table

DeviceNetworkEvents

DeviceNetworkEvents contains network connections and related endpoint network activity reported by Microsoft Defender for Endpoint.

tablesCurrent

Relationships

Schema

FieldTypeDescriptionCopy
TimestampdatetimeDate and time when the event was recorded.
DeviceIdstringUnique identifier for the device in the service.
DeviceNamestringFully qualified domain name of the device.
ActionTypestringType of network activity that triggered the event.
RemoteIPstringIP address that the device connected to.
RemotePortintTCP port on the remote device that was connected to.
RemoteUrlstringURL or fully qualified domain name that was connected to.
LocalIPstringSource IP address used during communication.
ProtocolstringProtocol used during the communication.
InitiatingProcessAccountSidstringSecurity identifier of the account that ran the process responsible for the network event.