This article provides the list of cybersecurity events that you can export using the Druva Cloud Platform Events API.
About Druva Cloud Platform Events API
Using the Events API, you can export the supported cybersecurity events. Here are its benefits:
- Get all the cybersecurity events in a single API call
- Monitor the reported failures and threats, and take corrective actions
- Integrate the exported events with the third-party SIEM tool
Supported events
The category of the event. The possible values are: EVENT
AUDIT
ALERT
.
Properties
Time at which the event was generated.
Unique ID of the resource for which the event is generated.
Reason for the error.
Name of the resource for which the event is generated.
Type of the resource for which the event is generated.
Snapshot ID of the affected snapshot.
Parent ID of the resource for which the event is generated.
Parent name of the resource for which the event is generated.
Type of the entity for which the event has happened.
Represents the global ID of the customer or MSP.
The epoch representation of the time at which the event occurred.
Syslog standard of defining the event origin/type.
SyslogSeverity represents the severity(0-7) of the event.
Type of the event. For example, 'SystemEvent' or 'UserRestore'. This event's title is its type.
The category of the event. The possible values are: EVENT
AUDIT
ALERT
.
Properties
Name of the alert. The possible values are:
Unusual Data Activity
.
Type of the UDA operation.
Time at which the operation was performed.
Unique ID of the resource for which the operation was performed.
Name of the resource for which the operation was performed.
Type of the resource for which the operation was performed.
Parent ID of the resource for which the operation was performed.
Parent name of the resource for which the operation was performed.
Reason for the encryption.
Snapshot timestamp of the affected snapshot
Properties
Number of new files.
Number of updated files.
Number of deleted files.
Number of encrypted files.
Or
Properties
Name of the alert. The possible values are:
Admin Login Event - New Location
.
Location from where the admin logged in.
Name of the admin who logged in.
Time at which the admin logged in.
Email of the admin who logged in.
Result of the login operation. The possible values are:
Success
Failure
.
IP address of the admin who logged in.
Or
Properties
Name of the alert. The possible values are:
Data Access Alert - New Location
.
Type of the data access. The possible values are:
User Download
User Restore
Admin Download
Admin Restore
.
Number of files restored.
Size of the data restored.
Status of the restore operation. The possible values are:
Successful
Failed
.
Time at which the restore operation started.
Time at which the restore operation ended.
Unique ID of the resource for which the event is generated.
Name of the resource for which the event is generated.
IP address of the target machine where the data is restored.
Location of the target machine where the data is restored.
Name of the user who initiated the restore operation.
Type of the entity for which the event has happened.
Represents the global ID of the customer or MSP.
The epoch representation of the time at which the event occurred.
Syslog standard of defining the event origin/type.
SyslogSeverity represents the severity(0-7) of the event.
Type of the event. For example, 'SystemEvent' or 'UserRestore'. This event's title is its type.
The category of the event. The possible values are: EVENT
AUDIT
ALERT
.
Properties
Number of files restored.
Size of the data restored.
Status of the restore operation. The possible values are:
Successful
Failed
.
Time at which the restore operation started.
Time at which the restore operation ended.
Unique ID of the resource for which the event is generated.
Name of the resource for which the event is generated.
IP address of the target machine where the data is restored.
Location of the target machine where the data is restored.
Name of the user who initiated the restore operation.
Type of the entity for which the event has happened.
Represents the global ID of the customer or MSP.
The epoch representation of the time at which the event occurred.
Syslog standard of defining the event origin/type.
SyslogSeverity represents the severity(0-7) of the event.
Type of the event. For example, 'SystemEvent' or 'UserRestore'. This event's title is its type.
The category of the event. The possible values are: EVENT
AUDIT
ALERT
.
Properties
Number of files downloaded.
Size of the data downloaded.
Status of the download operation. The possible values are:
Successful
Failed
.
Time at which the download operation started.
Time at which the download operation ended.
Unique ID of the resource for which the event is generated.
Name of the resource for which the event is generated.
IP address of the target machine where the data is downloaded.
Location of the target machine where the data is downloaded.
Name of the user who initiated the download operation.
Type of the entity for which the event has happened.
Represents the global ID of the customer or MSP.
The epoch representation of the time at which the event occurred.
Syslog standard of defining the event origin/type.
SyslogSeverity represents the severity(0-7) of the event.
Type of the event. For example, 'SystemEvent' or 'UserRestore'. This event's title is its type.
The category of the event. The possible values are: EVENT
AUDIT
ALERT
.
Properties
Number of files restored.
Size of the data restored.
Status of the restore operation. The possible values are:
Successful
Failed
.
Time at which the restore operation started.
Time at which the restore operation ended.
Unique ID of the resource for which the event is generated.
Name of the resource for which the event is generated.
IP address of the target machine where the data is restored.
Location of the target machine where the data is restored.
Name of the user who initiated the restore operation.
Type of the entity for which the event has happened.
Represents the global ID of the customer or MSP.
The epoch representation of the time at which the event occurred.
Syslog standard of defining the event origin/type.
SyslogSeverity represents the severity(0-7) of the event.
Type of the event. For example, 'SystemEvent' or 'UserRestore'. This event's title is its type.
The category of the event. The possible values are: EVENT
AUDIT
ALERT
.
Properties
Number of files downloaded.
Size of the data downloaded.
Status of the download operation. The possible values are:
Successful
Failed
.
Time at which the download operation started.
Time at which the download operation ended.
Unique ID of the resource for which the event is generated.
Name of the resource for which the event is generated.
IP address of the target machine where the data is downloaded.
Location of the target machine where the data is downloaded.
Name of the user who initiated the download operation.
Type of the entity for which the event has happened.
Represents the global ID of the customer or MSP.
The epoch representation of the time at which the event occurred.
Syslog standard of defining the event origin/type.
SyslogSeverity represents the severity(0-7) of the event.
Type of the event. For example, 'SystemEvent' or 'UserRestore'. This event's title is its type.
The category of the event. The possible values are: EVENT
AUDIT
ALERT
.
Properties
Number of files restored.
Size of the data restored.
Status of the restore operation. The possible values are:
Successful
Failed
.
Time at which the restore operation started.
Time at which the restore operation ended.
Unique ID of the resource for which the event is generated.
Name of the resource for which the event is generated.
IP address of the target machine where the data is restored.
Location of the target machine where the data is restored.
Name of the user who initiated the restore operation.
Type of the entity for which the event has happened.
Represents the global ID of the customer or MSP.
The epoch representation of the time at which the event occurred.
Syslog standard of defining the event origin/type.
SyslogSeverity represents the severity(0-7) of the event.
Type of the event. For example, 'SystemEvent' or 'UserRestore'. This event's title is its type.
The category of the event. The possible values are: EVENT
AUDIT
ALERT
.
Properties
Unique ID of the scan job.
Type of the job.
Activity of the job. The possible values are: Job Created
Job Completed
.
Time at which the job started.
Time at which the job ended for the Job Completed activity.
Name / Email of the user who created the job.
Product generated unique ID of the job.
Name of the resource for which the job was created.
Type of the resource for which the job was created.
Parent of the resource for which the job was created.
Number of files blocked for the Job Completed activity.
Number of files scanned for the Job Completed activity.
Number of files skipped for scanning for the Job Completed activity.
Number of files selected for restore for the Job Completed activity.
Type of the entity for which the event has happened.
Represents the global ID of the customer or MSP.
The epoch representation of the time at which the event occurred.
Syslog standard of defining the event origin/type.
SyslogSeverity represents the severity(0-7) of the event.
Type of the event. For example, 'SystemEvent' or 'UserRestore'. This event's title is its type.
The category of the event. The possible values are: EVENT
AUDIT
ALERT
.
Properties
Unique ID of the snapshot job.
Unique ID of the scan job.
Unique ID of the snapshot which contains the timestamp.
Activity of the snapshot job. The possible values are:
Curated snapshot created
Curated snapshot creation started
.
Time at which the snapshot job started.
Time at which the snapshot will expire.
Name / Email of the user who created the snapshot job.
Number of files blocked for the snapshot job.
Number of files excluded for the snapshot job.
Number of files included for the snapshot job.
Number of files skipped for scanning for the snapshot job.
Name of the resource for which the snapshot job was created.
Type of the resource for which the snapshot job was created.
Parent of the resource for which the snapshot job was created.
Start date of the snapshot range.
End date of the snapshot range.
Type of the snapshot job.
Name of the user who created the snapshot job. This field comes for the activity **Curated snapshot created**.
Type of the entity for which the event has happened.
Represents the global ID of the customer or MSP.
The epoch representation of the time at which the event occurred.
Syslog standard of defining the event origin/type.
SyslogSeverity represents the severity(0-7) of the event.
Type of the event. For example, 'SystemEvent' or 'UserRestore'. This event's title is its type.
The category of the event. The possible values are: EVENT
AUDIT
ALERT
.
Properties
Type of the UDA operation.
Name of the admin who performed the operation.
Time at which the operation was performed.
Unique ID of the resource for which the operation was performed.
Name of the resource for which the operation was performed.
Type of the resource for which the operation was performed.
Parent ID of the resource for which the operation was performed.
Parent name of the resource for which the operation was performed.
Activity performed by the admin. The possible values are:
Unusual Data Activity - Download logs
Unusual Data Activity - Ignore Alert
.
Snapshot timestamp of the affected snapshot
Properties
Number of new files.
Number of updated files.
Number of deleted files.
Number of encrypted files.
Type of the entity for which the event has happened.
Represents the global ID of the customer or MSP.
The epoch representation of the time at which the event occurred.
Syslog standard of defining the event origin/type.
SyslogSeverity represents the severity(0-7) of the event.
Type of the event. For example, 'SystemEvent' or 'UserRestore'. This event's title is its type.
The category of the event. The possible values are: EVENT
AUDIT
ALERT
.
Properties
Location from where the admin logged in.
Time at which the admin logged in.
Name of the admin who logged in.
Email of the admin who logged in.
Result of the login operation. The possible values are: Success
Failure
.
Activity performed by the admin. The possible values are:
Admin Login Event
.
IP address of the admin who logged in.
Type of the entity for which the event has happened.
Represents the global ID of the customer or MSP.
The epoch representation of the time at which the event occurred.
Syslog standard of defining the event origin/type.
SyslogSeverity represents the severity(0-7) of the event.
Type of the event. For example, 'SystemEvent' or 'UserRestore'. This event's title is its type.
The category of the event. The possible values are: EVENT
AUDIT
ALERT
.
Properties
Indicates if the operation was successful.
Indicates if the AV scan is enabled.
Indicates if the file hash scan is enabled.
Indicates if the Druva curated IOCs are used.
Indicates if the scan is skipped for device replacement.
Indicates if the admin is allowed to skip the scan for servers.
Indicates if the user is allowed to skip the scan for endpoints.
Indicates if the admin is allowed to skip the scan for endpoints.
Type of the entity for which the event has happened.
Represents the global ID of the customer or MSP.
The epoch representation of the time at which the event occurred.
Syslog standard of defining the event origin/type.
SyslogSeverity represents the severity(0-7) of the event.
Type of the event. For example, 'SystemEvent' or 'UserRestore'. This event's title is its type.
The category of the event. The possible values are: EVENT
AUDIT
ALERT
.
Properties
Mode of the quarantine range. The possible values are: Admin Portal
API
.
Note for the quarantine range.
Unique ID of the organization.
State of the quarantine range. The possible values are: Success
Failure
.
Action performed on the quarantine range. The possible values are:
Update Ranges
.
IP address of the machine.
Name / Email of the initiator.
Unique ID of the resource for which the event is generated.
Name of the resource for which the event is generated.
Type of the resource for which the event is generated.
Parent of the resource for which the event is generated.
Platform of the resource for which the event is generated.
Properties
Start time of the effective / delete date range.
End time of the effective / delete date range.
Type of the entity for which the event has happened.
Represents the global ID of the customer or MSP.
The epoch representation of the time at which the event occurred.
Syslog standard of defining the event origin/type.
SyslogSeverity represents the severity(0-7) of the event.
Type of the event. For example, 'SystemEvent' or 'UserRestore'. This event's title is its type.
The category of the event. The possible values are: EVENT
AUDIT
ALERT
.
Properties
Mode of the quarantine event. The possible values are: Admin Portal
API
.
Note for the quarantine range.
Unique ID of the organization.
State of the quarantine range. The possible values are: Success
Failure
.
Action performed on the quarantine range. The possible values are:
Create Range
Delete Range
.
IP address of the machine.
Name / Email of the initiator.
Unique ID of the resource for which the event is generated.
Name of the resource for which the event is generated.
Type of the resource for which the event is generated.
Parent of the resource for which the event is generated.
Platform of the resource for which the event is generated.
Start time of the quarantine range.
End time of the quarantine range.
Type of the entity for which the event has happened.
Represents the global ID of the customer or MSP.
The epoch representation of the time at which the event occurred.
Syslog standard of defining the event origin/type.
SyslogSeverity represents the severity(0-7) of the event.
Type of the event. For example, 'SystemEvent' or 'UserRestore'. This event's title is its type.
The category of the event. The possible values are: EVENT
AUDIT
ALERT
.
Properties
Mode of the quarantine event. The possible values are: Admin Portal
API
.
Note for the quarantine range.
Unique ID of the organization.
State of the quarantine range. The possible values are: Success
Failure
.
Action performed on the quarantine range. The possible values are:
Create Range
Delete Range
.
IP address of the machine.
Name / Email of the initiator.
Unique ID of the resource for which the event is generated.
Name of the resource for which the event is generated.
Type of the resource for which the event is generated.
Parent of the resource for which the event is generated.
Platform of the resource for which the event is generated.
Start time of the quarantine range.
End time of the quarantine range.
Type of the entity for which the event has happened.
Represents the global ID of the customer or MSP.
The epoch representation of the time at which the event occurred.
Syslog standard of defining the event origin/type.
SyslogSeverity represents the severity(0-7) of the event.
Type of the event. For example, 'SystemEvent' or 'UserRestore'. This event's title is its type.
The category of the event. The possible values are: EVENT
AUDIT
ALERT
.
Properties
Mode of the quarantine event. The possible values are: Admin Portal
API
.
Note for the quarantine range.
Unique ID of the organization.
State of the quarantine range. The possible values are: Success
Failure
.
Action performed on the quarantine range. The possible values are:
Delete Ranges
.
IP address of the machine.
Name / Email of the initiator.
Unique ID of the resource for which the event is generated.
Name of the resource for which the event is generated.
Type of the resource for which the event is generated.
Parent of the resource for which the event is generated.
Platform of the resource for which the event is generated.
Properties
Start time of the effective / delete date range.
End time of the effective / delete date range.
Type of the entity for which the event has happened.
Represents the global ID of the customer or MSP.
The epoch representation of the time at which the event occurred.
Syslog standard of defining the event origin/type.
SyslogSeverity represents the severity(0-7) of the event.
Type of the event. For example, 'SystemEvent' or 'UserRestore'. This event's title is its type.
The category of the event. The possible values are: EVENT
AUDIT
ALERT
.
Properties
Mode of the quarantine event. The possible values are: Admin Portal
API
.
Note for the quarantine range.
Unique ID of the organization.
State of the quarantine range. The possible values are: Success
Failure
.
Action performed on the quarantine range. The possible values are:
Create Ranges
.
IP address of the machine.
Name / Email of the initiator.
Unique ID of the resource for which the event is generated.
Name of the resource for which the event is generated.
Type of the resource for which the event is generated.
Parent of the resource for which the event is generated.
Platform of the resource for which the event is generated.
Properties
Start time of the effective / delete date range.
End time of the effective / delete date range.
Type of the entity for which the event has happened.
Represents the global ID of the customer or MSP.
The epoch representation of the time at which the event occurred.
Syslog standard of defining the event origin/type.
SyslogSeverity represents the severity(0-7) of the event.
Type of the event. For example, 'SystemEvent' or 'UserRestore'. This event's title is its type.