User

any: User (catch-all)

#

Description

Matches any user event.

Fields #

NameDescriptionRules
uuidUnique event identifier.
timestampTime the event occurred.
actor_uuidActor identifier.
actor_details.uuidActor identifier.
actor_details.nameActor's full name.
actor_details.emailActor's email address.
actor_typeType of actor.
actor_account_uuid1Password account identifier of the actor.
account_uuid1Password account identifier.
actionAction performed.1 detection rule
object_typeType of affected object.1 detection rule
object_uuidIdentifier of the affected object.
object_details.uuidAffected user identifier, when applicable.
object_details.nameAffected user's full name, when applicable.
object_details.emailAffected user's email address, when applicable.
aux_idNumeric identifier for related event data.
aux_uuidIdentifier for related event data.
aux_details.uuidRelated user identifier, when applicable.
aux_details.nameRelated user's full name, when applicable.
aux_details.emailRelated user's email address, when applicable.
aux_infoAdditional event information.
session.uuidSession identifier.
session.login_timeTime the session started.
session.device_uuidIdentifier of the session device.
session.ipIP address used for the session.
location.countryClient country inferred from IP address.
location.regionClient region inferred from IP address.
location.cityClient city inferred from IP address.
location.longitudeClient longitude inferred from IP address.
location.latitudeClient latitude inferred from IP address.

Common Indicators #

Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.

FieldKindValueRulesVendors
object_type (kusto rule field)equser1 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

References #

user-activate: Change User State From

#

Description

A user's state was changed.

Fields #

NameDescription
uuidUnique event identifier.
timestampTime the event occurred.
actor_uuidActor identifier.
actor_details.uuidActor identifier.
actor_details.nameActor's full name.
actor_details.emailActor's email address.
actor_typeType of actor.
actor_account_uuid1Password account identifier of the actor.
account_uuid1Password account identifier.
actionAction performed.
object_typeType of affected object.
object_uuidIdentifier of the affected object.
object_details.uuidAffected user identifier, when applicable.
object_details.nameAffected user's full name, when applicable.
object_details.emailAffected user's email address, when applicable.
aux_idNumeric identifier for related event data.
aux_uuidIdentifier for related event data.
aux_details.uuidRelated user identifier, when applicable.
aux_details.nameRelated user's full name, when applicable.
aux_details.emailRelated user's email address, when applicable.
aux_infoAdditional event information.
session.uuidSession identifier.
session.login_timeTime the session started.
session.device_uuidIdentifier of the session device.
session.ipIP address used for the session.
location.countryClient country inferred from IP address.
location.regionClient region inferred from IP address.
location.cityClient city inferred from IP address.
location.longitudeClient longitude inferred from IP address.
location.latitudeClient latitude inferred from IP address.

Example Event #

{
  "uuid": "GRXST7MM2VJIDNDOTI5XZKXFON",
  "timestamp": "12/15/2023, 11:05:51.266 AM",
  "location": {
    "country": "The Netherlands",
    "region": "North Holland",
    "city": "Amsterdam",
    "latitude": 52.3759,
    "longitude": 4.8975
  },
  "actor_uuid": "AVHAFAP4PRDF5K3724I67N3CEU",
  "actor_details": {
    "uuid": "AVHAFAP4PRDF5K3724I67N3CEU",
    "name": "Automated User Provisioning",
    "email": "zkv4c3mauxjbw@1passwordserviceaccounts.com"
  },
  "action": "activate",
  "object_type": "user",
  "object_uuid": "ZOMBFTD7YZA6ZKPY7SF22LGVQE",
  "object_details": {
    "uuid": "ZOMBFTD7YZA6ZKPY7SF22LGVQE",
    "name": "Arthur Shelby",
    "email": "arthur.shelby@securehats.nl"
  },
  "session": {
    "uuid": "KRG6S6ANAZB67JYNUQFNTMZQ6Y",
    "login_time": "2023-12-12T05:25:28.4465411Z",
    "device_uuid": "pjleru42mvdhql4nl7mab6ympm",
    "ip": "4.175.88.205"
  }
}

References #

user-beginr: Change User State From

#

Description

A user's state was changed.

Fields #

NameDescription
uuidUnique event identifier.
timestampTime the event occurred.
actor_uuidActor identifier.
actor_details.uuidActor identifier.
actor_details.nameActor's full name.
actor_details.emailActor's email address.
actor_typeType of actor.
actor_account_uuid1Password account identifier of the actor.
account_uuid1Password account identifier.
actionAction performed.
object_typeType of affected object.
object_uuidIdentifier of the affected object.
object_details.uuidAffected user identifier, when applicable.
object_details.nameAffected user's full name, when applicable.
object_details.emailAffected user's email address, when applicable.
aux_idNumeric identifier for related event data.
aux_uuidIdentifier for related event data.
aux_details.uuidRelated user identifier, when applicable.
aux_details.nameRelated user's full name, when applicable.
aux_details.emailRelated user's email address, when applicable.
aux_infoAdditional event information.
session.uuidSession identifier.
session.login_timeTime the session started.
session.device_uuidIdentifier of the session device.
session.ipIP address used for the session.
location.countryClient country inferred from IP address.
location.regionClient region inferred from IP address.
location.cityClient city inferred from IP address.
location.longitudeClient longitude inferred from IP address.
location.latitudeClient latitude inferred from IP address.

Example Event #

{
  "uuid": "BV4MOQ2K7BSKBWCJR4YYVYFFGC",
  "timestamp": "12/15/2023, 11:26:23.804 AM",
  "location": {
    "country": "The Netherlands",
    "region": "North Brabant",
    "city": "Rijen",
    "latitude": 51.5923,
    "longitude": 4.9218
  },
  "actor_uuid": "QD3Q2WVSVZFHZMC3O6HY3VSC6Y",
  "actor_details": {
    "uuid": "QD3Q2WVSVZFHZMC3O6HY3VSC6Y",
    "name": "Walter White",
    "email": "walter.white@securehats.nl"
  },
  "action": "beginr",
  "object_type": "user",
  "object_uuid": "KQIRZOBQP5DIHDDHEWTC375IF4",
  "object_details": {
    "uuid": "KQIRZOBQP5DIHDDHEWTC375IF4",
    "name": "Bryan Beekhof",
    "email": "bryan.beekhof@securehats.nl"
  },
  "session": {
    "uuid": "3AZWUJUQMBAOVHBUM246E3EWGU",
    "login_time": "2023-12-15T11:25:29.6672894Z",
    "device_uuid": "uh7t35mrsnycrf4vz6wbdhs4y4",
    "ip": "76.75.244.76"
  }
}

References #

user-cancelr: Cancel User Recovery

#

Description

A user recovery was canceled.

Fields #

NameDescription
uuidUnique event identifier.
timestampTime the event occurred.
actor_uuidActor identifier.
actor_details.uuidActor identifier.
actor_details.nameActor's full name.
actor_details.emailActor's email address.
actor_typeType of actor.
actor_account_uuid1Password account identifier of the actor.
account_uuid1Password account identifier.
actionAction performed.
object_typeType of affected object.
object_uuidIdentifier of the affected object.
object_details.uuidAffected user identifier, when applicable.
object_details.nameAffected user's full name, when applicable.
object_details.emailAffected user's email address, when applicable.
aux_idNumeric identifier for related event data.
aux_uuidIdentifier for related event data.
aux_details.uuidRelated user identifier, when applicable.
aux_details.nameRelated user's full name, when applicable.
aux_details.emailRelated user's email address, when applicable.
aux_infoAdditional event information.
session.uuidSession identifier.
session.login_timeTime the session started.
session.device_uuidIdentifier of the session device.
session.ipIP address used for the session.
location.countryClient country inferred from IP address.
location.regionClient region inferred from IP address.
location.cityClient city inferred from IP address.
location.longitudeClient longitude inferred from IP address.
location.latitudeClient latitude inferred from IP address.

References #

user-changeks: Change User Keyset

#

Description

A user's keyset changed.

Fields #

NameDescription
uuidUnique event identifier.
timestampTime the event occurred.
actor_uuidActor identifier.
actor_details.uuidActor identifier.
actor_details.nameActor's full name.
actor_details.emailActor's email address.
actor_typeType of actor.
actor_account_uuid1Password account identifier of the actor.
account_uuid1Password account identifier.
actionAction performed.
object_typeType of affected object.
object_uuidIdentifier of the affected object.
object_details.uuidAffected user identifier, when applicable.
object_details.nameAffected user's full name, when applicable.
object_details.emailAffected user's email address, when applicable.
aux_idNumeric identifier for related event data.
aux_uuidIdentifier for related event data.
aux_details.uuidRelated user identifier, when applicable.
aux_details.nameRelated user's full name, when applicable.
aux_details.emailRelated user's email address, when applicable.
aux_infoAdditional event information.
session.uuidSession identifier.
session.login_timeTime the session started.
session.device_uuidIdentifier of the session device.
session.ipIP address used for the session.
location.countryClient country inferred from IP address.
location.regionClient region inferred from IP address.
location.cityClient city inferred from IP address.
location.longitudeClient longitude inferred from IP address.
location.latitudeClient latitude inferred from IP address.

References #

user-changela: Change Language

#

Description

A user changed their preferred language.

Fields #

NameDescription
uuidUnique event identifier.
timestampTime the event occurred.
actor_uuidActor identifier.
actor_details.uuidActor identifier.
actor_details.nameActor's full name.
actor_details.emailActor's email address.
actor_typeType of actor.
actor_account_uuid1Password account identifier of the actor.
account_uuid1Password account identifier.
actionAction performed.
object_typeType of affected object.
object_uuidIdentifier of the affected object.
object_details.uuidAffected user identifier, when applicable.
object_details.nameAffected user's full name, when applicable.
object_details.emailAffected user's email address, when applicable.
aux_idNumeric identifier for related event data.
aux_uuidIdentifier for related event data.
aux_details.uuidRelated user identifier, when applicable.
aux_details.nameRelated user's full name, when applicable.
aux_details.emailRelated user's email address, when applicable.
aux_infoAdditional event information.
session.uuidSession identifier.
session.login_timeTime the session started.
session.device_uuidIdentifier of the session device.
session.ipIP address used for the session.
location.countryClient country inferred from IP address.
location.regionClient region inferred from IP address.
location.cityClient city inferred from IP address.
location.longitudeClient longitude inferred from IP address.
location.latitudeClient latitude inferred from IP address.

References #

user-changemp: Change 1Password Account Password

#

Description

A user changed their 1Password account password.

Fields #

NameDescription
uuidUnique event identifier.
timestampTime the event occurred.
actor_uuidActor identifier.
actor_details.uuidActor identifier.
actor_details.nameActor's full name.
actor_details.emailActor's email address.
actor_typeType of actor.
actor_account_uuid1Password account identifier of the actor.
account_uuid1Password account identifier.
actionAction performed.
object_typeType of affected object.
object_uuidIdentifier of the affected object.
object_details.uuidAffected user identifier, when applicable.
object_details.nameAffected user's full name, when applicable.
object_details.emailAffected user's email address, when applicable.
aux_idNumeric identifier for related event data.
aux_uuidIdentifier for related event data.
aux_details.uuidRelated user identifier, when applicable.
aux_details.nameRelated user's full name, when applicable.
aux_details.emailRelated user's email address, when applicable.
aux_infoAdditional event information.
session.uuidSession identifier.
session.login_timeTime the session started.
session.device_uuidIdentifier of the session device.
session.ipIP address used for the session.
location.countryClient country inferred from IP address.
location.regionClient region inferred from IP address.
location.cityClient city inferred from IP address.
location.longitudeClient longitude inferred from IP address.
location.latitudeClient latitude inferred from IP address.

References #

user-changenm: Change Name

#

Description

A user changed their name.

Fields #

NameDescription
uuidUnique event identifier.
timestampTime the event occurred.
actor_uuidActor identifier.
actor_details.uuidActor identifier.
actor_details.nameActor's full name.
actor_details.emailActor's email address.
actor_typeType of actor.
actor_account_uuid1Password account identifier of the actor.
account_uuid1Password account identifier.
actionAction performed.
object_typeType of affected object.
object_uuidIdentifier of the affected object.
object_details.uuidAffected user identifier, when applicable.
object_details.nameAffected user's full name, when applicable.
object_details.emailAffected user's email address, when applicable.
aux_idNumeric identifier for related event data.
aux_uuidIdentifier for related event data.
aux_details.uuidRelated user identifier, when applicable.
aux_details.nameRelated user's full name, when applicable.
aux_details.emailRelated user's email address, when applicable.
aux_infoAdditional event information.
session.uuidSession identifier.
session.login_timeTime the session started.
session.device_uuidIdentifier of the session device.
session.ipIP address used for the session.
location.countryClient country inferred from IP address.
location.regionClient region inferred from IP address.
location.cityClient city inferred from IP address.
location.longitudeClient longitude inferred from IP address.
location.latitudeClient latitude inferred from IP address.

Example Event #

{
  "uuid": "DUMMY-ID-0055",
  "action": "changenm",
  "session": {
    "uuid": "DUMMY-ID-0056",
    "login_time": "2026-08-20T14:43:23.780889197Z",
    "device_uuid": "DUMMY-ID-0003",
    "ip": "192.0.2.1"
  },
  "location": {
    "country": "Dummy Country 001",
    "region": "Dummy Region 001",
    "city": "Dummy City 001",
    "latitude": 0.0,
    "longitude": 0.0
  },
  "timestamp": "2026-08-20T17:57:23.693528547Z",
  "actor_type": "user",
  "actor_uuid": "DUMMY-USER-0001",
  "object_type": "user",
  "object_uuid": "DUMMY-USER-0020",
  "account_uuid": "DUMMY-ID-0004",
  "actor_details": {
    "uuid": "DUMMY-USER-0001",
    "name": "Dummy User 001",
    "email": "dummy.user001@example.invalid"
  },
  "object_details": {
    "uuid": "DUMMY-USER-0020",
    "name": "Dummy User 020",
    "email": "dummy.user020@example.invalid"
  }
}

References #

user-changesk: Change Secret Key

#

Description

A user changed their Secret Key.

Fields #

NameDescription
uuidUnique event identifier.
timestampTime the event occurred.
actor_uuidActor identifier.
actor_details.uuidActor identifier.
actor_details.nameActor's full name.
actor_details.emailActor's email address.
actor_typeType of actor.
actor_account_uuid1Password account identifier of the actor.
account_uuid1Password account identifier.
actionAction performed.
object_typeType of affected object.
object_uuidIdentifier of the affected object.
object_details.uuidAffected user identifier, when applicable.
object_details.nameAffected user's full name, when applicable.
object_details.emailAffected user's email address, when applicable.
aux_idNumeric identifier for related event data.
aux_uuidIdentifier for related event data.
aux_details.uuidRelated user identifier, when applicable.
aux_details.nameRelated user's full name, when applicable.
aux_details.emailRelated user's email address, when applicable.
aux_infoAdditional event information.
session.uuidSession identifier.
session.login_timeTime the session started.
session.device_uuidIdentifier of the session device.
session.ipIP address used for the session.
location.countryClient country inferred from IP address.
location.regionClient region inferred from IP address.
location.cityClient city inferred from IP address.
location.longitudeClient longitude inferred from IP address.
location.latitudeClient latitude inferred from IP address.

References #

user-completr: Complete User Recovery

#

Description

A user recovery was completed.

Fields #

NameDescription
uuidUnique event identifier.
timestampTime the event occurred.
actor_uuidActor identifier.
actor_details.uuidActor identifier.
actor_details.nameActor's full name.
actor_details.emailActor's email address.
actor_typeType of actor.
actor_account_uuid1Password account identifier of the actor.
account_uuid1Password account identifier.
actionAction performed.
object_typeType of affected object.
object_uuidIdentifier of the affected object.
object_details.uuidAffected user identifier, when applicable.
object_details.nameAffected user's full name, when applicable.
object_details.emailAffected user's email address, when applicable.
aux_idNumeric identifier for related event data.
aux_uuidIdentifier for related event data.
aux_details.uuidRelated user identifier, when applicable.
aux_details.nameRelated user's full name, when applicable.
aux_details.emailRelated user's email address, when applicable.
aux_infoAdditional event information.
session.uuidSession identifier.
session.login_timeTime the session started.
session.device_uuidIdentifier of the session device.
session.ipIP address used for the session.
location.countryClient country inferred from IP address.
location.regionClient region inferred from IP address.
location.cityClient city inferred from IP address.
location.longitudeClient longitude inferred from IP address.
location.latitudeClient latitude inferred from IP address.

Example Event #

{
  "uuid": "N7CPROXEZV65ZSJ5XVJNQQKAKR",
  "timestamp": "1/3/2024, 2:42:28.173 PM",
  "location": {
    "country": "The Netherlands",
    "region": "North Brabant",
    "city": "Rijen",
    "latitude": 51.5923,
    "longitude": 4.9218
  },
  "actor_uuid": "QD3Q2WVSVZFHZMC3O6HY3VSC6Y",
  "actor_details": {
    "uuid": "QD3Q2WVSVZFHZMC3O6HY3VSC6Y",
    "name": "Walter White",
    "email": "walter.white@securehats.nl"
  },
  "action": "completr",
  "object_type": "user",
  "object_uuid": "Q3IELCBNUFAYXAECYF6FHCLXXQ",
  "object_details": {
    "uuid": "Q3IELCBNUFAYXAECYF6FHCLXXQ",
    "name": "Nigel Powers",
    "email": "nigel.powers@securehats.nl"
  },
  "session": {
    "uuid": "5NP22Y4FMJAMPO7ZYZMUO6GG6E",
    "login_time": "2024-01-03T14:29:23.9986687Z",
    "device_uuid": "uh7t35mrsnycrf4vz6wbdhs4y4",
    "ip": "76.75.244.76"
  }
}

References #

user-dealldev: Delete All Devices

#

Description

All devices were deleted.

Fields #

NameDescription
uuidUnique event identifier.
timestampTime the event occurred.
actor_uuidActor identifier.
actor_details.uuidActor identifier.
actor_details.nameActor's full name.
actor_details.emailActor's email address.
actor_typeType of actor.
actor_account_uuid1Password account identifier of the actor.
account_uuid1Password account identifier.
actionAction performed.
object_typeType of affected object.
object_uuidIdentifier of the affected object.
object_details.uuidAffected user identifier, when applicable.
object_details.nameAffected user's full name, when applicable.
object_details.emailAffected user's email address, when applicable.
aux_idNumeric identifier for related event data.
aux_uuidIdentifier for related event data.
aux_details.uuidRelated user identifier, when applicable.
aux_details.nameRelated user's full name, when applicable.
aux_details.emailRelated user's email address, when applicable.
aux_infoAdditional event information.
session.uuidSession identifier.
session.login_timeTime the session started.
session.device_uuidIdentifier of the session device.
session.ipIP address used for the session.
location.countryClient country inferred from IP address.
location.regionClient region inferred from IP address.
location.cityClient city inferred from IP address.
location.longitudeClient longitude inferred from IP address.
location.latitudeClient latitude inferred from IP address.

Example Event #

{
  "uuid": "E5F5CT443DDB2JCS4A7GB5XHW2",
  "timestamp": "12/15/2023, 11:10:37.524 AM",
  "location": {
    "country": "The Netherlands",
    "region": "North Holland",
    "city": "Amsterdam",
    "latitude": 52.3759,
    "longitude": 4.8975
  },
  "actor_uuid": "AVHAFAP4PRDF5K3724I67N3CEU",
  "actor_details": {
    "uuid": "AVHAFAP4PRDF5K3724I67N3CEU",
    "name": "Automated User Provisioning",
    "email": "zkv4c3mauxjbw@1passwordserviceaccounts.com"
  },
  "action": "dealldev",
  "object_type": "user",
  "object_uuid": "AONGS2F7BFFPNG2LBTFMRH562Q",
  "object_details": {
    "uuid": "AONGS2F7BFFPNG2LBTFMRH562Q",
    "name": "Gideon Wories",
    "email": "gideon.wories@securehats.nl"
  },
  "session": {
    "uuid": "TPEFXHZ62ZGTHCHMSNEMLLDPMA",
    "login_time": "0001-01-01T00:00:00.0000000Z",
    "device_uuid": "pjleru42mvdhql4nl7mab6ympm",
    "ip": "4.175.88.205"
  }
}

References #

user-delete: Change User State From

#

Description

A user's state was changed.

Fields #

NameDescriptionRules
uuidUnique event identifier.
timestampTime the event occurred.
actor_uuidActor identifier.
actor_details.uuidActor identifier.
actor_details.nameActor's full name.
actor_details.emailActor's email address.
actor_typeType of actor.
actor_account_uuid1Password account identifier of the actor.
account_uuid1Password account identifier.
actionAction performed.1 detection rule
object_typeType of affected object.1 detection rule
object_uuidIdentifier of the affected object.
object_details.uuidAffected user identifier, when applicable.
object_details.nameAffected user's full name, when applicable.
object_details.emailAffected user's email address, when applicable.
aux_idNumeric identifier for related event data.
aux_uuidIdentifier for related event data.
aux_details.uuidRelated user identifier, when applicable.
aux_details.nameRelated user's full name, when applicable.
aux_details.emailRelated user's email address, when applicable.
aux_infoAdditional event information.
session.uuidSession identifier.
session.login_timeTime the session started.
session.device_uuidIdentifier of the session device.
session.ipIP address used for the session.
location.countryClient country inferred from IP address.
location.regionClient region inferred from IP address.
location.cityClient city inferred from IP address.
location.longitudeClient longitude inferred from IP address.
location.latitudeClient latitude inferred from IP address.

Example Event #

{
  "uuid": "6G4SUOYYRTP6LBU2SZH6DP5QGU",
  "timestamp": "1/8/2024, 6:40:52.312 PM",
  "location": {
    "country": "Portugal",
    "region": "Faro",
    "city": "Olh�o",
    "latitude": 37.0272,
    "longitude": -7.8338
  },
  "actor_uuid": "2C4RSXPRI5BVFOS3TCJFYDZYXY",
  "actor_details": {
    "uuid": "2C4RSXPRI5BVFOS3TCJFYDZYXY",
    "name": "Tommy Shelby",
    "email": "tommy.shelby@securehats.nl"
  },
  "action": "delete",
  "object_type": "user",
  "object_uuid": "SOI7VTRTWBEQHBZOS4U7J45SZA",
  "object_details": {
    "uuid": "SOI7VTRTWBEQHBZOS4U7J45SZA",
    "name": "Roy Stoop",
    "email": "roy@securehats.nl"
  },
  "session": {
    "uuid": "X4FWG32AEJEMLDS5LWQZQC4QZQ",
    "login_time": "2024-01-08T17:58:41.2889308Z",
    "device_uuid": "wnxznnlchyi4cpqratg6dzigjq",
    "ip": "95.93.92.51"
  }
}

Detection Patterns #

Common Indicators #

Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.

FieldKindValueRulesVendors
action (kusto rule field)eqdelete1 rulekusto
action (kusto rule field)eqexport1 rulekusto
object_type (kusto rule field)equser1 rulekusto
object_type (kusto rule field)eqvault1 rulekusto

References #

user-deolddev: Delete Old Devices

#

Description

Old devices were deleted.

Fields #

NameDescription
uuidUnique event identifier.
timestampTime the event occurred.
actor_uuidActor identifier.
actor_details.uuidActor identifier.
actor_details.nameActor's full name.
actor_details.emailActor's email address.
actor_typeType of actor.
actor_account_uuid1Password account identifier of the actor.
account_uuid1Password account identifier.
actionAction performed.
object_typeType of affected object.
object_uuidIdentifier of the affected object.
object_details.uuidAffected user identifier, when applicable.
object_details.nameAffected user's full name, when applicable.
object_details.emailAffected user's email address, when applicable.
aux_idNumeric identifier for related event data.
aux_uuidIdentifier for related event data.
aux_details.uuidRelated user identifier, when applicable.
aux_details.nameRelated user's full name, when applicable.
aux_details.emailRelated user's email address, when applicable.
aux_infoAdditional event information.
session.uuidSession identifier.
session.login_timeTime the session started.
session.device_uuidIdentifier of the session device.
session.ipIP address used for the session.
location.countryClient country inferred from IP address.
location.regionClient region inferred from IP address.
location.cityClient city inferred from IP address.
location.longitudeClient longitude inferred from IP address.
location.latitudeClient latitude inferred from IP address.

References #

user-disblmfa: Disable Multi-Factor Authentication

#

Description

Multi-factor authentication was disabled.

Fields #

NameDescription
uuidUnique event identifier.
timestampTime the event occurred.
actor_uuidActor identifier.
actor_details.uuidActor identifier.
actor_details.nameActor's full name.
actor_details.emailActor's email address.
actor_typeType of actor.
actor_account_uuid1Password account identifier of the actor.
account_uuid1Password account identifier.
actionAction performed.
object_typeType of affected object.
object_uuidIdentifier of the affected object.
object_details.uuidAffected user identifier, when applicable.
object_details.nameAffected user's full name, when applicable.
object_details.emailAffected user's email address, when applicable.
aux_idNumeric identifier for related event data.
aux_uuidIdentifier for related event data.
aux_details.uuidRelated user identifier, when applicable.
aux_details.nameRelated user's full name, when applicable.
aux_details.emailRelated user's email address, when applicable.
aux_infoAdditional event information.
session.uuidSession identifier.
session.login_timeTime the session started.
session.device_uuidIdentifier of the session device.
session.ipIP address used for the session.
location.countryClient country inferred from IP address.
location.regionClient region inferred from IP address.
location.cityClient city inferred from IP address.
location.longitudeClient longitude inferred from IP address.
location.latitudeClient latitude inferred from IP address.

Example Event #

The source export stringifies aux_id; the 1Password Events API schema defines aux_id as an integer.

{
  "uuid": "4WPGSI2CPDIDFTOIE2LD2SMXNP",
  "timestamp": "1/3/2024, 2:42:28.196 PM",
  "location": {
    "country": "The Netherlands",
    "region": "North Brabant",
    "city": "Rijen",
    "latitude": 51.5923,
    "longitude": 4.9218
  },
  "actor_uuid": "QD3Q2WVSVZFHZMC3O6HY3VSC6Y",
  "actor_details": {
    "uuid": "QD3Q2WVSVZFHZMC3O6HY3VSC6Y",
    "name": "Walter White",
    "email": "walter.white@securehats.nl"
  },
  "action": "disblmfa",
  "object_type": "user",
  "object_uuid": "Q3IELCBNUFAYXAECYF6FHCLXXQ",
  "object_details": {
    "uuid": "Q3IELCBNUFAYXAECYF6FHCLXXQ",
    "name": "Nigel Powers",
    "email": "nigel.powers@securehats.nl"
  },
  "aux_id": "1487957",
  "aux_info": "T",
  "session": {
    "uuid": "5NP22Y4FMJAMPO7ZYZMUO6GG6E",
    "login_time": "2024-01-03T14:29:23.9986687Z",
    "device_uuid": "uh7t35mrsnycrf4vz6wbdhs4y4",
    "ip": "76.75.244.76"
  }
}

References #

user-enblmfa: Enable Multi-Factor Authentication

#

Description

Multi-factor authentication was enabled.

Fields #

NameDescription
uuidUnique event identifier.
timestampTime the event occurred.
actor_uuidActor identifier.
actor_details.uuidActor identifier.
actor_details.nameActor's full name.
actor_details.emailActor's email address.
actor_typeType of actor.
actor_account_uuid1Password account identifier of the actor.
account_uuid1Password account identifier.
actionAction performed.
object_typeType of affected object.
object_uuidIdentifier of the affected object.
object_details.uuidAffected user identifier, when applicable.
object_details.nameAffected user's full name, when applicable.
object_details.emailAffected user's email address, when applicable.
aux_idNumeric identifier for related event data.
aux_uuidIdentifier for related event data.
aux_details.uuidRelated user identifier, when applicable.
aux_details.nameRelated user's full name, when applicable.
aux_details.emailRelated user's email address, when applicable.
aux_infoAdditional event information.
session.uuidSession identifier.
session.login_timeTime the session started.
session.device_uuidIdentifier of the session device.
session.ipIP address used for the session.
location.countryClient country inferred from IP address.
location.regionClient region inferred from IP address.
location.cityClient city inferred from IP address.
location.longitudeClient longitude inferred from IP address.
location.latitudeClient latitude inferred from IP address.

Example Event #

The source export stringifies aux_id; the 1Password Events API schema defines aux_id as an integer.

{
  "uuid": "WIX2XBHSBIIBPCOWYUKIMJLIEZ",
  "timestamp": "12/15/2023, 11:52:48.267 AM",
  "location": {
    "country": "The Netherlands",
    "region": "North Holland",
    "city": "Amsterdam",
    "latitude": 52.3426,
    "longitude": 4.8631
  },
  "actor_uuid": "54SFBG7JOJEQRKEY5TQ7JXRFVA",
  "actor_details": {
    "uuid": "54SFBG7JOJEQRKEY5TQ7JXRFVA",
    "name": "Gus Fring",
    "email": "gus.fring@securehats.nl"
  },
  "action": "enblmfa",
  "object_type": "user",
  "object_uuid": "54SFBG7JOJEQRKEY5TQ7JXRFVA",
  "object_details": {
    "uuid": "54SFBG7JOJEQRKEY5TQ7JXRFVA",
    "name": "Gus Fring",
    "email": "gus.fring@securehats.nl"
  },
  "aux_id": "1528119",
  "aux_info": "T",
  "session": {
    "uuid": "2CONSQ6LFJDZVAMYLUHJFAEWEQ",
    "login_time": "2023-12-15T11:52:48.2529735Z",
    "device_uuid": "tew7ipdhu3jyrqa3llawqiqciy",
    "ip": "178.132.215.44"
  }
}

References #

user-join: Change User State From

#

Description

A user's state was changed.

Fields #

NameDescription
uuidUnique event identifier.
timestampTime the event occurred.
actor_uuidActor identifier.
actor_details.uuidActor identifier.
actor_details.nameActor's full name.
actor_details.emailActor's email address.
actor_typeType of actor.
actor_account_uuid1Password account identifier of the actor.
account_uuid1Password account identifier.
actionAction performed.
object_typeType of affected object.
object_uuidIdentifier of the affected object.
object_details.uuidAffected user identifier, when applicable.
object_details.nameAffected user's full name, when applicable.
object_details.emailAffected user's email address, when applicable.
aux_idNumeric identifier for related event data.
aux_uuidIdentifier for related event data.
aux_details.uuidRelated user identifier, when applicable.
aux_details.nameRelated user's full name, when applicable.
aux_details.emailRelated user's email address, when applicable.
aux_infoAdditional event information.
session.uuidSession identifier.
session.login_timeTime the session started.
session.device_uuidIdentifier of the session device.
session.ipIP address used for the session.
location.countryClient country inferred from IP address.
location.regionClient region inferred from IP address.
location.cityClient city inferred from IP address.
location.longitudeClient longitude inferred from IP address.
location.latitudeClient latitude inferred from IP address.

References #

user-provsn: Provision (User)

#

Description

A user was provisioned; observed in telemetry but undocumented by 1Password.

Fields #

NameDescription
uuidUnique event identifier.
timestampTime the event occurred.
actor_uuidActor identifier.
actor_details.uuidActor identifier.
actor_details.nameActor's full name.
actor_details.emailActor's email address.
actor_typeType of actor.
actor_account_uuid1Password account identifier of the actor.
account_uuid1Password account identifier.
actionAction performed.
object_typeType of affected object.
object_uuidIdentifier of the affected object.
object_details.uuidAffected user identifier, when applicable.
object_details.nameAffected user's full name, when applicable.
object_details.emailAffected user's email address, when applicable.
aux_idNumeric identifier for related event data.
aux_uuidIdentifier for related event data.
aux_details.uuidRelated user identifier, when applicable.
aux_details.nameRelated user's full name, when applicable.
aux_details.emailRelated user's email address, when applicable.
aux_infoAdditional event information.
session.uuidSession identifier.
session.login_timeTime the session started.
session.device_uuidIdentifier of the session device.
session.ipIP address used for the session.
location.countryClient country inferred from IP address.
location.regionClient region inferred from IP address.
location.cityClient city inferred from IP address.
location.longitudeClient longitude inferred from IP address.
location.latitudeClient latitude inferred from IP address.

Example Event #

{
  "uuid": "F5E2U2KRZ45FQX3OQLEQ7KKXPU",
  "timestamp": "12/15/2023, 11:00:39.469 AM",
  "location": {
    "country": "The Netherlands",
    "region": "North Holland",
    "city": "Amsterdam",
    "latitude": 52.3759,
    "longitude": 4.8975
  },
  "actor_uuid": "AVHAFAP4PRDF5K3724I67N3CEU",
  "actor_details": {
    "uuid": "AVHAFAP4PRDF5K3724I67N3CEU",
    "name": "Automated User Provisioning",
    "email": "zkv4c3mauxjbw@1passwordserviceaccounts.com"
  },
  "action": "provsn",
  "object_type": "user",
  "object_uuid": "ZOMBFTD7YZA6ZKPY7SF22LGVQE",
  "object_details": {
    "uuid": "ZOMBFTD7YZA6ZKPY7SF22LGVQE",
    "name": "Arthur Shelby",
    "email": "arthur.shelby@securehats.nl"
  },
  "session": {
    "uuid": "TPEFXHZ62ZGTHCHMSNEMLLDPMA",
    "login_time": "2023-12-14T11:39:44.9931456Z",
    "device_uuid": "pjleru42mvdhql4nl7mab6ympm",
    "ip": "4.175.88.205"
  }
}

References #

user-reactive: Change User State From

#

Description

A user's state was changed.

Fields #

NameDescription
uuidUnique event identifier.
timestampTime the event occurred.
actor_uuidActor identifier.
actor_details.uuidActor identifier.
actor_details.nameActor's full name.
actor_details.emailActor's email address.
actor_typeType of actor.
actor_account_uuid1Password account identifier of the actor.
account_uuid1Password account identifier.
actionAction performed.
object_typeType of affected object.
object_uuidIdentifier of the affected object.
object_details.uuidAffected user identifier, when applicable.
object_details.nameAffected user's full name, when applicable.
object_details.emailAffected user's email address, when applicable.
aux_idNumeric identifier for related event data.
aux_uuidIdentifier for related event data.
aux_details.uuidRelated user identifier, when applicable.
aux_details.nameRelated user's full name, when applicable.
aux_details.emailRelated user's email address, when applicable.
aux_infoAdditional event information.
session.uuidSession identifier.
session.login_timeTime the session started.
session.device_uuidIdentifier of the session device.
session.ipIP address used for the session.
location.countryClient country inferred from IP address.
location.regionClient region inferred from IP address.
location.cityClient city inferred from IP address.
location.longitudeClient longitude inferred from IP address.
location.latitudeClient latitude inferred from IP address.

Example Event #

{
  "uuid": "DUMMY-ID-0038",
  "action": "reactive",
  "session": {
    "uuid": "DUMMY-ID-0039",
    "login_time": "2026-07-23T14:45:23.491952496Z",
    "device_uuid": "DUMMY-ID-0003",
    "ip": "192.0.2.1"
  },
  "location": {
    "country": "Dummy Country 001",
    "region": "Dummy Region 001",
    "city": "Dummy City 001",
    "latitude": 0.0,
    "longitude": 0.0
  },
  "timestamp": "2026-07-23T14:46:15.593777472Z",
  "actor_type": "user",
  "actor_uuid": "DUMMY-USER-0001",
  "object_type": "user",
  "object_uuid": "DUMMY-USER-0014",
  "account_uuid": "DUMMY-ID-0004",
  "actor_details": {
    "uuid": "DUMMY-USER-0001",
    "name": "Dummy User 001",
    "email": "dummy.user001@example.invalid"
  },
  "object_details": {
    "uuid": "DUMMY-USER-0014",
    "name": "Dummy User 014",
    "email": "dummy.user014@example.invalid"
  }
}

References #

user-resendts: Resend Provisioning Email

#

Description

A provisioning email was resent.

Fields #

NameDescription
uuidUnique event identifier.
timestampTime the event occurred.
actor_uuidActor identifier.
actor_details.uuidActor identifier.
actor_details.nameActor's full name.
actor_details.emailActor's email address.
actor_typeType of actor.
actor_account_uuid1Password account identifier of the actor.
account_uuid1Password account identifier.
actionAction performed.
object_typeType of affected object.
object_uuidIdentifier of the affected object.
object_details.uuidAffected user identifier, when applicable.
object_details.nameAffected user's full name, when applicable.
object_details.emailAffected user's email address, when applicable.
aux_idNumeric identifier for related event data.
aux_uuidIdentifier for related event data.
aux_details.uuidRelated user identifier, when applicable.
aux_details.nameRelated user's full name, when applicable.
aux_details.emailRelated user's email address, when applicable.
aux_infoAdditional event information.
session.uuidSession identifier.
session.login_timeTime the session started.
session.device_uuidIdentifier of the session device.
session.ipIP address used for the session.
location.countryClient country inferred from IP address.
location.regionClient region inferred from IP address.
location.cityClient city inferred from IP address.
location.longitudeClient longitude inferred from IP address.
location.latitudeClient latitude inferred from IP address.

Example Event #

{
  "uuid": "QRL3WULJSDSBSA5HKEFYWTVQRS",
  "timestamp": "1/12/2024, 2:04:44.269 PM",
  "location": {
    "country": "The Netherlands",
    "region": "North Brabant",
    "city": "Rijen",
    "latitude": 51.5923,
    "longitude": 4.9218
  },
  "actor_uuid": "QD3Q2WVSVZFHZMC3O6HY3VSC6Y",
  "actor_details": {
    "uuid": "QD3Q2WVSVZFHZMC3O6HY3VSC6Y",
    "name": "Walter White",
    "email": "walter.white@securehats.nl"
  },
  "action": "resendts",
  "object_type": "user",
  "object_uuid": "HKIMSOYIIZGQJLKGOTZNZRRQQI",
  "object_details": {
    "uuid": "HKIMSOYIIZGQJLKGOTZNZRRQQI",
    "name": "Felicity Shagwell",
    "email": "felicity.sShagwell@securehats.nl"
  },
  "session": {
    "uuid": "SYSZVH2JP5A75JDWJXWTUH3AGM",
    "login_time": "2024-01-12T14:00:27.5697249Z",
    "device_uuid": "uh7t35mrsnycrf4vz6wbdhs4y4",
    "ip": "76.75.244.76"
  }
}

References #

user-sdvcsso: Set up Single Sign-On Authentication

#

Description

A user set up their 1Password account to unlock with SSO.

Fields #

NameDescription
uuidUnique event identifier.
timestampTime the event occurred.
actor_uuidActor identifier.
actor_details.uuidActor identifier.
actor_details.nameActor's full name.
actor_details.emailActor's email address.
actor_typeType of actor.
actor_account_uuid1Password account identifier of the actor.
account_uuid1Password account identifier.
actionAction performed.
object_typeType of affected object.
object_uuidIdentifier of the affected object.
object_details.uuidAffected user identifier, when applicable.
object_details.nameAffected user's full name, when applicable.
object_details.emailAffected user's email address, when applicable.
aux_idNumeric identifier for related event data.
aux_uuidIdentifier for related event data.
aux_details.uuidRelated user identifier, when applicable.
aux_details.nameRelated user's full name, when applicable.
aux_details.emailRelated user's email address, when applicable.
aux_infoAdditional event information.
session.uuidSession identifier.
session.login_timeTime the session started.
session.device_uuidIdentifier of the session device.
session.ipIP address used for the session.
location.countryClient country inferred from IP address.
location.regionClient region inferred from IP address.
location.cityClient city inferred from IP address.
location.longitudeClient longitude inferred from IP address.
location.latitudeClient latitude inferred from IP address.

References #

user-sendpkg: Send Package

#

Description

A user sent an item to another user.

Fields #

NameDescription
uuidUnique event identifier.
timestampTime the event occurred.
actor_uuidActor identifier.
actor_details.uuidActor identifier.
actor_details.nameActor's full name.
actor_details.emailActor's email address.
actor_typeType of actor.
actor_account_uuid1Password account identifier of the actor.
account_uuid1Password account identifier.
actionAction performed.
object_typeType of affected object.
object_uuidIdentifier of the affected object.
object_details.uuidAffected user identifier, when applicable.
object_details.nameAffected user's full name, when applicable.
object_details.emailAffected user's email address, when applicable.
aux_idNumeric identifier for related event data.
aux_uuidIdentifier for related event data.
aux_details.uuidRelated user identifier, when applicable.
aux_details.nameRelated user's full name, when applicable.
aux_details.emailRelated user's email address, when applicable.
aux_infoAdditional event information.
session.uuidSession identifier.
session.login_timeTime the session started.
session.device_uuidIdentifier of the session device.
session.ipIP address used for the session.
location.countryClient country inferred from IP address.
location.regionClient region inferred from IP address.
location.cityClient city inferred from IP address.
location.longitudeClient longitude inferred from IP address.
location.latitudeClient latitude inferred from IP address.

References #

user-sendts: Send Provisioning Email

#

Description

A provisioning email was sent.

Fields #

NameDescription
uuidUnique event identifier.
timestampTime the event occurred.
actor_uuidActor identifier.
actor_details.uuidActor identifier.
actor_details.nameActor's full name.
actor_details.emailActor's email address.
actor_typeType of actor.
actor_account_uuid1Password account identifier of the actor.
account_uuid1Password account identifier.
actionAction performed.
object_typeType of affected object.
object_uuidIdentifier of the affected object.
object_details.uuidAffected user identifier, when applicable.
object_details.nameAffected user's full name, when applicable.
object_details.emailAffected user's email address, when applicable.
aux_idNumeric identifier for related event data.
aux_uuidIdentifier for related event data.
aux_details.uuidRelated user identifier, when applicable.
aux_details.nameRelated user's full name, when applicable.
aux_details.emailRelated user's email address, when applicable.
aux_infoAdditional event information.
session.uuidSession identifier.
session.login_timeTime the session started.
session.device_uuidIdentifier of the session device.
session.ipIP address used for the session.
location.countryClient country inferred from IP address.
location.regionClient region inferred from IP address.
location.cityClient city inferred from IP address.
location.longitudeClient longitude inferred from IP address.
location.latitudeClient latitude inferred from IP address.

Example Event #

{
  "uuid": "HWZXV2CJDMOP4CUOJK2N545C6J",
  "timestamp": "12/15/2023, 11:00:39.684 AM",
  "location": {
    "country": "The Netherlands",
    "region": "North Holland",
    "city": "Amsterdam",
    "latitude": 52.3759,
    "longitude": 4.8975
  },
  "actor_uuid": "AVHAFAP4PRDF5K3724I67N3CEU",
  "actor_details": {
    "uuid": "AVHAFAP4PRDF5K3724I67N3CEU",
    "name": "Automated User Provisioning",
    "email": "zkv4c3mauxjbw@1passwordserviceaccounts.com"
  },
  "action": "sendts",
  "object_type": "user",
  "object_uuid": "ZOMBFTD7YZA6ZKPY7SF22LGVQE",
  "object_details": {
    "uuid": "ZOMBFTD7YZA6ZKPY7SF22LGVQE",
    "name": "Arthur Shelby",
    "email": "arthur.shelby@securehats.nl"
  },
  "session": {
    "uuid": "TPEFXHZ62ZGTHCHMSNEMLLDPMA",
    "login_time": "2023-12-14T11:39:44.9931456Z",
    "device_uuid": "pjleru42mvdhql4nl7mab6ympm",
    "ip": "4.175.88.205"
  }
}

References #

user-suspend: Change User State From

#

Description

A user's state was changed.

Fields #

NameDescriptionRules
uuidUnique event identifier.
timestampTime the event occurred.
actor_uuidActor identifier.
actor_details.uuidActor identifier.
actor_details.nameActor's full name.
actor_details.emailActor's email address.
actor_typeType of actor.
actor_account_uuid1Password account identifier of the actor.
account_uuid1Password account identifier.
actionAction performed.1 detection rule
object_typeType of affected object.1 detection rule
object_uuidIdentifier of the affected object.
object_details.uuidAffected user identifier, when applicable.
object_details.nameAffected user's full name, when applicable.
object_details.emailAffected user's email address, when applicable.
aux_idNumeric identifier for related event data.
aux_uuidIdentifier for related event data.
aux_details.uuidRelated user identifier, when applicable.
aux_details.nameRelated user's full name, when applicable.
aux_details.emailRelated user's email address, when applicable.
aux_infoAdditional event information.
session.uuidSession identifier.
session.login_timeTime the session started.
session.device_uuidIdentifier of the session device.
session.ipIP address used for the session.
location.countryClient country inferred from IP address.
location.regionClient region inferred from IP address.
location.cityClient city inferred from IP address.
location.longitudeClient longitude inferred from IP address.
location.latitudeClient latitude inferred from IP address.

Example Event #

{
  "uuid": "N2W5JS4HXGXPEOR2RLKNOOC6GL",
  "timestamp": "12/15/2023, 11:00:37.305 AM",
  "location": {
    "country": "The Netherlands",
    "region": "North Holland",
    "city": "Amsterdam",
    "latitude": 52.3759,
    "longitude": 4.8975
  },
  "actor_uuid": "AVHAFAP4PRDF5K3724I67N3CEU",
  "actor_details": {
    "uuid": "AVHAFAP4PRDF5K3724I67N3CEU",
    "name": "Automated User Provisioning",
    "email": "zkv4c3mauxjbw@1passwordserviceaccounts.com"
  },
  "action": "suspend",
  "object_type": "user",
  "object_uuid": "AONGS2F7BFFPNG2LBTFMRH562Q",
  "object_details": {
    "uuid": "AONGS2F7BFFPNG2LBTFMRH562Q",
    "name": "Gideon Wories",
    "email": "gideon.wories@securehats.nl"
  },
  "session": {
    "uuid": "TPEFXHZ62ZGTHCHMSNEMLLDPMA",
    "login_time": "2023-12-14T11:39:44.9931456Z",
    "device_uuid": "pjleru42mvdhql4nl7mab6ympm",
    "ip": "4.175.88.205"
  }
}

Detection Patterns #

Common Indicators #

Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.

FieldKindValueRulesVendors
action (kusto rule field)eqdelete1 rulekusto
action (kusto rule field)eqexport1 rulekusto
object_type (kusto rule field)equser1 rulekusto
object_type (kusto rule field)eqvault1 rulekusto

References #

user-tdvcsso: Enroll Trusted Device

#

Description

A user set up a trusted device to unlock with SSO.

Fields #

NameDescription
uuidUnique event identifier.
timestampTime the event occurred.
actor_uuidActor identifier.
actor_details.uuidActor identifier.
actor_details.nameActor's full name.
actor_details.emailActor's email address.
actor_typeType of actor.
actor_account_uuid1Password account identifier of the actor.
account_uuid1Password account identifier.
actionAction performed.
object_typeType of affected object.
object_uuidIdentifier of the affected object.
object_details.uuidAffected user identifier, when applicable.
object_details.nameAffected user's full name, when applicable.
object_details.emailAffected user's email address, when applicable.
aux_idNumeric identifier for related event data.
aux_uuidIdentifier for related event data.
aux_details.uuidRelated user identifier, when applicable.
aux_details.nameRelated user's full name, when applicable.
aux_details.emailRelated user's email address, when applicable.
aux_infoAdditional event information.
session.uuidSession identifier.
session.login_timeTime the session started.
session.device_uuidIdentifier of the session device.
session.ipIP address used for the session.
location.countryClient country inferred from IP address.
location.regionClient region inferred from IP address.
location.cityClient city inferred from IP address.
location.longitudeClient longitude inferred from IP address.
location.latitudeClient latitude inferred from IP address.

Example Event #

{
  "uuid": "DUMMY-ID-0005",
  "action": "tdvcsso",
  "session": {
    "uuid": "DUMMY-ID-0006",
    "login_time": "2026-08-08T05:24:35.851548919Z",
    "device_uuid": "DUMMY-ID-0007",
    "ip": "2001:db8::2"
  },
  "aux_uuid": "DUMMY-ID-0007",
  "location": {
    "country": "Dummy Country 002",
    "region": "Dummy Region 002",
    "city": "Dummy City 002",
    "latitude": 0.0,
    "longitude": 0.0
  },
  "timestamp": "2026-08-08T05:24:39.189355795Z",
  "actor_type": "user",
  "actor_uuid": "DUMMY-USER-0003",
  "object_type": "user",
  "object_uuid": "DUMMY-USER-0003",
  "account_uuid": "DUMMY-ID-0004",
  "actor_details": {
    "uuid": "DUMMY-USER-0003",
    "name": "Dummy User 003",
    "email": "dummy.user003@example.invalid"
  },
  "object_details": {
    "uuid": "DUMMY-USER-0003",
    "name": "Dummy User 003",
    "email": "dummy.user003@example.invalid"
  }
}

References #

user-trvlaway: Mark User Away For Travel

#

Description

A user was marked as away for travel.

Fields #

NameDescription
uuidUnique event identifier.
timestampTime the event occurred.
actor_uuidActor identifier.
actor_details.uuidActor identifier.
actor_details.nameActor's full name.
actor_details.emailActor's email address.
actor_typeType of actor.
actor_account_uuid1Password account identifier of the actor.
account_uuid1Password account identifier.
actionAction performed.
object_typeType of affected object.
object_uuidIdentifier of the affected object.
object_details.uuidAffected user identifier, when applicable.
object_details.nameAffected user's full name, when applicable.
object_details.emailAffected user's email address, when applicable.
aux_idNumeric identifier for related event data.
aux_uuidIdentifier for related event data.
aux_details.uuidRelated user identifier, when applicable.
aux_details.nameRelated user's full name, when applicable.
aux_details.emailRelated user's email address, when applicable.
aux_infoAdditional event information.
session.uuidSession identifier.
session.login_timeTime the session started.
session.device_uuidIdentifier of the session device.
session.ipIP address used for the session.
location.countryClient country inferred from IP address.
location.regionClient region inferred from IP address.
location.cityClient city inferred from IP address.
location.longitudeClient longitude inferred from IP address.
location.latitudeClient latitude inferred from IP address.

References #

user-trvlback: Mark User Back From Travel

#

Description

A user was marked as back from travel.

Fields #

NameDescription
uuidUnique event identifier.
timestampTime the event occurred.
actor_uuidActor identifier.
actor_details.uuidActor identifier.
actor_details.nameActor's full name.
actor_details.emailActor's email address.
actor_typeType of actor.
actor_account_uuid1Password account identifier of the actor.
account_uuid1Password account identifier.
actionAction performed.
object_typeType of affected object.
object_uuidIdentifier of the affected object.
object_details.uuidAffected user identifier, when applicable.
object_details.nameAffected user's full name, when applicable.
object_details.emailAffected user's email address, when applicable.
aux_idNumeric identifier for related event data.
aux_uuidIdentifier for related event data.
aux_details.uuidRelated user identifier, when applicable.
aux_details.nameRelated user's full name, when applicable.
aux_details.emailRelated user's email address, when applicable.
aux_infoAdditional event information.
session.uuidSession identifier.
session.login_timeTime the session started.
session.device_uuidIdentifier of the session device.
session.ipIP address used for the session.
location.countryClient country inferred from IP address.
location.regionClient region inferred from IP address.
location.cityClient city inferred from IP address.
location.longitudeClient longitude inferred from IP address.
location.latitudeClient latitude inferred from IP address.

References #

user-updatmfa: Update Multi-Factor Authentication

#

Description

Multi-factor authentication was updated.

Fields #

NameDescription
uuidUnique event identifier.
timestampTime the event occurred.
actor_uuidActor identifier.
actor_details.uuidActor identifier.
actor_details.nameActor's full name.
actor_details.emailActor's email address.
actor_typeType of actor.
actor_account_uuid1Password account identifier of the actor.
account_uuid1Password account identifier.
actionAction performed.
object_typeType of affected object.
object_uuidIdentifier of the affected object.
object_details.uuidAffected user identifier, when applicable.
object_details.nameAffected user's full name, when applicable.
object_details.emailAffected user's email address, when applicable.
aux_idNumeric identifier for related event data.
aux_uuidIdentifier for related event data.
aux_details.uuidRelated user identifier, when applicable.
aux_details.nameRelated user's full name, when applicable.
aux_details.emailRelated user's email address, when applicable.
aux_infoAdditional event information.
session.uuidSession identifier.
session.login_timeTime the session started.
session.device_uuidIdentifier of the session device.
session.ipIP address used for the session.
location.countryClient country inferred from IP address.
location.regionClient region inferred from IP address.
location.cityClient city inferred from IP address.
location.longitudeClient longitude inferred from IP address.
location.latitudeClient latitude inferred from IP address.

Example Event #

The source export stringifies aux_id; the 1Password Events API schema defines aux_id as an integer.

{
  "uuid": "TEJZL5OGDWBDXBIB622S2TR3FD",
  "timestamp": "1/3/2024, 2:46:26.200 PM",
  "location": {
    "country": "South Africa",
    "region": "Western Cape",
    "city": "Cape Town",
    "latitude": -33.91,
    "longitude": 18.4304
  },
  "actor_uuid": "Q3IELCBNUFAYXAECYF6FHCLXXQ",
  "actor_details": {
    "uuid": "Q3IELCBNUFAYXAECYF6FHCLXXQ",
    "name": "Nigel Powers",
    "email": "nigel.powers@securehats.nl"
  },
  "action": "updatmfa",
  "object_type": "user",
  "object_uuid": "Q3IELCBNUFAYXAECYF6FHCLXXQ",
  "object_details": {
    "uuid": "Q3IELCBNUFAYXAECYF6FHCLXXQ",
    "name": "Nigel Powers",
    "email": "nigel.powers@securehats.nl"
  },
  "aux_id": "1487957",
  "aux_info": "T",
  "session": {
    "uuid": "4PEKJD4YRBDNNEJ5QYHJ5XMECI",
    "login_time": "2024-01-03T14:46:26.1592782Z",
    "device_uuid": "wztcewt57uwnhze3ktqe2kkwyu",
    "ip": "165.0.36.133"
  }
}

References #

user-upguest: Upgrade User

#

Description

A guest was promoted to a family or team member.

Fields #

NameDescription
uuidUnique event identifier.
timestampTime the event occurred.
actor_uuidActor identifier.
actor_details.uuidActor identifier.
actor_details.nameActor's full name.
actor_details.emailActor's email address.
actor_typeType of actor.
actor_account_uuid1Password account identifier of the actor.
account_uuid1Password account identifier.
actionAction performed.
object_typeType of affected object.
object_uuidIdentifier of the affected object.
object_details.uuidAffected user identifier, when applicable.
object_details.nameAffected user's full name, when applicable.
object_details.emailAffected user's email address, when applicable.
aux_idNumeric identifier for related event data.
aux_uuidIdentifier for related event data.
aux_details.uuidRelated user identifier, when applicable.
aux_details.nameRelated user's full name, when applicable.
aux_details.emailRelated user's email address, when applicable.
aux_infoAdditional event information.
session.uuidSession identifier.
session.login_timeTime the session started.
session.device_uuidIdentifier of the session device.
session.ipIP address used for the session.
location.countryClient country inferred from IP address.
location.regionClient region inferred from IP address.
location.cityClient city inferred from IP address.
location.longitudeClient longitude inferred from IP address.
location.latitudeClient latitude inferred from IP address.

References #

user-verify: Change User State From

#

Description

A user's state was changed.

Fields #

NameDescription
uuidUnique event identifier.
timestampTime the event occurred.
actor_uuidActor identifier.
actor_details.uuidActor identifier.
actor_details.nameActor's full name.
actor_details.emailActor's email address.
actor_typeType of actor.
actor_account_uuid1Password account identifier of the actor.
account_uuid1Password account identifier.
actionAction performed.
object_typeType of affected object.
object_uuidIdentifier of the affected object.
object_details.uuidAffected user identifier, when applicable.
object_details.nameAffected user's full name, when applicable.
object_details.emailAffected user's email address, when applicable.
aux_idNumeric identifier for related event data.
aux_uuidIdentifier for related event data.
aux_details.uuidRelated user identifier, when applicable.
aux_details.nameRelated user's full name, when applicable.
aux_details.emailRelated user's email address, when applicable.
aux_infoAdditional event information.
session.uuidSession identifier.
session.login_timeTime the session started.
session.device_uuidIdentifier of the session device.
session.ipIP address used for the session.
location.countryClient country inferred from IP address.
location.regionClient region inferred from IP address.
location.cityClient city inferred from IP address.
location.longitudeClient longitude inferred from IP address.
location.latitudeClient latitude inferred from IP address.

References #