Skip to main content
Skip table of contents

OneDrive Messages

Vendor Documentation

Classification

Rule NameRule TypeCommon EventClassification
OneDrive MessagesBase RuleGeneral File Monitoring EventOther Audit
WAC Token SharedSub RuleGeneral Authentication EventOther Audit
Shared File, Folder, or SiteSub RuleObject AddedAccess Success
File UploadedSub RuleObject AddedAccess Success
File Sync Uploaded FullSub RuleObject AddedAccess Success
File Sync Downloaded PartialSub RuleObject AddedAccess Success
File Sync Downloaded FullSub RuleObject AddedAccess Success
File RenamedSub RuleObject RenamedAccess Success
File PreviewedSub RuleObject ReadAccess Success
File MovedSub RuleObject MovedAccess Success
File ModifiedSub RuleObject ModifiedAccess Success
File DownloadedSub RuleObject AddedAccess Success
File DeletedSub RuleObject Deleted/RemovedAccess Success
File AccessedSub RuleObject AccessedAccess Success
Company Link UsedSub RuleObject AccessedAccess Success
Company Link CreatedSub RuleObject CreatedAccess Success
Added to GroupSub RulePrivilege GrantedAccess Granted
Access Request CreatedSub RuleRequest ReceivedOther Audit Success
Access Request ApprovedSub RulePrivilege GrantedAccess Granted
Anonymous Link CreatedSub RuleAccess Granted ActivityAccess Granted
Anonymous Link RemovedSub RuleAccess Revoked ActivityAccess Revoked
Anonymous Link UpdatedSub RuleObject ModifiedAccess Success
Anonymous Link UsedSub RuleObject AccessedAccess Success
Company Link RemovedSub RuleAccess Revoked ActivityAccess Revoked
File CopiedSub RuleObject AccessedAccess Success
Folder ModifiedSub RuleObject ModifiedAccess Success
Removed From Site CollectionSub RuleAccess Revoked ActivityAccess Revoked
Sharing Invitation CreatedSub RuleAccess Granted ActivityAccess Granted
Sharing RevokedSub RuleAccess Revoked ActivityAccess Revoked

Mapping with LogRhythm Schema

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
TSN/A N/A N/A 
SESSIDN/A N/A Session information
COMMAND<command>Text/StringCommand name
USERTYPEN/A  N/A Type of user
USERKEY<session>Text/StringUser key informations hexadecimal value
WORKLOAD

<process>

<vendorinfo>

Text/StringAudit log record type
RESULTCODE<tag1>Text/StringResult
OBJECT<object>Text/StringObject name
USER

<login>

<domain>

Text/StringSource user name
SIP<sip>IP AddressSource IP address
ITEMTYPE<objectname>Text/StringN/A 
EVENTSOURCE<subject>Text/StringN/A 
USERAGENT<useragent>Text/StringN/A 
DOMAINN/A  N/A N/A 
FILENAMEN/A  N/A N/A 
DESTINATIONN/A  N/A N/A 
DESTINATIONFILENAMEN/A  N/A N/A 
USERSHAREDWITH<account>Text/StringN/A 
SHARINGTYPEN/A  N/A N/A 
EventDataN/A  N/A N/A 
MODIFIEDPROPERTIESN/A  N/A N/A 

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.