DnsEvents

DnsEvents Schema #

Table description #

TableSection TableType TableSectionName Description
Usx Regular Microsoft Sentinel

Table retention #

HotDays ColdDays TotalInteractiveDays
14 76 90

Schema #

Name Description Type
_BilledSize Double
_IsBillable String
_ResourceId A unique identifier for the resource that the record is associated with String
_SubscriptionId A unique identifier for the subscription that the record is associated with String
ClientIP String
Computer String
Confidence String
Description Description of the information gathered String
EventId Contains the unique event identifier Int32
IndicatorThreatType String
IPAddresses JSON array containing all the IP addresses assigned to the adapter, along with their respective subnet prefix and the IP class (RFC 1918 & RFC 4291) String
MaliciousIP String
Message String
Name String
QueryType Type of the query String
RemoteIPCountry String
RemoteIPLatitude Double
RemoteIPLongitude Double
Result String
ResultCode Int32
Severity Indicates the potential impact (high, medium, or low) of the threat indicator or breach activity identified by the alert Int32
SourceSystem String
SubType String
TaskCategory String
TimeGenerated DateTime
Type The name of the table String

Schema changes #

Date Action
2024-10-18 Table added to tracking