Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
| Attribute | Value |
|---|---|
| Supports Transformations | ✓ Yes |
| Ingestion API Supported | ✓ Yes |
| Lake-Only Ingestion | ✓ Yes (source) |
Source: Connector definition
| Column Name | Type | Description |
|---|---|---|
| AccountId | string | Account id |
| AccountName | string | Account name |
| ActiveDirectory | string | Active directory |
| ActiveThreats | real | Active threats |
| AgentVersion | string | Agent version |
| AllowRemoteShell | bool | Allow remote shell |
| AppsVulnerabilityStatus | string | Apps vulnerability status |
| ComputerName | string | Computer name |
| ConsoleMigrationStatus | string | Console migration status |
| CoreCount | real | Core count |
| CpuCount | real | Cpu count |
| CpuId | string | Cpu id |
| CreatedAt | datetime | Created at |
| Domain | string | Domain |
| EncryptedApplications | bool | Encrypted applications |
| ExternalId | string | External id |
| ExternalIp | string | External ip |
| FullDiskScanLastUpdatedAt | datetime | Full disk scan last updated at |
| GroupId | string | Group id |
| GroupIp | string | Group ip |
| GroupName | string | Group name |
| GroupUpdatedAt | datetime | Group updated at |
| Id | string | Id |
| Infected | bool | Infected |
| InRemoteShellSession | bool | In remote shell session |
| InstallerType | string | Installer type |
| IsActive | bool | Is active |
| IsDecommissioned | bool | Is decommissioned |
| IsPendingUninstall | bool | Is pending uninstall |
| IsUninstalled | bool | Is uninstalled |
| IsUpToDate | bool | Is up to date |
| LastActiveDate | datetime | Last active date |
| LastIpToMgmt | string | Last ip to mgmt |
| LastLoggedInUserName | string | Last logged in user name |
| LicenseKey | string | License key |
| Locations | string | Locations |
| LocationType | string | Location type |
| MachineType | string | Machine type |
| MissingPermissions | string | Missing permissions |
| MitigationMode | string | Mitigation mode |
| MitigationModeSuspicious | string | Mitigation mode suspicious |
| ModelName | string | Model name |
| NetworkInterfaces | string | Network interfaces |
| NetworkQuarantineEnabled | bool | Network quarantine enabled |
| NetworkStatus | string | Network status |
| OperationalStateExpiration | string | Operational state expiration |
| OsArch | string | Os arch |
| OsName | string | Os name |
| OsRevision | string | Os revision |
| OsStartTime | datetime | Os start time |
| OsType | string | Os type |
| OsUsername | string | Os username |
| PolicyUpdatedAt | datetime | Policy updated at |
| RangerStatus | string | Ranger status |
| RangerVersion | string | Ranger version |
| RegisteredAt | datetime | Registered at |
| RemoteProfilingState | string | Remote profiling state |
| ScanAbortedAt | datetime | Scan aborted at |
| ScanFinishedAt | datetime | Scan finished at |
| ScanStartedAt | datetime | Scan started at |
| ScanStatus | string | Scan status |
| SiteId | string | Site id |
| SiteName | string | Site name |
| ThreatRebootRequired | bool | Threat reboot required |
| TimeGenerated | datetime | The timestamp (in UTC) when the log entry was generated. |
| TotalMemory | real | Total memory |
| UpdatedAt | datetime | Updated at |
| UserActionsNeeded | string | User actions needed |
| Uuid | string | Uuid |
Official Microsoft Learn documentation for field/column information:
This table is used by the following solutions:
This table is ingested by the following connectors:
| Connector | Selection Criteria |
|---|---|
| [DEPRECATED] SentinelOne (using Azure Function) |
In solution SentinelOne:
In solution SentinelOne:
In solution SentinelOne:
| Workbook | Selection Criteria |
|---|---|
| SentinelOne |
| Parser | Solution | Selection Criteria |
|---|---|---|
| SentinelOne | SentinelOne |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊