Admin Console
| eventName | Description | Sample | Rule |
|---|---|---|---|
| any | Source-only rules that filter on applicationName 'admin' without specifying an eventName attribute here. | N | N |
| ADD_ | An application was added to the Google Workspace domain. | N | Y |
| ADD_ | A user was added to a group. | Y | Y |
| ADD_ | A privilege was added to a role. | N | Y |
| ADD_ | A domain was added to the trusted domains list. | N | Y |
| ALLOW_ | The administrator changed the MFA enforcement setting (allow/require strong authentication). | N | Y |
| ASSIGN_ | An admin role was assigned to a user or service account. | Y | Y |
| AUTHORIZE_ | An API client was authorized domain-wide access via OAuth. | Y | Y |
| CHANGE_ | A setting for a Google Workspace application was modified. | Y | Y |
| CHANGE_ | A Gmail routing or mail-flow setting was changed. | N | Y |
| CREATE_ | A new application setting was created. | N | Y |
| CREATE_ | An admin initiated a data transfer (Drive file ownership reassignment) to another user. | N | Y |
| CREATE_ | A new Gmail routing or mail-flow setting was created. | N | Y |
| CREATE_ | A custom admin role was created. | N | Y |
| CUSTOMER_ | An admin initiated a Takeout export job for organizational data. | N | Y |
| DELETE_ | An admin role was permanently deleted. | N | Y |
| ENFORCE_ | The MFA/2SV enforcement policy was changed for the domain or an organizational unit. | N | Y |
| GRANT_ | Administrator privileges were granted to a user account. | N | Y |
| GRANT_ | Delegated administrator privileges were granted to a user. | N | Y |
| MOVE_ | A user was moved to a different organizational unit. | N | Y |
| REMOVE_ | An application was removed from the Google Workspace domain. | N | Y |
| REMOVE_ | An application was removed from the domain's marketplace allowlist. | N | Y |
| REMOVE_ | A privilege was removed from a role. | N | Y |
| RENAME_ | An admin role was renamed. | N | Y |
| SAML2_ | A SAML 2.0 service provider configuration was added, modified, or removed. | N | Y |
| TOGGLE_ | Outbound email relay routing was enabled or disabled. | N | Y |
| TURN_ | 2-Step Verification was disabled for a user or the domain. | N | Y |
| UNSUSPEND_ | A suspended user account was reactivated. | N | Y |
| UPDATE_ | An existing admin role was modified (e.g. description or privileges changed). | N | Y |
| BLOCK_ | An admin blocked all third-party application access to Google Workspace APIs. | N | N |
| UNBLOCK_ | An admin unblocked third-party application access to Google Workspace APIs. | N | N |
| ADD_ | An OAuth2 application was added to the trusted apps list. | N | N |
| ADD_ | An OAuth2 application was blocked from accessing Google Workspace data. | N | N |
| REMOVE_ | An OAuth2 application was removed from the blocked apps list. | N | N |
| REMOVE_ | An OAuth2 application was removed from the trusted apps list. | N | N |
| CREATE_ | A new user account was created in the Google Workspace domain. | Y | N |
| DELETE_ | A user account was deleted from the Google Workspace domain. | Y | N |
| SUSPEND_ | A user account was suspended by an administrator. | N | N |
| RENAME_ | A user's primary email address was changed. | Y | N |
| CHANGE_ | An administrator changed a user's password. | Y | N |
| REVOKE_ | An administrator revoked an application-specific password (ASP) for a user. | N | N |
| REVOKE_ | An administrator revoked an OAuth token for a user. | N | N |
| SESSION_ | Web session duration or re-authentication settings were changed. | N | N |
| WEAK_ | Settings controlling less-secure app access (LSA/basic auth) were changed. | N | N |
| CHANGE_ | SAML/SSO settings for the domain were changed. | N | N |
| TOGGLE_ | SSO (SAML-based single sign-on) was enabled or disabled for the domain. | N | N |
| REVOKE_ | Administrator privileges were revoked from a user account. | N | N |
| ALLOW_ | A Google service was allowed for OAuth2 API access. | N | N |
| DISALLOW_ | A Google service was disallowed for OAuth2 API access. | N | N |
| TOGGLE_ | Context-Aware Access was enabled or disabled for the domain. | N | N |
| CHANGE_ | A setting for a Google Group was changed by an administrator. | Y | N |
| ADD_ | An application was added to the domain's Google Workspace Marketplace allowlist. | N | N |
| CHANGE_ | The enrollment period for 2-Step Verification was changed. | N | N |
| CHANGE_ | The allowed methods for 2-Step Verification were changed. | N | N |
| APPLICATION_ | Events of this type are returned with type=APPLICATION_SETTINGS . | N | N |
| DELETE_ | For {APPLICATION_NAME} , {SETTING_NAME} with value {OLD_VALUE} deleted | N | N |
| REORDER_ | For {APPLICATION_NAME} , group override priorities for {SETTING_NAME} changed to {GROUP_PRIORITIES} . | N | N |
| GPLUS_ | Premium features for Google+ service for your organization changed to {NEW_VALUE} | N | N |
| CREATE_ | Managed configuration with name {MANAGED_CONFIGURATION_NAME} is created for {DEVICE_TYPE} application {MOBILE_APP_PACKAGE_ID} . | N | N |
| DELETE_ | Managed configuration with name {MANAGED_CONFIGURATION_NAME} is deleted for {DEVICE_TYPE} application {MOBILE_APP_PACKAGE_ID} . | N | N |
| UPDATE_ | Managed configuration with name {MANAGED_CONFIGURATION_NAME} is updated for {DEVICE_TYPE} application {MOBILE_APP_PACKAGE_ID} . | N | N |
| FLASHLIGHT_ | {FLASHLIGHT_EDU_NON_FEATURED_SERVICES_SELECTION} selection was made for Non-Featured Services. | N | N |
| UPDATE_ | Smart features and personalization setting has been updated to {NEW_VALUE} | N | N |
| CALENDAR_ | Events of this type are returned with type=CALENDAR_SETTINGS . | N | N |
| CREATE_ | Building {NEW_VALUE} created | N | N |
| DELETE_ | Building {OLD_VALUE} deleted | N | N |
| UPDATE_ | Building {RESOURCE_IDENTIFIER} updated field {FIELD_NAME} from {OLD_VALUE} to {NEW_VALUE} | N | N |
| EWS_ | Short description for EWS IN credentials generation. | N | N |
| EWS_ | Short description for clearing Calendar Interop Exchange endpoint configuration. | N | N |
| EWS_ | Short description for changing Calendar Interop Exchange endpoint configuration. | N | N |
| CREATE_ | Calendar resource {NEW_VALUE} created | N | N |
| DELETE_ | Calendar resource {OLD_VALUE} deleted | N | N |
| CREATE_ | Calendar resource feature {NEW_VALUE} created | N | N |
| DELETE_ | Calendar resource feature {OLD_VALUE} deleted | N | N |
| UPDATE_ | Calendar resource feature {RESOURCE_IDENTIFIER} updated field {FIELD_NAME} from {OLD_VALUE} to {NEW_VALUE} | N | N |
| RENAME_ | Calendar resource {OLD_VALUE} renamed to {NEW_VALUE} | N | N |
| UPDATE_ | Calendar resource {RESOURCE_IDENTIFIER} updated field {FIELD_NAME} from {OLD_VALUE} to {NEW_VALUE} | N | N |
| CHANGE_ | {SETTING_NAME} for calendar service in your organization changed from {OLD_VALUE} to {NEW_VALUE} | N | Y |
| CANCEL_ | Event cancellation request created for {USER_EMAIL} | N | N |
| RELEASE_ | Release resources request created for {USER_EMAIL} | N | N |
| CHAT_ | Note that this page also contains events for Google Hangouts, as well as the previous Google Chat product. Events of this type are returned with type=CHAT_SETTINGS . | N | N |
| MEET_ | A Hangouts Meet interoperability gateway was created | N | N |
| MEET_ | A Hangouts Meet interoperability gateway was deleted | N | N |
| MEET_ | A Hangouts Meet interoperability gateway was modified | N | N |
| CHANGE_ | {SETTING_NAME} for talk service for your organization changed from {OLD_VALUE} to {NEW_VALUE} | N | N |
| CHROME_ | Events of this type are returned with type=CHROME_OS_SETTINGS . | N | N |
| CHANGE_ | {SETTING_NAME} for Android app {APP_ID} for session type {CHROME_OS_SESSION_TYPE} changed from {OLD_VALUE} to {NEW_VALUE} | N | N |
| CHANGE_ | Event for 'Change device state'. | N | N |
| CHANGE_ | Changed upgrade from {OLD_VALUE} to {NEW_VALUE} for device with serial number {DEVICE_SERIAL_NUMBER} . | N | N |
| CHANGE_ | {SETTING_NAME} for Chrome app {APP_ID} for session type {CHROME_OS_SESSION_TYPE} changed from {OLD_VALUE} to {NEW_VALUE} | N | N |
| SEND_ | Sent {NEW_VALUE} command to ChromeOS device {DEVICE_SERIAL_NUMBER} | N | N |
| CHANGE_ | ChromeOS device {DEVICE_SERIAL_NUMBER} had its properties updated | N | N |
| CHANGE_ | {SETTING_NAME} for ChromeOS devices in {ORG_UNIT_NAME} organization unit changed from {OLD_VALUE} to {NEW_VALUE} | N | N |
| CHANGE_ | State of ChromeOS device {DEVICE_SERIAL_NUMBER} changed from {OLD_VALUE} to {NEW_VALUE} | N | N |
| CHANGE_ | {SETTING_NAME} for ChromeOS managed guest session in {ORG_UNIT_NAME} organization unit changed from {OLD_VALUE} to {NEW_VALUE} | N | N |
| INSERT_ | Print server is added. | N | N |
| DELETE_ | Existing print server is deleted. | N | N |
| UPDATE_ | Existing print server is updated. | N | N |
| INSERT_ | Printer is added. | N | N |
| DELETE_ | Existing printer is deleted. | N | N |
| UPDATE_ | Existing printer is updated. | N | N |
| CHANGE_ | {SETTING_NAME} for ChromeOS devices in your organization changed from {OLD_VALUE} to {NEW_VALUE} | N | N |
| CHANGE_ | {SETTING_NAME} for ChromeOS users in {ORG_UNIT_NAME} organization unit changed from {OLD_VALUE} to {NEW_VALUE} | N | N |
| CREATE_ | Event for 'Create ChromeOS enrollment token'. | N | N |
| CHANGE_ | Custom configurations JSON field in the {ORG_UNIT_NAME} organizational unit changed from {OLD_VALUE} to {NEW_VALUE} | N | N |
| DELETE_ | Event for 'Delete ChromeOS device'. | N | N |
| DELETE_ | Event for 'Delete duplicate ChromeOS device'. | N | N |
| CHANGE_ | {SETTING_NAME} for Isolated Web app {APP_ID} for session type {CHROME_OS_SESSION_TYPE} changed from {OLD_VALUE} to {NEW_VALUE} | N | N |
| ISSUE_ | Event for 'Issue device command'. | N | N |
| MOVE_ | Event for 'Move device to Org Unit'. | N | N |
| PRE_ | Event for 'Pre-provision ChromeOS device'. | N | N |
| REMOVE_ | {APP_TYPE} app {APP_ID} for session type {CHROME_OS_SESSION_TYPE} removed | N | N |
| REMOVE_ | Settings for Chrome app {APP_ID} removed | N | N |
| REMOVE_ | Settings for web origin {WEB_ORIGIN} for session type {CHROME_OS_SESSION_TYPE} removed | N | N |
| REPAIR_ | Event for 'Repair Center deprovision'. | N | N |
| REVOKE_ | Event for 'Revoke ChromeOS enrollment token'. | N | N |
| UPDATE_ | Event for 'Update device'. | N | N |
| CHANGE_ | {SETTING_NAME} for Web app {APP_ID} for session type {CHROME_OS_SESSION_TYPE} changed from {OLD_VALUE} to {NEW_VALUE} | N | N |
| CHANGE_ | {SETTING_NAME} for {WEB_ORIGIN} for session type {CHROME_OS_SESSION_TYPE} changed from {OLD_VALUE} to {NEW_VALUE} | N | N |
| CONTACTS_ | Events of this type are returned with type=CONTACTS_SETTINGS . | N | N |
| CHANGE_ | {SETTING_NAME} for contacts service changed from {OLD_VALUE} to {NEW_VALUE} | N | N |
| DOCS_ | Events of this type are returned with type=DOCS_SETTINGS . | N | N |
| TRANSFER_ | Owner of documents changed from {USER_EMAIL} to {NEW_VALUE} | N | N |
| DOCS_ | Organizational branding provisioning initiated for account {SERVICE_ACCOUNT_EMAIL} and shared drive {SHARED_DRIVE_NAME} with status {ORG_BRANDING_PROVISIONING_STATUS} | N | N |
| DOCS_ | Organizational branding document upload attempted for document {DOCUMENT_ID} in editor {ORG_BRANDING_EDITOR_TYPE} with status {ORG_BRANDING_UPLOAD_STATUS} | N | N |
| DRIVE_ | Drive data restoration initiated for {USER_EMAIL} | N | N |
| CHANGE_ | {SETTING_NAME} for Drive changed from {OLD_VALUE} to {NEW_VALUE} | N | N |
| MOVE_ | Shared drive {SHARED_DRIVE_ID} moved from {ORG_UNIT_NAME} to {NEW_VALUE} | N | N |
| DOMAIN_ | Events of this type are returned with type=DOMAIN_SETTINGS . | N | N |
| CHANGE_ | Account automatic renewal changed to {NEW_VALUE} on {DOMAIN_NAME} | N | N |
| CHANGE_ | Advertisement option for your organization changed from {OLD_VALUE} to {NEW_VALUE} | N | N |
| CREATE_ | Alert {ALERT_NAME} has been created | N | N |
| CHANGE_ | Alert criteria for {ALERT_NAME} has been changed | N | N |
| DELETE_ | Alert {ALERT_NAME} has been deleted | N | N |
| ALERT_ | Alert receivers for {ALERT_NAME} changed from {OLD_VALUE} to {NEW_VALUE} | N | N |
| RENAME_ | Alert {OLD_VALUE} has been renamed to {NEW_VALUE} | N | N |
| ALERT_ | Alert status for {ALERT_NAME} changed from {OLD_VALUE} to {NEW_VALUE} | N | N |
| ADD_ | An unverified {DOMAIN_ALIAS} created as an alias of {DOMAIN_NAME} | N | N |
| REMOVE_ | {DOMAIN_ALIAS} deleted as an alias of {DOMAIN_NAME} | N | N |
| SKIP_ | Skipped MX record setup of alias {DOMAIN_ALIAS} of domain {DOMAIN_NAME} | N | N |
| VERIFY_ | Verified MX record of alias {DOMAIN_ALIAS} of domain {DOMAIN_NAME} | N | N |
| VERIFY_ | {DOMAIN_ALIAS} verified as an alias of {DOMAIN_NAME} using {DOMAIN_VERIFICATION_METHOD} | N | N |
| TOGGLE_ | OAuth access for all APIs changed to {NEW_VALUE} for your organization | N | N |
| TOGGLE_ | Allow admin password reset setting changed to {NEW_VALUE} | N | N |
| ENABLE_ | API access for your organization changed from {OLD_VALUE} to {NEW_VALUE} | N | N |
| REMOVE_ | API client access to your organization from client {API_CLIENT_NAME} removed | N | N |
| CHROME_ | Licenses redeemed event name. | N | N |
| TOGGLE_ | Automatic addition for new services and pre-release features for your organization changed to {NEW_VALUE} | N | N |
| CHANGE_ | Primary domain name changed from {DOMAIN_NAME} to {NEW_VALUE} | N | N |
| CHANGE_ | {SETTING_NAME} changed from {OLD_VALUE} to {NEW_VALUE} for the domain | N | N |
| COMMUNICATION_ | {SETTING_NAME} setting in Communication Preferences changed from {OLD_VALUE} to {NEW_VALUE} (Domain Name : {DOMAIN_NAME} ) | N | N |
| CHANGE_ | Conflict account action for {DOMAIN_NAME} changed from {OLD_VALUE} to {NEW_VALUE} | N | N |
| CHANGE_ | Conflict accounts management setting changed to: {CONFLICT_ACCOUNTS_MANAGEMENT_SETTINGS} . | N | N |
| ENABLE_ | Can contact for feedback setting for your organization changed from {OLD_VALUE} to {NEW_VALUE} | N | N |
| TOGGLE_ | Contact sharing changed to {NEW_VALUE} | N | N |
| CREATE_ | MDM vendor enrollment token ( {PLAY_FOR_WORK_TOKEN_ID} ) created | N | N |
| TOGGLE_ | Use custom logo changed to {NEW_VALUE} | N | N |
| CHANGE_ | New custom logo uploaded for your organization | N | N |
| CHANGE_ | Setting for Data Localization for Russian Federation changed from {OLD_VALUE} to {NEW_VALUE} | N | N |
| CHANGE_ | Setting for Data Localization changed from {OLD_VALUE} to {NEW_VALUE} | N | N |
| CHANGE_ | Part of an audit log event for contact info update for Data Protection Officer. This is used as an indicator of what kind of event log this message is. | N | N |
| DELETE_ | MDM vendor enrollment token ( {PLAY_FOR_WORK_TOKEN_ID} ) deleted | N | N |
| VIEW_ | DNS console login details for {DOMAIN_NAME} viewed | N | N |
| CHANGE_ | Default locale for your organization changed from {OLD_VALUE} to {NEW_VALUE} | N | N |
| CHANGE_ | Default time zone for your organization changed from {OLD_VALUE} to {NEW_VALUE} | N | N |
| CHANGE_ | Change of domain name for {DOMAIN_NAME} to {NEW_VALUE} started | N | N |
| TOGGLE_ | Pre-release features for your organization was set to {NEW_VALUE} | N | N |
| CHANGE_ | Support message for your organization changed from {OLD_VALUE} to {NEW_VALUE} | N | N |
| REMOVE_ | Domains {DOMAIN_NAME} removed from Trusted Domains list | N | Y |
| CHANGE_ | Educational organization type changed from {OLD_VALUE} to {NEW_VALUE} | N | N |
| TOGGLE_ | Enabling OAuth consumer key changed to {NEW_VALUE} for your organization | N | N |
| TOGGLE_ | SSL Enforcement changed to {NEW_VALUE} for {DOMAIN_NAME} | N | N |
| CHANGE_ | Part of an audit log event for contact info update for EU Representative. This is used as an indicator of what kind of event log this message is. | N | N |
| GENERATE_ | Transfer token generated | N | N |
| CHANGE_ | Login background color for your organization changed from {OLD_VALUE} to {NEW_VALUE} | N | N |
| CHANGE_ | Login border color for your organization changed from {OLD_VALUE} to {NEW_VALUE} | N | N |
| CHANGE_ | Marketplace Login audit setting in {DOMAIN_NAME} changed from {OLD_VALUE} to {NEW_VALUE} | N | N |
| PLAY_ | Enrolled for {PLAY_FOR_WORK_MDM_VENDOR_NAME} mobile device management services using token ( {PLAY_FOR_WORK_TOKEN_ID} ) | N | N |
| PLAY_ | Unenrolled from {PLAY_FOR_WORK_MDM_VENDOR_NAME} mobile device management services | N | N |
| MX_ | {USER_EMAIL} claimed to verify the MX record for {DOMAIN_NAME} | N | N |
| TOGGLE_ | New app features for your organization changed to {NEW_VALUE} | N | N |
| TOGGLE_ | The setting to enable the new Admin Console changed to {NEW_VALUE} for your organization | N | N |
| UPLOAD_ | New OAuth certificate uploaded for your organization | N | N |
| REGENERATE_ | New OAuth consumer secret generated for your organization | N | N |
| TOGGLE_ | OpenId federated login for {DOMAIN_NAME} changed to {NEW_VALUE} | N | N |
| CHANGE_ | Organization name changed from {OLD_VALUE} to {NEW_VALUE} | N | N |
| CHANGE_ | Password maximum length for {DOMAIN_NAME} changed from {OLD_VALUE} to {NEW_VALUE} | N | N |
| CHANGE_ | Password minimum length for {DOMAIN_NAME} changed from {OLD_VALUE} to {NEW_VALUE} | N | N |
| UPDATE_ | Primary admin for your organization changed from {OLD_VALUE} to {NEW_VALUE} | N | N |
| ENABLE_ | Receive email notification setting for your organization changed from {OLD_VALUE} to {NEW_VALUE} | N | N |
| CHANGE_ | Renew domain registration setting in {DOMAIN_NAME} changed from {OLD_VALUE} to {NEW_VALUE} | N | N |
| CHANGE_ | Reseller access changed from {OLD_VALUE} to {NEW_VALUE} | N | N |
| CHANGE_ | Reseller access for {SKU_NAME} changed from {OLD_VALUE} to {NEW_VALUE} | N | N |
| RULE_ | Rule actions for {RULE_NAME} changed | N | N |
| CREATE_ | Rule {RULE_NAME} has been created | N | N |
| CHANGE_ | Rule criteria for {RULE_NAME} has been changed | N | N |
| DELETE_ | Rule {RULE_NAME} has been deleted | N | N |
| RENAME_ | Rule {OLD_VALUE} has been renamed to {NEW_VALUE} | N | N |
| RULE_ | Rule status for {RULE_NAME} changed from {OLD_VALUE} to {NEW_VALUE} | N | N |
| ADD_ | An unverified {SECONDARY_DOMAIN_NAME} created as a secondary domain of {DOMAIN_NAME} | N | N |
| REMOVE_ | {SECONDARY_DOMAIN_NAME} deleted as a secondary domain of {DOMAIN_NAME} | N | N |
| SKIP_ | Skipped MX record setup of secondary domain {SECONDARY_DOMAIN_NAME} of domain {DOMAIN_NAME} | N | N |
| VERIFY_ | Verified MX records of secondary domain {SECONDARY_DOMAIN_NAME} of domain {DOMAIN_NAME} | N | N |
| VERIFY_ | {SECONDARY_DOMAIN_NAME} verified as a secondary domain of {DOMAIN_NAME} | N | N |
| UPDATE_ | Secondary email for your organization changed from {OLD_VALUE} to {NEW_VALUE} | N | N |
| GENERATE_ | Customer support PIN generated | N | N |
| UPDATE_ | Update rule event name. | N | N |
| EMAIL_ | Events of this type are returned with type=EMAIL_SETTINGS . | N | N |
| DROP_ | The title for the event release from quarantine. This title shows the message was dropped from quarantine. | N | N |
| EMAIL_ | Email life of a message search is launched. | N | N |
| EMAIL_ | An email log search is performed for logs from {EMAIL_LOG_SEARCH_START_DATE} to {EMAIL_LOG_SEARCH_END_DATE} with a sender of [ {EMAIL_LOG_SEARCH_SENDER} ], a recipient of [ {EMAIL_LOG_SEARCH_RECIPIENT} ], and an email message id of [ {EMAIL_LOG_SEARCH_MSG_ID} ] | N | N |
| EMAIL_ | Email restoration from {START_DATE} to {END_DATE} initiated for {USER_EMAIL} | N | N |
| CHANGE_ | {SETTING_NAME} for email service in your organization changed from {OLD_VALUE} to {NEW_VALUE} | N | N |
| DELETE_ | Gmail setting {SETTING_NAME} was deleted | N | Y |
| REJECT_ | The title for the event release from quarantine. This title shows the message was rejected from quarantine. | N | N |
| RELEASE_ | The title for the event release from quarantine. This title shows the message was released from quarantine. | N | N |
| GROUP_ | Events of this type are returned with type=GROUP_SETTINGS . | N | N |
| WHITELISTED_ | Whitelisted groups updated event. | N | N |
| CREATE_ | Group {GROUP_EMAIL} created | N | N |
| DELETE_ | Group {GROUP_EMAIL} deleted | N | N |
| CHANGE_ | Description for group {GROUP_EMAIL} changed | N | N |
| CHANGE_ | Email of group {GROUP_EMAIL} changed to {NEW_VALUE} | N | N |
| GROUP_ | Group list was downloaded as a CSV file | N | N |
| REMOVE_ | User {USER_EMAIL} deleted from group {GROUP_EMAIL} | N | N |
| UPDATE_ | Group Setting Change. | N | N |
| UPDATE_ | Group Member Delivery Settings Change. | N | N |
| UPDATE_ | Group Member Delivery Settings Email Override Change. | N | N |
| GROUP_ | A total of {GROUP_MEMBER_BULK_UPLOAD_TOTAL_NUMBER} members selected for upload. {GROUP_MEMBER_BULK_UPLOAD_FAILED_NUMBER} out of {GROUP_MEMBER_BULK_UPLOAD_TOTAL_NUMBER} members failed to be uploaded | N | N |
| GROUP_ | Group member list was downloaded as a CSV file | N | N |
| CHANGE_ | Name of group {GROUP_EMAIL} changed to {NEW_VALUE} | N | N |
| LICENSES_ | Events of this type are returned with type=LICENSES_SETTINGS . | N | N |
| CHROME_ | Licenses enabled or not for a specified group/org unit event name. | N | N |
| ORG_ | Licenses for {PRODUCT_NAME} product and {NEW_VALUE} sku were assigned to all unassigned users of {ORG_UNIT_NAME} | N | N |
| ORG_ | Licenses for {PRODUCT_NAME} product and {NEW_VALUE} sku were assigned to all users of {ORG_UNIT_NAME} | N | N |
| SUPPRESSED_ | A suppressed license for {PRODUCT_NAME} product and {NEW_VALUE} sku was assigned to the user {USER_EMAIL} | N | N |
| TEMPORARY_ | A temporary license for {PRODUCT_NAME} product and {NEW_VALUE} sku was assigned to the user {USER_EMAIL} | N | N |
| USER_ | A license for {PRODUCT_NAME} product and {NEW_VALUE} sku was assigned to the user {USER_EMAIL} | N | N |
| CHANGE_ | License Auto Assign option changed to {NEW_VALUE} for {PRODUCT_NAME} product and {SKU_NAME} sku | N | N |
| SUPPRESSED_ | Suppressed license of the user {USER_EMAIL} for {PRODUCT_NAME} product and {NEW_VALUE} sku was converted to Active | N | N |
| TEMPORARY_ | Temporary license of the user {USER_EMAIL} for {PRODUCT_NAME} product and {NEW_VALUE} sku was converted to Active | N | N |
| TEMPORARY_ | Temporary license of the user {USER_EMAIL} for {PRODUCT_NAME} product and {NEW_VALUE} sku was expired and converted to Suppressed | N | N |
| FIRST_ | Audit log event generated when first temporary or suppressed license email notification is sent to the customer. | N | N |
| RESELLER_ | Audit log event generated when first temporary or suppressed license email notification is sent to the reseller. | N | N |
| USER_ | A license for {PRODUCT_NAME} product and {OLD_VALUE} sku was reassigned for user {USER_EMAIL} to new sku {NEW_VALUE} | N | N |
| ORG_ | Licenses for {PRODUCT_NAME} product and {OLD_VALUE} sku were removed from assigned users of {ORG_UNIT_NAME} | N | N |
| SUPPRESSED_ | A suppressed license for {PRODUCT_NAME} product and {OLD_VALUE} sku was revoked from the user {USER_EMAIL} | N | N |
| TEMPORARY_ | A temporary license for {PRODUCT_NAME} product and {OLD_VALUE} sku was revoked from the user {USER_EMAIL} | N | N |
| USER_ | A license for {PRODUCT_NAME} product and {OLD_VALUE} sku was revoked from user {USER_EMAIL} | N | N |
| TEMPORARY_ | Audit log event generated when temporary licenses expired email notification is sent to the customer. | N | N |
| RESELLER_ | Audit log event generated when temporary licenses expired email notification is sent to the reseller. | N | N |
| UPDATE_ | Auto Licensing settings for {PRODUCT_NAME} product in {ORG_UNIT_NAME} organization changed from {OLD_VALUE} to {NEW_VALUE} | N | N |
| CHROME_ | Short description to indicate user license is assigned. | N | N |
| CHROME_ | Short description to indicate user license is revoked. | N | N |
| MOBILE_ | Events of this type are returned with type=MOBILE_SETTINGS . | N | N |
| ACTION_ | {ACTION_TYPE} with id {ACTION_ID} on device type {DEVICE_TYPE} and id {DEVICE_ID} was cancelled by user {USER_EMAIL} | N | N |
| ACTION_ | {ACTION_TYPE} with id {ACTION_ID} on device type {DEVICE_TYPE} and id {DEVICE_ID} was requested by user {USER_EMAIL} | N | N |
| ADD_ | Mobile certificate {MOBILE_CERTIFICATE_COMMON_NAME} added for mobile devices in your organization | N | N |
| APPLE_ | Apple DEP sync triggered by {USER_EMAIL} | N | N |
| APPLE_ | Apple Device Enrollment tokens updated by {USER_EMAIL} | N | N |
| APPLE_ | Apple VPP token {TOKEN_OPERATION_NAME} was {TOKEN_OPERATION_STATUS} | N | N |
| COMPANY_ | Details of {NUMBER_OF_COMPANY_OWNED_DEVICES} company owned device(s) were imported | N | N |
| COMPANY_ | Company owned device {COMPANY_DEVICE_ID} was blocked | N | N |
| COMPANY_ | Company owned device {COMPANY_DEVICE_ID} was deleted | N | N |
| COMPANY_ | Company owned device {COMPANY_DEVICE_ID} was unblocked | N | N |
| COMPANY_ | Company owned device {COMPANY_DEVICE_ID} was wiped | N | N |
| CUSTOMER_ | Customer user device {COMPANY_DEVICE_ID} was deleted | N | N |
| CHANGE_ | Change in mobile application permission grant. | N | N |
| CHANGE_ | Change in priority order of mobile application. | N | N |
| REMOVE_ | {DEVICE_TYPE} application {MOBILE_APP_PACKAGE_ID} is no longer whitelisted for {DISTRIBUTION_ENTITY_NAME} {DISTRIBUTION_ENTITY_TYPE} | N | N |
| CHANGE_ | Change in mobile application setting. | N | N |
| ADD_ | Mobile application is added to whitelist. | N | Y |
| MOBILE_ | Mobile device for {USER_EMAIL} approved | N | N |
| MOBILE_ | Mobile device for {USER_EMAIL} blocked | N | N |
| MOBILE_ | Mobile device for {USER_EMAIL} deleted | N | N |
| MOBILE_ | Mobile device for {USER_EMAIL} wiped | N | N |
| CHANGE_ | {SETTING_NAME} for mobile devices in your organization changed from {OLD_VALUE} to {NEW_VALUE} | N | N |
| CHANGE_ | Administrator restrictions PIN for mobile devices in your organization changed | N | N |
| CHANGE_ | Mobile wireless network {MOBILE_WIRELESS_NETWORK_NAME} changed for mobile devices in your organization | N | N |
| ADD_ | Mobile wireless network {MOBILE_WIRELESS_NETWORK_NAME} created for mobile devices in your organization | N | N |
| REMOVE_ | Mobile wireless network {MOBILE_WIRELESS_NETWORK_NAME} deleted for mobile devices in your organization | N | N |
| CHANGE_ | Password changed for mobile wireless network {MOBILE_WIRELESS_NETWORK_NAME} in your organization | N | N |
| REMOVE_ | Mobile certificate {MOBILE_CERTIFICATE_COMMON_NAME} removed for mobile devices in your organization | N | N |
| ENROLL_ | Google Device Management is a part of the Google Admin console. | N | N |
| USE_ | You have selected Google Mobile Management to manage all your mobile devices | N | N |
| USE_ | You have selected Google Mobile Management to manage your Android and Active Sync devices | N | N |
| USE_ | You have selected Google Mobile Management to manage your iOS devices | N | N |
| MOBILE_ | Mobile account for {USER_EMAIL} has been wiped | N | N |
| MOBILE_ | Wipe on mobile device for {USER_EMAIL} was cancelled and the device was approved | N | N |
| MOBILE_ | Wipe on mobile device for {USER_EMAIL} was cancelled and the device has been blocked | N | N |
| ORG_ | Events of this type are returned with type=ORG_SETTINGS . | N | N |
| CHROME_ | Licenses enabled or not at an org unit event name. | N | N |
| CHROME_ | License reservation at an org unit is created. | N | N |
| CHROME_ | License reservation at an org unit is deleted. | N | N |
| CHROME_ | License reservation at an org unit is updated. | N | N |
| CREATE_ | Event for 'Create enrollment token'. | N | N |
| ASSIGN_ | New custom logo assigned for org unit {ORG_UNIT_NAME} | N | N |
| UNASSIGN_ | Custom logo unassigned for org unit {ORG_UNIT_NAME} | N | N |
| CREATE_ | A new enrollment token is generated for {ORG_UNIT_NAME} | N | N |
| REVOKE_ | The enrollment token of {ORG_UNIT_NAME} has been revoked | N | N |
| CHROME_ | Licenses allowed or not at an org unit event name. | N | N |
| CREATE_ | Org Unit {ORG_UNIT_NAME} created | N | N |
| REMOVE_ | Org Unit {ORG_UNIT_NAME} deleted | N | N |
| EDIT_ | Description of {ORG_UNIT_NAME} changed | N | N |
| MOVE_ | {ORG_UNIT_NAME} moved to parent {NEW_VALUE} | N | N |
| EDIT_ | Name of {ORG_UNIT_NAME} changed to {NEW_VALUE} | N | N |
| REVOKE_ | Event for 'Revoke enrollment token'. | N | N |
| TOGGLE_ | Service {SERVICE_NAME} changed to {NEW_VALUE} for {ORG_UNIT_NAME} organizational unit in your organization | N | N |
| SECURITY_ | Events of this type are returned with type=SECURITY_SETTINGS . | N | N |
| CHANGE_ | For {TARGET_ENTITY_TYPE} [ {TARGET_ENTITY_NAME} ]: Before: Access level [ {CAA_ACCESS_ASSIGNMENTS_OLD} ] applied to {CAA_ENFORCEMENT_ENDPOINTS_OLD} of [ {APPLICATION_NAME} ] in [ {MODE} ] mode. After: Access level [ {CAA_ACCESS_ASSIGNMENTS_NEW} ] applied to {CAA_ENFORCEMENT_ENDPOINTS_NEW} of [ {APPLICATION_NAME} ] in [ {MODE} ] mode. | N | N |
| UNDERAGE_ | All third party API access blocked for users under 18. | N | N |
| UNDERAGE_ | Allow Google Sign-in only third party API access for users under 18. | N | N |
| SIGN_ | Allow Google Sign-in only third party API access | N | N |
| CHANGE_ | App Access Settings Collection for the org unit {ORG_UNIT_NAME} has changed from {OLD_VALUE} to {NEW_VALUE} | N | N |
| ADD_ | {OAUTH2_APP_NAME} added to Limited list for {ORG_UNIT_NAME} | N | N |
| ADD_ | {OAUTH2_APP_NAME} added to trusted by OAuth scope list for {ORG_UNIT_NAME} | N | N |
| ADD_ | {OAUTH2_APP_NAME} allowlisted for exemption from API access blocks for {ORG_UNIT_NAME} | N | N |
| REMOVE_ | {OAUTH2_APP_NAME} removed from allowlist for exemption from API access blocks for {ORG_UNIT_NAME} | N | N |
| REMOVE_ | {OAUTH2_APP_NAME} removed from Limited list for {ORG_UNIT_NAME} | N | N |
| REMOVE_ | {OAUTH2_APP_NAME} removed from trusted by OAuth scope list for {ORG_UNIT_NAME} | N | N |
| MULTIPLE_ | {OAUTH2_NUM_APPS} apps added to Blocked list for {ORG_UNIT_NAME} | N | N |
| MULTIPLE_ | {OAUTH2_NUM_APPS} apps added to Limited list for {ORG_UNIT_NAME} | N | N |
| MULTIPLE_ | {OAUTH2_NUM_APPS} apps added to Trusted by OAuth Scope list for {ORG_UNIT_NAME} | N | N |
| MULTIPLE_ | {OAUTH2_NUM_APPS} apps added to Trusted list for {ORG_UNIT_NAME} | N | N |
| OAUTH_ | {BULK_UPLOAD_SUCCESS_OAUTH_APPS_NUMBER} of {BULK_UPLOAD_TOTAL_OAUTH_APPS_NUMBER} rows successfully uploaded | N | N |
| OAUTH_ | Notification of bulk upload for apps list sent to {USER_EMAIL} | N | N |
| BLOCK_ | Summary message to display in the audit log when device access for OAuth2 apps is blocked. | N | N |
| CHANGE_ | 2-step verification frequency for {ORG_UNIT_NAME} changed from {OLD_VALUE} to {NEW_VALUE} | N | N |
| CHANGE_ | 2-step verification grace period duration for {ORG_UNIT_NAME} changed from {OLD_VALUE} to {NEW_VALUE} | N | N |
| CHANGE_ | 2-step verification start date has been changed from {OLD_VALUE} to {NEW_VALUE} | N | N |
| CHANGE_ | Error message has been changed to [ {NEW_VALUE} ]. (OrgUnit Name: {ORG_UNIT_NAME} ) | N | N |
| TOGGLE_ | Context Aware Access Remediation has been {NEW_VALUE} . (OrgUnit Name: {ORG_UNIT_NAME} ) | N | N |
| EDU_ | Disabled Edu over 18 users apps requests for {ORG_UNIT_NAME} | N | N |
| EDU_ | Disabled over 18 users making delegated apps requests for {ORG_UNIT_NAME} | N | N |
| UNDERAGE_ | Disabled under 18 users apps requests for {ORG_UNIT_NAME} | N | N |
| USER_ | Disabled users over 18 to make apps requests for {ORG_UNIT_NAME} | N | N |
| UNTRUST_ | Domain Owned Apps removed from trusted list | N | N |
| TRUST_ | Domain Owned Apps added to trusted list | N | N |
| ENABLE_ | Enable non-admin user password recovery setting in {ORG_UNIT_NAME} organization changed from {OLD_VALUE} to {NEW_VALUE} | N | N |
| EDU_ | Enabled Edu over 18 users apps requests for {ORG_UNIT_NAME} | N | N |
| EDU_ | Enabled over 18 users making delegated apps requests for {ORG_UNIT_NAME} | N | N |
| UNDERAGE_ | Enabled under 18 users apps requests for {ORG_UNIT_NAME} | N | N |
| USER_ | Enabled users over 18 to make apps requests for {ORG_UNIT_NAME} | N | N |
| UPDATE_ | Summary message to display in the audit log for Oauth2 scope management settings. | N | N |
| CHANGE_ | Session length has been changed from {OLD_VALUE} to {NEW_VALUE} | N | N |
| UNBLOCK_ | Summary message to display in the audit log when device access for OAuth2 apps is unblocked. | N | N |
| DOWNLOAD_ | Downloaded list of users requesting access to {OAUTH2_APP_NAME} | N | N |
| SITES_ | Events of this type are returned with type=SITES_SETTINGS . | N | N |
| ADD_ | Event gets triggered when a web address is added via cpanel. | N | N |
| DELETE_ | Event gets triggered when a web address is deleted via cpanel. | N | N |
| CHANGE_ | {SETTING_NAME} for sites in your organization changed from {OLD_VALUE} to {NEW_VALUE} | N | N |
| CHANGE_ | Sites web address mapping update. | N | N |
| VIEW_ | Admin viewed the site details of {SITE_NAME} | N | N |
| USER_ | Events of this type are returned with type=USER_SETTINGS . | N | N |
| DELETE_ | 2-step verification scratch codes of the user {USER_EMAIL} deleted | N | N |
| GENERATE_ | New 2-step verification scratch codes generated for the user {USER_EMAIL} | N | N |
| REVOKE_ | 3-legged OAuth tokens issued by user {USER_EMAIL} for the device type {DEVICE_TYPE} and id {DEVICE_ID} were revoked | N | N |
| ACCEPT_ | User invitation accepted for user: {USER_EMAIL} | N | N |
| ADD_ | Recovery email added for {USER_EMAIL} | N | N |
| ADD_ | Recovery phone added for {USER_EMAIL} | N | N |
| TOGGLE_ | Automatic contact sharing for {USER_EMAIL} changed to {NEW_VALUE} | N | N |
| BULK_ | {BULK_UPLOAD_TOTAL_USERS_NUMBER} users selected for upload to your organization. {BULK_UPLOAD_FAIL_USERS_NUMBER} out of {BULK_UPLOAD_TOTAL_USERS_NUMBER} users were not uploaded. | N | N |
| BULK_ | Notification of bulk users upload sent to {USER_EMAIL} | N | N |
| CANCEL_ | Invite to {USER_EMAIL} cancelled | N | N |
| CHANGE_ | {USER_CUSTOM_FIELD} changed for {USER_EMAIL} from {OLD_VALUE} to {NEW_VALUE} | N | N |
| CHANGE_ | External Ids changed for {USER_EMAIL} from {OLD_VALUE} to {NEW_VALUE} | N | N |
| CHANGE_ | Change here is a verb. The genders will be customizable, so this should be broader than male vs female. | N | N |
| CHANGE_ | IMs changed for {USER_EMAIL} from {OLD_VALUE} to {NEW_VALUE} | N | N |
| ENABLE_ | IP whitelist changed for {USER_EMAIL} from {OLD_VALUE} to {NEW_VALUE} | N | N |
| CHANGE_ | Keywords are used on user profiles to help identify a user in searches. Example: find person with name 'Larry' and school 'Stanford'. 'Change' is a verb. | N | N |
| CHANGE_ | Can be a predefined set of more common languages provided by Google or a custom language. 'Change' here is a verb. | N | N |
| CHANGE_ | Location is different from address in the following ways: (1) Location can be fuzzy. Example: Near Seattle. (2) Hovercards and other short user summaries display location, not address. 'Change' is a verb. | N | N |
| CHANGE_ | Organizations changed for {USER_EMAIL} from {OLD_VALUE} to {NEW_VALUE} | N | N |
| CHANGE_ | Phone Numbers changed for {USER_EMAIL} from {OLD_VALUE} to {NEW_VALUE} | N | N |
| CHANGE_ | Recovery email changed for {USER_EMAIL} | N | N |
| CHANGE_ | Recovery phone changed for {USER_EMAIL} | N | N |
| CHANGE_ | Relations changed for {USER_EMAIL} from {OLD_VALUE} to {NEW_VALUE} | N | N |
| CHANGE_ | Addresses changed for {USER_EMAIL} from {OLD_VALUE} to {NEW_VALUE} | N | N |
| CREATE_ | Created an email monitor for {USER_EMAIL} to {EMAIL_MONITOR_DEST_EMAIL} that will expire on {END_DATE_TIME} | N | N |
| DELETE_ | Deleted account and login information dump for {USER_EMAIL} and request ID {REQUEST_ID} | N | N |
| DELETE_ | Deleted an email monitor for {USER_EMAIL} to {EMAIL_MONITOR_DEST_EMAIL} | N | N |
| DELETE_ | Deleted mailbox dump for {USER_EMAIL} and request ID {REQUEST_ID} | N | N |
| DELETE_ | Profile photo of {USER_EMAIL} has been deleted | N | N |
| ADD_ | {USER_DISPLAY_NAME} added as a display name of {USER_EMAIL} | N | N |
| CHANGE_ | Display name of {USER_EMAIL} changed from {OLD_VALUE} to {NEW_VALUE} | N | N |
| REMOVE_ | {USER_DISPLAY_NAME} removed as a display name of {USER_EMAIL} | N | N |
| CHANGE_ | First name of {USER_EMAIL} changed from {OLD_VALUE} to {NEW_VALUE} | N | N |
| GMAIL_ | Gmail account of {USER_EMAIL} reset | N | N |
| CHANGE_ | Last name of {USER_EMAIL} changed from {OLD_VALUE} to {NEW_VALUE} | N | N |
| MAIL_ | User {USER_EMAIL} has received the following individual mail routing destination: {NEW_VALUE} | N | N |
| MAIL_ | User {USER_EMAIL} has had the following individual mail routing destination removed: {OLD_VALUE} | N | N |
| ADD_ | {USER_NICKNAME} created as a nickname of {USER_EMAIL} | N | N |
| REMOVE_ | {USER_NICKNAME} deleted as a nickname of {USER_EMAIL} | N | N |
| PASSKEY_ | A passkey enrolled for user {USER_EMAIL} was revoked | N | N |
| CHANGE_ | Password change requirement for {USER_EMAIL} on next login changed from {OLD_VALUE} to {NEW_VALUE} | N | N |
| DOWNLOAD_ | Pending Invites List was downloaded as a CSV file | N | N |
| UPDATE_ | Public key certificate status updated to {PUBLIC_KEY_CERTIFICATE_STATUS} for email {USER_IMPACTED_EMAIL} of user {USER_EMAIL} | N | N |
| UPDATE_ | Public key certificate updated for {USER_DISPLAY_NAME} email {USER_EMAIL} | N | N |
| REMOVE_ | Recovery email removed for {USER_EMAIL} | N | N |
| REMOVE_ | Recovery phone removed for {USER_EMAIL} | N | N |
| REQUEST_ | Requested account and login information for {USER_EMAIL} | N | N |
| REQUEST_ | Requested mailbox dump for {USER_EMAIL} | N | N |
| RESEND_ | Invite email to {USER_EMAIL} resent | N | N |
| RESET_ | Cookies reset for {USER_EMAIL} and forced re-login | N | N |
| SECURITY_ | Security key registered for {USER_EMAIL} | N | N |
| REVOKE_ | A security key enrolled for user {USER_EMAIL} for 2-step verification was revoked | N | N |
| USER_ | {USER_EMAIL} invited to join your organization | N | N |
| VIEW_ | Temporary password for user {USER_EMAIL} viewed by the admin | N | N |
| UNBLOCK_ | User {USER_EMAIL} unblocked by temporarily disabling login challenge | N | N |
| UNMANAGED_ | A total of {BULK_UPLOAD_TOTAL_USERS_NUMBER} unmanaged users selected for upload. {BULK_UPLOAD_FAIL_USERS_NUMBER} out of {BULK_UPLOAD_TOTAL_USERS_NUMBER} users failed to be uploaded. | N | N |
| DOWNLOAD_ | Unmanaged Users list was downloaded as a CSV file | N | N |
| UPDATE_ | Profile photo of {USER_EMAIL} has been updated | N | N |
| UNENROLL_ | User {USER_EMAIL} unenrolled from Advanced Protection | N | N |
| ARCHIVE_ | {USER_EMAIL} archived | N | N |
| UPDATE_ | The birth date for {USER_EMAIL} changed to {BIRTHDATE} | N | N |
| USER_ | A user created passkey enrolled for user {USER_EMAIL} was revoked | N | N |
| DOWNGRADE_ | {USER_EMAIL} was downgraded from Google+ | N | N |
| USER_ | {USER_EMAIL} enrolled in 2-step verification | N | N |
| DOWNLOAD_ | User list was downloaded as a CSV file | N | N |
| DOWNLOAD_ | User list was downloaded in {FORMAT} | N | N |
| USER_ | 2-step verification grace period has been enabled on {USER_EMAIL} till {NEW_VALUE} | N | N |
| UNENROLL_ | User {USER_EMAIL} unenrolled from Strong Auth | N | Y |
| UNARCHIVE_ | {USER_EMAIL} unarchived | N | N |
| UNDELETE_ | {USER_EMAIL} undeleted | N | N |
| UPGRADE_ | {USER_EMAIL} was upgraded to Google+ | N | N |
| USERS_ | A total of {BULK_UPLOAD_TOTAL_USERS_NUMBER} users selected for upload. {BULK_UPLOAD_FAIL_USERS_NUMBER} out of {BULK_UPLOAD_TOTAL_USERS_NUMBER} users failed to be uploaded. | N | N |
| USERS_ | Notification of bulk users upload sent to {USER_EMAIL} | N | N |
any: Admin Console (any event)
#Description
Source-only rules that filter on applicationName 'admin' without specifying an eventName attribute here.
References #
ADD_APPLICATION: Add Application
#Description
An application was added to the Google Workspace domain.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1098, T1098.001YARA-L #
Panther #
References #
ADD_GROUP_MEMBER: Group Member Creation
#Description
A user was added to a group.
Example Audit Activity #
{
"kind": "admin#reports#activity",
"id": {
"time": "2022-08-02T07:23:13.421Z",
"uniqueQualifier": "-6242204098544478741",
"applicationName": "admin",
"customerId": "C00mpaiwz"
},
"etag": "\"_ZVRqe-BUDYcYeOIPo-gm6Eh1QaGne4ACjHHI6qsr6A/9oyhwvio4MjL25Tdz-HrTS7DwCc\"",
"actor": {
"callerType": "USER",
"email": "admin@cloud-response.com",
"profileId": "111440584475724055600"
},
"ipAddress": "86.48.11.48",
"events": [
{
"type": "GROUP_SETTINGS",
"name": "ADD_GROUP_MEMBER",
"parameters": [
{
"name": "USER_EMAIL",
"value": "workspace@cloud-response.com"
},
{
"name": "GROUP_EMAIL",
"value": "sales@cloud-response.com"
}
]
}
]
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1078, T1078.004, T1098YARA-L #
T1078
References #
ADD_PRIVILEGE: Add Privilege
#Description
A privilege was added to a role.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1098↳ also matches UPDATE_ROLE: Update Role
References #
ADD_TRUSTED_DOMAINS: Domains added to Trusted Domains
#Description
A domain was added to the trusted domains list.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1484, T1484.002, T1562, T1562.007YARA-L #
T1562Panther #
T1098↳ also matches REMOVE_TRUSTED_DOMAINS: Domains removed from Trusted Domains
References #
ALLOW_STRONG_AUTHENTICATION: Allow 2-Step Verification
#Description
The administrator changed the MFA enforcement setting (allow/require strong authentication).
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
google_workspace.admin.new_value (GWS) | eq | false | 2 rules | elastic |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
Elastic #
T1531, T1556, T1556.006↳ also matches ENFORCE_STRONG_AUTHENTICATION: Enforce 2-Step Verification T1556↳ also matches ENFORCE_STRONG_AUTHENTICATION: Enforce 2-Step Verification YARA-L #
T1556↳ also matches ENFORCE_STRONG_AUTHENTICATION: Enforce 2-Step Verification
References #
ASSIGN_ROLE: Assign Role
#Description
An admin role was assigned to a user or service account.
Example Audit Activity #
{
"kind": "admin#reports#activity",
"id": {
"time": "2022-03-19T22:20:43.530Z",
"uniqueQualifier": "-7508907472163717949",
"applicationName": "admin",
"customerId": "C00mpaiwz"
},
"etag": "\"_ZVRqe-BUDYcYeOIPo-gm6Eh1QaGne4ACjHHI6qsr6A/mBEzkDVa6667CpQAnS5-siNE7Q8\"",
"actor": {
"callerType": "USER",
"email": "admin@cloud-response.com",
"profileId": "111440584475724055600"
},
"ipAddress": "80.114.222.200",
"events": [
{
"type": "DELEGATED_ADMIN_SETTINGS",
"name": "ASSIGN_ROLE",
"parameters": [
{
"name": "ROLE_NAME",
"value": "_SEED_ADMIN_ROLE"
},
{
"name": "USER_EMAIL",
"value": "greg@cloud-response.com"
}
]
}
]
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
security_result.category_details (Chronicle) | eq | DELEGATED_ADMIN_SETTINGS | 1 rule | chronicle |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1098, T1098.003YARA-L #
T1098
References #
CHANGE_APPLICATION_SETTING: Application Setting Change
#Description
A setting for a Google Workspace application was modified.
Example Audit Activity #
{
"kind": "admin#reports#activity",
"id": {
"time": "2022-07-19T06:43:02.250Z",
"uniqueQualifier": "-6822745075951815011",
"applicationName": "admin",
"customerId": "C00mpaiwz"
},
"etag": "\"_ZVRqe-BUDYcYeOIPo-gm6Eh1QaGne4ACjHHI6qsr6A/1UHNER-nXmxzm1FTJ6hrJsN1r5w\"",
"actor": {
"callerType": "USER",
"email": "admin@cloud-response.com",
"profileId": "111440584475724055600"
},
"ipAddress": "80.114.222.200",
"events": [
{
"type": "APPLICATION_SETTINGS",
"name": "CHANGE_APPLICATION_SETTING",
"parameters": [
{
"name": "APPLICATION_NAME",
"value": "Google Cloud Platform Sharing Options"
},
{
"name": "ORG_UNIT_NAME",
"value": "cloud-response.com"
},
{
"name": "SETTING_NAME",
"value": "Data Sharing Settings between GCP and Google Workspace \"Sharing Options\""
},
{
"name": "OLD_VALUE",
"value": "DISABLED"
},
{
"name": "NEW_VALUE",
"value": "ENABLED"
}
]
}
]
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
google_workspace.admin.application.name (GWS) | eq | google workspace marketplace | 2 rules | elastic |
parameters.APPLICATION_NAME (panther rule field) | eq | gmail | 2 rules | panther |
parameters.NEW_VALUE (panther rule field) | eq | true | 2 rules | panther |
security_result.category_details (Chronicle) | eq | APPLICATION_SETTINGS | 2 rules | chronicle |
type (panther rule field) | eq | APPLICATION_SETTINGS | 2 rules | panther |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1098, T1098.003Elastic #
T1114, T1114.003↳ also matches CHANGE_GMAIL_SETTING: Gmail Setting Change, CREATE_APPLICATION_SETTING: Application Setting Creation, CREATE_GMAIL_SETTING: Gmail Setting Creation T1484, T1562, T1562.001T1484, T1562, T1562.001YARA-L #
T1562T1098↳ also matches CREATE_APPLICATION_SETTING: Application Setting Creation Panther #
T1566T1566T1110
References #
CHANGE_GMAIL_SETTING: Gmail Setting Change
#Description
A Gmail routing or mail-flow setting was changed.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1114, T1114.003↳ also matches CHANGE_APPLICATION_SETTING: Application Setting Change, CREATE_APPLICATION_SETTING: Application Setting Creation, CREATE_GMAIL_SETTING: Gmail Setting Creation Panther #
T1098↳ also matches CREATE_GMAIL_SETTING: Gmail Setting Creation, DELETE_GMAIL_SETTING: Gmail Setting Deletion
References #
CREATE_APPLICATION_SETTING: Application Setting Creation
#Description
A new application setting was created.
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
security_result.category_details (Chronicle) | eq | APPLICATION_SETTINGS | 1 rule | chronicle |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1114, T1114.003↳ also matches CHANGE_APPLICATION_SETTING: Application Setting Change, CHANGE_GMAIL_SETTING: Gmail Setting Change, CREATE_GMAIL_SETTING: Gmail Setting Creation T1098, T1484↳ also matches CHANGE_APPLICATION_SETTING: Application Setting Change YARA-L #
T1098↳ also matches CHANGE_APPLICATION_SETTING: Application Setting Change Panther #
References #
CREATE_DATA_TRANSFER_REQUEST: Data transfer request created
#Description
An admin initiated a data transfer (Drive file ownership reassignment) to another user.
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
security_result.category_details (Chronicle) | eq | USER_SETTINGS | 1 rule | chronicle |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1074, T1074.002, T1537↳ also matches CUSTOMER_TAKEOUT_CREATED: Customer Takeout Created YARA-L #
T1074
References #
CREATE_GMAIL_SETTING: Gmail Setting Creation
#Description
A new Gmail routing or mail-flow setting was created.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1114, T1114.003↳ also matches CHANGE_APPLICATION_SETTING: Application Setting Change, CHANGE_GMAIL_SETTING: Gmail Setting Change, CREATE_APPLICATION_SETTING: Application Setting Creation Panther #
T1098↳ also matches CHANGE_GMAIL_SETTING: Gmail Setting Change, DELETE_GMAIL_SETTING: Gmail Setting Deletion
References #
CREATE_ROLE: Create Role
#Description
A custom admin role was created.
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
security_result.category_details (Chronicle) | eq | DELEGATED_ADMIN_SETTINGS | 1 rule | chronicle |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1098, T1098.003YARA-L #
T1098Panther #
References #
CUSTOMER_TAKEOUT_CREATED: Customer Takeout Created
#Description
An admin initiated a Takeout export job for organizational data.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1074, T1074.002, T1537↳ also matches CREATE_DATA_TRANSFER_REQUEST: Data transfer request created Panther #
References #
DELETE_ROLE: Delete Role
#Description
An admin role was permanently deleted.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
Elastic #
T1484, T1531
References #
ENFORCE_STRONG_AUTHENTICATION: Enforce 2-Step Verification
#Description
The MFA/2SV enforcement policy was changed for the domain or an organizational unit.
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
google_workspace.admin.new_value (GWS) | eq | false | 2 rules | elastic |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
Elastic #
T1531, T1556, T1556.006↳ also matches ALLOW_STRONG_AUTHENTICATION: Allow 2-Step Verification T1556↳ also matches ALLOW_STRONG_AUTHENTICATION: Allow 2-Step Verification YARA-L #
T1556↳ also matches ALLOW_STRONG_AUTHENTICATION: Allow 2-Step Verification
References #
GRANT_ADMIN_PRIVILEGE: Admin Privileges Grant
#Description
Administrator privileges were granted to a user account.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1098↳ also matches GRANT_DELEGATED_ADMIN_PRIVILEGES: Delegated Admin Privileges Grant Kusto #
T1098
References #
GRANT_DELEGATED_ADMIN_PRIVILEGES: Delegated Admin Privileges Grant
#Description
Delegated administrator privileges were granted to a user.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1098↳ also matches GRANT_ADMIN_PRIVILEGE: Admin Privileges Grant
References #
MOVE_USER_TO_ORG_UNIT: User OrgUnit Change
#Description
A user was moved to a different organizational unit.
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
google_workspace.event.type (GWS) | eq | user_settings | 1 rule | elastic |
security_result.category_details (Chronicle) | eq | USER_SETTINGS | 1 rule | chronicle |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1098, T1098.003YARA-L #
T1098
References #
REMOVE_APPLICATION: Remove Application
#Description
An application was removed from the Google Workspace domain.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
References #
REMOVE_APPLICATION_FROM_WHITELIST: Remove Application from Whitelist
#Description
An application was removed from the domain's marketplace allowlist.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
References #
REMOVE_PRIVILEGE: Remove Privilege
#Description
A privilege was removed from a role.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
References #
RENAME_ROLE: Rename Role
#Description
An admin role was renamed.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
References #
SAML2_SERVICE_PROVIDER_CONFIG: SAML2 Service Provider Config
#Description
A SAML 2.0 service provider configuration was added, modified, or removed.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →YARA-L #
T1078
References #
TOGGLE_OUTBOUND_RELAY: Outbound Relay Change
#Description
Outbound email relay routing was enabled or disabled.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto #
T1114
References #
TURN_OFF_2_STEP_VERIFICATION: Turn off 2-step verification
#Description
2-Step Verification was disabled for a user or the domain.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto #
T1111
References #
UNSUSPEND_USER: User Unsuspension
#Description
A suspended user account was reactivated.
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
google_workspace.event.type (GWS) | eq | user_settings | 1 rule | elastic |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1078, T1078.004, T1098YARA-L #
T1078
References #
UPDATE_ROLE: Update Role
#Description
An existing admin role was modified (e.g. description or privileges changed).
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
Elastic #
T1098↳ also matches ADD_PRIVILEGE: Add Privilege
References #
BLOCK_ALL_THIRD_PARTY_API_ACCESS: All third party API access blocked
#Description
An admin blocked all third-party application access to Google Workspace APIs.
References #
UNBLOCK_ALL_THIRD_PARTY_API_ACCESS: All third party API access unblocked
#Description
An admin unblocked third-party application access to Google Workspace APIs.
References #
ADD_TO_TRUSTED_OAUTH2_APPS: App trusted
#Description
An OAuth2 application was added to the trusted apps list.
References #
ADD_TO_BLOCKED_OAUTH2_APPS: App added to Blocked list
#Description
An OAuth2 application was blocked from accessing Google Workspace data.
References #
REMOVE_FROM_BLOCKED_OAUTH2_APPS: App removed from Blocked list
#Description
An OAuth2 application was removed from the blocked apps list.
References #
REMOVE_FROM_TRUSTED_OAUTH2_APPS: App no longer trusted
#Description
An OAuth2 application was removed from the trusted apps list.
References #
CREATE_USER: User Creation
#Description
A new user account was created in the Google Workspace domain.
Example Audit Activity #
{
"kind": "admin#reports#activity",
"id": {
"time": "2022-07-19T10:30:16.448Z",
"uniqueQualifier": "-6485662965628883717",
"applicationName": "admin",
"customerId": "C00mpaiwz"
},
"etag": "\"_ZVRqe-BUDYcYeOIPo-gm6Eh1QaGne4ACjHHI6qsr6A/xgZr-1-dUUwmP7cz8G9pXT-7nL8\"",
"actor": {
"callerType": "USER",
"email": "admin@cloud-response.com",
"profileId": "111440584475724055600"
},
"ipAddress": "80.114.222.200",
"events": [
{
"type": "USER_SETTINGS",
"name": "CREATE_USER",
"parameters": [
{
"name": "USER_EMAIL",
"value": "suspicious@cloud-response.com"
}
]
}
]
}
References #
DELETE_USER: User Deletion
#Description
A user account was deleted from the Google Workspace domain.
Example Audit Activity #
{
"kind": "admin#reports#activity",
"id": {
"time": "2022-08-11T09:11:04.542Z",
"uniqueQualifier": "-8365490708529497756",
"applicationName": "admin",
"customerId": "C00mpaiwz"
},
"etag": "\"_ZVRqe-BUDYcYeOIPo-gm6Eh1QaGne4ACjHHI6qsr6A/PargyQuH7NlMI8Ov8vSZAlDrUEU\"",
"actor": {
"callerType": "USER",
"email": "admin@cloud-response.com",
"profileId": "111440584475724055600"
},
"ipAddress": "145.128.241.109",
"events": [
{
"type": "USER_SETTINGS",
"name": "DELETE_USER",
"parameters": [
{
"name": "USER_EMAIL",
"value": "workspace@cloud-response.com"
}
]
}
]
}
References #
SUSPEND_USER: User Suspension
#Description
A user account was suspended by an administrator.
References #
RENAME_USER: User Rename
#Description
A user's primary email address was changed.
Example Audit Activity #
{
"kind": "admin#reports#activity",
"id": {
"time": "2022-07-21T13:37:47.057Z",
"uniqueQualifier": "-6570038635980180654",
"applicationName": "admin",
"customerId": "C00mpaiwz"
},
"etag": "\"_ZVRqe-BUDYcYeOIPo-gm6Eh1QaGne4ACjHHI6qsr6A/v88-DyEM0pnIGTdGBaEFFudjFic\"",
"actor": {
"callerType": "USER",
"email": "admin@cloud-response.com",
"profileId": "111440584475724055600"
},
"ipAddress": "80.114.222.200",
"events": [
{
"type": "USER_SETTINGS",
"name": "RENAME_USER",
"parameters": [
{
"name": "USER_EMAIL",
"value": "suspicious@cloud-response.com"
},
{
"name": "NEW_VALUE",
"value": "workspace@cloud-response.com"
}
]
},
{
"type": "USER_SETTINGS",
"name": "CHANGE_FIRST_NAME",
"parameters": [
{
"name": "USER_EMAIL",
"value": "suspicious@cloud-response.com"
},
{
"name": "OLD_VALUE",
"value": "Suspicious"
},
{
"name": "NEW_VALUE",
"value": "Workspace"
}
]
},
{
"type": "USER_SETTINGS",
"name": "CHANGE_LAST_NAME",
"parameters": [
{
"name": "USER_EMAIL",
"value": "suspicious@cloud-response.com"
},
{
"name": "OLD_VALUE",
"value": "account"
},
{
"name": "NEW_VALUE",
"value": "Admin"
}
]
}
]
}
References #
CHANGE_PASSWORD: Password Change
#Description
An administrator changed a user's password.
Example Audit Activity #
{
"kind": "admin#reports#activity",
"id": {
"time": "2022-07-21T13:38:00.608Z",
"uniqueQualifier": "-8471045246260126614",
"applicationName": "admin",
"customerId": "C00mpaiwz"
},
"etag": "\"_ZVRqe-BUDYcYeOIPo-gm6Eh1QaGne4ACjHHI6qsr6A/41AqQRL7AL27pZdLqUiiksMUcEQ\"",
"actor": {
"callerType": "USER",
"email": "admin@cloud-response.com",
"profileId": "111440584475724055600"
},
"ipAddress": "80.114.222.200",
"events": [
{
"type": "USER_SETTINGS",
"name": "CHANGE_PASSWORD",
"parameters": [
{
"name": "USER_EMAIL",
"value": "workspace@cloud-response.com"
}
]
}
]
}
References #
REVOKE_ASP: Application Specific Password Revoke
#Description
An administrator revoked an application-specific password (ASP) for a user.
References #
REVOKE_3LO_TOKEN: 3-legged OAuth Token Revoke
#Description
An administrator revoked an OAuth token for a user.
References #
SESSION_CONTROL_SETTINGS_CHANGE: Session Control Settings Change
#Description
Web session duration or re-authentication settings were changed.
References #
WEAK_PROGRAMMATIC_LOGIN_SETTINGS_CHANGED: Less Secure Apps Access setting changed
#Description
Settings controlling less-secure app access (LSA/basic auth) were changed.
References #
CHANGE_SSO_SETTINGS: SSO Setting Change
#Description
SAML/SSO settings for the domain were changed.
References #
TOGGLE_SSO_ENABLED: Enable SSO Change
#Description
SSO (SAML-based single sign-on) was enabled or disabled for the domain.
References #
REVOKE_ADMIN_PRIVILEGE: Admin Privileges Revoke
#Description
Administrator privileges were revoked from a user account.
References #
ALLOW_SERVICE_FOR_OAUTH2_ACCESS: API Access Allowed
#Description
A Google service was allowed for OAuth2 API access.
References #
DISALLOW_SERVICE_FOR_OAUTH2_ACCESS: API Access Blocked
#Description
A Google service was disallowed for OAuth2 API access.
References #
CHANGE_GROUP_SETTING: Group Setting Change
#Description
A setting for a Google Group was changed by an administrator.
Example Audit Activity #
{
"kind": "admin#reports#activity",
"id": {
"time": "2022-08-02T07:23:13.089Z",
"uniqueQualifier": "-8719895655046965875",
"applicationName": "admin",
"customerId": "C00mpaiwz"
},
"etag": "\"_ZVRqe-BUDYcYeOIPo-gm6Eh1QaGne4ACjHHI6qsr6A/u50Xc4yaXja3OryKbjY0C8gwceE\"",
"actor": {
"callerType": "USER",
"email": "admin@cloud-response.com",
"profileId": "111440584475724055600"
},
"ipAddress": "86.48.11.48",
"events": [
{
"type": "GROUP_SETTINGS",
"name": "CHANGE_GROUP_SETTING",
"parameters": [
{
"name": "SETTING_NAME",
"value": "WHO_CAN_POST_MESSAGE"
},
{
"name": "GROUP_EMAIL",
"value": "sales@cloud-response.com"
},
{
"name": "OLD_VALUE",
"value": "ANYONE_CAN_POST"
},
{
"name": "NEW_VALUE",
"value": "ALL_MEMBERS_CAN_POST"
}
]
},
{
"type": "GROUP_SETTINGS",
"name": "CHANGE_GROUP_SETTING",
"parameters": [
{
"name": "SETTING_NAME",
"value": "IS_ARCHIVED"
},
{
"name": "GROUP_EMAIL",
"value": "sales@cloud-response.com"
},
{
"name": "OLD_VALUE",
"value": "false"
},
{
"name": "NEW_VALUE",
"value": "true"
}
]
}
]
}
References #
ADD_APPLICATION_TO_WHITELIST: Add Application to Whitelist
#Description
An application was added to the domain's Google Workspace Marketplace allowlist.
References #
CHANGE_TWO_STEP_VERIFICATION_ENROLLMENT_PERIOD_DURATION: Change 2-Step Verification Enrollment Period Duration
#Description
The enrollment period for 2-Step Verification was changed.
References #
CHANGE_ALLOWED_TWO_STEP_VERIFICATION_METHODS: Change Allowed 2-step Verification Methods
#Description
The allowed methods for 2-Step Verification were changed.
References #
APPLICATION_SETTINGS: Application Settings
#Description
Events of this type are returned with type=APPLICATION_SETTINGS .
References #
DELETE_APPLICATION_SETTING: Application Setting Deletion
#Description
For {APPLICATION_NAME} , {SETTING_NAME} with value {OLD_VALUE} deleted
References #
REORDER_GROUP_BASED_POLICIES_EVENT: Application Setting Group Priorities Change
#Description
For {APPLICATION_NAME} , group override priorities for {SETTING_NAME} changed to {GROUP_PRIORITIES} .
References #
CREATE_MANAGED_CONFIGURATION: Managed configuration is created
#Description
Managed configuration with name {MANAGED_CONFIGURATION_NAME} is created for {DEVICE_TYPE} application {MOBILE_APP_PACKAGE_ID} .
References #
DELETE_MANAGED_CONFIGURATION: Managed configuration is deleted
#Description
Managed configuration with name {MANAGED_CONFIGURATION_NAME} is deleted for {DEVICE_TYPE} application {MOBILE_APP_PACKAGE_ID} .
References #
UPDATE_MANAGED_CONFIGURATION: Managed configuration is updated
#Description
Managed configuration with name {MANAGED_CONFIGURATION_NAME} is updated for {DEVICE_TYPE} application {MOBILE_APP_PACKAGE_ID} .
References #
FLASHLIGHT_EDU_NON_FEATURED_SERVICES_SELECTED: Non-Featured Services Selected
#Description
{FLASHLIGHT_EDU_NON_FEATURED_SERVICES_SELECTION} selection was made for Non-Featured Services.
References #
UPDATE_SMART_FEATURES: Update Smart features and personalization
#Description
Smart features and personalization setting has been updated to {NEW_VALUE}
References #
CALENDAR_SETTINGS: Calendar Settings
#Description
Events of this type are returned with type=CALENDAR_SETTINGS .
References #
UPDATE_BUILDING: Building Update
#Description
Building {RESOURCE_IDENTIFIER} updated field {FIELD_NAME} from {OLD_VALUE} to {NEW_VALUE}
References #
EWS_IN_NEW_CREDENTIALS_GENERATED: Calendar Interop credentials generated
#Description
Short description for EWS IN credentials generation.
References #
EWS_OUT_ENDPOINT_CONFIGURATION_RESET: Calendar Interop Exchange endpoint configuration cleared
#Description
Short description for clearing Calendar Interop Exchange endpoint configuration.
References #
EWS_OUT_ENDPOINT_CONFIGURATION_CHANGED: Calendar Interop Exchange endpoint configuration updated
#Description
Short description for changing Calendar Interop Exchange endpoint configuration.
References #
CREATE_CALENDAR_RESOURCE: Calendar Resource Creation
#Description
Calendar resource {NEW_VALUE} created
References #
DELETE_CALENDAR_RESOURCE: Calendar Resource Deletion
#Description
Calendar resource {OLD_VALUE} deleted
References #
CREATE_CALENDAR_RESOURCE_FEATURE: Calendar Resource Feature Creation
#Description
Calendar resource feature {NEW_VALUE} created
References #
DELETE_CALENDAR_RESOURCE_FEATURE: Calendar Resource Feature Deletion
#Description
Calendar resource feature {OLD_VALUE} deleted
References #
UPDATE_CALENDAR_RESOURCE_FEATURE: Calendar Resource Feature Update
#Description
Calendar resource feature {RESOURCE_IDENTIFIER} updated field {FIELD_NAME} from {OLD_VALUE} to {NEW_VALUE}
References #
RENAME_CALENDAR_RESOURCE: Calendar Resource Rename
#Description
Calendar resource {OLD_VALUE} renamed to {NEW_VALUE}
References #
UPDATE_CALENDAR_RESOURCE: Calendar Resource Update
#Description
Calendar resource {RESOURCE_IDENTIFIER} updated field {FIELD_NAME} from {OLD_VALUE} to {NEW_VALUE}
References #
CHANGE_CALENDAR_SETTING: Calendar Setting Change
#Description
{SETTING_NAME} for calendar service in your organization changed from {OLD_VALUE} to {NEW_VALUE}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1087
References #
CANCEL_CALENDAR_EVENTS: Event cancellation request created
#Description
Event cancellation request created for {USER_EMAIL}
References #
RELEASE_CALENDAR_RESOURCES: Release resources request created
#Description
Release resources request created for {USER_EMAIL}
References #
CHAT_SETTINGS: Talk Settings
#Description
Note that this page also contains events for Google Hangouts, as well as the previous Google Chat product. Events of this type are returned with type=CHAT_SETTINGS .
References #
MEET_INTEROP_CREATE_GATEWAY: A Google Meet interoperability gateway was created.
#Description
A Hangouts Meet interoperability gateway was created
References #
MEET_INTEROP_DELETE_GATEWAY: A Google Meet interoperability gateway was deleted.
#Description
A Hangouts Meet interoperability gateway was deleted
References #
MEET_INTEROP_MODIFY_GATEWAY: A Google Meet interoperability gateway was modified.
#Description
A Hangouts Meet interoperability gateway was modified
References #
CHANGE_CHAT_SETTING: Hangouts Setting Change
#Description
{SETTING_NAME} for talk service for your organization changed from {OLD_VALUE} to {NEW_VALUE}
References #
CHROME_OS_SETTINGS: ChromeOS Settings
#Description
Events of this type are returned with type=CHROME_OS_SETTINGS .
References #
CHANGE_CHROME_OS_ANDROID_APPLICATION_SETTING: Android Application Setting Change
#Description
{SETTING_NAME} for Android app {APP_ID} for session type {CHROME_OS_SESSION_TYPE} changed from {OLD_VALUE} to {NEW_VALUE}
References #
CHANGE_DEVICE_UPGRADE: Change Device Upgrade
#Description
Changed upgrade from {OLD_VALUE} to {NEW_VALUE} for device with serial number {DEVICE_SERIAL_NUMBER} .
References #
CHANGE_CHROME_OS_APPLICATION_SETTING: Chrome Application Setting Change
#Description
{SETTING_NAME} for Chrome app {APP_ID} for session type {CHROME_OS_SESSION_TYPE} changed from {OLD_VALUE} to {NEW_VALUE}
References #
SEND_CHROME_OS_DEVICE_COMMAND: ChromeOS Device Command
#Description
Sent {NEW_VALUE} command to ChromeOS device {DEVICE_SERIAL_NUMBER}
References #
CHANGE_CHROME_OS_DEVICE_ANNOTATION: ChromeOS Device Property Change
#Description
ChromeOS device {DEVICE_SERIAL_NUMBER} had its properties updated
References #
CHANGE_CHROME_OS_DEVICE_SETTING: ChromeOS Device Setting Change
#Description
{SETTING_NAME} for ChromeOS devices in {ORG_UNIT_NAME} organization unit changed from {OLD_VALUE} to {NEW_VALUE}
References #
CHANGE_CHROME_OS_DEVICE_STATE: ChromeOS Device State Change
#Description
State of ChromeOS device {DEVICE_SERIAL_NUMBER} changed from {OLD_VALUE} to {NEW_VALUE}
References #
CHANGE_CHROME_OS_PUBLIC_SESSION_SETTING: ChromeOS managed guest session setting change
#Description
{SETTING_NAME} for ChromeOS managed guest session in {ORG_UNIT_NAME} organization unit changed from {OLD_VALUE} to {NEW_VALUE}
References #
INSERT_CHROME_OS_PRINT_SERVER: ChromeOS Print Server Added
#Description
Print server is added.
References #
DELETE_CHROME_OS_PRINT_SERVER: ChromeOS Print Server Deleted
#Description
Existing print server is deleted.
References #
UPDATE_CHROME_OS_PRINT_SERVER: ChromeOS Print Server Updated
#Description
Existing print server is updated.
References #
UPDATE_CHROME_OS_PRINTER: ChromeOS Printer Updated
#Description
Existing printer is updated.
References #
CHANGE_CHROME_OS_SETTING: ChromeOS Setting Change
#Description
{SETTING_NAME} for ChromeOS devices in your organization changed from {OLD_VALUE} to {NEW_VALUE}
References #
CHANGE_CHROME_OS_USER_SETTING: ChromeOS User Setting Change
#Description
{SETTING_NAME} for ChromeOS users in {ORG_UNIT_NAME} organization unit changed from {OLD_VALUE} to {NEW_VALUE}
References #
CREATE_CHROME_OS_ENROLLMENT_TOKEN: Create ChromeOS enrollment token
#Description
Event for 'Create ChromeOS enrollment token'.
References #
CHANGE_CHROME_OS_CUSTOM_CONFIGURATIONS_JSON_SETTING: Custom Configurations JSON Setting Change
#Description
Custom configurations JSON field in the {ORG_UNIT_NAME} organizational unit changed from {OLD_VALUE} to {NEW_VALUE}
References #
DELETE_CHROME_OS_DEVICE: Delete ChromeOS device
#Description
Event for 'Delete ChromeOS device'.
References #
DELETE_DUPLICATE_CHROME_OS_DEVICE: Delete duplicate ChromeOS device
#Description
Event for 'Delete duplicate ChromeOS device'.
References #
CHANGE_CHROME_OS_ISOLATED_WEB_APPLICATION_SETTING: Isolated Web Application Setting Change
#Description
{SETTING_NAME} for Isolated Web app {APP_ID} for session type {CHROME_OS_SESSION_TYPE} changed from {OLD_VALUE} to {NEW_VALUE}
References #
MOVE_DEVICE_TO_ORG_UNIT_DETAILED: Move device to Organizational unit
#Description
Event for 'Move device to Org Unit'.
References #
PRE_PROVISION_CHROME_OS_DEVICE: Pre-provision ChromeOS device
#Description
Event for 'Pre-provision ChromeOS device'.
References #
REMOVE_CHROME_OS_APPLICATION_SETTING: Remove Application Setting
#Description
{APP_TYPE} app {APP_ID} for session type {CHROME_OS_SESSION_TYPE} removed
References #
REMOVE_CHROME_OS_APPLICATION_SETTINGS: Remove Chrome Application Settings
#Description
Settings for Chrome app {APP_ID} removed
References #
REMOVE_CHROME_OS_WEB_ORIGIN_SETTINGS: Remove Web Origin Settings
#Description
Settings for web origin {WEB_ORIGIN} for session type {CHROME_OS_SESSION_TYPE} removed
References #
REPAIR_CENTER_DEPROVISION: Repair Center deprovision
#Description
Event for 'Repair Center deprovision'.
References #
REVOKE_CHROME_OS_ENROLLMENT_TOKEN: Revoke ChromeOS enrollment token
#Description
Event for 'Revoke ChromeOS enrollment token'.
References #
CHANGE_CHROME_OS_WEB_APPLICATION_SETTING: Web Application Setting Change
#Description
{SETTING_NAME} for Web app {APP_ID} for session type {CHROME_OS_SESSION_TYPE} changed from {OLD_VALUE} to {NEW_VALUE}
References #
CHANGE_CHROME_OS_WEB_PERMISSION_SETTING: Web Permission Setting Change
#Description
{SETTING_NAME} for {WEB_ORIGIN} for session type {CHROME_OS_SESSION_TYPE} changed from {OLD_VALUE} to {NEW_VALUE}
References #
CONTACTS_SETTINGS: Contacts Settings
#Description
Events of this type are returned with type=CONTACTS_SETTINGS .
References #
CHANGE_CONTACTS_SETTING: Contacts Setting Change
#Description
{SETTING_NAME} for contacts service changed from {OLD_VALUE} to {NEW_VALUE}
References #
DOCS_SETTINGS: Drive Settings
#Description
Events of this type are returned with type=DOCS_SETTINGS .
References #
TRANSFER_DOCUMENT_OWNERSHIP: Document Ownership Change
#Description
Owner of documents changed from {USER_EMAIL} to {NEW_VALUE}
References #
DOCS_ORG_BRANDING_PROVISIONING: Drive and Docs org branding provisioning initiated
#Description
Organizational branding provisioning initiated for account {SERVICE_ACCOUNT_EMAIL} and shared drive {SHARED_DRIVE_NAME} with status {ORG_BRANDING_PROVISIONING_STATUS}
References #
DOCS_ORG_BRANDING_UPLOAD: Drive and Docs org branding upload attempt
#Description
Organizational branding document upload attempted for document {DOCUMENT_ID} in editor {ORG_BRANDING_EDITOR_TYPE} with status {ORG_BRANDING_UPLOAD_STATUS}
References #
DRIVE_DATA_RESTORE: Drive Data Restore
#Description
Drive data restoration initiated for {USER_EMAIL}
References #
CHANGE_DOCS_SETTING: Drive Setting Change
#Description
{SETTING_NAME} for Drive changed from {OLD_VALUE} to {NEW_VALUE}
References #
DOMAIN_SETTINGS: Domain Settings
#Description
Events of this type are returned with type=DOMAIN_SETTINGS .
References #
CHANGE_ACCOUNT_AUTO_RENEWAL: Account Automatic Renewal Change
#Description
Account automatic renewal changed to {NEW_VALUE} on {DOMAIN_NAME}
References #
CHANGE_ADVERTISEMENT_OPTION: Advertisement Option Change
#Description
Advertisement option for your organization changed from {OLD_VALUE} to {NEW_VALUE}
References #
CHANGE_ALERT_CRITERIA: Alert Criteria Change
#Description
Alert criteria for {ALERT_NAME} has been changed
References #
ALERT_RECEIVERS_CHANGED: Alert Receivers Change
#Description
Alert receivers for {ALERT_NAME} changed from {OLD_VALUE} to {NEW_VALUE}
References #
ALERT_STATUS_CHANGED: Alert Status Change
#Description
Alert status for {ALERT_NAME} changed from {OLD_VALUE} to {NEW_VALUE}
References #
ADD_DOMAIN_ALIAS: Alias Creation
#Description
An unverified {DOMAIN_ALIAS} created as an alias of {DOMAIN_NAME}
References #
REMOVE_DOMAIN_ALIAS: Alias Deletion
#Description
{DOMAIN_ALIAS} deleted as an alias of {DOMAIN_NAME}
References #
SKIP_DOMAIN_ALIAS_MX: Alias MX Record Setup Skipped
#Description
Skipped MX record setup of alias {DOMAIN_ALIAS} of domain {DOMAIN_NAME}
References #
VERIFY_DOMAIN_ALIAS_MX: Alias MX Record Verification
#Description
Verified MX record of alias {DOMAIN_ALIAS} of domain {DOMAIN_NAME}
References #
VERIFY_DOMAIN_ALIAS: Alias Verification
#Description
{DOMAIN_ALIAS} verified as an alias of {DOMAIN_NAME} using {DOMAIN_VERIFICATION_METHOD}
References #
TOGGLE_OAUTH_ACCESS_TO_ALL_APIS: All API OAuth Access Change
#Description
OAuth access for all APIs changed to {NEW_VALUE} for your organization
References #
TOGGLE_ALLOW_ADMIN_PASSWORD_RESET: Allow Admin Password Reset
#Description
Allow admin password reset setting changed to {NEW_VALUE}
References #
ENABLE_API_ACCESS: API Access Change
#Description
API access for your organization changed from {OLD_VALUE} to {NEW_VALUE}
References #
REMOVE_API_CLIENT_ACCESS: API Client Access Remove
#Description
API client access to your organization from client {API_CLIENT_NAME} removed
References #
CHROME_LICENSES_REDEEMED: App Licenses Redeemed
#Description
Licenses redeemed event name.
References #
TOGGLE_AUTO_ADD_NEW_SERVICE: Automatic Addition Update
#Description
Automatic addition for new services and pre-release features for your organization changed to {NEW_VALUE}
References #
CHANGE_PRIMARY_DOMAIN: Change Primary Domain Name
#Description
Primary domain name changed from {DOMAIN_NAME} to {NEW_VALUE}
References #
COMMUNICATION_PREFERENCES_SETTING_CHANGE: Communication Preferences Setting Change
#Description
{SETTING_NAME} setting in Communication Preferences changed from {OLD_VALUE} to {NEW_VALUE} (Domain Name : {DOMAIN_NAME} )
References #
CHANGE_CONFLICT_ACCOUNT_ACTION: Conflict Account Action Change
#Description
Conflict account action for {DOMAIN_NAME} changed from {OLD_VALUE} to {NEW_VALUE}
References #
CHANGE_CONFLICT_ACCOUNTS_MANAGEMENT_SETTINGS: Conflict accounts management settings change
#Description
Conflict accounts management setting changed to: {CONFLICT_ACCOUNTS_MANAGEMENT_SETTINGS} .
References #
ENABLE_FEEDBACK_SOLICITATION: Contact for Feedback Setting Change
#Description
Can contact for feedback setting for your organization changed from {OLD_VALUE} to {NEW_VALUE}
References #
TOGGLE_CONTACT_SHARING: Contact Sharing Change
#Description
Contact sharing changed to {NEW_VALUE}
References #
CREATE_PLAY_FOR_WORK_TOKEN: Create MDM vendor enrollment token
#Description
MDM vendor enrollment token ( {PLAY_FOR_WORK_TOKEN_ID} ) created
References #
TOGGLE_USE_CUSTOM_LOGO: Custom Logo Change
#Description
Use custom logo changed to {NEW_VALUE}
References #
CHANGE_CUSTOM_LOGO: Custom Logo Upload
#Description
New custom logo uploaded for your organization
References #
CHANGE_DATA_LOCALIZATION_FOR_RUSSIA: Data Localization For Russian Federation Change
#Description
Setting for Data Localization for Russian Federation changed from {OLD_VALUE} to {NEW_VALUE}
References #
CHANGE_DATA_LOCALIZATION_SETTING: Data Localization Setting Change
#Description
Setting for Data Localization changed from {OLD_VALUE} to {NEW_VALUE}
References #
CHANGE_DATA_PROTECTION_OFFICER_CONTACT_INFO: Data Protection Officer Contact Information Change
#Description
Part of an audit log event for contact info update for Data Protection Officer. This is used as an indicator of what kind of event log this message is.
References #
DELETE_PLAY_FOR_WORK_TOKEN: Delete MDM vendor enrollment token
#Description
MDM vendor enrollment token ( {PLAY_FOR_WORK_TOKEN_ID} ) deleted
References #
VIEW_DNS_LOGIN_DETAILS: DNS console login details viewed
#Description
DNS console login details for {DOMAIN_NAME} viewed
References #
CHANGE_DOMAIN_DEFAULT_LOCALE: Domain Default Locale Change
#Description
Default locale for your organization changed from {OLD_VALUE} to {NEW_VALUE}
References #
CHANGE_DOMAIN_DEFAULT_TIMEZONE: Domain Default Timezone Change
#Description
Default time zone for your organization changed from {OLD_VALUE} to {NEW_VALUE}
References #
CHANGE_DOMAIN_NAME: Domain Name Change
#Description
Change of domain name for {DOMAIN_NAME} to {NEW_VALUE} started
References #
TOGGLE_ENABLE_PRE_RELEASE_FEATURES: Domain Pre-release Setting Change
#Description
Pre-release features for your organization was set to {NEW_VALUE}
References #
CHANGE_DOMAIN_SUPPORT_MESSAGE: Domain Support Message Change
#Description
Support message for your organization changed from {OLD_VALUE} to {NEW_VALUE}
References #
REMOVE_TRUSTED_DOMAINS: Domains removed from Trusted Domains
#Description
Domains {DOMAIN_NAME} removed from Trusted Domains list
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1098↳ also matches ADD_TRUSTED_DOMAINS: Domains added to Trusted Domains
References #
CHANGE_EDU_TYPE: Education Organization Type Change
#Description
Educational organization type changed from {OLD_VALUE} to {NEW_VALUE}
References #
TOGGLE_ENABLE_OAUTH_CONSUMER_KEY: Enable OAuth Consumer Key
#Description
Enabling OAuth consumer key changed to {NEW_VALUE} for your organization
References #
TOGGLE_SSL: Enforce SSL Change
#Description
SSL Enforcement changed to {NEW_VALUE} for {DOMAIN_NAME}
References #
CHANGE_EU_REPRESENTATIVE_CONTACT_INFO: EU Representative Contact Information Change
#Description
Part of an audit log event for contact info update for EU Representative. This is used as an indicator of what kind of event log this message is.
References #
CHANGE_LOGIN_BACKGROUND_COLOR: Login Background Color Change
#Description
Login background color for your organization changed from {OLD_VALUE} to {NEW_VALUE}
References #
CHANGE_LOGIN_BORDER_COLOR: Login Border Color Change
#Description
Login border color for your organization changed from {OLD_VALUE} to {NEW_VALUE}
References #
CHANGE_LOGIN_ACTIVITY_TRACE: Marketplace Login Audit Change
#Description
Marketplace Login audit setting in {DOMAIN_NAME} changed from {OLD_VALUE} to {NEW_VALUE}
References #
PLAY_FOR_WORK_ENROLL: MDM vendor enrollment
#Description
Enrolled for {PLAY_FOR_WORK_MDM_VENDOR_NAME} mobile device management services using token ( {PLAY_FOR_WORK_TOKEN_ID} )
References #
PLAY_FOR_WORK_UNENROLL: MDM vendor unenrollment
#Description
Unenrolled from {PLAY_FOR_WORK_MDM_VENDOR_NAME} mobile device management services
References #
MX_RECORD_VERIFICATION_CLAIM: MX Record Verification Claim
#Description
{USER_EMAIL} claimed to verify the MX record for {DOMAIN_NAME}
References #
TOGGLE_NEW_APP_FEATURES: New App Features Update
#Description
New app features for your organization changed to {NEW_VALUE}
References #
TOGGLE_USE_NEXT_GEN_CONTROL_PANEL: Next Generation CPanel Setting Change
#Description
The setting to enable the new Admin Console changed to {NEW_VALUE} for your organization
References #
UPLOAD_OAUTH_CERTIFICATE: OAuth Certificate Upload
#Description
New OAuth certificate uploaded for your organization
References #
REGENERATE_OAUTH_CONSUMER_SECRET: OAuth Consumer Secret Regenerate
#Description
New OAuth consumer secret generated for your organization
References #
TOGGLE_OPEN_ID_ENABLED: OpenId Change
#Description
OpenId federated login for {DOMAIN_NAME} changed to {NEW_VALUE}
References #
CHANGE_ORGANIZATION_NAME: Organization Name Change
#Description
Organization name changed from {OLD_VALUE} to {NEW_VALUE}
References #
CHANGE_PASSWORD_MAX_LENGTH: Password Maximum Length Change
#Description
Password maximum length for {DOMAIN_NAME} changed from {OLD_VALUE} to {NEW_VALUE}
References #
CHANGE_PASSWORD_MIN_LENGTH: Password Minimum Length Change
#Description
Password minimum length for {DOMAIN_NAME} changed from {OLD_VALUE} to {NEW_VALUE}
References #
UPDATE_DOMAIN_PRIMARY_ADMIN_EMAIL: Primary Admin Change
#Description
Primary admin for your organization changed from {OLD_VALUE} to {NEW_VALUE}
References #
ENABLE_SERVICE_OR_FEATURE_NOTIFICATIONS: Receive Email Notification Setting Change
#Description
Receive email notification setting for your organization changed from {OLD_VALUE} to {NEW_VALUE}
References #
CHANGE_RENEW_DOMAIN_REGISTRATION: Renew Domain Registration Setting Change
#Description
Renew domain registration setting in {DOMAIN_NAME} changed from {OLD_VALUE} to {NEW_VALUE}
References #
CHANGE_RESELLER_ACCESS: Reseller Access Change
#Description
Reseller access changed from {OLD_VALUE} to {NEW_VALUE}
References #
CHANGE_RESELLER_ACCESS_FOR_SKU: Reseller Access Change for SKU
#Description
Reseller access for {SKU_NAME} changed from {OLD_VALUE} to {NEW_VALUE}
References #
RULE_ACTIONS_CHANGED: Rule Actions Change
#Description
Rule actions for {RULE_NAME} changed
References #
CHANGE_RULE_CRITERIA: Rule Criteria Change
#Description
Rule criteria for {RULE_NAME} has been changed
References #
RULE_STATUS_CHANGED: Rule Status Change
#Description
Rule status for {RULE_NAME} changed from {OLD_VALUE} to {NEW_VALUE}
References #
REMOVE_SECONDARY_DOMAIN: Secondary Domain Deletion
#Description
{SECONDARY_DOMAIN_NAME} deleted as a secondary domain of {DOMAIN_NAME}
References #
SKIP_SECONDARY_DOMAIN_MX: Secondary Domain MX Record Setup Skipped
#Description
Skipped MX record setup of secondary domain {SECONDARY_DOMAIN_NAME} of domain {DOMAIN_NAME}
References #
VERIFY_SECONDARY_DOMAIN_MX: Secondary Domain MX Verification
#Description
Verified MX records of secondary domain {SECONDARY_DOMAIN_NAME} of domain {DOMAIN_NAME}
References #
VERIFY_SECONDARY_DOMAIN: Secondary Domain Verification
#Description
{SECONDARY_DOMAIN_NAME} verified as a secondary domain of {DOMAIN_NAME}
References #
UPDATE_DOMAIN_SECONDARY_EMAIL: Secondary Email Change
#Description
Secondary email for your organization changed from {OLD_VALUE} to {NEW_VALUE}
References #
EMAIL_SETTINGS: Email Settings
#Description
Events of this type are returned with type=EMAIL_SETTINGS .
References #
DROP_FROM_QUARANTINE: Drop from Quarantine
#Description
The title for the event release from quarantine. This title shows the message was dropped from quarantine.
References #
EMAIL_LIFE_OF_A_MESSAGE: Email life of a message search
#Description
Email life of a message search is launched.
References #
EMAIL_LOG_SEARCH: Email Log Search
#Description
An email log search is performed for logs from {EMAIL_LOG_SEARCH_START_DATE} to {EMAIL_LOG_SEARCH_END_DATE} with a sender of [ {EMAIL_LOG_SEARCH_SENDER} ], a recipient of [ {EMAIL_LOG_SEARCH_RECIPIENT} ], and an email message id of [ {EMAIL_LOG_SEARCH_MSG_ID} ]
References #
EMAIL_UNDELETE: Email Restore
#Description
Email restoration from {START_DATE} to {END_DATE} initiated for {USER_EMAIL}
References #
CHANGE_EMAIL_SETTING: Email Setting Change
#Description
{SETTING_NAME} for email service in your organization changed from {OLD_VALUE} to {NEW_VALUE}
References #
DELETE_GMAIL_SETTING: Gmail Setting Deletion
#Description
Gmail setting {SETTING_NAME} was deleted
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1098↳ also matches CHANGE_GMAIL_SETTING: Gmail Setting Change, CREATE_GMAIL_SETTING: Gmail Setting Creation
References #
REJECT_FROM_QUARANTINE: Reject from Quarantine
#Description
The title for the event release from quarantine. This title shows the message was rejected from quarantine.
References #
RELEASE_FROM_QUARANTINE: Release from Quarantine
#Description
The title for the event release from quarantine. This title shows the message was released from quarantine.
References #
GROUP_SETTINGS: Group Settings
#Description
Events of this type are returned with type=GROUP_SETTINGS .
References #
WHITELISTED_GROUPS_UPDATED: Filtering groups updated
#Description
Whitelisted groups updated event.
References #
CHANGE_GROUP_DESCRIPTION: Group Description Change
#Description
Description for group {GROUP_EMAIL} changed
References #
CHANGE_GROUP_EMAIL: Group Email Change
#Description
Email of group {GROUP_EMAIL} changed to {NEW_VALUE}
References #
GROUP_LIST_DOWNLOAD: Group List Download
#Description
Group list was downloaded as a CSV file
References #
REMOVE_GROUP_MEMBER: Group Member Deletion
#Description
User {USER_EMAIL} deleted from group {GROUP_EMAIL}
References #
UPDATE_GROUP_MEMBER_DELIVERY_SETTINGS: Group Member Update
#Description
Group Member Delivery Settings Change.
References #
UPDATE_GROUP_MEMBER_DELIVERY_SETTINGS_CAN_EMAIL_OVERRIDE: Group Member Update
#Description
Group Member Delivery Settings Email Override Change.
References #
GROUP_MEMBER_BULK_UPLOAD: Group Members Bulk Upload
#Description
A total of {GROUP_MEMBER_BULK_UPLOAD_TOTAL_NUMBER} members selected for upload. {GROUP_MEMBER_BULK_UPLOAD_FAILED_NUMBER} out of {GROUP_MEMBER_BULK_UPLOAD_TOTAL_NUMBER} members failed to be uploaded
References #
GROUP_MEMBERS_DOWNLOAD: Group Members Download
#Description
Group member list was downloaded as a CSV file
References #
CHANGE_GROUP_NAME: Group Name Change
#Description
Name of group {GROUP_EMAIL} changed to {NEW_VALUE}
References #
LICENSES_SETTINGS: Licenses Settings
#Description
Events of this type are returned with type=LICENSES_SETTINGS .
References #
CHROME_APP_LICENSES_ENABLED: App License Policy Setting Changed
#Description
Licenses enabled or not for a specified group/org unit event name.
References #
ORG_USERS_LICENSE_ASSIGNMENT: Assign Licenses to All Unassigned Users
#Description
Licenses for {PRODUCT_NAME} product and {NEW_VALUE} sku were assigned to all unassigned users of {ORG_UNIT_NAME}
References #
ORG_ALL_USERS_LICENSE_ASSIGNMENT: Assign Licenses to All Users
#Description
Licenses for {PRODUCT_NAME} product and {NEW_VALUE} sku were assigned to all users of {ORG_UNIT_NAME}
References #
SUPPRESSED_LICENSE_ASSIGNMENT: Assign Suppressed License
#Description
A suppressed license for {PRODUCT_NAME} product and {NEW_VALUE} sku was assigned to the user {USER_EMAIL}
References #
TEMPORARY_LICENSE_ASSIGNMENT: Assign Temporary License
#Description
A temporary license for {PRODUCT_NAME} product and {NEW_VALUE} sku was assigned to the user {USER_EMAIL}
References #
USER_LICENSE_ASSIGNMENT: Assign User License
#Description
A license for {PRODUCT_NAME} product and {NEW_VALUE} sku was assigned to the user {USER_EMAIL}
References #
CHANGE_LICENSE_AUTO_ASSIGN: Auto Assign Licenses
#Description
License Auto Assign option changed to {NEW_VALUE} for {PRODUCT_NAME} product and {SKU_NAME} sku
References #
SUPPRESSED_TO_ASSIGNED_LICENSE_CONVERSION: Convert user's Suppressed License to Active
#Description
Suppressed license of the user {USER_EMAIL} for {PRODUCT_NAME} product and {NEW_VALUE} sku was converted to Active
References #
TEMPORARY_TO_ASSIGNED_LICENSE_CONVERSION: Convert user's Temporary License to Active
#Description
Temporary license of the user {USER_EMAIL} for {PRODUCT_NAME} product and {NEW_VALUE} sku was converted to Active
References #
TEMPORARY_TO_SUPPRESSED_LICENSE_CONVERSION: Convert user's Temporary License to Suppressed
#Description
Temporary license of the user {USER_EMAIL} for {PRODUCT_NAME} product and {NEW_VALUE} sku was expired and converted to Suppressed
References #
FIRST_TEMPORARY_OR_SUPPRESSED_LICENSE_NOTIFICATION: First Temporary or Suppressed License Email Sent
#Description
Audit log event generated when first temporary or suppressed license email notification is sent to the customer.
References #
RESELLER_FIRST_TEMPORARY_OR_SUPPRESSED_LICENSE_NOTIFICATION: First Temporary or Suppressed License Email Sent for a User
#Description
Audit log event generated when first temporary or suppressed license email notification is sent to the reseller.
References #
USER_LICENSE_REASSIGNMENT: Reassign User License
#Description
A license for {PRODUCT_NAME} product and {OLD_VALUE} sku was reassigned for user {USER_EMAIL} to new sku {NEW_VALUE}
References #
ORG_LICENSE_REVOKE: Revoke Licenses to All Users
#Description
Licenses for {PRODUCT_NAME} product and {OLD_VALUE} sku were removed from assigned users of {ORG_UNIT_NAME}
References #
SUPPRESSED_LICENSE_REVOKE: Revoke Suppressed License
#Description
A suppressed license for {PRODUCT_NAME} product and {OLD_VALUE} sku was revoked from the user {USER_EMAIL}
References #
TEMPORARY_LICENSE_REVOKE: Revoke Temporary License
#Description
A temporary license for {PRODUCT_NAME} product and {OLD_VALUE} sku was revoked from the user {USER_EMAIL}
References #
USER_LICENSE_REVOKE: Revoke User License
#Description
A license for {PRODUCT_NAME} product and {OLD_VALUE} sku was revoked from user {USER_EMAIL}
References #
TEMPORARY_LICENSES_EXPIRED_NOTIFICATION: Temporary Licenses Expiration Email Notification Sent
#Description
Audit log event generated when temporary licenses expired email notification is sent to the customer.
References #
UPDATE_DYNAMIC_LICENSE: Update Auto Licensing
#Description
Auto Licensing settings for {PRODUCT_NAME} product in {ORG_UNIT_NAME} organization changed from {OLD_VALUE} to {NEW_VALUE}
References #
CHROME_APP_USER_LICENSE_ASSIGNED: User license is assigned
#Description
Short description to indicate user license is assigned.
References #
CHROME_APP_USER_LICENSE_REVOKED: User license is revoked
#Description
Short description to indicate user license is revoked.
References #
MOBILE_SETTINGS: Mobile Settings
#Description
Events of this type are returned with type=MOBILE_SETTINGS .
References #
ACTION_CANCELLED: Action Cancelled On Device
#Description
{ACTION_TYPE} with id {ACTION_ID} on device type {DEVICE_TYPE} and id {DEVICE_ID} was cancelled by user {USER_EMAIL}
References #
ACTION_REQUESTED: Action Requested On Device
#Description
{ACTION_TYPE} with id {ACTION_ID} on device type {DEVICE_TYPE} and id {DEVICE_ID} was requested by user {USER_EMAIL}
References #
ADD_MOBILE_CERTIFICATE: Add Mobile certificate
#Description
Mobile certificate {MOBILE_CERTIFICATE_COMMON_NAME} added for mobile devices in your organization
References #
APPLE_DEP_SYNC_TRIGGERED: Apple DEP sync triggered by admin
#Description
Apple DEP sync triggered by {USER_EMAIL}
References #
APPLE_DEP_TOKEN_SETUP_COMPLETE: Apple DEP token setup complete for customer
#Description
Apple Device Enrollment tokens updated by {USER_EMAIL}
References #
APPLE_VPP_TOKEN_OPERATION: Apple VPP token operation
#Description
Apple VPP token {TOKEN_OPERATION_NAME} was {TOKEN_OPERATION_STATUS}
References #
COMPANY_DEVICES_BULK_CREATION: Bulk import of company owned devices
#Description
Details of {NUMBER_OF_COMPANY_OWNED_DEVICES} company owned device(s) were imported
References #
COMPANY_OWNED_DEVICE_BLOCKED: Company owned device blocked
#Description
Company owned device {COMPANY_DEVICE_ID} was blocked
References #
COMPANY_DEVICE_DELETION: Company owned device deleted
#Description
Company owned device {COMPANY_DEVICE_ID} was deleted
References #
COMPANY_OWNED_DEVICE_UNBLOCKED: Company owned device unblocked
#Description
Company owned device {COMPANY_DEVICE_ID} was unblocked
References #
COMPANY_OWNED_DEVICE_WIPED: Company owned device wiped
#Description
Company owned device {COMPANY_DEVICE_ID} was wiped
References #
CUSTOMER_USER_DEVICE_DELETION_EVENT: Customer user device deleted
#Description
Customer user device {COMPANY_DEVICE_ID} was deleted
References #
CHANGE_MOBILE_APPLICATION_PERMISSION_GRANT: Mobile application permission grant change
#Description
Change in mobile application permission grant.
References #
CHANGE_MOBILE_APPLICATION_PRIORITY_ORDER: Mobile application priority order change
#Description
Change in priority order of mobile application.
References #
REMOVE_MOBILE_APPLICATION_FROM_WHITELIST: Mobile application removed from whitelist
#Description
{DEVICE_TYPE} application {MOBILE_APP_PACKAGE_ID} is no longer whitelisted for {DISTRIBUTION_ENTITY_NAME} {DISTRIBUTION_ENTITY_TYPE}
References #
CHANGE_MOBILE_APPLICATION_SETTINGS: Mobile application setting change
#Description
Change in mobile application setting.
References #
ADD_MOBILE_APPLICATION_TO_WHITELIST: Mobile application whitelisted
#Description
Mobile application is added to whitelist.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
References #
MOBILE_DEVICE_APPROVE: Mobile Device Approve
#Description
Mobile device for {USER_EMAIL} approved
References #
MOBILE_DEVICE_BLOCK: Mobile Device Block
#Description
Mobile device for {USER_EMAIL} blocked
References #
MOBILE_DEVICE_DELETE: Mobile Device Deletion
#Description
Mobile device for {USER_EMAIL} deleted
References #
CHANGE_MOBILE_SETTING: Mobile Setting Change
#Description
{SETTING_NAME} for mobile devices in your organization changed from {OLD_VALUE} to {NEW_VALUE}
References #
CHANGE_ADMIN_RESTRICTIONS_PIN: Mobile Setting Change: Administrator Restrictions Pin
#Description
Administrator restrictions PIN for mobile devices in your organization changed
References #
CHANGE_MOBILE_WIRELESS_NETWORK: Mobile Wireless Network Change
#Description
Mobile wireless network {MOBILE_WIRELESS_NETWORK_NAME} changed for mobile devices in your organization
References #
ADD_MOBILE_WIRELESS_NETWORK: Mobile Wireless Network Creation
#Description
Mobile wireless network {MOBILE_WIRELESS_NETWORK_NAME} created for mobile devices in your organization
References #
REMOVE_MOBILE_WIRELESS_NETWORK: Mobile Wireless Network Deletion
#Description
Mobile wireless network {MOBILE_WIRELESS_NETWORK_NAME} deleted for mobile devices in your organization
References #
CHANGE_MOBILE_WIRELESS_NETWORK_PASSWORD: Mobile Wireless Network Password Change
#Description
Password changed for mobile wireless network {MOBILE_WIRELESS_NETWORK_NAME} in your organization
References #
REMOVE_MOBILE_CERTIFICATE: Remove Mobile certificate
#Description
Mobile certificate {MOBILE_CERTIFICATE_COMMON_NAME} removed for mobile devices in your organization
References #
ENROLL_FOR_GOOGLE_DEVICE_MANAGEMENT: Use Google Device Management
#Description
Google Device Management is a part of the Google Admin console.
References #
USE_GOOGLE_MOBILE_MANAGEMENT: Use Google Mobile Management
#Description
You have selected Google Mobile Management to manage all your mobile devices
References #
USE_GOOGLE_MOBILE_MANAGEMENT_FOR_NON_IOS: Use Google Mobile Management for Android and Active Sync devices
#Description
You have selected Google Mobile Management to manage your Android and Active Sync devices
References #
USE_GOOGLE_MOBILE_MANAGEMENT_FOR_IOS: Use Google Mobile Management for iOS devices
#Description
You have selected Google Mobile Management to manage your iOS devices
References #
MOBILE_ACCOUNT_WIPE: Wipe Mobile Account
#Description
Mobile account for {USER_EMAIL} has been wiped
References #
MOBILE_DEVICE_CANCEL_WIPE_THEN_APPROVE: Wipe On Mobile Cancel And Approve Device
#Description
Wipe on mobile device for {USER_EMAIL} was cancelled and the device was approved
References #
MOBILE_DEVICE_CANCEL_WIPE_THEN_BLOCK: Wipe On Mobile Cancel And Block Device
#Description
Wipe on mobile device for {USER_EMAIL} was cancelled and the device has been blocked
References #
ORG_SETTINGS: Organization Settings
#Description
Events of this type are returned with type=ORG_SETTINGS .
References #
CHROME_LICENSES_ENABLED: App License Policy Changed
#Description
Licenses enabled or not at an org unit event name.
References #
CHROME_APPLICATION_LICENSE_RESERVATION_CREATED: App License Reservation Created
#Description
License reservation at an org unit is created.
References #
CHROME_APPLICATION_LICENSE_RESERVATION_DELETED: App License Reservation Deleted
#Description
License reservation at an org unit is deleted.
References #
CHROME_APPLICATION_LICENSE_RESERVATION_UPDATED: App License Reservation Updated
#Description
License reservation at an org unit is updated.
References #
CREATE_DEVICE_ENROLLMENT_TOKEN: Create enrollment token
#Description
Event for 'Create enrollment token'.
References #
ASSIGN_CUSTOM_LOGO: Custom Logo Assign
#Description
New custom logo assigned for org unit {ORG_UNIT_NAME}
References #
UNASSIGN_CUSTOM_LOGO: Custom Logo Unassign
#Description
Custom logo unassigned for org unit {ORG_UNIT_NAME}
References #
CREATE_ENROLLMENT_TOKEN: Enrollment Token Creation
#Description
A new enrollment token is generated for {ORG_UNIT_NAME}
References #
REVOKE_ENROLLMENT_TOKEN: Enrollment Token Revocation
#Description
The enrollment token of {ORG_UNIT_NAME} has been revoked
References #
EDIT_ORG_UNIT_DESCRIPTION: OrgUnit Description Change
#Description
Description of {ORG_UNIT_NAME} changed
References #
EDIT_ORG_UNIT_NAME: OrgUnit Name Change
#Description
Name of {ORG_UNIT_NAME} changed to {NEW_VALUE}
References #
REVOKE_DEVICE_ENROLLMENT_TOKEN: Revoke enrollment token
#Description
Event for 'Revoke enrollment token'.
References #
TOGGLE_SERVICE_ENABLED: Service Change
#Description
Service {SERVICE_NAME} changed to {NEW_VALUE} for {ORG_UNIT_NAME} organizational unit in your organization
References #
SECURITY_SETTINGS: Security Settings
#Description
Events of this type are returned with type=SECURITY_SETTINGS .
References #
CHANGE_CAA_APP_ASSIGNMENTS: (Context-aware access) Access level assignment changed for an app
#Description
For {TARGET_ENTITY_TYPE} [ {TARGET_ENTITY_NAME} ]: Before: Access level [ {CAA_ACCESS_ASSIGNMENTS_OLD} ] applied to {CAA_ENFORCEMENT_ENDPOINTS_OLD} of [ {APPLICATION_NAME} ] in [ {MODE} ] mode. After: Access level [ {CAA_ACCESS_ASSIGNMENTS_NEW} ] applied to {CAA_ENFORCEMENT_ENDPOINTS_NEW} of [ {APPLICATION_NAME} ] in [ {MODE} ] mode.
References #
UNDERAGE_BLOCK_ALL_THIRD_PARTY_API_ACCESS: All access to unconfigured third-party apps blocked for users under 18
#Description
All third party API access blocked for users under 18.
References #
UNDERAGE_SIGN_IN_ONLY_THIRD_PARTY_API_ACCESS: Allow Google Sign-in only access to unconfigured third-party apps for users under 18
#Description
Allow Google Sign-in only third party API access for users under 18.
References #
SIGN_IN_ONLY_THIRD_PARTY_API_ACCESS: Allow Google Sign-in only third party API access
#CHANGE_APP_ACCESS_SETTINGS_COLLECTION_ID: app access settings collection id change.
#Description
App Access Settings Collection for the org unit {ORG_UNIT_NAME} has changed from {OLD_VALUE} to {NEW_VALUE}
References #
ADD_TO_LIMITED_OAUTH2_APPS: App added to Limited list
#Description
{OAUTH2_APP_NAME} added to Limited list for {ORG_UNIT_NAME}
References #
ADD_TO_TRUSTED_BY_OAUTH_SCOPE_OAUTH2_APPS: App added to Trusted by OAuth Scope list
#Description
{OAUTH2_APP_NAME} added to trusted by OAuth scope list for {ORG_UNIT_NAME}
References #
ADD_TO_CAA_EXEMPT_OAUTH2_APPS: App allowlisted for exemption from API access blocks
#Description
{OAUTH2_APP_NAME} allowlisted for exemption from API access blocks for {ORG_UNIT_NAME}
References #
REMOVE_FROM_CAA_EXEMPT_OAUTH2_APPS: App no longer allowlisted for exemption from API access blocks
#Description
{OAUTH2_APP_NAME} removed from allowlist for exemption from API access blocks for {ORG_UNIT_NAME}
References #
REMOVE_FROM_LIMITED_OAUTH2_APPS: App removed from Limited list
#Description
{OAUTH2_APP_NAME} removed from Limited list for {ORG_UNIT_NAME}
References #
REMOVE_FROM_TRUSTED_BY_OAUTH_SCOPE_OAUTH2_APPS: App removed from Trusted by OAuth Scope list
#Description
{OAUTH2_APP_NAME} removed from trusted by OAuth scope list for {ORG_UNIT_NAME}
References #
MULTIPLE_ADD_TO_BLOCKED_OAUTH2_APPS: Apps added to Blocked list
#Description
{OAUTH2_NUM_APPS} apps added to Blocked list for {ORG_UNIT_NAME}
References #
MULTIPLE_ADD_TO_LIMITED_OAUTH2_APPS: Apps added to Limited list
#Description
{OAUTH2_NUM_APPS} apps added to Limited list for {ORG_UNIT_NAME}
References #
MULTIPLE_ADD_TO_TRUSTED_BY_OAUTH_SCOPE_OAUTH2_APPS: Apps added to Trusted by OAuth Scope list
#Description
{OAUTH2_NUM_APPS} apps added to Trusted by OAuth Scope list for {ORG_UNIT_NAME}
References #
MULTIPLE_ADD_TO_TRUSTED_OAUTH2_APPS: Apps added to Trusted list
#Description
{OAUTH2_NUM_APPS} apps added to Trusted list for {ORG_UNIT_NAME}
References #
OAUTH_APPS_BULK_UPLOAD: Apps lists bulk upload
#Description
{BULK_UPLOAD_SUCCESS_OAUTH_APPS_NUMBER} of {BULK_UPLOAD_TOTAL_OAUTH_APPS_NUMBER} rows successfully uploaded
References #
OAUTH_APPS_BULK_UPLOAD_NOTIFICATION_SENT: Apps lists bulk upload notification
#Description
Notification of bulk upload for apps list sent to {USER_EMAIL}
References #
BLOCK_ON_DEVICE_ACCESS: Block On Device Access
#Description
Summary message to display in the audit log when device access for OAuth2 apps is blocked.
References #
CHANGE_TWO_STEP_VERIFICATION_FREQUENCY: Change 2-Step Verification Frequency
#Description
2-step verification frequency for {ORG_UNIT_NAME} changed from {OLD_VALUE} to {NEW_VALUE}
References #
CHANGE_TWO_STEP_VERIFICATION_GRACE_PERIOD_DURATION: Change 2-Step Verification Grace Period Duration
#Description
2-step verification grace period duration for {ORG_UNIT_NAME} changed from {OLD_VALUE} to {NEW_VALUE}
References #
CHANGE_TWO_STEP_VERIFICATION_START_DATE: Change 2-Step Verification Start Date
#Description
2-step verification start date has been changed from {OLD_VALUE} to {NEW_VALUE}
References #
CHANGE_CAA_ERROR_MESSAGE: Context Aware Access Error Message Change
#Description
Error message has been changed to [ {NEW_VALUE} ]. (OrgUnit Name: {ORG_UNIT_NAME} )
References #
TOGGLE_CAA_REMEDIATION_ENABLEMENT: Context Aware Access Remediation Enablement
#Description
Context Aware Access Remediation has been {NEW_VALUE} . (OrgUnit Name: {ORG_UNIT_NAME} )
References #
EDU_OVER_18_APPROVAL_WORKFLOW_DISABLED: Disabled Edu over 18 users apps requests
#Description
Disabled Edu over 18 users apps requests for {ORG_UNIT_NAME}
References #
EDU_DELEGATED_USER_APPROVAL_WORKFLOW_DISABLED: Disabled over 18 users making delegated apps requests
#Description
Disabled over 18 users making delegated apps requests for {ORG_UNIT_NAME}
References #
UNDERAGE_USER_APPROVAL_WORKFLOW_DISABLED: Disabled under 18 users apps requests
#Description
Disabled under 18 users apps requests for {ORG_UNIT_NAME}
References #
USER_APPROVAL_WORKFLOW_DISABLED: Disabled users over 18 to make apps requests
#Description
Disabled users over 18 to make apps requests for {ORG_UNIT_NAME}
References #
UNTRUST_DOMAIN_OWNED_OAUTH2_APPS: Domain Owned Apps not trusted
#Description
Domain Owned Apps removed from trusted list
References #
TRUST_DOMAIN_OWNED_OAUTH2_APPS: Domain Owned Apps trusted
#Description
Domain Owned Apps added to trusted list
References #
ENABLE_NON_ADMIN_USER_PASSWORD_RECOVERY: Enable Non-Admin User Password Recovery
#Description
Enable non-admin user password recovery setting in {ORG_UNIT_NAME} organization changed from {OLD_VALUE} to {NEW_VALUE}
References #
EDU_OVER_18_APPROVAL_WORKFLOW_ENABLED: Enabled Edu over 18 users apps requests
#Description
Enabled Edu over 18 users apps requests for {ORG_UNIT_NAME}
References #
EDU_DELEGATED_USER_APPROVAL_WORKFLOW_ENABLED: Enabled over 18 users making delegated apps requests
#Description
Enabled over 18 users making delegated apps requests for {ORG_UNIT_NAME}
References #
UNDERAGE_USER_APPROVAL_WORKFLOW_ENABLED: Enabled under 18 users apps requests
#Description
Enabled under 18 users apps requests for {ORG_UNIT_NAME}
References #
USER_APPROVAL_WORKFLOW_ENABLED: Enabled users over 18 to make apps requests
#Description
Enabled users over 18 to make apps requests for {ORG_UNIT_NAME}
References #
UPDATE_ERROR_MSG_FOR_RESTRICTED_OAUTH2_APPS: Error message for restricted OAuth2 apps updated
#Description
Summary message to display in the audit log for Oauth2 scope management settings.
References #
CHANGE_SESSION_LENGTH: Session length changed
#Description
Session length has been changed from {OLD_VALUE} to {NEW_VALUE}
References #
UNBLOCK_ON_DEVICE_ACCESS: Unblock on Device Access
#Description
Summary message to display in the audit log when device access for OAuth2 apps is unblocked.
References #
DOWNLOAD_PENDING_APP_USER_REQUESTS: Users requesting access list download
#Description
Downloaded list of users requesting access to {OAUTH2_APP_NAME}
References #
SITES_SETTINGS: Sites Settings
#Description
Events of this type are returned with type=SITES_SETTINGS .
References #
ADD_WEB_ADDRESS: Add Web Address
#Description
Event gets triggered when a web address is added via cpanel.
References #
DELETE_WEB_ADDRESS: Delete Web Address
#Description
Event gets triggered when a web address is deleted via cpanel.
References #
CHANGE_SITES_WEB_ADDRESS_MAPPING_UPDATES: Sites web address mapping change
#Description
Sites web address mapping update.
References #
VIEW_SITE_DETAILS: Viewed Google Site details
#Description
Admin viewed the site details of {SITE_NAME}
References #
USER_SETTINGS: User Settings
#Description
Events of this type are returned with type=USER_SETTINGS .
References #
DELETE_2SV_SCRATCH_CODES: 2-step Verification Scratch Codes Deletion
#Description
2-step verification scratch codes of the user {USER_EMAIL} deleted
References #
GENERATE_2SV_SCRATCH_CODES: 2-step Verification Scratch Codes Generate
#Description
New 2-step verification scratch codes generated for the user {USER_EMAIL}
References #
REVOKE_3LO_DEVICE_TOKENS: 3-legged OAuth Device Tokens Revoke
#Description
3-legged OAuth tokens issued by user {USER_EMAIL} for the device type {DEVICE_TYPE} and id {DEVICE_ID} were revoked
References #
ACCEPT_USER_INVITATION: Accept User Invite
#Description
User invitation accepted for user: {USER_EMAIL}
References #
TOGGLE_AUTOMATIC_CONTACT_SHARING: Automatic Contact Share Change
#Description
Automatic contact sharing for {USER_EMAIL} changed to {NEW_VALUE}
References #
BULK_UPLOAD: Bulk Upload
#Description
{BULK_UPLOAD_TOTAL_USERS_NUMBER} users selected for upload to your organization. {BULK_UPLOAD_FAIL_USERS_NUMBER} out of {BULK_UPLOAD_TOTAL_USERS_NUMBER} users were not uploaded.
References #
BULK_UPLOAD_NOTIFICATION_SENT: Bulk Upload Notification
#Description
Notification of bulk users upload sent to {USER_EMAIL}
References #
CHANGE_USER_CUSTOM_FIELD: Change Custom Attribute
#Description
{USER_CUSTOM_FIELD} changed for {USER_EMAIL} from {OLD_VALUE} to {NEW_VALUE}
References #
CHANGE_USER_EXTERNAL_ID: Change External Id
#Description
External Ids changed for {USER_EMAIL} from {OLD_VALUE} to {NEW_VALUE}
References #
CHANGE_USER_GENDER: Change Gender
#Description
Change here is a verb. The genders will be customizable, so this should be broader than male vs female.
References #
CHANGE_USER_IM: Change IM
#Description
IMs changed for {USER_EMAIL} from {OLD_VALUE} to {NEW_VALUE}
References #
ENABLE_USER_IP_WHITELIST: Change IP Whitelist
#Description
IP whitelist changed for {USER_EMAIL} from {OLD_VALUE} to {NEW_VALUE}
References #
CHANGE_USER_KEYWORD: Change Keyword
#Description
Keywords are used on user profiles to help identify a user in searches. Example: find person with name 'Larry' and school 'Stanford'. 'Change' is a verb.
References #
CHANGE_USER_LANGUAGE: Change Language
#Description
Can be a predefined set of more common languages provided by Google or a custom language. 'Change' here is a verb.
References #
CHANGE_USER_LOCATION: Change Location
#Description
Location is different from address in the following ways: (1) Location can be fuzzy. Example: Near Seattle. (2) Hovercards and other short user summaries display location, not address. 'Change' is a verb.
References #
CHANGE_USER_ORGANIZATION: Change Organization
#Description
Organizations changed for {USER_EMAIL} from {OLD_VALUE} to {NEW_VALUE}
References #
CHANGE_USER_PHONE_NUMBER: Change Phone Numbers
#Description
Phone Numbers changed for {USER_EMAIL} from {OLD_VALUE} to {NEW_VALUE}
References #
CHANGE_RECOVERY_EMAIL: Change Recovery Email
#Description
Recovery email changed for {USER_EMAIL}
References #
CHANGE_RECOVERY_PHONE: Change Recovery Phone
#Description
Recovery phone changed for {USER_EMAIL}
References #
CHANGE_USER_RELATION: Change Relation
#Description
Relations changed for {USER_EMAIL} from {OLD_VALUE} to {NEW_VALUE}
References #
CHANGE_USER_ADDRESS: Change User Address
#Description
Addresses changed for {USER_EMAIL} from {OLD_VALUE} to {NEW_VALUE}
References #
CREATE_EMAIL_MONITOR: Create an email monitor
#Description
Created an email monitor for {USER_EMAIL} to {EMAIL_MONITOR_DEST_EMAIL} that will expire on {END_DATE_TIME}
References #
DELETE_ACCOUNT_INFO_DUMP: Delete account information dump
#Description
Deleted account and login information dump for {USER_EMAIL} and request ID {REQUEST_ID}
References #
DELETE_EMAIL_MONITOR: Delete an email monitor
#Description
Deleted an email monitor for {USER_EMAIL} to {EMAIL_MONITOR_DEST_EMAIL}
References #
DELETE_MAILBOX_DUMP: Delete mailbox dump
#Description
Deleted mailbox dump for {USER_EMAIL} and request ID {REQUEST_ID}
References #
DELETE_PROFILE_PHOTO: Delete Profile Photo
#Description
Profile photo of {USER_EMAIL} has been deleted
References #
ADD_DISPLAY_NAME: Display Name Added
#Description
{USER_DISPLAY_NAME} added as a display name of {USER_EMAIL}
References #
CHANGE_DISPLAY_NAME: Display Name Change
#Description
Display name of {USER_EMAIL} changed from {OLD_VALUE} to {NEW_VALUE}
References #
REMOVE_DISPLAY_NAME: Display Name Removed
#Description
{USER_DISPLAY_NAME} removed as a display name of {USER_EMAIL}
References #
CHANGE_FIRST_NAME: First Name Change
#Description
First name of {USER_EMAIL} changed from {OLD_VALUE} to {NEW_VALUE}
References #
CHANGE_LAST_NAME: Last Name Change
#Description
Last name of {USER_EMAIL} changed from {OLD_VALUE} to {NEW_VALUE}
References #
MAIL_ROUTING_DESTINATION_ADDED: Mail Routing Destination Creation
#Description
User {USER_EMAIL} has received the following individual mail routing destination: {NEW_VALUE}
References #
MAIL_ROUTING_DESTINATION_REMOVED: Mail Routing Destination Deletion
#Description
User {USER_EMAIL} has had the following individual mail routing destination removed: {OLD_VALUE}
References #
ADD_NICKNAME: Nickname Creation
#Description
{USER_NICKNAME} created as a nickname of {USER_EMAIL}
References #
REMOVE_NICKNAME: Nickname Deletion
#Description
{USER_NICKNAME} deleted as a nickname of {USER_EMAIL}
References #
PASSKEY_REVOKED: Passkey revoked
#Description
A passkey enrolled for user {USER_EMAIL} was revoked
References #
CHANGE_PASSWORD_ON_NEXT_LOGIN: Password Change on Next Login
#Description
Password change requirement for {USER_EMAIL} on next login changed from {OLD_VALUE} to {NEW_VALUE}
References #
DOWNLOAD_PENDING_INVITES_LIST: Pending Invites List Download
#Description
Pending Invites List was downloaded as a CSV file
References #
UPDATE_PUBLIC_KEY_CERTIFICATE_STATUS: Public Key Certificate Status Updated
#Description
Public key certificate status updated to {PUBLIC_KEY_CERTIFICATE_STATUS} for email {USER_IMPACTED_EMAIL} of user {USER_EMAIL}
References #
UPDATE_PUBLIC_KEY_CERTIFICATE: Public Key Certificate Updated
#Description
Public key certificate updated for {USER_DISPLAY_NAME} email {USER_EMAIL}
References #
REMOVE_RECOVERY_EMAIL: Remove Recovery Email
#Description
Recovery email removed for {USER_EMAIL}
References #
REMOVE_RECOVERY_PHONE: Remove Recovery Phone
#Description
Recovery phone removed for {USER_EMAIL}
References #
REQUEST_MAILBOX_DUMP: Request mailbox dump
#Description
Requested mailbox dump for {USER_EMAIL}
References #
SECURITY_KEY_REGISTERED_FOR_USER: Security Key Registered For User
#Description
Security key registered for {USER_EMAIL}
References #
REVOKE_SECURITY_KEY: Security Key Revoke
#Description
A security key enrolled for user {USER_EMAIL} for 2-step verification was revoked
References #
VIEW_TEMP_PASSWORD: Temporary Password Viewed
#Description
Temporary password for user {USER_EMAIL} viewed by the admin
References #
UNBLOCK_USER_SESSION: Unblock User Session
#Description
User {USER_EMAIL} unblocked by temporarily disabling login challenge
References #
UNMANAGED_USERS_BULK_UPLOAD: Unmanaged Users Bulk Upload
#Description
A total of {BULK_UPLOAD_TOTAL_USERS_NUMBER} unmanaged users selected for upload. {BULK_UPLOAD_FAIL_USERS_NUMBER} out of {BULK_UPLOAD_TOTAL_USERS_NUMBER} users failed to be uploaded.
References #
DOWNLOAD_UNMANAGED_USERS_LIST: Unmanaged Users List Download
#Description
Unmanaged Users list was downloaded as a CSV file
References #
UPDATE_PROFILE_PHOTO: Update Profile Photo
#Description
Profile photo of {USER_EMAIL} has been updated
References #
UNENROLL_USER_FROM_TITANIUM: User Advanced Protection Unenroll
#Description
User {USER_EMAIL} unenrolled from Advanced Protection
References #
UPDATE_BIRTHDATE: User BirthDate Change
#Description
The birth date for {USER_EMAIL} changed to {BIRTHDATE}
References #
USER_CREATED_PASSKEY_REVOKE: User created passkey revoked
#Description
A user created passkey enrolled for user {USER_EMAIL} was revoked
References #
DOWNGRADE_USER_FROM_GPLUS: User Downgrade From Google+
#Description
{USER_EMAIL} was downgraded from Google+
References #
USER_ENROLLED_IN_TWO_STEP_VERIFICATION: User Enrolled In 2-Step Verification
#Description
{USER_EMAIL} enrolled in 2-step verification
References #
DOWNLOAD_USERLIST_CSV: User List Download
#Description
User list was downloaded as a CSV file
References #
USER_PUT_IN_TWO_STEP_VERIFICATION_GRACE_PERIOD: User Put In 2-Step Verification Grace Period
#Description
2-step verification grace period has been enabled on {USER_EMAIL} till {NEW_VALUE}
References #
UNENROLL_USER_FROM_STRONG_AUTH: User Strong Auth Unenroll
#Description
User {USER_EMAIL} unenrolled from Strong Auth
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Splunk #
UNENROLL_USER_FROM_STRONG_AUTH command. This…T1556, T1556.006, T1586, T1586.003
References #
UPGRADE_USER_TO_GPLUS: User Upgrade To Google+
#Description
{USER_EMAIL} was upgraded to Google+
References #
USERS_BULK_UPLOAD: Users Bulk Upload
#Description
A total of {BULK_UPLOAD_TOTAL_USERS_NUMBER} users selected for upload. {BULK_UPLOAD_FAIL_USERS_NUMBER} out of {BULK_UPLOAD_TOTAL_USERS_NUMBER} users failed to be uploaded.