You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/sentinel/ueba-reference.md
+26-4Lines changed: 26 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -299,9 +299,9 @@ If you're onboarding Microsoft Sentinel to the Defender portal, select the "Comp
299
299
300
300
The following fields have been renamed in the unified version. Therefore, if you're onboarding Microsoft Sentinel to the Defender portal, check your queries for any references to these fields, and update them if necessary.
301
301
302
-
| Log Analytics field name | Unified schema field name | Comments |
The following field names no longer exist in the unified version. Be sure to remove them from any queries that reference them.
321
+
322
+
-**GroupMembership**
323
+
-**TenantID**—this field does *not* contain the same information as the **TenantId** field that replaces the **AccountTenantId** field.
324
+
-**UserState**
325
+
-**UserStateChangedOn**
326
+
327
+
The following fields, while they exist in the Log Analytics schema, are not used by Microsoft Sentinel at all, and they no longer exist in the unified version:
0 commit comments