Views:
Field Name
Type
General Field
Description
Example
Products
actionName
  • string
-
The user or service action
  • Create User
  • Add member to group
  • Update application
  • Microsoft Entra ID
clientApp
  • string
-
The app that the client accessed
  • browser
  • Mobile Apps and Desktop clients
  • Microsoft Entra ID
clientBrowser
  • string
-
The client browser
  • Chrome 119.0.0
  • Microsoft Entra ID
clientDisplayName
  • string
  • EndpointName
The client display name
  • DESKTOP-TKOS222
  • Microsoft Entra ID
clientId
  • string
-
The unique client device ID
  • 11111111-1111-1111-1111-111111111111
  • Microsoft Entra ID
clientOS
  • string
-
The client OS
  • Windows
  • Microsoft Entra ID
correlationId
  • string
-
The correlation id
  • 11111111-1111-1111-1111-111111111111
  • Microsoft Entra ID
eventAdditionalDetails
  • object_EventAdditionalDetail[]
-
The raw data string that contains additional information
  • [{"key": "<example>","value": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7)"}]
  • Microsoft Entra ID
eventCategory
  • string
-
The resource category targeted by the event
  • UserManagement
  • ApplicationManagement
  • Microsoft Entra ID
eventId
  • string
-
The identity provider event ID
  • 1 - EVENT_SOURCE_AAD_SIGN_INS
  • 2 - EVENT_SOURCE_AAD_DIR_AUDIT
  • Microsoft Entra ID
eventName
  • string
-
The identity provider event name
  • 4624
  • aad_signin
  • Microsoft Entra ID
eventTime
  • int64
-
The time the identity provider detected the event
  • 1657781088000
  • Microsoft Entra ID
filterRiskLevel
  • string
-
The top-level risk level of the event
  • info
  • low
  • medium
  • Security Analytics Engine
groupId
  • string
-
The group ID for the management scope filter
  • 11111111-1111-1111-1111-111111111111
  • Security Analytics Engine
idpId
  • string
-
The internal product code of the identity provider
  • aad
  • opa
  • Microsoft Entra ID
idpName
  • string
-
The identity provider
  • Microsoft Entra ID
  • Microsoft Active Directory
  • google
  • Microsoft Entra ID
initiatedByAppDisplayName
  • string
-
The application display name
  • Microsoft Intune
  • Microsoft Entra ID
initiatedByAppId
  • string
-
The resource category targeted by the event
  • 11111111-1111-1111-1111-111111111111
  • Microsoft Entra ID
initiatedByServicePrincipalId
  • string
-
The unique ID of the service principal
  • 11111111-1111-1111-1111-111111111111
  • Microsoft Entra ID
initiatedByServicePrincipalName
  • string
-
The unique ID of the service principal
  • Microsoft Intune
  • Microsoft Entra ID
initiatedByUserDisplayName
  • string
  • UserAccount
The user display name
  • Sample User
  • Microsoft Entra ID
initiatedByUserHomeTenantId
  • string
-
The tenant ID of the user
  • Microsoft Entra ID
initiatedByUserHomeTenantName
  • string
-
The tenant ID of the user
  • Microsoft Entra ID
initiatedByUserId
  • string
  • UserAccount
The unique ID of the user who initiated the event
  • Microsoft Entra ID
initiatedByUserIpAddress
  • string
  • IPv4
  • IPv6
The client IP of the user
  • 10.10.10.10
  • Microsoft Entra ID
initiatedByUserPrincipalName
  • string
  • UserAccount
The User Principal Name of the user
  • sample_email@trendmicro.com
  • Microsoft Entra ID
ipAddress
  • string
  • IPv4
  • IPv6
The client IP
  • 10.10.10.10
  • Microsoft Entra ID
locationCity
  • string
-
The city where the event happened
  • Singapore
  • Microsoft Entra ID
locationCountry
  • string
-
The country where the event happened
  • US
  • TW
  • Microsoft Entra ID
locationLatitude
  • string
-
The latitude of the event location
  • 121.568
  • Microsoft Entra ID
locationLongitude
  • string
-
The longitude of the event location
  • 121.568
  • Microsoft Entra ID
locationState
  • string
-
The state where the event happened
  • Central Singapore
  • Microsoft Entra ID
logBatchId
  • string
-
The batch data retrieval process ID
  • 11111111-1111-1111-1111-111111111111
  • Microsoft Entra ID
logReceivedTime
  • int64
-
The time when the XDR log was received
  • 1656324260000
  • Security Analytics Engine
loggedByService
  • string
-
The service that initiated the event
  • Core Directory
  • Microsoft Entra ID
operationType
  • string
-
The operation performed in the event
  • Add
  • Assign
  • Update
  • Microsoft Entra ID
orgId
  • string
-
The organization ID
  • 11111111-1111-1111-1111-111111111111
  • Microsoft Entra ID
pname
  • string
-
The internal product ID
  • 2200
  • 751
  • 533
  • Microsoft Entra ID
policyTreePath
  • string
-
The policy tree path (endpoint only)
  • policyname1/policyname2/policyname3
  • Security Analytics Engine
principalName
  • string
  • UserAccount
The User Principal Name
  • sample_email@trendmicro.com
  • Microsoft Entra ID
productCode
  • string
-
The internal product code of the identity provider (aad=Microsoft Entra ID, opa=Microsoft Active Directory)
  • aad
  • opa
  • Security Analytics Engine
  • Microsoft Entra ID
requestMethod
  • string
-
The sign-in authentication method
  • [{"authenticationStepDateTime": "2023-11-28T03:44:05Z","authenticationMethod": "Previously satisfied","authenticationMethodDetail": null,"succeeded" : true,"authenticationStepResultDetail": "MFA requirement satisfied by claim in the Token","authenticationStepRequirement": ""}]
  • Microsoft Entra ID
result
  • string
-
The event result
  • success
  • failure
  • timeout
  • Microsoft Entra ID
resultReason
  • string
-
The cause of event failure or timeout
  • success
  • failure
  • timeout
  • Microsoft Entra ID
status
  • string
-
The sign-in status result
  • 0
  • 50126
  • 50155
  • Microsoft Entra ID
statusDetail
  • string
-
The additional information about sign-in status
  • MFA requirement satisfied by claim in the token
  • Microsoft Entra ID
statusReason
  • string
-
The sign-in status
  • Error validating credentials due to invalid username or password.
  • Others.
  • Microsoft Entra ID
tags
  • string[]
  • Technique
  • Tactic
The attack technique ID detected by Trend Vision One based on the alert filter
  • MITREV9.T1057
  • MITREV9.T1059.003
  • XSAE.F2924
  • Security Analytics Engine
targetResourceDisplayName
  • string
-
The target resource display name
  • Microsoft Graph
  • Microsoft Entra ID
targetResourceId
  • string
-
The target resource ID
  • 11111111-1111-1111-1111-111111111111
  • Microsoft Entra ID
targetResources
  • object_TargetResource[]
-
The targeted resource of the event
  • Microsoft Entra ID
tenantId
  • string
-
The Microsoft Entra ID Tenant ID of the organization
  • 11111111-1111-1111-1111-111111111111
  • Microsoft Entra ID
userAgent
  • string
-
The user agent
  • Microsoft.OData.Client/7.12.5
  • Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36
  • Microsoft Entra ID
userDisplayName
  • string
  • UserAccount
The user display name
  • Test User(RD-TW)
  • Microsoft Entra ID
userId
  • string
  • UserAccount
The user ID
  • 11111111-1111-1111-1111-111111111111
  • Microsoft Entra ID
uuid
  • string
-
The unique key of the log entry
  • 11111111-1111-1111-1111-111111111111
  • Security Analytics Engine