exosp-device-control-logs
Fetch device control logs for specified date range from Exosphere service.
exosp-device-control-logs [profile=PROFILE] [duration=NUM{mon|w|d|h|m|s}] [from=yyyyMMddHHmmss] [to=yyyyMMddHHmmss] [order=ORDER]
- profile=PROFILE
- Connect profile code of Exosphere
- duration=NUM{mon|w|d|h|m|s}
- Scan only recent data. You should use s(second), m(minute), h(hour), d(day), mon(month) time unit. For example,
10s
means data from 10 seconds earlier. - from=yyyyMMddHHmmss
- Start time of range. yyyyMMddHHmmss format. If you omit time part, it will be padded by zero.
- to=yyyyMMddHHmmss
- End time of range. yyyyMMddHHmmss format. If you omit time part, it will be padded by zero.
- order=ORDER
- asc or desc.
Output Fields
Field | Type | Name | Description |
---|---|---|---|
_time | Date | Timestamp | Event occurrence time |
profile | String | Connect profile | Exosphere connect profile code |
emp_name | String | Name | e.g. Scott |
dept_name | String | Department name | e.g. Sales |
hostname | String | Hostname | e.g. DESKTOP-XXXXXXX |
os_name | String | OS name | e.g. windows, macos |
user | String | Account | OS account name |
category | String | Device category | e.g. Mobile Devices, Removable Disk, USB Tethering |
device_description | String | Device description | e.g. Apple iPhone |
volume_name | String | Volume name | Volume name (macOS) |
volume_size | String | Volume size | Volume capacity (macOS) |
device_serial | String | Device serial | e.g. USB\VID_05AC&PID_12A8\00008010000DDDDDDDDDDDDD |
device_class_name | String | Device class name | e.g. WPD |
device_class_guid | String | Device class GUID | e.g. {eec5ad98-8080-425f-922a-dabf3de3f69a} |
device_hardware_id | String | Device hardware ID | e.g. USB\VID_05AC&PID_12A8&REV_1703&MI_00 |
device_instance_id | String | Device instance ID | e.g. USB\VID_05AC&PID_12A8&MI_00\6&AAAAAAAA&0&0000 |
dept_path | String | Department path | e.g. Logpresso > Sales |