SlackAudit_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index


Attribute Value
Custom Log V1 Yes 🔶 — uses type-suffixed column names
Ingestion API Supported ✓ Yes

Contents

Schema (30 columns)

Source: KQL validation test schema

Column Name Type
_ResourceId string
action_description_s string
action_s string
actor_type_s string
actor_user_email_s string
actor_user_id_s string
actor_user_name_s string
actor_user_team_s string
Computer string
context_ip_address_s string
context_location_domain_s string
context_location_id_s string
context_location_name_s string
context_location_type_s string
context_session_id_d real
context_ua_s string
date_create_d real
entity_file_filetype_s string
entity_file_id_s string
entity_file_name_s string
entity_file_title_s string
entity_type_s string
id_g string
ManagementGroupName string
MG string
RawData string
SourceSystem string
TenantId string
TimeGenerated datetime
Type string

Solutions (1)

This table is used by the following solutions:

Connectors (1)

This table is ingested by the following connectors:

Connector Selection Criteria
[DEPRECATED] Slack Audit

Content Items Using This Table (20)

Analytic Rules (9)

In solution SlackAudit:

Analytic Rule Selection Criteria
SlackAudit - Empty User Agent
SlackAudit - Multiple archived files uploaded in short period of time
SlackAudit - Multiple failed logins for user
SlackAudit - Public link created for file which can contain sensitive information.
SlackAudit - Suspicious file downloaded.
SlackAudit - Unknown User Agent
SlackAudit - User email linked to account changed.
SlackAudit - User login after deactivated.
SlackAudit - User role changed to admin or owner

Hunting Queries (10)

In solution SlackAudit:

Hunting Query Selection Criteria
SlackAudit - Applications installed
SlackAudit - Deactivated users
SlackAudit - Downloaded files stats
SlackAudit - Failed logins with unknown username
SlackAudit - New User created
SlackAudit - Suspicious files downloaded
SlackAudit - Uploaded files stats
SlackAudit - User Permission Changed
SlackAudit - User logins by IP
SlackAudit - Users joined channels without invites

Workbooks (1)

In solution SlackAudit:

Workbook Selection Criteria
SlackAudit

Parsers Using This Table (1)

Other Parsers (1)

Parser Solution Selection Criteria
SlackAudit SlackAudit

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index