Microsoft Sentinel
Cloud and workloads

Ueba Reference

In brief

The UEBA reference now lists AWS GuardDuty (Preview) and CommonSecurityLog (Preview), with links to their data connectors, tables, and event details.

What Defender admins need to know

Administrators can use the updated reference to identify these data sources and review their documented event requirements.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

| AAD service principal sign-in logs (Preview)| Microsoft Entra ID | AADServicePrincipalSignInLogs | All service principal sign-in events | | Audit Logs | Microsoft Entra ID | AuditLogs | ApplicationManagement
DirectoryManagement
GroupManagement
Device
RoleManagement
UserManagementCategory | | AWS CloudTrail (Preview)| Amazon Web Services
Amazon Web Services S3 | AWSCloudTrail | Console sign-in events.
Identified by EventName = "ConsoleLogin" and EventSource = "signin.amazonaws.com". Events must have a valid UserIdentityPrincipalId. | | AWS GuardDuty (Preview) | Amazon Web Services S3 | AWSGuardDuty | AWS GuardDuty findings associated with AWS identities. Events must have valid ActivityType, AccountId, and ResourceDetails fields, including an accessKeyDetails.principalId. | | Azure Activity | Azure Activity | AzureActivity | Authorization
AzureActiveDirectory
Billing
Compute
Consumption
KeyVault
Devices
Network
Resources
Intune
Logic
Sql
Storage | | Device Logon Events (Preview)| Microsoft Defender XDR | DeviceLogonEvents | All device logon events | | GCP Audit Logs (Preview)| GCP Pub/Sub Audit Logs | GCPAuditLogs | apigee.googleapis.com - API Management Platform
iam.googleapis.com - Identity and Access Management (IAM) service
iamcredentials.googleapis.com - IAM Service Account Credentials API
cloudresourcemanager.googleapis.com - Cloud Resource Manager API
compute.googleapis.com - Compute Engine API
storage.googleapis.com - Cloud Storage API
container.googleapis.com - Kubernetes Engine API
k8s.io - Kubernetes API
cloudsql.googleapis.com - Cloud SQL API
bigquery.googleapis.com - BigQuery API
bigquerydatatransfer.googleapis.com - BigQuery Data Transfer Service API
cloudfunctions.googleapis.com - Cloud Functions API
appengine.googleapis.com - App Engine API
dns.googleapis.com - Cloud DNS API
bigquerydatapolicy.googleapis.com - BigQuery Data Policy API
firestore.googleapis.com - Firestore API
dataproc.googleapis.com - Dataproc API
osconfig.googleapis.com - OS Config API
cloudkms.googleapis.com - Cloud KMS API
secretmanager.googleapis.com - Secret Manager API
Events must have a valid:
- PrincipalEmail - The user or service account that called the API
- MethodName - The specific Google API method called
- Principal email, in [email protected] format. | | Okta CL (Preview)| Okta Single Sign-On (using Azure Functions)| Okta_CL, OktaV2_CL | Authentication, multifactor authentication (MFA), and session events, including:
app.oauth2.admin.consent.grant_success
app.oauth2.authorize.code_success
device.desktop_mfa.recovery_pin.generate
user.authentication.auth_via_mfa
user.mfa.attempt_bypass
user.mfa.factor.deactivate
user.mfa.factor.reset_all
user.mfa.factor.suspend
user.mfa.okta_verify
user.session.impersonation.grant
user.session.impersonation.initiate
user.session.start
Events must have a valid User ID (actor_id_s). | | Security Events | Windows Security Events via AMA
Windows Forwarded Events | WindowsEvent
SecurityEvent | 4624: An account was successfully logged on
4625: An account failed to log on
4648: A logon was attempted using explicit credentials
4672: Special privileges assigned to new logon
4688: A new process has been created | | Sign-in Logs | Microsoft Entra ID | SigninLogs | All sign-in events | | CommonSecurityLog (Preview) | Common Event Format (CEF) | CommonSecurityLog | Firewall, VPN, and web proxy events from the following vendors and products:

Check Point (DeviceVendor is Check Point)
- VPN-1 & FireWall-1 - VPN login events
- URL Filtering - web access events
- IPS, Anti-Bot, and Anti-Virus prevention events of medium severity or higher

Fortinet (DeviceVendor is Fortinet)
- FortiGate - VPN authentication events
- FortiGate - web filtering events
- FortiGate - administrative firewall policy changes

Zscaler (DeviceVendor is Zscaler)
- NSSWeblog - web proxy events
- Zscaler Private Access - VPN authentication events
- Zscaler portal - administrative actions (SIGN_IN, SIGN_OUT, CREATE, UPDATE, DELETE)

Events must have a valid SourceUserName value for user-based detections, or a valid Computer value for device-based detections. |

UEBA enrichments