SecurityNestedRecommendation

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Tables Index


Reference for SecurityNestedRecommendation table in Azure Monitor Logs.

Attribute Value
Category -
Basic Logs Eligible ✗ No (source)
Supports Transformations ✓ Yes (source)
Ingestion API Supported ✗ No
Azure Monitor Tables Reference View Documentation

Contents

Schema (30 columns)

Source: Azure Monitor documentation

Column Name Type Description
_BilledSize real The record size in bytes
_IsBillable string Specifies whether ingesting the data is billable. When _IsBillable is false ingestion isn't billed to your Azure account
_ResourceId string A unique identifier for the resource that the record is associated with
_SubscriptionId string A unique identifier for the subscription that the record is associated with
AdditionalData dynamic Additional details of the sub-assessment
AssessedResourceId string Id of the assessed resource
Category string Category of the sub-assessment
Cause string Cause of the assessment status
Description string Description of the assessment status
Id string Id of the assessed recommendation
Impact string Description of the impact of this sub-assessment
IsSnapshot bool Indicates whether the data was exported as part of a snapshot when 'true', or streamed in real-time when 'false'.
NestedRecommendationId string Id of the nested-recommendation
ParentRecommendationId string Id of the parent recommendation
RecommendationLink string Recommendation link URL
RecommendationName string Display name of the sub-assessment
RecommendationSeverity string The sub-assessment severity level
RecommendationState string The sub-assessment state
RecommendationSubscriptionId string Recommendation's subscription Id
RemediationDescription string Information on how to remediate this sub-assessment
RemidiationDescription string Information on how to remediate this sub-assessment
ResourceDetails dynamic Details of the resource that was assessed
ResourceGroup string Resource group name
ResourceProviderType string Resource provider type of the assessed resource
SourceSystem string The type of agent the event was collected by. For example, OpsManager for Windows agent, either direct connect or Operations Manager, Linux for all Linux agents, or Azure for Azure Diagnostics
SubAssessmentTimeGeneration datetime The date and time the sub-assessment was generated
TenantId string The Log Analytics workspace ID
TimeGenerated datetime The date and time the sub-assessment was exported
Type string Resource type
VulnerabilityId string Vulnerability Id

Schema References

Official Microsoft Learn documentation for field/column information:

Solutions (3)

This table is used by the following solutions:


Content Items Using This Table (4)

Analytic Rules (1)

In solution Apache Log4j Vulnerability Detection: RemediationDescription has "CVE-2021-44228"

Analytic Rule
Vulnerable Machines related to log4j CVE-2021-44228

Workbooks (3)

In solution Apache Log4j Vulnerability Detection: RemediationDescription has "CVE-2021-44228"

Workbook
Log4jPostCompromiseHunting

In solution AzureSecurityBenchmark: RecommendationState == "Unhealthy"

Workbook
AzureSecurityBenchmark

In solution ContinuousDiagnostics&Mitigation:

Workbook Selection Criteria
ContinuousDiagnostics&Mitigation

Selection Criteria Summary (2 criteria, 3 total references)

References by type: 0 connectors, 3 content items, 0 ASIM parsers, 0 other parsers.

Selection Criteria Connectors Content Items ASIM Parsers Other Parsers Total
RemediationDescription has "CVE-2021-44228" - 2 - - 2
RecommendationState == "Unhealthy" - 1 - - 1
Total 0 3 0 0 3

RecommendationState

Value Connectors Content Items ASIM Parsers Other Parsers Total
Unhealthy - 1 - - 1

RemediationDescription

Value Connectors Content Items ASIM Parsers Other Parsers Total
has CVE-2021-44228 - 2 - - 2

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Tables Index