---
title: "auth.all"
canonical: "https://docs.devo.com/space/latest/95126107/auth.all"
format: markdown
---
> Macro (toc)

## Scope

This table collects information about various authentication events generated by different platforms, including cloud distributors, virtual private networks (VPNs), databases, firewalls, and application delivery services. Working with this table will help you detect credential access threats.

## Send data to Devo

Among the 41 compatible data sources, the most popular and security-critical are:

- [Azure Entra ID collector](https://docs.devo.com/space/latest/94656498/Microsoft+Azure+collector)
- [Okta collectors](https://docs.devo.com/space/latest/94656823/Okta+collectors)
- [rsyslog](https://docs.devo.com/space/latest/94658299/rsyslog)
- [Snare](https://docs.devo.com/space/latest/479363146/Devo+Endpoint+Agent+2.0+by+Snare)
- [Microsoft 365 Management API collector](https://docs.devo.com/space/latest/622952489/Microsoft+365+Management+API+collector)
- [CloudTrail Audit SQS collector](https://docs.devo.com/space/latest/612859906/CloudTrail+Audit+SQS+collector)
- [Google Workspace Reports collector](https://docs.devo.com/space/latest/94656117/Google+Workspace+Reports+collector)

## Source tables

The information displayed is extracted from the following tables:

<details>
<summary>Check source tables</summary>

- `adn.f5.bigip.apm`
- `adn.f5.bigip.audit`
- `app.lastpass.events`
- `auth.cisco.ise`
- `auth.duo.administrator.login`
- `auth.duo.authentication.events`
- `auth.jumpcloud.all.events`
- `auth.okta.events`
- `auth.okta.system`
- `auth.onelogin.events`
- `auth.ping.federate.audit`
- `auth.ping.federate.security_audit`
- `auth.ping.id.mfa`
- `auth.rsa.secureid.runtime`
- `auth.securenvoy`
- `auth.thycotic.secretserver`
- `auth.unix`
- `box.all.win`
- `cef0.microsoft.microsoftWindows`
- `cloud.aws.cloudtrail.events`
- `cloud.aws.cloudtrail.signin`
- `cloud.azure.ad.signin_all`
- `cloud.azure.sql.audit`
- `cloud.gsuite.reports.login`
- `cloud.office365.management`
- `crm.salesforceobjects.loginhistory`
- `db.mssql.events`
- `db.oracle.audit_trail`
- `ddi.infoblox.audit`
- `firewall.all.vpn.auth`
- `firewall.cisco.asa`
- `firewall.fortinet.event.system`
- `firewall.juniper.srx.system`
- `firewall.paloalto.globalprotect`
- `firewall.paloalto.system`
- `helpdesk.zendesk.audit.logs`
- `network.cisco.switch`
- `network.citrix.adc.sslvpn`
- `siem.logtrust.web.connection`
- `vpn.aws.client`
- `vpn.cisco.asa.anyconnect`
</details>

## Table structure

This is the set of columns displayed by this union table, which is the result of the collection of columns present in all source tables:

> ⚠️ **Extra fields**
> ⚠️ 
> ⚠️ Fields marked as *Extra *in the table below are not shown by default in data tables and need to be explicitly requested in the query. You can find them marked as *Extra *when you perform a query so they can be easily identified. Learn more about this in [Selecting unrevealed columns](#).

| **Field** | **Type** | ***Extra***** fields** |
| --- | --- | --- |
| *eventdate* | `timestamp` |  |
| *source* | `str` |  |
| *action* | `str` |  |
| *machine* | `str` |  |
| hostname | `str` |  |
| *application* | `str` |  |
| *domain* | `str` |  |
| *user* | `str` |  |
| *source_ip* | `ip4` |  |
| *source_ipv4* | `ip4` |  |
| *source_hostname* | `str` |  |
| *source_user* | `str` |  |
| username | `str` |  |
| user_identity_username | `str` |  |
| *result* | `str` |  |
| *message* | `str` | **✓** |
| *hostchain* | `str` | **✓** |
| *tag* | `str` | **✓** |

## Secure it

Use the [authentication](https://devodocs.atlassian.net/wiki/spaces/latest/pages/2206367761/Query+and+alert+library#AUTH) queries from the library.