SOCRadar_Alarms_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index


Attribute Value
Ingestion API Supported ✓ Yes

Contents

Schema (14 columns)

Source: KQL validation test schema

Column Name Type
AlarmDate string
AlarmId string
AlarmMainType string
AlarmPayload dynamic
AlarmSubType string
AlarmText string
CompanyId string
Severity string
SourceSystem string
Status string
TenantId string
TimeGenerated datetime
Title string
Type string

Solutions (1)

This table is used by the following solutions:


Content Items Using This Table (6)

Analytic Rules (2)

In solution SOCRadar:

Analytic Rule Selection Criteria
SOCRadar Alarm Volume Spike
SOCRadar High or Critical Severity Alarm

Hunting Queries (3)

In solution SOCRadar:

Hunting Query Selection Criteria
SOCRadar Alarm Overview
SOCRadar Alarm Trends
SOCRadar Critical Alarms

Workbooks (1)

In solution SOCRadar:

Workbook Selection Criteria
SOCRadar-Dashboard

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index