Table of Contents | ||||
---|---|---|---|---|
|
Introduction
The tags beginning with edr.microsoft_defender
identify events generated by the Microsoft Defender for Endpoint.
Tag structure
The full tag must have 4 levels. The first three are fixed asedr.microsoft_defender
. The fourth level identifies the type of events sent.
Product / Service | Tags | Data tables |
---|---|---|
Microsoft Defender Endpoint |
|
|
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
Table structure
These are the fields displayed in the tables:
...
Rw tab | ||
---|---|---|
|
...
|
...
|
|
...
|
|
...
|
|
...
|
|
...
| |
Microsoft Defender for IoT |
|
...
|
...
|
|
...
Field
...
Type
...
Extra Field
...
eventdate
...
timestamp
...
-
...
hostname
...
str
...
-
...
id
...
str
...
-
...
name
...
str
...
-
...
vendor
...
str
...
-
...
weaknesses
...
int4
...
-
...
publicExploit
...
bool
...
-
...
activeAlert
...
bool
...
-
...
exposedMachines
...
int4
...
-
...
installedMachines
...
int4
...
-
...
impactScore
...
float8
...
-
...
isNormalized
...
bool
...
-
...
category
...
str
...
-
...
distributions
...
str
...
-
...
related_vulnerabilities
...
int4
...
-
...
related_machines
...
int4
...
-
...
related_version_distribution
...
int4
...
-
...
related_missing_kbs
...
int4
...
-
...
hostchain
...
str
...
✓
...
tag
...
str
...
✓
...
rawMessage
...
str
...
✓
...
Field
...
Type
...
Extra Field
...
eventdate
...
timestamp
...
-
...
hostname
...
str
...
-
...
at_odata_context
...
str
...
-
...
id
...
str
...
-
...
name
...
str
...
-
...
description
...
str
...
-
...
severity
...
str
...
-
...
cvssV3
...
float8
...
-
...
exposedMachines
...
int4
...
-
...
publishedOn
...
timestamp
...
-
...
updatedOn
...
timestamp
...
-
...
publicExploit
...
bool
...
-
...
exploitVerified
...
bool
...
-
...
exploitInKit
...
bool
...
-
...
exploitTypes
...
str
...
-
...
exploitUris
...
str
...
-
...
at_devo_pulling_id
...
str
...
-
...
related_machines
...
int4
...
|
Table structure
These are the fields displayed in the tables:
Rw ui tabs macro | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
alerts.alertsevents
at_odata_context
-
-
str
str
timestamp
timestamp
timestamp
timestamp
timestamp
[edr.microsoft_defender.endpoint.investigations] [edr.microsoft_defender.endpoint.assessment_secure_configuration] [edr.microsoft_defender.endpoint.machines] [edr.microsoft_defender.endpoint.recommendations] Anchor | | edr.microsoft_defender.endpoint.investigations | edr.microsoft_defender.endpoint.investigations | edr.microsoft_defender.endpoint.investigations||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Field | Type | Extra Label | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
eventdate |
| - | hostname |
| -
| |
mitreTechniques_str |
|
-
loggedOnUsers
str
-
comments
str
-
domains
str
-
at_devo_pulling_id
str
-
related_files
int4
-
related_ips
int4
-
related_machines
int4
-
related_domains
int4
-
related_users
int4
-
relatedUser_userName
str
-
relatedUser_domainName
str
-
related_evidences
int4
-
related_loggedOnUsers
int4
-
raw_evidences
str
-
evidence_entityType
str
-
evidence_evidenceCreationTime
timestamp
-
evidence_sha1
str
-
evidence_sha256
str
-
evidence_fileName
str
-
evidence_filePath
str
-
evidence_processId
str
-
evidence_processCommandLine
str
-
evidence_processCreationTime
timestamp
-
evidence_parentProcessId
str
-
evidence_parentProcessCreationTime
timestamp
-
evidence_parentProcessFileName
str
-
evidence_parentProcessFilePath
str
-
evidence_ipAddress
str
-
evidence_url
str
-
evidence_registryKey
str
-
evidence_registryHive
str
-
evidence_registryValueType
str
-
evidence_registryValue
str
-
evidence_registryValueName
str
-
evidence_accountName
str
-
evidence_domainName
str
-
evidence_userSid
str
-
evidence_aadUserId
str
-
evidence_userPrincipalName
str
-
evidence_detectionStatus
str
-
hostchain
str
✓
tag
str
✓
rawMessage
str
✓
Field
Type
Extra Field
eventdate
timestamp
-
hostname
str
-
at_devo_pulling_id
str
-
Id
str
-
DeviceId
str
-
DeviceName
str
-
OSPlatform
str
-
OSVersion
str
-
OSArchitecture
str
-
SoftwareVendor
str
-
SoftwareName
str
-
SoftwareVersion
str
-
CveId
str
-
CvssScore
float8
-
VulnerabilitySeverityLevel
str
-
RecommendedSecurityUpdate
str
-
RecommendedSecurityUpdateId
str
-
RecommendedSecurityUpdateUrl
str
-
DiskPaths
str
-
RegistryPaths_str
str
-
LastSeenTimestamp
timestamp
-
FirstSeenTimestamp
timestamp
-
ExploitabilityLevel
str
-
RecommendationReference
str
-
SecurityUpdateAvailable
bool
-
RbacGroupId
int4
-
RbacGroupName
str
-
hostchain
str
✓
tag
str
✓
rawMessage
str
✓
Field
Type
Extra Field
eventdate
timestamp
-
hostname
str
-
at_devo_pulling_id
str
-
DeviceId
str
-
DeviceName
str
-
OSPlatform
str
-
SoftwareVendor
str
-
SoftwareName
str
-
SoftwareVersion
str
-
NumberOfWeaknesses
int4
-
DiskPaths
str
-
RegistryPaths_str
str
-
SoftwareFirstSeenTimestamp
timestamp
-
SoftwareLastSeenTimestamp
timestamp
-
EndOfSupportStatus
str
-
EndOfSupportDate
str
-
RbacGroupId
int4
-
RbacGroupName
str
-
hostchain
str
✓
tag
str
✓
rawMessage
str
✓
| mitreTechniques | |||||
relatedUser__userName |
|
|
| |||
relatedUser__domainName |
|
|
| |||
comments__comment_str |
|
| comments__comment | |||
comments__createdBy_str |
|
| comments__createdBy | |||
comments__createdTime_str |
|
| comments__createdTime | |||
evidence__entityType_str |
|
| evidence__entityType | |||
evidence__evidenceCreationTime_str |
|
| evidence__evidenceCreationTime | |||
evidence__sha1_str |
|
| evidence__sha1 | |||
evidence__sha256_str |
|
| evidence__sha256 | |||
evidence__fileName_str |
|
| evidence__fileName | |||
evidence__filePath_str |
|
| evidence__filePath | |||
evidence__processId_str |
|
| evidence__processId | |||
evidence__processCommandLine_str |
|
| evidence__processCommandLine | |||
evidence__processCreationTime_str |
|
| evidence__processCreationTime | |||
evidence__parentProcessId_str |
|
| evidence__parentProcessId | |||
evidence__parentProcessCreationTime_str |
|
| evidence__parentProcessCreationTime | |||
evidence__parentProcessFileName_str |
|
| evidence__parentProcessFileName | |||
evidence__parentProcessFilePath_str |
|
| evidence__parentProcessFilePath | |||
evidence__ipAddress_str |
|
| evidence__ipAddress | |||
evidence__url_str |
|
| evidence__url | |||
evidence__registryKey_str |
|
| evidence__registryKey | |||
evidence__registryHive_str |
|
| evidence__registryHive | |||
evidence__registryValueType_str |
|
| evidence__registryValueType | |||
evidence__registryValue_str |
|
| evidence__registryValue | |||
evidence__accountName_str |
|
| evidence__accountName | |||
evidence__domainName_str |
|
| evidence__domainName | |||
evidence__userSid_str |
|
| evidence__userSid | |||
evidence__aadUserId_str |
|
| evidence__aadUserId | |||
evidence__userPrincipalName_str |
|
| evidence__userPrincipalName | |||
evidence__detectionStatus_str |
|
| evidence__detectionStatus | |||
hostchain |
|
|
| ✓ | ||
tag |
|
|
| ✓ | ||
rawMessage |
|
|
| ✓ |
Anchor | ||||
---|---|---|---|---|
|
Field | Type | Extra fields |
---|---|---|
eventdate |
| |
hostname |
| |
at_odata_context |
| |
id |
| |
incidentId |
| |
investigationId |
| |
assignedTo |
| |
severity |
| |
status |
| |
classification |
| |
determination |
| |
investigationState |
| |
detectionSource |
| |
detectorId |
| |
category |
| |
threatFamilyName |
| |
title |
| |
description |
| |
alertCreationTime |
| |
firstEventTime |
| |
lastEventTime |
| |
lastUpdateTime |
| |
resolvedTime |
| |
machineId |
| |
computerDnsName |
| |
rbacGroupName |
| |
aadTenantId |
| |
threatName |
| |
mitreTechniques |
| |
loggedOnUsers |
| |
comments |
| |
domains |
| |
at_devo_pulling_id |
|
related_files |
|
str
related_ips |
|
related_machines |
timestamp
|
related_domains |
|
timestamp
related_users |
|
relatedUser_userName |
|
-
relatedUser_domainName |
|
related_evidences |
|
str
related_loggedOnUsers |
|
raw_evidences |
|
evidence_entityType |
computerDnsName
|
-
evidence_evidenceCreationTime |
| |
evidence_sha1 |
|
-
hostchain
str
✓
tag
str
✓
rawMessage
str
✓
Field
Type
Extra Label
eventdate
timestamp
-
hostname
str
-
at_devo_pulling_id
str
-
DeviceId
str
-
DeviceName
str
-
OSPlatform
str
-
OSVersion
str
-
Timestamp
timestamp
-
ConfigurationId
str
-
ConfigurationCategory
str
-
ConfigurationSubcategory
str
-
ConfigurationImpact
int4
-
IsApplicable
bool
-
ConfigurationName
str
-
RecommendationReference
str
-
RbacGroupId
int4
-
RbacGroupName
str
-
IsCompliant
bool
-
hostchain
str
✓
tag
str
✓
rawMessage
str
✓
evidence_sha256 |
| |
evidence_fileName |
| |
evidence_filePath |
| |
evidence_processId |
| |
evidence_processCommandLine |
| |
evidence_processCreationTime |
| |
evidence_parentProcessId |
| |
evidence_parentProcessCreationTime |
| |
evidence_parentProcessFileName |
| |
evidence_parentProcessFilePath |
| |
evidence_ipAddress |
| |
evidence_url |
| |
evidence_registryKey |
| |
evidence_registryHive |
| |
evidence_registryValueType |
| |
evidence_registryValue |
| |
evidence_registryValueName |
| |
evidence_accountName |
| |
evidence_domainName |
| |
evidence_userSid |
| |
evidence_aadUserId |
| |
evidence_userPrincipalName |
| |
evidence_detectionStatus |
| |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
Anchor | ||||
---|---|---|---|---|
|
Field | Type | Extra fields |
---|---|---|
eventdate |
| |
hostname |
| |
at_devo_pulling_id |
| |
DeviceId |
| |
DeviceName |
| |
OSPlatform |
| |
OSVersion |
| |
Timestamp |
| |
ConfigurationId |
| |
ConfigurationCategory |
| |
ConfigurationSubcategory |
| |
ConfigurationImpact |
| |
IsApplicable |
| |
ConfigurationName |
| |
RecommendationReference |
| |
RbacGroupId |
| |
RbacGroupName |
| |
IsCompliant |
| |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
Anchor | ||||
---|---|---|---|---|
|
assessment_software_inventory
Field | Type | Extra |
---|
fields | |
---|---|
eventdate |
|
hostname |
|
-
at_devo_pulling_id |
|
-
DeviceId |
|
DeviceName |
|
timestamp
OSPlatform |
|
SoftwareVendor |
timestamp
|
-
SoftwareName |
|
SoftwareVersion |
|
str
NumberOfWeaknesses |
|
DiskPaths |
|
-
RegistryPaths_str |
|
SoftwareFirstSeenTimestamp |
|
ip4
SoftwareLastSeenTimestamp |
|
EndOfSupportStatus |
ip4
|
-
EndOfSupportDate |
|
-
RbacGroupId |
|
-
RbacGroupName |
|
-
rbacGroupId
int4
-
rbacGroupName
hostchain |
|
-
✓ | |
tag |
|
✓ |
exposureLevel
str
-
isAadJoined
bool
-
aadDeviceId
str
-
machineTags
str
-
defenderAvStatus
str
-
onboardingStatus
str
-
osArchitecture
str
-
managedBy
str
-
managedByStatus
str
-
ipAddresses
str
-
vmMetadata
str
rawMessage |
|
-
✓ |
Rw tab | ||
---|---|---|
|
Anchor | ||||
---|---|---|---|---|
|
Field | Type | Extra fields |
---|---|---|
eventdate |
| |
hostname |
| |
at_devo_pulling_id |
|
-
related_logon_users
int4
-
related_alerts
int4
-
related_vulnerabilities
int4
-
related_recommendations
int4
id |
| |
startTime |
| |
endTime |
| |
state |
| |
cancelledBy |
| |
statusDetails |
| |
machineId |
| |
computerDnsName |
| |
triggeringAlertId |
| |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
Anchor | ||
---|---|---|
|
|
|
machines
Field | Type | Extra |
---|
fields | |
---|---|
eventdate |
|
hostname |
|
id |
|
-
computerDnsName |
|
firstSeen |
|
str
-
weaknesses
int4
-
vendor
str
-
recommendedVersion
str
-
recommendedVendor
str
-
recommendedProgram
str
-
recommendationCategory
str
-
subCategory
str
-
severityScore
float8
-
publicExploit
bool
-
activeAlert
bool
-
associatedThreats
str
-
remediationType
str
-
status
str
-
configScoreImpact
float8
-
exposureImpact
float8
-
totalMachineCount
int4
-
exposedMachinesCount
int4
-
nonProductivityImpactedAssets
int4
-
relatedComponent
str
-
hasUnpatchableCve
bool
lastSeen |
| |
osPlatform |
| |
osVersion |
| |
osProcessor |
| |
version |
| |
lastIpAddress |
| |
lastExternalIpAddress |
| |
agentVersion |
| |
osBuild |
| |
healthStatus |
| |
deviceValue |
| |
rbacGroupId |
| |
rbacGroupName |
| |
riskScore |
| |
exposureLevel |
| |
isAadJoined |
| |
aadDeviceId |
| |
machineTags |
| |
defenderAvStatus |
| |
onboardingStatus |
| |
osArchitecture |
| |
managedBy |
| |
managedByStatus |
| |
ipAddresses |
| |
vmMetadata |
| |
at_devo_pulling_id |
| |
related_logon_users |
| |
related_alerts |
| |
related_vulnerabilities |
| |
related_recommendations |
| |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
Anchor | ||||
---|---|---|---|---|
|
Field | Type | Extra fields |
---|---|---|
eventdate |
| |
hostname |
| |
id |
| |
productName |
| |
recommendationName |
| |
weaknesses |
| |
vendor |
| |
recommendedVersion |
| |
recommendedVendor |
| |
recommendedProgram |
| |
recommendationCategory |
| |
subCategory |
| |
severityScore |
| |
publicExploit |
| |
activeAlert |
| |
associatedThreats |
| |
remediationType |
| |
status |
| |
configScoreImpact |
| |
exposureImpact |
| |
totalMachineCount |
| |
exposedMachinesCount |
| |
nonProductivityImpactedAssets |
| |
relatedComponent |
| |
hasUnpatchableCve |
| |
at_devo_pulling_id |
| |
related_software |
| |
related_machines |
| |
related_vulnerabilities |
| |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
Anchor | ||||
---|---|---|---|---|
|
Field | Type | Extra fields |
---|---|---|
eventdate |
| |
hostname |
| |
id |
| |
name |
| |
vendor |
| |
weaknesses |
| |
publicExploit |
| |
activeAlert |
| |
exposedMachines |
| |
installedMachines |
| |
impactScore |
| |
isNormalized |
| |
category |
| |
distributions |
| |
related_vulnerabilities |
| |
related_machines |
| |
related_version_distribution |
| |
related_missing_kbs |
| |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
Anchor | ||||
---|---|---|---|---|
|
Field | Type | Extra fields |
---|---|---|
eventdate |
| |
hostname |
| |
at_odata_context |
| |
id |
| |
name |
| |
description |
| |
severity |
| |
cvssV3 |
| |
exposedMachines |
| |
publishedOn |
| |
updatedOn |
| |
publicExploit |
| |
exploitVerified |
| |
exploitInKit |
| |
exploitTypes |
| |
exploitUris |
| |
at_devo_pulling_id |
| |
related_machines |
| |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
Anchor | ||||
---|---|---|---|---|
|
Field | Type | Field transformation | Source field name | Extra fields | ||
---|---|---|---|---|---|---|
eventdate |
|
|
| |||
hostname |
|
|
| |||
id |
|
|
| |||
name |
|
|
| |||
type |
|
|
| |||
tenant_id |
|
|
| |||
kind |
|
|
| |||
location |
|
|
| |||
resource_group |
|
|
| |||
subscription_id |
|
|
| |||
managed_by |
|
|
| |||
sku |
|
|
| |||
plan |
|
|
| |||
properties__product_component_name |
|
|
| |||
properties__azure_resource_id |
|
|
| |||
properties__extended_properties__device_resource_ids |
|
|
| |||
properties__extended_properties__alert_management_uri |
|
|
| |||
properties__extended_properties__device_id |
|
|
| |||
properties__extended_properties__site_display_name |
|
|
| |||
properties__extended_properties__source_device_address_ip4 |
|
| properties__extended_properties__source_device_address | |||
properties__extended_properties__source_device_address_ip6 |
|
| properties__extended_properties__source_device_address | |||
properties__extended_properties__compromised_entity_id |
|
|
| |||
properties__extended_properties__sensor_version |
|
|
| |||
properties__extended_properties__source_device_ip4 |
|
| properties__extended_properties__source_device | |||
properties__extended_properties__source_device_ip6 |
|
| properties__extended_properties__source_device | |||
properties__extended_properties__sensor_zone |
|
|
| |||
properties__extended_properties__sensor_type |
|
|
| |||
properties__extended_properties__protocol |
|
|
| |||
properties__extended_properties__sensor_id |
|
|
| |||
properties__extended_properties__category |
|
|
| |||
properties__extended_properties_plc_new_operating_mode |
|
|
| |||
properties__extended_properties__destination_device_address_ip4 |
|
| properties__extended_properties__destination_device_address | |||
properties__extended_properties__destination_device_address_ip6 |
|
| properties__extended_properties__destination_device_address | |||
properties__alert_learn_status |
|
|
| |||
properties__system_alert_id |
|
|
| |||
properties__start_time_utc |
|
| properties__start_time_utc_str | |||
properties__display_name |
|
|
| |||
properties__severity |
|
|
| |||
properties__techniques |
|
|
| |||
properties__end_time_utc_str |
|
|
| |||
properties__end_time_utc |
|
| properties__end_time_utc_str | |||
properties__alert_type |
|
|
| |||
properties__entities |
|
|
| |||
properties__status |
|
|
| |||
properties__intent |
|
|
| |||
tags |
|
|
| |||
identity |
|
|
| |||
zones |
|
|
| |||
extended_location |
|
|
| |||
at_devo_environment |
|
|
| |||
at_devo_pulling_id |
|
|
|
int4
hostchain |
|
|
int4
|
✓ |
tag |
int4
|
|
hostchain
str
| ✓ |
rawMessage |
|
|
rawMessage
str
| ✓ |