{ "$schema": "https://json-schema.org/draft/2020-12/schema", "title": "UserActivity", "description": "UserActivity schema from Palo Alto Networks SaaS Security API", "$id": "https://raw.githubusercontent.com/api-evangelist/palo-alto-networks/refs/heads/main/json-schema/saas-security-api-user-activity-schema.json", "type": "object", "properties": { "id": { "type": "string", "description": "Unique activity record identifier." }, "user_id": { "type": "string", "description": "ID of the user who performed the action." }, "app_id": { "type": "string", "description": "SaaS application where the activity occurred." }, "action": { "type": "string", "description": "Type of action performed (e.g., file_download, share_external)." }, "asset_id": { "type": "string", "description": "ID of the asset involved in the activity." }, "timestamp": { "type": "string", "format": "date-time", "description": "Timestamp when the activity occurred." }, "ip_address": { "type": "string", "description": "Source IP address of the activity." }, "risk_level": { "type": "string", "enum": [ "low", "medium", "high" ], "description": "Risk level assigned to this activity." } } }