Linux O/S specific logon session information.
Fields
| Field Name | Description |
|---|---|
utmpType - PosixLogonType!
|
The value of utmp type (ut_type field). |
ttyDeviceName - String!
|
The TTY device name associated with the logon session (ut_line field). |
host - String!
|
Hostname for remote login, or kernel version for run-level messages |
hostOrigin - LogonHostOrigin!
|
Where the host puts this session relative to your networks: local, a private address, a public address, or a hostname. A hostname counts on its own, never as the address it may resolve to. See LogonHostOrigin. |
pid - Int!
|
Process identifier (PID) of the login process. |
extended - LogonSessionLinuxExtended
|
Extended Linux specific logon session information found via systemd/login1, available if the session is currently active. |
Used by
LogonSessiontype: A user logon session observed on an Endpoint, identified by the username and the time the session started.LogonSessionOsSpecificunion: OS-specific logon session union type.
Example
Example
{
"utmpType": "EMPTY",
"ttyDeviceName": "xyz789",
"host": "abc123",
"hostOrigin": "LOCAL",
"pid": 123,
"extended": LogonSessionLinuxExtended
}