REFERENCE

Contribute structured examples

Help expand the JSON/XML examples with event structures from your environment. All published values are synthetic, and every contribution is reviewed before publication.

The XDR Schema Examples contribution repository contains the PowerShell tool, complete instructions, and a submission form. You do not need access to the website’s source repository.

  1. Download the PowerShell-only tool and choose any accessible table and structured column, including custom tables.
  2. Collect up to 10 samples per event group over 7 days using Sentinel in PowerShell/Cloud Shell, Defender with delegated Graph authentication, or a CSV/JSON export from the hunting portal. Suggested grouping columns can be overridden; unfamiliar tables require explicit grouping or ungrouped mode.
  3. Run the tool to create a synthetic contribution file. More than 100 groups triggers a warning and stops API payload collection unless you explicitly supply -Force.
  4. Open and review the exact generated file. Arbitrary property names, named-property labels, XML namespaces, and event grouping labels are retained for your review. Rename or remove tenant-specific names locally and revalidate the file. Never submit original exports.
  5. Submit the generated example. Include the table, column, context, and your preferred public GitHub credit.

The public tool does not restrict tables, field names, or event groupings to the website’s approved lists. Publication eligibility is reviewed separately by the website maintainer. Sampling covers discovered groups but cannot guarantee every payload structure. Examples illustrate observed or documented structures; they do not establish required fields or complete vendor schemas.

After review, accepted examples are merged into the public contribution repository, imported into the website through a separately validated update, and credited beside the example and in Sources & credits. Acceptance and publication are separate steps; the public submission links to the site when publication is complete.