GitHubAuditLogsV2_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index


Attribute Value
Ingestion API Supported ✓ Yes

Contents

Schema (232 columns)

Source: Connector definition

Column Name Type
Action string
Active bool
ActiveWas bool
ActivityType string
Actor string
ActorId real
ActorIp string
ActorIsBot bool
AdminEnforced bool
After string
AlertNumbers string
AllowDeletionsEnforcementLevel real
AllowedValues string
AllowForcePushesEnforcementLevel real
ApplicationClientId string
AuditLogStreamId real
AuditLogStreamResult string
AuditLogStreamSink string
AuditLogStreamSinkDetails string
AuthorizedActorNames string
BaseRole string
Before string
BlockedUser string
Branch string
Business string
BusinessId real
CanCreateRepositories bool
CommitId string
CommitOid string
CompletedAt datetime
Conclusion string
Config string
ConfigWas string
ContentType string
CountryCode string
CreatedAt real
CreateProtected bool
CustomPattern string
Data string
DefaultForNewPrivateRepos bool
DefaultForNewPublicRepos bool
DefaultValue string
DefinitionId real
DeployKeyFingerprint string
Description string
DismissalApproverId real
DismissStaleReviewsOnPush bool
DocumentId string
DomainName string
Email string
Emoji string
Enablement string
EnforcementLevel string
EnvironmentName string
Event string
Events string
EventsWere string
ExemptAdministrators bool
Explanation string
ExternalIdentityNameid string
ExternalIdentityUsername string
Fingerprint string
GhsaId string
HashedToken string
HeadBranch string
HeadSha string
HookId real
IgnoreApprovalsFromContributors bool
Integration string
InvitationId real
InviteeEmail string
IpAllowListEntry string
IsHostedRunner bool
Issuer string
IssueTypeName string
JobName string
JobWorkflowRef string
Key string
Limit real
LimitedAvailability bool
LinearHistoryRequirementEnforcementLevel real
LockAllowsFetchAndMerge bool
LockBranchEnforcementLevel real
MembershipType string
MergeQueueEnforcementLevel real
Message string
Name string
NewAccess string
NewPolicy string
NewProjectBaseRole string
NewRepoPermission string
NewRepoRunnersPolicy string
OauthApplication string
OauthApplicationId real
OauthApplicationState string
OauthApplicationUrl string
OldAccess string
OldDefaultValue string
OldDescription string
OldEnabled bool
OldIssueTypeName string
OldPermission string
OldProjectBaseRole string
OldRepoPermission string
OldRepoRunnersPolicy string
OldRequired bool
OldRolePermissions string
OldTokenExpiration real
OldUser string
OldValuesEditableBy string
OpensshPublicKey string
OperationType string
Org string
OrganizationRoleId real
OrganizationRoleName string
OrgId real
OverriddenCodes string
Owner string
OwnerType string
Permission string
Policy string
PreviousVisibility string
ProgrammaticAccessType string
ProjectId real
ProjectNumber real
PropertyName string
PublicProject bool
PublicRepo bool
PullRequestId real
PullRequestReviewsEnforcementLevel real
PullRequestTitle string
PullRequestUrl string
QuerySuite string
ReadOnly bool
Reason string
Reasons string
Recipient string
Ref string
Referrer string
Repo string
RepoId real
RepositoriesRemoved string
RepositoriesRemovedNames string
RepositorySecurityConfigurationFailureReason dynamic
RepositorySecurityConfigurationState dynamic
RepositorySelection string
RequestAccessSecurityHeader string
RequestCategory string
RequestId string
RequireCodeOwnerReview bool
Required bool
RequiredApprovingReviewCount real
RequiredDeploymentsEnforcementLevel real
RequiredReviewThreadResolutionEnforcementLevel real
RequiredStatusChecksEnforcementLevel real
RequireLastPushApproval bool
RolePermissions string
RulesetBypassActors string
RulesetConditions string
RulesetConditionsUpdated string
RulesetEnforcement string
RulesetId real
RulesetName string
RulesetRules string
RulesetRulesDeleted string
RulesetSourceType string
RuleSuiteId real
RunAttempt real
RunnerGroupAllowPublic bool
RunnerGroupId real
RunnerGroupName string
RunnerGroupRestrictedToWorkflows bool
RunnerGroupSelectedWorkflowRefs string
RunnerId real
RunnerLabels string
RunnerName string
RunnerOwnerType string
RunNumber real
SecretsPassed string
SecurityConfigurationCodeScanning string
SecurityConfigurationCodeSecuritySkuEnabled bool
SecurityConfigurationCreatedAt datetime
SecurityConfigurationDependabotAlerts string
SecurityConfigurationDependabotSecurityUpdates string
SecurityConfigurationDependencyGraph string
SecurityConfigurationDependencyGraphAutosubmitAction string
SecurityConfigurationDescription string
SecurityConfigurationEnableGhas bool
SecurityConfigurationId real
SecurityConfigurationName string
SecurityConfigurationPrivateVulnerabilityReporting string
SecurityConfigurationSecretProtectionSkuEnabled bool
SecurityConfigurationSecretScanning string
SecurityConfigurationSecretScanningDelegatedBypass string
SecurityConfigurationSecretScanningGenericSecrets string
SecurityConfigurationSecretScanningNonProviderPatterns string
SecurityConfigurationSecretScanningPushProtection string
SecurityConfigurationSecretScanningValidityChecks string
SecurityConfigurationUpdatedAt datetime
SignatureRequirementEnforcementLevel real
Source string
SsoUrl string
StartedAt datetime
StrictRequiredStatusChecksPolicy bool
TargetLogin string
Team string
ThreatModel string
TimeGenerated datetime
TokenExpiration real
TokenId real
Topic string
TransportProtocol real
TransportProtocolName string
TriggerId real
TwoFactorMethod string
UpdatedAllowedTypes bool
User string
UserAgent string
UserCanInviteCollaborators bool
UserId real
ValuesEditableBy string
ValueType string
Visibility string
VulnerabilityAlertRuleActionsAlertActionsAutoDismiss string
VulnerabilityAlertRuleActionsVersion real
VulnerabilityAlertRuleConditionsCwe string
VulnerabilityAlertRuleConditionsEcosystem string
VulnerabilityAlertRuleConditionsScope string
VulnerabilityAlertRuleId real
VulnerabilityAlertRuleName string
WorkflowId real
WorkflowRunId real

Solutions (1)

This table is used by the following solutions:

Connectors (2)

This table is ingested by the following connectors:

Connector Selection Criteria
GitHub Enterprise Audit Log (via Codeless Connector Framework)
[Deprecated] GitHub Enterprise Audit Log

Content Items Using This Table (21)

Analytic Rules (13)

In solution GitHub:

Analytic Rule Selection Criteria
GitHub - A payment method was removed
GitHub - Oauth application - a client secret was removed
GitHub - Repository was created
GitHub - Repository was destroyed
GitHub - User visibility Was changed
GitHub - User was added to the organization
GitHub - User was blocked
GitHub - User was invited to the repository
GitHub - pull request was created
GitHub - pull request was merged
GitHub Activites from a New Country
GitHub Two Factor Auth Disable
NRT GitHub Two Factor Auth Disable

Hunting Queries (8)

In solution GitHub:

Hunting Query Selection Criteria
GitHub First Time Invite Member and Add Member to Repo

GitHub Only:

Hunting Query Selection Criteria
GitHub First Time Repo Delete
GitHub Inactive or New Account Access or Usage
GitHub Mass Deletion of repos or projects
GitHub OAuth App Restrictions Disabled
GitHub Repo switched from private to public
GitHub Update Permissions
GitHub User Grants Access and Other User Grants Access

Parsers Using This Table (1)

Other Parsers (1)

Parser Solution Selection Criteria
GitHubAuditData GitHub

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index