Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
| Attribute | Value |
|---|---|
| Ingestion API Supported | ✓ Yes |
Source: Connector definition
| Column Name | Type | Description |
|---|---|---|
| certainty | real | Certainty score (legacy 330 backward compatibility) |
| entity_id | real | ID of the related entity |
| entity_name | string | Name of the related entity |
| entity_type | string | Type of the related entity (Account or Host) |
| id | real | Autoincrementing ID |
| lock_event_timestamp | datetime | Time when the lockdown occurred |
| locked_by | string | User who issued the lockdown |
| TimeGenerated | datetime | |
| unlock_event_timestamp | datetime | Time when the lockdown expires |
Official Microsoft Learn documentation for field/column information:
This table is used by the following solutions:
This table is ingested by the following connectors:
| Connector | Selection Criteria |
|---|---|
| Vectra RUX Security Data Connector (via Codeless Connector Framework) |
In solution Vectra XDR:
| Workbook | Selection Criteria |
|---|---|
| VectraRUXSecurityDashboard | |
| VectraXDR |
| Parser | Solution | Selection Criteria |
|---|---|---|
| VectraLockdown | Vectra XDR |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊