\n \n association.connection.from.type <\/td>\n | \n The association object from. <\/td>\n | \n \n- Directory<\/li>\n<\/ul><\/div> <\/td>\n <\/tr>\n
\n \n association.connection.to.type <\/td>\n | \n The association object to. <\/td>\n | \n \n- Directory<\/li>\n<\/ul><\/div> <\/td>\n <\/tr>\n
\n \n attr <\/td>\n | \n A set of attributes to be returned to the client. <\/td>\n | \n \n- LDAP<\/li>\n<\/ul><\/div> <\/td>\n <\/tr>\n
\n \n auth_method <\/td>\n | \n Session = console, api-key = api-key <\/td>\n | \n \n \n- Directory<\/li>\n
- LDAP<\/li>\n<\/ul>\n<\/div> <\/td>\n <\/tr>\n
\n \n auth_type <\/td>\n | \n The authentication type. <\/td>\n | \n \n- RADIUS<\/li>\n<\/ul><\/div> <\/td>\n <\/tr>\n
\n \n client_ip <\/td>\n | \n The IP address the request came from. <\/td>\n | \n \n \n- Directory<\/li>\n
- MDM<\/li>\n
- RADIUS<\/li>\n
- SSO<\/li>\n
- Systems<\/li>\n<\/ul>\n<\/div> <\/td>\n <\/tr>\n
\n \n correlation.id <\/td>\n | \n The correlated event ID. <\/td>\n | \n \n- Directory<\/li>\n<\/ul><\/div> <\/td>\n <\/tr>\n
\n \n deref <\/td>\n | \n The alias dereferencing behavior, which indicates how the server should treat any aliases it encounters while processing the search. <\/td>\n | \n \n- LDAP<\/li>\n<\/ul><\/div> <\/td>\n <\/tr>\n
\n \n device <\/td>\n | \n All logs associated with the selected device for the supported services. <\/td>\n | \n \n \n- Directory<\/li>\n
- Systems<\/li>\n<\/ul>\n<\/div> <\/td>\n <\/tr>\n
\n \n dn <\/td>\n | \n Distinguished name (DN) provided for authentication. <\/td>\n | \n \n- LDAP<\/li>\n<\/ul><\/div> <\/td>\n <\/tr>\n
\n \n eap_type <\/td>\n | \n The EAP type. <\/td>\n | \n \n- RADIUS<\/li>\n<\/ul><\/div> <\/td>\n <\/tr>\n
\n \n error_chain.error_code <\/td>\n | \n The mdm error code. <\/td>\n | \n \n- MDM<\/li>\n<\/ul><\/div> <\/td>\n <\/tr>\n
\n \n error_chain.error_domain <\/td>\n | \n The mdm error domain. <\/td>\n | \n \n- MDM<\/li>\n<\/ul><\/div> <\/td>\n <\/tr>\n
\n \n error_code <\/td>\n | \n The result code. <\/td>\n | \n \n- LDAP<\/li>\n<\/ul><\/div> <\/td>\n <\/tr>\n
\n \n error_message <\/td>\n | \n Error message in the event. <\/td>\n | \n \n- Directory<\/span><\/li>\n
- RADIUS<\/li>\n
- LDAP<\/li>\n<\/ul><\/div> <\/td>\n <\/tr>\n
\n \n event_type <\/td>\n | \n The event type. <\/td>\n | \n \n \n- Directory<\/li>\n
- LDAP<\/li>\n
- MDM<\/li>\n
- RADIUS<\/li>\n
- SSO<\/li>\n
- Systems<\/li>\n<\/ul>\n<\/div> <\/td>\n <\/tr>\n
\n \n filter <\/td>\n | \n The filter criteria for the search with the scope. <\/td>\n | \n \n- LDAP<\/li>\n<\/ul><\/div> <\/td>\n <\/tr>\n
\n \n geoip.continent_code <\/td>\n | \n The client IP continent code. <\/td>\n | \n \n- Directory<\/li>\n
- RADIUS<\/li>\n
- SSO<\/li>\n
- Systems<\/li>\n<\/ul><\/div> <\/td>\n <\/tr>\n
\n \n geoip.country_code <\/td>\n | \n The client IP country code. <\/td>\n | \n \n- Directory<\/li>\n
- RADIUS<\/li>\n
- SSO<\/li>\n
- Systems<\/li>\n<\/ul><\/div> <\/td>\n <\/tr>\n
\n \n geoip.region_code <\/td>\n | \n The client IP region code. <\/td>\n | \n \n- Directory<\/li>\n
- RADIUS<\/li>\n
- SSO<\/li>\n
- Systems<\/li>\n<\/ul><\/div> <\/td>\n <\/tr>\n
\n \n geoip.region_name <\/td>\n | \n The client IP region name. <\/td>\n | \n \n- Directory<\/li>\n
- RADIUS<\/li>\n
- SSO<\/li>\n
- Systems<\/li>\n<\/ul><\/div> <\/td>\n <\/tr>\n
\n \n geoip.timezone <\/td>\n | \n The client IP region's timezone. <\/td>\n | \n \n- Directory<\/li>\n
- RADIUS<\/li>\n
- SSO<\/li>\n
- Systems<\/li>\n<\/ul><\/div> <\/td>\n <\/tr>\n
\n \n id <\/td>\n | \n The event\u2019s unique id. <\/td>\n | \n \n- Directory<\/li>\n
- MDM<\/li>\n
- RADIUS<\/li>\n
- SSO<\/li>\n
- Systems<\/li>\n<\/ul><\/div> <\/td>\n <\/tr>\n
\n \n idp_initiated <\/td>\n | \n True if the request was initiated from the Identity Provider (JumpCloud). False if the auth was initiated from the service provider. <\/td>\n | \n \n- SSO<\/li>\n<\/ul><\/div> <\/td>\n <\/tr>\n
\n \n initiated_by.email <\/td>\n | \n Event initiated by email. <\/td>\n | \n \n- Directory<\/span><\/li>\n
- SSO<\/li>\n<\/ul><\/div> <\/td>\n <\/tr>\n
\n \n initiated_by.type <\/td>\n | \n Event initiated by type. <\/td>\n | \n \n- Directory<\/span><\/li>\n
- SSO<\/li>\n<\/ul><\/div> <\/td>\n <\/tr>\n
\n \n initiated_by.username <\/td>\n | \n Event initiated by username. <\/td>\n | \n \n- Directory<\/span><\/li>\n
- SSO<\/li>\n<\/ul><\/div> <\/td>\n <\/tr>\n
\n \n mech <\/td>\n | \n The authentication method used. Either simple or SASL Note that we don't currently support SASL. <\/td>\n | \n \n- LDAP<\/li>\n<\/ul><\/div> <\/td>\n <\/tr>\n
\n \n mfa <\/td>\n | \n If MFA was used on an authentication attempt. <\/td>\n | \n \n- Directory<\/li>\n
- RADIUS<\/li>\n<\/ul><\/div> <\/td>\n <\/tr>\n
\n \n mfa_meta.type <\/td>\n | \n The type of MFA used. <\/td>\n | \n \n- Directory<\/li>\n
- RADIUS<\/li>\n<\/ul><\/div> <\/td>\n <\/tr>\n
\n \n nas_mfa_state <\/td>\n | \n | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |