Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
Internal Use Table: This table is created and used internally by the following solutions: Infoblox, Infoblox SOC Insights. It is written to by playbooks for solution-specific data storage.
| Attribute | Value |
|---|---|
| Category | Internal |
| Supports Transformations | ✗ No |
| Ingestion API Supported | ✓ Yes |
| Lake-Only Ingestion | ✗ No (source) |
Source: Connector definition
| Column Name | Type | Description |
|---|---|---|
| ConnectorName | string | Connector friendly name assigned during connector setup |
| DateChanged | datetime | Timestamp when the insight was last modified |
| EventsBlockedCount | string | Number of events that were blocked (string from API) |
| EventsNotBlockedCount | string | Number of events that were not blocked (string from API) |
| FeedSource | string | Source of the threat intelligence feed |
| InsightId | string | Unique identifier for the insight |
| MostRecentAt | datetime | Timestamp of the most recent event related to this insight |
| NumEvents | string | Total number of events associated with this insight (string from API) |
| PriorityText | string | Priority level in text format (e.g., CRITICAL, HIGH, MEDIUM, LOW) |
| StartedAt | datetime | Timestamp when the insight was first detected |
| Status | string | Current status of the insight (e.g., Active, Closed, Dismissed) |
| TClass | string | Threat class or category |
| TenantHost | string | Infoblox API host extracted from the configured API URL |
| TFamily | string | Threat family classification |
| ThreatType | string | Type of threat detected (e.g., Malware, DNS Tunneling, C2, DGA) |
| TimeGenerated | datetime | The timestamp (in UTC) when the insight was first detected. |
Official Microsoft Learn documentation for field/column information:
This table is used by the following solutions:
This table is ingested by the following connectors:
| Connector | Selection Criteria |
|---|---|
| Infoblox SOC Insights (via Codeless Connector Framework) | |
| Infoblox SOC Insight Data Connector via REST API |
In solution Infoblox:
| Analytic Rule | Selection Criteria |
|---|---|
| Infoblox - SOC Insight Detected - API Source |
In solution Infoblox SOC Insights:
| Analytic Rule | Selection Criteria |
|---|---|
| Infoblox - SOC Insight Detected - API Source |
In solution Infoblox:
| Workbook | Selection Criteria |
|---|---|
| Infoblox_Workbook |
In solution Infoblox SOC Insights:
| Workbook | Selection Criteria |
|---|---|
| InfobloxSOCInsightsWorkbook |
| Parser | Solution | Selection Criteria |
|---|---|---|
| InfobloxInsight | Infoblox | |
| InfobloxInsight | Infoblox SOC Insights |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊