← Browse all tablesLoading table information…
SecurityCaseEvent Schema
Table description
| TableSection |
TableType |
TableSectionName |
Description |
|
|
Other hunting tables |
Audit log table tracking all field-level changes to Case Management entities including cases, tasks, comments, attachments, and relations. |
Schema
| Name |
Description |
Type |
| _BilledSize |
|
Double |
| _IsBillable |
|
String |
| AadTenantId |
Azure AD tenant GUID where the change occurred. |
String |
| EntityCreatedTime |
Original creation timestamp of the entity. |
DateTime |
| EntityId |
Unique identifier of the changed entity. |
String |
| EntityType |
Type of entity changed: Case, CaseTask, Comment, Attachment, CaseRelation etc… |
String |
| EventTime |
Timestamp when the change was made in the source system. |
DateTime |
| IsDeleted |
Indicates if the entity was deleted. |
Boolean |
| ModifiedBy |
User principal name (UPN) of the user who made the change. |
String |
| NewValues |
New value(s) after the change. Null for Delete operations. Can be a simple value or JSON object. |
Object |
| OperationName |
Type of operation: Create, Update, Delete, Link, or Unlink. |
String |
| ParentEntityId |
Parent entity ID. Null for Case entities, contains Case ID for child entities like CaseTask, Comment, Attachment, etc. |
String |
| PreviousValues |
Previous value(s) before the change. Null for Create operations. Can be a simple value or JSON object. |
Object |
| PropertyNames |
Property name(s) that changed. |
Object |
| RecordId |
Unique identifier for this audit record. |
String |
| SourceSystem |
|
String |
| TenantId |
Unique identifier of the tenant into which the data connector ingests data. |
String |
| TimeGenerated |
Timestamp when the record was ingested into Log Analytics. |
DateTime |
| Type |
The name of the table |
String |
Schema changes
| Date |
Action |
| 2026-10-07 |
Table added to tracking |