BoxEventsV2_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index


Attribute Value
Ingestion API Supported ✓ Yes

Contents

Schema (38 columns)

Source: KQL validation test schema

Column Name Type
accessible_by_id string
accessible_by_login string
accessible_by_name string
accessible_by_type string
additional_details dynamic
created_at datetime
created_by_id string
created_by_login string
created_by_name string
created_by_type string
event_category string
event_id string
event_type string
EventEndTime string
ip_address string
session_id dynamic
source_file_id string
source_file_name string
source_folder_id string
source_folder_name string
source_id string
source_item_id string
source_item_name string
source_item_type string
source_login string
source_name string
source_owned_by_id string
source_owned_by_login string
source_owned_by_name string
source_owned_by_type string
source_parent_id string
source_parent_name string
source_parent_type string
source_type string
source_user_email string
source_user_id string
source_user_name string
TimeGenerated datetime

Solutions (1)

This table is used by the following solutions:

Connectors (2)

This table is ingested by the following connectors:

Connector Selection Criteria
[DEPRECATED] Box Events (using Azure Function)
Box Events (via Codeless Connector Framework)

Content Items Using This Table (21)

Analytic Rules (10)

In solution Box:

Analytic Rule Selection Criteria
Box - Abmormal user activity
Box - Executable file in folder
Box - File containing sensitive data
Box - Forbidden file type downloaded
Box - Inactive user login
Box - Item shared to external entity
Box - Many items deleted by user
Box - New external user
Box - User logged in as admin
Box - User role changed to owner

Hunting Queries (10)

In solution Box:

Hunting Query Selection Criteria
Box - Deleted users
Box - Downloaded data volume per user
Box - IP list for admin users
Box - Inactive admin users
Box - Inactive users
Box - New users
Box - New users
Box - Suspicious or sensitive files
Box - Uploaded data volume per user
Box - Users with owner permissions

Workbooks (1)

In solution Box:

Workbook Selection Criteria
Box

Parsers Using This Table (1)

Other Parsers (1)

Parser Solution Selection Criteria
BoxEvents Box

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index