| _BilledSize |
|
Double |
| _IsBillable |
|
String |
| AccountSid |
Security identifier (SID) of the account. |
String |
| AdditionalFields |
Additional information about the entity or event. |
Object |
| AppGuardContainerId |
Identifier for the virtualized container used by Application Guard to isolate browser activity. |
String |
| DeviceId |
Unique identifier for the device in the service. |
String |
| DeviceName |
Fully qualified domain name (FQDN) of the device. |
String |
| EventId |
Contains the unique event identifier. |
Int64 |
| InitiatingProcessAccountDomain |
Domain of the account that ran the process responsible for the event. |
String |
| InitiatingProcessAccountName |
User name of the account that ran the process responsible for the event. |
String |
| InitiatingProcessAccountObjectId |
Azure AD object ID of the user account that ran the process responsible for the event. |
String |
| InitiatingProcessAccountSid |
Security Identifier (SID) of the account that ran the process responsible for the event. |
String |
| InitiatingProcessAccountUpn |
User principal name (UPN) of the account that ran the process responsible for the event. In Active Directory, a UPN is the name of a system user in an email address format (for example: john.doe@domain.com) |
String |
| InitiatingProcessCreationTime |
Date and time when the process that initiated the event was started. |
DateTime |
| InitiatingProcessFolderPath |
Folder containing the process (image file) that initiated the event. |
String |
| InitiatingProcessId |
Process ID (PID) of the process that initiated the event. |
Int64 |
| InitiatingProcessLogonId |
Identifier for a logon session of the process that initiated the event. This identifier is unique on the same machine only between restarts. |
Int64 |
| InitiatingProcessMD5 |
MD5 hash of the process (image file) that initiated the event. |
String |
| InitiatingProcessParentCreationTime |
Date and time when the parent of the process responsible for the event was started. |
DateTime |
| InitiatingProcessParentFileName |
Name of the parent process that spawned the process responsible for the event. |
String |
| InitiatingProcessParentId |
Process ID (PID) of the parent process that spawned the process responsible for the event. |
Int64 |
| InitiatingProcessSHA1 |
SHA-1 hash of the process (image file) that initiated the event. |
String |
| LocalIP |
IP address assigned to the local machine used during communication. |
String |
| LocalPort |
TCP port on the local machine used during communication. |
Int32 |
| MachineGroup |
Machine group of the machine. This group is used by role-based access control to determine access to the machine. |
String |
| ProcessCommandLine |
Command line used to create the new process. |
String |
| RemoteDeviceName |
Name of the device that performed a remote operation on the affected machine. Depending on the event being reported, this name could be a fully-qualified domain name (FQDN), a NetBIOS name, or a host name without domain information.. |
String |
| RemoteIP |
IP address that was being connected to. |
String |
| RemotePort |
TCP port on the remote device that was being connected to. |
Int32 |
| ReportId |
Unique identifier for the event. |
Int64 |
| SourceSystem |
|
String |
| TenantId |
Unique identifier of the tenant into which the data connector ingests data. |
String |
| TimeGenerated |
Date and time the event was recorded by the MDE agent on the endpoint. |
DateTime |
| Timestamp |
Date and time when the record was generated |
DateTime |
| Type |
The name of the table |
String |