Skip to main content
Version: 1.5.0

CSL

The Common Security Log (CSL) is a standardized schema used in Microsoft Sentinel. It provides:

Common Fields:

Field CategoryFieldsDescription
Base FieldsTimeGenerated, Type, TenantId, SourceSystem, ComputerCore fields for event identification and source tracking
Identity FieldsAccountName, AccountDomain, UserPrincipalName, UserIdUser identification and authentication tracking
Network FieldsSourceIP, DestinationIP, SourcePort, DestinationPortNetwork communication endpoints
Security FieldsActivity, Status, ResultType, ResultDescriptionSecurity operation outcomes and status information

Schema Categories:

CategoryFieldsPurpose
AuthenticationLogonType, AuthenticationMethod, LogonProcessName, ImpersonationLevelTrack authentication events and access control
Network SessionProtocol, Direction, BytesSent, BytesReceived, DurationMonitor network communications and traffic patterns
ProcessProcessName, CommandLine, ProcessId, ParentProcessNameTrack process creation and execution
FileFileName, FilePath, FileHash, FileOperationMonitor file access and modifications
RegistryRegistryKey, RegistryValueName, RegistryValueDataTrack registry changes and access

Event Types:

TypeEvent ClassesDescription
AuthenticationSignInLogs, AuditLogs, AADNonInteractiveUserSignInLogsAuthentication-related events and outcomes
SecuritySecurityEvent, SecurityAlert, SecurityIncidentSecurity-related events and alerts
NetworkAzureNetworkAnalytics, CommonSecurityLog, DnsEventsNetwork activity and communications
IdentityIdentityInfo, IdentityDirectoryEvents, IdentityLogonEventsIdentity and directory service events
EndpointDeviceEvents, DeviceProcessEvents, DeviceFileEventsEndpoint detection and response events