You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
@@ -273,13 +272,12 @@ This article provides details on the Common schema as well as service-specific s
273
272
|361|DataScanClassification| Events from Purview On-Demand classification for SharePoint and OneDrive for business.|
274
273
|363|Microsoft365CopilotScheduledPrompt| Events from Microsoft 365 Copilot scheduled prompt.|
275
274
|364|PlacesDirectory| Events from Microsoft Places Directory.|
276
-
|365|SentinelNotebookOnLake |Events from notebook execution on Sentinel Data Lake.|
275
+
|365|SentinelNotebookOnLake |Events from notebook execution on Sentinel Data Lake.|
277
276
|366|SentinelJob | Events from operations on jobs in Sentinel Data Lake.|
278
277
|367|SentinelKQLOnLake | Events from running KQL on Sentinel Data Lake.|
279
-
|368|SentinelLakeOnboarding| Events from onboarding to Sentinel Data Lake.|
278
+
|368|SentinelLakeOnboarding| Events from onboarding to Sentinel Data Lake.|
280
279
|369|SentinelLakeDataOnboarding | Data loading events into Sentinel Data Lake.|
281
280
282
-
283
281
### Enum: User Type - Type: Edm.Int32
284
282
285
283
#### User Type
@@ -888,15 +886,14 @@ DLP (Data Loss Prevention) events will always have UserKey="DlpAgent" in the com
888
886
|:-----|:-----|:-----|:-----|
889
887
|SharePointMetaData|Self.[SharePointMetadata](#sharepointmetadata-complex-type)|No|Describes metadata about the document in SharePoint or OneDrive for Business that contained the sensitive information.|
890
888
|ExchangeMetaData|Self.[ExchangeMetadata](#exchangemetadata-complex-type)|No|Describes metadata about the email message that contained the sensitive information.|
891
-
|EndpointMetaData|Self.[EndpointMetadata](#endpointmetadata-complex-type)|No|Describes metadata about the document in endpoint that contained the sensitive information|
889
+
|EndpointMetaData|Self.[EndpointMetadata](#endpointmetadata-complex-type)|No|Describes metadata about the document in endpoint that contained the sensitive information|
892
890
|ExceptionInfo|Edm.String|No|Identifies reasons why a policy no longer applies and/or any information about false positive and/or override noted by the end user.|
893
891
|PolicyDetails|Collection(Self.[PolicyDetails](#policydetails-complex-type))|Yes|Information about 1 or more policies that triggered the DLP event.|
894
892
|SensitiveInfoDetectionIsIncluded|Boolean|Yes|Indicates whether the event contains the value of the sensitive data type and surrounding context from the source content. Accessing sensitive data requires the "Read DLP policy events including sensitive details" permission in Azure Active Directory.|
895
893
896
894
### eDiscovery schema
897
895
898
-
The eDiscovery audit schema is designed to capture and log activities related to eDiscovery processes within the organization.
899
-
896
+
The eDiscovery audit schema is designed to capture and log activities related to eDiscovery processes within the organization.
@@ -923,7 +920,6 @@ The eDiscovery audit schema is designed to capture and log activities related to
923
920
|JobId|Edm.String|No|The GUID of the eDiscovery process.|
924
921
|RecordNumber|Edm.String|No|Used when an audit record is divided into multiple parts due to size. It indicates the sequence of each part within the total splits.|
@@ -1258,7 +1254,7 @@ The Yammer events listed in [Search the audit log in the Security & Compliance C
1258
1254
|Phish Confidence Level |Edm.String|No|Indicates the confidence level associated with Phish verdict. It can be Normal or High.|
1259
1255
1260
1256
> [!NOTE]
1261
-
> We recommend that you use the new ThreatsAndDetectionTech field because it shows multiple verdicts and the updated detection technologies. This field also aligns with the values you would see within other experiences like Threat Explorer and Advanced Hunting.
1257
+
> We recommend that you use the new ThreatsAndDetectionTech field because it shows multiple verdicts and the updated detection technologies. This field also aligns with the values you would see within other experiences like Threat Explorer and Advanced Hunting.
1262
1258
1263
1259
### Detection technologies
1264
1260
@@ -1399,7 +1395,7 @@ The Yammer events listed in [Search the audit log in the Security & Compliance C
|FileData|Self.[FileData](#filedata)|Yes|Data about the file that triggered the event.|
1402
-
|SourceWorkload|Self.[SourceWorkload](#sourceworkload)|Yes|Workload or service where the file was found (for example, SharePoint Online, OneDrive for Business, or Microsoft Teams)
1398
+
|SourceWorkload|Self.[SourceWorkload](#sourceworkload)|Yes|Workload or service where the file was found (for example, SharePoint Online, OneDrive for Business, or Microsoft Teams)|
1403
1399
|DetectionMethod|Edm.String|Yes|The method or technology used by Microsoft Defender for Office 365 for the detection.|
1404
1400
|LastModifiedDate|Edm.Date|Yes|The date and time in Coordinated Universal Time (UTC) when the file was created or last modified.|
1405
1401
|LastModifiedBy|Edm.String|Yes|Identifier (for example, an email address) for the user who created or last modified the file.|
@@ -1563,7 +1559,7 @@ Currently, only automated investigation are logged. (Events for manually generat
|InvestigationName |Edm.String |Name of the investigation. |
1566
-
|InvestigationType |Edm.String |Type of the investigation. Can take one of the following values:<br/>- User-Reported Messages<br/>- Zapped Malware<br/>- Zapped Phish<br/>- Url Verdict Change<p>(Manual investigations are currently not available and are coming soon.) |
1562
+
|InvestigationType |Edm.String |Type of the investigation. Can take one of the following values:<br/>- User-Reported Messages<br/>- Zapped Malware<br/>- Zapped Phish<br/>- Url Verdict Change<br/>(Manual investigations are currently not available and are coming soon.) |
1567
1563
|LastUpdateTimeUtc |Edm.Date |UTC time of the last update for an investigation. |
1568
1564
|StartTimeUtc |Edm.Date |Start time for an investigation. |
1569
1565
|Status |Edm.String |State of investigation, Running, Pending Actions, etc. |
@@ -2149,7 +2145,7 @@ The following table contain information related to AIP heartbeat events.
2149
2145
| TemplateId | TemplateID parameter to get a specific template. The Get-AipServiceTemplate cmdlet gets all existing or selected protection templates from Azure Information Protection. |
2150
2146
| UserId | The UPN of the user who performed the action (specified in the Operation property) that resulted in the record being logged; for example, my_name@my_domain_name. Note that records for activity performed by system accounts (such as SHAREPOINT\system or NT AUTHORITY\SYSTEM) are also included. In SharePoint, another value display in the UserId property is app@sharepoint. This indicates that the "user" who performed the activity was an application that has the necessary permissions in SharePoint to perform organization-wide actions (such as search a SharePoint site or OneDrive account) on behalf of a user, admin, or service. For more information, see the app@sharepoint user in audit records. |
2151
2147
|UserType | The type of user that performed the operation. See the UserType table for details on the types of users.</br>0 = Regular</br>1 = Reserved</br>2 = Admin </br>3 = DcAdmin</br>4 = Systeml</br>5 = Application</br>6 = ServicePrincipal</br>7 = CustomPolicy</br>8 = SystemPolicy|
2152
-
|UserKey | An alternative ID for the user identified in the UserId property. This property is populated with the passport unique ID (PUID) for events performed by users in SharePoint, OneDrive for Business, and Exchange.|
2148
+
|UserKey | An alternative ID for the user identified in the UserId property. This property is populated with the passport unique ID (PUID) for events performed by users in SharePoint, OneDrive for Business, and Exchange.|
2153
2149
2154
2150
### MicrosoftGraphDataConnectConsent complex type
2155
2151
@@ -2434,11 +2430,11 @@ Values taken by SettingsChange properties in Details for different operations ar
2434
2430
|All Operations |OriginalValue | Original value for new setting.|
2435
2431
2436
2432
> [!NOTE]
2433
+
>
2437
2434
> 1. For role changes the name will be the role type.
2438
-
2. The audit record will reflect the change in event, such as user is assigned a role or revoked role.
2439
-
3. The original and new value will have the emails of the user for which the role has changed.
2440
-
4. In case there is no change in the role, that role type will not be present in the audit record.
2441
-
2435
+
> 2. The audit record will reflect the change in event, such as user is assigned a role or revoked role.
2436
+
> 3. The original and new value will have the emails of the user for which the role has changed.
2437
+
> 4. In case there is no change in the role, that role type will not be present in the audit record.
2442
2438
2443
2439
## Backup Policy schema
2444
2440
@@ -2694,7 +2690,7 @@ The audit records for events related to Microsoft Edge WebContentFiltering use t
2694
2690
|DomainURL|Edm.String|Yes|The domain URL that was browsed.|
2695
2691
|Category|Edm.String|Yes|Category of browsed URL.|
2696
2692
2697
-
## Microsoft 365 Copilot scheduled prompt schema
2693
+
## Microsoft 365 Copilot scheduled prompt schema
2698
2694
2699
2695
Copilot scheduled prompts allow users to automate Copilot prompts, so they run on a defined schedule in Microsoft 365 Copilot Chat. The audit records for events related to Copilot scheduled prompts use this schema (in addition to the [Common schema](#common-schema)). For details on how you can search for the audit logs from the compliance portal, see [Audit log activities](/microsoft-365/compliance/audit-log-activities).
2700
2696
@@ -2715,13 +2711,12 @@ The audit records for events related to Places Directory operations use this sch
2715
2711
|Parameters|Collection(Common.NameValuePair)|No|The name and value for all parameters that were used with the cmdlet that is identified in the Operations property.|
2716
2712
|ModifiedProperties|Collection(Common.ModifiedProperty)|No|The property includes the name of the property that was modified, the new value of the modified property, and the previous value of the modified object.|
2717
2713
2718
-
2719
2714
## Microsoft Sentinel data lake schema
2720
2715
2721
2716
The audit records for events related to Microsoft Sentinel data lake operations use this schema (in addition to the [Common schema](#common-schema)). For details on how you can search for the audit logs from the compliance portal, see [Audit log activities](/microsoft-365/compliance/audit-log-activities).
0 commit comments