuite_role_logNetSuite Roles Events
notion_auditlogNotion Audit Events
o365_audit_azure_active_directoryMicrosoft 365 Azure Active Directory Audit Events
o365_audit_exchangeMicrosoft 365 Exchange Audit Events
o365_audit_generalMicrosoft 365 General Audit Events
o365_audit_sharepointMicrosoft 365 Sharepoint Audit Events
o365_dlp_allMicrosoft 365 DLP Events
mongodb_atlasMongoDB Atlas Events
okta_syslogOkta System Events
onelogin_eventlogOneLogin Events
openblue_auditlogOpenBlue Audit Events
sapsf_sfapi_eventlogSAP SuccessFactors API Events
sapsf_odata_api_eventlogSAP SuccessFactors OData Events
ping_eventlogPing Identity
sfdc_admin_setup_event_tableSalesforce Admin Setup Events
sfdc_api_anomaly_event_storeSalesforce API Usage Anomalies Events
sfdc_api_event_tableSalesforce Read-Only API Events
sfdc_audit_trailSalesforce Audit Events
sfdc_batch_event_logSalesforce Batch Events
sfdc_bulk_api_result_event_storeSalesforce Bulk API Events
sfdc_content_transfer_event_storeSalesforce Content Transfer Events
sfdc_credential_stuffing_event_storeSalesforce Credential Stuffing Login Events
sfdc_data_querySalesforce Data Query Events
sfdc_field_modification_historySalesforce Field History Events
sfdc_fsecureSalesforce F-Secure Events
sfdc_identity_verification_event_storeSalesforce User Identity Verification Events
sfdc_idp_event_storeSalesforce Identity Provider Events
sfdc_lightning_uri_event_tableSalesforce Lightning Experience User CRUD Events
sfdc_list_view_event_tableSalesforce List View Events
sfdc_login_as_event_tableSalesforce Admin Login As User Events
sfdc_login_event_tableSalesforce User Login Events
sfdc_logout_event_tableSalesforce User Logout events
sfdc_oauth_connectionSalesforce OAuth Connection Events
sfdc_permission_event_storeSalesforce Permission Events
sfdc_report_anomaly_event_storeSalesforce Report Anomaly Events
sfdc_report_event_tableSalesforce Report Events
sfdc_session_hijacking_event_storeSalesforce Session Hijacking Events
sfdc_uri_event_tableSalesforce User Record CRUD Events
sfmc_audit_eventSalesforce Marketing Cloud Audit Events
sfmc_security_eventSalesforce Marketing Cloud Security Events
slack_auditlogSlack Audit Events
smartsheet_auditlogSmartsheet Audit Events
sendgrid_auditlogSendGrid Events
snow_export_logServiceNow Export Events
snow_mid_command_logServiceNow MID Server Command Events
snow_sysauditServiceNow System Audit Events
snow_sysaudit_roleServiceNow System Role Events
snow_syseventServiceNow System Events
snow_syslogServiceNow Syslog Events
snowflake_login_historySnowflake Login Events
snowflake_query_historySnowflake Query History Events
stripe_eventlogStripe Events
tableau_activitylogsTableau Activity Events
veevavault_login_audit_trailVeevaVault Login Events
veevavault_system_audit_trailVeevaVault System Events
veevavault_document_audit_trailVeevaVault Document Events
veevavault_object_audit_trailVeevaVault Object Record Events
versa_auditlogVersa Audit Events
webex_admin_auditWebEx Admin Audit Events
wiz_auditWiz Audit Events
workday_auditlog_user_activityWorkday User Activity Events
workday_activity_loggingWorkday Activity Logging Events
zendesk_auditlogZendesk Audit Events
zoom_recordingsZoom Recording Events
zoom_webhookZoom Webhook Events

appomni.event.enrichments

Required Field: False
Type: ARRAY
Example: ['ipinfo']
Detection Supported Field: True

List of 3rd party sources that contributed enrichment information to an event.


appomni.event.id

Required Field: True
Type: UUID
Example: 312b0a2d-a7a3-4529-bd61-bf3c2e2ba11d
Detection Supported Field: False

Unique AppOmni-assigned ID of the event.


appomni.event.ingestion_time

Required Field: False
Type: DATETIME
Example: 2022-11-17T06:34:18.429Z
Detection Supported Field: False

Timestamp when the event arrived in AppOmni's data store.


appomni.event.parent_id

Required Field: False
Type: UUID
Example: 733e5b47-d79b-40c1-bc8c-b19c22137785
Detection Supported Field: False

Unique ID of the parent event.


appomni.event.sortable_event_id

Required Field: False
Type: ULID
Example: 01GJ3CQYGGJ4GJP2WWBPRH07H8
Detection Supported Field: False

Unique sortable ID of the event assigned when it's collected.


appomni.event.sortable_ingest_id

Required Field: False
Type: ULID
Example: 01GJ3CQYGGJ4GJP2WWBPRH07H8
Detection Supported Field: False

Unique sortable ID of the event assigned when it arrives in AppOmni's data store.


appomni.organization.id

Required Field: True
Type: INTEGER
Example: 1
Detection Supported Field: False

ID of the AppOmni Tenant this event originated from.


appomni.service.account_id

Required Field: False
Type: STRING
Example: wehg385
Detection Supported Field: False

Unique platform-assigned ID of the connected monitored service.


appomni.service.id

Required Field: False
Type: INTEGER
Example: 1
Detection Supported Field: False

Unique AppOmni-assigned ID of the connected monitored service.


appomni.service.name

Required Field: False
Type: STRING
Example: AppOmni QA
Detection Supported Field: False

The tenant owner-assigned name of the connected monitored service.


appomni.service.slug

Required Field: False
Type: STRING
Example: tenant__uniq_svc_name
Detection Supported Field: False

The identifier of the monitored service, either the platform shortname for out-of-the-box (OOTB) services or the unique identifier for custom monitored services.


appomni.service.type

Required Field: False
Type: STRING
Example: ao_qa
Detection Supported Field: False

The platform shortname of the monitored service.

Allowed Values

NameDescription
ao_qaAppOmni QA
appomniAppOmni
asanaAsana
auth0Auth0
bitbucketBitbucket
boxBox
confluenceConfluence
crowdstrikeCrowdStrike
customCustom
databricksDatabricks
docusignDocuSign
duoDuo
fastlyFastly
githubGitHub
gsuiteGoogle Workspace
hubspotHubSpot
imanageiManage
jamfJamf
jiraJira
jumpcloudJumpCloud
lucidLucidchart
miroMiro
mongoMongoDB
mondayMonday
multipleMultiple (only used in Alerting)
netsuiteNetsuite
notionNotion
o365Microsoft 365
oktaOkta
oneloginOneLogin
pingPing Identity
sapsfSAP SuccessFactors
sfdcSalesforce
sfmcSalesforce Marketing Cloud
slackSlack
sendgridSendGrid
smartsheetSmartsheet
snowServiceNow
snowflakeSnowflake
stripeStripe
tableauTableau
veevavaultVeevaVault
webexWebEx
wizWiz
workdayWorkday
zendeskZendesk
zoomZoom

appomni.source.id

Required Field: False
Type: STRING
Example: 123e4567-e89b-12d3-a456-426614174000
Detection Supported Field: False

Unique AppOmni-assigned ID of the detection event source.