AlertEvidence
In brief
The documentation now lists alerts from Defender for Endpoint, Office 365, Cloud Apps, Identity, and onboarded Microsoft Sentinel sources. It also clarifies that data availability depends on deployed services and accessible Sentinel workspaces, and recommends joining AlertEvidence with AlertInfo by AlertId for alert metadata.
What Defender admins need to know
Review service deployments and workspace access when troubleshooting missing AlertEvidence results; no administrator action is required.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
AlertEvidence
The AlertEvidence table in the advanced hunting schema contains information about various entities—files, IP addresses, URLs, users, or devices—entities associated with alerts from Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Microsoft Defender for Cloud Apps, and Microsoft Defender for Identity.Identity, and onboarded Microsoft Sentinel workspaces. Entities can include files, IP addresses, URLs, users, and devices. Use this reference to construct queries that return information from this table.
This advanced hunting table is populated by records from variousData availability depends on the Microsoft Defender services. If your organization hasn’tservices deployed and the serviceMicrosoft Sentinel workspaces you can access in Microsoftthe Defender XDR, queries that useportal. Join AlertEvidence with AlertInfo on the table aren’t goingAlertId column to work or return any results.retrieve alert metadata with its related entities and evidence. For more information about how to deploy services in Defender XDR, readinformation, see Deploy supported services and Transition your Microsoft Sentinel environment to the Defender portal.
For information on other tables in the advanced hunting schema, see the advanced hunting reference.
@@ -12,11 +12,12 @@ ms.collection: ms.custom: - cx-ti - cx-ah+- msecd-doc-authoring-1015 appliesto: - Microsoft Defender XDR - Microsoft Sentinel in the Microsoft Defender portal ms.topic: reference-ms.date: 03/28/2025+ms.date: 08/07/2026 --- # AlertEvidence@@ -25,9 +26,9 @@ ms.date: 03/28/2025 -The `AlertEvidence` table in the [advanced hunting](advanced-hunting-overview.md) schema contains information about various entities—files, IP addresses, URLs, users, or devices—associated with alerts from Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Microsoft Defender for Cloud Apps, and Microsoft Defender for Identity. Use this reference to construct queries that return information from this table.+The `AlertEvidence` table in the [advanced hunting](advanced-hunting-overview.md) schema contains entities associated with alerts from Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Microsoft Defender for Cloud Apps, Microsoft Defender for Identity, and onboarded Microsoft Sentinel workspaces. Entities can include files, IP addresses, URLs, users, and devices. Use this reference to construct queries that return information from this table. -This advanced hunting table is populated by records from various Microsoft Defender services. If your organization hasn’t deployed the service in Microsoft Defender XDR, queries that use the table aren’t going to work or return any results. For more information about how to deploy services in Defender XDR, read [Deploy supported services](deploy-supported-services.md).+Data availability depends on the Microsoft Defender services deployed and the Microsoft Sentinel workspaces you can access in the Defender portal. Join `AlertEvidence` with [`AlertInfo`](advanced-hunting-alertinfo-table.md) on the `AlertId` column to retrieve alert metadata with its related entities and evidence. For more information, see [Deploy supported services](deploy-supported-services.md) and [Transition your Microsoft Sentinel environment to the Defender portal](/azure/sentinel/move-to-defender). For information on other tables in the advanced hunting schema, [see the advanced hunting reference](advanced-hunting-schema-tables.md). 