{ "$schema": "https://json-schema.org/draft/2020-12/schema", "$id": "https://raw.githubusercontent.com/api-evangelist/palo-alto-networks/main/json-schema/palo-alto-networks-user-activity-schema.json", "title": "UserActivity", "x-generated": "2026-10-04", "x-method": "derived", "x-generator": "derive-json-schema.py", "x-source": "openapi/palo-alto-networks-users-api-openapi.yml#/components/schemas/UserActivity", "type": "object", "properties": { "id": { "type": "string", "description": "Unique activity record identifier." }, "user_id": { "type": "string", "description": "ID of the user who performed the action." }, "app_id": { "type": "string", "description": "SaaS application where the activity occurred." }, "action": { "type": "string", "description": "Type of action performed (e.g., file_download, share_external)." }, "asset_id": { "type": "string", "description": "ID of the asset involved in the activity." }, "timestamp": { "type": "string", "format": "date-time", "description": "Timestamp when the activity occurred." }, "ip_address": { "type": "string", "description": "Source IP address of the activity." }, "risk_level": { "type": "string", "enum": [ "low", "medium", "high" ], "description": "Risk level assigned to this activity." } } }