Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊
| Attribute | Value |
|---|---|
| Custom Log V1 | Yes 🔶 — uses type-suffixed column names |
| Ingestion API Supported | ✓ Yes |
Source: KQL validation test schema
| Column Name | Type |
|---|---|
| access_device_browser_s | string |
| access_device_browser_version_s | string |
| access_device_ip_s | string |
| access_device_is_encryption_enabled_s | string |
| access_device_is_firewall_enabled_s | string |
| access_device_is_password_set_s | string |
| access_device_location_city_s | string |
| access_device_location_country_s | string |
| access_device_location_state_s | string |
| access_device_os_s | string |
| access_device_os_version_s | string |
| alias_s | string |
| application_key_s | string |
| application_name_s | string |
| auth_device_name_s | string |
| email_s | string |
| event_type_s | string |
| factor_s | string |
| isotimestamp_t | datetime |
| reason_s | string |
| result_s | string |
| TimeGenerated | datetime |
| timestamp_d | real |
| txid_g | string |
| user_groups_s | string |
| user_key_s | string |
| user_name_s | string |
This table is used by the following solutions:
In solution Threat Intelligence:
| Analytic Rule | Selection Criteria |
|---|---|
| TI Map IP Entity to Duo Security |
GitHub Only:
| Workbook | Selection Criteria |
|---|---|
| DuoSecurity |
| Parser | Solution | Selection Criteria |
|---|---|---|
| DuoSecurityAuthentication | (Legacy) |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊