Skip to main content

SharePoint Online JSON Log File

The JSON log file format is used to send SharePoint Online activity monitoring data to Access Analyzer v10.0 consoles. The following information lists all of the attributes generated by SharePoint Online Activity Monitor into a JSON log file:

Base Schema

The following table details lists of attributes for base schema generated by SharePoint Online Activity Monitor.

Attribute NameDescriptionExample
TimeLoggedEvent time (UTC)2019-03-14T18:13:39.0 00Z
ActivityTypeConstant "SharePoint"SharePointOnline
AgentHostHost name where agent is installed.sphost
SourceSharePoint, SharePointFileOperation, SharePointListOperation, SharePointListItemOperation, SharePointContentTypeOperation, SharePointFieldOperation, SharePointSharingOperation, ComplianceDLPSharePoint, ComplianceDLPSharePointClassificationSharePointFileOperation
IdUnique id of an audit record5ed5f834-7609-4ea6-df9b-08d76f79a875
EventTypeAccessInvitationCreated AccessInvitationExpired AccessInvitationRevoked AccessInvitationUpdated AccessRequestApproved AccessRequestCreated AccessRequestRejected ActivationEnabled AdministratorAddedToTermStore AdministratorDeletedFromTermStore AllowGroupCreationSet AppCatalogCreated AuditPolicyRemoved AuditPolicyUpdate AzureStreamingEnabledSet CollaborationTypeModified ConnectedSiteSettingModified CreateSSOApplication CustomFieldOrLookupTableCreated CustomFieldOrLookupTableDeleted CustomFieldOrLookupTableModified CustomizeExemptUsers DefaultLanguageChangedInTermStore DelegateModified DelegateRemoved DeleteSSOApplication eDiscoveryHoldApplied eDiscoveryHoldRemoved eDiscoverySearchPerformed EngagementAccepted EngagementModified EngagementRejected EnterpriseCalendarModified EntityDeleted EntityForceCheckedIn ExemptUserAgentSet FileAccessed FileCheckOutDiscarded FileCheckedIn FileCheckedOut FileCopied FileDeleted FileDeletedFirstStageRecycleBin FileDeletedSecondStageRecycleBin FileDownloaded FileFetched FileModified FileMoved FilePreviewed FileRenamed FileRestored FileSyncDownloadedFull FileSyncDownloadedPartial FileSyncUploadedFull FileSyncUploadedPartial FileUploaded FileViewed FolderCopied FolderCreated FolderDeleted FolderDeletedFirstStageRecycleBin FolderDeletedSecondStageRecycleBin FolderModified FolderMoved FolderRenamed FolderRestored GroupAdded GroupRemoved GroupUpdated LanguageAddedToTermStore LanguageRemovedFromTermStore LegacyWorkflowEnabledSet LookAndFeelModified ManagedSyncClientAllowed MaxQuotaModified MaxResourceUsageModified MySitePublicEnabledSet NewsFeedEnabledSet ODBNextUXSettings OfficeOnDemandSet PageViewed PeopleResultsScopeSet PermissionSyncSettingModified PermissionTemplateModified PortfolioDataAccessed PortfolioDataModified PreviewModeEnabledSet ProjectAccessed ProjectCheckedIn ProjectCheckedOut ProjectCreated ProjectDeleted ProjectForceCheckedIn ProjectModified ProjectPublished ProjectWorkflowRestarted PWASettingsAccessed PWASettingsModified QueueJobStateModified QuotaWarningEnabledModified RenderingEnabled ReportingAccessed ReportingSettingModified ResourceAccessed ResourceCheckedIn ResourceCheckedOut ResourceCreated ResourceDeleted ResourceForceCheckedIn ResourceModified ResourcePlanCheckedInOrOut ResourcePlanModified ResourcePlanPublished ResourceRedacted ResourceWarningEnabledModified SSOGroupCredentialsSet SSOUserCredentialsSet SearchCenterUrlSet SecondaryMySiteOwnerSet SecurityCategoryModified SecurityGroupModified SendToConnectionAdded SendToConnectionRemoved SharedLinkCreated SharedLinkDisabled SharingInvitationAccepted SharingRevoked SharingSet SiteAdminChangeRequest SiteCollectionAdminAdded SiteCollectionCreated SiteRenamed StatusReportModified SyncGetChanges TaskStatusAccessed TaskStatusApproved TaskStatusRejected TaskStatusSaved TaskStatusSubmitted TimesheetAccessed TimesheetApproved TimesheetRejected TimesheetSaved TimesheetSubmitted UnmanagedSyncClientBlocked UpdateSSOApplication UserAddedToGroup UserRemovedFromGroup WorkflowModifiedFileDeleted
OrganizationIdOrganization tenant ID86e5dcbf-56e9-4452-8c43-1e99f0e9aabd
UserTypeType of the user performed the operation.Regular
UserIdThe UPN of the user who performed the operationuser1@stealthbitstechnologie.onmicrosoft.com
UserNameName of the user who performed the operationUser1
UserLoginAn alternative ID of the user. "DlpAgent" for DLP eventsi:0h.f/membership/10033fff8a7ae322@live.com
ClientIPIP address of the user or a trusted application75.155.180.82
ProtocolProtocol: HTTPSHTTPS
WorkloadOffice 365 service where the activty occurred.SharePoint
ResultStatusSucceeded, ParticallySucceeded, Failed, True, FalseParticallySucceeded
AbsoluteUrlFull path of the file/folder accessed by the userhttps://stealthbitstechnologie-my.sharepoint.com/personal/sgiles_stealthbitstechnologie_onmicrosoft_com/personal/myfiles/21ded
ScopeWas this event created by a hosted O365 service or an on-premises server? online or onprem
SiteIdGuid of the siteaef1ad6b-11c5-4b25-a669-b5f8379f8c55
ItemTypeObject type: File, Folder, Web, Site, Tenant, DocumentLibrary, Page, Differs from SP typesFile
ItemTitle
EventSourceSharePoint or ObjectModelSharePoint
UserAgentUser client or browser
MachineDomainInfoInformation about device sync operations
MachineIdInformation about device sync operations
UpdateTypeAdded, Removed, or UpdatedAdded
VersionThe new version of the document/version of deleted document1

File/Folder Operations

The following table details lists of attributes for file/folder operations generated by SharePoint Online Activity Monitor.

Attribute NameDescriptionExample
SiteUrlURL of the sitehttps://example-url.sharepoint.com/
DocLocationRelative URL of the file or document accessed by the userShared Documents/100 Sensitive Docs/Document.docx
SourceRelativeUrlThe URL of the folder that contains the file accessed by the user. The combination of the values for the SiteURL, SourceRelativeURL, and SourceFileName parameters is the same as the value for the AbsoluteUrl propertyShared Documents/100 Sensitive Docs
SourceFileNameFile or folder nameMy Document.docx
SourceFileExtensionFile extensiondocx
NewDocLocationA relative URL to which the object is copied or movedShared Documents/100 Sensitive Docs/Copy.docx
DestinationRelativeUrlOnly for EventType: FileCopied, FileMoved The URL of the destination folder where a file is copied or moved.Shared Documents/100 Sensitive Docs
DestinationFileNameOnly for EventType: FileCopied, FileMoved The name of the file that is copied or moved.Copy.docx
DestinationFileExtensionOnly for EventType: FileCopied, FileMoveddocx

Sharing

The following table details lists of attributes for sharing generated by SharePoint Online Activity Monitor by Sharing.

Attribute NameDescription
SharingTypeThe type of sharing permissions that were assigned to the user that the resource was shared with
TargetUserOrGroupNameUPN or name of the target user or group that a resource was shared with
TargetUserOrGroupTypeMember, Guest, Group, or Partner
EventData

Other SharePoint Events

The following table details lists of attributes for other SharePoint events generated by SharePoint Online Activity Monitor by Sharing.

Attribute NameDescription
CustomEvent
EventDataOptional payload
ModifiedPropertiesThe property is included for admin events, such as adding a user as a member of a site or a site collection admin group. The property includes the name of the property that was modified, old, and new value

DLP Events

The following table details lists of attributes for DLP events generated by SharePoint Online Activity Monitor by Sharing.

Attribute NameDescriptionExample
SharePointMetaDataMetadata about the document that contained the sensitive informationhttps://docs.microsoft.com/en-us/office/office-365-management-api/office-365-management-activity-api-schema#sharepointmetadata-complex-type
ExceptionInfoReasons why a policy no longer applies and any information about false positive or override
PolicyDetailsPolicy(s) that triggered the eventhttps://docs.microsoft.com/en-us/office/office-365-management-api/office-365-management-activity-api-schema#policydetails-complex-type
SensitiveInfoDetectionIsIncludedIndicates whether the event contains the value of the sensitive data type