Query Logs in Azure Sentinel
Query Logs in Logs Page
Understand Azure Sentinel Table
Table |
Description |
SecurityAlert |
Contains
alerts generated from Sentinel Analytical Rules. Also, it includes alerts
created directly from Sentinel Data Connector. |
SecurityIncident |
Alerts
can generate incidents. Incidents are related to alert(s). |
ThreatIntelligenceIndicator |
Contains
user-created or data connector ingested indicators such as File Hashes, IP
Addresses, Domain. |
Watchlist |
An
Azure Sentinel watchlist contains imported data. |
Understand Common Tables
Table |
Description |
AzureActivity |
Entries
from the Azure Activity log that provides insights into any
subscription-level or management group level events that have occurred in
Azure. |
AzureDiagnostics |
Stores
resource logs for Azure Services that use Azure Diagnostics mode. Resource
logs describes the internal operation of Azure resources. |
AuditLogs |
Audit
Logs for Azure Active Directory includes system activity information about
user and group management managed applications as well as directory
activities. |
CommonSecurityLog |
Syslog
messages using the Common Event Format (CEF). |
McasShadowltReporting |
Microsoft
Cloud App Security logs. |
OfficeActivity |
Audit
logs for Office 365 tenants collected by Azure Sentinel. Including Exchange,
SharePoint, and Teams Logs. |
SecurityEvent |
Security
events collected from Windows machines by Azure Security Center or Azure
Sentinel. |
SigninLogs |
Azure
Active Directory Sign in logs. |
Syslog |
Syslog
events on Linux computers using the Log Analytics agent. |
Event |
Sysmon
Events collected from a Windows host. |
WindowsFirewall |
Windows
Firewall Events. |
Understand Microsoft 365 Defender Tables
Table |
Description |
DeviceEvents |
The
miscellaneous device events table contains information about various event
types including, events triggered by security controls, such as Microsoft
Defender Antivirus and exploit protection. |
DeviceFileEvents |
This
table contains information about file creation, modification, and other file
system events. |
DeviceImageLoadEvents |
This
table contains information about DLL loading events. |
DeviceInfo |
This
table contains information about devices in the organization, including their
OS version, active users, and computer name. |
DeviceLogonEvents |
This
table contains information about user logons and other authentication events. |
DeviceNetworkInfo |
This
table contains information about networking configuration of devices, including
network adapters, IP and MAC addresses, and connected networks or domains. |
DeviceProcessEvents |
This
table contains information about process creation and related events. |
DeviceRegistryEvents |
This
table contains information about the creation and modification of registry
entries. |
DeviceNetworkEvents |
This
table contains information about network connection and related events. |
Comments
Post a Comment