Skip to main content

1Password Event Logs connector reference

Beta

This feature is in Beta. To use it, a workspace admin must turn on Lakeflow Connect for 1Password Event Logs from the Previews page. See Manage Databricks previews.

Reference information for the managed 1Password Event Logs connector, including the supported source tables, destination schemas, and connection options.

Supported source tables​

The 1Password Event Logs connector supports the following source tables, under the default source schema:

Source table

Primary key

Description

Sync mode

Cursor field

audit_events

lw_id

Actions performed in your 1Password account, such as changes to users, vaults, and items.

Incremental

time

item_usages

lw_id

Item access events from shared vaults.

Incremental

time

sign_in_attempts

lw_id

Authentication attempts against your 1Password account.

Incremental

time

Source table

Primary key

Description

Sync mode

Cursor field

audit_events

lw_id

Actions performed in your 1Password account, such as changes to users, vaults, and items.

Incremental

time

item_usages

lw_id

Item access events from shared vaults.

Incremental

time

sign_in_attempts

lw_id

Authentication attempts against your 1Password account.

Incremental

time

Connection options​

Set these options when you create the Unity Catalog connection.

Option

Type

Required

Description

base_url

String

No

The Events API host without an https:// prefix. The default is events.1password.com. Allowed hosts match *.1password.com, *.1password.ca, and *.1password.eu.

bearer_token

String (secret)

Yes

The Events Reporting bearer token used to authenticate to the Events API.

Option

Type

Required

Description

base_url

String

No

The Events API host without an https:// prefix. The default is events.1password.com. Allowed hosts match *.1password.com, *.1password.ca, and *.1password.eu.

bearer_token

String (secret)

Yes

The Events Reporting bearer token used to authenticate to the Events API.

Connector options​

The 1Password Event Logs connector has no additional configuration options beyond the pipeline settings available for all managed connectors. See Ingest data from 1Password.

Destination table schemas​

These columns are the Events API fields the connector writes. SCD Type 2 is not supported.

audit_events​

Primary key: lw_id Cursor field: time

Field

Data type

lw_id

STRING

time

TIMESTAMP

uuid

STRING

timestamp

STRING

actor_uuid

STRING

actor_details

STRUCT<uuid: STRING, name: STRING, email: STRING>

actor_type

STRING

actor_account_uuid

STRING

account_uuid

STRING

action

STRING

object_type

STRING

object_uuid

STRING

object_details

STRUCT<uuid: STRING, name: STRING, email: STRING>

aux_id

INT

aux_uuid

STRING

aux_details

STRUCT<uuid: STRING, name: STRING, email: STRING>

aux_info

STRING

session

STRUCT<uuid: STRING, login_time: STRING, device_uuid: STRING, ip: STRING>

location

STRUCT<country: STRING, region: STRING, city: STRING, longitude: DOUBLE, latitude: DOUBLE>

Field

Data type

lw_id

STRING

time

TIMESTAMP

uuid

STRING

timestamp

STRING

actor_uuid

STRING

actor_details

STRUCT<uuid: STRING, name: STRING, email: STRING>

actor_type

STRING

actor_account_uuid

STRING

account_uuid

STRING

action

STRING

object_type

STRING

object_uuid

STRING

object_details

STRUCT<uuid: STRING, name: STRING, email: STRING>

aux_id

INT

aux_uuid

STRING

aux_details

STRUCT<uuid: STRING, name: STRING, email: STRING>

aux_info

STRING

session

STRUCT<uuid: STRING, login_time: STRING, device_uuid: STRING, ip: STRING>

location

STRUCT<country: STRING, region: STRING, city: STRING, longitude: DOUBLE, latitude: DOUBLE>

item_usages​

Primary key: lw_id Cursor field: time

Field

Data type

lw_id

STRING

time

TIMESTAMP

uuid

STRING

timestamp

STRING

used_version

INT

vault_uuid

STRING

item_uuid

STRING

action

STRING

user

STRUCT<uuid: STRING, name: STRING, email: STRING, user_type: STRING, user_account_uuid: STRING>

client

STRUCT<app_name: STRING, app_version: STRING, platform_name: STRING, platform_version: STRING, os_name: STRING, os_version: STRING, ip_address: STRING>

location

STRUCT<country: STRING, region: STRING, city: STRING, longitude: DOUBLE, latitude: DOUBLE>

account_uuid

STRING

Field

Data type

lw_id

STRING

time

TIMESTAMP

uuid

STRING

timestamp

STRING

used_version

INT

vault_uuid

STRING

item_uuid

STRING

action

STRING

user

STRUCT<uuid: STRING, name: STRING, email: STRING, user_type: STRING, user_account_uuid: STRING>

client

STRUCT<app_name: STRING, app_version: STRING, platform_name: STRING, platform_version: STRING, os_name: STRING, os_version: STRING, ip_address: STRING>

location

STRUCT<country: STRING, region: STRING, city: STRING, longitude: DOUBLE, latitude: DOUBLE>

account_uuid

STRING

sign_in_attempts​

Primary key: lw_id Cursor field: time

Field

Data type

lw_id

STRING

time

TIMESTAMP

uuid

STRING

session_uuid

STRING

timestamp

STRING

category

STRING

type

STRING

country

STRING

details

STRUCT<value: STRING>

target_user

STRUCT<uuid: STRING, name: STRING, email: STRING, user_type: STRING, user_account_uuid: STRING>

client

STRUCT<app_name: STRING, app_version: STRING, platform_name: STRING, platform_version: STRING, os_name: STRING, os_version: STRING, ip_address: STRING>

location

STRUCT<country: STRING, region: STRING, city: STRING, longitude: DOUBLE, latitude: DOUBLE>

account_uuid

STRING

Field

Data type

lw_id

STRING

time

TIMESTAMP

uuid

STRING

session_uuid

STRING

timestamp

STRING

category

STRING

type

STRING

country

STRING

details

STRUCT<value: STRING>

target_user

STRUCT<uuid: STRING, name: STRING, email: STRING, user_type: STRING, user_account_uuid: STRING>

client

STRUCT<app_name: STRING, app_version: STRING, platform_name: STRING, platform_version: STRING, os_name: STRING, os_version: STRING, ip_address: STRING>

location

STRUCT<country: STRING, region: STRING, city: STRING, longitude: DOUBLE, latitude: DOUBLE>

account_uuid

STRING

Required 1Password account permissions​

Issue an Events Reporting bearer token with access to audit events, item usages, and sign-in attempts. See Configure authentication to 1Password.