Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊
| Attribute | Value |
|---|---|
| Custom Log V1 | Yes 🔶 — uses type-suffixed column names |
| Ingestion API Supported | ✓ Yes |
Source: KQL validation test schema
| Column Name | Type |
|---|---|
| _ResourceId | string |
| Computer | string |
| Document_Id_g | guid |
| Domain_s | string |
| Email_s | string |
| Infected_Machine_Id | string |
| Infected_Machine_Id_g | guid |
| Infected_Path_s | string |
| Infected_Time_t | datetime |
| IP_Address_s | string |
| ManagementGroupName | string |
| MG | string |
| Password_Plaintext_s | string |
| Password_s | string |
| RawData | string |
| Severity_s | string |
| Source_Id_s | string |
| SourceSystem | string |
| SpyCloud_Publish_Date_t | datetime |
| Target_Domain_s | string |
| Target_SubDomain_s | string |
| Target_URL_s | string |
| TenantID | string |
| TimeGenerated | datetime |
| Type | string |
| User_Hostname_s | string |
| User_OS_s | string |
| Username_s | string |
This table is used by the following solutions:
In solution SpyCloud Enterprise Protection:
| Analytic Rule | Selection Criteria |
|---|---|
| SpyCloud Enterprise Breach Detection | |
| SpyCloud Enterprise Malware Detection |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊