CrowdStrikeVulnerabilities

CrowdStrikeVulnerabilities Schema #

Table description #

TableSection TableType TableSectionName Description
Usx Regular Microsoft Sentinel The CrowdStrikeVulnerabilities table contains logs from the CrowdStrike Vulnerabilities API that have been ingested into Microsoft Sentinel.

Table retention #

HotDays ColdDays TotalInteractiveDays
14 16 30

Schema #

Name Description Type
_BilledSize Double
_IsBillable String
Aid Agent ID of the system where vulnerability was detected. String
App Detailed information about the affected application. Object
Apps List of affected applications. Object
Cid Customer ID in the CrowdStrike platform. String
Confidence Confidence level of the vulnerability detection. String
CreatedTimestamp Timestamp when the vulnerability was first detected. DateTime
Cve Common Vulnerabilities and Exposures (CVE) information. Object
DataProviders List of data providers that reported this vulnerability. Object
HostInfo Information about the affected host system. Object
Id Unique identifier for the vulnerability record. String
Remediation Remediation steps or recommendations for the vulnerability. Object
SourceSystem String
Status Current status of the vulnerability. String
SuppressionInfo Information about vulnerability suppression if applied. Object
TenantId Unique identifier of the tenant into which the data connector ingests data. String
TimeGenerated The timestamp (UTC) when the event was ingested. DateTime
Type The name of the table String
UpdatedTimestamp Timestamp when the vulnerability record was last updated. DateTime
VulnerabilityId Unique identifier for the specific vulnerability. String

Schema changes #

Date Action
2026-01-02 Table added to tracking