user-role-revoke
March 22, 2023 · View on GitHub
Description
A user account was revoked a security role
Parameters
| Parameter | Value |
|---|---|
| Subject | user |
| Activity | role-revoke |
| Activity Type | user-role-revoke |
| Pretty Name | User Role Revoke |
Fields
The possible fields for this activity type will vary depending on whether the activity was a success or a fail.
user-role-revoke:success
| Field | Core | Detection | Informational |
|---|---|---|---|
| role_name | ✓ |
user-role-revoke:fail
| Field | Core | Detection | Informational |
|---|---|---|---|
| role_name | ✓ | ||
| failure_code | ✓ | ||
| failure_reason | ✓ |