Skip to content

Commit c68ae83

Browse files
committed
Learn Editor: Update traffic-analytics-schema.md
1 parent 67cec5a commit c68ae83

File tree

1 file changed

+0
-2
lines changed

1 file changed

+0
-2
lines changed

articles/network-watcher/traffic-analytics-schema.md

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -195,8 +195,6 @@ List of threat types:
195195
| PUA | Potentially Unwanted Application. |
196196
| WatchList | A generic bucket into which indicators are placed when it can't be determined exactly what the threat is or will require manual interpretation. `WatchList` should typically not be used by partners submitting data into the system. |
197197

198-
199-
200198
## Notes
201199

202200
- In case of `AzurePublic` and `ExternalPublic` flows, customer owned Azure virtual machine IP is populated in `VMIP_s` field, while the Public IP addresses are populated in the `PublicIPs_s` field. For these two flow types, you should use `VMIP_s` and `PublicIPs_s` instead of `SrcIP_s` and `DestIP_s` fields. For AzurePublic and ExternalPublic IP addresses, we aggregate further, so that the number of records ingested to log analytics workspace is minimal. (This field will be deprecated soon and you should be using SrcIP_ and DestIP_s depending on whether the virtual machine was the source or the destination in the flow).

0 commit comments

Comments
 (0)