Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊
| Attribute | Value |
|---|---|
| Custom Log V1 | Yes 🔶 — uses type-suffixed column names |
| Ingestion API Supported | ✓ Yes |
Source: KQL validation test schema
| Column Name | Type |
|---|---|
| _ResourceId | string |
| AdditionalProgramInfo_s | string |
| Computer | string |
| ConfigurationTarget_s | string |
| DeviceDescription_s | string |
| Drive_s | string |
| Event_s | string |
| InternalID_s | string |
| ManagementGroupName | string |
| Message | string |
| MG | string |
| Model_s | string |
| PreviousPropertyValue_s | string |
| ProgramName_s | string |
| ProgramPID_s | string |
| PropertyAction_s | string |
| PropertyName_s | string |
| PropertyOperationStatus_s | string |
| PropertyValue_s | string |
| RawData | string |
| SerialNumber_s | string |
| SourceFile_s | string |
| SourceFileLastWrite_s | string |
| SourceFileSize_s | string |
| SourceSystem | string |
| TargetFile_s | string |
| TenantId | string |
| Time_s | string |
| TimeGenerated | datetime |
| Type | string |
| User_s | string |
| UserSID_s | string |
| Volume_s | string |
This table is used by the following solutions:
This table is ingested by the following connectors:
| Connector | Selection Criteria |
|---|---|
| Squadra Technologies secRMM |
In solution Squadra Technologies SecRmm:
| Analytic Rule | Selection Criteria |
|---|---|
| Removable storage ONLINE event from secRMM |
In solution Squadra Technologies SecRmm:
| Workbook | Selection Criteria |
|---|---|
| AzureSentinelWorkbookForRemovableStorageSecurityEvents |
GitHub Only:
| Workbook | Selection Criteria |
|---|---|
| SquadraTechnologiesSecRMM |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊