Find which users have used USB mass storage devices on managed devices. This collector gets details about last usage and device details.
Field | Type | Description |
|---|---|---|
vendor_id | String | Device's vendor ID. |
product_id | String | Device's product ID. |
serial_number | String | Device's serial number. |
device_type | String | Only "USB storage" type is supported. |
guid | String | ID provided by operating system (Windows only). |
last_connection_time | Timestamp | Last time the device was plugged (Windows only). |
user_name | String | User that mounted the device. If no user was logged in when device was mounted, then the field will be empty (Windows only). |
last_time_used_by_user | Timestamp | Last time the operating system touched the device. |
Windows | Linux | macOS |
|---|---|---|
3.0 and later | 3.0 and later | 3.0 and later |
UsbConnectedStorageDevices where HostInfo os contains "win"
UsbConnectedStorageDevices where HostInfo os contains "win"