DeviceEvents
DeviceEvents contains multiple event types reported by devices, including security control and endpoint activity events that are not represented in more specific advanced hunting tables.
tablesCurrent
Relationships
Microsoft Defender for Endpoint
Source productproductMicrosoft Defender for Endpoint P2
Required licenselicenseMicrosoft Graph Security API
API accessapiMicrosoft Defender for Endpoint APIs
API accessapiLegacy Microsoft Defender XDR APIs
API accessapiDeviceProcessEvents
Related tabletableDeviceFileEvents
Related tabletableDeviceNetworkEvents
Related tabletableDeviceRegistryEvents
Related tabletableDeviceLogonEvents
Related tabletableDeviceInfo
Related tabletable
Source productproductMicrosoft Defender for Endpoint P2
Required licenselicenseMicrosoft Graph Security API
API accessapiMicrosoft Defender for Endpoint APIs
API accessapiLegacy Microsoft Defender XDR APIs
API accessapiDeviceProcessEvents
Related tabletableDeviceFileEvents
Related tabletableDeviceNetworkEvents
Related tabletableDeviceRegistryEvents
Related tabletableDeviceLogonEvents
Related tabletableDeviceInfo
Related tabletable
Schema
| Field | Type | Description | Copy |
|---|---|---|---|
Timestamp | datetime | Date and time when the event was recorded. | |
DeviceId | string | Unique identifier for the device in the service. | |
DeviceName | string | Fully qualified domain name of the device. | |
ActionType | string | Type of activity that triggered the event. | |
AdditionalFields | dynamic | Additional event information represented as a property bag. | |
RemoteIP | string | Remote IP address associated with the event, when available. |