N/A Data Sources Data Sources

1 / 1
Name Platform Sourcetype Source Supported TA Date
Cisco Secure Application AppDynamics Alerts N/A appdynamics_security AppDynamics Security

            1
            
          
            2
            
          
            3
            
          
            4
            
          
            5
            
          
            6
            
          
            7
            MS Defender ATP Alerts
          
            8
            
          
            9
            
          
            10
            N/A
          
            11
            
          
            12
            
          
            13
            ms:defender:atp:alerts
          
            14
            
          
            15
            
          
            16
            ms_defender_atp_alerts
          
            17
            
          
            18
            
          
            20
            
          
            21
            
          
            22
            
          
            23
            
          
            24
            
          
            25
            
          
            26
            Ivanti VTM Audit
          
            27
            
          
            28
            
          
            29
            N/A
          
            30
            
          
            31
            
          
            32
            ivanti_vtm_audit
          
            33
            
          
            34
            
          
            35
            ivanti_vtm
          
            36
            
          
            37
            
          
            39
            
          
            40
            
          
            41
            
          
            42
            
          
            43
            
          
            44
            
          
            45
            Bro
          
            46
            
          
            47
            
          
            48
            N/A
          
            49
            
          
            50
            
          
            51
            bro:http:json
          
            52
            
          
            53
            
          
            54
            bro:http:json
          
            55
            
          
            56
            
          
            58
            
          
            59
            
          
            60
            
          
            61
            
          
            62
            
          
            63
            
          
            64
            CircleCI
          
            65
            
          
            66
            
          
            67
            N/A
          
            68
            
          
            69
            
          
            70
            circleci
          
            71
            
          
            72
            
          
            73
            circleci
          
            74
            
          
            75
            
          
            77
            
          
            78
            
          
            79
            
          
            80
            
          
            81
            
          
            82
            
          
            83
            Cisco AI Defense Alerts
          
            84
            
          
            85
            
          
            86
            N/A
          
            87
            
          
            88
            
          
            89
            cisco:ai:defense
          
            90
            
          
            91
            
          
            92
            cisco_ai_defense
          
            93
            
          
            94
            
          
            96
            
          
            97
            
          
            98
            
          
            99
            
          
            100
            
          
            101
            
          
            102
            CrowdStrike ProcessRollup2
          
            103
            
          
            104
            
          
            105
            N/A
          
            106
            
          
            107
            
          
            108
            crowdstrike:events:sensor
          
            109
            
          
            110
            
          
            111
            crowdstrike
          
            112
            
          
            113
            
          
            115
            
          
            116
            
          
            117
            
          
            118
            
          
            119
            
          
            120
            
          
            121
            CrushFTP
          
            122
            
          
            123
            
          
            124
            N/A
          
            125
            
          
            126
            
          
            127
            crushftp:sessionlogs
          
            128
            
          
            129
            
          
            130
            crushftp
          
            131
            
          
            132
            
          
            134
            
          
            135
            
          
            136
            
          
            137
            
          
            138
            
          
            139
            
          
            140
            G Suite Drive
          
            141
            
          
            142
            
          
            143
            N/A
          
            144
            
          
            145
            
          
            146
            gsuite:drive:json
          
            147
            
          
            148
            
          
            149
            http:gsuite
          
            150
            
          
            151
            
          
            153
            
          
            154
            
          
            155
            
          
            156
            
          
            157
            
          
            158
            
          
            159
            G Suite Gmail
          
            160
            
          
            161
            
          
            162
            N/A
          
            163
            
          
            164
            
          
            165
            gsuite:gmail:bigquery
          
            166
            
          
            167
            
          
            168
            http:gsuite
          
            169
            
          
            170
            
          
            172
            
          
            173
            
          
            174
            
          
            175
            
          
            176
            
          
            177
            
          
            178
            Google Workspace login_failure
          
            179
            
          
            180
            
          
            181
            N/A
          
            182
            
          
            183
            
          
            184
            gws:reports:admin
          
            185
            
          
            186
            
          
            187
            gws:reports:admin
          
            188
            
          
            189
            
          
            191
            
          
            192
            
          
            193
            
          
            194
            
          
            195
            
          
            196
            
          
            197
            Google Workspace login_success
          
            198
            
          
            199
            
          
            200
            N/A
          
            201
            
          
            202
            
          
            203
            gws:reports:admin
          
            204
            
          
            205
            
          
            206
            gws:reports:admin
          
            207
            
          
            208
            
          
            210
            
          
            211
            
          
            212
            
          
            213
            
          
            214
            
          
            215
            
          
            216
            MS365 Defender Incident Alerts
          
            217
            
          
            218
            
          
            219
            N/A
          
            220
            
          
            221
            
          
            222
            ms365:defender:incident:alerts
          
            223
            
          
            224
            
          
            225
            ms365_defender_incident_alerts
          
            226
            
          
            227
            
          
            229
            
          
            230
            
          
            231
            
          
            232
            
          
            233
            
          
            234
            
          
            235
            Nginx Access
          
            236
            
          
            237
            
          
            238
            N/A
          
            239
            
          
            240
            
          
            241
            nginx:plus:kv
          
            242
            
          
            243
            
          
            244
            /var/log/nginx/access.log
          
            245
            
          
            246
            
          
            248
            
          
            249
            
          
            250
            
          
            251
            
          
            252
            
          
            253
            
          
            254
            O365
          
            255
            
          
            256
            
          
            257
            N/A
          
            258
            
          
            259
            
          
            260
            o365:management:activity
          
            261
            
          
            262
            
          
            263
            o365
          
            264
            
          
            265
            
          
            267
            
          
            268
            
          
            269
            
          
            270
            
          
            271
            
          
            272
            
          
            273
            O365 Add app role assignment grant to user.
          
            274
            
          
            275
            
          
            276
            N/A
          
            277
            
          
            278
            
          
            279
            o365:management:activity
          
            280
            
          
            281
            
          
            282
            o365
          
            283
            
          
            284
            
          
            286
            
          
            287
            
          
            288
            
          
            289
            
          
            290
            
          
            291
            
          
            292
            O365 Add app role assignment to service principal.
          
            293
            
          
            294
            
          
            295
            N/A
          
            296
            
          
            297
            
          
            298
            o365:management:activity
          
            299
            
          
            300
            
          
            301
            o365
          
            302
            
          
            303
            
          
            305
            
          
            306
            
          
            307
            
          
            308
            
          
            309
            
          
            310
            
          
            311
            O365 Add-MailboxPermission
          
            312
            
          
            313
            
          
            314
            N/A
          
            315
            
          
            316
            
          
            317
            o365:management:activity
          
            318
            
          
            319
            
          
            320
            o365
          
            321
            
          
            322
            
          
            324
            
          
            325
            
          
            326
            
          
            327
            
          
            328
            
          
            329
            
          
            330
            O365 Add member to role.
          
            331
            
          
            332
            
          
            333
            N/A
          
            334
            
          
            335
            
          
            336
            o365:management:activity
          
            337
            
          
            338
            
          
            339
            o365
          
            340
            
          
            341
            
          
            343
            
          
            344
            
          
            345
            
          
            346
            
          
            347
            
          
            348
            
          
            349
            O365 Add owner to application.
          
            350
            
          
            351
            
          
            352
            N/A
          
            353
            
          
            354
            
          
            355
            o365:management:activity
          
            356
            
          
            357
            
          
            358
            o365
          
            359
            
          
            360
            
          
            362
            
          
            363
            
          
            364
            
          
            365
            
          
            366
            
          
            367
            
          
            368
            O365 Add service principal.
          
            369
            
          
            370
            
          
            371
            N/A
          
            372
            
          
            373
            
          
            374
            o365:management:activity
          
            375
            
          
            376
            
          
            377
            o365
          
            378
            
          
            379
            
          
            381
            
          
            382
            
          
            383
            
          
            384
            
          
            385
            
          
            386
            
          
            387
            O365 Change user license.
          
            388
            
          
            389
            
          
            390
            N/A
          
            391
            
          
            392
            
          
            393
            o365:management:activity
          
            394
            
          
            395
            
          
            396
            o365
          
            397
            
          
            398
            
          
            400
            
          
            401
            
          
            402
            
          
            403
            
          
            404
            
          
            405
            
          
            406
            O365 Consent to application.
          
            407
            
          
            408
            
          
            409
            N/A
          
            410
            
          
            411
            
          
            412
            o365:management:activity
          
            413
            
          
            414
            
          
            415
            o365
          
            416
            
          
            417
            
          
            419
            
          
            420
            
          
            421
            
          
            422
            
          
            423
            
          
            424
            
          
            425
            O365 Disable Strong Authentication.
          
            426
            
          
            427
            
          
            428
            N/A
          
            429
            
          
            430
            
          
            431
            o365:management:activity
          
            432
            
          
            433
            
          
            434
            o365
          
            435
            
          
            436
            
          
            438
            
          
            439
            
          
            440
            
          
            441
            
          
            442
            
          
            443
            
          
            444
            O365 MailItemsAccessed
          
            445
            
          
            446
            
          
            447
            N/A
          
            448
            
          
            449
            
          
            450
            o365:management:activity
          
            451
            
          
            452
            
          
            453
            o365
          
            454
            
          
            455
            
          
            457
            
          
            458
            
          
            459
            
          
            460
            
          
            461
            
          
            462
            
          
            463
            O365 ModifyFolderPermissions
          
            464
            
          
            465
            
          
            466
            N/A
          
            467
            
          
            468
            
          
            469
            o365:management:activity
          
            470
            
          
            471
            
          
            472
            o365
          
            473
            
          
            474
            
          
            476
            
          
            477
            
          
            478
            
          
            479
            
          
            480
            
          
            481
            
          
            482
            O365 Set Company Information.
          
            483
            
          
            484
            
          
            485
            N/A
          
            486
            
          
            487
            
          
            488
            o365:management:activity
          
            489
            
          
            490
            
          
            491
            o365
          
            492
            
          
            493
            
          
            495
            
          
            496
            
          
            497
            
          
            498
            
          
            499
            
          
            500
            
          
            501
            O365 Set-Mailbox
          
            502
            
          
            503
            
          
            504
            N/A
          
            505
            
          
            506
            
          
            507
            o365:management:activity
          
            508
            
          
            509
            
          
            510
            o365
          
            511
            
          
            512
            
          
            514
            
          
            515
            
          
            516
            
          
            517
            
          
            518
            
          
            519
            
          
            520
            O365 Update application.
          
            521
            
          
            522
            
          
            523
            N/A
          
            524
            
          
            525
            
          
            526
            o365:management:activity
          
            527
            
          
            528
            
          
            529
            o365
          
            530
            
          
            531
            
          
            533
            
          
            534
            
          
            535
            
          
            536
            
          
            537
            
          
            538
            
          
            539
            O365 Update authorization policy.
          
            540
            
          
            541
            
          
            542
            N/A
          
            543
            
          
            544
            
          
            545
            o365:management:activity
          
            546
            
          
            547
            
          
            548
            o365
          
            549
            
          
            550
            
          
            552
            
          
            553
            
          
            554
            
          
            555
            
          
            556
            
          
            557
            
          
            558
            O365 Update user.
          
            559
            
          
            560
            
          
            561
            N/A
          
            562
            
          
            563
            
          
            564
            o365:management:activity
          
            565
            
          
            566
            
          
            567
            o365
          
            568
            
          
            569
            
          
            571
            
          
            572
            
          
            573
            
          
            574
            
          
            575
            
          
            576
            
          
            577
            O365 UserLoggedIn
          
            578
            
          
            579
            
          
            580
            N/A
          
            581
            
          
            582
            
          
            583
            o365:management:activity
          
            584
            
          
            585
            
          
            586
            o365
          
            587
            
          
            588
            
          
            590
            
          
            591
            
          
            592
            
          
            593
            
          
            594
            
          
            595
            
          
            596
            O365 UserLoginFailed
          
            597
            
          
            598
            
          
            599
            N/A
          
            600
            
          
            601
            
          
            602
            o365:management:activity
          
            603
            
          
            604
            
          
            605
            o365
          
            606
            
          
            607
            
          
            609
            
          
            610
            
          
            611
            
          
            612
            
          
            613
            
          
            614
            
          
            615
            Okta
          
            616
            
          
            617
            
          
            618
            N/A
          
            619
            
          
            620
            
          
            621
            OktaIM2:log
          
            622
            
          
            623
            
          
            624
            Okta
          
            625
            
          
            626
            
          
            628
            
          
            629
            
          
            630
            
          
            631
            
          
            632
            
          
            633
            
          
            634
            osquery
          
            635
            
          
            636
            
          
            637
            N/A
          
            638
            
          
            639
            
          
            640
            osquery:results
          
            641
            
          
            642
            
          
            643
            osquery
          
            644
            
          
            645
            
          
            647
            
          
            648
            
          
            649
            
          
            650
            
          
            651
            
          
            652
            
          
            653
            PingID
          
            654
            
          
            655
            
          
            656
            N/A
          
            657
            
          
            658
            
          
            659
            XmlWinEventLog
          
            660
            
          
            661
            
          
            662
            XmlWinEventLog:Security
          
            663
            
          
            664
            
          
            666
            
          
            667
            
          
            668
            
          
            669
            
          
            670
            
          
            671
            
          
            672
            Suricata
          
            673
            
          
            674
            
          
            675
            N/A
          
            676
            
          
            677
            
          
            678
            suricata
          
            679
            
          
            680
            
          
            681
            suricata
          
            682
            
          
            683
            
          
            685
            
          
            686
            
          
            687
            
          
            688
            
          
            689
            
          
...
not set