Skip to main content

Supported Alert Fields

Supported Compliance Findings

Rules

A control states an outcome; a rule is one criterion behind it. “Ensure diagnostic settings capture the right categories” can be failed for several separate reasons, and a rule is the one each finding actually failed. Ask for them with includeRules=true on List Compliance Data and includeRule=true on List Compliance Findings. Both are opt-in: a request without them returns exactly what it returned before. A control then carries rules, each with the counts the tool publishes for that rule under that control, plus rule_counts summarising how many of its rules pass, fail or do not apply. A finding carries rule, the criterion it failed, as {id, vendor_id, name}. The counts belong to the pairing of a rule and a control, not to the rule alone: one criterion cited by two controls can report different numbers under each, and Leen keeps both rather than picking one.
A field a tool does not publish comes back empty rather than guessed. Microsoft Defender for Cloud, for example, publishes no unsupported-resource count and no rule logic, and a definition nothing in the tenant is assessed against carries no description, remediation or severity.
For any additional information about our field mappings or integrations please contact us.