This article describes the metadata eShare collects and logs as part of normal platform activity, for eShare administrators who need to understand what data is captured during file, sharing, and account operations. The following will be reviewed:
Overview
Every time a user or administrator interacts with eShare — opening a file, creating a Trusted Share, changing a policy, signing in — eShare logs an event that captures the action taken, who performed it, and the context around it (file, location, sharing policy, network origin, and so on). This metadata supports auditing, compliance reporting and streaming to SIEM.
Metadata falls into two related groups, covered in the sections below:
Fields — the individual data points captured, grouped by what they describe (the actor, the file, the location, and so on).
Events — the named actions that trigger metadata capture (for example, 'FileDownload' or 'Create Policy').
Metadata Fields by Category
The following fields may be captured, depending on the type of event.
Event
Field | Description |
|---|---|
| A unique identifier assigned to the event. |
| The type of the audit event, indicating the action performed. |
| The timestamp when the event was logged by the server. |
| The timestamp when the event was logged by the client. |
| The category of the event (for example, Sharing Event, Admin Event). |
| The duration of the event in milliseconds. |
| The source system that generated the event. |
Actor
Field | Description |
|---|---|
| The email of the user who performed the action. |
Location
Field | Description |
|---|---|
| The continent where the event took place. |
| The country where the event occurred. |
| The country code where the event occurred. |
| The region or state where the event occurred. |
| The city where the event occurred. |
| The longitude coordinate of the event's location. |
| The latitude coordinate of the event's location. |
IP Address
Field | Description |
|---|---|
| The IP address from which the event originated. |
| Indicates whether the IP address is a private address. |
| The IP registry associated with the IP address. |
| The autonomous system number (ASN) associated with the IP address. |
| The description of the ASN. |
| The country code associated with the ASN. |
| The CIDR block of the IP address. |
Trusted Share
Field | Description |
|---|---|
| A unique identifier for the Trusted Share. |
| The name of the Trusted Share. |
| A unique identifier for the identity of the share owner. |
| The full name of the Trusted Share owner. |
| The email of the Trusted Share owner. |
| The email of the Trusted Share recipient. |
| The expiration date of the Trusted Share for this recipient. |
| Whether the Sharing Policy enforces a watermark on downloaded files. |
| Whether the Sharing Policy allows content creation. |
| Whether the Sharing Policy allows content deletion. |
| Whether the Sharing Policy allows content downloading. |
| Whether the Sharing Policy allows content editing. |
| Whether the Sharing Policy allows content viewing. |
| Whether the Sharing Policy allows content sharing. |
| Whether the Sharing Policy enforces PDF conversion (with Terms of Use as a cover page, if applicable) on download. |
| Whether the Sharing Policy requires login to access the Trusted Share. |
| Whether the Sharing Policy requires a PIN to access the Trusted Share. |
Sharing Policy
Field | Description |
|---|---|
| A unique identifier of the Sharing Policy used. |
| The name of the Sharing Policy used. |
| A unique identifier of the sensitivity label of the Sharing Policy. |
| The sensitivity label name of the Sharing Policy. |
File
Field | Description |
|---|---|
| The name of the file involved in the event. |
| Indicates whether the item is a folder. |
| The path of the file in this event. |
| The file extension (for example, .pdf, .docx). |
| The size of the file, in bytes. |
| The unique identifier for the file's sensitivity label. |
| The name of the file's sensitivity label. |
| The unique identifier for the file's Data Loss Prevention (DLP) tag. |
| The name of the file's DLP tag. |
| The page of the file associated with the event, if applicable. |
| The unique identifier for the file page view, if applicable. |
| The URL of the file's location, if applicable. |
| The name of the SharePoint site the file belongs to, if applicable. |
| The URL of the SharePoint site the file belongs to, if applicable. |
| The cloud storage provider for this event (for example, SharePoint, OneDrive, Dropbox). |
| The organization name of the cloud storage account provider. |
Microsoft 365 DLP
Field | Description |
|---|---|
| The M365 DLP audit event ID of the DlpRuleMatch event. |
| The timestamp of the DlpRuleMatch M365 DLP event. |
| The M365 DLP policy that was matched through one of its rules. |
| The M365 DLP rule that was matched. |
| The severity of the M365 DLP rule match. |
| The M365 DLP sensitive information type (SIT) that was detected. |
| The number of times the SIT was detected. |
| The confidence level with which the SIT was detected. |
Activity Events That Generate Metadata
Metadata is captured whenever one of the following named events occurs. Events are grouped by activity type.
File Operations
Event | Description |
|---|---|
| Folder was created. |
| New file was created. |
| File was uploaded. |
| Uploading multiple items in bulk. |
| File was downloaded. |
| Multiple files were downloaded at the same time. |
| File was edited. |
| File was updated. |
| File was deleted. |
| File was renamed. |
| Item was copied from one location to another. |
| Item was moved from one location to another. |
| A policy was applied. |
PDF Interactions
Event | Description |
|---|---|
| PDF document was viewed. |
| PDF document was closed. |
| PDF document page was viewed. |
| PDF document was printed. |
| PDF document was downloaded. |
| PDF document was edited. |
| PDF fillable form was created. |
| Recipient added a signature to a PDF form. |
| Recipient invalidated a signature on a PDF form. |
| Recipient completed signing a PDF form. |
| Recipient invalidated a completed PDF signing. |
Trusted Sharing & Sharing Policies
Event | Description |
|---|---|
| User created a Trusted Share. |
| Added a recipient to a Trusted Share. |
| Recipient was invited with an access link. |
| Shareable link was created by a user. |
| A native M365 link was converted to an eShare link. |
| Recipient was enabled on a Trusted Share. |
| Recipient was disabled from a Trusted Share. |
| Recipient's access to a Trusted Share expired. |
| Recipient's access to a Trusted Share was extended. |
| Recipient's request to extend Trusted Share access was approved. |
| Recipient's request to extend Trusted Share access was denied. |
| Recipient access to a Trusted Share was authorized. |
| Recipient access to a Trusted Share was revoked. |
| Recipient successfully accessed a Trusted Share. |
| Recipient opened the Trusted Share link. |
| Ownership of a Trusted Share was transferred to another user. |
| Owner changed the permissions on a Trusted Share. |
| Recipient's invitation request was approved. |
| Recipient's invitation request was ignored. |
| Recipient's invitation request was rejected. |
| Recipient's invitation request was approved. |
| Blocked recipient submitted a label-override request. |
| Blocked recipient's override request was approved. |
| Blocked recipient's override request was rejected. |
| A decision was made whether to block or allow a recipient. |
| Created a new Sharing Policy. |
| Updated a Sharing Policy. |
| Added the Shared Mailbox flag to a recipient. |
| Removed the Shared Mailbox flag from a recipient. |
| User submitted a request to enable sharing on a SharePoint site. |
| Request to enable sharing on a SharePoint site was approved. |
Secure Conversations
Event | Description |
|---|---|
| Secure conversation reply was posted. |
| Secure conversation reply was edited. |
| Secure conversation reply was deleted. |
| Secure conversation reply was un-deleted. |
| User exported a secure conversation from a Trusted Share. |
Email & Notification Templates
Event | Description |
|---|---|
| Email was delivered to the recipient. |
| Email failed to deliver to the recipient. |
| SMS notification was sent to the recipient. |
| New Secure Mail email template was created. |
| Secure Mail email template was set as default. |
| Secure Mail email template was finalized. |
| Secure Mail email template was deleted. |
Authentication & Verification
Event | Description |
|---|---|
| User logged into the eShare tenant. |
| User accepted the internal login Terms of Use. |
| User declined the internal login Terms of Use. |
| Trusted Share Terms of Use was displayed to a recipient. |
| Recipient accepted the Trusted Share Terms of Use. |
| Recipient declined the Trusted Share Terms of Use. |
| A one-time password was requested. |
| A one-time password was sent. |
| A one-time password verification code was sent. |
| A one-time password was entered correctly. |
| An incorrect one-time password was entered. |
| An incorrect one-time password was entered. |
| An incorrect one-time password was entered. |
| Recipient reached the maximum number of one-time password attempts. |
| A request was initiated to verify a phone number by one-time password. |
| A phone number was successfully verified by one-time password. |
| A mobile number was saved to a user profile. |
| A user verified their mobile number. |
Admin & Tenant Configuration
Event | Description |
|---|---|
| An admin role was assigned to a user. |
| An admin role was removed from a user. |
| A new SharePoint site was added to eShare. |
| Settings on a linked SharePoint site were updated. |
| Settings on a linked SharePoint site were updated. |
| A cloud provider was updated in the eShare tenant. |
| A cloud provider was removed from the eShare tenant. |
| The Graph cloud provider was enabled. |
| The Personal Graph Tokens feature was enabled. |
| The Outlook API feature was enabled. |
| The Outlook API feature was disabled. |
| The Shared With Me feature was enabled. |
| The Shared With Me feature was disabled. |
| Sensitivity label sync to eShare was enabled. |
| Sensitivity label sync to eShare was disabled. |
| A new DLP tag was created. |
| A DLP tag was updated. |
| A DLP tag was deleted. |
| An Information Barrier group was added. |