SecurityAlert
SecurityAlert stores alerts generated by Microsoft Sentinel analytics rules and alerts ingested from connected Microsoft security products.
tablesCurrent
Relationships
Schema
| Field | Type | Description | Copy |
|---|---|---|---|
TimeGenerated | datetime | Time the alert was generated in UTC. | |
SystemAlertId | string | Internal unique ID for the alert in Microsoft Sentinel. | |
AlertName | string | Display name of the alert. | |
AlertSeverity | string | Severity of the alert. | |
AlertType | string | Type of alert. | |
Status | string | Status of the alert lifecycle. | |
Tactics | string | MITRE ATT&CK tactics associated with the alert. | |
Techniques | string | MITRE ATT&CK techniques associated with the alert. | |
VendorName | string | Vendor of the product that produced the alert. | |
ProviderName | string | Provider that generated or supplied the alert. |