<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
</head>
<body>
<style type="text/css" style="display:none;"><!-- P {margin-top:0;margin-bottom:0;} --></style>
<div id="divtagdefaultwrapper" style="font-size:11pt;color:#000000;font-family:Calibri,Helvetica,sans-serif;" dir="ltr">
<p>This should be a good starting point: <a href="https://wiki.shibboleth.net/confluence/display/IDP30/AuditLoggingConfiguration" class="OWAAutoLink" id="LPlnk385686" previewremoved="true">https://wiki.shibboleth.net/confluence/display/IDP30/AuditLoggingConfiguration</a><br>
<br>
</p>
</div>
<hr style="display:inline-block;width:98%" tabindex="-1">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Vipin Jain <vjain@simeiosolutions.com><br>
<b>Sent:</b> Thursday, July 27, 2017 12:43:37 PM<br>
<b>To:</b> Shib Users<br>
<b>Subject:</b> Re: IDP Logs - SIEM</font>
<div> </div>
</div>
<div>
<div dir="auto">Thanks Scott.
<div dir="auto"><br>
</div>
<div dir="auto">Can you please let us know which document link you are referring and which log file does all info has which I need.</div>
<div dir="auto"><br>
<div data-smartmail="gmail_signature" dir="auto">Sent from my phone</div>
</div>
</div>
<div class="gmail_extra"><br>
<div class="gmail_quote">On 27 Jul 2017 10:36 pm, "Cantor, Scott" <<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>> wrote:<br type="attribution">
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
On 7/27/17, 1:03 PM, "users on behalf of Vipin Jain" <<a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a> on behalf of
<a href="mailto:vjain@simeiosolutions.com">vjain@simeiosolutions.com</a>> wrote:<br>
<br>
> How can I get user attributes in logs which my SIEM tool can learn.<br>
<br>
There is no built-in audit field that contains the values, only the names of the attributes. If you want actual attribute data in the log you would have to supply a custom field extraction function per the documentation.<br>
<br>
-- Scott<br>
<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">
users-unsubscribe@shibboleth.<wbr>net</a><br>
</blockquote>
</div>
</div>
<br>
<span style="font-family:Arial,Helvetica,sans-serif;font-size:small">The information in this message may contain confidential information and may be legally privileged. It is intended solely for the individual(s) named. Access to this email by anyone else is
 unauthorized. Please notify the sender immediately if you have received this email by mistake and delete this email from your system. If you are not the intended recipient, any disclosure, copying, distribution or any action taken or omitted to be taken in
 reliance on it, is prohibited and may be unlawful. Email transmission cannot be guaranteed to be secure or error-free, as information could be intercepted, corrupted, lost, destroyed, arrive late or incomplete, or contain viruses. When addressed to our clients
 any decisions or recommendations contained in this email are subject to the terms and conditions expressed our contract and related statement of work letter(s)</span></div>
</body>
</html>