MS Windows O/S specific logon session information.
Fields
| Field Name | Description |
|---|---|
logonId - Luid!
|
A locally unique identifier (LUID) that identifies a logon session. |
logonDomain - String!
|
The name of the domain used to authenticate the owner of the logon session. |
authenticationPackage - String!
|
The name of the authentication package used to authenticate the owner of the logon session. |
logonType - WindowsLogonType
|
How the session was established, such as interactive, network, or remote interactive. See WindowsLogonType. |
logonSid - String!
|
Security identifier (SID) of the user logged in, a variable-length string that uniquely identifies users or groups in the MS Windows O/S. |
logonServer - String!
|
The name of the server used to authenticate the owner of the logon session. |
dnsDomainName - String!
|
Contains the DNS name for the owner of the logon session. |
logonScript - String!
|
The script used for logging on. |
profilePath - String!
|
Contains the path to the user's profile. |
homeDirectory - String!
|
The home directory for the logon session. |
homeDirectoryDrive - String!
|
Drive location of the home directory of the logon session. |
Used by
LogonSessiontype: A user logon session observed on an Endpoint, identified by the username and the time the session started.LogonSessionOsSpecificunion: OS-specific logon session union type.
Example
Example
{
"logonId": "999",
"logonDomain": "abc123",
"authenticationPackage": "xyz789",
"logonType": "UNDEFINED",
"logonSid": "abc123",
"logonServer": "xyz789",
"dnsDomainName": "xyz789",
"logonScript": "xyz789",
"profilePath": "abc123",
"homeDirectory": "xyz789",
"homeDirectoryDrive": "xyz789"
}