CommvaultAlertsCCF_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Tables Index


Attribute Value
Ingestion API Supported ✓ Yes

Contents

Schema (11 columns)

Source: Connector definition

Column Name Type Description
AnomalyType int Bitfield integer representing the type(s) of anomaly detected. Common bits: 64=Ransomware, 8192=VSA Attack.
ClientId int Numeric identifier of the Commvault client.
ClientName string Name of the Commvault client (endpoint) where the anomaly was detected.
CreateCount int Number of files created during the anomaly window.
DeleteCount int Number of files deleted during the anomaly window.
InfectedFilesCount int Number of files identified as infected.
Location string Location or region associated with the anomaly.
ModCount int Number of files modified during the anomaly window.
RefTime long Raw epoch timestamp (seconds) from the Commvault anomaly event.
RenameCount int Number of files renamed during the anomaly window.
TimeGenerated datetime Timestamp derived from the anomaly refTime field.

Schema References

Official Microsoft Learn documentation for field/column information:

Solutions (1)

This table is used by the following solutions:

Connectors (1)

This table is ingested by the following connectors:

Connector Selection Criteria
Commvault Security IQ (via Codeless Connector Framework)

Content Items Using This Table (1)

Analytic Rules (1)

In solution Commvault Security IQ:

Analytic Rule Selection Criteria
Commvault Cloud Alert

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Tables Index