Corelight_v3_notice_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Tables Index


Attribute Value
Ingestion API Supported ✓ Yes

Contents

Schema (33 columns)

Source: KQL validation test schema

Column Name Type
actions dynamic
dst string
email_dest dynamic
file_desc string
file_mime_type string
fuid string
id_orig_h string
id_orig_p int
id_resp_h string
id_resp_p int
msg string
note string
notice_n long
notice_p int
path string
peer_descr string
proto string
remote_location_city string
remote_location_country_code string
remote_location_latitude real
remote_location_longitude real
remote_location_region string
severity_level long
severity_name string
src string
sub string
suppress_for real
system_name string
TimeGenerated datetime
ts datetime
Type string
uid string
write_ts datetime

Schema References

Official Microsoft Learn documentation for field/column information:

Solutions (1)

This table is used by the following solutions:

Connectors (1)

This table is ingested by the following connectors:

Connector Selection Criteria
Corelight Connector Exporter

Content Items Using This Table (3)

Workbooks (3)

In solution Corelight:

Workbook Selection Criteria
Corelight
Corelight_Data_Explorer
Corelight_Security_Workflow

Parsers Using This Table (1)

Other Parsers (1)

Parser Solution Selection Criteria
corelight_notice Corelight

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Tables Index