exosp-app-file-transfer-logs
Fetch application file transfer logs for specified date range from Exosphere service.
exosp-app-file-transfer-logs [profile=PROFILE] [duration=NUM{mon|w|d|h|m|s}] [from=yyyyMMddHHmmss] [to=yyyyMMddHHmmss] [order=ORDER]
- profile=PROFILE
- Connect profile code of Exosphere
- duration=NUM{mon|w|d|h|m|s}
- Scan only recent data. You should use s(second), m(minute), h(hour), d(day), mon(month) time unit. For example,
10s
means data from 10 seconds earlier. - from=yyyyMMddHHmmss
- Start time of range. yyyyMMddHHmmss format. If you omit time part, it will be padded by zero.
- to=yyyyMMddHHmmss
- End time of range. yyyyMMddHHmmss format. If you omit time part, it will be padded by zero.
- order=ORDER
- asc or desc.
Output Fields
Field | Type | Name | Description |
---|---|---|---|
_time | Date | Timestamp | Event occurrence time |
profile | String | Connect profile | Exosphere connect profile code |
emp_name | String | Name | e.g. Scott |
dept_name | String | Department name | e.g. Sales |
hostname | String | Hostname | e.g. DESKTOP-XXXXXXX |
os_name | String | OS name | e.g. windows, macos |
user | String | User | OS account name |
url | String | URL | HTTP upload address |
action | String | Action | e.g. PERMIT, BLOCK |
category | String | App category | e.g. Web Browser, Messenger, Note Taking Apps |
publisher | String | Publisher | e.g. Google, Inc., Apple Inc., Notion Labs, Inc. |
product_name | String | Product name | e.g. Chrome, KakaoTalk, Slack |
process_name | String | Process name | e.g. Google Chrome, KakaoTalk, slack.exe |
file_name | String | File name | Name of the exported file |
file_size | Long | File size | Size of the exported file |
file_type | String | File type | e.g. Not Scanned, General, Scan Failed, Sensitive |
pii_count | Integer | Detected PII count | Number of personal information items included in the exported file |
pii_details | List | PII Details | Array of key-value pairs with name and count. Name includes Email, Bank Account/Credit Card (Korea), etc. |
file_path | String | File path | Path of the exported file |
dept_path | String | Department path | e.g. Logpresso > Sales |