Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
| Attribute | Value |
|---|---|
| Ingestion API Supported | ✓ Yes |
Source: Connector definition
| Column Name | Type | Description |
|---|---|---|
| Actions | dynamic | Actions taken on or available for the event. |
| AdditionalData | string | Additional parameters and links related to the event. |
| AvailableEventActions | dynamic | List of available actions that can be performed on the event. |
| ConfidenceIndicator | string | Confidence level of the threat detection (e.g., malicious, suspicious). |
| CustomerId | string | Customer identifier in the Check Point platform. |
| Data | string | Additional event data. |
| Description | string | Detailed description of the security event. |
| EntityId | string | Entity identifier associated with the event. |
| EntityLink | string | Deep link to the entity in the Check Point portal. |
| EventCreated | datetime | Timestamp when the event was created. |
| EventId | string | Unique identifier for the security event. |
| EventType | string | Type of security event (e.g., dlp, phishing, malware). |
| Saas | string | SaaS platform source (e.g., office365_emails, gmail). |
| SenderAddress | string | Email address of the sender associated with the event. |
| Severity | string | Severity level of the event (Low, Medium, High, Highest). |
| State | string | Current state of the event (e.g., dismissed, active). |
| TimeGenerated | datetime | The timestamp (in UTC) when the log entry was generated. |
Official Microsoft Learn documentation for field/column information:
This table is used by the following solutions:
This table is ingested by the following connectors:
| Connector | Selection Criteria |
|---|---|
| Check Point Email Security (via Codeless Connector Framework) |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊