Document toolboxDocument toolbox

casb.microsoft_defender

Introduction

The tags beginning with casb.microsoft identify events generated by Microsoft Defender.

Valid tags and data tables

The full tag must have 4 levels. The first two are fixed as casb.microsoft. The third level identifies the type of events sent.

These are the valid tags and corresponding data tables that will receive the parsers' data:

Product / Service

Tags

Data tables

Product / Service

Tags

Data tables

Microsoft Defender

casb.microsoft_defender.cloud_apps.activities

casb.microsoft_defender.cloud_apps.activities

casb.microsoft_defender.cloud_apps.alerts

casb.microsoft_defender.cloud_apps.alerts

casb.microsoft_defender.cloud_apps.data_enrichement

casb.microsoft_defender.cloud_apps.data_enrichement

casb.microsoft_defender.cloud_apps.entities

asb.microsoft_defender.cloud_apps.entities

casb.microsoft_defender.cloud_apps.files

casb.microsoft_defender.cloud_apps.files

Table structure

This is the set displayed by these tables.