Rules
| eventName | Description | Sample | Rule |
|---|---|---|---|
| any | Source-only rules that filter on applicationName 'rules' without specifying an eventName attribute here. | N | Y |
| rule_ | A data protection or DLP rule matched content in a Google Workspace service. | N | N |
| rule_ | A configured rule was triggered by user activity. | N | N |
| action_ | An automated action defined by a rule completed execution. | N | N |
| label_ | A sensitivity or classification label was applied to a document by a rule. | N | N |
| label_ | A sensitivity label was removed from a document by a rule. | N | N |
| label_ | A field value within a document label was changed. | N | N |
any: Rules (any event)
#Description
Source-only rules that filter on applicationName 'rules' without specifying an eventName attribute here.
Detection Fields #
Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema.
| Name | Rules | Vendors |
|---|---|---|
id.applicationName | 1 detection rule | Panther |
parameters.triggered_actions | 1 detection rule | Panther |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
References #
rule_match: Rule Match
#Description
A data protection or DLP rule matched content in a Google Workspace service.
References #
action_complete: Action Complete
#Description
An automated action defined by a rule completed execution.
References #
label_applied: Label Applied
#Description
A sensitivity or classification label was applied to a document by a rule.
References #
label_removed: Label Removed
#Description
A sensitivity label was removed from a document by a rule.