table

DeviceLogonEvents

DeviceLogonEvents contains sign-in and authentication events on devices reported by Microsoft Defender for Endpoint.

tablesCurrent

Relationships

Schema

FieldTypeDescriptionCopy
TimestampdatetimeDate and time when the event was recorded.
DeviceIdstringUnique identifier for the device in the service.
DeviceNamestringFully qualified domain name of the device.
ActionTypestringType of logon activity that triggered the event.
LogonTypestringType of logon session.
AccountNamestringUser name of the account that attempted or completed logon.
AccountDomainstringDomain of the account that attempted or completed logon.
AccountSidstringSecurity identifier of the account that attempted or completed logon.
RemoteIPstringRemote IP address associated with the logon event, when available.
FailureReasonstringInformation explaining why the recorded logon action failed.