Forum Discussion

sirkillnotalot's avatar
sirkillnotalot
Copper Contributor
Aug 17, 2021

DataSources and missing docs?

Hi all,

 

I'm probably being dense but I cannot find where these data types are being created, or any documentation on them:

I’m also trying to determine what the ActionType of AntiVirusReport is under the DeviceEvents table:

 

https://docs.microsoft.com/en-us/microsoft-365/security/defender/advanced-hunting-deviceevents-table?view=o365-worldwide says to check the security.microsoft.com documentation but the AntivirusReport actiontype doesn’t appear in the documen:

Any ideas?

    • sirkillnotalot's avatar
      sirkillnotalot
      Copper Contributor

      Thanks Gary, that article really helped.

      As for the data - yeah it's the MDE connector streaming the data but understanding the actual values is where I'm falling down. None of the documentation actually explains what this particular value actually means. I suspect that it's a detection based off of a scheduled scan but would rather not rely on my assumptions.

      I've reached out to the product team to get a steer but not particularly hopefuly.

      • GaryBushey's avatar
        GaryBushey
        Bronze Contributor
        Have you looked at the tables in Defender. Maybe it has better documentation. Or try posting something similar to this post in the Defender group. Someone there may be able to provide better information.

Share