entra.tenantId | CHARBUF | Entra Tenant ID |
entra.time | CHARBUF | Entra event time |
entra.geo.city | CHARBUF | Entra geo city |
entra.geo.country_or_region | CHARBUF | Entra geo country or region |
entra.geo.lat | CHARBUF | Entra geo latitude |
entra.geo.lon | CHARBUF | Entra geo longitude |
entra.geo.state | CHARBUF | Entra geo state |
entra.operation | CHARBUF | Entra operation |
entra.operationType | CHARBUF | Entra operation type |
entra.srcip | CHARBUF | Entra source IP |
entra.resourceId | CHARBUF | Entra resource ID |
entra.correlationId | CHARBUF | Entra correlation ID |
entra.logCategory | CHARBUF | Entra log category |
entra.eventCategory | CHARBUF | Entra event category |
entra.userAgent | CHARBUF | Entra user agent |
entra.appId | CHARBUF | Entra app ID |
entra.user | CHARBUF | Entra user |
entra.userDisplayName | CHARBUF | Entra user display name |
entra.userRoles | CHARBUF | Entra user roles |
entra.app | CHARBUF | Entra app |
entra.service | CHARBUF | Entra service |
entra.result | CHARBUF | Entra result |
entra.resultReason | CHARBUF | Entra result reason |
entra.errorCode | CHARBUF | Entra error code |
entra.severity | CHARBUF | Entra severity |
entra.clientApp | CHARBUF | Entra client app |
entra.device.deviceId | CHARBUF | Entra device ID |
entra.device.displayName | CHARBUF | Entra device display name |
entra.device.browser | CHARBUF | Entra device browser |
entra.device.operatingSystem | CHARBUF | Entra device operating system |
entra.condAccess | CHARBUF | Entra conditional access |
entra.isInteractive | CHARBUF | Entra is interactive |
entra.idProvider | CHARBUF | Entra ID provider |
entra.idProviderType | CHARBUF | Entra ID provider type |
entra.authProcDetails | CHARBUF | Entra authentication processing details |
entra.networkDetails | CHARBUF | Entra network details |
entra.risk | CHARBUF | Entra risk |
entra.aggrRisk | CHARBUF | Entra aggregated risk |
entra.signinRisk | CHARBUF | Entra sign-in risk |
entra.riskEvents | CHARBUF | Entra risk events |
entra.signinResource | CHARBUF | Entra sign-in resource |
entra.homeTenantId | CHARBUF | Entra home tenant ID |
entra.authDetails | CHARBUF | Entra authentication details |
entra.authReqPolicies | CHARBUF | Entra authentication requirement policies |
entra.sessionPolicies | CHARBUF | Entra session policies |
entra.authReq | CHARBUF | Entra authentication requirement |
entra.servicePrincipalId | CHARBUF | Entra service principal ID |
entra.userType | CHARBUF | Entra user type |
entra.flaggedFailure | CHARBUF | Entra flagged failure |
entra.asn | CHARBUF | Entra autonomous system number |
entra.crossTenantType | CHARBUF | Entra cross tenant type |
entra.authStrengths | CHARBUF | Entra authentication strengths |
entra.tokenType | CHARBUF | Entra token type |
entra.authProtocol | CHARBUF | Entra authentication protocol |
entra.appServicePrincipalId | CHARBUF | Entra app service principal ID |
entra.resServicePrincipalId | CHARBUF | Entra resource service principal ID |
entra.tokenProtection | CHARBUF | Entra token protection |
entra.transferMethod | CHARBUF | Entra transfer method |
entra.targetResourceOfType.displayName | CHARBUF | Entra target resource display name filtered by type |
entra.targetResourceOfType.userPrincipalName | CHARBUF | Entra target resource user principal name filtered by type |
entra.targetResourceOfType.id | CHARBUF | Entra target resource ID filtered by type |
entra.targetResourceOfType.propertyWithDisplayName.oldValue | CHARBUF | Entra target resource property old value filtered by type and property display name |
entra.targetResourceOfType.propertyWithDisplayName.newValue | CHARBUF | Entra target resource property new value filtered by type and property display name |
entra.targetResourceOfType.propertyWithDisplayName.displayName | CHARBUF | Entra target resource property display name filtered by type and property display name |
entra.targetUsers | LIST(CHARBUF) | Entra target users |
entra.targetNames | LIST(CHARBUF) | Entra target names |
entra.targetTypes | LIST(CHARBUF) | Entra target types |
entra.targetIds | LIST(CHARBUF) | Entra target IDs |
entra.condAccessPolicies | LIST(CHARBUF) | Entra conditional access policies |
entra.additionalDetail | CHARBUF | Extracts from additionalDetail json a value in input. Syntax is entra.additionalDetail[], where is a json pointer (see https://datatracker.ietf.org/doc/html/rfc6901) |
entra.targetResources.propertyOldValue | CHARBUF | Extracts from properties.targetResources[arg1].modifiedProperties[arg2].oldValue[] |
entra.targetResources.propertyNewValue | CHARBUF | Extracts from properties.targetResources[arg1].modifiedProperties[arg2].newValue[] |