secRMM_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index


Attribute Value
Custom Log V1 Yes 🔶 — uses type-suffixed column names
Ingestion API Supported ✓ Yes

Contents

Schema (33 columns)

Source: KQL validation test schema

Column Name Type
_ResourceId string
AdditionalProgramInfo_s string
Computer string
ConfigurationTarget_s string
DeviceDescription_s string
Drive_s string
Event_s string
InternalID_s string
ManagementGroupName string
Message string
MG string
Model_s string
PreviousPropertyValue_s string
ProgramName_s string
ProgramPID_s string
PropertyAction_s string
PropertyName_s string
PropertyOperationStatus_s string
PropertyValue_s string
RawData string
SerialNumber_s string
SourceFile_s string
SourceFileLastWrite_s string
SourceFileSize_s string
SourceSystem string
TargetFile_s string
TenantId string
Time_s string
TimeGenerated datetime
Type string
User_s string
UserSID_s string
Volume_s string

Solutions (1)

This table is used by the following solutions:

Connectors (1)

This table is ingested by the following connectors:

Connector Selection Criteria
Squadra Technologies secRMM

Content Items Using This Table (3)

Analytic Rules (1)

In solution Squadra Technologies SecRmm:

Analytic Rule Selection Criteria
Removable storage ONLINE event from secRMM

Workbooks (2)

In solution Squadra Technologies SecRmm:

Workbook Selection Criteria
AzureSentinelWorkbookForRemovableStorageSecurityEvents

GitHub Only:

Workbook Selection Criteria
SquadraTechnologiesSecRMM

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index