All Rules in Microsoft.AdvancedThreatAnalytics.1_7 Management Pack

 DisplayNameDescriptionIDTargetCategoryEnabledInstance NameCounter NameFrequencyEvent_IDEvent SourceAlert GenerateAlert SeverityAlert PriorityRemotableEvent Log
Microsoft.AdvancedThreatAnalytics.1_7.Center.AbnormalBehaviorSuspiciousActivity异常行为可疑活动Microsoft.AdvancedThreatAnalytics.1_7.Center.AbnormalBehaviorSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_7.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.AbnormalSmbSuspiciousActivity异常 SMB 可疑活动Microsoft.AdvancedThreatAnalytics.1_7.Center.AbnormalSmbSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_7.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.AccountEnumerationSuspiciousActivity帐户枚举可疑活动Microsoft.AdvancedThreatAnalytics.1_7.Center.AccountEnumerationSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_7.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.BruteForceSuspiciousActivity暴力破解可疑活动Microsoft.AdvancedThreatAnalytics.1_7.Center.BruteForceSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_7.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.CenterDatabaseDataDriveFreeSpaceMonitoringAlert中心数据库数据驱动器可用空间监视警报Microsoft.AdvancedThreatAnalytics.1_7.Center.CenterDatabaseDataDriveFreeSpaceMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_7.CenterAvailabilityHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.CenterOverloadedMonitoringAlert中心重载监视警报Microsoft.AdvancedThreatAnalytics.1_7.Center.CenterOverloadedMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_7.CenterPerformanceHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.CertificateExpiryMonitoringAlert证书到期监视警报Microsoft.AdvancedThreatAnalytics.1_7.Center.CertificateExpiryMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_7.CenterConfigurationHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.ComputerPreauthenticationFailedSuspiciousActivity计算机预身份验证失败可疑活动Microsoft.AdvancedThreatAnalytics.1_7.Center.ComputerPreauthenticationFailedSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_7.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.DatabaseAtSvcBlockSize数据库 AtSVC 块大小排队等待写入数据库的特定类型的网络活动数量Microsoft.AdvancedThreatAnalytics.1_7.Center.DatabaseAtSvcBlockSizeMicrosoft.AdvancedThreatAnalytics.1_7.CenterPerformanceCollectionTrueMicrosoft ATA CenterDatabase AtSVC Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Center.DatabaseDirectoryServicesActivityBlockSize数据库 DirectoryServicesActivity 块大小排队等待写入数据库的特定类型的网络活动数量Microsoft.AdvancedThreatAnalytics.1_7.Center.DatabaseDirectoryServicesActivityBlockSizeMicrosoft.AdvancedThreatAnalytics.1_7.CenterPerformanceCollectionTrueMicrosoft ATA CenterDatabase DirectoryServicesActivity Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Center.DatabaseDisconnectedMonitoringAlert数据库断开监视警报Microsoft.AdvancedThreatAnalytics.1_7.Center.DatabaseDisconnectedMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_7.CenterAvailabilityHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.DatabaseDnsBlockSize数据库 DNS 块大小排队等待写入数据库的特定类型的网络活动数量Microsoft.AdvancedThreatAnalytics.1_7.Center.DatabaseDnsBlockSizeMicrosoft.AdvancedThreatAnalytics.1_7.CenterPerformanceCollectionTrueMicrosoft ATA CenterDatabase DNS Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Center.DatabaseDrsrBlockSize数据库 DRSR 块大小排队等待写入数据库的特定类型的网络活动数量Microsoft.AdvancedThreatAnalytics.1_7.Center.DatabaseDrsrBlockSizeMicrosoft.AdvancedThreatAnalytics.1_7.CenterPerformanceCollectionTrueMicrosoft ATA CenterDatabase DRSR Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Center.DatabaseKerberosApBlockSize数据库 KerberosAP 块大小排队等待写入数据库的特定类型的网络活动数量Microsoft.AdvancedThreatAnalytics.1_7.Center.DatabaseKerberosApBlockSizeMicrosoft.AdvancedThreatAnalytics.1_7.CenterPerformanceCollectionTrueMicrosoft ATA CenterDatabase KerberosAP Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Center.DatabaseKerberosAsBlockSize数据库 KerberosAP 块大小排队等待写入数据库的特定类型的网络活动数量Microsoft.AdvancedThreatAnalytics.1_7.Center.DatabaseKerberosAsBlockSizeMicrosoft.AdvancedThreatAnalytics.1_7.CenterPerformanceCollectionTrueMicrosoft ATA CenterDatabase KerberosAS Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Center.DatabaseKerberosTgsBlockSize数据库 KerberosTGS 块大小排队等待写入数据库的特定类型的网络活动数量Microsoft.AdvancedThreatAnalytics.1_7.Center.DatabaseKerberosTgsBlockSizeMicrosoft.AdvancedThreatAnalytics.1_7.CenterPerformanceCollectionTrueMicrosoft ATA CenterDatabase KerberosTGS Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Center.DatabaseLdapBlockSize数据库 LDAP 块大小排队等待写入数据库的特定类型的网络活动数量Microsoft.AdvancedThreatAnalytics.1_7.Center.DatabaseLdapBlockSizeMicrosoft.AdvancedThreatAnalytics.1_7.CenterPerformanceCollectionTrueMicrosoft ATA CenterDatabase LDAP Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Center.DatabaseLsaRpcBlockSize数据库 LsaRPC 块大小排队等待写入数据库的特定类型的网络活动数量Microsoft.AdvancedThreatAnalytics.1_7.Center.DatabaseLsaRpcBlockSizeMicrosoft.AdvancedThreatAnalytics.1_7.CenterPerformanceCollectionTrueMicrosoft ATA CenterDatabase LsaRPC Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Center.DatabaseNetlogonBlockSize数据库 Netlogon 块大小排队等待写入数据库的特定类型的网络活动数量Microsoft.AdvancedThreatAnalytics.1_7.Center.DatabaseNetlogonBlockSizeMicrosoft.AdvancedThreatAnalytics.1_7.CenterPerformanceCollectionTrueMicrosoft ATA CenterDatabase Netlogon Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Center.DatabaseNtlmBlockSize数据库 NTLM 块大小排队等待写入数据库的特定类型的网络活动数量Microsoft.AdvancedThreatAnalytics.1_7.Center.DatabaseNtlmBlockSizeMicrosoft.AdvancedThreatAnalytics.1_7.CenterPerformanceCollectionTrueMicrosoft ATA CenterDatabase NTLM Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Center.DatabaseNtlmEventBlockSize数据库 NTLMEvent 块大小排队等待写入数据库的特定类型的网络活动数量Microsoft.AdvancedThreatAnalytics.1_7.Center.DatabaseNtlmEventBlockSizeMicrosoft.AdvancedThreatAnalytics.1_7.CenterPerformanceCollectionTrueMicrosoft ATA CenterDatabase NTLMEvent Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Center.DatabaseServiceControlBlockSize数据库 ServiceControl 块大小排队等待写入数据库的特定类型的网络活动数量Microsoft.AdvancedThreatAnalytics.1_7.Center.DatabaseServiceControlBlockSizeMicrosoft.AdvancedThreatAnalytics.1_7.CenterPerformanceCollectionTrueMicrosoft ATA CenterDatabase ServiceControl Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Center.DatabaseSmbBlockSize数据库 SMB 块大小排队等待写入数据库的特定类型的网络活动数量Microsoft.AdvancedThreatAnalytics.1_7.Center.DatabaseSmbBlockSizeMicrosoft.AdvancedThreatAnalytics.1_7.CenterPerformanceCollectionTrueMicrosoft ATA CenterDatabase SMB Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Center.DatabaseSrvSvcBlockSize数据库 SrvSVC 块大小排队等待写入数据库的特定类型的网络活动数量Microsoft.AdvancedThreatAnalytics.1_7.Center.DatabaseSrvSvcBlockSizeMicrosoft.AdvancedThreatAnalytics.1_7.CenterPerformanceCollectionTrueMicrosoft ATA CenterDatabase SrvSVC Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Center.DatabaseTaskSchedulerBlockSize数据库 TaskScheduler 块大小排队等待写入数据库的特定类型的网络活动数量Microsoft.AdvancedThreatAnalytics.1_7.Center.DatabaseTaskSchedulerBlockSizeMicrosoft.AdvancedThreatAnalytics.1_7.CenterPerformanceCollectionTrueMicrosoft ATA CenterDatabase TaskScheduler Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Center.DirectoryServicesClientAccountPasswordExpiryMonitoringAlert目录服务客户端帐户密码过期监视警报Microsoft.AdvancedThreatAnalytics.1_7.Center.DirectoryServicesClientAccountPasswordExpiryMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_7.CenterConfigurationHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.DirectoryServicesReplicationSuspiciousActivity目录服务复制可疑活动Microsoft.AdvancedThreatAnalytics.1_7.Center.DirectoryServicesReplicationSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_7.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.DnsReconnaissanceSuspiciousActivityDNS 侦测可疑活动Microsoft.AdvancedThreatAnalytics.1_7.Center.DnsReconnaissanceSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_7.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.DomainSynchronizerNotAssignedMonitoringAlert域同步器未分配监视警报Microsoft.AdvancedThreatAnalytics.1_7.Center.DomainSynchronizerNotAssignedMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_7.CenterConfigurationHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.EncryptionDowngradeSuspiciousActivity加密降级可疑活动Microsoft.AdvancedThreatAnalytics.1_7.Center.EncryptionDowngradeSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_7.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.EncryptionDowngradeSuspiciousActivity_GoldenTicket加密降级可疑活动(黄金票证)Microsoft.AdvancedThreatAnalytics.1_7.Center.EncryptionDowngradeSuspiciousActivity_GoldenTicketMicrosoft.AdvancedThreatAnalytics.1_7.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.EncryptionDowngradeSuspiciousActivity_OverpasstheHash加密降级可疑活动(超哈希传递攻击)Microsoft.AdvancedThreatAnalytics.1_7.Center.EncryptionDowngradeSuspiciousActivity_OverpasstheHashMicrosoft.AdvancedThreatAnalytics.1_7.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.EncryptionDowngradeSuspiciousActivity_SkeletonKey加密降级可疑活动(万能钥匙)Microsoft.AdvancedThreatAnalytics.1_7.Center.EncryptionDowngradeSuspiciousActivity_SkeletonKeyMicrosoft.AdvancedThreatAnalytics.1_7.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.EntityProfilerNetworkActivityBlockSizeEntityProfiler 网络活动块大小排队等待分析的网络活动(NA)数量Microsoft.AdvancedThreatAnalytics.1_7.Center.EntityProfilerNetworkActivityBlockSizeMicrosoft.AdvancedThreatAnalytics.1_7.CenterPerformanceCollectionTrueMicrosoft ATA CenterEntityProfiler Network Activity Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Center.EntityReceiverEntityBatchBlockSizeEntityReceiver 实体批块大小由 ATA 中心排队的实体批数Microsoft.AdvancedThreatAnalytics.1_7.Center.EntityReceiverEntityBatchBlockSizeMicrosoft.AdvancedThreatAnalytics.1_7.CenterPerformanceCollectionTrueMicrosoft ATA CenterEntityReceiver Entity Batch Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Center.EnumerateSessionsSuspiciousActivity枚举会话可疑活动Microsoft.AdvancedThreatAnalytics.1_7.Center.EnumerateSessionsSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_7.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.ForgedPacSuspiciousActivity伪造 PAC 可疑活动Microsoft.AdvancedThreatAnalytics.1_7.Center.ForgedPacSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_7.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.GatewayCaptureNetworkAdapterFaultedMonitoringAlert网关捕捉网络适配器出错监视警报Microsoft.AdvancedThreatAnalytics.1_7.Center.GatewayCaptureNetworkAdapterFaultedMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_7.CenterAvailabilityHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.GatewayCaptureNetworkAdapterMissingMonitoringAlert网关捕捉网络适配器缺少监视警报Microsoft.AdvancedThreatAnalytics.1_7.Center.GatewayCaptureNetworkAdapterMissingMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_7.CenterConfigurationHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.GatewayDirectoryServicesClientConnectivityMonitoringAlert网关目录服务客户端连接性监视警报Microsoft.AdvancedThreatAnalytics.1_7.Center.GatewayDirectoryServicesClientConnectivityMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_7.CenterAvailabilityHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.GatewayDisconnectedMonitoringAlert网关断开监视警报Microsoft.AdvancedThreatAnalytics.1_7.Center.GatewayDisconnectedMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_7.CenterAvailabilityHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.GatewayLowMemoryMonitoringAlert网关内存不足监视警报Microsoft.AdvancedThreatAnalytics.1_7.Center.GatewayLowMemoryMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_7.CenterPerformanceHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.GatewayNotReceivingTrafficMonitoringAlert网关未收到流量监视警报Microsoft.AdvancedThreatAnalytics.1_7.Center.GatewayNotReceivingTrafficMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_7.CenterAvailabilityHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.GatewayOverloadedEventActivitiesMonitoringAlert网关重载事件活动监视警报Microsoft.AdvancedThreatAnalytics.1_7.Center.GatewayOverloadedEventActivitiesMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_7.CenterPerformanceHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.GatewayOverloadedNetworkActivitiesMonitoringAlert网关重载网络活动监视警报Microsoft.AdvancedThreatAnalytics.1_7.Center.GatewayOverloadedNetworkActivitiesMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_7.CenterPerformanceHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.GatewaysOutdatedMonitoringAlert网关过时监视警报Microsoft.AdvancedThreatAnalytics.1_7.Center.GatewaysOutdatedMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_7.CenterConfigurationHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.GatewayStartFailureMonitoringAlert网关启动失败监视警报Microsoft.AdvancedThreatAnalytics.1_7.Center.GatewayStartFailureMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_7.CenterAvailabilityHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.HoneytokenActivitySuspiciousActivity蜜标活动可疑活动Microsoft.AdvancedThreatAnalytics.1_7.Center.HoneytokenActivitySuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_7.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.LdapSimpleBindCleartextPasswordSuspiciousActivityLDAP 简单绑定明文密码可疑活动Microsoft.AdvancedThreatAnalytics.1_7.Center.LdapSimpleBindCleartextPasswordSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_7.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.MailMonitoringAlert邮件监视警报Microsoft.AdvancedThreatAnalytics.1_7.Center.MailMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_7.CenterConfigurationHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.MassiveObjectDeletionSuspiciousActivity大规模对象删除可疑活动Microsoft.AdvancedThreatAnalytics.1_7.Center.MassiveObjectDeletionSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_7.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.NetworkActivityProcessorNetworkActivityBlockSizeNetworkActivityProcessor 网络活动块大小排队等待处理的网络活动(NA)数量Microsoft.AdvancedThreatAnalytics.1_7.Center.NetworkActivityProcessorNetworkActivityBlockSizeMicrosoft.AdvancedThreatAnalytics.1_7.CenterPerformanceCollectionTrueMicrosoft ATA CenterNetworkActivityProcessor Network Activity Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Center.PassTheHashSuspiciousActivity哈希传递攻击可疑活动Microsoft.AdvancedThreatAnalytics.1_7.Center.PassTheHashSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_7.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.PassTheTicketSuspiciousActivity票证传递攻击可疑活动Microsoft.AdvancedThreatAnalytics.1_7.Center.PassTheTicketSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_7.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.RemoteExecutionSuspiciousActivity远程执行可疑活动Microsoft.AdvancedThreatAnalytics.1_7.Center.RemoteExecutionSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_7.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.RetrieveDataProtectionBackupKeySuspiciousActivity检索数据保护备份密钥可疑活动Microsoft.AdvancedThreatAnalytics.1_7.Center.RetrieveDataProtectionBackupKeySuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_7.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.SamrReconnaissanceSuspiciousActivitySAMR 侦测可疑活动Microsoft.AdvancedThreatAnalytics.1_7.Center.SamrReconnaissanceSuspiciousActivityMicrosoft.AdvancedThreatAnalytics.1_7.CenterSecurityHealthFalse00TrueErrorNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Center.SyslogMonitoringAlertSyslog 监视警报Microsoft.AdvancedThreatAnalytics.1_7.Center.SyslogMonitoringAlertMicrosoft.AdvancedThreatAnalytics.1_7.CenterConfigurationHealthTrue00TrueWarningNormalTrueMicrosoft ATA
Microsoft.AdvancedThreatAnalytics.1_7.Gateway.ActiveDirectoryAuthenticationFailureATA 网关未能针对域控制器进行身份验证监视 Microsoft ATA 1.7 网关的规则 - ATA 网关未能针对域控制器进行身份验证Microsoft.AdvancedThreatAnalytics.1_7.Gateway.ActiveDirectoryAuthenticationFailureMicrosoft.AdvancedThreatAnalytics.1_7.GatewayAvailabilityHealthTrue00TrueErrorNormalTrue
Microsoft.AdvancedThreatAnalytics.1_7.Gateway.CountersDisabled注册表中可能禁用计数器监视 Microsoft ATA 1.7 网关的规则 - 注册表中可能禁用计数器Microsoft.AdvancedThreatAnalytics.1_7.Gateway.CountersDisabledMicrosoft.AdvancedThreatAnalytics.1_7.GatewayAvailabilityHealthTrue00TrueErrorNormalTrue
Microsoft.AdvancedThreatAnalytics.1_7.Gateway.EntityResolverActivityBlockSizeEntityResolver 活动块大小排队等待解决方案的网络活动(NA)的数量Microsoft.AdvancedThreatAnalytics.1_7.Gateway.EntityResolverActivityBlockSizeMicrosoft.AdvancedThreatAnalytics.1_7.GatewayPerformanceCollectionTrueMicrosoft ATA GatewayEntityResolver Activity Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Gateway.EntitySenderEntityBatchBlockSizeEntitySender 实体批块大小排队等待被发送至 ATA 中心的网络活动(NA)的数量Microsoft.AdvancedThreatAnalytics.1_7.Gateway.EntitySenderEntityBatchBlockSizeMicrosoft.AdvancedThreatAnalytics.1_7.GatewayPerformanceCollectionTrueMicrosoft ATA GatewayEntitySender Entity Batch Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Gateway.EntitySenderEntityBatchSendTimeEntitySender 实体批处理发送时间发送上一批所用的时间Microsoft.AdvancedThreatAnalytics.1_7.Gateway.EntitySenderEntityBatchSendTimeMicrosoft.AdvancedThreatAnalytics.1_7.GatewayPerformanceCollectionTrueMicrosoft ATA GatewayEntitySender Entity Batch Send Time3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Gateway.FailedToAuthenticateAgainstCenterATA 网关未能针对中心进行身份验证监视 Microsoft ATA 1.7 网关的规则 - ATA 网关未能针对中心进行身份验证Microsoft.AdvancedThreatAnalytics.1_7.Gateway.FailedToAuthenticateAgainstCenterMicrosoft.AdvancedThreatAnalytics.1_7.GatewayAvailabilityHealthTrue00TrueErrorNormalTrue
Microsoft.AdvancedThreatAnalytics.1_7.Gateway.FailedToEstablishConnectionToCenterATA 网关未能建立与 ATA 中心的连接监视 Microsoft ATA 1.7 网关的规则 - ATA 网关未能建立与 ATA 中心的连接Microsoft.AdvancedThreatAnalytics.1_7.Gateway.FailedToEstablishConnectionToCenterMicrosoft.AdvancedThreatAnalytics.1_7.GatewayAvailabilityHealthTrue00TrueErrorNormalTrue
Microsoft.AdvancedThreatAnalytics.1_7.Gateway.FailedToParseSyslogATA 网关未能分析 SIEM Syslog 消息监视 Microsoft ATA 1.7 网关的规则 - ATA 网关未能分析 SIEM Syslog 消息Microsoft.AdvancedThreatAnalytics.1_7.Gateway.FailedToParseSyslogMicrosoft.AdvancedThreatAnalytics.1_7.GatewayAvailabilityHealthTrue00TrueErrorNormalTrue
Microsoft.AdvancedThreatAnalytics.1_7.Gateway.FailedToQueryDCUsingLDAPProtocolATA 网关未能使用 LDAP 协议查询域控制器监视 Microsoft ATA 1.7 网关的规则 - ATA 网关未能使用 LDAP 协议查询域控制器Microsoft.AdvancedThreatAnalytics.1_7.Gateway.FailedToQueryDCUsingLDAPProtocolMicrosoft.AdvancedThreatAnalytics.1_7.GatewayAvailabilityHealthTrue00TrueErrorNormalTrue
Microsoft.AdvancedThreatAnalytics.1_7.Gateway.FailedToSynchronizeConfigurationFromCenterATA 网关未能从 ATA 中心同步配置监视 Microsoft ATA 1.7 网关的规则 - ATA 网关未能从 ATA 中心同步配置Microsoft.AdvancedThreatAnalytics.1_7.Gateway.FailedToSynchronizeConfigurationFromCenterMicrosoft.AdvancedThreatAnalytics.1_7.GatewayAvailabilityHealthTrue00TrueErrorNormalTrue
Microsoft.AdvancedThreatAnalytics.1_7.Gateway.FailedToValidateCenterCertificateChainATA 网关未能验证中心证书链监视 Microsoft ATA 1.7 网关的规则 - ATA 网关未能验证中心证书链Microsoft.AdvancedThreatAnalytics.1_7.Gateway.FailedToValidateCenterCertificateChainMicrosoft.AdvancedThreatAnalytics.1_7.GatewayAvailabilityHealthTrue00TrueErrorNormalTrue
Microsoft.AdvancedThreatAnalytics.1_7.Gateway.GatewayDoesNotHaveEnoughMemoryATA 网关内存不足监视 Microsoft ATA 1.7 网关的规则 - ATA 网关内存不足Microsoft.AdvancedThreatAnalytics.1_7.Gateway.GatewayDoesNotHaveEnoughMemoryMicrosoft.AdvancedThreatAnalytics.1_7.GatewayAvailabilityHealthTrue00TrueErrorNormalTrue
Microsoft.AdvancedThreatAnalytics.1_7.Gateway.GatewayUpdaterResourceManagerCommitMemoryMaxSizeGatewayUpdaterResourceManager 提交内存最大大小轻型网关进程可使用的提交内存的最大值(以字节为单位)Microsoft.AdvancedThreatAnalytics.1_7.Gateway.GatewayUpdaterResourceManagerCommitMemoryMaxSizeMicrosoft.AdvancedThreatAnalytics.1_7.GatewayPerformanceCollectionTrueMicrosoft ATA Gateway UpdaterGatewayUpdaterResourceManager Commit Memory Max Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Gateway.GatewayUpdaterResourceManagerCPUTimeMax_GatewayUpdaterResourceManager CPU 时间最大 \%轻型网关进程可使用的 CPU 时间的最大值(以百分比表示)Microsoft.AdvancedThreatAnalytics.1_7.Gateway.GatewayUpdaterResourceManagerCPUTimeMax_Microsoft.AdvancedThreatAnalytics.1_7.GatewayPerformanceCollectionTrueMicrosoft ATA Gateway UpdaterGatewayUpdaterResourceManager CPU Time Max \%3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Gateway.GatewayUpdaterResourceManagerWorkingSetLimitSizeGatewayUpdaterResourceManager 工作集限制大小轻型网关进程可使用的物理内存的最大值(以字节为单位)Microsoft.AdvancedThreatAnalytics.1_7.Gateway.GatewayUpdaterResourceManagerWorkingSetLimitSizeMicrosoft.AdvancedThreatAnalytics.1_7.GatewayPerformanceCollectionTrueMicrosoft ATA Gateway UpdaterGatewayUpdaterResourceManager Working Set Limit Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Gateway.HostEntryInHOSTSFileHOSTS 文件中包含一个指向计算机简称的主机条目监视 Microsoft ATA 1.7 网关的规则 - HOSTS 文件中包含一个指向计算机简称的主机条目Microsoft.AdvancedThreatAnalytics.1_7.Gateway.HostEntryInHOSTSFileMicrosoft.AdvancedThreatAnalytics.1_7.GatewayAvailabilityHealthTrue00TrueErrorNormalTrue
Microsoft.AdvancedThreatAnalytics.1_7.Gateway.MessageAnalyzerIsInstalledOnGateway已在 ATA 网关安装消息分析器监视 Microsoft ATA 1.7 网关的规则 - 消息分析器安装于 ATA 网关上Microsoft.AdvancedThreatAnalytics.1_7.Gateway.MessageAnalyzerIsInstalledOnGatewayMicrosoft.AdvancedThreatAnalytics.1_7.GatewayAvailabilityHealthTrue00TrueErrorNormalTrue
Microsoft.AdvancedThreatAnalytics.1_7.Gateway.NetworkActivityTranslatorMessageData0BlockSizeNetworkActivityTranslator 消息数据 0 块大小排队等待转换为网络活动(NA)的流量Microsoft.AdvancedThreatAnalytics.1_7.Gateway.NetworkActivityTranslatorMessageData0BlockSizeMicrosoft.AdvancedThreatAnalytics.1_7.GatewayPerformanceCollectionTrueMicrosoft ATA GatewayNetworkActivityTranslator Message Data 0 Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Gateway.NetworkActivityTranslatorMessageData1BlockSizeNetworkActivityTranslator 消息数据 1 块大小排队等待转换为网络活动(NA)的流量Microsoft.AdvancedThreatAnalytics.1_7.Gateway.NetworkActivityTranslatorMessageData1BlockSizeMicrosoft.AdvancedThreatAnalytics.1_7.GatewayPerformanceCollectionTrueMicrosoft ATA GatewayNetworkActivityTranslator Message Data 1 Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Gateway.NetworkActivityTranslatorMessageData2BlockSizeNetworkActivityTranslator 消息数据 2 块大小排队等待转换为网络活动(NA)的流量Microsoft.AdvancedThreatAnalytics.1_7.Gateway.NetworkActivityTranslatorMessageData2BlockSizeMicrosoft.AdvancedThreatAnalytics.1_7.GatewayPerformanceCollectionTrueMicrosoft ATA GatewayNetworkActivityTranslator Message Data 2 Block Size3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Gateway.NetworkListenerETWDroppedEvents_SecNetworkListener ETW 丢弃事件数/秒ATA 网关每秒丢弃的流量Microsoft.AdvancedThreatAnalytics.1_7.Gateway.NetworkListenerETWDroppedEvents_SecMicrosoft.AdvancedThreatAnalytics.1_7.GatewayPerformanceCollectionTrueMicrosoft ATA GatewayNetworkListener ETW Dropped Events/Sec3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Gateway.NetworkListenerPEFDroppedEvents_SecNetworkListener PEF 丢弃事件数/秒ATA 网关每秒丢弃的流量Microsoft.AdvancedThreatAnalytics.1_7.Gateway.NetworkListenerPEFDroppedEvents_SecMicrosoft.AdvancedThreatAnalytics.1_7.GatewayPerformanceCollectionTrueMicrosoft ATA GatewayNetworkListener PEF Dropped Events/Sec3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Gateway.NetworkListenerPEFParsedMessages_SecNetworkListener PEF 分析消息数/秒ATA 网关每秒处理的流量Microsoft.AdvancedThreatAnalytics.1_7.Gateway.NetworkListenerPEFParsedMessages_SecMicrosoft.AdvancedThreatAnalytics.1_7.GatewayPerformanceCollectionTrueMicrosoft ATA GatewayNetworkListener PEF Parsed Messages/Sec3000FalseTrue
Microsoft.AdvancedThreatAnalytics.1_7.Gateway.OtherPendingInstallations计算机上存在其他挂起的安装监视 Microsoft ATA 1.7 网关的规则 - 计算机上存在其他挂起的安装Microsoft.AdvancedThreatAnalytics.1_7.Gateway.OtherPendingInstallationsMicrosoft.AdvancedThreatAnalytics.1_7.GatewayAvailabilityHealthTrue00TrueErrorNormalTrue
Microsoft.AdvancedThreatAnalytics.1_7.Gateway.PEFWasNotInstalledCorrectlyPEF (消息分析器)未正确安装监视 Microsoft ATA 1.7 网关的规则 - PEF (消息分析器)未正确安装Microsoft.AdvancedThreatAnalytics.1_7.Gateway.PEFWasNotInstalledCorrectlyMicrosoft.AdvancedThreatAnalytics.1_7.GatewayAvailabilityHealthTrue00TrueErrorNormalTrue
Microsoft.AdvancedThreatAnalytics.1_7.Gateway.PIDsWasEnabledForProcessNamesInGateway已针对 ATA 网关中的进程名称启用 PID监视 Microsoft ATA 1.7 网关的规则 - 已针对 ATA 网关中的进程名称启用 PIDMicrosoft.AdvancedThreatAnalytics.1_7.Gateway.PIDsWasEnabledForProcessNamesInGatewayMicrosoft.AdvancedThreatAnalytics.1_7.GatewayAvailabilityHealthTrue00TrueErrorNormalTrue