Key mappings worth memorising
The lookups people get wrong. Both tables are in the catalogue below with full detail and sample KQL.
A user’s job title, department or manager
IdentityInfo.JobTitle
Job title lives in IdentityInfo — the User and Entity
Behavior Analytics (UEBA) identity enrichment table — in the
JobTitle column, alongside Department,
Manager, City, EmployeeId,
AssignedRoles and GroupMembership.
It is not in SigninLogs, and it is not in
SecurityAlert; enrich by joining on
AccountObjectId (or AccountUPN).
IdentityInfo is append-only snapshot data: take the newest
row per identity with
summarize arg_max(TimeGenerated, *) by AccountObjectId.
Who changed an attribute, and from what to what
AuditLogs → TargetResources[].modifiedProperties
Directory changes are in AuditLogs, not in the
sign-in tables. Each record’s TargetResources array
carries a modifiedProperties array whose elements have
displayName, oldValue and
newValue — the before/after pair for a role
assignment, a JobTitle edit, a group membership change, an
app credential being added, and so on.
oldValue and newValue arrive JSON-encoded
(usually quoted strings), so strip the quotes or re-parse them:
trim('"', tostring(mp.newValue)).
Search and filter the catalogue
Matches table names, aliases, plain-language concepts and column names. Press / to jump to this box, Esc to clear it, Enter or Space on a card to open details.
Direct answer
Table catalogue
No tables match that
Nothing in the catalogue matches your search and category filter. This catalogue is a curated subset — a real workspace holds hundreds of tables, including custom *_CL tables that only exist in your tenant. Try a broader word, or clear the filters.
Investigation guides
Ordered paths through the catalogue for the investigations a SOC actually runs. Each step names the tables to query, says why that table matters at that point, states the question it answers, and gives a starter query you can copy. Pick an investigation, then work down. Every table name is a button that opens the full catalogue entry.
Table relationship map
How these tables connect, and on exactly which keys. Select a table to highlight every documented relationship it has; the panel beside the diagram lists the join keys, what the pivot is for, and the caveat that applies. Solid lines are reliable key joins; dashed lines are weaker correlations that need normalising, time-binning or a tolerance for misses. Keyboard: Tab to a table, Enter or Space to select, Esc to clear.
- Reliable key join
- Weak or approximate correlation
- Table (select to highlight)
The diagram scrolls sideways on narrow screens. It is a curated subset of the relationships that matter most, not an exhaustive schema graph.
What this diagram does not tell you
- A line means a join is possible and commonly useful, not that it is cheap or lossless. Read the caveat beside each key before building on it.
- Several relationships are name-based rather than key-based (hostname, UPN, URL). Those break on case, FQDN versus short name, aliasing and rewriting. Normalise both sides, every time.
- Append-only tables (IdentityInfo, DeviceInfo, SecurityIncident, SecurityAlert, ThreatIntelligenceIndicator, Watchlist) must be reduced with arg_max before joining, or you multiply rows and read stale values.
- Some pairs are alternative sources for the same fact rather than joins — ASIM versus the product table, Defender process events versus Windows 4688. Unioning those double-counts.
- Cardinality is not shown. One-to-many is the norm: one message to many recipients, one process to many connections, one device to many snapshots.
- Whether a relationship exists at all depends on which connectors and licences you have. Confirm with getschema before relying on a column.
Concepts and where they physically live
One idea, many column names. Each concept below lists every table.field location that holds it, what that particular field actually means, and the caveats that stop these fields being interchangeable. Start here when you know what you want but not what it is called.
No concept matches that
Nothing in the concept list matches your filter. Try a column name (AccountSid, RemoteIP), a plain word (manager, hash), or clear the filter to see all of them.
Join recipe library
The joins worth memorising, written out in full with the mistakes annotated. Each recipe gives the exact keys and why they are the right ones, how the join duplicates rows if you are careless, what makes it slow, a copyable query, and the caveats that bite in production.
Reference
Background that applies to everything else on this page: what ASIM is and when to prefer it, and the schema-variability, accuracy and privacy caveats you should read before trusting any field name here.
What ASIM is, and when to query it instead of a product table
ASIM is the Advanced Security Information
Model — Microsoft Sentinel’s normalisation layer. It
defines a vendor-neutral schema per activity type (authentication,
network session, DNS activity, process event, file event, web session,
registry event, audit event, user management) with standard column names
such as SrcIpAddr, DstPortNumber,
TargetUsername, EventResult,
DvcAction and EventProduct. It is Sentinel’s
implementation of the Open Source Security Events Metadata (OSSEM)
common model.
Two ways normalised data reaches you
-
Query-time parsers — KQL functions that read raw
product tables and emit the normalised schema on the fly. Call the
unifying parser (
_Im_NetworkSession,_Im_Authentication,_Im_Dns,_Im_ProcessCreate,_Im_WebSession…) and one query spans every supported source. Nothing is re-ingested, so there is no extra storage cost, but there is query-time CPU cost and you depend on the parsers being deployed in the workspace. -
Native ASIM tables — physical tables that already
hold normalised rows:
ASimAuthenticationEventLogs,ASimNetworkSessionLogs,ASimDnsActivityLogs,ASimProcessEventLogs,ASimFileEventLogs,ASimWebSessionLogs,ASimAuditEventLogs,ASimRegistryEventLogs,ASimUserManagementActivityLogs. Connectors and transformation DCRs write straight into them. Faster to query, and they still show up under the matching_Im_*parser.
Choosing
- Use ASIM for detections and hunts that must work across multiple vendors, for content you want to share between workspaces, and when you do not know in advance which firewall, proxy or EDR a customer runs.
-
Use the native product table when you need a field ASIM
does not model, when you need the vendor’s exact verdict strings,
or when performance on a single known source matters more than
portability. ASIM normalisation is deliberately lossy at the edges;
source-specific nuance lives in
AdditionalFieldsor in the original table. - Normalised and raw are not mutually exclusive. A common pattern is detect on ASIM, then pivot into the product table for the full record.
Caveats
- Parser coverage is uneven. A source may have a parser for network sessions but not for authentication.
-
There are parameterised parsers (filtering, e.g.
_Im_NetworkSession(srcipaddr_has_any_prefix=...)) and plain ones (_ASim_NetworkSession). The filtering form pushes predicates down and is much cheaper on large volumes. - Schema versions move. Column sets differ between ASIM schema versions, so confirm against the workspace before shipping a detection.
Schema variability, accuracy and privacy — read before trusting a field name
Schema variability
Every column list here is a curated highlight, not a contract. The real schema of a table in your workspace depends on:
- which connector version and ingestion path wrote the data (MMA vs Azure Monitor Agent, classic connector vs Codeless Connector Platform);
- whether the resource logs in Azure Diagnostics mode (everything lands in
AzureDiagnosticswith type-suffixed columns) or resource-specific mode (dedicated tables); - licensing and feature flags — UEBA tables such as
IdentityInfoandBehaviorAnalyticsonly exist once UEBA is enabled, and some Entra ID log categories need a P1/P2 licence; - ingestion-time transformations and DCR column additions in your own workspace;
- custom columns: CEF
DeviceCustomString1..6mean different things per appliance, and*_CLtables are entirely tenant-specific; - Microsoft deprecations and renames — tables and columns move (legacy
ThreatIntelligenceIndicatorto the newer STIX-aligned threat intel tables,AzureActivity’sOperationNametoOperationNameValue, the classic DNS solution to Windows DNS Events via AMA).
Always confirm before you build on a field. In the
workspace run TableName | getschema | project ColumnName, ColumnType,
or TableName | take 10 to see real values. Treat anything in
this catalogue that disagrees with getschema as wrong.
Accuracy
Descriptions, columns and KQL here are written from common SOC practice and are intended as orientation and a starting query, not as authoritative documentation. Sample KQL is deliberately simple: it has no tuning, no allow-lists and no time-window sizing for your data volume. Review and test every query before it becomes a scheduled analytics rule.
Privacy and data handling
The hosted edition is a multi-file static site with local HTML, CSS
and JavaScript assets. It makes no network
requests, loads no external fonts, scripts, styles or
images and sets no cookies. The Daily learning
tab stores learning progress in localStorage in this browser;
typed scratch answers are not stored. Search terms stay only in page
memory and disappear when you close the tab. There is no telemetry,
no analytics and no backend; it works with
the network cable unplugged, from a USB stick, or inside an air-gapped
analyst VM.
The only thing it touches outside itself is the system clipboard, and only when you press a Copy KQL button. Nothing is ever read from the clipboard.
Because it never calls out, the catalogue cannot contain customer data, hostnames or identities from your estate. Keep it that way: if you add your own notes, avoid pasting live incident data into the file.
Keyboard and pointer support
- / focuses the search box (unless you are already typing in a field).
- Esc clears the search box; inside the details dialog it closes the dialog.
- Tab / Shift+Tab moves between chips, cards and dialog controls; focus is trapped inside the open dialog and restored to the card you came from on close.
- Enter or Space activates a focused card or chip.
- Cards reveal their interesting fields on hover and on keyboard focus. On touch devices, where there is no hover, the fields are always visible.
- All controls are at least 36–44 px tall for touch, and motion is suppressed when the OS requests reduced motion.
