List of all event_class_id types - CAS-SIEM Integration.

%3CLINGO-SUB%20id%3D%22lingo-sub-187338%22%20slang%3D%22en-US%22%3EList%20of%20all%20event_class_id%20types%20-%20CAS-SIEM%20Integration.%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-187338%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20everyone%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20been%20using%20Cloud%20App%20Security%20for%20a%20few%20months%20now%20and%20overall%20I%20have%20found%20it%20very%20useful.%20It%20gives%20a%20very%20good%20level%20of%20visibility%20into%20O365%20and%20the%20Alerting%20is%20useful%20too.%26nbsp%3B%20Good%20work%20-%20thank%20you.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20do%20find%20it%20difficult%20to%20find%20the%20correct%20MS%20documentation%20though.%26nbsp%3B%26nbsp%3BIs%20there%20a%20list%20of%20all%20the%26nbsp%3B%3CSPAN%3EEVENT_CATEGORY_*%20types%3F%26nbsp%3B%20E.g.%26nbsp%3BEVENT_CATEGORY_LOGIN%2C%26nbsp%3BEVENT_CATEGORY_UPDATE_USER%2C%26nbsp%3BEVENT_CATEGORY_SET_FORWARDING_MAILBOX%20etc.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EThanks%20for%20reading%2C%20regards%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-187338%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3ECloud%20App%20Security%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-187342%22%20slang%3D%22en-US%22%3ERe%3A%20List%20of%20all%20event_class_id%20types%20-%20CAS-SIEM%20Integration.%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-187342%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Jagdip%2C%3C%2FP%3E%0A%3CP%3EThe%20categories%20correspond%20to%20the%20categories%20you%20can%20find%20under%20the%20Activity%20Type%20filter.%3C%2FP%3E%0A%3CP%3EThere%20isnt%20a%20written%20list%20as%20its%20constantly%20updating%20and%20changing.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ERegards%2C%3C%2FP%3E%0A%3CP%3EDima.%3C%2FP%3E%3C%2FLINGO-BODY%3E
New Contributor

Hi everyone

 

I have been using Cloud App Security for a few months now and overall I have found it very useful. It gives a very good level of visibility into O365 and the Alerting is useful too.  Good work - thank you.

 

I do find it difficult to find the correct MS documentation though.  Is there a list of all the EVENT_CATEGORY_* types?  E.g. EVENT_CATEGORY_LOGIN, EVENT_CATEGORY_UPDATE_USER, EVENT_CATEGORY_SET_FORWARDING_MAILBOX etc.

 

Thanks for reading, regards

 

1 Reply

Hi Jagdip,

The categories correspond to the categories you can find under the Activity Type filter.

There isnt a written list as its constantly updating and changing.

 

Regards,

Dima.