Supported Alert Fields
Supported Compliance Findings
Rules
A control states an outcome; a rule is one criterion behind it. “Ensure diagnostic settings capture the right categories” can be failed for several separate reasons, and a rule is the one each finding actually failed. Ask for them withincludeRules=true on List Compliance Data
and includeRule=true on List Compliance Findings.
Both are opt-in: a request without them returns exactly what it returned before.
A control then carries rules, each with the counts the tool publishes for that rule under that
control, plus rule_counts summarising how many of its rules pass, fail or do not apply. A
finding carries rule, the criterion it failed, as {id, vendor_id, name}.
The counts belong to the pairing of a rule and a control, not to the rule alone: one criterion
cited by two controls can report different numbers under each, and Leen keeps both rather than
picking one.
A field a tool does not publish comes back empty rather than guessed. Microsoft Defender for
Cloud, for example, publishes no unsupported-resource count and no rule logic, and a definition
nothing in the tenant is assessed against carries no description, remediation or severity.