| _BilledSize |
|
Double |
| _IsBillable |
|
String |
| _ResourceId |
A unique identifier for the resource that the record is associated with |
String |
| _SubscriptionId |
A unique identifier for the subscription that the record is associated with |
String |
| AADTenantId |
The Azure Active Directory tenant identifier associated with the asset or entity. |
String |
| AdditionalAssetOwners |
A dynamic collection of additional owners or co-owners associated with the asset. |
Object |
| AdditionalFields |
Additional information about the entity that is not captured by other fields in the schema. |
Object |
| AssetClassificationLastScanDateTime |
The timestamp (UTC) of when the asset was last scanned for data classification. |
DateTime |
| AssetIsProtectedByDlp |
Indicates whether the asset is protected by a Data Loss Prevention (DLP) policy. |
Boolean |
| AssetOriginalDataClassificationType |
The original data classification type(s) assigned to the asset as reported by the source system. |
Object |
| AssetOriginalPermissions |
The original permission set assigned to the asset as reported by the source system. |
Object |
| AssetOriginalRiskDetails |
The full risk details for the asset as provided by the source system. |
Object |
| AssetOriginalRiskLevel |
The risk level assigned to the asset as reported by the source system, before normalization. |
String |
| AssetOriginalSensitivityLevel |
The sensitivity level as reported by the source system, before normalization. |
String |
| AssetOriginalType |
The original type of the asset as reported by the source system. |
String |
| AssetOwnerId |
The identifier of the user or principal that owns the asset. |
String |
| AssetOwnerIdType |
The type or format of the asset owner identifier, such as UPN or SID. |
String |
| AssetOwnerScope |
The organizational or administrative scope to which the asset owner belongs. |
String |
| AssetOwnerScopeId |
The identifier of the scope to which the asset owner belongs. |
String |
| AssetOwnerType |
The type of the asset owner, such as User, Group, or ServicePrincipal. |
String |
| AssetPath |
The alias of either FilePath or SitePath. |
String |
| AssetRelatedIndicators |
A dynamic collection of threat indicators or signals related to the asset. |
Object |
| AssetRiskFirstReportedTime |
The timestamp (UTC) of when the risk associated with the asset was first reported. |
DateTime |
| AssetRiskLastReportedTime |
The timestamp (UTC) of when the risk associated with the asset was most recently reported. |
DateTime |
| AssetRiskLevel |
The normalized risk level assigned to the asset, such as Low, Medium, High, or Critical. |
String |
| AssetRiskName |
The normalized name of the risk or threat associated with the asset. |
String |
| AssetSensitivityLabel |
The sensitivity label applied to the asset, such as Confidential or Public. |
String |
| AssetType |
The high-level type of the asset, such as File, or Site. |
String |
| EntityCreatedTime |
The timestamp (UTC) of when the entity was originally created in the source system. |
DateTime |
| EntityFeedType |
The type or category of the data feed that provided the entity record. |
String |
| EntityId |
A unique identifier for the entity within the normalized schema. |
String |
| EntityIdType |
The type or format of the entity identifier. |
String |
| EntityIngestionTime |
The timestamp (UTC) of when the entity record was ingested into the system. |
DateTime |
| EntityIsDeleted |
Indicates whether the entity has been deleted in the source system. |
Boolean |
| EntityKey |
The unique identifier of the entity, used for correlation across schemas. |
String |
| EntityLastAccessedTime |
The timestamp (UTC) of when the entity was last accessed. |
DateTime |
| EntityLastModifiedTime |
The timestamp (UTC) of when the entity was last modified in the source system. |
DateTime |
| EntityName |
The display name or identifier of the entity. |
String |
| EntityNameType |
The type or format of the entity name, such as UPN, or username. |
String |
| EntityOriginalId |
The original identifier for the entity as reported by the source system. |
String |
| EntityOriginalSource |
The original data source or connector that provided the entity record. |
String |
| EntityProduct |
The product name associated with the source that reported the entity. |
String |
| EntitySchema |
The ASIM schema name for this entity record. |
String |
| EntitySchemaVersion |
The version of the ASIM schema used for this entity record. |
String |
| EntitySnapshotId |
The identifier of the snapshot to which the current record belongs. |
String |
| EntitySource |
The data source or connector that provided the entity record. |
String |
| EntitySubProduct |
The sub-product or component name associated with the source that reported the entity. |
String |
| EntityUpdatedTime |
The timestamp (UTC) of when the entity record was last updated. |
DateTime |
| EntityVendor |
The vendor or provider that reported the entity. |
String |
| ExternalUsersCount |
The number of external users associated with or having access to the asset. |
Int32 |
| FileExtension |
The file extension of the file associated with the asset, such as .exe or .pdf. |
String |
| FileIsSignatureValid |
Indicates whether the digital signature of the file is valid. |
Boolean |
| FileMD5 |
The MD5 hash of the file associated with the asset. |
String |
| FilePath |
The full path of the file associated with the asset. |
String |
| FileSHA1 |
The SHA-1 hash of the file associated with the asset. |
String |
| FileSHA256 |
The SHA-256 hash of the file associated with the asset. |
String |
| FileSHA512 |
The SHA-512 hash of the file associated with the asset. |
String |
| FileSignatureDetails |
Details about the digital signature of the file, such as the signer or certificate information. |
String |
| FileSize |
The size of the file in bytes. |
Int64 |
| IdentityDirectoryId |
The identifier of the identity directory associated with the entity. |
String |
| IdentityDirectoryName |
The name of the identity directory, such as Active Directory or Azure AD, associated with the entity. |
String |
| InternalUsersCount |
The number of internal users associated with or having access to the asset. |
Int32 |
| SitePath |
The path of the site or storage location associated with the asset. |
String |
| SitePrimaryUri |
The primary URI of the site or storage location associated with the asset. |
String |
| SourceSystem |
|
String |
| TenantId |
Unique identifier of the tenant into which the data connector ingests data. |
String |
| TimeGenerated |
The timestamp (UTC) of when the log was generated. |
DateTime |
| Type |
The name of the table |
String |
| User |
The alias of AssetOwnerId. |
String |