azure log analytics FileHash

%3CLINGO-SUB%20id%3D%22lingo-sub-1457273%22%20slang%3D%22en-US%22%3Eazure%20log%20analytics%20FileHash%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1457273%22%20slang%3D%22en-US%22%3E%3CP%3EFileHash%20in%20Azure%20log%20analytics%20just%20has%20sha256%2C%20is%20there%20a%20way%20to%20get%20Sha1%20and%20or%20md5%3F%20Is%20this%20something%20configurable%20and%20how%2Fwhere%20do%20we%20set%20that%3F%20Thanks%3C%2FP%3E%3CP%3Eex.%26nbsp%3B%3C%2FP%3E%3CDIV%3E%3CDIV%3E%3CSPAN%3ESecurityEvent%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%7C%20%3C%2FSPAN%3E%3CSPAN%3Ewhere%3C%2FSPAN%3E%3CSPAN%3E%20FileHash%3C%2FSPAN%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1457273%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20Log%20Analytics%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1461613%22%20slang%3D%22en-US%22%3ERe%3A%20azure%20log%20analytics%20FileHash%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1461613%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F696839%22%20target%3D%22_blank%22%3E%40johnadamsp%3C%2FA%3E%2C%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThe%20FileHash%20value%20is%20coming%20from%20the%20Security%20Event%20on%20that%20machine.%20Log%20Analytics%20doesn't%20calculate%20file%20hashes.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIt%20is%20usually%20coming%20from%20here%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fprevious-versions%2Fwindows%2Fit-pro%2Fwindows-server-2012-R2-and-2012%2Fee844150(v%3Dws.11)%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fprevious-versions%2Fwindows%2Fit-pro%2Fwindows-server-2012-R2-and-2012%2Fee844150(v%3Dws.11)%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThanks%2C%3C%2FP%3E%0A%3CP%3EMeir%20%3A%26gt%3B%3C%2Fimg%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Visitor

FileHash in Azure log analytics just has sha256, is there a way to get Sha1 and or md5? Is this something configurable and how/where do we set that? Thanks

ex. 

SecurityEvent
| where FileHash
1 Reply

@johnadamsp,

 

The FileHash value is coming from the Security Event on that machine. Log Analytics doesn't calculate file hashes.

 

It is usually coming from here: https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/ee...

 

Thanks,

Meir :>