CommonSecurityLog Table does not show Outcome Field in Sentinel Workspace
CommonSecurityLog Table does not show Outcome Field in Sentinel Workspace
Document Details
⚠ Do not edit this section. It is required for learn.microsoft.com ➟ GitHub issue linking.
- ID: 34e19f18-b108-2702-eac9-86ed2f1b0e82
- Version Independent ID: b2d206e7-61cf-781b-1d8a-6ff4e6116233
- Content: Common Event Format (CEF) key and CommonSecurityLog field mapping
- Content Source: articles/sentinel/cef-name-mapping.md
- Service: microsoft-sentinel
- GitHub Login: @limwainstein
- Microsoft Alias: lwainstein

The outcome is shown in AdditionalExtensions but not in its own Outcome field as explained in the Official Docs.

@LaraibKhan555
Thanks for your feedback! We will investigate and update as appropriate.
@LaraibKhan555 I can see in the mentioned link that Outcome field is explained in the docs. https://learn.microsoft.com/en-us/azure/sentinel/cef-name-mapping#m---p Can you explain in detail what needs to be done from our end.
Also kindly share details regarding

There's no Outcome field in the CommonSecurityLog table as written in the documentation, but there's one field called EventOutcome in the sentinel CommonSecurityLog schema.

However, our raw log includes outcome value (success, failure) but it does not appear in the CommonSecurityLog table in sentinel.
SEC-CommonSecurityLog Schema Outcome Field Mapping Issue-131222-1023.pdf
Attaching pdf to explain the issue.
@LaraibKhan555 Thanks for elaborating so well. It makes sense that outcome shown in official docs should be replaced with "Event Outcome". @limwainstein Kindly provide your inputs.
Also note, the issue is not a simple documentation error.
If the outcome is present in the RAW event it should also appear in the CommonSecurityLog table schema under the EventOutcome field.
Thank you for raising this @LaraibKhan555 . We've fixed the doc issue. https://learn.microsoft.com/en-us/azure/sentinel/cef-name-mapping#m---p
With regards to changes to the schema, please open a Support ticket or consult with the PM team.
#please-close