DarktraceModelAlerts_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Tables Index


Attribute Value
Ingestion API Supported ✓ Yes

Contents

Schema (39 columns)

Source: Data Collection Rule definition

Column Name Type
alertTime datetime
alertUrl string
antigena boolean
category string
compliance boolean
cSensor boolean
cSensorId string
customLabel string
darktraceProduct string
description string
destHost string
destIp string
destMac string
destPort string
details string
deviceCredentials dynamic
deviceHostname string
deviceId int
deviceLabel string
deviceSubnet string
deviceType string
latitude real
longitude real
message string
mitreTechniques dynamic
modelName string
modelTags dynamic
pid int
score int
sid int
sourceHost string
sourceIp string
sourceMac string
sourcePort string
threatId int
TimeGenerated datetime
triggeredComponents string
typeLabel string
uuid string

Schema References

Official Microsoft Learn documentation for field/column information:

Solutions (1)

This table is used by the following solutions:

Connectors (1)

This table is ingested by the following connectors:

Connector Selection Criteria
Darktrace ActiveAI Security Platform Connector

Content Items Using This Table (2)

Analytic Rules (1)

In solution Darktrace:

Analytic Rule Selection Criteria
Darktrace Model Alert

Workbooks (1)

In solution Darktrace:

Workbook Selection Criteria
DarktraceActiveAISecurityPlatformWorkbook

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Tables Index