NISTSP80053

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


Attribute Value
Type Workbook
Solution NISTSP80053
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Selection Criteria Transformations Ingestion API Lake-Only
AADUserRiskEvents ?
AWSCloudTrail ?
AWSVPCFlow ?
AlertEvidence ?
AuditLogs OperationName contains "Delete"
OperationName contains "PIM"
OperationName contains "Remove"
?
AzureActivity ? ?
AzureDiagnostics 🔶 Category in "NetworkSecurityGroupEvent,kube-audit"
Category contains "SQL"
ResourceProvider == "MICROSOFT.KEYVAULT"
ResourceType in "APPLICATIONGATEWAYS,AZUREFIREWALLS,CDNWEBAPPLICATIONFIREWALLPOLICIES,FRONTDOORS,PROFILES,PUBLICIPADDRESSES"
? ?
CarbonBlack_Alerts_CL ? ?
CommonSecurityLog ?
ConfigurationChange ?
DeviceFileEvents ?
DnsEvents ?
Dynamics365Activity ?
EmailEvents ?
GCP_IAM_CL 🔶 ? ?
Heartbeat ? ?
IdentityInfo ?
OfficeActivity ?
Operation ? ?
QualysHostDetectionV3_CL ? ?
SecureScores ?
SecurityAlert ?
SecurityBaseline ?
SecurityEvent ?
SecurityIncident ?
SecurityRecommendation ?
SecurityRegulatoryCompliance ?
SigninLogs ?
StorageBlobLogs ?
Syslog ?
ThreatIntelligenceIndicator ?
Usage ? ?
WindowsFirewall ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Workbooks · Back to NISTSP80053