Authomation Rule Condition
Properties
The property to use for evaluate the condition. Possible values are AccountAadTenantId
, AccountAadUserId
, AccountNTDomain
, AccountName
, AccountObjectGuid
, AccountPUID
, AccountSid
, AccountUPNSuffix
, AlertAnalyticRuleIds
, AlertProductNames
, AzureResourceResourceId
, AzureResourceSubscriptionId
, CloudApplicationAppId
, CloudApplicationAppName
, DNSDomainName
, FileDirectory
, FileHashValue
, FileName
, HostAzureID
, HostNTDomain
, HostName
, HostNetBiosName
, HostOSVersion
, IPAddress
, IncidentCustomDetailsKey
, IncidentCustomDetailsValue
, IncidentDescription
, IncidentLabel
, IncidentProviderName
, IncidentRelatedAnalyticRuleIds
, IncidentSeverity
, IncidentStatus
, IncidentTactics
, IncidentTitle
, IncidentUpdatedBySource
, IoTDeviceId
, IoTDeviceModel
, IoTDeviceName
, IoTDeviceOperatingSystem
, IoTDeviceType
, IoTDeviceVendor
, MailMessageDeliveryAction
, MailMessageDeliveryLocation
, MailMessageP1Sender
, MailMessageP2Sender
, MailMessageRecipient
, MailMessageSenderIP
, MailMessageSubject
, MailboxDisplayName
, MailboxPrimaryAddress
, MailboxUPN
, MalwareCategory
, MalwareName
, ProcessCommandLine
, ProcessId
, RegistryKey
, RegistryValueData
and Url
.