ThinkstCanaryIncidents_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Tables Index


Attribute Value
Ingestion API Supported ✓ Yes

Contents

Schema (29 columns)

Source: KQL validation test schema

Column Name Type
Acknowledged string
Created real
CreatedPrintable string
Description string
DestinationIP string
DestinationPort string
Events dynamic
EventsCount string
FlockId string
FlockName string
HashId string
Host dynamic
IncidentId string
IncidentUpdated datetime
IpAddress string
LocalTime string
LogType string
Memo string
NodeId string
Notified string
PreviouslySeenCount real
RawEvent dynamic
Sensor string
SourceIP string
SourcePort string
SrcHostReverse string
TimeGenerated datetime
UpdatedId real
UpdatedTimePrintable string

Schema References

Official Microsoft Learn documentation for field/column information:

Solutions (1)

This table is used by the following solutions:

Connectors (1)

This table is ingested by the following connectors:

Connector Selection Criteria
Thinkst Canary

Content Items Using This Table (1)

Analytic Rules (1)

In solution ThinkstCanary:

Analytic Rule Selection Criteria
Canary alerts to incidents

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Tables Index