changes.mady.by.user Juan Tomás Alonso Nieto (Deactivated)
Saved on May 31, 2023
Saved on Jun 06, 2023
cloud.azure.vm.systemevent
cloud.azure.vm.unix
cloud.azure.vm.unknown_events
cloud.azure.vmscalesets.administrative
cloud.azure.vmscalesets.autoscale
cloud.azure.vmscalesets.policy
Field
Type
Field transformation
Source field name
Extra fields
eventdate
timestamp
hostname
str
hostIp
ip4
Computer
EventCategory
int4
EventData
EventID
EventLevel
EventLevelName
EventLog
MG
ManagementGroupName
ParameterXml
RenderedDescription
Source
SourceSystem
TenantId
TimeGenerated
parsedate(TimeGenerated_str, dateformat("YYYY-MM-DD[T]HH:mm:ss.SSSSSSS[Z]", "UTC"))
TimeGenerated_str
UserName
service
serviceSid
serviceFileName
serviceType
serviceStartType
serviceAccount
ServicePrincipalNames
imagePath
startType
accountName
procId
procName
currentBias
currentTimeZoneID
deviceName
deviceNameLength
deviceTime
deviceVersionMajor
deviceVersionMinor
dirtyPages
exitReason
finalStatus
firstRefresh
hiveName
hiveNameLength
keysUpdated
newTime
oldTime
reason
tSId
timeZoneInfoCacheUpdated
param1
param2
param3
param4
param5
param6
param7
param8
param9
param10
EventData_data
EventData_unkData
Internal_WorkspaceResourceId
ResourceId
at_devo_collector_version
at_entry_offset
at_enqueued_time
hostchain
✓
tag
rawMessage
EventTime
Facility
HostIP
HostName
ProcessName
ProcessID
SeverityLevel
SyslogMessage
srcUser
action
tty
pwd
user
cmd
obj
srcIp
srcPort
attempt
device
session
msg
srceventdate
pid
uid
euid
auid
ses
ruser
rhost
arch
syscall
success
exit
op
grantors
addr
type
res
terminal
comm
msg2
message
region
roleLocation
parsedate(time, dateformat("YYYY-MM-DD[T]HH:mm:ss.SSSSSSS[Z]", "UTC"))
time
resourceId
operationName
category
resultType
resultSignature
durationMs
callerIpAddress
correlationId
identity__authorization__scope
identity__authorization__action
identity__authorization__evidence__role
identity__authorization__evidence__roleAssignmentScope
identity__authorization__evidence__roleAssignmentId
identity__authorization__evidence__roleDefinitionId
identity__authorization__evidence__principalId
identity__authorization__evidence__principalType
identity__claims
json
identity__claims__aud
identity__claims__iss
identity__claims__iat
identity__claims__nbf
identity__claims__exp
identity__claims__aio
identity__claims__appid
identity__claims__appidacr
identity__claims__groups
identity__claims__rh
identity__claims__uti
identity__claims__ver
identity__claims__xms_tcdt
level
properties__eventCategory
properties__entity
properties__message
properties__hierarchy
tenantId
resultDescription
properties__eventName
properties__operationId
properties__eventProperties__OldInstancesCount
properties__eventProperties__NewInstancesCount
properties__isComplianceCheck
properties__resourceLocation
properties__ancestors
properties__policies
cloud.azure.vmscalesets.resourcehealth
cloud.azure.vngateways.ikediagnos
cloud.azure.wad.waddirectories
cloud.azure.wad.wadperformancecounters
cloud.azure.wad.wadwindowseventlogs
cloud.azure.workflows.workflow_runtime
properties__eventProperties__title
properties__eventProperties__details
properties__eventProperties__currentHealthStatus
properties__eventProperties__previousHealthStatus
properties__eventProperties__type
properties__eventProperties__cause
resourceid
properties__instance
clientOperationId
correlationRequestId
role
roleInstance
partitionKey
rowKey
absolutePath
container
deploymentId
eventTickCount
int8
relativePath
rootDir
rawSource
counterName
counterValue
float8
channel
eventId
providerGuid
providerName
description
tid
rawXml
workflow_id
resource_id
level2
operation_name
properties__dollar_schema
properties__start_time
properties__end_time
properties__status
properties__execution_cluster_type
properties__resource__subscription_id
properties__resource__resource_group_name
properties__resource__workflow_id
properties__resource__workflow_name
properties__resource__run_id
properties__resource__location
properties__resource__action_name
properties__correlation__action_tracking_id
properties__correlation__client_tracking_id
location