table

DeviceEvents

DeviceEvents contains multiple event types reported by devices, including security control and endpoint activity events that are not represented in more specific advanced hunting tables.

tablesCurrent

Relationships

Schema

FieldTypeDescriptionCopy
TimestampdatetimeDate and time when the event was recorded.
DeviceIdstringUnique identifier for the device in the service.
DeviceNamestringFully qualified domain name of the device.
ActionTypestringType of activity that triggered the event.
AdditionalFieldsdynamicAdditional event information represented as a property bag.
RemoteIPstringRemote IP address associated with the event, when available.