Skip to content

Commit bcf0a35

Browse files
Merge pull request #236532 from yelevin/docs-editor/ueba-reference-1683015829
Update ueba-reference.md
2 parents 686d366 + cfd27fe commit bcf0a35

File tree

1 file changed

+3
-3
lines changed

1 file changed

+3
-3
lines changed

articles/sentinel/ueba-reference.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,7 @@ These are the data sources from which the UEBA engine collects and analyzes data
2121
| **Azure Active Directory**<br>Sign-in logs | All |
2222
| **Azure Active Directory**<br>Audit logs | ApplicationManagement<br>DirectoryManagement<br>GroupManagement<br>Device<br>RoleManagement<br>UserManagementCategory |
2323
| **Azure Activity logs** | Authorization<br>AzureActiveDirectory<br>Billing<br>Compute<br>Consumption<br>KeyVault<br>Devices<br>Network<br>Resources<br>Intune<br>Logic<br>Sql<br>Storage |
24-
| **Windows Security events** | 4624: An account was successfully logged on<br>4625: An account failed to log on<br>4648: A logon was attempted using explicit credentials<br>4672: Special privileges assigned to new logon<br>4688: A new process has been created |
24+
| **Windows Security events**<br>*WindowsEvent* or<br>*SecurityEvent* | 4624: An account was successfully logged on<br>4625: An account failed to log on<br>4648: A logon was attempted using explicit credentials<br>4672: Special privileges assigned to new logon<br>4688: A new process has been created |
2525

2626
## UEBA enrichments
2727

@@ -75,8 +75,6 @@ The following table describes the behavior analytics data displayed on each [ent
7575
> - The first, in **bold**, is the "friendly name" of the enrichment.
7676
> - The second *(in italics and parentheses)* is the field name of the enrichment as stored in the [**Behavior Analytics table**](#behavioranalytics-table).
7777
78-
79-
8078
#### UsersInsights field
8179

8280
The following table describes the enrichments featured in the **UsersInsights** dynamic field in the BehaviorAnalytics table:
@@ -271,3 +269,5 @@ This document described the Microsoft Sentinel entity behavior analytics table s
271269
- Learn more about [entity behavior analytics](identify-threats-with-entity-behavior-analytics.md).
272270
- [Enable UEBA in Microsoft Sentinel](enable-entity-behavior-analytics.md).
273271
- [Put UEBA to use](investigate-with-ueba.md) in your investigations.
272+
273+

0 commit comments

Comments
 (0)