← Browse all tablesLoading table information…
WindowsFirewall Schema
Table description
| TableSection |
TableType |
TableSectionName |
Description |
|
|
Other hunting tables |
Contains fully formed Windows Firewall log messages that already match the WindowsFirewall table format. |
Schema
| Name |
Description |
Type |
| _BilledSize |
|
Double |
| _IsBillable |
|
String |
| _ResourceId |
A unique identifier for the resource that the record is associated with |
String |
| _SubscriptionId |
A unique identifier for the subscription that the record is associated with |
String |
| CommunicationDirection |
|
String |
| Computer |
|
String |
| Confidence |
|
String |
| Description |
Description of the information gathered |
String |
| DestinationIP |
|
String |
| DestinationPort |
Destination port of the activity |
Int32 |
| FirewallAction |
|
String |
| FirstReportedDateTime |
|
String |
| FullDestinationAddress |
|
String |
| IndicatorThreatType |
|
String |
| Info |
|
String |
| IsActive |
|
String |
| LastReportedDateTime |
|
String |
| MaliciousIP |
|
String |
| MaliciousIPCountry |
|
String |
| MaliciousIPLatitude |
|
Double |
| MaliciousIPLongitude |
|
Double |
| ManagementGroupName |
|
String |
| Protocol |
Protocol used during the communication |
String |
| RemoteIP |
IP address that was being connected to |
String |
| RequestSizeInBytes |
|
Int64 |
| Severity |
Indicates the potential impact (high, medium, or low) of the threat indicator or breach activity identified by the alert |
Int32 |
| SourceIP |
|
String |
| SourcePort |
Port where the attacker communication originated from |
Int32 |
| SourceSystem |
|
String |
| TimeGenerated |
|
DateTime |
| TLPLevel |
|
String |
| Type |
The name of the table |
String |
Schema changes
| Date |
Action |
| 2026-10-07 |
Table added to tracking |