Entities_Data_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index


Attribute Value
Ingestion API Supported ✓ Yes

Contents

Schema (35 columns)

Source: KQL validation test schema

Column Name Type
account_type dynamic
assignment dynamic
assignment_assigned_by dynamic
assignment_assigned_by_id real
assignment_assigned_by_username string
assignment_assigned_to dynamic
assignment_assigned_to_id real
assignment_assigned_to_username string
assignment_date_assigned datetime
assignment_id real
attack_profile string
attack_rating real
breadth_contrib real
detection_set dynamic
entity_type string
host_type dynamic
id real
importance real
ip string
is_prioritized bool
last_detection_timestamp datetime
last_modified_timestamp datetime
name string
notes dynamic
privilege_category string
privilege_level real
sensors dynamic
severity string
state string
tags dynamic
TimeGenerated datetime
Type string
urgency_score real
url string
velocity_contrib real

Solutions (1)

This table is used by the following solutions:

Connectors (1)

This table is ingested by the following connectors:

Connector Selection Criteria
Vectra XDR

Content Items Using This Table (4)

Analytic Rules (4)

In solution Vectra XDR:

Analytic Rule Selection Criteria
Vectra Create Incident Based on Priority for Accounts
Vectra Create Incident Based on Priority for Hosts
Vectra Create Incident Based on Tag for Accounts
Vectra Create Incident Based on Tag for Hosts

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index