Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
| Attribute | Value |
|---|---|
| Ingestion API Supported | ✓ Yes |
Source: KQL validation test schema
| Column Name | Type |
|---|---|
| Acknowledged | string |
| Created | real |
| CreatedPrintable | string |
| Description | string |
| DestinationIP | string |
| DestinationPort | string |
| Events | dynamic |
| EventsCount | string |
| FlockId | string |
| FlockName | string |
| HashId | string |
| Host | dynamic |
| IncidentId | string |
| IncidentUpdated | datetime |
| IpAddress | string |
| LocalTime | string |
| LogType | string |
| Memo | string |
| NodeId | string |
| Notified | string |
| PreviouslySeenCount | real |
| RawEvent | dynamic |
| Sensor | string |
| SourceIP | string |
| SourcePort | string |
| SrcHostReverse | string |
| TimeGenerated | datetime |
| UpdatedId | real |
| UpdatedTimePrintable | string |
Official Microsoft Learn documentation for field/column information:
This table is used by the following solutions:
This table is ingested by the following connectors:
| Connector | Selection Criteria |
|---|---|
| Thinkst Canary |
In solution ThinkstCanary:
| Analytic Rule | Selection Criteria |
|---|---|
| Canary alerts to incidents |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊