Azure-Sentinel/Tools/externaldata/event.yaml

5 строки
500 B
YAML

externaldata(TenantId:string, SourceSystem:string, TimeGenerated:datetime, Source:string, EventLog:string, Computer:string, EventLevel:int, EventLevelName:string, ParameterXml:string, EventData:string, EventID:int, RenderedDescription:string, AzureDeploymentID:string, Role:string, EventCategory:int, UserName:string, Message:string, MG:string, ManagementGroupName:string, Type:string, _ResourceId:string)
[
h@"https://STORAGEACCOUNTNAME.blob.core.windows.net/am-event/SASSIG"
]
with(format="json")