1Password-ManagedAccount
| Event | Title | Channel | Sample | Rule |
|---|---|---|---|---|
| any | Managed account (catch-all) | _catch_all | N | N |
| mngdacc-create | Add Managed Company | mngdacc-create | N | N |
| mngdacc-launchi | Launch Into Managed Company | mngdacc-launchi | N | N |
| mngdacc-unlink | Unlink Managed Company | mngdacc-unlink | N | N |
any: Managed account (catch-all)
#Description
Catch-all entry for 1Password rules that match managed account events without naming a specific action.
Fields #
| Name | Description |
|---|---|
uuid | The unique identifier for the event. |
timestamp | When the action was performed. |
actor_uuid | The unique identifier for the team member who performed the action. |
actor_details.uuid | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_details.name | Full name |
actor_details.email | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_type | |
actor_account_uuid | |
account_uuid | |
action | The type of action that was performed. |
object_type | The type of object that the action was performed on. |
object_uuid | The unique identifier for the object the action was performed on. |
object_details.uuid | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
object_details.name | Full name |
object_details.email | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
aux_id | The identifier that relates to additional information about the activity. |
aux_uuid | The unique identifier that relates to additional information about the activity. |
aux_details.uuid | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_details.name | Full name |
aux_details.email | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_info | Additional information about the activity. |
session.uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.login_time | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.device_uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.ip | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
location.country | The geolocation information of the client based on their IP address at the time the event was performed. |
location.region | The geolocation information of the client based on their IP address at the time the event was performed. |
location.city | The geolocation information of the client based on their IP address at the time the event was performed. |
location.longitude | The geolocation information of the client based on their IP address at the time the event was performed. |
location.latitude | The geolocation information of the client based on their IP address at the time the event was performed. |
mngdacc-create: Add Managed Company
#Description
A managed company was added to an MSP account.
Fields #
| Name | Description |
|---|---|
uuid | The unique identifier for the event. |
timestamp | When the action was performed. |
actor_uuid | The unique identifier for the team member who performed the action. |
actor_details.uuid | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_details.name | Full name |
actor_details.email | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_type | |
actor_account_uuid | |
account_uuid | |
action | The type of action that was performed. |
object_type | The type of object that the action was performed on. |
object_uuid | The unique identifier for the object the action was performed on. |
object_details.uuid | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
object_details.name | Full name |
object_details.email | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
aux_id | The identifier that relates to additional information about the activity. |
aux_uuid | The unique identifier that relates to additional information about the activity. |
aux_details.uuid | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_details.name | Full name |
aux_details.email | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_info | Additional information about the activity. |
session.uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.login_time | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.device_uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.ip | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
location.country | The geolocation information of the client based on their IP address at the time the event was performed. |
location.region | The geolocation information of the client based on their IP address at the time the event was performed. |
location.city | The geolocation information of the client based on their IP address at the time the event was performed. |
location.longitude | The geolocation information of the client based on their IP address at the time the event was performed. |
location.latitude | The geolocation information of the client based on their IP address at the time the event was performed. |
mngdacc-launchi: Launch Into Managed Company
#Description
An MSP technician launched into a managed company.
Fields #
| Name | Description |
|---|---|
uuid | The unique identifier for the event. |
timestamp | When the action was performed. |
actor_uuid | The unique identifier for the team member who performed the action. |
actor_details.uuid | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_details.name | Full name |
actor_details.email | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_type | |
actor_account_uuid | |
account_uuid | |
action | The type of action that was performed. |
object_type | The type of object that the action was performed on. |
object_uuid | The unique identifier for the object the action was performed on. |
object_details.uuid | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
object_details.name | Full name |
object_details.email | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
aux_id | The identifier that relates to additional information about the activity. |
aux_uuid | The unique identifier that relates to additional information about the activity. |
aux_details.uuid | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_details.name | Full name |
aux_details.email | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_info | Additional information about the activity. |
session.uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.login_time | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.device_uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.ip | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
location.country | The geolocation information of the client based on their IP address at the time the event was performed. |
location.region | The geolocation information of the client based on their IP address at the time the event was performed. |
location.city | The geolocation information of the client based on their IP address at the time the event was performed. |
location.longitude | The geolocation information of the client based on their IP address at the time the event was performed. |
location.latitude | The geolocation information of the client based on their IP address at the time the event was performed. |
mngdacc-unlink: Unlink Managed Company
#Description
A managed company was unlinked from an MSP account.
Fields #
| Name | Description |
|---|---|
uuid | The unique identifier for the event. |
timestamp | When the action was performed. |
actor_uuid | The unique identifier for the team member who performed the action. |
actor_details.uuid | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_details.name | Full name |
actor_details.email | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_type | |
actor_account_uuid | |
account_uuid | |
action | The type of action that was performed. |
object_type | The type of object that the action was performed on. |
object_uuid | The unique identifier for the object the action was performed on. |
object_details.uuid | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
object_details.name | Full name |
object_details.email | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
aux_id | The identifier that relates to additional information about the activity. |
aux_uuid | The unique identifier that relates to additional information about the activity. |
aux_details.uuid | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_details.name | Full name |
aux_details.email | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_info | Additional information about the activity. |
session.uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.login_time | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.device_uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.ip | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
location.country | The geolocation information of the client based on their IP address at the time the event was performed. |
location.region | The geolocation information of the client based on their IP address at the time the event was performed. |
location.city | The geolocation information of the client based on their IP address at the time the event was performed. |
location.longitude | The geolocation information of the client based on their IP address at the time the event was performed. |
location.latitude | The geolocation information of the client based on their IP address at the time the event was performed. |