Microsoft Defender XDR
General

AlertEvidence

In brief

The documentation now lists alerts from Defender for Endpoint, Office 365, Cloud Apps, Identity, and onboarded Microsoft Sentinel sources. It also clarifies that data availability depends on deployed services and accessible Sentinel workspaces, and recommends joining AlertEvidence with AlertInfo by AlertId for alert metadata.

What Defender admins need to know

Review service deployments and workspace access when troubleshooting missing AlertEvidence results; no administrator action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

AlertEvidence

The AlertEvidence table in the advanced hunting schema contains information about various entities—files, IP addresses, URLs, users, or devices—entities associated with alerts from Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Microsoft Defender for Cloud Apps, and Microsoft Defender for Identity.Identity, and onboarded Microsoft Sentinel workspaces. Entities can include files, IP addresses, URLs, users, and devices. Use this reference to construct queries that return information from this table.

This advanced hunting table is populated by records from variousData availability depends on the Microsoft Defender services. If your organization hasn’tservices deployed and the serviceMicrosoft Sentinel workspaces you can access in Microsoftthe Defender XDR, queries that useportal. Join AlertEvidence with AlertInfo on the table aren’t goingAlertId column to work or return any results.retrieve alert metadata with its related entities and evidence. For more information about how to deploy services in Defender XDR, readinformation, see Deploy supported services and Transition your Microsoft Sentinel environment to the Defender portal.

For information on other tables in the advanced hunting schema, see the advanced hunting reference.