TrendMicro_XDR_WORKBENCH_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index


Attribute Value
Custom Log V1 Yes 🔶 — uses type-suffixed column names
Ingestion API Supported ✓ Yes

Contents

Schema (20 columns)

Source: KQL validation test schema

Column Name Type
alertProvider_s string
alertTriggerTimestamp_t datetime
createdTime_t datetime
description_s string
FileDirectory_s string
FileName_s string
impactScope_Summary_s string
model_s string
priorityScore_d int
ProcessCommandLine_s string
RegistryKey_s string
RegistryValue_s string
RegistryValueName_s string
severity_s string
TimeGenerated datetime
UserAccountName_s string
UserAccountNTDomain_s string
workbenchId_s string
workbenchLink_s string
workbenchName_s string

Solutions (1)

This table is used by the following solutions:

Connectors (1)

This table is ingested by the following connectors:

Connector Selection Criteria
Trend Vision One

Content Items Using This Table (4)

Analytic Rules (1)

In solution Trend Micro Vision One:

Analytic Rule Selection Criteria
Create Incident for XDR Alerts

Workbooks (3)

In solution Trend Micro Vision One:

Workbook Selection Criteria
TrendMicroXDROverview

GitHub Only:

Workbook Selection Criteria
Data_Latency_Workbook
TrendMicroXDROverview

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index