1Password Event Logs connector reference

Important

This feature is in Beta. To use it, a workspace admin must turn on Lakeflow Connect for 1Password Event Logs from the Previews page. See Manage Azure Databricks previews.

Reference information for the managed 1Password Event Logs connector, including the supported source tables, destination schemas, and connection options.

Supported source tables

The 1Password Event Logs connector supports the following source tables, under the default source schema:

Source table Primary key Description Sync mode Cursor field
audit_events lw_id Actions performed in your 1Password account, such as changes to users, vaults, and items. Incremental time
item_usages lw_id Item access events from shared vaults. Incremental time
sign_in_attempts lw_id Authentication attempts against your 1Password account. Incremental time

Connection options

Set these options when you create the Unity Catalog connection.

Option Type Required Description
base_url String No The Events API host without an https:// prefix. The default is events.1password.com. Allowed hosts match *.1password.com, *.1password.ca, and *.1password.eu.
bearer_token String (secret) Yes The Events Reporting bearer token used to authenticate to the Events API.

Connector options

The 1Password Event Logs connector has no additional configuration options beyond the pipeline settings available for all managed connectors. See Ingest data from 1Password.

Destination table schemas

These columns are the Events API fields the connector writes. SCD Type 2 is not supported.

audit_events

Primary key: lw_id Cursor field: time

Field Data type
lw_id STRING
time TIMESTAMP
uuid STRING
timestamp STRING
actor_uuid STRING
actor_details STRUCT<uuid: STRING, name: STRING, email: STRING>
actor_type STRING
actor_account_uuid STRING
account_uuid STRING
action STRING
object_type STRING
object_uuid STRING
object_details STRUCT<uuid: STRING, name: STRING, email: STRING>
aux_id INT
aux_uuid STRING
aux_details STRUCT<uuid: STRING, name: STRING, email: STRING>
aux_info STRING
session STRUCT<uuid: STRING, login_time: STRING, device_uuid: STRING, ip: STRING>
location STRUCT<country: STRING, region: STRING, city: STRING, longitude: DOUBLE, latitude: DOUBLE>

item_usages

Primary key: lw_id Cursor field: time

Field Data type
lw_id STRING
time TIMESTAMP
uuid STRING
timestamp STRING
used_version INT
vault_uuid STRING
item_uuid STRING
action STRING
user STRUCT<uuid: STRING, name: STRING, email: STRING, user_type: STRING, user_account_uuid: STRING>
client STRUCT<app_name: STRING, app_version: STRING, platform_name: STRING, platform_version: STRING, os_name: STRING, os_version: STRING, ip_address: STRING>
location STRUCT<country: STRING, region: STRING, city: STRING, longitude: DOUBLE, latitude: DOUBLE>
account_uuid STRING

sign_in_attempts

Primary key: lw_id Cursor field: time

Field Data type
lw_id STRING
time TIMESTAMP
uuid STRING
session_uuid STRING
timestamp STRING
category STRING
type STRING
country STRING
details STRUCT<value: STRING>
target_user STRUCT<uuid: STRING, name: STRING, email: STRING, user_type: STRING, user_account_uuid: STRING>
client STRUCT<app_name: STRING, app_version: STRING, platform_name: STRING, platform_version: STRING, os_name: STRING, os_version: STRING, ip_address: STRING>
location STRUCT<country: STRING, region: STRING, city: STRING, longitude: DOUBLE, latitude: DOUBLE>
account_uuid STRING

Required 1Password account permissions

Issue an Events Reporting bearer token with access to audit events, item usages, and sign-in attempts. See Configure authentication to 1Password.