Nexcloud admin_audit message parsing for SIEM

Hi,
I am applying some “parse” processes to meaningfully transfer Nextcloud logs to SIEM. Actions like file deletion, sharing, previewing, and accessing. However, as far as I understand, there is no standard for the “messages” section. How can I find all the statuses related to file operations?

Regards,

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.