UniqkeyEvents_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Tables Index


Attribute Value
Ingestion API Supported ✓ Yes

Contents

Schema (17 columns)

Source: KQL validation test schema

Column Name Type
Action string
ActionId string
ActionSource string
ActorEmail string
ActorId string
ActorType string
Category string
ClientSystem string
EventId string
EventTime datetime
OrganizationId string
Outcome string
SrcIpAddr string
TargetId string
TargetName string
TargetType string
TimeGenerated datetime

Schema References

Official Microsoft Learn documentation for field/column information:

Solutions (1)

This table is used by the following solutions:

Connectors (1)

This table is ingested by the following connectors:

Connector Selection Criteria
Uniqkey Security Events

Content Items Using This Table (10)

Analytic Rules (9)

In solution Uniqkey:

Analytic Rule Selection Criteria
Uniqkey - Credential export from newly created account
Uniqkey - Data export activity
Uniqkey - Departing employee credential export
Uniqkey - Event ingestion stopped
Uniqkey - Excessive credential access
Uniqkey - Platform threat detection
Uniqkey - Security policy change
Uniqkey - Self-granted privilege or access change
Uniqkey - Sign-in from unfamiliar IP address

Workbooks (1)

In solution Uniqkey:

Workbook Selection Criteria
Uniqkey

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Tables Index