Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
| Attribute | Value |
|---|---|
| Ingestion API Supported | ✓ Yes |
Source: Connector definition
| Column Name | Type | Description |
|---|---|---|
| Action | string | Event action type - primary field for threat detection (e.g., user.access.granted, user.authentication.failed, policy.updated, api.token.created) |
| ActorEmail | string | Primary identity - email of user who performed the action |
| ActorId | string | Actor unique identifier for correlation across events |
| ActorName | string | Human-readable actor name for investigation |
| AppId | string | Third-party app monitoring - detects unauthorized app usage or OAuth token compromise |
| AuthTokenLabel | string | Token/app identification - critical for detecting compromised API keys or unauthorized integrations |
| AuthType | string | Authentication method - api-token, container-token, connect-token, OAuth (detects token vs interactive login) |
| CityName | string | City-level tracking - location-based alerting, regional access patterns |
| Container | dynamic | Scope context - organization, site, product where action occurred (multi-tenant environments) |
| Context | dynamic | Target identification - users, groups, policies affected by action (enables detailed investigation) |
| CountryName | string | Geo-analysis - impossible travel detection, geographic anomalies, country-based alerting |
| EventId | string | Unique identifier for the audit event - used for deduplication and correlation |
| EventMessage | string | Human-readable security event description for investigation |
| EventUrl | string | Investigation link - direct access to full event details in Atlassian API |
| OnBehalfOfEmail | string | Delegation detection - identifies impersonation or privilege escalation scenarios |
| ProcessedAt | datetime | Event processing timestamp - latency monitoring, detects API delays or event manipulation |
| SrcIpAddr | string | Network origin - suspicious IP detection, IP allowlist validation, impossible travel |
| TimeGenerated | datetime |
Official Microsoft Learn documentation for field/column information:
This table is used by the following solutions:
This table is ingested by the following connectors:
| Connector | Selection Criteria |
|---|---|
| Atlassian Organization Audit Events (via Codeless Connector Framework) |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊