BoxEvents_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index


Attribute Value
Custom Log V1 Yes 🔶 — uses type-suffixed column names
Ingestion API Supported ✓ Yes

Contents

Schema (72 columns)

Source: KQL validation test schema

Column Name Type
_ResourceId string
accessible_by_id_s string
accessible_by_login_s string
accessible_by_name_s string
accessible_by_type_s string
action_by_id_s string
action_by_login_s string
action_by_name_s string
action_by_type_s string
additional_details_access_token_identifier_s string
additional_details_advancedFolderSettings_newOwnerOnlyInvite_b bool
additional_details_advancedFolderSettings_oldOwnerOnlyInvite_b bool
additional_details_annotation_id_d real
additional_details_collab_id_s string
additional_details_comment_id_d real
additional_details_ekm_id_g string
additional_details_group_id_s string
additional_details_group_name_s string
additional_details_is_performed_by_admin_b bool
additional_details_message_s string
additional_details_metadata_operationParams_s string
additional_details_metadata_type_s string
additional_details_role_s string
additional_details_service_id_s string
additional_details_service_name_s string
additional_details_shared_link_id_s string
additional_details_size_d real
additional_details_task_assignment_assigned_to_id_d real
additional_details_task_assignment_assigned_to_login_s string
additional_details_task_assignment_message_s string
additional_details_task_assignment_status_s string
additional_details_task_created_by_id_d real
additional_details_task_created_by_login_s string
additional_details_task_due_at_t datetime
additional_details_task_id_d real
additional_details_task_message_s string
additional_details_type_s string
additional_details_version_id_s string
created_at_t datetime
created_by_id_s string
created_by_login_s string
created_by_name_s string
created_by_type_s string
event_id_g string
event_type_s string
ip_address_s string
source_file_id_s string
source_file_name_s string
source_folder_id_s string
source_folder_name_s string
source_id_s string
source_item_id_s string
source_item_name_g string
source_item_name_s string
source_item_type_s string
source_login_s string
source_name_s string
source_owned_by_id_s string
source_owned_by_login_s string
source_owned_by_name_s string
source_owned_by_type_s string
source_parent_id_s string
source_parent_name_g string
source_parent_name_s string
source_parent_type_s string
source_type_s string
source_user_email_s string
source_user_id_s string
source_user_name_s string
TimeGenerated datetime
Type string
type_s string

Solutions (1)

This table is used by the following solutions:

Connectors (2)

This table is ingested by the following connectors:

Connector Selection Criteria
[DEPRECATED] Box Events (using Azure Function)
Box Events (via Codeless Connector Framework)

Content Items Using This Table (21)

Analytic Rules (10)

In solution Box:

Analytic Rule Selection Criteria
Box - Abmormal user activity
Box - Executable file in folder
Box - File containing sensitive data
Box - Forbidden file type downloaded
Box - Inactive user login
Box - Item shared to external entity
Box - Many items deleted by user
Box - New external user
Box - User logged in as admin
Box - User role changed to owner

Hunting Queries (10)

In solution Box:

Hunting Query Selection Criteria
Box - Deleted users
Box - Downloaded data volume per user
Box - IP list for admin users
Box - Inactive admin users
Box - Inactive users
Box - New users
Box - New users
Box - Suspicious or sensitive files
Box - Uploaded data volume per user
Box - Users with owner permissions

Workbooks (1)

In solution Box:

Workbook Selection Criteria
Box

Parsers Using This Table (1)

Other Parsers (1)

Parser Solution Selection Criteria
BoxEvents Box

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index