Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊
| Property | Value |
|---|---|
| Parser Name | ASimAlertEventMicrosoftDefenderXDR |
| Built-in Parser | _ASim_AlertEvent_MicrosoftDefenderXDR |
| Schema | AlertEvent |
| Schema Version | 0.1 |
| Parser Type | 🔌 Source (product-specific) |
| Product | Microsoft Defender XDR |
| Parser Version | 0.2.0 (version history) |
| Last Updated | Jan 09, 2026 |
| Unifying Parser | ASimAlertEvent |
| Source File | Parsers\ASimAlertEvent\Parsers\ASimAlertEventMicrosoftDefenderXDR.yaml |
This ASIM parser supports normalizing the Microsoft Defender XDR logs to the ASIM Alert normalized schema.
This parser reads from the following tables:
| Table | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|
AlertEvidence |
✓ | ✗ | ? |
| Name | Type | Default |
|---|---|---|
disabled |
bool | False |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊