Microsoft XDR table schema

Microsoft XDR table schema #

This site documents all table schema in Microsoft XDR and Sentinel and documents changes to the schema. All data is sourced from the official Microsoft XDR page and contains only publicly available information. The schema is subject to change and the information here may not be up to date.

Caution: The data presented here might be incomplete or incorrect. This stems from the fact that not all XDR features are enabled in the tenant used to generate this documentation.

Caution: Dates shown are not guaranteed to be accurate and there was a long pause between 2024-10-19 and 2025-12-30.

Latest changes #

The following changes have been made to the schema:

Date Table Action
2026-01-12 GraphAPIAuditEvents Column ResponseSize added
2026-01-12 DeviceEvents Action type added: UserAccountPasswordResetAttempt
2026-01-05 ContainerRegistryLoginEvents Table removed from tracking
2026-01-05 AzureMetrics Table removed from tracking
2026-01-05 ContainerRegistryRepositoryEvents Table removed from tracking
2026-01-04 AzureMetricsV2 Table removed from tracking
2026-01-04 AzureDiagnostics Table removed from tracking
2026-01-04 AppServiceServerlessSecurityPluginData Table removed from tracking
2026-01-04 AppServicePlatformLogs Table removed from tracking
2026-01-04 AppServiceIPSecAuditLogs Table removed from tracking
2026-01-04 AppServiceHTTPLogs Table removed from tracking
2026-01-04 AppServiceConsoleLogs Table removed from tracking
2026-01-04 AppServiceAuditLogs Table removed from tracking
2026-01-04 ContainerAppConsoleLogs Table removed from tracking
2026-01-04 AppServiceAppLogs Table removed from tracking
2026-01-04 AppServiceAntivirusScanAuditLogs Table removed from tracking
2026-01-04 AppEnvSpringAppConsoleLogs Table removed from tracking
2026-01-04 AppEnvSessionPoolEventLogs Table removed from tracking
2026-01-04 AppEnvSessionLifecycleLogs Table removed from tracking
2026-01-04 AppEnvSessionConsoleLogs Table removed from tracking
2026-01-04 AppServiceAuthenticationLogs Table removed from tracking
2026-01-04 ContainerAppSystemLogs Table removed from tracking
2026-01-04 AppServiceFileAuditLogs Table removed from tracking
2026-01-04 FunctionAppLogs Table removed from tracking
2026-01-04 Event Table removed from tracking
2026-01-04 StorageTableLogs Table removed from tracking
2026-01-04 StorageQueueLogs Table removed from tracking
2026-01-04 StorageFileLogs Table removed from tracking
2026-01-04 StorageBlobLogs Table removed from tracking
2026-01-04 OTelTracesAgent Table removed from tracking
2026-01-04 OTelTraces Table removed from tracking
2026-01-04 OTelSpans Table removed from tracking
2026-01-04 Syslog Table removed from tracking
2026-01-04 OTelLogs Table removed from tracking
2026-01-04 OTelEvents Table removed from tracking
2026-01-04 LogicAppWorkflowRuntime Table removed from tracking
2026-01-04 LASummaryLogs Table removed from tracking
2026-01-04 LAQueryLogs Table removed from tracking
2026-01-04 LAJobLogs Table removed from tracking
2026-01-04 Heartbeat Table removed from tracking
2026-01-04 OTelResources Table removed from tracking
2026-01-03 AzureMetricsV2 Table added to tracking
2026-01-03 AzureMetrics Table added to tracking
2026-01-03 AzureDiagnostics Table added to tracking
2026-01-03 AppServiceServerlessSecurityPluginData Table added to tracking
2026-01-03 AppServicePlatformLogs Table added to tracking
2026-01-03 AppServiceIPSecAuditLogs Table added to tracking
2026-01-03 AppServiceFileAuditLogs Table added to tracking
2026-01-03 AppServiceConsoleLogs Table added to tracking
2026-01-03 AppServiceAntivirusScanAuditLogs Table added to tracking

This list is limited to the latest 50 changes.