CrowdStrikeAuditEvents

The CrowdStrikeAuditEvents table contains audit and detection event logs from CrowdStrike that have been ingested into Microsoft Sentinel.

Table attributes

Attribute Value
Resource types -
Categories Security
Solutions SecurityInsights
Basic log Yes
Ingestion-time DCR support No
Lake-only ingestion Yes
Sample Queries Yes

Columns

Column Type Description
AccountId string Cloud account ID.
AddedPrivileges string Privileges that were added to the account.
AgentId string Unique identifier for the CrowdStrike agent.
AgentIdString string The agent ID string.
AggregateId string Aggregate identifier for related detections.
ApiClientId string API client ID used for the request.
AppId string Application ID.
AuditEventType string Event type from the audit attributes.
AuditKeyValues string JSON string containing audit key-value pairs.
AuthenticationProtocol string Authentication protocol used (e.g., NTLM, Kerberos).
Author string Author of the detection rule.
_BilledSize real The record size in bytes
Category string Category of the identity protection event (e.g., Incident).
Cid string Customer ID in the CrowdStrike platform.
CloudIndicator string Indicates if the detection involves cloud-based indicators.
CloudPlatform string Cloud platform (e.g., AWS, Azure, GCP).
CloudProvider string Cloud provider (e.g., aws, azure, gcp).
CloudService string Cloud service involved (e.g., EC2, S3).
CommandLine string Command line used to execute the process.
CompositeId string Composite identifier combining multiple detection attributes.
ComputerName string Name of the computer where the IOC was detected.
ConnectionDirection string Direction of the network connection.
Consumes string Content type consumed by the API.
ContextTimeStamp datetime Context timestamp of the IDP detection event (Unix epoch).
CurrentPrivileges string Current privilege level of the account.
CustomerId string Customer identifier in the CrowdStrike platform.
CustomerIdString string The customer ID string.
DataDomains string Data domains associated with the event.
Description string Detailed description of the detection.
DestinationEndpointIp string IP address of the destination endpoint.
DestinationEndpointName string Name of the destination endpoint.
DeviceId string Unique identifier for the device.
Disposition string Assessment result (e.g., Failed, Passed).
Eid string Event ID.
ElapsedMicroseconds string Elapsed time in microseconds.
ElapsedTime string Elapsed time of the request.
EndpointIp string IP address of the endpoint involved in the incident.
EndpointName string Name of the endpoint involved in the incident.
EndTime datetime End time of the event.
EndTimestamp datetime Unix epoch timestamp when the session ended.
EventAction string Action that triggered the IOA (e.g., TerminateInstances).
EventSource string Source of the event (e.g., aws.cloudtrail).
EventType string The type of event, used to filter logs.
EventUuid string Unique UUID for the event.
ExecutionId string Execution identifier for the report run.
ExternalApiType string The external API type.
FalconHostLink string Link to the detection details in the CrowdStrike Falcon console.
FileName string Name of the file associated with the IOC.
FilePath string Full path to the file.
Finding string Details of the finding.
FineScore string Fine score of the incident.
FirstSeen datetime First time the hash spreading was observed.
Flags string JSON string containing firewall rule flags (Audit, Log, Monitor).
GrandParentCommandLine string Command line of the grandparent process.
GrandParentImageFileName string Image file name of the grandparent process.
GrandParentImageFilePath string Full path to the grandparent process image file.
Hash string Credential hash observed spreading across hosts.
Highlights string JSON string containing highlights of the notification.
HostGroups string Host groups the system belongs to.
HostId string Identifier of the host involved in the incident.
Hostname string Name of the host where the event occurred.
HostnameField string Hostname of the target system.
IcmpCode string ICMP code if the protocol is ICMP.
IcmpType string ICMP type if the protocol is ICMP.
IdentityProtectionIncidentId string Unique identifier for the identity protection incident.
ImageFileName string Image file name of the process associated with the event.
IncidentDescription string Description of the hash spreading incident.
IncidentEndTime datetime End time of the incident (Unix epoch).
IncidentId string Unique identifier for the incident.
IncidentStartTime datetime Start time of the incident (Unix epoch).
IncidentType string Type of identity protection incident (e.g., GoldenTicketAlert).
Ipv string IP version (ipv4 or ipv6).
_IsBillable string Specifies whether ingesting the data is billable. When _IsBillable is false ingestion isn't billed to your Azure account
ItemId string Identifier of the matched item.
ItemPostedTimestamp datetime Timestamp when the item was posted.
ItemType string Type of the matched item.
LastSeen datetime Last time the hash spreading was observed.
LateralMovement string Lateral movement indicator for the incident.
LocalAddress string Local IP address involved in the firewall event.
LocalIp string Local IP address of the host.
LocalIpv6 string Local IPv6 address of the host.
LocalPort string Local port number involved in the firewall event.
LogonDomain string Logon domain associated with the detection.
MACAddress string MAC address of the host.
MatchCount string Number of times the firewall rule was matched.
MatchCountSinceLastReport string Number of matches since the last report.
MatchedTimestamp datetime Timestamp when the match was found.
MD5String string MD5 hash of the file.
Message string Message associated with the audit event.
MitreAttack string JSON string containing MITRE ATT&CK framework details.
MobileDetectionId string Unique identifier for the mobile detection.
Name string Name of the detection (e.g., Attacker Methodology).
NetworkProfile string Network profile identifier.
Nonce string A unique nonce value.
NotificationId string Unique identifier for the recon notification.
NumberOfCompromisedEntities string Number of compromised entities in the incident.
NumbersOfAlerts string Number of alerts associated with the incident.
Objective string Objective of the detection (e.g., Follow Through).
Offset string Stream offset value.
OperationName string Name of the operation performed.
ParentCommandLine string Command line of the parent process.
ParentImageFileName string Image file name of the parent process.
ParentImageFilePath string Full path to the parent process image file.
ParentProcessId string Process ID of the parent process.
Partition string Stream partition.
PatternDispositionDescription string Description of the pattern disposition action.
PatternDispositionFlags string JSON string containing flags indicating various pattern disposition actions.
PatternDispositionValue string Numerical value of the pattern disposition.
PatternId string Identifier for the detection pattern.
Pid string Process ID associated with the firewall event.
PlatformId string Platform ID (e.g., 0=Windows, 1=Mac, 2=Linux).
PlatformName string Name of the platform (e.g., Windows, Linux, Mac).
PolicyId string Policy identifier.
PolicyName string Name of the firewall policy.
PolicyStatement string Description of the CSPM policy that was triggered.
PreviousPrivileges string Previous privilege level of the account.
ProcessEndTime datetime Timestamp when the detected process ended.
ProcessId string Process ID associated with the IOC.
ProcessStartTime datetime Timestamp when the detected process started.
Produces string Content type produced by the API.
Protocol string Network protocol (e.g., 1=ICMP, 6=TCP, 17=UDP).
ReceivedTime datetime Time the request was received.
Region string Cloud region.
RemoteAddress string Remote IP address involved in the firewall event.
RemotePort string Remote port number involved in the firewall event.
ReportFileReference string File reference path for downloading the report.
ReportId string Unique identifier for the report.
ReportName string Name of the scheduled report.
ReportType string Type of the report (e.g., spotlight_vulnerabilities).
ReportUrl string URL to the CSPM assessment report.
RequestAccept string Accept header of the request.
RequestContentType string Content type of the request.
RequestMethod string HTTP method of the request (e.g., POST, GET).
RequestPath string Path of the API request.
RequestUriLength string Length of the request URI.
ResourceAttributes string JSON string containing resource attributes.
ResourceCreateTime datetime Creation time of the resource.
ResourceIdType string Type of the resource identifier (e.g., Instance Id).
ResourcesId string Identifier of the cloud resource.
ResourcesName string Name of the cloud resource.
ResourceUrl string URL to the resource in the cloud console.
RiskScore string Risk score associated with the detection.
RuleAction string Action taken by the firewall rule.
RuleDescription string Description of the firewall rule.
RuleFamilyId string Family identifier of the firewall rule.
RuleGroupName string Name of the firewall rule group.
RuleId string Identifier of the recon rule.
RuleName string Name of the recon rule.
RulePriority string Priority of the recon rule.
RuleTopic string Topic of the recon rule (e.g., Credential Exposure).
Scopes string API scopes used for the request.
SensorId string Unique identifier for the CrowdStrike sensor on the mobile device.
SensorIds string Sensor IDs associated with the detection.
ServiceName string Name of the service (e.g., api_request).
SessionId string Unique identifier for the remote response session.
Severity string Numerical severity level.
SeverityName string Text representation of the severity level.
SHA1String string SHA1 hash of the detected file.
SHA256Hashes string SHA256 hashes associated with the detection.
SHA256String string SHA256 hash of the detected file.
Source string Source of the audit event.
SourceAccountDomain string Domain of the source account.
SourceAccountName string Name of the source account.
SourceAccountObjectSid string Object SID of the source account.
SourceAccountUpn string User principal name of the source account.
SourceEndpointIp string IP address of the source endpoint.
SourceEndpointName string Name of the source endpoint.
SourceIp string Source IP address.
SourceProducts string Products associated with the detection source.
SourceSystem string The type of agent the event was collected by. For example, OpsManager for Windows agent, either direct connect or Operations Manager, Linux for all Linux agents, or Azure for Azure Diagnostics
SourceVendors string Vendors associated with the detection source.
SpreadCount string Number of hosts the hash has been observed on.
StartTime datetime Start time of the event.
StartTimestamp datetime Unix epoch timestamp when the session started.
State string Current state of the incident (e.g., IN_PROGRESS, CLOSED).
Status string Status of the report execution.
StatusCode string HTTP status code of the response.
StatusMessage string Status message for the report execution.
Success bool Whether the API call was successful.
Tactic string MITRE ATT&CK tactic.
TacticId string The MITRE ATT&CK tactic ID associated with the detection.
TacticIds string MITRE ATT&CK tactic IDs associated with the detection.
Tactics string MITRE ATT&CK tactics associated with the detection.
Tags string JSON string containing resource tags.
Technique string MITRE ATT&CK technique.
TechniqueId string The MITRE ATT&CK technique ID associated with the detection.
TechniqueIds string MITRE ATT&CK technique IDs associated with the detection.
Techniques string MITRE ATT&CK techniques associated with the detection.
TenantId string The Log Analytics workspace ID
TimeGenerated datetime The timestamp (in UTC) when the log entry was generated.
TraceId string Trace ID for request tracing.
TreeId string Tree identifier for the process tree.
Type string The name of the table
UserAgent string User agent string of the request.
UserId string User ID associated with the activity.
UserIp string IP address of the user making the API call.
UserName string Username who performed the action.
UserSourceIp string Source IP of the user.
UserUuid string UUID of the user who owns the scheduled report.
XdrType string Type of XDR detection (e.g., xdr).