Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
| Attribute | Value |
|---|---|
| Supports Transformations | ✓ Yes |
| Ingestion API Supported | ✓ Yes |
| Lake-Only Ingestion | ✓ Yes (source) |
Source: Connector definition
| Column Name | Type | Description |
|---|---|---|
| AccountId | string | Account id |
| AccountName | string | Account name |
| ActivityType | real | Activity type |
| ActivityUuid | string | Activity uuid |
| AgentId | string | Agent id |
| AgentUpdatedVersion | string | Agent updated version |
| Comments | string | Comments |
| CreatedAt | datetime | Created at |
| Data | string | Data |
| Description | string | Description |
| GroupId | string | Group id |
| GroupName | string | Group name |
| Hash | string | Hash |
| Id | string | Id |
| OsFamily | string | Os family |
| PrimaryDescription | string | Primary description |
| SecondaryDescription | string | Secondary description |
| SiteId | string | Site id |
| SiteName | string | Site name |
| ThreatId | string | Threat id |
| TimeGenerated | datetime | The timestamp (in UTC) when the log entry was generated. |
| UpdatedAt | datetime | Updated at |
| UserId | string | User id |
Official Microsoft Learn documentation for field/column information:
This table is used by the following solutions:
This table is ingested by the following connectors:
| Connector | Selection Criteria |
|---|---|
| [DEPRECATED] SentinelOne (using Azure Function) |
In solution SentinelOne:
In solution SentinelOne:
In solution SentinelOne:
| Workbook | Selection Criteria |
|---|---|
| SentinelOne |
| Parser | Solution | Selection Criteria |
|---|---|---|
| SentinelOne | SentinelOne |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊