ASimDhcpEventLogs

ASimDhcpEventLogs Schema #

Table description #

TableSection TableType TableSectionName Description
Usx Regular Microsoft Sentinel The ASIM DHCP schema represents DHCP server activity, including serving requests for DHCP IP address leased from client systems and updating a DNS server with the leases granted.

Table retention #

HotDays ColdDays TotalInteractiveDays
14 76 90

Schema #

Name Description Type
_BilledSize Double
_IsBillable String
_ResourceId A unique identifier for the resource that the record is associated with String
_SubscriptionId A unique identifier for the subscription that the record is associated with String
AdditionalFields Additional information, represented using key/value pairs provided by the source which do not map to ASim. Object
DhcpCircuitId The DHCP circuit ID, as defined by RFC3046. String
DhcpLeaseDuration The length of the lease granted to a client, in seconds. Int32
DhcpSessionDuration The amount of time, in milliseconds, for the completion of the DHCP session. Int32
DhcpSessionId The session identifier as reported by the reporting device. For the Windows DHCP server, set this to the TransactionID field. String
DhcpSrcDHCId The DHCP client ID, as defined by RFC4701. String
DhcpSubscriberId The DHCP subscriber ID, as defined by RFC3993. String
DhcpUserClass The DHCP User Class, as defined by RFC3004. String
DhcpUserClassId The DHCP User Class Id, as defined by RFC3004. String
DhcpVendorClass The DHCP Vendor Class, as defined by RFC3925. String
DhcpVendorClassId The DHCP Vendor Class Id, as defined by RFC3925. String
DvcAction For reporting security systems, the action taken by the system, if applicable. String
DvcDescription A descriptive text associated with the device. String
DvcDomain The domain of the device on which the event occurred or which reported the event, depending on the schema String
DvcDomainType The type of DvcDomain. String
DvcFQDN The hostname of the device on which the event occurred or which reported the event, depending on the schema. String
DvcHostname The hostname of the device on which the event occurred or which reported the event, depending on the schema. String
DvcId The unique ID of the device on which the event occurred or which reported the event, depending on the schema. String
DvcIdType The type of DvcId. String
DvcInterface The network interface on which data was captured. This field is typically relevant to network related activity which is captured by an intermediate or tap device. String
DvcIpAddr The IP address of the device on which the event occurred or which reported the event, depending on the schema. String
DvcMacAddr The MAC address of the device on which the event occurred or which reported the event. String
DvcOriginalAction The original DvcAction as provided by the reporting device. String
DvcOs The operating system running on the device on which the event occurred or which reported the event. String
DvcOsVersion The version of the operating system on the device on which the event occurred or which reported the event. String
DvcScope The cloud platform scope the device belongs to. DvcScope map to a subscription name on Azure and to an account ID on AWS. String
DvcScopeId The cloud platform scope ID the device belongs to. DvcScopeId map to a subscription ID on Azure and to an account ID on AWS. String
DvcZone The network on which the event occurred or which reported the event, depending on the schema. The zone is defined by the reporting device. String
EventCount The number of events described by the record. This value is used when the source supports aggregation, and a single record might represent multiple events. Int32
EventEndTime The time in which the event ended. If the source supports aggregation and the record represents multiple events, the time when the last event was generated. If not provided by the source record, this field aliases the TimeGenerated field. DateTime
EventMessage A general message or description, either included in or generated from the record. String
EventOriginalResultDetails The original result details provided by the source. This value is used to derive EventResultDetails, which should have only one of the values documented for each schema. String
EventOriginalSeverity The original severity as provided by the reporting device. This value is used to derive EventSeverity. String
EventOriginalSubType The original event subtype or ID, if provided by the source. String
EventOriginalType The original event type or ID, if provided by the source. String
EventOriginalUid A unique ID of the original record, if provided by the source. String
EventOwner The owner of the event, which is usually the department or subsidiary in which it was generated. String
EventProduct The product generating the event. The value should be one of the values listed in Vendors and Products. String
EventProductVersion The version of the product generating the event. String
EventReportUrl A URL provided in the event for a resource that provides more information about the event. String
EventResult The outcome of the event, represented by one of the following values: Success, Partial, Failure, NA (Not Applicable). String
EventResultDetails Reason or details for the result reported in the EventResult field. String
EventSchema The schema the event is normalized to. Each schema documents its schema name. String
EventSchemaVersion The version of the schema. Each schema documents its current version. String
EventSeverity The severity of the event. String
EventStartTime The time in which the event started. If the source supports aggregation and the record represents multiple events, the time when the first event was generated. If not provided by the source record, this field aliases the TimeGenerated field. DateTime
EventSubType Describes a subdivision of the operation reported in the EventType field. String
EventType Describes the operation reported by the record. String
EventVendor The vendor of the product generating the event. The value should be one of the values listed in Vendors and Products. String
RequestedIpAddr The IP address requested by the DHCP client, when available. String
RuleName The name or ID of the rule by associated with the inspection results. String
RuleNumber The number of the rule associated with the inspection results. Int32
SourceSystem String
SrcDescription A descriptive text associated with the device. String
SrcDeviceType The type of the device. String
SrcDomain The domain of the device. String
SrcDomainType The type of the domain. String
SrcDvcId The ID of the device. String
SrcDvcIdType The type of the DvcId. String
SrcDvcScope The cloud platform scope the device belongs to. String
SrcDvcScopeId The cloud platform scope ID the device belongs to. String
SrcFQDN The device hostname, including domain information when available. String
SrcGeoCity The city associated with the source IP address. String
SrcGeoCountry The country associated with the source IP address. String
SrcGeoLatitude The latitude of the geographical coordinate associated with the source IP address. Double
SrcGeoLongitude The longitude of the geographical coordinate associated with the source IP address. Double
SrcGeoRegion The region within a country associated with the source IP address.. String
SrcHostname The device hostname, excluding domain information. String
SrcIpAddr The IP address of the source device. String
SrcMacAddr The MAC address of the network interface from which the connection or session originated. String
SrcOriginalRiskLevel The risk level associaeted with the identified Source as reported by the reporting device. String
SrcOriginalUserType The original source user type, if provided by the source. String
SrcPortNumber The IP port on which the device communicated, if applicable. Int32
SrcRiskLevel The risk level associated with the identified Source. Int32
SrcUserId A machine-readable, alphanumeric, unique representation of the user. String
SrcUserIdType The type of SrcUserId. String
SrcUsername The user’s username, including domain information when available. String
SrcUsernameType The type of username. String
SrcUserScope The type of username. String
SrcUserScopeId The scope ID, such as Azure AD tenant ID, in which UserId and Username are defined. String
SrcUserSessionId The unique ID of the sign-in session of the user. String
SrcUserType The type of user String
SrcUserUid The Unix or Linux user ID of the user. String
TenantId String
ThreatCategory The category of the threat or malware identified in activity. String
ThreatConfidence The confidence level of the threat identified, normalized to a value between 0 and a 100. Int32
ThreatField The field for which a threat was identified. String
ThreatFirstReportedTime The first time the IP address or domain were identified as a threat. DateTime
ThreatId The ID of the threat or malware identified in the activity. String
ThreatIsActive True ID the threat identified is considered an active threat. Boolean
ThreatLastReportedTime The last time the IP address or domain were identified as a threat. DateTime
ThreatName The name of the threat or malware identified in the activity. String
ThreatOriginalConfidence The original confidence level of the threat identified, as reported by the reporting device. String
ThreatOriginalRiskLevel The risk level as reported by the reporting device. String
ThreatRiskLevel The risk level associated with the identified threat. The level should be a number between 0 and 100. Int32
TimeGenerated The timestamp (UTC) reflecting the time in which the event was generated. DateTime
Type The name of the table String

Schema changes #

Date Action
2024-10-18 Table added to tracking