Skip to main content

Events Table Attributes

The Events table provides detailed information about each event that has occurred. It includes fields that describe the event itself, the file involved, the applications used, and the user's interaction.

The following table provides the list of event attributes that are displayed in the table.

Column NameDescription
App commandlineThe command line used to start the application involved in the event.
App descriptionA description of the application involved in the event.
App main window titleThe title of the main window of the application that generated the event.
App nameThe name of the application that was part of the event.
App package nameThe package name for modern Windows applications involved in the event.
BlockedA flag indicating whether the event was blocked by a policy.
Browser page domainThe domain extracted from the referrer URL of the browser page.
Browser page titleThe title of the browser page where the event occurred.
Browser page urlThe referrer URL of the browser page.
Cloud access levelThe cloud sharing access role type, such as viewer, editor, or commenter.
Cloud appThe type of cloud application, for example, OneDrive, SharePoint, or Google Drive.
Cloud app accountThe user account used to log in to the cloud application.
Cloud destination accountThe email addresses of the cloud app accounts that have been granted sharing access as a destination for the data.
Cloud destination groupsThe group name in the cloud application that has been granted sharing access as a destination for the data.
Cloud domainThe domain of the cloud application.
Cloud messaging groupsThe source or destination group name in the cloud messaging app.
Cloud messaging usersThe source or destination username in the cloud messaging app.
Cloud providerThe type of cloud provider storing the data, for example, Office 365 or Salesforce.
Cloud scopeThe scope of users with cloud sharing access, for example, user, group, or anyone.
Cloud workspaceThe workspace name of the cloud application (e.g., in Slack or other collaboration apps).
Content identification policiesThe policies that matched the event's content, if any.
Content uriThe URL path of the content involved in the event.
Data sizeThe size of a piece of data involved in the event, such as data copied and pasted.
DatasetThe dataset used to classify the data that was involved in the event.
Destination file pathThe specific location where the data resides after the event.
Destination location outlineThe type of destination location for the event, such as endpoint, website, etc.
Destination typeA short outline of the destination location (e.g., node, hostname for an endpoint; email for cloud; device name for removable media).
Document tagsAny document tags applied to the document containing the sensitive data.
DomainThe domain name where the event occurred, in the format sub.domain.tld.
Domain categoryA classification that categorizes domains based on content type, purpose, or industry.
Email accountThe email address identifying a mailbox where the data involved in the event resides.
Email groupsThe geographic location of the email account.
Endpoint idAn identifier for the endpoint where the event was generated.
Event timeThe time at which the event occurred.
Event typeThe type of event that led to data arriving or leaving a location.
Exact data matchThe exact data match attributes that were found in the event.
Fail close statusesThe status of a policy when the policy response pop-up was not displayed to the user due to a session timeout or device connectivity issues.
FileThe name of the file involved in the event.
File extensionThe file type or extension of the file.
File sizeThe size of the file in bytes.
Group nameThe list of Active Directory groups to which the user belongs.
HostnameThe hostname of the endpoint or share where the data resides.
Local machine nameThe hostname of the machine where the event happened.
Local time utcThe time in UTC when the event occurred.
Local user nameThe username of the user who caused the event.
Local user sidThe Security Identifier (SID) of the user who caused the event.
Md5 hashThe MD5 hash of the file involved in the event.
Media categoryThe type of removable media used, if applicable.
Notion account idThe unique ID of the Notion account involved in the event.
Notion account nameThe name of the Notion account involved in the event.
Notion page full pathThe full path of the Notion page involved in the event.
Notion page idThe unique ID of the Notion page involved in the event.
Notion page nameThe name of the Notion page involved in the event.
PolicyThe policy that matched the event.
Printer nameThe name of the printer used for the event.
Removable device nameThe name of the removable device used.
Removable device product idThe 16-bit number assigned to a specific USB device model.
Removable device vendor idThe 16-bit number assigned to the USB device manufacturer.
Repository nameThe name of the repository containing the data.
Repository organizationThe organization structure of the content repository.
Salesforce account domainsThe Salesforce domain name from the user's email address.
Salesforce account idThe unique ID of the Salesforce account involved in the event.
Salesforce account nameThe name of the Salesforce account involved in the event.
Salesforce opportunity idThe unique ID of the Salesforce opportunity involved in the event.
Salesforce opportunity nameThe name of the Salesforce opportunity involved in the event.
Salesforce report idThe unique ID of the Salesforce report involved in the event.
Salesforce report nameThe name of the Salesforce report involved in the event.
Sensor typeThe type of sensor that generated the event (e.g., Endpoint Sensor, Cloud Sensor).
SensitivityThe sensitivity rating assigned in the dataset definition. Possible values include Critical, High, Moderate, Low, and Unrestricted.
SeverityThe severity of the event as defined in the policy. Possible values include Critical, High, Medium, Low, and Informational.
Sha256 hashThe SHA256 hash of the file involved in the event.
Source file pathThe file path location of the source containing the data.
Source location outlineThe type of source location for the event, such as endpoint, website, etc.
Source typeA short outline of the source location (e.g., node, hostname for an endpoint; email for cloud; device name for removable media).
Temporary blockedThis applies when an action is blocked temporarily because a policy is triggered multiple times in a short duration due to throttling.
UrlThe exact URL used to access the data.
UsersThe user who caused the event.