Skip to main content

SharePoint TSV Log File

The TSV log file format is used to send SharePoint activity monitoring data to Access Analyzer v10.0 and earlier consoles. The following information lists all of the columns generated by SharePoint Activity Monitor into a TSV log file:

Column NameDescription
Operation TimeDate timestamp of the event in UTC time
HostHost name of the monitored device as entered by the user
UserSid/UidUnique identifier for the SharePoint user: - For CIFS activity – user SID - For NFS activity – UID
User NameSharePoint user name
UserIDID of the SharePoint user
UserLoginIdentity claims using encoding format for user login
PathTruncated path where the event took place, e.g. sites/TestSite/Shared Documents/Testing.txt
ProtocolProtocol of the event
FullPathFull path where the event took place, e.g. http://sharepoint.local/sites/TestSite/Shared Documents/Testing.txt
WebApplicationTitle of the SharePoint web application
SiteIdID of the site collection
SiteUrlURL of the site collection
WebTitleTitle of the site collection
DocLocationLocation of the document
ItemIDID of the item
ItemTitleTitle of the item
Item TypeType of item
EventTypeType of SharePoint event
EventSourceSource where the event came from
LocationTypeLocation type of the SharePoint document location
AppPrincipalIdApplication principal ID
SourceNameName of the source
EventDataRaw event data
ParamParameters for the event