Windows-itpro-docs: MDATP Advanced Hunting table name changes

Created on 3 Jan 2020  Â·  5Comments  Â·  Source: MicrosoftDocs/windows-itpro-docs

Advanced Hunting table names have changed to:

  • DeviceAlertEvents
  • DeviceInfo
  • DeviceNetworkInfo
  • DeviceProcessEvents
  • DeviceNetworkEvents
  • DeviceFileEvents
    *DeviceRegistryEvents
  • DeviceLogonEvents
  • DeviceImageLoadEvents
  • DeviceEvents
  • DeviceTvmSoftwareInventoryVulnerabilities
  • DeviceTvmSoftwareVulnerabilitiesKB
  • DeviceTvmSecureConfigurationAssessment
  • DeviceTvmSecureConfigurationAssessmentKB

Ref: https://techcommunity.microsoft.com/t5/microsoft-defender-atp/advanced-hunting-data-schema-changes/ba-p/1043914


Document Details

⚠ Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

All 5 comments

@lomayor

Looks like one was missed in the update AlertEvents should be DeviceAlertEvents.

@lomayor
Here are a few other small changes needed related to this:

Hello, As someone who consumes the advanced_queries api resource these recent changes without any sort of versioning or even documented change log has caused a significant disruption. Is there any plan in the future to provide a warning before breaking changes such as these are made to the api?

Thanks everyone for chiming in.

@benkawecki-expel, old names will continue to work for several months to give folks the chance to fully transition. I do need to check how we are monitoring use of old names and whether we need to provided additional guidance for when we fully retire them.

@iadgovuser1, appreciate the feedback as always. All issues you've listed have been fixed.

Closing this case, but feel free to open a new one anytime.

Was this page helpful?
0 / 5 - 0 ratings

Related issues

ATR-Master picture ATR-Master  Â·  3Comments

iadgovuser1 picture iadgovuser1  Â·  3Comments

sundhaug92 picture sundhaug92  Â·  3Comments

ang216 picture ang216  Â·  3Comments

SwiftOnSecurity picture SwiftOnSecurity  Â·  3Comments