Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊
Reference for ProtectionStatus table in Azure Monitor Logs.
| Attribute | Value |
|---|---|
| Category | Security |
| Basic Logs Eligible | ✗ No (source) |
| Supports Transformations | ✓ Yes (source) |
| Ingestion API Supported | ✗ No |
| Azure Monitor Tables Reference | View Documentation |
Source: Azure Monitor documentation
| Column Name | Type | Description |
|---|---|---|
| _BilledSize | real | The record size in bytes |
| _IsBillable | string | Specifies whether ingesting the data is billable. When _IsBillable isfalseingestion isn't billed to your Azure account |
| _ResourceId | string | A unique identifier for the resource that the record is associated with |
| _SubscriptionId | string | A unique identifier for the subscription that the record is associated with |
| AMProductVersion | string | |
| Computer | string | |
| ComputerEnvironment | string | |
| ComputerIP_Hidden | string | |
| DetectionId | string | |
| DeviceName | string | |
| ManagementGroupName | string | |
| OSName | string | |
| ProtectionStatus | string | |
| ProtectionStatusDetails | string | |
| ProtectionStatusRank | int | |
| Resource | string | |
| ResourceGroup | string | |
| ResourceId | string | |
| ResourceProvider | string | |
| ResourceType | string | |
| ScanDate | datetime | |
| SignatureVersion | string | |
| SourceComputerId | string | |
| SourceSystem | string | The type of agent the event was collected by. For example,OpsManagerfor Windows agent, either direct connect or Operations Manager,Linuxfor all Linux agents, orAzurefor Azure Diagnostics |
| SubscriptionId | string | |
| TenantId | string | The Log Analytics workspace ID |
| Threat | string | |
| ThreatStatus | string | |
| ThreatStatusDetails | string | |
| ThreatStatusRank | int | |
| TimeGenerated | datetime | |
| Type | string | The name of the table |
| TypeofProtection | string | |
| VMUUID | string |
This table is used by the following solutions:
In solution AzureSecurityBenchmark:
| Workbook | Selection Criteria |
|---|---|
| AzureSecurityBenchmark |
In solution SOC Handbook:
| Workbook | Selection Criteria |
|---|---|
| InvestigationInsights |
GitHub Only:
| Workbook | Selection Criteria |
|---|---|
| ASC-ComplianceandProtection | |
| InvestigationInsights |
This table collects data from the following Azure resource types:
microsoft.compute/virtualmachinesmicrosoft.conenctedvmwarevsphere/virtualmachinesmicrosoft.azurestackhci/virtualmachinesmicrosoft.scvmm/virtualmachinesmicrosoft.compute/virtualmachinescalesetsBrowse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊