Skip to main content

Directory Insights Activity Log Filters

You can filter the Directory Insights Data Activity Log with the following filters.

note

Please see the Directory Insights API for a list of event types.

DI Activity Log Table

Field NameDescriptionService Support
application.nameThe application name.- SSO
application.displayNameThe application display name.- SSO
application.display_labelThe application display label.- SSO
application.sso_urlThe application URL.- SSO
association.connection.from.typeThe association object from.- Directory
association.connection.to.typeThe association object to.- Directory
attrA set of attributes to be returned to the client.- LDAP
auth_methodSession = console, api-key = api-key- Directory - LDAP
auth_typeThe authentication type.- RADIUS
client_ipThe IP address the request came from.- Directory - MDM - RADIUS - SSO - Systems
correlation.idThe correlated event ID.- Directory
derefThe alias dereferencing behavior, which indicates how the server should treat any aliases it encounters while processing the search.- LDAP
deviceAll logs associated with the selected device for the supported services.- Directory - Systems
dnDistinguished name (DN) provided for authentication.- LDAP
eap_typeThe EAP type.- RADIUS
error_chain.error_codeThe mdm error code.- MDM
error_chain.error_domainThe mdm error domain.- MDM
error_codeThe result code.- LDAP
error_messageError message in the event.- Directory - RADIUS - LDAP
event_typeThe event type.- Directory - LDAP - MDM - RADIUS - SSO - Systems
filterThe filter criteria for the search with the scope.- LDAP
geoip.continent_codeThe client IP continent code.- Directory - RADIUS - SSO - Systems
geoip.country_codeThe client IP country code.- Directory - RADIUS - SSO - Systems
geoip.region_codeThe client IP region code.- Directory - RADIUS - SSO - Systems
geoip.region_nameThe client IP region name.- Directory - RADIUS - SSO - Systems
geoip.timezoneThe client IP region's timezone.- Directory - RADIUS - SSO - Systems
idThe event’s unique id.- Directory - MDM - RADIUS - SSO - Systems
idp_initiatedTrue if the request was initiated from the Identity Provider (JumpCloud). False if the auth was initiated from the service provider.- SSO
initiated_by.emailEvent initiated by email.- Directory - SSO
initiated_by.typeEvent initiated by type.- Directory - SSO
initiated_by.usernameEvent initiated by username.- Directory - SSO
jumpcloud_durt_eanblement_updateJumpCloud Go toggled on or off in Admin Portal.- Directory
jumpcloud_durt_registrationJumpCloud Go registration on device.- Directory
mechThe authentication method used. Either simple or SASL Note that we don't currently support SASL.- LDAP
mfaIf MFA was used on an authentication attempt.- Directory - RADIUS
mfa_meta.typeThe type of MFA used.- Directory - RADIUS
nas_mfa_state- Disabled: No MFA required - Enabled: MFA is required if the user is configured for MFA - Required: MFA is required unless the user is excluded and not configured for MFA - Always: MFA always required- RADIUS
number_of_resultsThe number of rows returned from the search.- LDAP
operation_numberAll operation requests and operation result pairs are given incremental operation numbers beginning with operation_number=0 to identify the distinct operations being performed.- LDAP
outer.eap_typeThe outer EAP type.- RADIUS
outer.usernameThe outer username.- RADIUS
process_nameThe process that initiated a login attempt.- Systems
providerThe org id of the provider if the org is a provider org.- Directory - Systems
request_typeThe type of command.- MDM
resource.emailThe resource object email.- Directory - Systems
resource.hostnameThe resource object hostname.- Directory - Systems
resource.hostnameThe resource object hostname.- Directory - Systems
resource.nameThe resource name.- Directory - Systems
resource.displayNameThe resource display name.- Directory - Systems
resource.displayLabelThe resource display label.- Directory - Systems
resource.typeThe resource object type.- Directory - Systems
resource.usernameThe resource object username.- Directory - Systems
scopeThe search scope. This specifies the portion of the target subtree that should be considered. Can be: base, only return the specified entry. singleLevel (1) only the immediate children of the entry are considered.- LDAP
serviceWhich service the event originated from.- Directory - LDAP - MDM - RADIUS - SSO - Systems
src_ipThe IP address the login request came from.- Systems
start_tlsThe starttls protocol that was used to open the LDAP connection.- LDAP
statusThe command result: acknowledged, error, command format error, and idle.- MDM
successDeNotes if a login attempt was successful or not.- Directory - LDAP - RADIUS - Systems
system.hostnameThe system hostname.- Systems
system.idSystem unique ID- System - Software
tls_establishedThe LDAPS protocol was used to open the LDAP connection.- LDAP
usernameThe username provided for the auth attempt.- LDAP - RADIUS - Systems
userAll logs associated with the selected user.- Directories - LDAP - RADIUS - SSO - Systems
windows elevatedIf the user had elevated privileges at the time of log in.- Windows
windows logon typeThe type of windows log on. Select a number to view logons for a type. 2 - Interactive logon; log ons from a Windows device's local keyboard and screen We've removed the collection of Windows Service Account log ons to reduce the noise in Directory Insights events to make it easier for customers to identify log ins from JumpCloud managed users. We audit data periodically to ensure that we're collecting the most important information for our customers. Though these events aren't included in Directory Insights, the events are available locally on Windows devices using the Windows Event Viewer. These events can be identified by an Events ID of 4624 and 4625 with the logon_type of 5. We've added a PowerShell command to the JumpCloud Command Gallery you can use to query these events.- Windows

Was this information helpful?