Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
| Attribute | Value |
|---|---|
| Ingestion API Supported | ✓ Yes |
Source: KQL validation test schema
| Column Name | Type |
|---|---|
| Created | datetime |
| CurrentlyConnected | bool |
| DeviceCount | int |
| DisplayName | string |
| LastSeen | datetime |
| LoginName | string |
| ProfilePicUrl | string |
| Role | string |
| SourceSystem | string |
| Status | string |
| TailnetId | string |
| TenantId | string |
| TimeGenerated | datetime |
| UserId | string |
| UserType | string |
Official Microsoft Learn documentation for field/column information:
This table is used by the following solutions:
This table is ingested by the following connectors:
| Connector | Selection Criteria |
|---|---|
| Tailscale Standard (CCF) | |
| Tailscale Premium (CCF) |
In solution Tailscale (CCF):
| Analytic Rule | Selection Criteria |
|---|---|
| Tailscale: User role elevated to admin or owner |
In solution Tailscale (CCF):
| Hunting Query | Selection Criteria |
|---|---|
| Tailscale: Users with zero devices |
In solution Tailscale (CCF):
| Workbook | Selection Criteria |
|---|---|
| TailscalePremiumOperations | |
| TailscaleStandardOperations |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊