Skip to main content
Skip table of contents

Microsoft Apps Activity Messages

Vendor Documentation

Classification

Rule NameRule TypeCommon EventClassification
Microsoft Apps Activity MessagesBase RuleGeneral Microsoft Exchange Server InformationInformation
PowerApps MessagesSub RuleModule LoadedOther Audit Success
Quarantine MessagesSub RuleQuarantineActivity
AirInvestigation MessagesSub RuleGeneral Security AlertWarning
CRM MessagesSub RuleGeneral Microsoft CRM InformationInformation

Mapping with LogRhythm Schema

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
TSN/AN/AN/A
SESSID<session>Text/StringSession information
COMMAND<command>Text/StringCommand name
USERTYPE<objecttype>Text/StringType of user
USERKEYN/A 
User key information
WORKLOAD

<tag1>
<process>

<vendorinfo>

Text/StringAudit log record type
RESULTCODE<result>Text/StringN/A
OBJECT<object>Text/StringObject name
USER<login>
<domainorigin>
Text/StringSource user name
SIP

<sip>

<sport>

IP Address

Number

Source IP address
DETAILSN/A N/AN/A
CreationTimeN/A N/AN/A
IDN/A N/AN/A
OperationN/A N/AN/A
OrganizationIdN/A N/AN/A
RecordTypeN/A N/AN/A
ResultStatusN/A N/AN/A
UserKeyN/A N/AN/A
UserTypeN/A N/AN/A
Version<version>NumberN/A
WorkloadN/A N/AN/A
UserIdN/A N/AN/A
NetworkMessageIdN/A N/AN/A
ReleaseToN/A N/AN/A
RequestSourceN/A N/AN/A
RequestTypeN/A N/AN/A
URL<url>Text/StringN/A
Useragent<useragent>Text/StringN/A
AppName<objectname>Text/StringN/A

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.