Document toolboxDocument toolbox

cloud.msgraph

Introduction

The tags beginning with cloud.msgraph identify events generated by Microsoft Graph.

Valid tags and data tables

The full tag must have at least 2 levels. The first two are fixed as cloud.msgraph. The third level identifies the type of events sent, and the fourth level indicates the event subtype.

These are the valid tags and corresponding data tables that will receive the parsers' data:

Product / Service

Tags

Data tables

Product / Service

Tags

Data tables

Microsoft Graph

cloud.msgraph

cloud.msgraph

cloud.msgraph.security.alerts

cloud.msgraph.security.alerts

cloud.msgraph.security.alerts_v2

cloud.msgraph.security.alerts_v2

cloud.msgraph.security.scorecontrol

cloud.msgraph.security.scorecontrol

cloud.msgraph.security.scores

cloud.msgraph.security.scores

For more information, read more About Devo tags.

Table structure

These are the fields displayed in these tables:

cloud.msgraph

Field

Type

Source field name

Extra fields

Field

Type

Source field name

Extra fields

eventdate

timestamp

 

 

hostname

str

 

 

product

str

vproduct

 

type

str

vtype

 

rawMessage

str

 

 

hostchain

str

 

✓

tag

str

 

✓

cloud.msgraph.security.alerts

Field

Type

Field transformation

Source field name

Extra fields

Field

Type

Field transformation

Source field name

Extra fields

eventdate

timestamp

 

 

 

hostname

str

 

 

 

id

str

 

 

 

azureTenantId

str

 

 

 

azureSubscriptionId

str

 

 

 

riskScore

str

 

 

 

tags

str

 

 

 

activityGroupName

str

 

 

 

assignedTo

str

 

 

 

category

str

 

 

 

closedDateTime

timestamp

 

 

 

comments

str

 

 

 

confidence

int4

 

 

 

createdDateTime

str

 

 

 

description

str

 

 

 

detectionIds

str

 

 

 

eventDateTime

str

 

 

 

feedback

str

 

 

 

incidentIds

str

 

 

 

lastModifiedDateTime

str

 

 

 

recommendedActions

str

 

 

 

severity

str

 

 

 

sourceMaterials

str

 

 

 

status

str

 

 

 

title

str

 

 

 

vendorInformation__provider

str

 

 

 

vendorInformation__providerVersion

str

 

 

 

vendorInformation__subProvider

str

 

 

 

vendorInformation__vendor

str

 

 

 

cloudAppStates_json

json

 

 

 

fileStates_json

json

 

 

 

hostStates_json

json

 

 

 

historyStates_json

json

 

 

 

malwareStates_json

json

 

 

 

networkConnections_json

json

 

 

 

processes_json

json

 

 

 

registryKeyStates_json

json

 

 

 

securityResources_json

json

 

 

 

triggers_json

json

 

 

 

userStates__aadUserId_str

str

join(userStates__aadUserId, ',')

userStates__aadUserId

 

userStates__accountName_str

str

join(userStates__accountName, ',')

userStates__accountName

 

userStates__domainName_str

str

join(userStates__domainName, ',')

userStates__domainName

 

userStates__emailRole_str

str

userStates__emailRole

 

userStates__isVpn_str

str

userStates__isVpn

 

userStates__logonDateTime_str

str

userStates__logonDateTime

 

userStates__logonId_str

str

userStates__logonId

 

userStates__logonIp_str

str

userStates__logonIp

 

userStates__logonLocation_str

str

userStates__logonLocation

 

userStates__logonType_str

str

userStates__logonType

 

userStates__onPremisesSecurityIdentifier_str

str

userStates__onPremisesSecurityIdentifier

 

userStates__riskScore_str

str

userStates__riskScore

 

userStates__userAccountType_str

str

userStates__userAccountType

 

userStates__userPrincipalName_str

str

userStates__userPrincipalName

 

vulnerabilityStates_json

json

 

 

 

hostchain

str

 

 

✓

tag

str

 

 

✓

rawMessage

str

 

 

✓

cloud.msgraph.security.alerts_v2

Field

Type

Extra fields

Field

Type

Extra fields

eventdate

timestamp

 

hostname

str

 

id

str

 

provider_alert_id

str

 

incident_id

str

 

status

str

 

severity

str

 

classification

str

 

determination

str

 

service_source

str

 

detection_source

str

 

detector_id

str

 

tenant_id

str

 

title

str

 

description

str

 

recommended_actions

str

 

category

str

 

assigned_to

str

 

alert_web_url

str

 

incident_web_url

str

 

actor_display_name

str

 

threat_display_name

str

 

threat_family_name

str

 

mitre_techniques

str

 

created_date_time

str

 

last_update_date_time

str

 

resolved_date_time

str

 

first_activity_date_time

str

 

last_activity_date_time

str

 

comments

str

 

evidence

str

 

at_devo_environment

str

 

at_devo_pulling_id

str

 

hostchain

str

 ✓

tag

str

 ✓

rawMessage

str

 ✓

cloud.msgraph.security.scorecontrol

Field

Type

Extra fields

Field

Type

Extra fields

eventdate

timestamp

 

hostname

str

 

id

str

 

azureTenantId

str

 

actionType

str

 

actionUrl

str

 

controlCategory

str

 

title

str

 

deprecated

bool

 

implementationCost

str

 

lastModifiedDateTime

str

 

maxScore

float8

 

rank

int4

 

remediation

str

 

remediationImpact

str

 

service

str

 

threats

str

 

tier

str

 

userImpact

str

 

vendorInformation__provider

str

 

vendorInformation__providerVersion

str

 

vendorInformation__subProvider

str

 

vendorInformation__vendor

str

 

complianceInformation

str

 

controlStateUpdates

str

 

hostchain

str

 ✓

tag

str

 ✓

rawMessage

str

✓ 

cloud.msgraph.security.scores

Field

Type

Extra fields

Field

Type

Extra fields

eventdate

timestamp

 

hostname

str

 

id

str

 

azureTenantId

str

 

activeUserCount

int4

 

createdDateTime

timestamp

 

currentScore

float8

 

enabledServices

str

 

licensedUserCount

int4

 

maxScore

float8

 

vendorInformation__provider

str

 

vendorInformation__providerVersion

str

 

vendorInformation__subProvider

str

 

vendorInformation__vendor

str

 

averageComparativeScores

str

 

controlScores

str

 

hostchain

str

 ✓ 

tag

str

 ✓ 

rawMessage

str

 ✓Â