casb.microsoft_defender
Introduction
The tags beginning with casb.microsoft
identify events generated by Microsoft Defender.
Valid tags and data tables
The full tag must have 4 levels. The first two are fixed as casb.microsoft
. The third level identifies the type of events sent.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
Microsoft Defender |
|
|
|
| |
|
| |
|
| |
|
|
Table structure
This is the set displayed by these tables.