ADSecurityAssessmentRecommendation

Recommendations generated by AD Security assessments that are started through a scheduled task. When you schedule the assessment it runs by default every 7 days and upload the data into Azure Log Analytics

Table attributes

Attribute Value
Resource types -
Categories Workloads
Solutions ADSecurityAssessment, AzureResources
Basic log No
Ingestion-time transformation Yes
Sample Queries -

Columns

Column Type Description
ActionArea string
ActionAreaId string
AffectedObjectName string
AffectedObjectType string
AssessmentId string
_BilledSize real The record size in bytes
Computer string
CustomData string
Description string
DNSServer string
DNSZone string
Domain string
DomainController string
FocusArea string
FocusAreaId string
Forest string
GroupPolicyObject string
_IsBillable string Specifies whether ingesting the data is billable. When _IsBillable is false ingestion isn't billed to your Azure account
NamingContext string
Recommendation string
RecommendationId string
RecommendationResult string
RecommendationWeight real
Site string
SourceSystem string The type of agent the event was collected by. For example, OpsManager for Windows agent, either direct connect or Operations Manager, Linux for all Linux agents, or Azure for Azure Diagnostics
Technology string
TimeGenerated datetime
Type string The name of the table