+ "transformKql": "source\n| extend \n entity_id_d = toint(entity.id),\n entity_name_s = tostring(entity.name),\n entity_image_s = tostring(entity.image),\n entity_labels_s = tostring(entity.labels),\n entity_entity_group_id_d = toint(entity.entity_group_id),\n entity_entity_group_name_s = tostring(entity.entity_group_name),\n entity_term_s = tostring(entity.term),\n entity_account_s = tostring(entity.account),\n entity_email_receiver_id_s = tostring(entity.email_receiver_id),\n perpetrator_name_s = tostring(perpetrator.name),\n perpetrator_display_name_s = tostring(perpetrator.display_name),\n perpetrator_id_d = toint(perpetrator.id),\n perpetrator_url_s = tostring(perpetrator.url),\n perpetrator_content_s = tostring(perpetrator.content),\n perpetrator_type_s = tostring(perpetrator.type),\n perpetrator_timestamp_t = todatetime(perpetrator.timestamp),\n perpetrator_network_s = tostring(perpetrator.network),\n asset_id_d = toint(asset.id),\n asset_name_s = tostring(asset.name),\n asset_image_s = tostring(asset.image),\n asset_labels_s = tostring(asset.labels),\n asset_entity_group_id_d = toint(asset.entity_group_id),\n asset_entity_group_name_s = tostring(asset.entity_group_name),\n id_d = toint(id),\n Severity = toint(severity),\n rule_group_id_d = toint(rule_group_id),\n reviewed_b = tobool(reviewed),\n escalated_b = tobool(escalated),\n rule_id_d = toint(rule_id),\n last_modified_t = last_modified\n | project-rename \n TimeGenerated = last_modified,\n alert_type_s = alert_type,\n logs_s = logs,\n offending_content_url_s = offending_content_url,\n asset_term_s = asset_term,\n assignee_s = assignee,\n content_created_at_t = content_created_at,\n entered_by_s = entered_by,\n metadata_s = metadata,\n status_s = status,\n rule_name_s = rule_name,\n protected_locations_s = protected_locations,\n darkweb_term_s = darkweb_term,\n business_network_s = business_network,\n network_s = network,\n protected_social_object_s = protected_social_object,\n notes_s = notes,\n reviews_s = reviews,\n tags_s = tags\n| project TimeGenerated, alert_type_s, logs_s, offending_content_url_s, asset_term_s, assignee_s, entity_id_d, entity_name_s, entity_image_s, entity_labels_s, entity_entity_group_id_d, entity_entity_group_name_s, entity_term_s, content_created_at_t, id_d, Severity, perpetrator_name_s, perpetrator_display_name_s, perpetrator_id_d, perpetrator_url_s, perpetrator_content_s, perpetrator_type_s, perpetrator_timestamp_t, perpetrator_network_s, rule_group_id_d, asset_id_d, asset_name_s, asset_image_s, asset_labels_s, asset_entity_group_id_d, asset_entity_group_name_s, entered_by_s, metadata_s, status_s, rule_name_s, last_modified_t, protected_locations_s, darkweb_term_s, business_network_s, reviewed_b, escalated_b, network_s, protected_social_object_s, notes_s, reviews_s, rule_id_d, entity_account_s, entity_email_receiver_id_s, tags_s",
0 commit comments