← Browse all tablesLoading table information…
DnsEvents Schema
Table description
| TableSection |
TableType |
TableSectionName |
Description |
|
|
Other hunting tables |
|
Schema
| Name |
Description |
Type |
| _BilledSize |
|
Double |
| _IsBillable |
|
String |
| _ResourceId |
A unique identifier for the resource that the record is associated with |
String |
| _SubscriptionId |
A unique identifier for the subscription that the record is associated with |
String |
| ClientIP |
|
String |
| Computer |
|
String |
| Confidence |
|
String |
| Description |
Description of the information gathered |
String |
| EventId |
Contains the unique event identifier |
Int32 |
| IndicatorThreatType |
|
String |
| IPAddresses |
JSON array containing all the IP addresses assigned to the adapter, along with their respective subnet prefix and the IP class (RFC 1918 & RFC 4291) |
String |
| MaliciousIP |
|
String |
| Message |
|
String |
| Name |
Display name of the agent. |
String |
| QueryType |
Type of the query |
String |
| RemoteIPCountry |
|
String |
| RemoteIPLatitude |
|
Double |
| RemoteIPLongitude |
|
Double |
| Result |
|
String |
| ResultCode |
|
Int32 |
| Severity |
Indicates the potential impact (high, medium, or low) of the threat indicator or breach activity identified by the alert |
Int32 |
| SourceSystem |
|
String |
| SubType |
|
String |
| TaskCategory |
|
String |
| TimeGenerated |
|
DateTime |
| Type |
The name of the table |
String |
Schema changes
| Date |
Action |
| 2026-10-07 |
Table added to tracking |
| 2026-02-27 |
Table removed from tracking |
| 2024-10-18 |
Table added to tracking |