Ticketing System (TS)

Application login

Application login operations include:

  • Application sign in success
  • Application sign in failure
Fields in the log entry that contain audit information
Audit metadata Audit field name Value
User or service identity user

jimmy.watchcommander

(Also present: user_id=8e3e...)

Target / Mode

mode

login

(Also relevant: url=/login.do)

Action / Event

event

LOGIN_SUCCESS

Event timestamp Time

1669936335020

(Epoch milliseconds, corresponds to Thu, 01 Dec 2022 18:12:15.020 GMT)

Source of action source_ip, host, http_uagent

Source IP: 10.253.168.66

Host: as1

User Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36

Outcome event

LOGIN_SUCCESS

Other useful fields session_id, user_roles, log_type

Session ID: 5307B5

User Roles: sn_request_read

Log Type: SECLOG

Host: as1

Example log

Time=1669936335020 host=as1 Default-thread-23  event="LOGIN_SUCCESS" authentication_multi_factor_enabled="false" mode="login" authentication_parameter1="user_name=jimmy.watchcommander" user_roles="sn_request_read" log_type="SECLOG" session_id="5307B5" source_ip="10.253.168.66" tx_num="2985" url="/login.do" domain="global" http_last_time="1668193688784" jsession_id="A6F412" http_uagent="Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36" user="jimmy.watchcommander" user_id="8e3e1d3b872a5910f91431dd0ebb357c" http_time_zone="America/New_York" user_group="[c92a31ea979d5910ea2a7b021153af00, 9a293b0897155110ea2a7b021153af84]" http_browser="chrome"