Mobile / Device Management GoogleWorkspace-mobile
8 operations, identified by eventName in the audit log.
| eventName | Description |
|---|---|
| any | Source-only rules that filter on applicationName 'mobile' without specifying an eventName attribute here. |
| DEVICE_REGISTER_UNREGISTER_EVENT | A mobile or managed device was registered or unregistered from Google Workspace MDM. Elastic uses dataset 'google_workspace.device' for this applicationName. |
| DEVICE_COMPROMISED_EVENT | A managed device was detected as compromised or rooted/jailbroken. |
| DEVICE_ACTION_EVENT | An administrative action was taken on a managed device (e.g. remote wipe, lock). |
| FAILED_PASSWORD_ATTEMPTS_EVENT | Multiple failed attempts to unlock a managed device were detected. |
| SUSPICIOUS_ACTIVITY_EVENT | Suspicious activity was detected on a managed mobile device. |
| DEVICE_SYNC_EVENT | A managed device synced with Google Workspace MDM. |
| DEVICE_COMPLIANCE_CHANGED_EVENT | A managed device's compliance status changed. |
any: Mobile / Device Management (any event)
#Description
Source-only rules that filter on applicationName 'mobile' without specifying an eventName attribute here.
Fields #
| Name | Description |
|---|---|
applicationName | Reports API applicationName value identifying the GWS service (e.g. admin, login, drive). |
eventName | The specific action within this application. |
actor.email | Email address of the user or administrator who performed the action. |
actor.profileId | Unique Google Workspace profile ID of the actor. |
ipAddress | IP address of the actor at the time of the event. |
parameters | Array of event-specific key-value parameters documenting affected resources. |
References #
- Reports API: mobile activity events https://developers.google.com/workspace/admin/reports/v1/appendix/activity/mobile
- Reports API activities.list reference https://developers.google.com/workspace/admin/reports/reference/rest/v1/activities/list
DEVICE_REGISTER_UNREGISTER_EVENT: Device Register/Unregister Event
#Description
A mobile or managed device was registered or unregistered from Google Workspace MDM. Elastic uses dataset 'google_workspace.device' for this applicationName.
Fields #
| Name | Description |
|---|---|
applicationName | Reports API applicationName value identifying the GWS service (e.g. admin, login, drive). |
eventName | The specific action within this application. |
actor.email | Email address of the user or administrator who performed the action. |
actor.profileId | Unique Google Workspace profile ID of the actor. |
ipAddress | IP address of the actor at the time of the event. |
parameters | Array of event-specific key-value parameters documenting affected resources. |
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
EventType | eq | DEVICE_REGISTER_UNREGISTER_EVENT | 2 rules | elastic |
gws::device_account_state | eq | REGISTERED | 2 rules | elastic |
user.email | is_not_null | | 2 rules | elastic |
Detection Rules #
View all rules referencing this event →Elastic #
References #
- Mobile Activity Events reference https://developers.google.com/workspace/admin/reports/v1/appendix/activity/mobile
DEVICE_COMPROMISED_EVENT: Device Compromised Event
#Description
A managed device was detected as compromised or rooted/jailbroken.
Fields #
| Name | Description |
|---|---|
applicationName | Reports API applicationName value identifying the GWS service (e.g. admin, login, drive). |
eventName | The specific action within this application. |
actor.email | Email address of the user or administrator who performed the action. |
actor.profileId | Unique Google Workspace profile ID of the actor. |
ipAddress | IP address of the actor at the time of the event. |
parameters | Array of event-specific key-value parameters documenting affected resources. |
References #
- Mobile Activity Events reference https://developers.google.com/workspace/admin/reports/v1/appendix/activity/mobile
DEVICE_ACTION_EVENT: Device Action Event
#Description
An administrative action was taken on a managed device (e.g. remote wipe, lock).
Fields #
| Name | Description |
|---|---|
applicationName | Reports API applicationName value identifying the GWS service (e.g. admin, login, drive). |
eventName | The specific action within this application. |
actor.email | Email address of the user or administrator who performed the action. |
actor.profileId | Unique Google Workspace profile ID of the actor. |
ipAddress | IP address of the actor at the time of the event. |
parameters | Array of event-specific key-value parameters documenting affected resources. |
References #
- Mobile Activity Events reference https://developers.google.com/workspace/admin/reports/v1/appendix/activity/mobile
FAILED_PASSWORD_ATTEMPTS_EVENT: Failed Password Attempts Event
#Description
Multiple failed attempts to unlock a managed device were detected.
Fields #
| Name | Description |
|---|---|
applicationName | Reports API applicationName value identifying the GWS service (e.g. admin, login, drive). |
eventName | The specific action within this application. |
actor.email | Email address of the user or administrator who performed the action. |
actor.profileId | Unique Google Workspace profile ID of the actor. |
ipAddress | IP address of the actor at the time of the event. |
parameters | Array of event-specific key-value parameters documenting affected resources. |
References #
- Mobile Activity Events reference https://developers.google.com/workspace/admin/reports/v1/appendix/activity/mobile
SUSPICIOUS_ACTIVITY_EVENT: Suspicious Activity Event
#Description
Suspicious activity was detected on a managed mobile device.
Fields #
| Name | Description |
|---|---|
applicationName | Reports API applicationName value identifying the GWS service (e.g. admin, login, drive). |
eventName | The specific action within this application. |
actor.email | Email address of the user or administrator who performed the action. |
actor.profileId | Unique Google Workspace profile ID of the actor. |
ipAddress | IP address of the actor at the time of the event. |
parameters | Array of event-specific key-value parameters documenting affected resources. |
References #
- Mobile Activity Events reference https://developers.google.com/workspace/admin/reports/v1/appendix/activity/mobile
DEVICE_SYNC_EVENT: Device Sync Event
#Description
A managed device synced with Google Workspace MDM.
Fields #
| Name | Description |
|---|---|
applicationName | Reports API applicationName value identifying the GWS service (e.g. admin, login, drive). |
eventName | The specific action within this application. |
actor.email | Email address of the user or administrator who performed the action. |
actor.profileId | Unique Google Workspace profile ID of the actor. |
ipAddress | IP address of the actor at the time of the event. |
parameters | Array of event-specific key-value parameters documenting affected resources. |
References #
- Mobile Activity Events reference https://developers.google.com/workspace/admin/reports/v1/appendix/activity/mobile
DEVICE_COMPLIANCE_CHANGED_EVENT: Device Compliance Changed Event
#Description
A managed device's compliance status changed.
Fields #
| Name | Description |
|---|---|
applicationName | Reports API applicationName value identifying the GWS service (e.g. admin, login, drive). |
eventName | The specific action within this application. |
actor.email | Email address of the user or administrator who performed the action. |
actor.profileId | Unique Google Workspace profile ID of the actor. |
ipAddress | IP address of the actor at the time of the event. |
parameters | Array of event-specific key-value parameters documenting affected resources. |
References #
- Mobile Activity Events reference https://developers.google.com/workspace/admin/reports/v1/appendix/activity/mobile