ContraForceEvents_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Tables Index


Attribute Value
Ingestion API Supported ✓ Yes

Contents

Schema (13 columns)

Source: Connector definition

Column Name Type Description
ActivityAction string The activity action name, e.g. Update.
ActivityType string The activity type name, e.g. WorkspaceRoleChanged.
ActorEmail string The email of the actor, when recorded.
ActorId string The id of the user or agent that performed the activity.
ActorName string The display name of the actor, when recorded.
CfWorkspaceId string The ContraForce workspace the event belongs to.
Discriminator string The audit domain, e.g. WorkspaceManagement or IncidentInvestigation.
EventId string The audit entry's unique id.
Metadata string Activity-specific metadata as a JSON string including its $type discriminator; parse with parse_json in queries.
TargetResourceId string The id of the resource the activity targeted.
TargetResourceName string The human-readable name of the target resource, when recorded.
TargetResourceType string The type of the resource the activity targeted, e.g. Incident or User.
TimeGenerated datetime When the audited activity happened (UTC).

Schema References

Official Microsoft Learn documentation for field/column information:

Solutions (1)

This table is used by the following solutions:

Connectors (1)

This table is ingested by the following connectors:

Connector Selection Criteria
ContraForce Events

Content Items Using This Table (3)

Analytic Rules (3)

In solution ContraForce:

Analytic Rule Selection Criteria
ContraForce - Destructive workspace action
ContraForce - Machine credential activity
ContraForce - Privileged access change

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Tables Index