Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
Reference for Windows365ConnectionLogs table in Azure Monitor Logs.
| Attribute | Value |
|---|---|
| Category | Azure Monitor |
| Basic Logs Eligible | ✓ Yes (source) |
| Supports Transformations | ✗ No (source) |
| Ingestion API Supported | ✗ No |
| Lake-Only Ingestion | ✓ Yes |
| Azure Monitor Tables Reference | View Documentation |
Source: Azure Monitor documentation
| Column Name | Type | Description |
|---|---|---|
| _BilledSize | real | The record size in bytes |
| _IsBillable | string | Specifies whether ingesting the data is billable. When _IsBillable isfalseingestion isn't billed to your Azure account |
| _ResourceId | string | A unique identifier for the resource that the record is associated with |
| _SubscriptionId | string | A unique identifier for the subscription that the record is associated with |
| ActivityId | string | The activity Id for correlating with network, error, and checkpoint data. |
| CallerIPAddress | string | The IP address of the caller. |
| ClientOS | string | The OS of the client that is connecting (if available). |
| CloudPCId | string | The unique identifier of the Cloud PC. |
| GatewayRegion | string | The region of the gateway for the server side user connection. |
| ManagedDeviceName | string | The name of the managed device. |
| PlatformName | string | The platform name of the client application. |
| PlatformVersion | string | The version of the client platform. |
| ResultType | string | The result type of the connection. |
| SessionHostIPAddress | string | The IP address of the session host. |
| SessionHostOSDescription | string | The OS SKU description of the machine where the user connection was orchestrated. |
| SessionHostOSVersion | string | The OS version of the session host. |
| SessionHostSxSStackVersion | string | The side-by-side (SxS) stack version of the session host. |
| SourceSystem | string | The type of agent the event was collected by. For example,OpsManagerfor Windows agent, either direct connect or Operations Manager,Linuxfor all Linux agents, orAzurefor Azure Diagnostics |
| State | string | The state of the connection. |
| TenantId | string | The Log Analytics workspace ID |
| TimeGenerated | datetime | The timestamp (UTC) of the event. |
| TransportType | string | The type of transport used by the RDP connection: Shortpath, TURN, Websocket. |
| Type | string | The name of the table |
| UserPrincipalName | string | The user principal name of the user who initiated the connection. |
Official Microsoft Learn documentation for field/column information:
This table collects data from the following Azure resource types:
microsoft.intune/operationsBrowse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊