Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
The CrowdStrikeAuditEvents table contains audit and detection event logs from CrowdStrike that have been ingested into Microsoft Sentinel.
Table attributes
| Attribute | Value |
|---|---|
| Resource types | - |
| Categories | Security |
| Solutions | SecurityInsights |
| Basic log | Yes |
| Ingestion-time DCR support | No |
| Lake-only ingestion | Yes |
| Sample Queries | Yes |
Columns
| Column | Type | Description |
|---|---|---|
| AccountId | string | Cloud account ID. |
| AddedPrivileges | string | Privileges that were added to the account. |
| AgentId | string | Unique identifier for the CrowdStrike agent. |
| AgentIdString | string | The agent ID string. |
| AggregateId | string | Aggregate identifier for related detections. |
| ApiClientId | string | API client ID used for the request. |
| AppId | string | Application ID. |
| AuditEventType | string | Event type from the audit attributes. |
| AuditKeyValues | string | JSON string containing audit key-value pairs. |
| AuthenticationProtocol | string | Authentication protocol used (e.g., NTLM, Kerberos). |
| Author | string | Author of the detection rule. |
| _BilledSize | real | The record size in bytes |
| Category | string | Category of the identity protection event (e.g., Incident). |
| Cid | string | Customer ID in the CrowdStrike platform. |
| CloudIndicator | string | Indicates if the detection involves cloud-based indicators. |
| CloudPlatform | string | Cloud platform (e.g., AWS, Azure, GCP). |
| CloudProvider | string | Cloud provider (e.g., aws, azure, gcp). |
| CloudService | string | Cloud service involved (e.g., EC2, S3). |
| CommandLine | string | Command line used to execute the process. |
| CompositeId | string | Composite identifier combining multiple detection attributes. |
| ComputerName | string | Name of the computer where the IOC was detected. |
| ConnectionDirection | string | Direction of the network connection. |
| Consumes | string | Content type consumed by the API. |
| ContextTimeStamp | datetime | Context timestamp of the IDP detection event (Unix epoch). |
| CurrentPrivileges | string | Current privilege level of the account. |
| CustomerId | string | Customer identifier in the CrowdStrike platform. |
| CustomerIdString | string | The customer ID string. |
| DataDomains | string | Data domains associated with the event. |
| Description | string | Detailed description of the detection. |
| DestinationEndpointIp | string | IP address of the destination endpoint. |
| DestinationEndpointName | string | Name of the destination endpoint. |
| DeviceId | string | Unique identifier for the device. |
| Disposition | string | Assessment result (e.g., Failed, Passed). |
| Eid | string | Event ID. |
| ElapsedMicroseconds | string | Elapsed time in microseconds. |
| ElapsedTime | string | Elapsed time of the request. |
| EndpointIp | string | IP address of the endpoint involved in the incident. |
| EndpointName | string | Name of the endpoint involved in the incident. |
| EndTime | datetime | End time of the event. |
| EndTimestamp | datetime | Unix epoch timestamp when the session ended. |
| EventAction | string | Action that triggered the IOA (e.g., TerminateInstances). |
| EventSource | string | Source of the event (e.g., aws.cloudtrail). |
| EventType | string | The type of event, used to filter logs. |
| EventUuid | string | Unique UUID for the event. |
| ExecutionId | string | Execution identifier for the report run. |
| ExternalApiType | string | The external API type. |
| FalconHostLink | string | Link to the detection details in the CrowdStrike Falcon console. |
| FileName | string | Name of the file associated with the IOC. |
| FilePath | string | Full path to the file. |
| Finding | string | Details of the finding. |
| FineScore | string | Fine score of the incident. |
| FirstSeen | datetime | First time the hash spreading was observed. |
| Flags | string | JSON string containing firewall rule flags (Audit, Log, Monitor). |
| GrandParentCommandLine | string | Command line of the grandparent process. |
| GrandParentImageFileName | string | Image file name of the grandparent process. |
| GrandParentImageFilePath | string | Full path to the grandparent process image file. |
| Hash | string | Credential hash observed spreading across hosts. |
| Highlights | string | JSON string containing highlights of the notification. |
| HostGroups | string | Host groups the system belongs to. |
| HostId | string | Identifier of the host involved in the incident. |
| Hostname | string | Name of the host where the event occurred. |
| HostnameField | string | Hostname of the target system. |
| IcmpCode | string | ICMP code if the protocol is ICMP. |
| IcmpType | string | ICMP type if the protocol is ICMP. |
| IdentityProtectionIncidentId | string | Unique identifier for the identity protection incident. |
| ImageFileName | string | Image file name of the process associated with the event. |
| IncidentDescription | string | Description of the hash spreading incident. |
| IncidentEndTime | datetime | End time of the incident (Unix epoch). |
| IncidentId | string | Unique identifier for the incident. |
| IncidentStartTime | datetime | Start time of the incident (Unix epoch). |
| IncidentType | string | Type of identity protection incident (e.g., GoldenTicketAlert). |
| Ipv | string | IP version (ipv4 or ipv6). |
| _IsBillable | string | Specifies whether ingesting the data is billable. When _IsBillable is false ingestion isn't billed to your Azure account |
| ItemId | string | Identifier of the matched item. |
| ItemPostedTimestamp | datetime | Timestamp when the item was posted. |
| ItemType | string | Type of the matched item. |
| LastSeen | datetime | Last time the hash spreading was observed. |
| LateralMovement | string | Lateral movement indicator for the incident. |
| LocalAddress | string | Local IP address involved in the firewall event. |
| LocalIp | string | Local IP address of the host. |
| LocalIpv6 | string | Local IPv6 address of the host. |
| LocalPort | string | Local port number involved in the firewall event. |
| LogonDomain | string | Logon domain associated with the detection. |
| MACAddress | string | MAC address of the host. |
| MatchCount | string | Number of times the firewall rule was matched. |
| MatchCountSinceLastReport | string | Number of matches since the last report. |
| MatchedTimestamp | datetime | Timestamp when the match was found. |
| MD5String | string | MD5 hash of the file. |
| Message | string | Message associated with the audit event. |
| MitreAttack | string | JSON string containing MITRE ATT&CK framework details. |
| MobileDetectionId | string | Unique identifier for the mobile detection. |
| Name | string | Name of the detection (e.g., Attacker Methodology). |
| NetworkProfile | string | Network profile identifier. |
| Nonce | string | A unique nonce value. |
| NotificationId | string | Unique identifier for the recon notification. |
| NumberOfCompromisedEntities | string | Number of compromised entities in the incident. |
| NumbersOfAlerts | string | Number of alerts associated with the incident. |
| Objective | string | Objective of the detection (e.g., Follow Through). |
| Offset | string | Stream offset value. |
| OperationName | string | Name of the operation performed. |
| ParentCommandLine | string | Command line of the parent process. |
| ParentImageFileName | string | Image file name of the parent process. |
| ParentImageFilePath | string | Full path to the parent process image file. |
| ParentProcessId | string | Process ID of the parent process. |
| Partition | string | Stream partition. |
| PatternDispositionDescription | string | Description of the pattern disposition action. |
| PatternDispositionFlags | string | JSON string containing flags indicating various pattern disposition actions. |
| PatternDispositionValue | string | Numerical value of the pattern disposition. |
| PatternId | string | Identifier for the detection pattern. |
| Pid | string | Process ID associated with the firewall event. |
| PlatformId | string | Platform ID (e.g., 0=Windows, 1=Mac, 2=Linux). |
| PlatformName | string | Name of the platform (e.g., Windows, Linux, Mac). |
| PolicyId | string | Policy identifier. |
| PolicyName | string | Name of the firewall policy. |
| PolicyStatement | string | Description of the CSPM policy that was triggered. |
| PreviousPrivileges | string | Previous privilege level of the account. |
| ProcessEndTime | datetime | Timestamp when the detected process ended. |
| ProcessId | string | Process ID associated with the IOC. |
| ProcessStartTime | datetime | Timestamp when the detected process started. |
| Produces | string | Content type produced by the API. |
| Protocol | string | Network protocol (e.g., 1=ICMP, 6=TCP, 17=UDP). |
| ReceivedTime | datetime | Time the request was received. |
| Region | string | Cloud region. |
| RemoteAddress | string | Remote IP address involved in the firewall event. |
| RemotePort | string | Remote port number involved in the firewall event. |
| ReportFileReference | string | File reference path for downloading the report. |
| ReportId | string | Unique identifier for the report. |
| ReportName | string | Name of the scheduled report. |
| ReportType | string | Type of the report (e.g., spotlight_vulnerabilities). |
| ReportUrl | string | URL to the CSPM assessment report. |
| RequestAccept | string | Accept header of the request. |
| RequestContentType | string | Content type of the request. |
| RequestMethod | string | HTTP method of the request (e.g., POST, GET). |
| RequestPath | string | Path of the API request. |
| RequestUriLength | string | Length of the request URI. |
| ResourceAttributes | string | JSON string containing resource attributes. |
| ResourceCreateTime | datetime | Creation time of the resource. |
| ResourceIdType | string | Type of the resource identifier (e.g., Instance Id). |
| ResourcesId | string | Identifier of the cloud resource. |
| ResourcesName | string | Name of the cloud resource. |
| ResourceUrl | string | URL to the resource in the cloud console. |
| RiskScore | string | Risk score associated with the detection. |
| RuleAction | string | Action taken by the firewall rule. |
| RuleDescription | string | Description of the firewall rule. |
| RuleFamilyId | string | Family identifier of the firewall rule. |
| RuleGroupName | string | Name of the firewall rule group. |
| RuleId | string | Identifier of the recon rule. |
| RuleName | string | Name of the recon rule. |
| RulePriority | string | Priority of the recon rule. |
| RuleTopic | string | Topic of the recon rule (e.g., Credential Exposure). |
| Scopes | string | API scopes used for the request. |
| SensorId | string | Unique identifier for the CrowdStrike sensor on the mobile device. |
| SensorIds | string | Sensor IDs associated with the detection. |
| ServiceName | string | Name of the service (e.g., api_request). |
| SessionId | string | Unique identifier for the remote response session. |
| Severity | string | Numerical severity level. |
| SeverityName | string | Text representation of the severity level. |
| SHA1String | string | SHA1 hash of the detected file. |
| SHA256Hashes | string | SHA256 hashes associated with the detection. |
| SHA256String | string | SHA256 hash of the detected file. |
| Source | string | Source of the audit event. |
| SourceAccountDomain | string | Domain of the source account. |
| SourceAccountName | string | Name of the source account. |
| SourceAccountObjectSid | string | Object SID of the source account. |
| SourceAccountUpn | string | User principal name of the source account. |
| SourceEndpointIp | string | IP address of the source endpoint. |
| SourceEndpointName | string | Name of the source endpoint. |
| SourceIp | string | Source IP address. |
| SourceProducts | string | Products associated with the detection source. |
| SourceSystem | string | The type of agent the event was collected by. For example, OpsManager for Windows agent, either direct connect or Operations Manager, Linux for all Linux agents, or Azure for Azure Diagnostics |
| SourceVendors | string | Vendors associated with the detection source. |
| SpreadCount | string | Number of hosts the hash has been observed on. |
| StartTime | datetime | Start time of the event. |
| StartTimestamp | datetime | Unix epoch timestamp when the session started. |
| State | string | Current state of the incident (e.g., IN_PROGRESS, CLOSED). |
| Status | string | Status of the report execution. |
| StatusCode | string | HTTP status code of the response. |
| StatusMessage | string | Status message for the report execution. |
| Success | bool | Whether the API call was successful. |
| Tactic | string | MITRE ATT&CK tactic. |
| TacticId | string | The MITRE ATT&CK tactic ID associated with the detection. |
| TacticIds | string | MITRE ATT&CK tactic IDs associated with the detection. |
| Tactics | string | MITRE ATT&CK tactics associated with the detection. |
| Tags | string | JSON string containing resource tags. |
| Technique | string | MITRE ATT&CK technique. |
| TechniqueId | string | The MITRE ATT&CK technique ID associated with the detection. |
| TechniqueIds | string | MITRE ATT&CK technique IDs associated with the detection. |
| Techniques | string | MITRE ATT&CK techniques associated with the detection. |
| TenantId | string | The Log Analytics workspace ID |
| TimeGenerated | datetime | The timestamp (in UTC) when the log entry was generated. |
| TraceId | string | Trace ID for request tracing. |
| TreeId | string | Tree identifier for the process tree. |
| Type | string | The name of the table |
| UserAgent | string | User agent string of the request. |
| UserId | string | User ID associated with the activity. |
| UserIp | string | IP address of the user making the API call. |
| UserName | string | Username who performed the action. |
| UserSourceIp | string | Source IP of the user. |
| UserUuid | string | UUID of the user who owns the scheduled report. |
| XdrType | string | Type of XDR detection (e.g., xdr). |