Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
| Attribute | Value |
|---|---|
| Ingestion API Supported | ✓ Yes |
Source: Connector definition
| Column Name | Type | Description |
|---|---|---|
| ActivityAction | string | The activity action name, e.g. Update. |
| ActivityType | string | The activity type name, e.g. WorkspaceRoleChanged. |
| ActorEmail | string | The email of the actor, when recorded. |
| ActorId | string | The id of the user or agent that performed the activity. |
| ActorName | string | The display name of the actor, when recorded. |
| CfWorkspaceId | string | The ContraForce workspace the event belongs to. |
| Discriminator | string | The audit domain, e.g. WorkspaceManagement or IncidentInvestigation. |
| EventId | string | The audit entry's unique id. |
| Metadata | string | Activity-specific metadata as a JSON string including its $type discriminator; parse with parse_json in queries. |
| TargetResourceId | string | The id of the resource the activity targeted. |
| TargetResourceName | string | The human-readable name of the target resource, when recorded. |
| TargetResourceType | string | The type of the resource the activity targeted, e.g. Incident or User. |
| TimeGenerated | datetime | When the audited activity happened (UTC). |
Official Microsoft Learn documentation for field/column information:
This table is used by the following solutions:
This table is ingested by the following connectors:
| Connector | Selection Criteria |
|---|---|
| ContraForce Events |
In solution ContraForce:
| Analytic Rule | Selection Criteria |
|---|---|
| ContraForce - Destructive workspace action | |
| ContraForce - Machine credential activity | |
| ContraForce - Privileged access change |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊