Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
Reference for CrowdStrikeAuditEvents table in Azure Monitor Logs.
| Attribute | Value |
|---|---|
| Category | Crowdstrike |
| Basic Logs Eligible | ✓ Yes (source) |
| Supports Transformations | ✓ Yes (source) |
| Ingestion API Supported | ✓ Yes |
| Lake-Only Ingestion | ✓ Yes |
| Azure Monitor Tables Reference | View Documentation |
| Azure Monitor Logs Ingestion API | View Documentation |
Source: Azure Monitor documentation
| Column Name | Type | Description |
|---|---|---|
| _BilledSize | real | The record size in bytes |
| _IsBillable | string | Specifies whether ingesting the data is billable. When _IsBillable isfalseingestion isn't billed to your Azure account |
| AccountId | string | Cloud account ID. |
| AddedPrivileges | string | Privileges that were added to the account. |
| AgentId | string | Unique identifier for the CrowdStrike agent. |
| AgentIdString | string | The agent ID string. |
| AggregateId | string | Aggregate identifier for related detections. |
| ApiClientId | string | API client ID used for the request. |
| AppId | string | Application ID. |
| AuditEventType | string | Event type from the audit attributes. |
| AuditKeyValues | string | JSON string containing audit key-value pairs. |
| AuthenticationProtocol | string | Authentication protocol used (e.g., NTLM, Kerberos). |
| Author | string | Author of the detection rule. |
| Category | string | Category of the identity protection event (e.g., Incident). |
| Cid | string | Customer ID in the CrowdStrike platform. |
| CloudIndicator | string | Indicates if the detection involves cloud-based indicators. |
| CloudPlatform | string | Cloud platform (e.g., AWS, Azure, GCP). |
| CloudProvider | string | Cloud provider (e.g., aws, azure, gcp). |
| CloudService | string | Cloud service involved (e.g., EC2, S3). |
| CommandLine | string | Command line used to execute the process. |
| CompositeId | string | Composite identifier combining multiple detection attributes. |
| ComputerName | string | Name of the computer where the IOC was detected. |
| ConnectionDirection | string | Direction of the network connection. |
| Consumes | string | Content type consumed by the API. |
| ContextTimeStamp | datetime | Context timestamp of the IDP detection event (Unix epoch). |
| CrowdStrikeDomain | string | CrowdStrike host/domain configured for this connection; hard-coded on every record so hosts can be differentiated. |
| CurrentPrivileges | string | Current privilege level of the account. |
| CustomerId | string | Customer identifier in the CrowdStrike platform. |
| CustomerIdString | string | The customer ID string. |
| DataDomains | string | Data domains associated with the event. |
| Description | string | Detailed description of the detection. |
| DestinationEndpointIp | string | IP address of the destination endpoint. |
| DestinationEndpointName | string | Name of the destination endpoint. |
| DeviceId | string | Unique identifier for the device. |
| Disposition | string | Assessment result (e.g., Failed, Passed). |
| Eid | string | Event ID. |
| ElapsedMicroseconds | string | Elapsed time in microseconds. |
| ElapsedTime | string | Elapsed time of the request. |
| EndpointIp | string | IP address of the endpoint involved in the incident. |
| EndpointName | string | Name of the endpoint involved in the incident. |
| EndTime | datetime | End time of the event. |
| EndTimestamp | datetime | Unix epoch timestamp when the session ended. |
| EventAction | string | Action that triggered the IOA (e.g., TerminateInstances). |
| EventSource | string | Source of the event (e.g., aws.cloudtrail). |
| EventType | string | The type of event, used to filter logs. |
| EventUuid | string | Unique UUID for the event. |
| ExecutionId | string | Execution identifier for the report run. |
| ExternalApiType | string | The external API type. |
| FalconHostLink | string | Link to the detection details in the CrowdStrike Falcon console. |
| FileName | string | Name of the file associated with the IOC. |
| FilePath | string | Full path to the file. |
| Finding | string | Details of the finding. |
| FineScore | string | Fine score of the incident. |
| FirstSeen | datetime | First time the hash spreading was observed. |
| Flags | string | JSON string containing firewall rule flags (Audit, Log, Monitor). |
| GrandParentCommandLine | string | Command line of the grandparent process. |
| GrandParentImageFileName | string | Image file name of the grandparent process. |
| GrandParentImageFilePath | string | Full path to the grandparent process image file. |
| Hash | string | Credential hash observed spreading across hosts. |
| Highlights | string | JSON string containing highlights of the notification. |
| HostGroups | string | Host groups the system belongs to. |
| HostId | string | Identifier of the host involved in the incident. |
| Hostname | string | Name of the host where the event occurred. |
| HostnameField | string | Hostname of the target system. |
| IcmpCode | string | ICMP code if the protocol is ICMP. |
| IcmpType | string | ICMP type if the protocol is ICMP. |
| IdentityProtectionIncidentId | string | Unique identifier for the identity protection incident. |
| ImageFileName | string | Image file name of the process associated with the event. |
| IncidentDescription | string | Description of the hash spreading incident. |
| IncidentEndTime | datetime | End time of the incident (Unix epoch). |
| IncidentId | string | Unique identifier for the incident. |
| IncidentStartTime | datetime | Start time of the incident (Unix epoch). |
| IncidentType | string | Type of identity protection incident (e.g., GoldenTicketAlert). |
| Ipv | string | IP version (ipv4 or ipv6). |
| ItemId | string | Identifier of the matched item. |
| ItemPostedTimestamp | datetime | Timestamp when the item was posted. |
| ItemType | string | Type of the matched item. |
| LastSeen | datetime | Last time the hash spreading was observed. |
| LateralMovement | string | Lateral movement indicator for the incident. |
| LocalAddress | string | Local IP address involved in the firewall event. |
| LocalIp | string | Local IP address of the host. |
| LocalIpv6 | string | Local IPv6 address of the host. |
| LocalPort | string | Local port number involved in the firewall event. |
| LogonDomain | string | Logon domain associated with the detection. |
| MACAddress | string | MAC address of the host. |
| MatchCount | string | Number of times the firewall rule was matched. |
| MatchCountSinceLastReport | string | Number of matches since the last report. |
| MatchedTimestamp | datetime | Timestamp when the match was found. |
| MD5String | string | MD5 hash of the file. |
| Message | string | Message associated with the audit event. |
| MitreAttack | string | JSON string containing MITRE ATT&CK framework details. |
| MobileDetectionId | string | Unique identifier for the mobile detection. |
| NetworkProfile | string | Network profile identifier. |
| Nonce | string | A unique nonce value. |
| NotificationId | string | Unique identifier for the recon notification. |
| NumberOfCompromisedEntities | string | Number of compromised entities in the incident. |
| NumbersOfAlerts | string | Number of alerts associated with the incident. |
| Objective | string | Objective of the detection (e.g., Follow Through). |
| Offset | string | Stream offset value. |
| OperationName | string | Name of the operation performed. |
| ParentCommandLine | string | Command line of the parent process. |
| ParentImageFileName | string | Image file name of the parent process. |
| ParentImageFilePath | string | Full path to the parent process image file. |
| ParentProcessId | string | Process ID of the parent process. |
| Partition | string | Stream partition. |
| PatternDispositionDescription | string | Description of the pattern disposition action. |
| PatternDispositionFlags | string | JSON string containing flags indicating various pattern disposition actions. |
| PatternDispositionValue | string | Numerical value of the pattern disposition. |
| PatternId | string | Identifier for the detection pattern. |
| Pid | string | Process ID associated with the firewall event. |
| PlatformId | string | Platform ID (e.g., 0=Windows, 1=Mac, 2=Linux). |
| PlatformName | string | Name of the platform (e.g., Windows, Linux, Mac). |
| PolicyId | string | Policy identifier. |
| PolicyName | string | Name of the firewall policy. |
| PolicyStatement | string | Description of the CSPM policy that was triggered. |
| PreviousPrivileges | string | Previous privilege level of the account. |
| ProcessEndTime | datetime | Timestamp when the detected process ended. |
| ProcessId | string | Process ID associated with the IOC. |
| ProcessStartTime | datetime | Timestamp when the detected process started. |
| Produces | string | Content type produced by the API. |
| Protocol | string | Network protocol (e.g., 1=ICMP, 6=TCP, 17=UDP). |
| ReceivedTime | datetime | Time the request was received. |
| Region | string | Cloud region (e.g., us-west-2). |
| RemoteAddress | string | Remote IP address involved in the firewall event. |
| RemotePort | string | Remote port number involved in the firewall event. |
| ReportFileReference | string | File reference path for downloading the report. |
| ReportId | string | Unique identifier for the report. |
| ReportName | string | Name of the scheduled report. |
| ReportType | string | Type of the report (e.g., spotlight_vulnerabilities). |
| ReportUrl | string | URL to the CSPM assessment report. |
| RequestAccept | string | Accept header of the request. |
| RequestContentType | string | Content type of the request. |
| RequestMethod | string | HTTP method of the request (e.g., POST, GET). |
| RequestPath | string | Path of the API request. |
| RequestUriLength | string | Length of the request URI. |
| ResourceAttributes | string | JSON string containing resource attributes. |
| ResourceCreateTime | datetime | Creation time of the resource. |
| ResourceIdType | string | Type of the resource identifier (e.g., Instance Id). |
| ResourcesId | string | Identifier of the cloud resource. |
| ResourcesName | string | Name of the cloud resource. |
| ResourceUrl | string | URL to the resource in the cloud console. |
| RiskScore | string | Risk score associated with the detection. |
| RuleAction | string | Action taken by the firewall rule. |
| RuleDescription | string | Description of the firewall rule. |
| RuleFamilyId | string | Family identifier of the firewall rule. |
| RuleGroupName | string | Name of the firewall rule group. |
| RuleId | string | Identifier of the recon rule. |
| RuleName | string | Name of the recon rule. |
| RulePriority | string | Priority of the recon rule. |
| RuleTopic | string | Topic of the recon rule (e.g., Credential Exposure). |
| Scopes | string | API scopes used for the request. |
| SensorId | string | Unique identifier for the CrowdStrike sensor on the mobile device. |
| SensorIds | string | Sensor IDs associated with the detection. |
| ServiceName | string | Name of the service (e.g., api_request). |
| SessionId | string | Unique identifier for the remote response session. |
| Severity | string | Numerical severity level. |
| SeverityName | string | Text representation of the severity level. |
| SHA1String | string | SHA1 hash of the detected file. |
| SHA256Hashes | string | SHA256 hashes associated with the detection. |
| SHA256String | string | SHA256 hash of the detected file. |
| Source | string | Source of the audit event. |
| SourceAccountDomain | string | Domain of the source account. |
| SourceAccountName | string | Name of the source account. |
| SourceAccountObjectSid | string | Object SID of the source account. |
| SourceAccountUpn | string | User principal name of the source account. |
| SourceEndpointIp | string | IP address of the source endpoint. |
| SourceEndpointName | string | Name of the source endpoint. |
| SourceIp | string | Source IP address. |
| SourceProducts | string | Products associated with the detection source. |
| SourceSystem | string | The type of agent the event was collected by. For example,OpsManagerfor Windows agent, either direct connect or Operations Manager,Linuxfor all Linux agents, orAzurefor Azure Diagnostics |
| SourceVendors | string | Vendors associated with the detection source. |
| SpreadCount | string | Number of hosts the hash has been observed on. |
| StartTime | datetime | Start time of the event. |
| StartTimestamp | datetime | Unix epoch timestamp when the session started. |
| State | string | Current state of the incident (e.g., IN_PROGRESS, CLOSED). |
| Status | string | Status of the report execution. |
| StatusCode | string | HTTP status code of the response. |
| StatusMessage | string | Status message for the report execution. |
| Success | bool | Whether the API call was successful. |
| Tactic | string | MITRE ATT&CK tactic. |
| TacticId | string | The MITRE ATT&CK tactic ID associated with the detection. |
| TacticIds | string | MITRE ATT&CK tactic IDs associated with the detection. |
| Tactics | string | MITRE ATT&CK tactics associated with the detection. |
| Tags | string | JSON string containing resource tags. |
| Technique | string | MITRE ATT&CK technique. |
| TechniqueId | string | The MITRE ATT&CK technique ID associated with the detection. |
| TechniqueIds | string | MITRE ATT&CK technique IDs associated with the detection. |
| Techniques | string | MITRE ATT&CK techniques associated with the detection. |
| TenantId | string | The Log Analytics workspace ID |
| TimeGenerated | datetime | The timestamp (in UTC) when the log entry was generated. |
| TraceId | string | Trace ID for request tracing. |
| TreeId | string | Tree identifier for the process tree. |
| Type | string | The name of the table |
| UserAgent | string | User agent string of the request. |
| UserId | string | User ID associated with the activity. |
| UserIp | string | IP address of the user making the API call. |
| UserName | string | Username who performed the action. |
| UserSourceIp | string | Source IP of the user. |
| UserUuid | string | UUID of the user who owns the scheduled report. |
| XdrType | string | Type of XDR detection (e.g., xdr). |
Official Microsoft Learn documentation for field/column information:
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊