Edit

ZTSMetadata

Node metadata and control messages for Zero Trust Segmentation.

Table attributes

Attribute Value
Resource types microsoft.zerotrustsegmentation/segmentationmanagers
Categories Azure Resources, Security
Solutions LogManagement
Basic log No
Ingestion-time DCR support No
Lake-only ingestion Yes
Sample Queries -

Columns

Column Type Description
AdditionalInfo dynamic NSP and Firewall additional info.
_BilledSize real The record size in bytes
Identifier string VM's MAC address.
IP string IP address of the VM.
_IsBillable string Specifies whether ingesting the data is billable. When _IsBillable is false ingestion isn't billed to your Azure account
Location string Location of the VM.
MessageType string Used for control messages like label updates and run control info.
NodeType string Type of the node.
ParentResourceId string Container resourceId (VMSS).
_ResourceId string A unique identifier for the resource that the record is associated with
ResourceTags dynamic VM tags.
RunVersion string Run version identifier.
Segments dynamic Labels/tags for segmentation.
SourceSystem string The type of agent the event was collected by. For example, OpsManager for Windows agent, either direct connect or Operations Manager, Linux for all Linux agents, or Azure for Azure Diagnostics
_SubscriptionId string A unique identifier for the subscription that the record is associated with
TenantId string The Log Analytics workspace ID
TimeGenerated datetime DateTime rounded by the hour.
Type string The name of the table
VNetResourceId string VNet resource identifier.
WorkloadResourceId string VM resource identifier.