Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -27,7 +27,7 @@
"displayName": "Authentication ASIM schema function",
"category": "ASIM",
"FunctionAlias": "vimAuthenticationEmpty",
"query": "let EmptyAuthenticationTable=datatable(\n TimeGenerated:datetime,\n Type:string,\n ActingAppId:string,\n ActingAppName:string,\n ActingAppType:string,\n ActingOriginalAppType:string,\n ActorDNUsername:string,\n ActorOriginalUserType:string,\n ActorScope:string,\n ActorScopeId:string,\n ActorSessionId:string,\n ActorSimpleUsername:string,\n ActorUserAadId:string,\n ActorUserAWSId:string,\n ActorUserId:string,\n ActorUserIdType:string,\n ActorUsername:string,\n ActorUsernameType:string,\n ActorUserOktaId:string,\n ActorUserPuid:string,\n ActorUserSid:string,\n ActorUserType:string,\n ActorUserUid:string,\n ActorUserUpn:string,\n ActorWindowsUsername:string,\n AdditionalFields:dynamic,\n Application:string,\n Dst:string,\n Dvc:string,\n DvcAction:string,\n DvcDescription:string,\n DvcDomain:string,\n DvcDomainType:string,\n DvcFQDN:string,\n DvcHostname:string,\n DvcId:string,\n DvcIdType:string,\n DvcInterface:string,\n DvcIpAddr:string,\n DvcMacAddr:string,\n DvcOriginalAction:string,\n DvcOs:string,\n DvcOsVersion:string,\n DvcScope:string,\n DvcScopeId:string,\n DvcZone:string,\n EventCount:int,\n EventEndTime:datetime,\n EventMessage:string,\n EventOriginalResultDetails:string,\n EventOriginalSeverity:string,\n EventOriginalSubType:string,\n EventOriginalType:string,\n EventOriginalUid:string,\n EventOwner:string,\n EventProduct:string,\n EventProductVersion:string,\n EventReportUrl:string,\n EventResult:string,\n EventResultDetails:string,\n EventSchema:string,\n EventSchemaVersion:string,\n EventSeverity:string,\n EventStartTime:datetime,\n EventSubType:string,\n EventType:string,\n EventUid:string,\n EventVendor:string,\n HttpUserAgent:string,\n IpAddr:string,\n LogonMethod:string,\n LogonProtocol:string,\n LogonTarget:string,\n Rule:string,\n RuleName:string,\n RuleNumber:int,\n Src:string,\n SrcDescription:string,\n SrcDeviceType:string,\n SrcDomain:string,\n SrcDomainType:string,\n SrcDvcHostnameType:string,\n SrcDvcId:string,\n SrcDvcIdType:string,\n SrcDvcOs:string,\n SrcDvcScope:string,\n SrcDvcScopeId:string,\n SrcFQDN:string,\n SrcGeoCity:string,\n SrcGeoCountry:string,\n SrcGeoLatitude:real,\n SrcGeoLongitude:real,\n SrcGeoRegion:string,\n SrcHostname:string,\n SrcIpAddr:string,\n SrcIsp:string,\n SrcOriginalRiskLevel:string,\n SrcPortNumber:string,\n SrcRiskLevel:int,\n TargetAppId:string,\n TargetAppName:string,\n TargetAppType:string,\n TargetDescription:string,\n TargetDeviceType:string,\n TargetDNUsername:string,\n TargetDomain:string,\n TargetDomainType:string,\n TargetDvcId:string,\n TargetDvcIdType:string,\n TargetDvcOs:string,\n TargetDvcScope:string,\n TargetDvcScopeId:string,\n TargetFQDN:string,\n TargetGeoCity:string,\n TargetGeoCountry:string,\n TargetGeoLatitude:real,\n TargetGeoLongitude:real,\n TargetGeoRegion:string,\n TargetHostname:string,\n TargetIpAddr:string,\n TargetOriginalAppType:string,\n TargetOriginalRiskLevel:string,\n TargetOriginalUserType:string,\n TargetPortNumber:int,\n TargetRiskLevel:int,\n TargetSessionId:string,\n TargetSimpleUsername:string,\n TargetUrl:string,\n TargetUserAadId:string,\n TargetUserAWSId:string,\n TargetUserId:string,\n TargetUserIdType:string,\n TargetUsername:string,\n TargetUsernameType:string,\n TargetUserOktaId:string,\n TargetUserPuid:string,\n TargetUserScope:string,\n TargetUserScopeId:string,\n TargetUserSid:string,\n TargetUserType:string,\n TargetUserUid:string,\n TargetUserUpn:string,\n TargetWindowsUsername:string,\n ThreatCategory:string,\n ThreatConfidence:int,\n ThreatField:string,\n ThreatFirstReportedTime:datetime,\n ThreatId:string,\n ThreatIpAddr:string,\n ThreatIsActive:bool,\n ThreatLastReportedTime:datetime,\n ThreatName:string,\n ThreatOriginalConfidence:string,\n ThreatOriginalRiskLevel:string,\n ThreatRiskLevel:int,\n User:string\n)[];\nEmptyAuthenticationTable",
"query": "let EmptyAuthenticationTable=datatable(\n TimeGenerated:datetime,\n Type:string,\n ActingAppId:string,\n ActingAppName:string,\n ActingAppType:string,\n ActingOriginalAppType:string,\n ActorDNUsername:string,\n ActorOriginalUserType:string,\n ActorScope:string,\n ActorScopeId:string,\n ActorSessionId:string,\n ActorSimpleUsername:string,\n ActorUserAadId:string,\n ActorUserAWSId:string,\n ActorUserId:string,\n ActorUserIdType:string,\n ActorUsername:string,\n ActorUsernameType:string,\n ActorUserOktaId:string,\n ActorUserPuid:string,\n ActorUserSid:string,\n ActorUserType:string,\n ActorUserUid:string,\n ActorUserUpn:string,\n ActorWindowsUsername:string,\n AdditionalFields:dynamic,\n Application:string,\n Dst:string,\n Dvc:string,\n DvcAction:string,\n DvcDescription:string,\n DvcDomain:string,\n DvcDomainType:string,\n DvcFQDN:string,\n DvcHostname:string,\n DvcId:string,\n DvcIdType:string,\n DvcInterface:string,\n DvcIpAddr:string,\n DvcMacAddr:string,\n DvcOriginalAction:string,\n DvcOs:string,\n DvcOsVersion:string,\n DvcScope:string,\n DvcScopeId:string,\n DvcZone:string,\n EventCount:int,\n EventEndTime:datetime,\n EventMessage:string,\n EventOriginalResultDetails:string,\n EventOriginalSeverity:string,\n EventOriginalSubType:string,\n EventOriginalType:string,\n EventOriginalUid:string,\n EventOwner:string,\n EventProduct:string,\n EventProductVersion:string,\n EventReportUrl:string,\n EventResult:string,\n EventResultDetails:string,\n EventSchema:string,\n EventSchemaVersion:string,\n EventSeverity:string,\n EventStartTime:datetime,\n EventSubType:string,\n EventType:string,\n EventUid:string,\n EventVendor:string,\n HttpUserAgent:string,\n IpAddr:string,\n LogonMethod:string,\n LogonProtocol:string,\n LogonTarget:string,\n Rule:string,\n RuleName:string,\n RuleNumber:int,\n Src:string,\n SrcDescription:string,\n SrcDeviceType:string,\n SrcDomain:string,\n SrcDomainType:string,\n SrcDvcHostnameType:string,\n SrcDvcId:string,\n SrcDvcIdType:string,\n SrcDvcOs:string,\n SrcDvcScope:string,\n SrcDvcScopeId:string,\n SrcFQDN:string,\n SrcGeoCity:string,\n SrcGeoCountry:string,\n SrcGeoLatitude:real,\n SrcGeoLongitude:real,\n SrcGeoRegion:string,\n SrcHostname:string,\n SrcIpAddr:string,\n SrcIsp:string,\n SrcOriginalRiskLevel:string,\n SrcPortNumber:int,\n SrcRiskLevel:int,\n TargetAppId:string,\n TargetAppName:string,\n TargetAppType:string,\n TargetDescription:string,\n TargetDeviceType:string,\n TargetDNUsername:string,\n TargetDomain:string,\n TargetDomainType:string,\n TargetDvcId:string,\n TargetDvcIdType:string,\n TargetDvcOs:string,\n TargetDvcScope:string,\n TargetDvcScopeId:string,\n TargetFQDN:string,\n TargetGeoCity:string,\n TargetGeoCountry:string,\n TargetGeoLatitude:real,\n TargetGeoLongitude:real,\n TargetGeoRegion:string,\n TargetHostname:string,\n TargetIpAddr:string,\n TargetOriginalAppType:string,\n TargetOriginalRiskLevel:string,\n TargetOriginalUserType:string,\n TargetPortNumber:int,\n TargetRiskLevel:int,\n TargetSessionId:string,\n TargetSimpleUsername:string,\n TargetUrl:string,\n TargetUserAadId:string,\n TargetUserAWSId:string,\n TargetUserId:string,\n TargetUserIdType:string,\n TargetUsername:string,\n TargetUsernameType:string,\n TargetUserOktaId:string,\n TargetUserPuid:string,\n TargetUserScope:string,\n TargetUserScopeId:string,\n TargetUserSid:string,\n TargetUserType:string,\n TargetUserUid:string,\n TargetUserUpn:string,\n TargetWindowsUsername:string,\n ThreatCategory:string,\n ThreatConfidence:int,\n ThreatField:string,\n ThreatFirstReportedTime:datetime,\n ThreatId:string,\n ThreatIpAddr:string,\n ThreatIsActive:bool,\n ThreatLastReportedTime:datetime,\n ThreatName:string,\n ThreatOriginalConfidence:string,\n ThreatOriginalRiskLevel:string,\n ThreatRiskLevel:int,\n User:string\n)[];\nEmptyAuthenticationTable",
"version": 1
}
}
Expand Down
Original file line number Diff line number Diff line change
@@ -1,5 +1,9 @@
# Changelog for vimAuthenticationEmpty.yaml

## Version 0.3.0

- (2026-04-06) Change SrcPortNumber type from string to int to align with documentation - [PR #13851](https://github.com/Azure/Azure-Sentinel/pull/13851)

## Version 0.2.0

- (2026-03-17) Update empty parser alphabetically and align with columns from ASimTester.csv - [PR #13851](https://github.com/Azure/Azure-Sentinel/pull/13851)
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -115,7 +115,7 @@ ParserQuery: |
SrcIpAddr:string,
SrcIsp:string,
SrcOriginalRiskLevel:string,
SrcPortNumber:string,
SrcPortNumber:int,
SrcRiskLevel:int,
TargetAppId:string,
TargetAppName:string,
Expand Down
Loading