table

SecurityAlert

SecurityAlert stores alerts generated by Microsoft Sentinel analytics rules and alerts ingested from connected Microsoft security products.

tablesCurrent

Relationships

Schema

FieldTypeDescriptionCopy
TimeGenerateddatetimeTime the alert was generated in UTC.
SystemAlertIdstringInternal unique ID for the alert in Microsoft Sentinel.
AlertNamestringDisplay name of the alert.
AlertSeveritystringSeverity of the alert.
AlertTypestringType of alert.
StatusstringStatus of the alert lifecycle.
TacticsstringMITRE ATT&CK tactics associated with the alert.
TechniquesstringMITRE ATT&CK techniques associated with the alert.
VendorNamestringVendor of the product that produced the alert.
ProviderNamestringProvider that generated or supplied the alert.