RedCanaryDetections_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index


Attribute Value
Custom Log V1 Yes 🔶 — uses type-suffixed column names
Ingestion API Supported ✓ Yes

Contents

Schema (23 columns)

Source: KQL validation test schema

Column Name Type
_ResourceId string
_SubscriptionId string
child_process_iocs_s string
Computer string
cross_process_iocs_s string
detection_details_s string
detection_headline_s string
detection_id_s string
detection_severity_s string
detection_url_s string
file_modification_iocs_s string
host_full_name_s string
host_name_s string
host_os_family_s string
host_os_version_s string
identities_s string
network_connection_iocs_s string
process_iocs_s string
RawData string
registry_modification_iocs_s string
tactics_s string
TimeGenerated datetime
Type string

Solutions (1)

This table is used by the following solutions:

Connectors (1)

This table is ingested by the following connectors:

Connector Selection Criteria
Red Canary Threat Detection

Content Items Using This Table (1)

Analytic Rules (1)

In solution Red Canary:

Analytic Rule Selection Criteria
Red Canary Threat Detection

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index