🔒 New browser security hardening is live to help defend against AI-driven attacks. Learn more

Metadata collected by eSHARE

Prev Next

This article describes the metadata eShare collects and logs as part of normal platform activity, for eShare administrators who need to understand what data is captured during file, sharing, and account operations. The following will be reviewed:

Overview

Every time a user or administrator interacts with eShare — opening a file, creating a Trusted Share, changing a policy, signing in — eShare logs an event that captures the action taken, who performed it, and the context around it (file, location, sharing policy, network origin, and so on). This metadata supports auditing, compliance reporting and streaming to SIEM.

Metadata falls into two related groups, covered in the sections below:

  • Fields — the individual data points captured, grouped by what they describe (the actor, the file, the location, and so on).

  • Events — the named actions that trigger metadata capture (for example, 'FileDownload' or 'Create Policy').

Metadata Fields by Category

The following fields may be captured, depending on the type of event.

Event

Field

Description

event_id

A unique identifier assigned to the event.

event_type_name

The type of the audit event, indicating the action performed.

event_server_timestamp

The timestamp when the event was logged by the server.

event_timestamp

The timestamp when the event was logged by the client.

event_category

The category of the event (for example, Sharing Event, Admin Event).

event_duration_millis

The duration of the event in milliseconds.

event_source_app_id

The source system that generated the event.

Actor

Field

Description

actor_user_email

The email of the user who performed the action.

Location

Field

Description

location_continent

The continent where the event took place.

location_country

The country where the event occurred.

location_country_code

The country code where the event occurred.

location_region

The region or state where the event occurred.

location_city

The city where the event occurred.

location_longitude

The longitude coordinate of the event's location.

location_latitude

The latitude coordinate of the event's location.

IP Address

Field

Description

ip_ip_address

The IP address from which the event originated.

ip_is_private

Indicates whether the IP address is a private address.

ip_registry

The IP registry associated with the IP address.

ip_asn_id

The autonomous system number (ASN) associated with the IP address.

ip_asn_description

The description of the ASN.

ip_asn_country_code

The country code associated with the ASN.

ip_ip_network_cidr

The CIDR block of the IP address.

Trusted Share

Field

Description

trusted_share_id

A unique identifier for the Trusted Share.

trusted_share_name

The name of the Trusted Share.

trusted_share_owner_eshare_identity_id

A unique identifier for the identity of the share owner.

trusted_share_owner_fullname

The full name of the Trusted Share owner.

trusted_share_owner_email

The email of the Trusted Share owner.

trusted_share_recipient_email

The email of the Trusted Share recipient.

trusted_share_recipient_expiry

The expiration date of the Trusted Share for this recipient.

trusted_share_recipient_permissions_watermark

Whether the Sharing Policy enforces a watermark on downloaded files.

trusted_share_recipient_permissions_can_create

Whether the Sharing Policy allows content creation.

trusted_share_recipient_permissions_can_delete

Whether the Sharing Policy allows content deletion.

trusted_share_recipient_permissions_can_download

Whether the Sharing Policy allows content downloading.

trusted_share_recipient_permissions_can_edit

Whether the Sharing Policy allows content editing.

trusted_share_recipient_permissions_can_read

Whether the Sharing Policy allows content viewing.

trusted_share_recipient_permissions_can_share

Whether the Sharing Policy allows content sharing.

trusted_share_recipient_permissions_convert_to_pdf

Whether the Sharing Policy enforces PDF conversion (with Terms of Use as a cover page, if applicable) on download.

trusted_share_recipient_permissions_login_required

Whether the Sharing Policy requires login to access the Trusted Share.

trusted_share_recipient_permissions_pin_protected

Whether the Sharing Policy requires a PIN to access the Trusted Share.

Sharing Policy

Field

Description

sharing_policy_id

A unique identifier of the Sharing Policy used.

sharing_policy_name

The name of the Sharing Policy used.

sharing_policy_sensitivity_label_id

A unique identifier of the sensitivity label of the Sharing Policy.

sharing_policy_sensitivity_label_name

The sensitivity label name of the Sharing Policy.

File

Field

Description

file_name

The name of the file involved in the event.

file_is_folder

Indicates whether the item is a folder.

file_path

The path of the file in this event.

file_extension

The file extension (for example, .pdf, .docx).

file_size

The size of the file, in bytes.

file_sensitivity_label_id

The unique identifier for the file's sensitivity label.

file_sensitivity_label_name

The name of the file's sensitivity label.

file_dlp_tag_id

The unique identifier for the file's Data Loss Prevention (DLP) tag.

file_dlp_tag_name

The name of the file's DLP tag.

file_page

The page of the file associated with the event, if applicable.

file_pageview_id

The unique identifier for the file page view, if applicable.

file_url

The URL of the file's location, if applicable.

sharepoint_site_name

The name of the SharePoint site the file belongs to, if applicable.

sharepoint_site_url

The URL of the SharePoint site the file belongs to, if applicable.

cloud_storage_provider

The cloud storage provider for this event (for example, SharePoint, OneDrive, Dropbox).

cloud_storage_provider_organization_name

The organization name of the cloud storage account provider.

Microsoft 365 DLP

Field

Description

m365_dlp_event_id

The M365 DLP audit event ID of the DlpRuleMatch event.

m365_dlp_event_timestamp

The timestamp of the DlpRuleMatch M365 DLP event.

m365_dlp_policy

The M365 DLP policy that was matched through one of its rules.

m365_dlp_rule

The M365 DLP rule that was matched.

m365_dlp_rule_severity

The severity of the M365 DLP rule match.

m365_dlp_sit

The M365 DLP sensitive information type (SIT) that was detected.

m365_dlp_sit_count

The number of times the SIT was detected.

m365_dlp_sit_confidence

The confidence level with which the SIT was detected.

Activity Events That Generate Metadata

Metadata is captured whenever one of the following named events occurs. Events are grouped by activity type.

File Operations

Event

Description

FolderCreate

Folder was created.

FileCreate

New file was created.

FileUpload

File was uploaded.

Bulk Upload

Uploading multiple items in bulk.

FileDownload

File was downloaded.

FileDownloadBundle

Multiple files were downloaded at the same time.

FileEdit

File was edited.

FileUpdated

File was updated.

FileDelete

File was deleted.

Rename

File was renamed.

Copy

Item was copied from one location to another.

Move

Item was moved from one location to another.

ApplyPolicy

A policy was applied.

PDF Interactions

Event

Description

PDF View

PDF document was viewed.

PDF Close

PDF document was closed.

PDF PageView

PDF document page was viewed.

PDF Print

PDF document was printed.

PDF Download

PDF document was downloaded.

PDF Edit

PDF document was edited.

PDF Request Fillable Form

PDF fillable form was created.

PDF Signature added

Recipient added a signature to a PDF form.

PDF Signature invalidated

Recipient invalidated a signature on a PDF form.

PDF Signing Completed

Recipient completed signing a PDF form.

PDF Signing Invalidated

Recipient invalidated a completed PDF signing.

Trusted Sharing & Sharing Policies

Event

Description

Trusted Sharing

User created a Trusted Share.

Add recipient

Added a recipient to a Trusted Share.

Invite with Access Link

Recipient was invited with an access link.

Link Created

Shareable link was created by a user.

M365 Link Conversion

A native M365 link was converted to an eShare link.

Enable Recipient

Recipient was enabled on a Trusted Share.

Disable Recipient

Recipient was disabled from a Trusted Share.

Expire Recipient

Recipient's access to a Trusted Share expired.

Extend Recipient

Recipient's access to a Trusted Share was extended.

Extension Request Approved

Recipient's request to extend Trusted Share access was approved.

Extension Request Rejected

Recipient's request to extend Trusted Share access was denied.

Authorizing Access

Recipient access to a Trusted Share was authorized.

Revoking Access

Recipient access to a Trusted Share was revoked.

Trusted Share Access

Recipient successfully accessed a Trusted Share.

Trusted Share Request

Recipient opened the Trusted Share link.

Trusted Share Ownership Changed

Ownership of a Trusted Share was transferred to another user.

Options Update

Owner changed the permissions on a Trusted Share.

Invitation Request Approved

Recipient's invitation request was approved.

Invitation Request Ignored

Recipient's invitation request was ignored.

Invitation Request Rejected

Recipient's invitation request was rejected.

Invite Request Approved

Recipient's invitation request was approved.

Label Restrictions Override Request

Blocked recipient submitted a label-override request.

Label Override Request Approved

Blocked recipient's override request was approved.

Label Override Request Rejected

Blocked recipient's override request was rejected.

PDP Decision

A decision was made whether to block or allow a recipient.

Create Policy

Created a new Sharing Policy.

Update Policy

Updated a Sharing Policy.

Shared Mailbox Recipient

Added the Shared Mailbox flag to a recipient.

Revoke Shared Mailbox Recipient

Removed the Shared Mailbox flag from a recipient.

Request to Enable SharePoint Sharing

User submitted a request to enable sharing on a SharePoint site.

Request to Enable SharePoint Sharing approved

Request to enable sharing on a SharePoint site was approved.

Secure Conversations

Event

Description

Share reply posted

Secure conversation reply was posted.

Share reply edited

Secure conversation reply was edited.

Share reply deleted

Secure conversation reply was deleted.

Undo deleted share reply

Secure conversation reply was un-deleted.

Secure conversation exported

User exported a secure conversation from a Trusted Share.

Email & Notification Templates

Event

Description

Email Delivered

Email was delivered to the recipient.

Email Failed

Email failed to deliver to the recipient.

SMS notification

SMS notification was sent to the recipient.

New Dynamic Template Set

New Secure Mail email template was created.

Assigned Default Dynamic Template

Secure Mail email template was set as default.

Finalized Dynamic Template

Secure Mail email template was finalized.

Removed Default Dynamic Template

Secure Mail email template was deleted.

Authentication & Verification

Event

Description

User login

User logged into the eShare tenant.

Login terms accepted

User accepted the internal login Terms of Use.

Login terms declined

User declined the internal login Terms of Use.

Terms displayed

Trusted Share Terms of Use was displayed to a recipient.

Terms accepted

Recipient accepted the Trusted Share Terms of Use.

Terms declined

Recipient declined the Trusted Share Terms of Use.

One-Time Password Requested

A one-time password was requested.

One-Time Password Sent

A one-time password was sent.

Send verification code

A one-time password verification code was sent.

One-Time Password Successfully Applied

A one-time password was entered correctly.

Incorrect One-Time Password Used

An incorrect one-time password was entered.

Incorrect OTP Used

An incorrect one-time password was entered.

Incorrect Passcode Used

An incorrect one-time password was entered.

Max One-Time Password attempts

Recipient reached the maximum number of one-time password attempts.

One-Time Password Request for phone verification

A request was initiated to verify a phone number by one-time password.

One-Time Password Phone Verified

A phone number was successfully verified by one-time password.

Saved mobile

A mobile number was saved to a user profile.

Verified mobile

A user verified their mobile number.

Admin & Tenant Configuration

Event

Description

Assign admin roles

An admin role was assigned to a user.

Revoke admin roles

An admin role was removed from a user.

Add Sharepoint Sites

A new SharePoint site was added to eShare.

Update Sharepoint Site

Settings on a linked SharePoint site were updated.

Update SPO

Settings on a linked SharePoint site were updated.

Update Cloud Provider

A cloud provider was updated in the eShare tenant.

Remove Cloud Provider

A cloud provider was removed from the eShare tenant.

Enable Graph API

The Graph cloud provider was enabled.

Enable Personal Tokens Graph API

The Personal Graph Tokens feature was enabled.

Enable Outlook API

The Outlook API feature was enabled.

Disable Outlook API

The Outlook API feature was disabled.

Enable Shared With Me

The Shared With Me feature was enabled.

Disable Shared With Me

The Shared With Me feature was disabled.

Enable Document Labels

Sensitivity label sync to eShare was enabled.

Disable Document Labels

Sensitivity label sync to eShare was disabled.

Create Tag

A new DLP tag was created.

Update Tag

A DLP tag was updated.

Delete Tag

A DLP tag was deleted.

IB Group Added

An Information Barrier group was added.