icon-zia.svg
Secure Internet and SaaS Access (ZIA)

NSS Feed Output Format: SaaS Security Activity Logs

The SaaS Security Activity Nanolog Streaming Service (NSS) feed specifies the data from the SaaS Security Activity logs that the NSS sends to the security information and event management (SIEM) system. You can configure an NSS feed by including one or more fields. The fields and their values display in the NSS feed output.

The following tables display information about the SaaS Security Activity log fields and possible values for those fields.

Date/Time

FieldDescriptionExample
%s{time}The time and date of the transaction. This excludes the time zone.Mon Oct 16 22:55:48 2023
%s{tz}The time zone. This is the same as the time zone you specified when you configured the NSS feed.GMT
%02d{ss}Seconds (0–59)48
%02d{mm}Minutes (0–59)55
%02d{hh}Hours (0–23)22
%02d{dd}The day of the month (1–31)16
%02d{mth}The month of the year10
%04d{yyyy}Year2023
%s{mon}The name of the monthOct
%s{day}The day of the weekMon

SaaS Security Activity Logs

FieldDescriptionExample
%s{username}The user who performed the activitypshah@zslr.onmicrosoft.com
%s{is_admin_act}Indicates if the user who performed the activity is an administrator
  • 1 = Yes
  • 0 = No
%s{tenant}The SaaS application tenant associated with the activityod-test
%s{objtypename1}The object type associated with the activityFile
%s{objtypename2}The second object type associated with the activity, if applicableFolder
%s{appname}The SaaS application associated with the activityONEDRIVE
%s{objnames1}The object name associated with the first object typesanity2022-09-04 00-06.pdf
%s{objnames2}The object name associated with the second object type, if applicableMaverick
%d{act_cnt}The activity count55
%s{act_type_name}The type of activity performed by the userDownload
%s{eventtime}The event time of the activityTue Oct 18 10:24:53 2022
%s{extownername}The external owner of the SaaS applicationapp@sharepoint
%s{src_ip}The IP address associated with the activity104.129.203.39
Related Articles
General Guidelines for NSS Feeds and Feed FormatsNSS Feed Output Format: Web LogsNSS Feed Output Format: Firewall LogsNSS Feed Output Format: DNS LogsNSS Feed Output Format: Tunnel LogsNSS Feed Output Format: SaaS Security LogsNSS Feed Output Format: SaaS Security Activity LogsNSS Feed Output Format: Admin Audit LogsNSS Feed Output Format: Endpoint DLP LogsNSS Feed Output Format: Email DLP Logs