DeviceNetworkInfoDeviceNetworkInfo

重要

改良的 Microsoft 365 安全性中心現在可用。The improved Microsoft 365 security center is now available. 這個新的體驗會將適用於端點的 Defender、適用於 Office 365 的 Defender、Microsoft 365 Defender 和更多功能帶到 Microsoft 365 安全性中心。This new experience brings Defender for Endpoint, Defender for Office 365, Microsoft 365 Defender, and more into the Microsoft 365 security center. 了解新功能Learn what's new.

適用於:Applies to:

  • Microsoft 365 DefenderMicrosoft 365 Defender
  • 適用於端點的 Microsoft DefenderMicrosoft Defender for Endpoint

[!附注] DeviceNetworkInfo 高級搜尋 架構中的表格包含電腦網路設定的相關資訊,包括網路介面卡、IP 及 MAC 位址,以及連線的網路或網域。The DeviceNetworkInfo table in the advanced hunting schema contains information about networking configuration of machines, including network adapters, IP and MAC addresses, and connected networks or domains. 使用這個參考來建立從此表格取回之資訊的查詢。Use this reference to construct queries that return information from this table.

如需進階搜捕結構描述中其他表格的資訊,請參閱進階搜捕參考 (部分內容為機器翻譯)。For information on other tables in the advanced hunting schema, see the advanced hunting reference.

欄名稱Column name 資料類型Data type 描述Description
Timestamp datetimedatetime 事件記錄的日期和時間Date and time when the event was recorded
DeviceId stringstring 服務中電腦的唯一識別碼Unique identifier for the machine in the service
DeviceName stringstring 電腦的完整網域名稱 (FQDN)Fully qualified domain name (FQDN) of the machine
NetworkAdapterName stringstring 網路介面卡的名稱Name of the network adapter
MacAddress stringstring 網路介面卡的 MAC 位址MAC address of the network adapter
NetworkAdapterType stringstring 網路介面卡類型。Network adapter type. 如需可能的值,請參閱 this 列舉For the possible values, refer to this enumeration
NetworkAdapterStatus stringstring 網路介面卡的運作狀態。Operational status of the network adapter. 如需可能的值,請參閱 this 列舉For the possible values, refer to this enumeration
TunnelType stringstring 隧道通訊協定,如果此介面是用於此用途,例如6to4、Teredo、ISATAP、PPTP、SSTP 和 SSHTunneling protocol, if the interface is used for this purpose, for example 6to4, Teredo, ISATAP, PPTP, SSTP, and SSH
ConnectedNetworks stringstring 連接到配接器的網路。Networks that the adapter is connected to. 每個 JSON 陣列都包含網路名稱、類別 (public、private 或 domain) 、描述及表明其是否已公開連接到網際網路的標誌。Each JSON array contains the network name, category (public, private or domain), a description, and a flag indicating if it's connected publicly to the internet
DnsAddresses stringstring JSON 陣列格式的 DNS 伺服器位址DNS server addresses in JSON array format
IPv4Dhcp stringstring DHCP 伺服器的 IPv4 位址IPv4 address of DHCP server
IPv6Dhcp stringstring DHCP 伺服器的 IPv6 位址IPv6 address of DHCP server
DefaultGateways stringstring 以 JSON 陣列格式的預設閘道位址Default gateway addresses in JSON array format
IPAddresses stringstring 包含所有指派給該配接器之 IP 位址的 JSON 陣列,以及其各自的子網前置詞和 IP 位址空間,例如 public、private 或 link 本機。JSON array containing all the IP addresses assigned to the adapter, along with their respective subnet prefix and IP address space, such as public, private, or link-local
ReportId longlong 以重複計數器為基礎的事件識別碼。Event identifier based on a repeating counter. 若要識別唯一的事件,此資料行必須與 DeviceName 及 Timestamp 資料行一起使用To identify unique events, this column must be used in conjunction with the DeviceName and Timestamp columns