Menlo Security

Download 10
Last updated Aug 4, 2024

menlo-audit-logs

Get audit logs from Menlo Security service.

menlo-audit-logs [profile=PROFILE] [duration=NUM{mon|w|d|h|m|s}] [from=yyyyMMddHHmmss] [to=yyyyMMddHHmmss]
profile=PROFILE
Menlo Security connect profile code
duration=NUM{mon|w|d|h|m|s}
Scan only recent data. You should use s(second), m(minute), h(hour), d(day), mon(month) time unit. For example, 10s means data from 10 seconds earlier.
from=yyyyMMddHHmmss
Start time of range. yyyyMMddHHmmss format. If you omit time part, it will be padded by zero.
to=yyyyMMddHHmmss
End time of range. yyyyMMddHHmmss format. If you omit time part, it will be padded by zero.

Output Fields

FieldTypeNameDescription
_timeDateTime
src_ipIP addressSource IP
userStringUserEmail format
rolesStringRolese.g. Default
req_typeStringRequest typee.g. authentication
sub_event_typeStringEvent typee.g. login, logout
actionStringActione.g. login, logout
detailsStringDetailsJSON format
rev_idStringRevision ID
vendorStringVendore.g. Menlo Security
productStringProducte.g. MSIP
versionStringVersione.g. 2.0