home

Mobile Endpoint Security

Lookout Product Documentation

Find answers about using and optimizing Lookout products.

Reviewing the Event Feed

A custom script runs every 60 seconds to retrieve events from the Lookout Cloud that are associated with the API key provided during configuration, without the need to query the API endpoint yourself. All such events have a source value of lookout:



If you are reviewing events from more than one tenant, use the value of the entName field to distinguish between them.

Note:

NOTE: All eventTime values in JSON are returned in Coordinated Universal Time (UTC), and list the time that Lookout generated the event. The value in the Time column is the timestamp that Splunk generates when Lookout pushes a set of events to Splunk.