Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
| Attribute | Value |
|---|---|
| Ingestion API Supported | ✓ Yes |
Source: Connector definition
| Column Name | Type | Description |
|---|---|---|
| Action | string | Action taken by the security system. |
| ActionResult | string | Result of the action taken. |
| AffectedUser | string | Email address or username of the affected user. |
| ConnectorName | string | Connector Friendly Name assigned during connector setup |
| DetectedBy | string | Detection mechanism or engine that identified the threat. |
| DetectionTime | datetime | Timestamp when the threat was detected. |
| DetectionType | string | Type of detection method used. |
| Event | string | Type of security event (securityrisk, virtualanalyzer, ransomware, dlp). |
| FileName | string | Name of the file where the threat was detected. |
| FileSHA1 | string | SHA-1 hash of the detected file. |
| FileSHA256 | string | SHA-256 hash of the detected file. |
| FileUploadTime | datetime | Timestamp when the file was uploaded. |
| Location | string | File path or location where the threat was detected. |
| LogItemId | string | Unique identifier for the log entry. |
| MailMessageDeliveryTime | datetime | Timestamp when the email message was delivered. |
| MailMessageFileName | string | Name of the attachment file in the email. |
| MailMessageId | string | Unique identifier for the email message. |
| MailMessageRecipient | dynamic | Email addresses of message recipients. |
| MailMessageSender | string | Email address of the message sender. |
| MailMessageSubject | string | Subject line of the email message. |
| MailMessageSubmitTime | datetime | Timestamp when the email message was submitted. |
| RansomwareName | string | Name of the ransomware variant detected. |
| RiskLevel | string | Risk level classification (e.g., High, Medium, Low). |
| ScanType | string | The type of scan performed on the message or file. |
| SecurityRiskName | string | Name of the identified security risk. |
| Service | string | Cloud service where the event occurred (exchange, sharepoint, onedrive, dropbox, box, googledrive, gmail, teams, exchangeserver, salesforce_sandbox, salesforce_production, teams_chat). |
| TimeGenerated | datetime | |
| TriggeredDlpTemplate | dynamic | Data Loss Prevention template that was triggered. |
| TriggeredPolicyName | string | Name of the security policy that was triggered. |
| TriggeredSecurityFilter | string | Security filter that triggered the alert. |
| VirusName | string | Name of the virus or malware detected. |
Official Microsoft Learn documentation for field/column information:
This table is used by the following solutions:
This table is ingested by the following connectors:
| Connector | Selection Criteria |
|---|---|
| Trend Micro Cloud App Security | |
| Trend Micro Cloud App Security (via Codeless Connector Framework) |
In solution Trend Micro Cloud App Security:
In solution Trend Micro Cloud App Security:
In solution Trend Micro Cloud App Security:
| Workbook | Selection Criteria |
|---|---|
| TrendMicroCAS |
| Parser | Solution | Selection Criteria |
|---|---|---|
| TrendMicroCAS | Trend Micro Cloud App Security |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊