Forum Discussion

pho30's avatar
pho30
Copper Contributor
Jul 26, 2022

MDE Action Value Mapping in M365 Defender

Is there a mapping of the Action Values (under Additional Fields) for the DeviceEvents table? I see either blank, 1, 2, or 3 but have no clue as to what that is referring to.

 

I can also see that within the same section, the field WasRemediated will either be True or False, where the Action values dont necessarily link to whether it is true or false for WasRemediated (Action Value = 2 and WasRemediated = False for one event, but then Action Value = 2 and WasRemediated = True for a different event).

 

Any insight into what these numbers are indicating would be helpful. Thanks!

Resources