KnowBe4Defend_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index


Attribute Value
Custom Log V1 Yes 🔶 — uses type-suffixed column names
Ingestion API Supported ✓ Yes

Contents

Schema (15 columns)

Source: KQL validation test schema

Column Name Type
email_attachments_s string
email_firstTimeSender_b bool
email_linksClicked_d real
email_mailFrom_s string
email_messageId_s string
email_payload_Type_s string
email_phishType_s string
email_rcptTo_s string
email_senderIp_s string
email_subject_s string
email_threat_s string
email_trust_s string
event_s string
linkClicked_s string
TimeGenerated datetime

Solutions (3)

This table is used by the following solutions:

Connectors (3)

This table is ingested by the following connectors:

Connector Selection Criteria
Egress Defend
Egress Iris Connector
KnowBe4 Defend

Content Items Using This Table (7)

Analytic Rules (4)

In solution Egress Defend:

Analytic Rule Selection Criteria
Egress Defend - Dangerous Attachment Detected
Egress Defend - Dangerous Link Click

In solution KnowBe4 Defend:

Analytic Rule Selection Criteria
KnowBe4 Defend - Dangerous Attachment Detected
KnowBe4 Defend - Dangerous Link Click

Hunting Queries (1)

In solution KnowBe4 Defend:

Hunting Query Selection Criteria
Dangerous emails with links clicked

Workbooks (2)

In solution Egress Defend:

Workbook Selection Criteria
DefendMetrics

In solution KnowBe4 Defend:

Workbook Selection Criteria
KnowBe4DefendMetrics

Parsers Using This Table (1)

Other Parsers (1)

Parser Solution Selection Criteria
DefendAuditData KnowBe4 Defend

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index