DeviceTvmSecureConfigurationAssessment

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index


Microsoft Defender Vulnerability Management assessment events, indicating the status of various security configurations on devices

Attribute Value
Category MDE
Basic Logs Eligible ✓ Yes (source)
Supports Transformations ✓ Yes (source)
Ingestion API Supported ✗ No
Azure Monitor Tables Reference View Documentation
Defender XDR Advanced Hunting Schema View Documentation

Contents

Schema (18 columns)

Source: Azure Monitor documentation

Column Name Type Description
_BilledSize real The record size in bytes
_IsBillable string Specifies whether ingesting the data is billable. When _IsBillable isfalseingestion isn't billed to your Azure account
ConfigurationCategory string Category or grouping to which the configuration belongs
ConfigurationId string Unique identifier for a specific configuration
ConfigurationImpact real Rated impact of the configuration to the overall configuration score (1-10)
ConfigurationSubcategory string Subcategory or subgrouping to which the configuration belongs. In many cases, this describes specific capabilities or features.
Context dynamic Machine data configuration context
DeviceId string Unique identifier for the device in the service
DeviceName string Fully qualified domain name (FQDN) of the device
IsApplicable bool Indicates whether the configuration or policy is applicable
IsCompliant bool Indicates whether the configuration or policy is properly configured
IsExpectedUserImpact bool Indicates if user impact is expected when configuration applied
OSPlatform string Platform of the operating system running on the device. This indicates specific operating systems, including variations within the same family, such as Windows 10 and Windows 7
SourceSystem string The type of agent the event was collected by. For example,OpsManagerfor Windows agent, either direct connect or Operations Manager,Linuxfor all Linux agents, orAzurefor Azure Diagnostics
TenantId string The Log Analytics workspace ID
TimeGenerated datetime Date and time when the record was generated
Timestamp datetime Date and time when the record was generated
Type string The name of the table

Solutions (1)

This table is used by the following solutions:


Content Items Using This Table (3)

Hunting Queries (3)

Standalone Content:

Hunting Query Selection Criteria
MDE_DeviceHealth

GitHub Only:

Hunting Query Selection Criteria
Endpoint Agent Health Status Report
MD AV Signature and Platform Version

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index