Cloud Security Supported Fields

This document shows the fields supported by each provider and operation.

query_cloud_resource_inventory

FieldCrowdStrike Cloud SecurityMicrosoft Defender for CloudType
activity_idnumber
activity_namestring
category_namestring
category_uidnumber
class_uidnumber
cloud.account.namestring
cloud.account.typestring
cloud.account.type_idnumber
cloud.account.uidstring
cloud.providerstring
cloud.regionstring
device.first_seen_timetimestamp
device.first_seen_time_dtstring
device.last_seen_timetimestamp
device.last_seen_time_dtstring
device.modified_timetimestamp
device.modified_time_dtstring
device.namestring
device.regionstring
device.typestring
device.type_idnumber
device.uidstring
enrichments[].data.benchmark_versionsunknown
enrichments[].data.controlsunknown
enrichments[].data.controls[].benchmarks[].idstring
enrichments[].data.controls[].benchmarks[].namestring
enrichments[].data.controls[].benchmarks[].versionstring
enrichments[].data.controls[].frameworkstring
enrichments[].data.controls[].namestring
enrichments[].data.controls[].typestring
enrichments[].data.controls[].versionstring
enrichments[].data.ioa_countsnumber
enrichments[].data.iom_countsnumber
enrichments[].data.legacy_policy_ids[]number
enrichments[].data.rulesunknown
enrichments[].data.rules[]string
enrichments[].descstring
enrichments[].namestring
enrichments[].providerstring
enrichments[].typestring
enrichments[].valuestring
messagestring
metadata.product.feature.namestring
metadata.product.vendor_namestring
metadata.tenant_uidstring
metadata.uidstring
metadata.versionstring
resources[].group.namestring
resources[].group.uidstring
resources[].labels[]string
resources[].namestring
resources[].typestring
resources[].uidstring
severity_idnumber
timenumber
time_dtstring
type_uidnumber

query_compliance_findings

FieldCrowdStrike Cloud SecurityMicrosoft Defender for CloudType
activity_idnumber
activity_namestring
category_namestring
category_uidnumber
class_uidnumber
compliance.standardsunknown
compliance.statusstring
compliance.status_idnumber
countnumber
device.descstring
device.first_seen_timetimestamp
device.hostnamestring
device.hw_info.bios_manufacturerstring
device.hw_info.bios_verstring
device.hw_info.chassisstring
device.hw_info.serial_numberstring
device.instance_uidstring
device.ipstring
device.last_seen_timetimestamp
device.macstring
device.modified_timetimestamp
device.namestring
device.network_statusstring
device.network_status_idnumber
device.org.namestring
device.org.uidstring
device.os.buildstring
device.os.namestring
device.os.typestring
device.os.type_idnumber
device.os.versionstring
device.typestring
device.type_idnumber
device.uidstring
device.zonestring
finding_infounknown
messagestring
metadata.labels[]string
metadata.loggers[].namestring
metadata.loggers[].versionstring
metadata.product.namestring
metadata.product.vendor_namestring
metadata.product.versionstring
metadata.versionstring
resource.namestring
resource.typestring
resource.uidstring
severitystring
severity_idnumber
statusstring
status_idnumber
timenumber
type_namestring
type_uidnumber