Skip to content

Commit d9fb370

Browse files
committed
Merge branch 'WI375793-populate-cloud-app-events' of https://github.com/DeCohen/defender-docs-pr into WI375793-populate-cloud-app-events
2 parents 966140e + dd19ae6 commit d9fb370

File tree

2 files changed

+11
-0
lines changed

2 files changed

+11
-0
lines changed

defender-xdr/advanced-hunting-cloudappevents-table.md

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -30,6 +30,17 @@ ms.date: 06/09/2024
3030

3131
The `CloudAppEvents` table in the [advanced hunting](advanced-hunting-overview.md) schema contains information about events involving accounts and objects in Office 365 and other [cloud apps and services](#apps-and-services-covered). Use this reference to construct queries that return information from this table.
3232

33+
## Prerequisites
34+
35+
Before events can populate, ensure:
36+
37+
1. Verify that the checkbox "Pull activities" is selected within the Microsoft 365 connector settings.
38+
39+
:::image type="content" source="media/microsoft365-activities.png" alt-text="Screenshot showing the Microsoft 365 components":::
40+
41+
1. Connect any relevant connector via the App Connector page to pull the activities data for that application. For more details, see: [Connect Microsoft 365 to Microsoft Defender for Cloud Apps](/defender-cloud-apps/protect-office-365#prerequisites)
42+
43+
3344

3445
For information on other tables in the advanced hunting schema, [see the advanced hunting reference](advanced-hunting-schema-tables.md).
3546

94.8 KB
Loading

0 commit comments

Comments
 (0)