DeviceTvmInfoGathering

DeviceTvmInfoGathering Schema #

Table description #

TableSection TableType TableSectionName Description
Tvm Regular The DeviceTvmInfoGathering table contains Threat & Vulnerability Management assessment events including the status of various configurations and attack surface area states of devices.

Table retention #

HotDays ColdDays TotalInteractiveDays
30 0 30

Schema #

Name Description Type
AdditionalFields Additional information about the entity or event Object
DeviceId Unique identifier for the device in Microsoft Defender for Endpoint String
DeviceName Fully qualified domain name (FQDN) of the device String
LastSeenTime Date and time when the service last saw the device DateTime
OSPlatform Platform of the operating system running on the device. This indicates specific operating systems, including variations within the same family, such as Windows 10 and Windows 7 String
Timestamp Date and time when the record was generated DateTime

Schema changes #

Date Action
2026-02-27 Column TenantId removed
2026-02-27 Column Type removed
2026-02-27 Column SourceSystem removed
2026-02-27 Column MachineGroup removed
2024-10-18 Table added to tracking