WsSecurityEvents_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index


Attribute Value
Ingestion API Supported ✓ Yes

Contents

Schema (16 columns)

Source: KQL validation test schema

Column Name Type
Activity string
AdditionalExtensions string
DeviceAction string
DeviceCustomString1 string
DeviceCustomString1Label string
DeviceCustomString2 string
DeviceCustomString2Label string
DeviceEventClassID string
DeviceVendor string
LogSeverity int
Message string
PersistenceTimestamp datetime
SimplifiedDeviceAction string
SourceHostName string
SourceUserName string
TimeGenerated datetime

Solutions (1)

This table is used by the following solutions:

Connectors (1)

This table is ingested by the following connectors:

Connector Selection Criteria
WithSecure Elements API (Azure Function)

Content Items Using This Table (2)

Workbooks (2)

In solution WithSecureElementsViaFunction:

Workbook Selection Criteria
WithSecureTopComputersByInfections

GitHub Only:

Workbook Selection Criteria
WithSecureTopComputersByInfections

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index